Access to Accounting Systems and Commercial Books

Earlier this year, following a webinar on UAE tax audits that we hosted with Mahmoud Abuwasel, we posted on a point that surprises many businesses: during a tax audit the FTA may inspect not only the documents a company chooses to submit, but the accounting system itself. The authority is Article 17(1)(c) of Cabinet Decision No. 74 of 2023, which permits the Authority, for the purposes of conducting a Tax Audit, to inspect the accounting systems used by the Person subject to the Tax Audit. Our conclusions then were that:
- the power is real though not routinely exercised.
- the access may extend beyond what the taxpayer intended to submit, including user activity logs and change history where the auditor tests the integrity of records; and
- the sensible responses are:
- to keep out of the accounting system anything one would not expect to disclose,
- to segregate accounting modules from operational modules, and
- to treat ERP access as a potential audit deliverable rather than an abstract risk.
None of that has been displaced. What has moved is the setting. On 2 June 2026 the Chairman of the Board of Directors of the FTA issued Decision No. 4 of 2026 on the Rules and Requirements for Maintaining the Information Contained in Accounting Records and Commercial Books, following Board approval at the 44th meeting of 30 April 2026. It runs to five articles. In those five articles:
- the system-access power is lifted out of the audit chapter and restated as a general record-keeping obligation;
- a right of access to the physical places where copies are stored appears for the first time; and
- taxpayers are required to surrender encryption keys and passwords.
This article addresses four questions that follow:
- What exactly must now be made accessible, and in how many distinct forms?
- What are “accounting records and commercial books”, and where in a taxpayer’s systems do they sit?
- Does the Decision stay within the authority delegated to the FTA?
- How should systems and documentation be organized so that compliance is straightforward and the perimeter of any access is defined in advance rather than negotiated under pressure?
The Decision, in outline
- Article 1 defines two terms and only two: Electronic Copy (a document or record created, saved or converted in electronic format so that it can be viewed, retrieved and read through electronic systems or media) and Photocopy (an identical copy produced by photocopying, scanning or photographic reproduction, preserving the content and form of the original clearly and legibly).
- Article 2 lays down three rules for maintaining the information contained in accounting records and commercial books:
- the records and books must be complete and identical to the original documents;
- they must be clear and easily legible; and
- “access to the records and commercial books must be provided to the Authority upon request, including access to the system in which such records and commercial books are saved”.
- Article 3 turns each rule into requirements:
- on completeness, the copy must be identical and must include all pages in the same order, and partial scanning of any part of the document shall not be accepted;
- on legibility, the data must be clear on a computer screen, and ink and paper must be of a quality that prevents fading during the record-keeping period, a monochrome copy of a colour document being acceptable if the data remain legible.
- on access, Article 3(3) provides that “the Authority must be able to access the records and commercial books retained in the form of an Electronic Copy or a Photocopy upon request, in accordance with Clause 3 of Article 2 of this Decision, as follows:
- Where the Electronic Copies or systems in which they are kept are protected by encryption or passwords, the Person must provide the encryption keys or passwords necessary to enable access to the Authority.
- Access to Photocopies must be available, including the places where they are stored”.
- Article 4 permits a Person to engage a third party to maintain the records and books, but the Person remains legally responsible for maintaining them and ensuring their safety. Article 5 governs commencement.
Three access objects, not one
- It is tempting to read Articles 2(3) and 3(3) as a single undifferentiated duty to “let the FTA in”. They are not. Read together, they describe three distinct objects, each with its own trigger and its own natural boundary.
Provision Object of access Where it typically sits Art. 2(3) The records and commercial books themselves, and the system in which they are saved The accounting application or ERP finance modules Art. 3(3)(a) Electronic Copies, and the systems in which those copies are kept, together with the keys or passwords Document management system, shared drive, cloud archive, i.e. often not the accounting application Art. 3(3)(b) Photocopies, and the physical places where they are stored An archive room, a storage unit, a third-party records facility
- The third object is genuinely new and has attracted almost no comment. Article 3(3)(b) confers a right of physical access to premises by way of an FTA decision, unlinked from any audit. That is a striking place for such a power to appear, because the primary law already addresses precisely this subject and addresses it with care. Article 16(3) of Tax Procedures Law provides that the FTA “may perform the Tax Audit at its premises or the place of business of the Person subject to the Tax Audit or any other place where such Person conducts Business, stores goods or keeps records”. Therefore, the place where records are kept is already recognized as a place the Authority may attend, but expressly as a venue for conducting a Tax Audit, and on at least ten days’ prior notice under Article 16(2). Article 17 sets forth that the tax auditor may “access original records or photocopies”, or seize them but, expressly, “while conducting the Tax Audit”.
- Article 3(3)(b) of the Decision sits outside every element of that structure. It makes access to the place of storage an incident of the record-keeping obligation itself, exercisable on request: no audit, no notice period, no Director-General’s consent, no prosecutorial permission where the archive happens to be located in a residence, which, for sole establishments and small businesses that keep their paper records at home, is not a hypothetical. If any limb of the Decision invites narrow interpretation, it is this one, and we return to the point later in this study.
- The practical significance of the three-way split is that a request engages one object, not all three:
- a request for access to the environment holding electronic copies of invoices is not a request for the general ledger;
- a request to inspect a paper archive is not a request for system credentials.
But whether a taxpayer can actually respond that narrowly (opening only what was asked for and nothing else) depends entirely on how its systems were organized long before the request arrived. That is the subject of discussion later in this study.
The perimeter is described, but not located
- Article 2(3) of the Decision fixes the object of access by reference to “the records and commercial books” and to the system in which “such” records and books are saved. Neither the Tax Procedures Law nor the Decision defines that expression. The Executive Regulation does, in Article 2(1)(a), but it does so functionally: business records and books in which payments, receipts, purchases, sales, revenues, expenses and any other items required by the Tax Law or any other applicable law are recorded, “including without limitation” the balance sheet and profit and loss accounts, wages and salaries records, fixed asset records, and inventory records and statements. The definition is by content, and it is expressly open-ended.
- The expression itself is borrowed from the Commercial Transactions Law No. 50 of 2022, Book 1, Section 1, Chapter 3, headed “Commercial Books”, where Article 25 requires the trader to keep books that accurately reflect his financial position and his rights and liabilities related to his trade, and Article 25(2) identifies two of them: the General Journal and the General Ledger. For tax purposes, however, the class defined by the Executive Regulation is the wider one, and it is the Executive Regulation that governs the record-keeping obligation to which the Decision attaches.
- One boundary within that class matters for what follows: supporting documents are treated separately from the books themselves. Article 2(1)(b) of the Executive Regulation covers correspondence, invoices, licenses and contracts, and documents recording any election, assessment, determination or calculation, as a category distinct from the records and books in Article 2(1)(a). The Commercial Transactions Law draws the same line, imposing in its Article 29 a separate five-year retention duty for correspondence, invoices and other documents of the trade, and referring in Article 29(2) to “the commercial books and the documents supporting the entries made therein” as distinct things.
The consequence: the taxpayer should map its records to its systems, in writing
- The legislation says what the records are. It says nothing about where they are. In a paper world the two questions collapsed: the ledger was a book, and the book was on a shelf. In an integrated accounting environment they come apart, and neither the Decision, nor the Executive Regulation, nor the Tax Procedures Law performs the mapping. The taxpayer is the only party positioned to do it, and it should do so deliberately rather than by default.
- Every UAE taxpayer should record, in its accounting policy or an internal record-keeping procedure adopted alongside it:
- an identification of which of its ledgers, registers, reports and repositories hold the records and books described in Article 2(1)(a) of Cabinet Decision No. 74 of 2023, and the supporting documents described in Article 2(1)(b); and
- precisely where in its systems each of them is held.
The designation should track the statutory categories, item by item, and should identify the module, ledger or repository for each:
- general ledger and journals;
- balance sheet and profit and loss;
- payroll records;
- fixed asset register;
- inventory records and stock counts; and,
- listed separately, the supporting documents governed by Article 2(1)(b).
- Such a document does three things at once:
- it evidences compliance with the maintenance obligation itself;
- it gives the finance team an unambiguous rule about where records must be posted and stored, which is what makes the designation true rather than aspirational; and
- it identifies, in advance and on the taxpayer’s own terms, what “the system in which such records and commercial books are saved” actually is. A taxpayer that has never asked itself that question will find it answered for it, expansively, at the least convenient moment.
- Two cautions should be nevertheless factored in:
- The mapping locates the statutory class. It does not define it. Article 2(1)(a) applies “including without limitation”, so a policy cannot narrow the class by omitting from its list a record in which sales, purchases, receipts or payments are in fact entered.
- The mapping must be accurate: a policy pointing to a tidy sub-ledger while the substantive accounting lives elsewhere would not survive contact with Article 2(1)(a), which measures the class by what is recorded in the records rather than by what they are called. The exercise is one of mapping and disciplined housekeeping, not of relabeling.
Is the access obligation within the delegated authority?
- We raise this question with respect for the Authority’s position and without suggesting the Decision is invalid. The purpose is to distinguish what is firmly anchored in the parent legislation from what rests on construction, because that difference tells a taxpayer how to behave when a request arrives. As we have argued in relation to the limits of FTA-level instruments generally, a subordinate instrument cannot enlarge the obligation it implements, and where it appears to do so the disciplined response is to read it down to the enabling provision rather than to disregard it.
The delegation
- The Decision recites the Constitution, Federal Decree-Law No. 13 of 2016, Federal Decree-Law No. 28 of 2022, Cabinet Decision No. 74 of 2023, and the Chairman’s delegation decision, but no specific article. The delegation must therefore be located by construction. It is Article 4(2) of the Executive Regulation: “The Authority may specify the rules for maintaining the information contained in accounting records and commercial books, and impose reasonable requirements for ensuring that the information will be available as if the original records themselves had been preserved”.
- The title of the Decision is very nearly a transcription of that clause, which puts the identification beyond serious doubt. Article 4(2) sits within Article 4(1)(b), establishing the route under which a taxpayer discharges the record-keeping duty by retaining the information contained in original documents rather than the originals themselves. Article 4(1)(b)(2) provides a condition that “the information is retained or stored in either photocopy or electronic copy, and an easily readable copy of which can be reproduced, if requested by the Authority”. Article 4(1)(b)(3) requires that “the information is retained or stored in a manner that enables the Authority to verify the Person’s Tax obligations”.
Where the Decision extends beyond what preceded it
From audit to standing obligation
- Before this Decision, the only authority to inspect an accounting system was Article 17(1)(c) of the Executive Regulation, expressly confined to the purposes of a tax audit. Article 2(3) of the Decision applies on request. The nearest untethered parent is Article 29 of the Executive Regulation, but Article 29 authorizes the FTA to request “the accounting records, commercial books and any other data and information”. It does not authorize a request for access to a system. The distinction is substantive: a tax audit is a bounded procedure carrying notice under Article 16 of the Tax Procedures Law, defined taxpayer rights under Article 21 and a defined conclusion under Article 22. A standing access duty carries none of that.
From production to access.
- Article 4(1)(b)(2) of the Executive Regulation requires that “an easily readable copy … can be reproduced, if requested”. That is an obligation to produce an output, and it leaves the taxpayer in control of the boundary of the disclosure. Article 2(3) of the Decision is an obligation to admit the Authority into an environment, which transfers that control.
Credential surrender.
- Article 3(3)(a) requires the Person to hand over encryption keys or passwords. Nothing in the Decree-Law or the Executive Regulation says this expressly. Article 20 of the Tax Procedures Law, the broadest cooperation duty in the primary law, requires “a Person subject to a Tax Audit, his Tax Agent or Legal Representative to facilitate and provide assistance to the Tax Auditor to enable him to perform his duties”. This wording is capable of covering the provision of a working access route during an audit, but a considerable distance from compelling the surrender of a credential outside one.
Access to places.
- Article 3(3)(b) is, on its face, the boldest of the four. It converts a record-keeping decision into an instrument conferring physical access to premises, without notice requirements, without the conditions attaching to entry during an audit, and without the safeguards the Decree-Law attaches to the removal of records. If any limb of the Decision invites a reading-down, it is this one.
The object problem, and why it bites hardest on commercial books
- The sharper difficulty is not that an access right exists but how its object is described. Article 2(3) requires access to “the system in which such records and commercial books are saved”. Where the system holds only the books, obligation and object coincide. Where the system holds far more, as a general ERP always does, the literal object of the access right is wider than the obligation it exists to serve.
- Article 4(2) of the Executive Regulation licenses “reasonable requirements for ensuring that the information will be available as if the original records themselves had been preserved”. That is a comparative benchmark: the reference point is the position the Authority would have occupied had originals been kept. Had originals been kept, the Authority would have been entitled to the books and the supporting documents. It would not thereby have obtained the taxpayer’s HR files, board papers, legal correspondence, customer database, pricing models or unrelated business lines unless the tax audit is initiated. A requirement that delivers more than parity with the original-retention position is not, on the face of Article 4(2), a reasonable requirement for the stated purpose; it is a requirement of a different character.
- That reading also runs against the only expression of legislative intention on the subject. The Cabinet addressed access to accounting systems once, in Article 17(1)(c) of the Executive Regulation, and confined it to the purposes of conducting a Tax Audit. Where the delegating authority has itself drawn that line, an instrument made under the delegation cannot be construed as achieving outside an audit what the Cabinet permitted only within one. A construction that produces that result is a reason to doubt the construction.
The reading that keeps the Decision within its parent
- Two arguments point the same way:
- The first is purposive: Article 2(3) should be read as conferring access coextensive with the record-keeping obligation it serves – to the system, or to the part of the system, in which the records and commercial books are in fact kept, and no further.
- The second is textual and, we think, stronger. Article 1 of the Decision defines only “Electronic Copy” and “Photocopy.” Article 3, the operative requirements article, addresses itself throughout to information “retained in either Electronic Copy or Photocopy form”, and the access requirement in Article 3(3) speaks expressly of records “retained in the form of an Electronic Copy or a Photocopy”. That is the vocabulary of Article 4(1)(b) of the Executive Regulation, the copy-retention route, and not of Article 4(1)(a), under which originals are kept.
Read against its enabling provision, the Decision is best understood as regulating the copy-retention election: it tells a taxpayer, who has chosen not to keep originals, what it must do so that its copies stand in the originals’ place. On that construction the access obligation attaches to the environment holding those copies, which is a narrower and far more manageable object than “the accounting system.”
- We do not suggest either reading is beyond argument, or that a taxpayer should decline a request in reliance on them. The realistic posture is the one set out next: the interpretive uncertainty is best resolved not by contesting the Decision but by organizing systems so that the narrow and the broad readings produce the same practical result. Where the books are kept in a defined, separately accessible environment, the two readings have nothing to disagree about.
Practical architecture
- The recommendation we gave in January (segregate accounting modules from operational modules) was offered as prudent housekeeping. Under Article 2(3) of the Decision it does more work than that. Because the obligation attaches to “the system in which such records and commercial books are saved”, and because the taxpayer decides where the records and books described in Article 2(1)(a) of the Executive Regulation are held, the taxpayer largely determines the legal object of the access right by its own configuration choices. Segregation is not merely a way of making an inspection tidier. It is how the perimeter is drawn.
Two ways to separate
- Separation does not require separate software. There are two models, and they are equally effective for present purposes.
Model A. Separation by system.
- Electronic copies of supporting documents are held in a repository distinct from the accounting application: a document management system, a dedicated archive, a controlled file store. The two have different addresses, different credentials and different administrators. A request directed at one does not touch the other, and there is nothing to explain.
Model B. Separation by permission within one system.
- Documents and books sit in the same application,1 but the system’s own role and permission framework is used to create an access profile that reaches only the document repository, or only the designated record objects, without exposing the remainder. Modern accounting platforms support this natively: roles are defined by module and by permission, and a role can be granted read access to attachments and specified reports while every other module remains invisible to it. Model B is usually the practical answer, because it requires no migration and no change to how the finance team works.
- Whichever model is adopted, three elements should be in place before any request arrives:
- A pre-provisioned, scoped and read-only access profile, configured, named, documented in the record-keeping policy, and mapped to the designated record objects. Article 3(3)(a) of the Decision requires the keys or passwords necessary to enable access; where a scoped credential enables the requested access, that is the credential the provision calls for. An administrator login goes beyond what is required and exposes what has not been asked for.
- A tested route. An access path that has never been exercised will fail when it is first used, and from the outside a failed access is hard to distinguish from a refusal. Rehearse it, and keep evidence that it was rehearsed.
- Clean contents. Legal advice, board material, HR files, commercial strategy and unrelated business lines should not sit inside the perimeter that Decision’s Article 2(3) opens. This was the first of our January recommendations and it is unchanged.
Separation is worth doing even if the Authority’s power is wider
- A client will reasonably ask why any of this matters if the FTA’s power turns out, on the broad reading, to extend beyond the place where the documents are stored. The answer is that the scope of the request governs the scope of the response, whatever the outer limit of the power may be.
- Suppose the FTA requests under an Article 3(3)(a) access to the system in which electronic copies of supporting documents are kept. The taxpayer’s obligation is to enable access to that. It is entirely proper, and it is good practice, to provide precisely that and no more: access to the documents, without opening the accounting system or broader environment, none of which have been requested. Even on the widest view of what the Authority could ask for, it has not asked. Responding to the request actually made is not obstruction; it is accuracy, and it preserves the ordinary discipline that an authority’s exercise of a power is bounded by the terms in which it is exercised. If the Authority wishes to widen the request, it can, and the taxpayer should comply with the wider request in turn, having preserved, in the meantime, a clear record of what was asked and what was given.
- That answer is only available to a taxpayer whose architecture can deliver it. Where every record sits behind a single login, a request for the documents is, in practice, a request for everything, because there is no narrower thing to give. Separation (by system or by permission) is what converts a legal distinction into an operational one.
Third parties, groups and offshore hosting
- Article 4 permits outsourcing but leaves legal responsibility with the Person. Responsibility and control are therefore separated: the duty binds the taxpayer while the credentials, the infrastructure and often the physical archive sit with a bookkeeping provider, a group shared service center or a cloud host. Engagement letters and service agreements should carry an express obligation to enable access to the Authority on request within a defined period, credential custody arrangements, an indexing and retention standard, and an undertaking to preserve and return records on termination.
- Where books are held on a group server outside the UAE, granting access to an environment situated abroad may engage foreign data protection or localisation rules and will almost always engage group IT security policy. That is not a question to begin resolving inside the period the Authority allows for compliance. The cleanest solution is usually a UAE-resident mirror of the designated record objects maintained under Article 4(1)(b) of the Executive Regulation, which is precisely the arrangement Decision No. 4 of 2026 exists to regulate.
Other consequences that follow from the Decision
Partial scanning is now expressly prohibited
- Article 3(1)(b) states that partial scanning of any part of a document shall not be accepted, and Article 3(1)(a) requires all pages in the same order as the original. In our experience this is the most frequently breached provision in the entire Decision, and the breach is usually invisible to management: scanning workflows routinely capture the face of an invoice and drop annexes, standard terms, delivery notes or the Arabic counterpart. Where the copy is the retained record, an incomplete scan is a failure of the record-keeping obligation itself, not a housekeeping lapse. Scanning procedures should be audited against Article 3(1) and the result documented.
Media degradation is now a compliance question
- Article 3(2)(b) requires that ink and paper be of a quality preventing fading over the record-keeping period. Thermal-paper receipts and older toner copies will not survive that period. They should be converted, and the conversion should itself satisfy Article 3(1).
What is written into the system may become evidence
- The FTA accredits accounting software, and the accredited products in common use such as Zoho Books, which is also an accredited Digital Tax Integrator supporting direct VAT filing, and First BIT ERP. They are designed to capture not only transactions but the narrative around them. Zoho Books prompts for, or permits, a reason when an entry is edited. Both above products maintain audit trails, user attribution and change history as standard. These features exist for sound internal-control reasons, but once Article 2(3) is engaged they are no longer purely internal.
- Two provisions give the point legal weight.
- The first is Article 31 of Commercial Transaction Law: “Entries and incidents recorded in commercial books by the merchant’s authorized employees shall be deemed as entries recorded by the merchant himself, and it shall be assumed that such entries were made with his knowledge and consent until he proves otherwise”. That is a rebuttable presumption of attribution and knowledge: what an authorized user writes into the books is treated as written by the business, with its knowledge and consent, unless the contrary is proved. A free-text explanation attached to an entry is not obviously outside that presumption.
- The second is the role awareness plays across the penalty and offence provisions2. Under Article 10(1) of Tax Procedures Law, a Voluntary Disclosure should be submitted “if a Taxable Person becomes aware that a Tax Return … is incorrect”. Under Article 25(2), tax evasion turns on deliberate acts and omissions. Under Article 25(4)(b), intentionally hiding or destroying documents required to be kept and provided is a distinct offence. In each case the pivotal fact is what was known and when. A dated comment inside an accessible system can fix that date with a precision no witness could achieve: favourably or unfavourably.
- The answer is not to suppress commentary. Quite apart from degrading the internal controls the Authority expects to see, Article 25(4)(b) of Tax Procedures Law makes it an offence to hide or destroy documents, data, information or other materials required to be kept and provided to the Authority, and Article 25(4)(a) makes the provision of false information an offence in its own right. Therefore, everything the legislation requires to be recorded must be recorded, completely and accurately, and once created, a record is not removed or altered to improve its appearance.
- The narrative fields in a modern accounting system (the reason prompted on an edit, the memo attached to a journal, the internal note on a reconciliation) are, for the most part, not required by any tax or commercial legislation. They are a facility the software offers, and the taxpayer has a genuine choice about how to use it. That choice should be exercised deliberately, because at present it is usually exercised by accident: these notes are typed by staff who have no reason to imagine that the FTA will ever read them, and who are not in a position to state a tax conclusion accurately. The result is commentary that is speculative rather than considered, and that is frequently simply wrong. For example, a note recording that a treatment “looks incorrect” may attach to a position that is, on proper analysis, entirely correct. An inaccurate annotation serves nobody: it misleads the business’s own management, it will be read as an admission it was never meant to be, and it is a poor record of what actually happened.
- Treated carefully, the same facility is an opportunity. A comment that records what was done, on what basis, and by reference to the authorizing instruction, document or accounting policy is a contemporaneous record of the reasoning behind an entry. This is precisely the evidence a business wants when a position is questioned years later. Where an error is identified, a dated note recording its identification and escalation is directly relevant under Article 10(1) of Tax Procedures Law, where the voluntary disclosure obligation is triggered by awareness, and relevant to the question of deliberateness under Article 25(2). The presumption in Article 31 of Commercial Transactions Law, which treats what authorized users write as written with the knowledge and consent of the business, works as readily in the taxpayer’s favor as against it.
- A comment discipline policy should therefore be adopted as an ordinary element of internal control, and should address at least the following:
- Narrative commentary states facts and their documented basis (what was done, on whose instruction, under which policy) rather than conclusions about tax consequences, which the person entering the comment is generally not qualified to reach.
- Unconsidered speculation about tax treatment by staff who are not in a position to reach a conclusion should be avoided.
- The policy should accordingly identify who is authorized to add narrative commentary and to what standard, distinguishing routine descriptive notes, which any competent bookkeeper may make, from commentary on tax treatment, which should be reserved to persons qualified to reach that conclusion.
- Where a record involves a genuinely uncertain treatment, the better course is that an authorised person (someone competent to reach a tax conclusion, identified as such in the policy) records the position and the reasoning that supports it:
- the grounds on which the treatment was adopted,
- the provisions and any guidance relied upon, and
- where the point is arguable, an acknowledgement that it is arguable together with the reasons for adopting the treatment chosen.
Suppose that position is later challenged on audit and held to be wrong, whether by the Authority or on appeal. The contemporaneous note is then evidence of something distinct from the substantive outcome: that the treatment was the product of considered analysis rather than of an intention to reduce the tax due. That distinction is decisive under Article 25(2) of the Tax Tax Procedures Law, where every limb of tax evasion turns on the taxpayer having acted deliberately, and under Article 25(4)(a), which requires that false information be provided intentionally.
- The point extends beyond the criminal provisions, and this is where the practice earns its keep. The obligation to submit a voluntary disclosure under Article 10(1) and (2) of the Tax Procedures Law is a triggered duty, activated only when the taxpayer becomes aware of the relevant inaccuracy, and that awareness is accordingly an element of the violation the Authority must establish rather than a matter it may presume.3 What a system records about the taxpayer’s state of mind therefore is directly relevant, and Article 2(3) has now made those records accessible on request.
- The consequence cuts both ways, and precisely along the line drawn above:
- a careless annotation recording unexamined doubt supplies the Authority with a dated fixing of awareness that it would otherwise have to prove, and does so in the taxpayer’s own words;
- a reasoned note explaining why a treatment was adopted evidences the opposite: that the taxpayer considered the position and concluded it was correct, which is to say that no awareness of an error had arisen, and that the Article 10 trigger had not been activated.
The same field, on the same day, can produce either result.
- Two limits should be stated plainly:
- The analysis above bears on obligations whose elements include a state of mind: the offence provisions in Article 25, and the voluntary disclosure duty in Article 10 on the reading we have advanced. It does not answer the penalty for submitting an incorrect return, which is properly assessed against an objective standard of due care and which no annotation improves. A well-reasoned position that proves incorrect remains an incorrect position with its ordinary consequences.
- The protection lies in the reasoning, not in the record’s existence. Take a note recording that “there is a risk of unfavourable interpretation, but we believe it is not wrong”. It states a belief, but gives no grounds for it. Or take a note showing that the person knew there were two possible treatments, knew which produced less tax, and chose that one. It records a preference, not a conclusion. Neither gives any reason for thinking the chosen treatment was correct.That distinction matters because of what awareness under Article 10 actually requires. A taxpayer who analysed a question and concluded the treatment was right was not aware of an error. There was, in their considered view, no error to be aware of. That is where the defensive position is available. But a taxpayer who merely preferred one treatment has not concluded anything. They have documented, in their own words, that they were conscious of a live question and resolved it by reference to outcome rather than to law.A note of that kind therefore works against the taxpayer twice over. It fixes the date on which the taxpayer knew the question was open, which the Authority would otherwise have to establish. And it offers nothing to show that the question was resolved. The practice protects only where the analysis it records was actually performed, and where the note sets out enough of that analysis for a reader to see it was.
Penalties
- Failure to keep the required records and failure to facilitate the work of a tax auditor are separately penalized under Article 24(1)(a) and (m) of Tax Procedures Law, priced under Cabinet Decisions No. 129 of 2025 and 75 of 2023. Decision No. 4 of 2026 does not create new penalties. It enlarges the set of acts and omissions capable of engaging the existing ones.
Conclusion
- Decision No. 4 of 2026 does not create the Authority’s interest in accounting systems. That interest was already visible in Article 17(1)(c) of the Executive Regulation and was the subject of our January commentary, which remains accurate as far as it goes. What the Decision changes is the character of the obligation: a power that was exceptional, audit-bound and procedurally framed becomes a standing compliance requirement, extended for the first time to encryption keys, passwords, and the physical places where records are stored.
- Whether the access obligation, read literally, exceeds the delegation in Article 4(2) of the Executive Regulation is a fair question, and one we raise in the spirit of clarifying the instrument rather than resisting it. A reading under which access is coextensive with the record-keeping obligation, and directed at the copy-retention route to which the Decision’s own defined terms point, keeps the Decision comfortably within its parent and is, we suggest, the better construction. Confirmation from the FTA would be welcome, and the point is well suited to a public clarification.
- Pending that, effort is better spent on architecture than on argument. Five things are worth doing now:
- Map the statutory records to your systems, in writing. Record in the accounting policy which ledgers, registers, reports and repositories hold the records and books described in Article 2(1)(a) of the Executive Regulation, and which hold the supporting documents described in Article 2(1)(b).
- Separate the document repository from the ledgers either by holding them in different systems, or by using the permission framework of a single system to keep them separately accessible.
- Set up a scoped, read-only access profile, and test that it works. It should reach only the mapped records, and it should be exercised before it is ever needed.
- Answer the request that was made, not the one that could have been. Where the FTA asks for the environment holding electronic copies, provide access to that environment and no more.
- Govern what is written into the system as carefully as what is posted to it. Narrative fields are read by the FTA on the same terms as entries.
A business that does those things will find that the difference between the narrow and the broad reading of Article 2(3) never has to be argued.
Disclaimer
Pursuant to the MoF’s press-release issued on 19 May 2023 “a number of posts circulating on social media and other platforms that are issued by private parties, contain inaccurate and unreliable interpretations and analyses of Corporate Tax”.
The Ministry issued a reminder that official sources of information on Federal Taxes in the UAE are the MoF and FTA only. Therefore, analyses that are not based on official publications by the MoF and FTA, or have not been commissioned by them, are unreliable and may contain misleading interpretations of the law. See the full press release here.
The same reservation applies to the judicial issues addressed in this article. This study has not been commissioned, authorised, or endorsed by the Ministry of Justice, the Federal Supreme Court, or any other judicial authority in the UAE. It is not intended to convey, and should not be understood as conveying, any official position of those authorities. Nor does it purport to suggest that the interpretations, conclusions, or proposals set out in it are binding on the courts or must necessarily be adopted in judicial practice.
You should factor this in when dealing with this article as well. It is not commissioned by the MoF or FTA. The interpretation, conclusions, proposals, surmises, guesswork, etc., it comprises have the status of the author’s opinion only. Furthermore, it is not legal or tax advice. Like any human job, it may contain inaccuracies and mistakes that I have tried my best to avoid. If you find any inaccuracies or errors, please let me know so that I can make corrections.
1 The ordinary position for users of accredited products such as Zoho Books or First BIT ERP, where scanned attachments live alongside the entries they support.
2 See our earlier study “Voluntary Disclosure penalties in the UAE: why “awareness” should be treated as an element of the violation”, available at link.
3 Ibid