Quick answer
Under Regulation 10 of the DIFC Data Protection Law, any AI system used for High Risk Processing Activities must be certified by an Accredited Certification Body (ACB) approved by the DIFC Commissioner before it can be commercially operated. Certification confirms the system meets the requirements set out in the Regulation 10 Accreditation and Certification Framework. As of June 2026, White Label Consultancy is the only external body accredited by the DIFC to carry out this certification. System certification is valid for up to three years, subject to ongoing monitoring.
Why Does Certification Exist?
Regulation 10.3.3 of the DIFC Data Protection Regulations prohibits commercial operation of any AI system for High Risk Processing unless the system has been certified. The certification requirement exists because a mandatory DPIA alone does not constitute proof of compliance. Certification is the external, independent confirmation that a system has been assessed against the Commissioner's published standards and found to meet them.
Without certification, a firm cannot lawfully use, operate, provide, or offer an AI system for High Risk Processing. This applies to Deployers, the organisations under whose authority the system runs, and Operators, the providers who operate or supervise the system on a Deployer's behalf.
What Does the Certification Framework Require?
The Commissioner published the Regulation 10 Accreditation and Certification Framework to implement Articles 50 and 51 of the DIFC Data Protection Law. Part 2 of that Framework sets out what a system must demonstrate to be certified. The certification assessment covers four areas:
Principles applicable to Deployers, Operators, and Providers. The system must be designed to be ethical, fair, transparent, secure, and accountable. It must process personal data only for human-defined or human-approved purposes. Systems capable of setting their own processing purposes must remain within human-defined constraints.
Third parties and compliance. The firm must demonstrate that third-party providers involved in the system's operation are also meeting their obligations under Regulation 10 and the DIFC Data Protection Law.
Governance and oversight. The firm must show that appropriate governance structures are in place, including a named Autonomous Systems Officer (ASO) and documented accountability for the system's operation and outputs.
Audit criteria. The system must produce evidence of compliance with applicable audit requirements, including records of algorithmic triggers for human intervention when processing may lead to unfair or discriminatory outcomes.
Who Can Certify an AI System Under Regulation 10?
Only an Accredited Certification Body approved by the Commissioner can certify a system. The Commissioner accredits these bodies under Article 51 of the DIFC Data Protection Law. Accreditation is valid for five years, subject to periodic reviews.
To become accredited, a body must demonstrate independence from the systems it certifies, relevant expertise in data protection and AI, established procedures for assessment and complaints handling, absence of conflicts of interest, and financial stability to carry out the role without external influence.
As of June 2026, White Label Consultancy is the only external Accredited Certification Body approved by the DIFC under Regulation 10.
How Long Does System Certification Last?
System certification is valid for up to three years from the date of issue, subject to ongoing monitoring and periodic compliance checks. The ACB can revoke, suspend, or reinstate certification if the system no longer meets the requirements.
Accreditation of the certification body itself is valid for five years, also subject to periodic reviews by the Commissioner.
What Is the Regulation 10 Accelerator?
The DIFC soft-launched the Regulation 10 Accelerator as a sandbox programme for firms developing, acquiring, or currently operating AI systems. It allows firms to assess their system's compliance posture against the Data Protection Law and Regulation 10 before formal certification, and to identify risks associated with their use of personal data.
Participation in the Accelerator is not a substitute for certification. It is a preparatory step that helps firms understand gaps before engaging an ACB.
What Is Changing Under the Proposed 2026 Amendments?
The DIFC published Consultation Paper No. 3 of 2026 on 18 June 2026, open for comment until 18 July 2026. The proposals include a new Regulation 11, which would give the Commissioner formal power to recognise accreditation and certification schemes. This is intended to provide greater clarity on which assurance routes the Commissioner accepts, and to strengthen the Commissioner's oversight of the certification market as more bodies seek accreditation.
The proposed amendments would also sharpen certification obligations under Regulation 10 and clarify the ASO role. These proposals are not yet in force. Firms should track the outcome, as it will shape what certification compliance looks like for the remainder of 2026 and beyond.
What Does Certification Not Cover?
Certification under Regulation 10 is system-specific, not entity-specific. A certificate issued for one AI system does not extend to other systems operated by the same firm. Each system used for High Risk Processing requires its own certification.
Certification also does not replace the other obligations that apply under Regulation 10. A certified system still requires a completed DPIA, a transparency notice, an appointed ASO, and audit trail documentation. Certification confirms the system meets the Framework's standards. It does not mean the firm is fully compliant with Regulation 10 in all respects.
What Should Firms Do Now?
Firms using AI systems for High Risk Processing that have not yet been certified should take three steps.
First, complete a DPIA for each in-scope system. This is a prerequisite for certification and also carries a separate fine of USD 50,000 if not done before high-risk processing begins.
Second, engage with the Regulation 10 Accelerator to assess each system's compliance posture and identify gaps before entering the formal certification process.
Third, contact White Label Consultancy, the only external ACB currently approved by the DIFC, to understand the certification process and timeline for each system.
Firms should also monitor the outcome of Consultation Paper No. 3 of 2026. The amendments that follow will determine whether additional certification bodies are recognised and how certification obligations are clarified going forward.
Magpie generates the audit trails, DPIA documentation, and observability records that Regulation 10 requires as part of the certification process. Request a demo.