A mid-sized trading company in Jebel Ali once told me they only discovered their biggest risk on a Tuesday morning, when a single supplier in Asia stopped answering emails. Contracts stalled, cash flow tightened, and the finance team spent three weeks patching a problem nobody had ever written down. The founder said something I have heard from a lot of UAE business owners since: we knew the risk existed, we just never made a list. That is usually where the trouble starts. Companies here move fast, licences renew quickly, teams grow in months rather than years, and the reflex is to solve problems as they appear rather than map them in advance. A written list of the main risks is not a bureaucratic exercise. It is the difference between a Tuesday morning you can handle and one that costs you a quarter.
Where risks hide
Start with the departments, not the disasters
The instinct is to brainstorm scary scenarios: fire, fraud, a sudden regulatory change. That produces a colourful list and very little action. A better approach is to walk through the company one department at a time and ask what could realistically go wrong inside each function. In a typical UAE business you will look at finance, IT and data, legal and documentation, HR and Emiratisation obligations, supply chain, and the wider political or macroeconomic environment that touches the region.
Finance risks include cash-flow gaps, VAT filing errors, currency exposure for companies that buy in euros or yuan and sell in dirhams, and the growing corporate tax obligations introduced in 2023. IT risks cover ransomware, data leaks, and the reality that the UAE sits inside a heavily targeted region for cyber attacks, something the TDRA has flagged repeatedly. Documentation risks are unglamorous but painful: an expired trade licence, a missed Ejari renewal, or a shareholder resolution that was never notarised. Political and macro risks include shifts in regional trade routes, sanctions exposure, and sudden changes to visa or labour rules.

Get the department heads in one room
Once you have the categories, the list itself has to come from the people who actually run the work. A founder or general manager can guess at what might break, but the finance controller knows which client always pays 45 days late, the IT lead knows which server is still running an unsupported OS, and the PRO knows which document is about to expire. Skip that conversation and your risk list will be a projection of one person’s worries, not a picture of the company.
Run the session as a working meeting, not a presentation. Give each head of department fifteen minutes to answer three questions: what could go wrong in your area in the next twelve months, how likely is it, and how badly would it hurt the business. Write everything down, even the items that sound minor. A single overlooked risk, like a key employee holding the only password to the payment gateway, is exactly the kind of thing that never makes it into a formal report and always causes the biggest mess.
Cluster the answers by category, remove duplicates, and you will already have a draft list of thirty to sixty items. That draft is the raw material for everything that follows.
“The risk you can name is the risk you can price. The one you cannot name always ends up on the balance sheet anyway.”
Turn the list into a working register
A list of thirty risks with no structure is just a longer worry. To make it useful, each item needs four columns next to it: a plain description, the likely consequence in business terms, a rough probability, and a first idea of how to reduce or remove it. This is the moment where the list stops being a document and starts being a tool. According to the ISO 31000 framework, that combination of identification, analysis and treatment is the core of any credible risk process, and it works just as well for a 20-person SME in Sharjah as for a listed company on the DFM.
Prioritise by combining probability and impact. A risk that is very likely but cheap to fix, like a lapsed antivirus subscription, should be closed the same week. A risk that is unlikely but would end the company, like losing your only client, deserves a written contingency plan even if the odds seem low. Everything in the middle needs an owner and a deadline, otherwise the list will slowly turn into wallpaper.

Four practical steps to build the list this month
Map your departments
Draw a simple org chart and mark every function that touches money, data, people, or paperwork. Those are your risk zones. Nothing outside them matters yet.
Interview the heads
Sit with each department lead for a focused conversation. Ask what breaks, what almost broke last year, and what keeps them awake. Write it all down without filtering.
Score and rank
Rate each risk by likelihood and impact on a simple one-to-five scale. Multiply the two. Sort the list top-down. The top ten items are your real agenda.
Assign owners and review dates
Every top-ten risk needs a named owner and a review date within 90 days. Unowned risks do not get fixed. Diarised risks almost always do.
When to bring in help
A second pair of eyes usually pays for itself
Once the internal draft exists, a specialist firm can stress-test it against data your team simply does not have access to: industry loss statistics, comparable company incidents in the UAE, evolving regulator guidance, and cyber threat intelligence. Bringing in an external partner for risk management at that stage is efficient because you are not paying them to discover your business from scratch, you are paying them to challenge a list you already believe in and to spot the blind spots. They typically add items you missed, downgrade risks you over-rated, and propose controls that would have taken you months to design in-house.
Share your assumptions openly, including the improvements you would like to introduce. The more context they have, the sharper the recommendations. A good advisor will also help you decide which risks to accept, which to transfer through insurance, and which to reduce through process changes, so the final register is a decision document rather than a wish list.
Keep the list alive
A risk register that is written once and filed is worse than no register at all, because it creates a false sense of control. Review the top ten every quarter, the full list at least once a year, and any time the business changes materially: a new licence activity, a new market, a new senior hire, an acquisition, or a shift in the regulatory environment. In the UAE that last trigger fires more often than most owners expect, whether it is a new corporate tax clarification, a change in free zone rules, or fresh guidance from the Central Bank.
Done properly, the list becomes something the board actually reads before meetings and something the finance and operations teams reference before signing contracts. That is when risk management stops being a compliance chore and starts being a competitive advantage, because you are making decisions with the map in front of you instead of guessing at the terrain.
Frequently asked questions
How many risks should a company risk list contain?
There is no fixed number, but most SMEs in the UAE end up with somewhere between 25 and 60 items in the full register, and a working top ten that gets active attention. If your list is under fifteen items you have almost certainly missed categories. If it is over a hundred you are probably listing symptoms instead of root causes.
Who should own the risk register inside the company?
In smaller companies the CFO or general manager usually owns it, because they see finance, operations, and compliance in one view. In larger businesses it sits with a dedicated risk or internal audit function. What matters is that one named person is accountable for keeping it current, even though each individual risk has its own owner.
How often should the list be reviewed?
Review the top ten risks every quarter and the full list at least once a year. Also review it whenever something material changes, such as a new licence activity, entry into a new market, a senior leadership change, or a significant regulatory update from UAE authorities.
Do UAE regulators require a formal risk register?
It depends on the entity type. Listed companies, banks, insurance firms, and DFSA or FSRA regulated firms in DIFC and ADGM have explicit risk management obligations. Most mainland and free zone SMEs are not legally required to keep one, but auditors, banks, and larger customers increasingly ask to see one before extending credit or signing long contracts.
Should we buy insurance for every risk on the list?
No. Insurance is only one of four responses: accept, reduce, transfer, or avoid. Transfer through insurance makes sense for low-probability, high-impact risks such as major property damage or professional liability. High-probability risks are usually better reduced through better processes, and some risks are simply not insurable at a reasonable price.
What is the difference between a risk and an issue?
A risk is something that might happen and would hurt the business if it did. An issue is something that has already happened and is hurting the business now. Risk registers deal with the first category. Confusing the two is a common mistake and leads to lists that are really just complaint logs.
Can we build the list without external help?
Yes, especially for the first draft. The internal knowledge inside your department heads is usually enough to identify 80 percent of the meaningful risks. External advisors add most value in the review stage, when they can benchmark your list against industry data, challenge assumptions, and design controls that meet UAE regulatory expectations.
Hiking addict, foodie, music blogger, Mad Men fan and front-end developer. Working at the junction of beauty and sustainability to craft experiences both online and in real life. Let’s design a world that’s thoughtful, considered and aesthetically pleasing.