Financial News
As Regional Banks Chart their Digital Journeys, Should They Buy or Build Their Innovations?
By Nick Curran, Head of Endava MENA
In a study published last month, McKinsey showed banking to be one of the Middle East’s most digitised industries. The means of brand interaction among banking customers was 87% digital in the United Arab Emirates. This proportion of customers reported that their engagement was either fully digital or involved remote assistance.
This proportion of customers reported that their engagement was either fully digital or involved remote assistance. This proportion was even higher in Saudi Arabia (92%), anticipating that 70% of its payment transactions will be digital by 2030. The McKinsey study also showed Egypt’s banking sector to have 82% digital interaction.
The GCC has always been out in front of regional peers with the digitisation of the FSI sector. Dubai’s Mashreq launched Neo, the first digital bank in the Middle East. And Kuwait Finance House developed KFH-Go, the region’s first e-branch — an unstaffed business unit capable of providing more than 30 services. Each of these innovative project teams faced a common question in their journey to “pioneerhood”: build or buy?
Today’s consumers wait for nothing and no one. If you drag your feet for too long, you miss the boat. One of your competitors will have done it first. In the early years of the digital era, building was the only option, but today the region is strewn with FinTechs. Their offerings are often API-first, which makes them highly customisable. However, considering the strides in cloud technology and software-development methodologies that make in-house rapid deployment possible, we are back to the quandary: build or buy. Let us look at each in turn.
Buying: a no-brainer… with headaches
There is a comfort to be had from procuring a tool or platform that just fits. CIOs are spared nail-biting months of business analysis and user workshops. All that need be done is integrate a solution that has been rigorously tested, albeit in isolation of one’s own business model. In a cloud-native environment, this is even easier. Even if the bank runs core systems on premises, software-as-a-service (SaaS) solutions still end up being easier to bolt in and bed down. The cloud also adds a welcome element of predictability, not only for project management, but for upfront and ongoing costs.
Already, the “buy” option seems preferable. In a region with technology skills gaps, buying a ready-made solution — one that dozens may use if not hundreds of similar businesses across the region — is a great way of avoiding lengthy recruitment drives. But buying is not without its downsides. Try as they might, commercial off-the-shelf solutions (COTS) vendors design their products for a broad operational model and may not be a perfect fit. Even where the requisite customisation is possible, it may come with a list of unacceptable side effects, including a hefty price tag. COTS scaling is also challenging, as is its user-acceptance testing, maintenance, and upgrades, given the reliance on an external team.
Of course, I could write a separate article on the cybersecurity implications of having a third party in the technology mix. And that is before we have even begun to discuss the impact of multiple vendors and FinTechs — which may be necessary to bring the organisation’s digital vision to life. The bank would need to employ someone full-time to liaise with these business partners, negotiate and oversee SLAs, and police the fine line between these activities and regulatory compliance.
Building: a dream for the control-conscious, but where’s the talent?
What CIO doesn’t relish the prospect of complete control over the IT stack? Building their systems gives them that. Development and integration are theirs to command. Use cases can fully govern implementation rather than the twist and bend that IT has to go through to accommodate even 90% requirements fit with a COTS purchase. Stakeholders can join the dots from aspiration to value for each business unit. CIOs and their teams know the business inside and out. They can pivot from the needs of customers and customer-facing employees to cybersecurity and risk management and consider one while developing solutions for another — something COTS vendors cannot do to the same extent.
And then, there is deployment. It tends to be less invasive and more straightforward when its planners oversee the same production environment every day. DevOps and the CI/CD pipeline also allow the modern style of rapid development that helps meet market needs in time to reap the rewards. Building its solutions also allows the organisation to build its IP portfolio, giving it an edge in the market.
The caveats, then? There needs to be a rich in-house talent pool, including IT leaders and analysts who can scope large projects and price them accurately before a single line of code is written. Remember, one of the attractions of COTS solutions is the predictability of their costing models compared with the all-too-common tendency of self-builds costs to spiral out of control. Bringing in third-party expertise to plug these talent gaps is always possible. Failing this, the organisation’s HR team must go on a fastidious recruitment drive before any planning can occur. Low-code platforms and citizen developers may seem like fine options, but without the proper governance, this is a highway to nowhere.
Each to their own
Ultimately, the program’s needs will help make the build-or-buy decision. Despite the control it offers, building may still not be right for standard use cases such as CRM and HR, which an off-the-shelf solution can appropriately serve. On the other hand, if the organisation has a differentiating vision, then almost by definition, COTS tools will fall short. The decision maker must be as fluid as the decision and consider the benefits and drawbacks of each approach in the context of the specific use case they are looking to implement.
Financial
Dhruva to Rebrand as Ryan Across the Middle East, Signaling Unified Global Brand
Dhruva will adopt the Ryan brand across the UAE and Saudi Arabia by the end of 2026, uniting the practice with Ryan’s global identity and international platform.
Dhruva, a leading tax consultancy firm in the Middle East, and Ryan, a leading global tax services and software provider, today announced that Dhruva will transition to the Ryan brand across the United Arab Emirates (UAE) and the Kingdom of Saudi Arabia. The rebranding will be completed by the end of 2026, bringing the practice under Ryan’s global identity and reinforcing its position as part of the world’s leading global-scale specialist in business tax.
The transition marks the next phase of the strategic joint venture announced in 2025 and reflects the continued integration of Dhruva’s regional capabilities with Ryan’s global platform, technology, and international resources. Clients across the Middle East will continue to benefit from the same trusted advisory teams, enhanced by access to Ryan’s worldwide expertise and service capabilities.
“The Middle East has been a strategic growth market for us for many years, and we have built a strong advisory practice founded on deep client relationships, technical excellence, and local market understanding,” said Dinesh Kanabar, Founder, Chairman, and CEO, Dhruva Advisors and Vice Chairman, Ryan.
“The transition to the Ryan brand marks a significant milestone in our journey and reflects the strength of our partnership. By combining our regional expertise with Ryan’s global scale, technology, and international capabilities, we are creating an even stronger platform to support clients across the region as they navigate an increasingly dynamic and evolving tax landscape.”
“The Middle East is one of the most important growth markets for tax advisory services globally, and we are investing in the region with a long-term view,” said Tom Shave, President of Ryan’s European and Asia-Pacific Operations. “Uniting under the Ryan brand strengthens how we serve clients across the UAE, Saudi Arabia, and Europe—bringing seamless access to our global expertise, technology, and international resources through one trusted platform. This transition marks an important milestone in our integration and reinforces our commitment to the region’s future.”
Ryan will continue to invest in its Middle East operations, expanding its team, capabilities, and regional presence across key markets, including Dubai, Abu Dhabi, and Riyadh. The practice provides comprehensive tax advisory services spanning corporate tax, value-added tax (VAT) and indirect tax, transfer pricing, mergers and acquisitions (M&A) tax structuring, research and development (R&D), and cross-border compliance.
“The response from our clients over the past year has been the clearest validation of this partnership,” said Nimish Goel, Leader, Middle East, Dhruva, a Ryan Affiliate. “From the outset, our teams have been integrating Ryan’s global capabilities in technology, specialized expertise, and best practices into the work we already lead in the region. Adopting the Ryan brand is the natural next step. It is the same people and the same trusted relationships, now carrying the name of the largest Firm in the world dedicated exclusively to business taxes.”
The rebranding will be implemented in phases during the second half of 2026, with signage, visual identity, and digital properties transitioning to the Ryan brand across the region.
Financial
Al Ansari Exchange Partners with RTA Dubai to Offer nol Travel Cards
Al Ansari Exchange, the UAE’s leading remittance and foreign exchange company and a subsidiary of Al Ansari Financial Services PJSC (DFM: ALANSARI), has partnered with Dubai’s Roads and Transport Authority (RTA) and in association with MDX Technology Solutions ME, to make nol Travel Cards available at selected branches across Dubai.
The collaboration broadens Al Ansari Exchange’s portfolio of third-party products and extends access to Dubai’s integrated mobility payment system through the UAE’s largest branch networks. It also reflects the company’s strategy of building a connected physical and digital ecosystem that provides customers with convenient access to a wider range of everyday financial and lifestyle services.
Residents and visitors can now purchase nol Travel Cards from selected Al Ansari Exchange branches, distributed through MDX Technology Solutions ME, the RTA-authorised distributor of nol Travel Cards, providing an additional point of access to one of Dubai’s most widely used mobility payment solutions.
The nol Travel Card enables cashless payments across Dubai’s public transport network, including the Dubai Metro, Dubai Tram, public buses, marine transport and public parking. It is also accepted at more than 14,000 retail outlets across the UAE. Through the nol Pay App, cardholders can access more than 200 lifestyle offers and discounts.
Commenting on the collaboration, Musad Ibrahim Alhammadi, Director of Automated Collection Systems at Corporate Technology Support Services Sector, Roads and Transport Authority (RTA), said: “Expanding the availability of nol Travel Cards through strategic collaborations supports RTA’s efforts to make mobility services more accessible across Dubai. Providing additional distribution channels contributes to wider adoption of digital payment solutions and enhances the travel experience for residents and visitors.”
Ali Al Najjar, Chief Executive Officer of Al Ansari Exchange, added: “As customer expectations continue to evolve, we are expanding the role of Al Ansari Exchange beyond traditional financial transactions by bringing together financial, payment and everyday lifestyle services through both our branch network and digital platforms. Making nol Travel Cards available through our branches complements our broader strategy of creating a seamless customer experience while supporting Dubai’s vision for a smart, digitally connected city.”
Financial
The rights you think you have: five legal stress tests for a more resilient business
Resilience is not only about cash reserves, backup servers or alternative suppliers. It also depends on whether a company’s legal rights and permissions still work when the business is under pressure.
By: Maroun Abou Harb, Associate at BSA LAW
Resilience is discussed as an operational or financial discipline. Businesses test liquidity, back up systems and diversify supply chains. Yet every continuity plan rests on legal infrastructure: licenses, delegated authorities, contracts, data permissions, employment arrangements, security rights and evidence.
That infrastructure can fail when needed most. The replacement supplier cannot be appointed without third-party consent. Customer data cannot lawfully be moved to the backup provider. An insurance claim is compromized by late notification. A guarantee was signed incorrectly. The company owns a platform, but not all of its intellectual property.
The most dangerous legal risk is not the missing clause. It is the right management assumes the business has, but cannot use.
In the UAE, the Central Bank’s 2026 Operational Risk Management Regulation now requires licensed financial institutions to implement a comprehensive operational risk and resilience proecedure. The principle is valuable for every company: identify what must continue, locate the legal points of failure and test them before disruption does.
- Can the business lawfully act?
Start with corporate authority, check that licenses match actual activities, constitutional documents reflect the ownership and governance structure, and beneficial-owner, shareholder and director records are accurate. Review reserved matters, signing matrices, powers of attorney and banking mandates.
A deal, borrowing or emergency payment can stall because the authorized signatory is unavailable, a power has expired or an approval threshold was misunderstood. Group companies should confirm which entity employs people, owns assets, contracts with customers and receives revenue.
Run this scenario: if the chief executive and chief financial officer were unreachable tomorrow, who could bind the company, access its accounts and appoint an alternative supplier? If the answer is uncertain, the business has a legal single point of failure.
- Which contracts become dangerous under stress?
Most contract reviews examine value and liability. A resilience review asks a different question: what happens when performance is interrupted?
Build a heat map of critical customer and supplier contracts, ranked by operational importance and consequence of failure. For each, test termination and suspension rights, force majeure and change-in-law provisions, service levels, price-adjustment mechanisms, liability caps, indemnities, insurance, governing law and dispute forum, subcontracting, assignment and change-of-control restrictions. Check notice methods and cure periods; a valuable right can disappear if a notice is sent late or to the wrong address.
Then examine optionality, can the company use a replacement supplier, obtain transition assistance, retrieve its data in a usable format and continue using essential intellectual property? Is there a source-code escrow or step-in mechanism where appropriate?
The aim is not to renegotiate every contract. It is to know which five contracts could stop the business and to fix those first.
- Can technology fail without the legal part failing too?
A technical recovery plan is incomplete if the contracts do not support it. Cloud, payment, telecommunications and managed-service arrangements should align promised recovery times with the company’s tolerance for disruption. Audit rights, incident cooperation, subcontractor controls, data-location commitments and exit assistance should be tested.
The incident playbook must allocate legal decisions. Who determines whether regulators, customers, insurers or affected individuals must be notified? Who preserves evidence and engages external advisers? How will legal privilege or professional confidentiality be preserved? A cyber incident moves quickly; ambiguity over decision-making wastes the hours that matter most.
Conduct an exercise with management, technology, legal, communications and finance. Introduce a realistic vendor outage or data breach and follow the contracts: who calls whom, what must be notified, and what can actually be recovered?
- Does the company know what data and technology it is using?
Across the GCC, privacy and cybersecurity regimes increasingly regulate how data is collected, processed, retained, transferred and protected. A company cannot comply, or recover confidently, without knowing where its data goes.
Create a data map covering customers, employees, vendors and website users. Record the purpose and legal basis for processing, storage location, access rights, retention period, cross-border transfers and third-party processors.
The same exercise should include artificial intelligence, by identifying public and embedded AI tools, the information supplied to them, the outputs relied upon and the human review applied. Confidential information, personal data and third-party intellectual property should not enter a tool because an employee can access it. An approved-use policy, procurement review and output-verification process are proportionate safeguards.
- Can the company protect value when conditions deteriorate?
Management should monitor covenant breaches, unpaid taxes, overdue receivables, expiring insurance, threatened claims and counterparties showing signs of insolvency. The legal team should know which rights permit suspension, security enforcement, contract termination or protective court relief, and whether exercising them could create risk.
People and intellectual property also require continuity planning. Confirm that employment and consultancy terms contain appropriate confidentiality, invention-assignment and post-termination protections, tailored to the governing law. Identify key-person dependencies, succession gaps and access held by departing staff. Register intellectual property where appropriate and maintain evidence of creation and ownership.
Business needs also to review insurance as a contract, not a certificate. Map material risks to coverage, exclusions, deductibles, notification deadlines and consent requirements. The policy is only useful if the company knows how to activate it.
In brief, the output should be that for every critical risk, record the business service affected, relevant entity and contract, responsible owner, required action, deadline and escalation threshold.
Report the highest exposures to the board and repeat the exercise after major acquisitions, restructurings, regulatory changes or technology deployments.
A focused review can produce four useful assets:
- an authority and obligations calendar;
- a critical-contract heat map;
- a data and AI inventory; and
- a tested incident playbook.
No company can remove disruption. It can, however, remove the uncertainty surrounding who may act, what must be done and which rights remain available.
-
News11 years ago
SENDQUICK (TALARIAX) INTRODUCES SQOOPE – THE BREAKTHROUGH IN MOBILE MESSAGING
-
Trending10 months agoOPPO A6 Pro 5G Review: Reliable Daily Driver
-
Tech News2 years agoDenodo Bolsters Executive Team by Hiring Christophe Culine as its Chief Revenue Officer
-
VAR1 year agoMicrosoft Launches New Surface Copilot+ PCs for Business
-
Automotive2 years agoAGMC Launches the RIDDARA RD6 High Performance Fully Electric 4×4 Pickup
-
Tech Interviews2 years ago
Navigating the Cybersecurity Landscape in Hybrid Work Environments
-
Tech News1 year agoNothing Launches flagship Nothing Phone (3) and Headphone (1) in theme with the Iconic Museum of the Future in Dubai
-
VAR2 years agoSamsung Galaxy Z Fold6 vs Google Pixel 9 Pro Fold: Clash Of The Folding Phenoms



