Financial
Payments Security: The Key to Winning Consumer Loyalty in MENA
The adoption of digital commerce in MENA has skyrocketed over the past few years. Countries that were once deeply attached to cash and physical transactions have shot to digital maturity in just a few years. According to Checkout.com’s 4th annual MENA ecommerce report, The State of Digital Commerce in MENA 2024, 91% of the region’s consumers have reported shopping e-commerce in the past two years. The number of people who shop online in MENA at least once per day has grown by 80% since 2020, with the Kingdom of Saudi Arabia leading the way with a staggering 90% increase.
In response to evolving consumer demands, merchants across MENA are embarking on ambitious digitization journeys and adopting innovative payment strategies. As digital commerce moves beyond the early-adoption phase, the focus is shifting toward fine tuning performance. In doing so, strengthening payment security has become a top priority.
As innovation stimulates advancements in the payment industry, fraudsters don’t rest on laurels, further sophisticating their own scam methods and tricks. Furthermore, the very aspects of e-commerce that make it an enticing prospect for consumers – speed, convenience, and anonymity – also work in cybercriminals’ favor. Because the e-commerce ecosystem includes multiple stakeholders, the retailer, the customer, the processor, and the networks, fraudsters have multiple potential access points that they can exploit.
According to Remo Giovanni Abbondandolo, General Manager – MENA at Checkout.com, ecommerce fraud can take many forms, such as criminals using stolen credit card numbers to make purchases, transaction replays, and chargeback fraud. The diverse and complex nature of e-commerce fraud emphasizes the importance of vigilance and secure practices merchants must adopt to avoid such incidents.
But it’s not just the initial financial loss that merchants need to be concerned about. Falling prey to ecommerce fraud can damage customer trust and the company’s reputation. Alarmingly, 33% of MENA consumers say they have been a victim of payments fraud. According to The State of Digital Commerce in MENA 2024 report, safe and secure checkout is now a priority for 39% of MENA consumers. In contrast, in 2020, survey respondents placed the highest value on speedy delivery.
Furthermore, up to 30% of shoppers have said a single falsely declined payment- when a payment is declined despite the payee having sufficient funds in the account, would lead them to shop from a competitor’s website. With the cost of customer acquisition for e-commerce merchants having increased, a rise in falsely declined payments adds insult to injury. This makes high-performing acceptance solutions a matter of huge competitive importance in MENA.
To this point, it’s important to mention that the region also continues to see a relatively high number of false declined payments. According to Checkout.com’s latest report, 23% of respondents experienced a falsely declined payment in recent months. In today’s fast-paced digital economy, consumers are also less patient, less loyal, and savvier than before.
Shoppers want to know their payment is being handled by a safe and reliable partner. The good news for merchants is that fortifying payments security is a much simpler task than dealing with widespread data breaches.
In this context, Abbondandolo outlines effective strategies that merchants in MENA can adopt to minimize payment fraud and false declines, thereby enhancing consumer trust and loyalty.
- Choose a trusted partner
Partnering with a regulated payments service provider (PSP) that offers acquiring capabilities, advanced technology support, and comprehensive regional regulatory expertise can significantly bolster a business’s security measures against fraud. Regulated PSPs provide acceptance solutions that enhance payment processes through optimized messaging, routing, and retries, ensuring robust security and seamless transactions throughout. Furthermore, because fraudsters have no boundaries, partnering with a regulated global PSPs with local experience offers advanced technology solutions that include real-time fraud detection systems that are trained on detecting the most advanced global fraud scams and techniques. By analyzing transactional data in milliseconds, identifying suspicious patterns and behaviors that may indicate fraudulent activity.
By partnering with a regulated PSP that offers acquiring capabilities and advanced technology support, businesses can benefit from a holistic approach to fraud prevention and payment security.
- Harness the power of embedded AI
Regional merchants are increasingly safeguarding their businesses from fraud by leveraging a combination of tools and machine learning. Advanced payment technology empower merchants to seamlessly integrate fraud detection solutions into their platforms, without requiring additional set up. Meanwhile, AI is now trained on billions of global transactions, with merchants benefitting from a global network effect that allows them to analyze vast amounts of data to detect patterns, anomalies and emerging fraud like never before.
Minimizing fraud and improving performance in payment processing are closely intertwined goals that can significantly impact a business’s bottom line and customer satisfaction. When a business effectively reduces fraud, it tends to experience several concurrent benefits that contribute to overall performance enhancement.
Our merchants in the region have been benefiting from a whole new level of payment performance with Intelligent Acceptance. This product combines advanced Artificial Intelligence and Machine Learning, vast network data, and deep payment expertise to increase conversion and unlock untapped revenue. We have already recovered $1.1 billion of revenue, and increased acceptance rates on average by 2% for globally.
- Make data work for you
Research conducted by Checkout.com alongside Oxford Economics found that $50.7 billion was lost due to false declines in recent years. Large data sets can empower merchants to track and respond to customer payment trends with laser accuracy in real-time. Here we have seen the great benefit from Intelligent Acceptance that draws on insights from these data sets to deliver a whole new level of payment performance, increasing conversion and unlocking untapped revenue, as well as Network Tokens that have helped our merchants achieve higher authorization rates, reduced fraud and allow businesses to offer an improved customer experience, while keeping customers data
Looking ahead, half of all shoppers in MENA anticipate an increase in their online spending over the next 12 months. Abbondandolo believes that MENA merchants still have significant untapped opportunity to combat fraud, reduce false declines and their overall payments costs, while increasing their revenue. As consumers increasingly embrace digital shopping and payments, optimizing every aspect of the ecommerce experience remains crucial for merchants to capitalize on this growing trend.
Financial
The rights you think you have: five legal stress tests for a more resilient business
Resilience is not only about cash reserves, backup servers or alternative suppliers. It also depends on whether a company’s legal rights and permissions still work when the business is under pressure.
By: Maroun Abou Harb, Associate at BSA LAW
Resilience is discussed as an operational or financial discipline. Businesses test liquidity, back up systems and diversify supply chains. Yet every continuity plan rests on legal infrastructure: licenses, delegated authorities, contracts, data permissions, employment arrangements, security rights and evidence.
That infrastructure can fail when needed most. The replacement supplier cannot be appointed without third-party consent. Customer data cannot lawfully be moved to the backup provider. An insurance claim is compromized by late notification. A guarantee was signed incorrectly. The company owns a platform, but not all of its intellectual property.
The most dangerous legal risk is not the missing clause. It is the right management assumes the business has, but cannot use.
In the UAE, the Central Bank’s 2026 Operational Risk Management Regulation now requires licensed financial institutions to implement a comprehensive operational risk and resilience proecedure. The principle is valuable for every company: identify what must continue, locate the legal points of failure and test them before disruption does.
- Can the business lawfully act?
Start with corporate authority, check that licenses match actual activities, constitutional documents reflect the ownership and governance structure, and beneficial-owner, shareholder and director records are accurate. Review reserved matters, signing matrices, powers of attorney and banking mandates.
A deal, borrowing or emergency payment can stall because the authorized signatory is unavailable, a power has expired or an approval threshold was misunderstood. Group companies should confirm which entity employs people, owns assets, contracts with customers and receives revenue.
Run this scenario: if the chief executive and chief financial officer were unreachable tomorrow, who could bind the company, access its accounts and appoint an alternative supplier? If the answer is uncertain, the business has a legal single point of failure.
- Which contracts become dangerous under stress?
Most contract reviews examine value and liability. A resilience review asks a different question: what happens when performance is interrupted?
Build a heat map of critical customer and supplier contracts, ranked by operational importance and consequence of failure. For each, test termination and suspension rights, force majeure and change-in-law provisions, service levels, price-adjustment mechanisms, liability caps, indemnities, insurance, governing law and dispute forum, subcontracting, assignment and change-of-control restrictions. Check notice methods and cure periods; a valuable right can disappear if a notice is sent late or to the wrong address.
Then examine optionality, can the company use a replacement supplier, obtain transition assistance, retrieve its data in a usable format and continue using essential intellectual property? Is there a source-code escrow or step-in mechanism where appropriate?
The aim is not to renegotiate every contract. It is to know which five contracts could stop the business and to fix those first.
- Can technology fail without the legal part failing too?
A technical recovery plan is incomplete if the contracts do not support it. Cloud, payment, telecommunications and managed-service arrangements should align promised recovery times with the company’s tolerance for disruption. Audit rights, incident cooperation, subcontractor controls, data-location commitments and exit assistance should be tested.
The incident playbook must allocate legal decisions. Who determines whether regulators, customers, insurers or affected individuals must be notified? Who preserves evidence and engages external advisers? How will legal privilege or professional confidentiality be preserved? A cyber incident moves quickly; ambiguity over decision-making wastes the hours that matter most.
Conduct an exercise with management, technology, legal, communications and finance. Introduce a realistic vendor outage or data breach and follow the contracts: who calls whom, what must be notified, and what can actually be recovered?
- Does the company know what data and technology it is using?
Across the GCC, privacy and cybersecurity regimes increasingly regulate how data is collected, processed, retained, transferred and protected. A company cannot comply, or recover confidently, without knowing where its data goes.
Create a data map covering customers, employees, vendors and website users. Record the purpose and legal basis for processing, storage location, access rights, retention period, cross-border transfers and third-party processors.
The same exercise should include artificial intelligence, by identifying public and embedded AI tools, the information supplied to them, the outputs relied upon and the human review applied. Confidential information, personal data and third-party intellectual property should not enter a tool because an employee can access it. An approved-use policy, procurement review and output-verification process are proportionate safeguards.
- Can the company protect value when conditions deteriorate?
Management should monitor covenant breaches, unpaid taxes, overdue receivables, expiring insurance, threatened claims and counterparties showing signs of insolvency. The legal team should know which rights permit suspension, security enforcement, contract termination or protective court relief, and whether exercising them could create risk.
People and intellectual property also require continuity planning. Confirm that employment and consultancy terms contain appropriate confidentiality, invention-assignment and post-termination protections, tailored to the governing law. Identify key-person dependencies, succession gaps and access held by departing staff. Register intellectual property where appropriate and maintain evidence of creation and ownership.
Business needs also to review insurance as a contract, not a certificate. Map material risks to coverage, exclusions, deductibles, notification deadlines and consent requirements. The policy is only useful if the company knows how to activate it.
In brief, the output should be that for every critical risk, record the business service affected, relevant entity and contract, responsible owner, required action, deadline and escalation threshold.
Report the highest exposures to the board and repeat the exercise after major acquisitions, restructurings, regulatory changes or technology deployments.
A focused review can produce four useful assets:
- an authority and obligations calendar;
- a critical-contract heat map;
- a data and AI inventory; and
- a tested incident playbook.
No company can remove disruption. It can, however, remove the uncertainty surrounding who may act, what must be done and which rights remain available.
Financial
Tax Is Not a Strategy – Why Dubai’s Smartest Founders Think Beyond Zero Per Cent
By Joe David, CEO of Nephos Group
“Move to Dubai for tax.”
I hear this constantly. From founders, investors, crypto-native operators – people building real businesses who reduce one of the biggest decisions of their professional lives to a single line on a spreadsheet.

And honestly, it is the wrong way to think about it.
Tax should rarely be the sole reason to relocate. When it is, it is usually where things go wrong. The corporate structure is not set up correctly. The banking relationships are not in place. The founder leaves within 18 months because the deeper rationale was never really there. I have seen this pattern play out dozens of times over the past decade, and it almost always traces back to the same root cause: a decision built on a tax rate rather than a strategy.
The tax-first trap
Dubai’s zero per cent personal income tax rate is real, and it is significant. But leading with tax creates a narrow frame that obscures the fuller picture. Founders who relocate purely for a rate often fail to consider the operational realities of building in a new jurisdiction. They underestimate the compliance infrastructure required to make the move defensible. They overlook the substance requirements that tax authorities in their home countries will scrutinise. When the expected savings do not materialise cleanly, because the structure was an afterthought, disillusionment sets in fast.
This does Dubai a disservice. It reduces a genuinely world-class business environment to a line in a tax planning brochure. The city deserves better than that, and so do the founders making life-altering decisions based on incomplete thinking.
What the successful ones actually optimise for
The founders and investors who get the most out of Dubai are not chasing a tax rate. They are making a broader strategic move.
Jurisdictional access is a major factor. Dubai sits at the crossroads of Europe, Africa and Asia, offering time zone coverage and travel connectivity that few cities can match. For businesses operating across multiple markets, particularly in digital assets, fintech and professional services, that geographic positioning is a genuine competitive edge.
Then there is the capital environment. Dubai has become a magnet for institutional and private capital, with fund structures, family offices and venture vehicles establishing a permanent presence. The banking infrastructure, while still maturing in certain areas, has improved significantly. For crypto-native businesses in particular, the regulatory clarity offered by frameworks like the Virtual Assets Regulatory Authority (VARA) provides something that many Western jurisdictions still cannot: a clear, codified path to operating legally with digital assets.
The business ecosystem itself is another draw. The speed at which you can incorporate, hire, open accounts and begin operating is remarkable compared to legacy jurisdictions. Free zones offer tailored licensing, and the government’s responsiveness to emerging sectors – AI, blockchain, tokenised finance – signals a jurisdiction that is building forward rather than regulating backward.
And then, yes, there is the lifestyle. Climate, safety, connectivity, quality of infrastructure. These are not trivial considerations when you are asking a founding team to commit to a base for the next five to ten years.
Tax is often the outcome of all of this. It is not the strategy itself.
The compliance landscape is shifting
There is another reason the tax-first mindset is increasingly risky. The global compliance environment is tightening rapidly. The Crypto-Asset Reporting Framework (CARF), developed by the OECD, will require automatic exchange of information on crypto transactions between jurisdictions. The EU’s DAC8 directive introduces similar obligations across member states. The days of relocating and assuming your home country’s tax authority will not follow are numbered.
This means that substance, genuine economic activity, real operational presence, defensible corporate structures, matters more than ever. A Dubai relocation that is purely cosmetic will not survive scrutiny. One that is built on genuine strategic foundations, with proper advisory support and compliant structures, will.
The conversation worth having
None of this is an argument against moving to Dubai. Quite the opposite. For the right founder, with the right business, at the right stage, it can be a transformative decision. But that decision needs to be grounded in strategy, not arithmetic.
Before you start calculating your tax savings, ask the harder questions. Does your business model benefit from being in this jurisdiction? Can you build genuine substance here? Are your corporate structures defensible under international reporting frameworks? Do you have the advisory infrastructure to get this right from day one?
That distinction – between tax as a tactic and strategy as a foundation – matters more than most people realise. And it is a conversation worth having before you make any decisions.
Financial
Why Financial Firms Keep Losing the Messaging Battle
By: Avi Pardo, Co-Founder & CBO, LeapXpert

Financial firms globally have similar playbooks for off-channel communications: ban the channel, run a training, and send attestations for signing. Yet, the conversations are still happening on personal phones. Calling that playbook ‘good enough’ only hides how little has changed.
More than 100 organisations have faced charges under the US Securities and Exchange Commission’s off-channel communications initiative, while other regulators have pursued similar failures. Yet the response is still another rule, another warning, another ban.
The missing piece is the psychology behind banning. Until firms understand what drives employees towards off-channel apps, even banned ones, the next record-keeping failure is already on its way.
Why employees find workarounds
These channels are already part of the client relationship. A banker may be chasing a decision, dealing with a concern or replying to a question that has come through on Signal, WeChat or WhatsApp. In that moment, getting back to the client takes priority.
If replying through the approved channel takes too long, creates operational friction, or disrupts the conversation flow, the employee is likely to answer somewhere else. The message gets sent, but the firm may never see the full exchange.
Psychologists have studied this response to bans for decades. Jack Brehm’s work on psychological reactance shows people can push back when they feel their freedom of choice has been restricted. Research into imposed workplace change points to the same response: people who feel pushed into a new way of working may quietly find another route. Someone reads the policy, completes the training and then uses a personal phone when a client needs an answer.
Daniel Wegner’s work on ironic rebound also helps explain why bans can misfire. Tell people often enough to avoid something and it can make it more appealing. The channel remains on the phone, the client is waiting and the approved route takes longer.
Once the conversation moves to a personal phone, the firm may never recover the full exchange. Employers also face legal limits on how far they can inspect a private device.
Governance beats the workaround
Governance should redirect behaviour instead of trying to suppress it. Employees need an approved route that works while the client conversation is happening, or the workaround will keep winning.
Financial firms still need clear rules and a complete record of business conversations. Regulators expect those messages to be kept, whether they were sent by email, text, WhatsApp or another service.
The problem usually shows up during an ordinary working day: between meetings, on a journey or while a client is waiting for an answer. If the approved channel holds things up, few people will pause the conversation to sort out the process. They will reply another way.
Businesses are losing valuable conversation data
Regulatory risk is obvious when messages go missing: a firm cannot supervise what it cannot see or produce records that were never captured.
Client conversations carry information a business would want to know: a concern raised weeks before a relationship starts to slip, pricing pushback that never reaches the CRM or a salesperson handling a difficult exchange in a way others could learn from. Repeated questions may also point to problems with onboarding, service or product design.
Governed communication creates a record the organisation can learn from. Applied responsibly, conversation data can support supervision, client service, dispute resolution, coaching and a clearer view of relationship risk.
That information is already being generated every day. The difference is whether it remains scattered across personal devices or becomes something the organisation can understand and act on.
Bring the conversation back into view
Plenty of companies have the basics in place: a policy, training and an approved tool. What is often missing is a setup that matches how people work and talk to clients.
The existence of a policy says very little about whether it works. ‘Good enough’ governance can leave a business with all the right paperwork while the same behaviour carries on underneath it.
A quick exchange can soon include a shared document, a follow-up question and another colleague joining the conversation. Messages, files, participants and timing all form part of the record, which needs to stay within the firm without someone rebuilding the exchange later.
If senior leaders use the same channels they have banned for everyone else, the policy is a sham. Employees follow what leaders do, rather than what the compliance manual says. Training can help, particularly when people understand the reason behind it. But explanations only go so far if the approved route slows down a live client conversation. Technology can capture the record, but leadership decides whether people take the rules seriously. No system can rescue a policy that senior figures ignore.
Keeping those exchanges within view gives the business more than a record for compliance. It can also pick up concerns, repeated questions and early signs that a client relationship is beginning to change.
More rules have not stopped the conversations. They have pushed them onto personal phones and out of sight. Calling that ‘good enough’ is no longer credible.
-
News11 years ago
SENDQUICK (TALARIAX) INTRODUCES SQOOPE – THE BREAKTHROUGH IN MOBILE MESSAGING
-
Trending10 months agoOPPO A6 Pro 5G Review: Reliable Daily Driver
-
Tech News2 years agoDenodo Bolsters Executive Team by Hiring Christophe Culine as its Chief Revenue Officer
-
VAR1 year agoMicrosoft Launches New Surface Copilot+ PCs for Business
-
Automotive2 years agoAGMC Launches the RIDDARA RD6 High Performance Fully Electric 4×4 Pickup
-
Tech Interviews2 years ago
Navigating the Cybersecurity Landscape in Hybrid Work Environments
-
Tech News1 year agoNothing Launches flagship Nothing Phone (3) and Headphone (1) in theme with the Iconic Museum of the Future in Dubai
-
VAR2 years agoSamsung Galaxy Z Fold6 vs Google Pixel 9 Pro Fold: Clash Of The Folding Phenoms


