Connect with us

Financial

Dhruva to Rebrand as Ryan Across the Middle East, Signaling Unified Global Brand

Published

on

Dhruva will adopt the Ryan brand across the UAE and Saudi Arabia by the end of 2026, uniting the practice with Ryan’s global identity and international platform.

Dhruva, a leading tax consultancy firm in the Middle East, and Ryan, a leading global tax services and software provider, today announced that Dhruva will transition to the Ryan brand across the United Arab Emirates (UAE) and the Kingdom of Saudi Arabia. The rebranding will be completed by the end of 2026, bringing the practice under Ryan’s global identity and reinforcing its position as part of the world’s leading global-scale specialist in business tax.

The transition marks the next phase of the strategic joint venture announced in 2025 and reflects the continued integration of Dhruva’s regional capabilities with Ryan’s global platform, technology, and international resources. Clients across the Middle East will continue to benefit from the same trusted advisory teams, enhanced by access to Ryan’s worldwide expertise and service capabilities.


“The Middle East has been a strategic growth market for us for many years, and we have built a strong advisory practice founded on deep client relationships, technical excellence, and local market understanding,” said Dinesh Kanabar, Founder, Chairman, and CEO, Dhruva Advisors and Vice Chairman, Ryan.

“The transition to the Ryan brand marks a significant milestone in our journey and reflects the strength of our partnership. By combining our regional expertise with Ryan’s global scale, technology, and international capabilities, we are creating an even stronger platform to support clients across the region as they navigate an increasingly dynamic and evolving tax landscape.”


“The Middle East is one of the most important growth markets for tax advisory services globally, and we are investing in the region with a long-term view,” said Tom Shave, President of Ryan’s European and Asia-Pacific Operations. “Uniting under the Ryan brand strengthens how we serve clients across the UAE, Saudi Arabia, and Europe—bringing seamless access to our global expertise, technology, and international resources through one trusted platform. This transition marks an important milestone in our integration and reinforces our commitment to the region’s future.”


Ryan will continue to invest in its Middle East operations, expanding its team, capabilities, and regional presence across key markets, including Dubai, Abu Dhabi, and Riyadh. The practice provides comprehensive tax advisory services spanning corporate tax, value-added tax (VAT) and indirect tax, transfer pricing, mergers and acquisitions (M&A) tax structuring, research and development (R&D), and cross-border compliance.


“The response from our clients over the past year has been the clearest validation of this partnership,” said Nimish Goel, Leader, Middle East, Dhruva, a Ryan Affiliate. “From the outset, our teams have been integrating Ryan’s global capabilities in technology, specialized expertise, and best practices into the work we already lead in the region. Adopting the Ryan brand is the natural next step. It is the same people and the same trusted relationships, now carrying the name of the largest Firm in the world dedicated exclusively to business taxes.”


The rebranding will be implemented in phases during the second half of 2026, with signage, visual identity, and digital properties transitioning to the Ryan brand across the region.

Cover Story

Saudi Arabia’s tax amnesty is entering its final months

Published

on


What could follow the December deadline is an assessment cycle, not a filing cycle.

By Manish Bansal, Associate Partner, Dhruva Advisors, A Ryan Affiliate, Saudi Arabia

For most of the past five years, inter-alia, one of the major topics of tax conversation in Saudi boardrooms has been e-invoicing. Are we on the Fatoora platform? Which wave are we in? Has the ERP been configured or do we go with a third-party e-invoicing solution? Will we make the deadline?

Those were the right questions for the period we have just left. They are not necessarily the right questions for the period we are entering.

Manish Bansal

On 29 June 2026, the Zakat, Tax and Customs Authority (“ZATCA”), acting on a decision of the Minister of Finance, extended the Cancellation of Fines and Exemption of Financial Penalties initiative for a further six months, running from 1 July to 31 December 2026. It covers excise tax, value added tax, real estate transaction tax, withholding tax and corporate income tax. That much has been widely reported.

Less widely noticed is a condition set out in the accompanying guideline. If the Authority extends the initiative again past December, that further extension will not reach returns that fell due after 30 June 2026.

The Authority has not simply granted more time. It has informed the market, in advance, where the relief eventually stops. Whatever is announced in December, the clean-up window for historical positions is being drawn shut. For a tax administration, that is about as clear a statement as one can give.

What the regulator already sees

The reason this matters now, rather than in some indeterminate future, is that the Authority’s information position has changed fundamentally.

Wave 24 of the e-invoicing Integration Phase closed on 30 June 2026. Announced in September 2025, it captured every taxpayer whose VAT-subject revenues exceeded SAR 375,000 in 2022, 2023 or 2024. That figure is not arbitrary: it is the mandatory VAT registration threshold. In effect, the wave brought the entire registered population into scope.

And the direction has not stopped there. On 24 July 2026 – ZATCA published the criteria for Wave 25, halving the threshold to SAR 187,500 of VAT-subject revenue in 2022, 2023, 2024 or 2025, with integration required by 1 February 2027.

Under the Integration Phase, standard business-to-business invoices are cleared by ZATCA before they reach the buyer, and simplified business-to-consumer invoices are reported within twenty-four hours. Invoices must be issued in a prescribed structured format, carrying a cryptographic stamp and a unique identifier.

The Authority is therefore no longer reliant on what appears in a filed return. It holds the underlying transactional record, in structured form, close to real time, across the whole economy.

This is the shift most finance functions have not yet absorbed. For years, the Saudi assessment process began with an information request. In an environment of structured, near-live data, it begins instead with an anomaly the system has already identified. The taxpayer’s first substantive contact with the process is not a request for documents. It is a proposition to be answered.

Key exposure areas to be mindful of

In our experience, the following key areas could be more visible and exposed to assessment risk in the Kingdom once transactional data can be cross matched against declarations.

The first is permanent establishment risk arising from project delivery. Groups routinely deploy technical staff, secondees and subcontracted specialists into Saudi projects while treating the arrangement as an offshore supply.  Given that most KSA government portals are inter-linked, careful monitoring of in-Kingdom presence is critical, in particular, employees of non-resident companies undertaking fly-in/fly-out assignments in the Kingdom.  It is worth noting that the current tax law has no de minimis threshold for the creation of a permanent establishment.  Accordingly, even a single day of presence in the Kingdom could potentially give rise to a permanent establishment, although in practice, the ZATCA may apply a more facts-based approach when assessing whether a permanent establishment exists.

Second is related-party pricing, and here a change that took effect two years ago is still under-appreciated. Following amendments to the Transfer Pricing By-Laws, the transfer pricing provisions apply to zakat payers as well as taxpayers for financial years beginning on or after 1 January 2024, and Advance Pricing Agreements became available to both. For a Saudi family group with decades of intercompany arrangements built for operational convenience rather than for documentation, this is a material change in obligation, and one that many such groups have not yet worked through.

Lastly, needless to state that VAT audits are likely to get much more sophisticated with real time data and the data analytics and AI tools available.

What the amnesty covers, and what it does not

Many companies are counting on this window. It is worth being precise about what it covers.

The initiative covers late registration, late payment and late filing fines, penalties on the amendment or correction of a VAT return, and other financial fines imposed under Article 45 of the VAT Law, including field detection and e-invoicing violations. To benefit, a taxpayer must register where registration is required, submit the outstanding returns, and either pay the amounts due or obtain ZATCA’s approval for an instalment plan.

Two limits deserve emphasis. The initiative does not extend to penalties relating to tax evasion violations. And it operates on fines for returns falling due up to 30 June 2026.

There is also a point that no guideline states because it does not need to. The initiative waives penalties. It does not validate a technical position. A voluntary disclosure that corrects an arithmetic omission is a straightforward matter. A voluntary disclosure that reveals a contestable tax treatment is a different exercise entirely, because it puts a position on the record that will be read. The analysis must come before the filing, not after it.

Fewer than four months

For most groups, what remains to be done before 31 December is a short list. It is also, notably, not a systems exercise. The e-invoicing platforms are already built and connected. The work now is reviewing the positions those systems have been reporting all along.

Reconcile first. Take VAT/ Tax/ Zakat returns, customs declarations, withholding tax filings and audited financial statements for the open years and reconcile them against one another before ZATCA’s systems do it. Where the numbers do not tie, understand why, and document the reason contemporaneously rather than reconstructing it under assessment.

Then sort. Separate the genuine errors, which the current window is designed to resolve, from the judgement positions, which need to be assessed on their merits and defended with evidence that pre-dates the query.

Finally, treat documentation as a deliverable with a deadline. Substantiation assembled after an assessment notice arrives carries markedly less weight than substantiation prepared when the transaction occurred.

A regulator that publishes wave criteria six months ahead, that notifies taxpayers directly, that issues guidance with worked examples, and that tells the market in advance where relief will end, is behaving like the administration of a mature investment destination. That predictability is an asset for serious businesses, and it is what long-term capital looks for.

But predictability runs in both directions. The Kingdom has been clear about what it expects and when. The businesses that will move through the coming assessment cycle with least disruption are those that use the next few months to answer the questions before they are asked.

Continue Reading

Financial

Al Ansari Exchange Partners with RTA Dubai to Offer nol Travel Cards

Published

on

Al Ansari Exchange, the UAE’s leading remittance and foreign exchange company and a subsidiary of Al Ansari Financial Services PJSC (DFM: ALANSARI), has partnered with Dubai’s Roads and Transport Authority (RTA) and in association with MDX Technology Solutions ME, to make nol Travel Cards available at selected branches across Dubai.

The collaboration broadens Al Ansari Exchange’s portfolio of third-party products and extends access to Dubai’s integrated mobility payment system through the UAE’s largest branch networks. It also reflects the company’s strategy of building a connected physical and digital ecosystem that provides customers with convenient access to a wider range of everyday financial and lifestyle services.

Residents and visitors can now purchase nol Travel Cards from selected Al Ansari Exchange branches, distributed through MDX Technology Solutions ME, the RTA-authorised distributor of nol Travel Cards, providing an additional point of access to one of Dubai’s most widely used mobility payment solutions.

The nol Travel Card enables cashless payments across Dubai’s public transport network, including the Dubai Metro, Dubai Tram, public buses, marine transport and public parking. It is also accepted at more than 14,000 retail outlets across the UAE. Through the nol Pay App, cardholders can access more than 200 lifestyle offers and discounts.

Commenting on the collaboration, Musad Ibrahim Alhammadi, Director of Automated Collection Systems at Corporate Technology Support Services Sector, Roads and Transport Authority (RTA), said: “Expanding the availability of nol Travel Cards through strategic collaborations supports RTA’s efforts to make mobility services more accessible across Dubai. Providing additional distribution channels contributes to wider adoption of digital payment solutions and enhances the travel experience for residents and visitors.”

Ali Al Najjar, Chief Executive Officer of Al Ansari Exchange, added: “As customer expectations continue to evolve, we are expanding the role of Al Ansari Exchange beyond traditional financial transactions by bringing together financial, payment and everyday lifestyle services through both our branch network and digital platforms. Making nol Travel Cards available through our branches complements our broader strategy of creating a seamless customer experience while supporting Dubai’s vision for a smart, digitally connected city.”

Continue Reading

Financial

The rights you think you have: five legal stress tests for a more resilient business

Published

on

Resilience is not only about cash reserves, backup servers or alternative suppliers. It also depends on whether a company’s legal rights and permissions still work when the business is under pressure.

By: Maroun Abou Harb, Associate at BSA LAW

Resilience is discussed as an operational or financial discipline. Businesses test liquidity, back up systems and diversify supply chains. Yet every continuity plan rests on legal infrastructure: licenses, delegated authorities, contracts, data permissions, employment arrangements, security rights and evidence.

That infrastructure can fail when needed most. The replacement supplier cannot be appointed without third-party consent. Customer data cannot lawfully be moved to the backup provider. An insurance claim is compromized by late notification. A guarantee was signed incorrectly. The company owns a platform, but not all of its intellectual property.

The most dangerous legal risk is not the missing clause. It is the right management assumes the business has, but cannot use.

In the UAE, the Central Bank’s 2026 Operational Risk Management Regulation now requires licensed financial institutions to implement a comprehensive operational risk and resilience proecedure. The principle is valuable for every company: identify what must continue, locate the legal points of failure and test them before disruption does.

  1. Can the business lawfully act?

Start with corporate authority, check that licenses match actual activities, constitutional documents reflect the ownership and governance structure, and beneficial-owner, shareholder and director records are accurate. Review reserved matters, signing matrices, powers of attorney and banking mandates.

A deal, borrowing or emergency payment can stall because the authorized signatory is unavailable, a power has expired or an approval threshold was misunderstood. Group companies should confirm which entity employs people, owns assets, contracts with customers and receives revenue.

Run this scenario: if the chief executive and chief financial officer were unreachable tomorrow, who could bind the company, access its accounts and appoint an alternative supplier? If the answer is uncertain, the business has a legal single point of failure.

  • Which contracts become dangerous under stress?

Most contract reviews examine value and liability. A resilience review asks a different question: what happens when performance is interrupted?

Build a heat map of critical customer and supplier contracts, ranked by operational importance and consequence of failure. For each, test termination and suspension rights, force majeure and change-in-law provisions, service levels, price-adjustment mechanisms, liability caps, indemnities, insurance, governing law and dispute forum, subcontracting, assignment and change-of-control restrictions. Check notice methods and cure periods; a valuable right can disappear if a notice is sent late or to the wrong address.

Then examine optionality, can the company use a replacement supplier, obtain transition assistance, retrieve its data in a usable format and continue using essential intellectual property? Is there a source-code escrow or step-in mechanism where appropriate?

The aim is not to renegotiate every contract. It is to know which five contracts could stop the business and to fix those first.

  • Can technology fail without the legal part failing too?

A technical recovery plan is incomplete if the contracts do not support it. Cloud, payment, telecommunications and managed-service arrangements should align promised recovery times with the company’s tolerance for disruption. Audit rights, incident cooperation, subcontractor controls, data-location commitments and exit assistance should be tested.

The incident playbook must allocate legal decisions. Who determines whether regulators, customers, insurers or affected individuals must be notified? Who preserves evidence and engages external advisers? How will legal privilege or professional confidentiality be preserved? A cyber incident moves quickly; ambiguity over decision-making wastes the hours that matter most.

Conduct an exercise with management, technology, legal, communications and finance. Introduce a realistic vendor outage or data breach and follow the contracts: who calls whom, what must be notified, and what can actually be recovered?

  • Does the company know what data and technology it is using?

Across the GCC, privacy and cybersecurity regimes increasingly regulate how data is collected, processed, retained, transferred and protected. A company cannot comply, or recover confidently, without knowing where its data goes.

Create a data map covering customers, employees, vendors and website users. Record the purpose and legal basis for processing, storage location, access rights, retention period, cross-border transfers and third-party processors.

The same exercise should include artificial intelligence, by identifying public and embedded AI tools, the information supplied to them, the outputs relied upon and the human review applied. Confidential information, personal data and third-party intellectual property should not enter a tool because an employee can access it. An approved-use policy, procurement review and output-verification process are proportionate safeguards.

  • Can the company protect value when conditions deteriorate?

Management should monitor covenant breaches, unpaid taxes, overdue receivables, expiring insurance, threatened claims and counterparties showing signs of insolvency. The legal team should know which rights permit suspension, security enforcement, contract termination or protective court relief, and whether exercising them could create risk.

People and intellectual property also require continuity planning. Confirm that employment and consultancy terms contain appropriate confidentiality, invention-assignment and post-termination protections, tailored to the governing law. Identify key-person dependencies, succession gaps and access held by departing staff. Register intellectual property where appropriate and maintain evidence of creation and ownership.

Business needs also to review insurance as a contract, not a certificate. Map material risks to coverage, exclusions, deductibles, notification deadlines and consent requirements. The policy is only useful if the company knows how to activate it.

In brief, the output should be that for every critical risk, record the business service affected, relevant entity and contract, responsible owner, required action, deadline and escalation threshold.

Report the highest exposures to the board and repeat the exercise after major acquisitions, restructurings, regulatory changes or technology deployments.

A focused review can produce four useful assets:

  1. an authority and obligations calendar;
  2. a critical-contract heat map;
  3. a data and AI inventory; and
  4. a tested incident playbook.

No company can remove disruption. It can, however, remove the uncertainty surrounding who may act, what must be done and which rights remain available.

Continue Reading

Trending

Copyright © 2023 | The Integrator