Civil Law And Uae Enterprise Risk Management And Legal Exposure .

 

Civil Law and UAE Enterprise Risk Management and Legal Exposure

1. Introduction

Enterprise Risk Management (ERM) is the systematic process by which a business identifies, evaluates, controls and monitors risks that could affect its assets, operations, reputation, contractual performance and legal position.

Under UAE civil and commercial law, ERM is not merely an internal management concept. Poor risk management can become a source of legal exposure where it results in:

  • breach of contract;
  • negligence or gross error;
  • misuse of managerial authority;
  • fraud;
  • regulatory violations;
  • damage to customers or third parties;
  • shareholder or partner losses;
  • environmental or workplace harm;
  • cybersecurity or data-related damage;
  • insolvency-related losses;
  • dissipation of company assets;
  • obstruction of enforcement.

The central principle is that ordinary commercial failure is not automatically personal legal liability. Personal exposure generally requires a legally recognised basis such as fraud, abuse of power, breach of law or constitutional documents, gross error, or a tortious act satisfying the applicable requirements.

For UAE mainland companies, Federal Decree-Law No. 32 of 2021 on Commercial Companies is particularly important. Article 84 addresses liability of LLC managers, while Article 162 addresses directors and executive management of joint-stock companies.

2. Meaning of Enterprise Risk Management

Enterprise risk management can be understood as a continuous cycle:

Risk identification → Risk assessment → Risk mitigation → Monitoring → Documentation → Response → Review

Legal risk management adds another dimension:

What legal obligation exists? → What conduct may breach it? → Who may be liable? → What loss may result? → What evidence demonstrates compliance?

Thus, UAE ERM should not be restricted to financial risk.

It should cover:

  1. contractual risk;
  2. corporate-governance risk;
  3. litigation risk;
  4. regulatory risk;
  5. employment risk;
  6. tax and financial risk;
  7. data and cybersecurity risk;
  8. intellectual-property risk;
  9. health and safety risk;
  10. environmental risk;
  11. insolvency risk;
  12. enforcement risk;
  13. fraud risk;
  14. director/manager liability;
  15. third-party liability.

3. Separate Legal Personality as the Starting Point

A UAE company generally possesses a legal personality separate from its shareholders and managers.

Consequently:

The company's debt is not automatically the manager's personal debt.

This principle is fundamental to enterprise risk allocation.

However, corporate personality does not protect a manager from liability for his or her own legally actionable conduct.

For example, if a company simply fails commercially because a new product fails, that fact alone does not ordinarily make the CEO personally responsible.

But if the manager:

  • diverts company funds;
  • commits fraud;
  • deliberately violates corporate law;
  • acts outside authority;
  • commits gross error;
  • conceals assets;
  • deliberately obstructs enforcement,

personal exposure can arise.

Article 84 of the Companies Law expressly provides for liability of LLC managers in specified circumstances, while Article 162 establishes liability of directors and executive management of joint-stock companies.

4. Article 22 — Prudent Management

Article 22 of the Companies Law establishes an important ERM principle.

A person authorised to manage a company must:

  • preserve the company's rights;
  • act for the company's benefit;
  • exercise the care and diligence expected from a prudent person;
  • act consistently with the company's objectives;
  • operate within the powers granted by the company.

This makes reasonable corporate decision-making and internal controls legally significant.

Accordingly, an ERM system should allow the company to demonstrate that management:

  • identified material risks;
  • obtained appropriate information;
  • followed approval procedures;
  • considered foreseeable consequences;
  • complied with applicable laws;
  • documented important decisions.

5. Article 84 — LLC Manager Liability

Article 84 is especially important for enterprise risk.

An LLC manager may be liable to:

  • the company;
  • partners;
  • third parties,

for fraudulent acts.

The manager may also be liable for losses or expenses resulting from:

  • improper exercise of powers;
  • violation of applicable law;
  • violation of the memorandum of association;
  • violation of the manager's appointment contract;
  • gross error.

The statutory protection cannot simply be contracted away.

Therefore, ERM has a direct connection with managerial liability.

6. Article 162 — Directors and Executive Management

For joint-stock companies, Article 162 provides liability of directors and executive management toward the company, shareholders and third parties for:

  • fraud;
  • abuse of power;
  • violations of the Companies Law;
  • violations of the company's articles of association.

The provision also contains special rules concerning board resolutions.

Where a resolution is unanimous, liability can extend to all relevant directors.

Where a resolution is passed by majority, a director who objects and records the objection in the minutes may avoid liability under the statutory conditions.

ERM lesson

Board minutes are therefore not merely administrative documents.

They can become important evidence concerning:

  • who approved a decision;
  • who opposed it;
  • what information was available;
  • whether a director warned of the risk;
  • whether proper governance procedures were followed.

7. Enterprise Risk and Civil Liability

The UAE Civil Code provides the broader civil-law framework.

Where wrongful conduct causes legally recognised damage, tort principles can create liability independently of the company's internal corporate structure.

This means ERM should consider both:

Corporate-law exposure

and

General civil-law exposure.

For example:

Manager violates Companies Law → corporate liability

and potentially:

Manager's wrongful conduct causes third-party damage → tortious liability

The two legal bases can sometimes operate alongside one another.

8. Case Law 1 — Dubai Court of Cassation, 11 February 2025

A significant Dubai Court of Cassation decision dated 11 February 2025 concerned personal liability of an LLC manager arising from serious managerial misconduct.

The dispute involved yacht renovation work. An arbitral award had been obtained against the company, but subsequent enforcement difficulties revealed substantial problems concerning the company's assets and management.

The evidence included:

  • failure to maintain proper accounting records;
  • absence of proper financial statements;
  • depletion of company funds;
  • managerial misconduct;
  • diversion of company resources;
  • conduct affecting enforcement.

The Court ultimately imposed personal liability on the manager. The case demonstrates that the corporate structure does not necessarily shield an individual whose own misconduct causes legally compensable damage.

ERM significance

A robust enterprise-risk system should therefore include:

  • accounting controls;
  • asset controls;
  • financial reporting;
  • segregation of company and personal funds;
  • audit trails;
  • post-award asset protection procedures.

Failure in these areas can transform a corporate dispute into personal managerial exposure.

9. Case Law 2 — Dubai Court of Cassation, Commercial Cassation No. 9/2023

In Commercial Cassation No. 9/2023, the Court considered the consequences of failing to identify the company as an LLC and state its capital in the required manner.

The relevant statutory rule can result in personal liability of the manager for obligations arising from the company's transaction, but the liability is not automatic merely because of the formal omission.

The third party must establish that the omission caused the relevant harm and that it was the effective cause of that harm.

ERM significance

This case demonstrates the importance of corporate compliance controls.

A simple-looking administrative failure can become a liability issue where:

compliance failure → misleading or legally significant omission → damage → causation → personal exposure.

Therefore, ERM should include regular checks of:

  • trade licences;
  • corporate names;
  • constitutional documents;
  • capital disclosures;
  • registration information;
  • commercial correspondence.

10. Case Law 3 — Dubai Court of Cassation, Cassation Nos. 312 and 331/2015

The Dubai Court of Cassation authorities cited in later UAE litigation establish an important principle concerning LLC managers.

A manager/shareholder is not ordinarily personally responsible for the company's debts merely because he or she occupies that position.

Personal liability can arise where the manager commits:

  • personal wrongdoing;
  • deception;
  • fraud;
  • gross error;
  • breach of managerial obligations.

The authority is particularly relevant to the distinction between corporate debt and managerial misconduct.

ERM significance

The case illustrates why ERM must distinguish:

Business risk from wrongful conduct risk.

A company can legitimately lose money.

A manager does not automatically become personally liable for that loss.

But deliberate or seriously wrongful conduct can change the legal position.

11. Case Law 4 — Dubai Court of First Instance, Judgment No. 207 of 2020

In Dubai Court of First Instance Judgment No. 207 of 2020, the court considered the personal responsibility of a manager/shareholder toward a creditor.

The court dealt with circumstances involving:

  • fraudulent and deceptive conduct;
  • dissipation of company assets;
  • unexplained withdrawals;
  • transfers of assets to third parties;
  • acquisition of assets in third-party names;
  • conduct affecting creditor recovery.

The manager was held personally liable in circumstances treated as an exception to ordinary corporate personality.

ERM significance

This case highlights asset-protection risk.

Companies should maintain controls over:

  • related-party transactions;
  • asset transfers;
  • shareholder withdrawals;
  • intercompany transactions;
  • unusual payments;
  • beneficial ownership;
  • conflict-of-interest transactions.

These are classic ERM areas because weak controls can create evidence of improper conduct.

12. Case Law 5 — BAM Higgs & Hill LLC v Affan Innovative Structures LLC & Amer Affan, [2021] DIFC CFI 106

This is a DIFC Court decision rather than an onshore UAE court judgment, but it is highly useful because the court analysed Articles 84 and 162 of the UAE Companies Law.

The case examined claims against a manager involving:

  • fraud;
  • misuse of powers;
  • violation of law;
  • managerial error.

The court emphasised the importance of correctly identifying the statutory basis and the nature of the claimant's loss. It also discussed Dubai Court of Cassation Case No. 393/411/2021 concerning proof of fraud and the requirement that allegations of fraud be established by evidence.

ERM significance

This case demonstrates that an allegation such as:

“Management failed to manage risk properly”

is not necessarily enough.

The claimant must connect the alleged conduct to an applicable legal duty and establish the required elements of liability.

13. Case Law 6 — Union Properties PJSC & Another v Trinkler & Partners Ltd & Others, [2026] ADGMCFI 0010

This is a significant 2026 ADGM Court decision involving claims governed by UAE law concerning directors' duties.

The court examined:

  • Article 22 of the UAE Companies Law;
  • Article 162;
  • directors' duties;
  • alleged breach of duty;
  • causation;
  • the relationship between UAE corporate law and tort principles.

The judgment stressed the importance of identifying the correct statutory foundation for a director-liability claim.

ERM significance

The case is particularly relevant to board-level ERM because it shows that the legal question is not simply:

“Was the business decision unsuccessful?”

Instead, the analysis can involve:

  1. What duty existed?
  2. Who owed it?
  3. What conduct allegedly breached it?
  4. Was the conduct within the person's authority?
  5. Did it cause legally recoverable damage?

This is the core of legal risk assessment.

14. Case Law 7 — Abu Dhabi Commercial Bank PJSC v NMC Healthcare Ltd, [2025] ADGMCFI 0004

The NMC litigation provides a major example of enterprise-wide legal exposure.

The claims included allegations involving:

  • fraudulent conduct;
  • failure to exercise reasonable care;
  • director and manager duties;
  • UAE Civil Code Articles 282 and 285;
  • Companies Law duties;
  • unjust enrichment;
  • insolvency-related wrongdoing.

The court therefore had to consider multiple legal bases arising from the same corporate events.

ERM significance

This illustrates risk stacking.

One corporate failure may produce several simultaneous exposures:

Corporate-law liability

  •  

Tort liability

  •  

Contractual liability

  •  

Insolvency liability

  •  

Restitutionary liability

  •  

Regulatory exposure

A good ERM framework therefore cannot operate in isolated legal departments.

15. Case Law 8 — Abu Dhabi Court of Cassation, Judgment No. 70/2026

In Judgment No. 70 of 2026, the Abu Dhabi Court of Cassation examined the personal position of a former LLC manager in enforcement proceedings.

The Court recognised that the LLC remains a separate legal person and that its debts are ordinarily its own.

However, under the Civil Procedures Law, the company's legal representative can face personal enforcement measures where the statutory requirements for responsibility for non-compliance with the judgment are satisfied.

The Court held that transferring ownership of the company did not automatically eliminate the former manager's position in relation to the relevant enforcement obligations, particularly where the underlying contracts had been entered into during his management and financial records had not been properly handed over.

Important distinction

This case does not simply mean:

“A company manager personally owes every company debt.”

The distinction is critical.

The enforcement measures were connected to the manager's role as the person responsible for the company's compliance with the judgment, rather than automatically converting the company's underlying debt into the manager's personal debt.

ERM significance

Companies should therefore maintain:

  • proper handover procedures;
  • financial records;
  • accounting books;
  • enforcement files;
  • litigation records;
  • asset registers;
  • documentary evidence of management transitions.

16. Risk of Fraud

Fraud presents one of the clearest routes from enterprise risk to personal legal exposure.

Potential examples include:

  • falsified accounts;
  • concealment of assets;
  • fraudulent invoices;
  • false representations;
  • related-party deception;
  • manipulation of financial statements;
  • diversion of corporate funds.

Article 84 expressly addresses fraudulent conduct by LLC managers, while Article 162 addresses fraud by directors and executive management in joint-stock companies.

ERM control

Companies should maintain:

  • segregation of duties;
  • dual payment approval;
  • internal audit;
  • whistleblowing mechanisms;
  • related-party transaction review;
  • forensic accounting procedures;
  • independent board oversight.

17. Risk of Abuse of Power

A manager may possess substantial authority but must exercise that authority within the legal and corporate framework.

Examples of risk include:

  • entering transactions outside delegated authority;
  • using company assets for personal purposes;
  • approving related-party transactions without required approvals;
  • transferring assets without legitimate corporate purpose;
  • using corporate authority to prejudice creditors.

The Companies Law expressly recognises misuse or improper exercise of powers as a basis for liability.

18. Contractual Risk

Enterprise risk also arises from contracts.

A company may face liability because of:

  • missed contractual deadlines;
  • defective performance;
  • failure to obtain required approvals;
  • inadequate warranties;
  • indemnity obligations;
  • liquidated damages;
  • termination;
  • guarantees;
  • confidentiality breaches.

ERM should therefore include a contract lifecycle management system:

Negotiation → approval → execution → performance monitoring → variation control → renewal/termination → dispute management

19. Construction and Engineering Risk

Construction businesses face particularly high civil-law exposure.

Potential claims include:

  • defective design;
  • defective construction;
  • delay;
  • professional negligence;
  • certification errors;
  • structural damage;
  • failure to comply with specifications;
  • subcontractor failures.

Enterprise risk management should therefore integrate:

  • technical inspection;
  • professional indemnity insurance;
  • contract review;
  • change-order controls;
  • site documentation;
  • expert certification;
  • health and safety procedures.

20. Cybersecurity and Data Risk

Modern ERM must also include cyber risk.

Examples:

  • ransomware;
  • unauthorised access;
  • data leakage;
  • employee misuse;
  • compromised payment systems;
  • fraudulent electronic instructions;
  • destruction of digital records.

The civil exposure may include:

  • contractual claims;
  • tort claims;
  • regulatory consequences;
  • confidentiality claims;
  • data-protection exposure;
  • employee claims;
  • customer claims.

The crucial ERM question is:

Could the company demonstrate that it took legally reasonable measures to prevent or mitigate the harm?

21. Financial Risk

Financial controls are central to legal exposure.

High-risk areas include:

  • unauthorised withdrawals;
  • related-party payments;
  • inadequate accounting;
  • inaccurate financial statements;
  • undocumented loans;
  • asset transfers;
  • excessive leverage;
  • failure to maintain records.

The 2025 Dubai manager-liability decision demonstrates how deficiencies in accounting and financial records can become important evidence in establishing personal managerial responsibility.

22. Insolvency Risk

When financial distress becomes severe, ERM must change from ordinary business management to distress management.

Management should monitor:

  • liquidity;
  • creditor concentration;
  • overdue debts;
  • cash flow;
  • asset values;
  • contingent liabilities;
  • pending litigation;
  • guarantees;
  • related-party transactions.

Improper transactions during financial distress may generate additional exposure under applicable insolvency and company laws.

The NMC litigation demonstrates how corporate misconduct allegations can coexist with insolvency-related claims.

23. Litigation Risk

Litigation itself is an enterprise risk.

A company should maintain a litigation register containing:

  • claimant;
  • defendant;
  • amount claimed;
  • jurisdiction;
  • procedural stage;
  • limitation period;
  • evidence;
  • settlement possibilities;
  • enforcement prospects;
  • accounting provision.

Failure to monitor litigation can produce additional losses through:

  • missed limitation periods;
  • default judgments;
  • adverse procedural orders;
  • enforcement measures;
  • increased legal costs.

24. Insurance as an ERM Tool

Insurance does not eliminate legal liability.

However, appropriate insurance can transfer part of the financial consequences of particular risks.

Potential forms include:

  • directors' and officers' liability insurance;
  • professional indemnity;
  • public liability;
  • cyber insurance;
  • property insurance;
  • business interruption insurance;
  • construction insurance.

Insurance policies must themselves be reviewed carefully because exclusions may apply to:

  • fraud;
  • wilful misconduct;
  • regulatory penalties;
  • known circumstances;
  • contractual liabilities.

25. Corporate Records as Risk Evidence

Documentation is one of the most important ERM controls.

Companies should preserve:

  • board minutes;
  • shareholder resolutions;
  • contracts;
  • powers of attorney;
  • accounting records;
  • audit reports;
  • compliance reports;
  • risk assessments;
  • internal investigation reports;
  • emails;
  • approval records;
  • conflict disclosures.

The reason is straightforward:

In litigation, the existence of a risk-control system is much easier to demonstrate when decisions were contemporaneously documented.

26. Board Risk Management

A board should generally monitor major enterprise risks through a structured framework.

A useful model is:

Risk Identification

What could go wrong?

Risk Ownership

Who is responsible?

Risk Assessment

How serious could the consequence be?

Legal Analysis

What legal obligation is involved?

Controls

What safeguards exist?

Escalation

When must the matter reach senior management or the board?

Documentation

What evidence demonstrates the decision-making process?

Review

Has the control actually worked?

27. Enterprise Risk and Causation

A crucial principle in UAE civil liability is causation.

The existence of a management mistake does not automatically establish damages.

A claimant generally needs to connect:

wrongful conduct → causation → damage

The 2025 Dubai manager-liability litigation specifically illustrates the importance of connecting managerial misconduct to the claimant's legally recoverable loss.

Therefore, ERM should focus not only on preventing wrongful conduct but also on preventing the chain of causation from developing into actual damage.

28. Risk Matrix for UAE Enterprises

RiskPotential legal exposureERM control
FraudCivil/criminal liabilityInternal audit and segregation
Abuse of authorityManager/director liabilityDelegation matrix
Contract breachDamages/terminationContract monitoring
Poor accountingManagerial/regulatory exposureFinancial controls
Asset diversionPersonal liability/creditor claimsAsset controls
Cyber incidentContract/tort/regulatory exposureCybersecurity controls
Employee misconductCorporate/individual liabilityHR compliance
Product defectCustomer/third-party claimsQuality controls
Construction defectContract/tort liabilityTechnical QA
InsolvencyCreditor/insolvency exposureEarly-warning system
Regulatory breachCivil/administrative/criminal exposureCompliance programme
LitigationJudgments/enforcementLitigation register
Related-party transactionsConflict/fraud claimsIndependent approval
Poor recordsEvidentiary and enforcement riskDocument retention

29. Corporate Veil and Enterprise Risk

The expression “piercing the corporate veil” should be used carefully in UAE legal analysis.

The basic rule remains separate corporate personality.

Personal exposure may arise where the manager or shareholder has personally engaged in legally actionable conduct.

The 2025 Dubai litigation involving an LLC manager demonstrates circumstances in which courts can impose personal liability based on the manager's own misconduct rather than simply treating the company's debt as the manager's debt.

Thus:

Corporate personality protects legitimate corporate activity; it does not necessarily protect personal wrongdoing carried out through the company.

30. Enterprise Risk and Good Faith

Good faith is an important concept within UAE civil and commercial law.

Risk-management decisions should therefore be assessed not only through:

“Was the decision profitable?”

but also:

“Was the decision taken honestly, within authority, with appropriate information and in accordance with the company's legal obligations?”

A commercially unsuccessful decision is not necessarily wrongful.

Conversely, a profitable decision can still generate legal exposure if it involves fraud, abuse of power or violation of law.

31. Enterprise Risk and Third Parties

Legal exposure does not stop at shareholders.

Potential claimants include:

  • customers;
  • suppliers;
  • lenders;
  • employees;
  • contractors;
  • government bodies;
  • shareholders;
  • partners;
  • insurers;
  • competitors;
  • creditors.

Article 84 expressly recognises potential manager liability toward third parties, while Article 162 similarly identifies third-party exposure for directors and executive management in the circumstances specified by the statute.

32. Practical UAE ERM Model

A UAE enterprise can organise legal risk management into seven levels:

Level 1 — Governance

Board, management and delegated authorities.

Level 2 — Identification

Identify legal and commercial risks.

Level 3 — Assessment

Assess probability, financial consequences and legal consequences.

Level 4 — Prevention

Introduce policies and internal controls.

Level 5 — Documentation

Create evidence of compliance and decision-making.

Level 6 — Response

Investigate incidents and mitigate damage.

Level 7 — Remediation

Correct the control failure and prevent recurrence.

33. Six Core Case-Law Principles

The authorities discussed above collectively demonstrate several important propositions:

Principle 1

A company remains a separate legal person.

Principle 2

Managers do not automatically become personally liable for company debts.

Principle 3

Fraud, misuse of authority, statutory violations and serious managerial misconduct can create personal liability.

Principle 4

Damage and causation remain important.

Principle 5

Corporate records and financial controls can become important evidence.

Principle 6

Enforcement exposure and substantive liability are not always the same thing.

The 2026 Abu Dhabi judgment is particularly useful on the sixth distinction: a representative may face enforcement measures connected with facilitating execution against a company without the company's underlying debt automatically becoming the representative's personal debt.

34. Conclusion

Enterprise Risk Management under UAE civil and commercial law is closely connected with legal exposure.

The most important statutory foundations include:

  • Article 22 — prudent management;
  • Article 84 — LLC manager liability;
  • Article 162 — board and executive-management liability;
  • UAE Civil Code provisions concerning tort, contracts and compensation;
  • Civil Procedures Law provisions concerning enforcement;
  • applicable insolvency, regulatory, employment, data and sector-specific legislation. 

The case law demonstrates that UAE law generally distinguishes between ordinary commercial risk and actionable managerial misconduct.

A failed investment, declining market or ordinary business loss does not by itself establish personal liability. The legal exposure becomes substantially more serious where there is evidence of:

Fraud + Abuse of Power + Legal Violation + Gross Error + Damage + Causation + Poor Corporate Controls.

The modern UAE approach therefore makes ERM not merely a business-management technique but an important corporate-law, civil-liability and litigation-prevention mechanism.

LEAVE A COMMENT