Most guides on this subject give you a list of questions. The questions are usually fine. A list still does not help you, because you cannot tell a good answer from a bad one.
So this guide is built the other way round. Each question comes with the answer you want, and the answer that should worry you.
We read every legal point below from the law itself, not from a summary. Where a number is widely quoted and cannot be traced, we say so and leave it out.
The twelve questions
| # | Ask this | What you are really testing |
|---|---|---|
| 1 | Who writes the code, and where do they sit | Whether the work is subcontracted |
| 2 | Show me something you built that still runs | Whether they can support what they build |
| 3 | What worries you about my plan | Whether they read it |
| 4 | Can I speak to a client who left you | Whether they only show happy clients |
| 5 | Fixed price or by the hour | Who carries the risk |
| 6 | What is the warranty, and what do I get if it fails | Whether the promise has teeth |
| 7 | What will this cost me every year after launch | Whether they have told you the real price |
| 8 | Which paid services will this depend on | The bill that arrives after you launch |
| 9 | Who does the code belong to when we finish | Whether you can leave |
| 10 | What happens if you are late | Whether the contract protects you |
| 11 | Where will my data live | Whether you are allowed to build it that way |
| 12 | What is in the requirements document | Whether anyone agreed what you are buying |
The team and the work
1. Who writes the code, and where do they sit
The answer you want. Names, roles and locations. How many are employees. Who is the lead.
The answer that should worry you. "We have a team of 200 developers." Team size is not an answer. Neither is "our resources". Ask whether any part is subcontracted to another company, and get the answer in the contract.
There is no standard definition of a "dedicated team", staff augmentation or white labelling. No standards body or regulator defines any of them. Each seller means something different, so ask what the words mean in your contract.
2. Show me something you built that still runs
The answer you want. A live product, with a link, that they still support.
The answer that should worry you. A portfolio of screenshots. Building software and running software are different jobs, and most agencies only do the first.
This is the question that separates agencies fastest. At COM8 STUDIO we build and run COM8 Realty, a CRM used by Dubai brokerages, so we also pay to fix whatever we get wrong. Ask any agency what they still run, and who answers the phone when it breaks.
3. What worries you about my plan
The answer you want. A specific concern. "Your reporting screen needs data you do not collect yet." That answer proves they read your brief.
The answer that should worry you. "It all looks good." Nobody's plan is all good. An agency that agrees with everything in a sales meeting will agree with everything later, and then bill you for the changes.
4. Can I speak to a client who left you
The answer you want. A name, or an honest explanation of why not.
The answer that should worry you. Only current, happy references. Every agency can produce those. The useful conversation is with someone whose project ended.
The money
5. Fixed price or by the hour
Both models are normal. They move the risk to different people, and you should know which.
The United States federal procurement rules define both clearly. A firm fixed price contract, in the words of FAR 16.202-1, "places upon the contractor maximum risk and full responsibility for all costs and resulting profit or loss". Time and materials is the opposite. FAR 16.601 says it "provides no positive profit incentive to the contractor for cost control or labor efficiency".
Two rules from the same regulation are worth copying into your own contract. Time and materials work must carry a ceiling price, and the supplier goes past it at its own risk. And it may be used only when no other contract type is suitable.
One finding here goes against common sense. A 2017 study in the International Journal of Project Management ran two separate studies. Its finding: "the use of fixed price contracts is connected with a higher risk of project failure compared to time and materials types of contracts". A fixed price does not remove risk. It moves the risk into the scope argument.
The answer you want. A fixed price after a paid discovery stage, or time and materials with a ceiling.
The answer that should worry you. A fixed price quoted in the first meeting, before anyone has written down what you are buying. That price is a guess, and you will pay for the guess through change requests.
6. What is the warranty, and what do I get if it fails
Ask two things: how long, and what the remedy is. Most people ask only the first.
There is no published industry standard for a software warranty period. The "30 to 90 days" figure you will be quoted comes from agency blogs and contract template sites, not from any standards body.
Public buyers are stricter than that. The World Bank's standard contract for information systems sets a default warranty of thirty six months, and it starts at operational acceptance, not at delivery. California's standard IT contract terms keep software and services under warranty for as long as the state keeps using them.
California also sets the remedy, and the buyer chooses it. One option is to make the supplier fix the work. The other is to end the contract, take the money back, and make the supplier pay the difference for an equivalent product elsewhere.
The answer you want. A warranty that starts when the software goes live, and a written remedy.
The answer that should worry you. A warranty that starts at delivery and runs 30 days. Bugs in real use take longer than that to appear.
7. What will this cost me every year after launch
This is the number most quotes leave out, and it is bigger than the build.
Ruediger Zarnekow and Walter Brenner of the University of St. Gallen studied this. Their peer reviewed paper tracked 30 systems across three large European companies. Over a five year life, 79 percent of total cost came after launch. Only 21 percent was planning and building.
Other sources put the share differently. Robert Glass records 40 to 80 percent. Stephen Schach's textbook says at least 67 percent. The estimates disagree, and that is worth knowing. What they agree on is direction: the build is the smaller half.
You will also be quoted "15 to 25 percent of build cost per year" as the maintenance rate. We could not trace that figure to any research body, standards body or published dataset. It appears only on agency pricing pages.
The answer you want. A written annual figure, and a list of what it covers. Security patches, framework upgrades, hosting, and the work caused when a service you depend on changes.
The answer that should worry you. "We will sort that out later."
8. Which paid services will this depend on
Your software will sit on top of other people's software. Each one has its own bill, and its own price rises.
The answer you want. A list, with the monthly cost of each at your expected volume. Hosting, payment gateway, email and SMS, maps, identity checks, storage.
The answer that should worry you. A build price with no running costs attached. Those services are not optional extras. They are part of what you are buying. We did the same exercise for online stores in our guide to ecommerce platforms, where five of the payment providers we checked publish no price at all.
The contract and the law
9. Who does the code belong to when we finish
You will read that the developer keeps copyright by default. You will read that you only get it if the contract assigns it. In the UAE that is not what the law says.
Federal Decree-Law No. 38 of 2021 protects software expressly. Article 2 lists "smart applications, software and software applications, databases" as protected works.
Article 28 then sets the default. It applies "unless otherwise agreed in writing". The rule itself reads: "If the Author makes an Innovation in favour of another Person, the copyright shall be attributed to such Person." So on the face of it, the client who paid for the work starts with the economic rights.
But Article 9 of the same law points the other way. It says any right not expressly assigned stays with the author. It also requires every transfer to be in writing, naming the right, the purpose, the duration and the place of use.
The two articles point in opposite directions, and UAE courts have not decided between them. So do not rely on the default in either direction. Put the assignment in the contract, right by right, with those four elements named.
Two more points from the same law. Moral rights cannot be assigned at all, so credit stays with the developer permanently. And registration is not required for protection. Article 4 says failure to register "shall not prejudice any aspect of the protection or rights established" by the law. Anyone who tells you that you must register software with the Ministry of Economy to own it is wrong.
The answer you want. A written assignment of economic rights, naming the right, the purpose, the duration and the place. Plus the source code repository, in your company's account, from day one.
The answer that should worry you. "You own it, obviously." If it is obvious, it is easy to write down.
10. What happens if you are late
The UAE rewrote this law recently, and most advice online has not caught up.
Federal Decree-Law No. 25 of 2025 replaced the 1985 Civil Transactions Law. It came into force on 1 June 2026. Almost every article you will read still cites Article 390 of the old law for penalty clauses. That law no longer exists. The equivalent is now Article 340.
Under Article 340 you may agree the compensation in advance. A court may reduce it if the amount was excessive, or if part of the work was done. Under Article 337, compensation is generally not due until you have formally put the supplier in default, unless your contract says otherwise.
Article 813 is the one to know before you sign. A works contract must specify its subject, the method, the period of completion and the payment. If no period is agreed, Article 818 requires the work to be finished within a reasonable time.
For a model of what a delay clause looks like, the World Bank's contract charges 0.5% of the contract price for each week of delay, capped at 10%.
The answer you want. A dated delivery schedule, a written consequence for missing it, and a notice process.
The answer that should worry you. A timeline in the proposal that never reaches the contract.
11. Where will my data live
Start with what the law does not say. The UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, contains no data residency rule. Across its 31 articles, nothing requires personal data to stay inside the country. Articles 22 and 23 assume the opposite, and set conditions for moving it out.
Two sectors are different, and they are specific.
Health data must stay in the country. Federal Law No. 2 of 2019, Article 13, says it is "not permissible to store, process, generate or transform the health data and information outside State" where the service was provided inside the UAE. Article 24 sets the penalty at between 500,000 and 700,000 dirhams.
Banking has its own rule. The Central Bank's Consumer Protection Standards, clause 6.1.6.3, require licensed financial institutions to "hold and store all Consumer and transaction Data within the UAE".
The answer you want. A named country and provider for the database, with the sector rules checked against your business.
The answer that should worry you. "It is on the cloud." That is not a location.
12. What is in the requirements document
If nobody wrote down what you are buying, every argument later becomes your word against theirs.
There is a current standard for this. It is ISO/IEC/IEEE 29148:2018, and clause 9.6 lists what a software requirements specification should contain. If an agency cites IEEE 830 instead, that document has been superseded twice, in 2011 and again in 2018.
Ask about acceptance too. The International Software Testing Qualifications Board defines user acceptance testing as testing "performed to determine if intended users accept the system". Your contract should say who tests, against what, and what happens if the answer is no.
The answer you want. A written specification you can read without a developer next to you, and a sign off process.
The answer that should worry you. "We are agile, so we do not write requirements." Agile changes when you write things down. It does not remove the need to agree what you are buying.
The numbers you will be quoted that nobody can check
Software sales decks are full of statistics. We tried to trace the common ones to their source. Most do not survive.
| What you will be told | What we found |
|---|---|
| UAE data law fines reach 5 million dirhams | The PDPL sets no fine at all. Article 26 leaves penalties to a Cabinet decision that has not been issued |
| The PDPL executive regulations are in force | They were due in March 2022. They have still not been published |
| 70 percent of software projects fail | Traces back to arithmetic performed on a 1994 report by people other than its authors |
| Projects run 189 percent over budget | From 1994, and only for the projects that ran over. The same publisher reported 43 percent by 2002 |
| The IEEE says maintenance is 60 to 80 percent of cost | The IEEE's own body of knowledge says only "a major share" |
| Maintenance costs 15 to 25 percent of build per year | No research body publishes this. Only agency pricing pages |
| You must register software with the Ministry of Economy | Article 4 of the copyright law says registration is not required for protection |
| Penalty clauses are governed by Article 390 | That law was repealed on 1 June 2026 |
The most useful test of a statistic is to ask where it came from. Researchers once asked the publisher of the most quoted software failure numbers how its projects were selected. The answer they published was that the reports "should be considered Standish opinion and the reader bears all risk in the use of this opinion".
The same researchers showed why the numbers move. They took a real company that scored 5.8 percent successful, kept every estimating error exactly the same size, and flipped only the direction. The same accuracy then scored 94.2 percent successful.
Numbers that hold up better come from named, checkable studies. Oxford researchers Bent Flyvbjerg and Alexander Budzier analysed 1,471 IT projects and found an average cost overrun of 27 percent, with one in six running 200 percent over. Their sample was very large public programmes, with an average cost of 167 million dollars, so read it as a warning about scale, not about your project.
Two UAE details that change the price
VAT applies, including from free zones. The standard rate is 5 percent. A common belief is that a free zone supplier charges none. For services that is wrong. Article 51 of the VAT Executive Regulation gives the answer. The place of supply of services in a designated zone counts as inside the country, and so does the company. Designated zone status covers goods, not services.
Check the trade licence. There is no national website that lists every UAE company. Licences are checked with whichever authority issued them, and each emirate and free zone runs its own. Ask which authority licensed the agency, and check with that authority.
How to run the meeting
Ask the twelve questions in order. Write the answers down as they are given.
Then look at the answers rather than the proposal. A supplier who answers question 2 and question 9 well is usually safe. A supplier who cannot answer either is selling you a build and leaving you with the rest.
If you would rather talk it through, our custom software team answers these twelve questions in writing before any contract is signed. If you have not decided whether to build at all, that is a different question, and often the answer is no.




