Short answer
The answer, before the reasoning
A defensible UAE Climate Law gap assessment compares a dated, route-specific requirements matrix with operating evidence - not only with the current sustainability report. Score maturity separately across legal status, boundary and source mapping, data and evidence, methods and factors, internal controls, verifier readiness, reduction/adaptation plans, and registry/filing governance.
Critical applicability, material-error or filing gaps must not be averaged away by stronger scores elsewhere. Every finding needs an owner, due date, evidence of correction and independent retest.
Technical status. Current law, separate Resolution 67 requirements and emirate-level implementation must remain visibly separated from anticipated federal guidance. The assessment should be reopened whenever an official designation, resolution, form, threshold, verifier rule or deadline changes.
Educational material. It does not replace Federal Decree-Law No. 11 of 2024, implementing decisions, a competent-authority instruction, legal advice, engineering or scientific expertise, professional judgement or an assurance conclusion.
A report gap assessment is not enough
Comparing last year's sustainability report with a list of legal headings may identify missing narrative. It does not demonstrate that the organisation has the right legal route, complete source population, accepted methods, original evidence, operating controls or verifier readiness.
A strong gap assessment uses three tests for every material requirement:
Requirement design: Is the applicable, current requirement correctly identified and interpreted?
Evidence design: What record, calculation, approval or control should exist if the requirement is met?
Operating effectiveness: Does that evidence exist for the relevant population and period, and has it been independently challenged?
The output is a remediation plan, not a coloured score alone.
Step 1 - build a dated, route-specific requirements matrix
Start with legal routes rather than disclosure topics. For each requirement record:
instrument, article/section and source URL;
version, publication/effective context and last checked date;
jurisdiction, entity, facility, operator and sector;
trigger, threshold, designation or authority instruction;
boundary, gases, Scope, period and deadline;
approved method/form and verifier requirement;
expected evidence and internal control;
current conclusion, owner, reviewer and open question;
update trigger and superseded source.
Keep current requirements, local implementation and anticipated/future requirements in separate status fields. A likely future rule is useful for planning but cannot be scored as a current breach.
Step 2 - apply a five-level maturity model
Figure 1. A five-level maturity model. Score each domain separately and preserve critical-gate overrides. Original London Reporting Academy practitioner visual.
Do not average the scores into a single comforting number without override rules. A score of 4 for reduction planning cannot offset a score of 0 for designation status or source completeness.
In practice
| Score | Maturity | Typical evidence — Assessment implication |
|---|---|---|
| 0 | Unaware | No route analysis, owner or source register — Critical programme-design gap |
| 1 | Ad hoc | Partial inventory or informal advice — High risk of incomplete or inconsistent output |
| 2 | Defined | Documented methods, roles and planned controls — Design exists; operation must be tested |
| 3 | Controlled | Recurring data controls, evidence links, findings and retest — Ready for detailed verification preparation |
| 4 | Assurance-ready | Integrated governance, independent challenge, version control and complete filing trail — Strong readiness, subject to current authority requirements |
Domain 1: legal status and applicability
Key questions: Which legal route applies? Has the Source been designated? Is a local facility route triggered? Does Resolution 67 apply? Has Article 18 status been checked? Which authority instruction is current?
Evidence: legal memorandum, entity/facility population, official source register, designation/portal evidence, authority correspondence, threshold calculation and approval.
Critical finding examples: no route analysis; wrong threshold; free-zone entity omitted; material authority question presented as a concluded exemption.
Domain 2: boundary and source completeness
Key questions: Are legal entity, facility operator and voluntary inventory boundaries distinguished? Are all facilities, sources and streams mapped? Are structural changes controlled?
Evidence: licences, permits, ownership/lease records, P&IDs, equipment and fuel registers, refrigerant logs, production data, site walkdowns, source map and operations sign-off.
Critical finding examples: material facility or source absent; operator not established; acquisitions/disposals not reflected.
Domain 3: data and evidence
Key questions: Can every material activity-data input be traced to original records? Are period, unit, cut-off and transformations controlled? Can Article 6 records be retrieved for five years?
Evidence: invoices, meter extracts, calibration, stock and production records, data dictionary, evidence index, retrieval test and management representations.
Critical finding examples: calculated total without original evidence; material data gap hidden; inaccessible source system; no retention design.
Domain 4: methods, factors and estimates
Key questions: Is the method accepted for the route? Are factors, units, GWP, oxidation/conversion and uncertainty documented? Are estimates and method changes approved?
Evidence: monitoring plan, methods-and-factors register, authority approval, dimensional checks, estimate register, change log and independent recalculation.
Critical finding examples: unsupported factor; systematic unit error; method conflicts with authority guidance; silent factor change.
Domain 5: internal controls and issue management
Key questions: Are completeness, extraction, calculation, review, access, estimate, change, final-file and claims controls designed and operating? Are findings independently retested?
Evidence: RACI, control descriptions, operation samples, reconciliations, sign-offs, exception logs, correction evidence, retest and access reports.
Critical finding examples: preparation and approval performed by one user without review; material finding closed without retest; submitted file differs from approved file.
Domain 6: verifier readiness
Key questions: Is verification required for the route and period? Does the body have the correct accreditation scope and sector competence? Are conflicts resolved? Is the timetable realistic?
Evidence: authority criteria, RFP, accreditation certificate/scope, team CVs, conflict questionnaire, engagement letter, evidence request, site plan, findings and conclusion.
Critical finding examples: wrong accreditation scope; verifier also designed material inventory judgements without safeguards; fieldwork starts after filing.
Domain 7: reduction and adaptation readiness
Key questions: Are current/planned reductions and expected results traceable to the inventory? Are gross reductions separated from removals and credits? Are physical risks, costs and residual risks governed?
Evidence: baseline, targets, action register, capex/opex, expected and actual tCO2e, measurement method, variance, credit register, adaptation risk/action register and board approval.
Critical finding examples: target boundary differs from inventory without explanation; credits netted from gross emissions; material adaptation risk omitted from business continuity.
Domain 8: registry, filing and governance
Key questions: Are portal access, authorised contacts, final approval, submission, receipt, corrections, retention and public claims controlled? Is the regulatory watchlist current?
Evidence: authorised-user list, board minutes, final file/checksum, portal receipt, correspondence log, correction/resubmission evidence, claims ledger and update watchlist.
Critical finding examples: no evidence of submission; unapproved employee files; public “compliant” claim exceeds the legal analysis or verifier conclusion.
Step 4 - test evidence, not only document existence
Figure 2. From legal requirement to expected evidence, sample, test, finding, remediation and retest. Original London Reporting Academy practitioner visual.
For each selected requirement, define the population and sampling logic. Inspect evidence, recalculate material amounts, reconcile populations, interview owners and test approval/version fields. A policy can score no higher than “defined” unless there is evidence that the control operated for the period.
A finding should record condition, criterion, cause, consequence, severity, affected data/claim, owner, due date, required evidence and retest result. Avoid vague actions such as “improve data quality”. State what must change and how closure will be proven.
Step 5 - prioritise remediation with critical-gate overrides
Use four remediation waves:
Do not close a critical gap because its long-term system solution will take time. Establish an approved interim control, transparent limitation and remediation milestone.
In practice
| Wave | Focus | Typical deadline logic |
|---|---|---|
| 1 - critical legal/data gates | Applicability, material source omissions, wrong method, unsupported filing or claim | Immediate executive escalation |
| 2 - first-cycle close | Original evidence, estimates, reconciliations, access, verifier preparation | Before internal close / fieldwork |
| 3 - system improvement | Metering, automation, factor governance, site training, retention | Funded implementation plan |
| 4 - maturity enhancement | Advanced analytics, continuous controls, integrated finance and scenario analysis | Next-cycle roadmap |
Hypothetical maturity assessment
A logistics group scores itself as follows:
The arithmetic average is 1.6, but the conclusion is not “moderate readiness”. Legal status and verification are critical gates, so the programme is not ready until those decisions are resolved and evidenced.
In practice
| Domain | Initial score | Key gap — Priority action |
|---|---|---|
| Legal status | 1 | No entity/facility route analysis — Legal memorandum and authority questions |
| Sources | 2 | Contractor fuel sources not assessed — Source and boundary review |
| Data/evidence | 2 | Fuel-card extracts retained, invoices incomplete — Evidence retrieval and reconciliation |
| Methods | 3 | Factors controlled but authority acceptance open — Method confirmation |
| Controls | 1 | Reviews described but not evidenced — Operate and sample controls |
| Verification | 0 | No route or RFP — Confirm requirement, scope and timetable |
| Plans | 3 | Reduction plan exists; credits are mixed with savings — Separate gross reductions and credits |
| Filing/governance | 1 | No authorised-contact or final-file protocol — Approval and submission control |
Common gap-assessment mistakes
Comparing only published wording with requirements.
Scoring a planned control as if it operated.
Mixing current law, local rules and anticipated guidance in one status.
Averaging away a critical legal or source-completeness gap.
Treating an estimate as a data-quality score rather than a governed judgement.
Closing findings without correction evidence and independent retest.
Assigning remediation to “the ESG team” without site or finance ownership.
Failing to reopen the matrix after a regulatory or organisational change.
Rule
Myth. “A high maturity score proves compliance.”
Reality. Maturity describes readiness and control strength. Compliance depends on the applicable current rule, facts, accepted methods, complete evidence, required verification and an accepted filing or other legal outcome.
Readiness
Gap-assessment evidence checklist
- Dated requirements matrix with current official sources and route status.
- Complete UAE entity, facility, operator and source population.
- Approved boundaries, methods, factors, GWP and estimates.
- Original data evidence and five-year retrieval test.
- Samples proving key controls operated.
- Verifier requirement, accreditation scope, competence and conflicts assessed.
- Reduction, adaptation and credit information reconciled to gross inventory.
- Findings prioritised by severity, not averaged score.
- Remediation owners, due dates and evidence of correction recorded.
- Independent retest and governance approval completed.
Sources
Primary sources
- UAE Federal Decree-Law No. 11 of 2024 on the Reduction of Climate Change Effects
- Cabinet Resolution No. 67 of 2024 concerning the National Register for Carbon Credits
- Official launch of the National MRV System, 16 October 2025
- Environment Agency - Abu Dhabi Facility-Level MRV portal
- EAD Facility-Level MRV workshop, 12 March 2026
- Ropes & Gray / Al Tamimi implementation alert, 10 April 2026
Take it with you
The checklists as a working spreadsheet
Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.
✓ LRA AI Assistant · Human-in-the-loop
Ask about this guide
It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.
Go deeper · UAE FDL 11 / 2024
UAE Climate Law training
Obligations under Federal Decree-Law 11 of 2024, from inventory to the reduction plan.
Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.
