Knowledge base / regulation10.ae product guide (DIFC Reg 10)
Generate an evidence pack and share it with an ACB
To produce an evidence pack, open the AI system and click Generate evidence pack. The platform assembles the system's completed module runs, attached artefacts, and a tamper-evident audit trail into a single export. You can then share it with an Accredited Compliance Body (ACB) or the DFSA through a time-limited, access-controlled share link, or download the pack and send it yourself.
The pack exists because assessment work only counts when it can be shown. DIFC Regulation 10 anticipates certification and supervisory review, and both depend on an organisation producing its compliance record in a form a third party can examine. Assembling that record by hand from tickets, documents, and spreadsheets is slow and error-prone. The generate step replaces that assembly with an export built from work already recorded in the platform.
What goes in is exactly what the system's record contains: each completed module run with its findings and scores, the documents you attached to the system, and the audit trail of who did what and when. Nothing is written for the occasion. If the record has gaps, the pack shows the gaps. That property is deliberate, because a reviewer who finds one polished inconsistency will distrust the whole submission, while a record with honest gaps and visible remediation reads as a working compliance programme.
The audit trail is tamper-evident, meaning the export lets a reviewer verify that entries were not altered after the fact. For a certification exercise this is the difference between asserting your history and demonstrating it.
Sharing is a separate, deliberate act. Generating a pack does not disclose anything. When you are ready, create a share link from the evidence page. The link is time-limited, so access lapses on the date you set, and access-controlled, so it reaches the reviewer you intended rather than anyone holding the URL. If your ACB prefers to receive files directly, download the pack and send it through whatever channel they specify; the content is the same either way.
Every generation and every share is itself recorded in the audit log. This gives you a defensible answer to a question that arises more often than expected: what exactly did we disclose, to whom, and when? If a supervisory conversation later turns on what a reviewer had seen at a given date, your log answers it precisely.
Packs are point-in-time exports. A pack generated today reflects the record today, and later work does not retroactively change an export already shared. When your record improves materially, generate a fresh pack rather than expecting an old link to update.
The practical rhythm that works: generate a pack after each significant round of module runs, review it internally as if you were the ACB, close what you find, and only then share externally. The internal read-through costs an hour. Discovering the same issues during certification costs a great deal more.
Who should hold the task depends on your setup. Generating and sharing sit with the roles that manage the system's record, so the compliance lead usually owns the rhythm while the system owner supplies the missing artefacts a read-through exposes. Keeping those two in the same review session shortens the loop from found gap to closed gap considerably.
Steps
- Open the AI system and click Generate evidence pack.
- Let the platform assemble your module runs, artefacts, and audit trail.
- Create a time-limited, access-controlled share link for the ACB or the DFSA.