ERP for UAE Inspection Companies: SACS-002 Data Residency and Aramco Vendor Portals
UAE NDT companies juggle Aramco and ADNOC vendor portals at once. Here is how to evaluate ERP data residency, VAT, and bilingual reporting needs.
Why a UAE Inspection Company Cannot Plan Its ERP Around ADNOC Alone
Most inspection companies headquartered in Abu Dhabi, Dubai, or Sharjah did not build their business on a single client relationship. A typical mid-sized UAE NDT provider runs technicians on ADNOC-operated assets in the Upper Zakum or Ruwais complex one month, then mobilizes a crew to a Saudi Aramco-operated gas plant in the Eastern Province as an approved sub-vendor to a main EPC contractor the next, with a smaller job for a Qatari petrochemical operator or a Bahrain refinery turnaround filling the gap in between. That is the normal operating pattern for a GCC-facing inspection company, and it means the company is never managing compliance against one operator's rulebook. It is managing three or four simultaneously, each with its own vendor portal, its own document refresh cycle, and its own idea of what "current" certification evidence looks like.
This matters for enterprise resource planning because most ERP systems sold into the region, including generic Atlantis ERP implementations pulled off the shelf, are built around a single-entity, single-jurisdiction mental model: one chart of accounts, one tax regime, one compliance calendar. A GCC inspection company needs something closer to a multi-tenant compliance tracker sitting on top of standard financial and operational modules. Getting this wrong does not just create administrative friction, it creates real commercial risk: a lapsed vendor registration with one operator can freeze a crew's site access mid-project, and a missed document resubmission window can knock a company off an approved bidders list for a renewal cycle that will not come around again for a year or more.
The Multi-Portal Reality: Aramco, ADNOC, and Everyone In Between
Saudi Aramco's supplier registration process, run through its vendor management and iSupplier-style portal infrastructure, requires registered vendors to maintain a standing set of company documents (commercial registration, GOSI/Saudization evidence for locally operating entities, quality certifications, insurance, HSE statistics, and inspection personnel certification records) and to keep that document set current against expiry dates the portal tracks automatically. For a UAE company operating as an approved sub-vendor into Aramco-operated or Aramco-affiliated work, the practical burden falls on the prime EPC or main contractor to flow down qualification requirements, but the inspection subcontractor still has to produce and refresh the same underlying evidence: current ASNT SNT-TC-1A written practice records for technicians performing UT, RT, MT, PT, and ET work, equipment calibration certificates, and radiation source licensing documentation for radiographic testing crews.
ADNOC runs a parallel but structurally different process. Vendor registration with ADNOC and its group companies is tied to the In-Country Value (ICV) program, which scores and weights suppliers partly on their contribution to UAE Emiratization, local spend, and local manufacturing or service delivery, in addition to the standard technical and HSE qualification criteria every operator applies. An inspection company chasing both Aramco-linked sub-vendor work and direct ADNOC group contracts is therefore maintaining two structurally different qualification files: one weighted toward document currency and technical qualification depth, the other weighted partly toward ICV scoring inputs that have nothing to do with NDT technical capability at all, but still have to be tracked, certified, and resubmitted on their own cycle.
The Operational Cost of Duplicate Document Sets
None of this is exotic if a company only ever touches one operator's system. The cost shows up when a company is maintaining three or four of these portfolios at once, each with different expiry logic, different upload formats, and different renewal notice periods. In practice this usually falls to one or two administrative staff who track expiry dates in spreadsheets, and it is precisely the kind of process that degrades quietly. A technician certification that expires mid-quarter, a calibration certificate that lapses two weeks before a scheduled inspection, or an insurance renewal that slips past a portal's grace period does not usually cause an obvious failure. It shows up later as a rejected invoice, a technician pulled from a job site by the client's own document audit, or a vendor status downgrade that only becomes visible when the next tender round opens and the company discovers it is no longer on the approved list.
An ERP built for this environment needs a compliance layer that treats each operator relationship as its own tracked entity: separate document expiry calendars per portal, automated renewal alerts tied to the actual lead time each operator's portal requires (Aramco and ADNOC do not use the same notice windows), and a single dashboard view so operations management can see, at a glance, which vendor files are current and which are approaching a gap. This is one of the areas where a purpose-built Atlantis NDT ERP deployment earns its keep over a generic implementation: the vendor-portal compliance tracking has to be a first-class object in the system, not a spreadsheet bolted on beside it.
Third-Party Cybersecurity and Data-Handling Expectations
Large GCC operators, Saudi Aramco prominent among them, have been steadily formalizing what they expect from contractors and vendors who connect to their systems or who handle their operational and inspection data. Saudi Aramco maintains a documented third-party cybersecurity standard commonly referred to in the industry as SACS-002, which governs the security posture expected of vendors with system access or data-handling responsibility. It is worth being precise about what an inspection company actually needs to know here, because this is an area where vague secondhand summaries circulate and get repeated as fact. Atlantis NDT is not a certifying or auditing body for SACS-002 or any equivalent operator cybersecurity standard, and this article does not attempt to reproduce specific clause numbers, control lists, or pass/fail audit criteria, because doing so with confidence requires direct, current access to the operator's own published requirements and, in most cases, the operator's own third-party risk team.
What is safe to describe, because it holds across essentially every major operator's third-party requirements in this category (not just Aramco's), is the shape of what gets asked for. Operators in this category generally want visibility into:
- Data residency and hosting location: where inspection data, reports, and any system that touches the operator's asset or process information physically resides, and whether that location sits inside or outside the operator's home jurisdiction.
- Access control: who inside the vendor organization can reach systems or data tied to the operator's assets, how that access is provisioned and revoked, and whether multi-factor authentication and role-based permissions are enforced rather than assumed.
- Incident reporting: a defined obligation to notify the operator within a set window if the vendor experiences a security incident that could touch the operator's data or connected systems.
- Vendor risk assessment: a periodic or pre-qualification review of the vendor's own security posture, often via questionnaire, sometimes via a more formal audit for vendors with deeper system integration.
An inspection company should treat this category of requirement as a standing evaluation criterion, not a one-time hurdle to clear during onboarding. That means asking real, specific questions of any software vendor before signing, ERP or otherwise: where is the database physically hosted, who has administrative access to it, what happens in the event of a breach, and can the vendor produce a straight answer rather than a marketing paragraph. If a software vendor cannot describe its own hosting location and access control model in plain terms, that is itself useful information before a company puts its Aramco or ADNOC vendor-portal data anywhere near that system.
Data Residency: On-Premise, Regional Cloud, or Offshore Hosting
This is the practical decision UAE inspection companies actually have to make when selecting or upgrading an ERP, and it has no universally correct answer. It depends on the mix of clients a company serves and how sensitive its data handling requirements are on any given contract.
On-premise or UAE-based private hosting
Keeping the ERP database physically inside the UAE, whether on company-owned servers or a UAE-region cloud provider, gives the most direct answer to a data residency question and the most control over the access control story. It also carries the highest ongoing IT overhead: someone has to own patching, backup integrity, and uptime, which is a real operational cost for a company whose core business is inspection, not server administration.
Regional (GCC or Middle East) cloud hosting
Major cloud providers now operate data center regions physically located in the UAE and Saudi Arabia, which lets a company keep data inside the GCC without owning the hardware. This is often the practical middle ground: it satisfies most operators' residency expectations while offloading infrastructure management to a provider with security and uptime resources most 25 to 150-person inspection companies cannot replicate in-house.
Offshore hosting outside the GCC
Many software products sold into the region, including a large share of generic ERP and reporting tools, host data in Europe, the United States, or wherever the vendor's default infrastructure happens to sit. This is not automatically disqualifying, but it is exactly the kind of detail that should be surfaced and evaluated deliberately rather than discovered after a client's third-party risk team asks the question during a vendor audit. A company should know, in writing, where its ERP vendor hosts its data before that becomes a live issue in a client qualification review.
The right question to ask any ERP or reporting software vendor is not "are you compliant," which is a meaningless claim without a named standard and a named auditor. The right question is "where is our data physically hosted, who can access it, and can you show me that in writing." A vendor that can answer clearly is a materially lower-risk choice than one that answers with reassurance instead of specifics, regardless of which particular operator's requirements eventually get applied to the relationship.
Multi-Currency and VAT Handling
The UAE introduced a 5 percent Value Added Tax in January 2018, administered by the Federal Tax Authority, and most GCC-facing inspection companies now invoice across at least two or three currencies in a normal operating year: AED for UAE-based work, SAR for Saudi-side contracts, and often USD for international EPC clients who price in dollars regardless of project location. An ERP that treats currency as a single default setting rather than a per-invoice, per-client configuration creates real accounting friction, particularly at VAT return time when UAE-sourced revenue has to be cleanly separable from cross-border service income for FTA reporting purposes. A properly configured system needs multi-currency invoicing with automatic exchange-rate handling, VAT-compliant invoice formatting for UAE-domestic work, and a chart of accounts structured so finance staff are not manually reclassifying transactions at quarter-end to figure out which revenue is even VAT-applicable.
Arabic and English Bilingual Reporting
Inspection reports, calibration certificates, and vendor-facing documentation for GCC operators frequently need to exist in both Arabic and English, sometimes as parallel bilingual documents and sometimes as separate translated sets depending on the client and the contract language requirements. An ERP or reporting workflow that treats Arabic as an afterthought, bolted on through manual translation after the English report is finalized, adds real turnaround time and real error risk on every job. Report templates that natively support bilingual layout, with technical terminology (weld numbers, defect classifications, acceptance criteria referencing ASME Section V or API 1104 as applicable) rendered consistently in both languages, save meaningful QA review time compared to reconciling two separately produced documents. This is one of the reasons a purpose-built NDT reporting software platform designed with GCC bilingual requirements in mind outperforms a generic reporting tool retrofitted after the fact.
Free Zone Structures and ERP Entity Setup
A meaningful share of UAE-based inspection and technology companies operate through free zone entities such as JAFZA (Jebel Ali Free Zone), DMCC (Dubai Multi Commodities Centre), or ADGM (Abu Dhabi Global Market), each with its own licensing regime, its own rules on mainland trading permissions, and in ADGM's case a separate common-law legal framework distinct from onshore UAE civil law. This matters for ERP configuration in a very concrete way: a company operating through a free zone entity while also holding a mainland trade license, or coordinating invoicing between a free zone parent and an onshore branch, needs a multi-entity chart of accounts structure that keeps those legal entities cleanly separated for statutory filing purposes while still giving management a consolidated operational view across the whole business. An ERP configured around a single flat entity assumption will force manual workarounds the first time a company needs to produce entity-specific financials for a free zone authority audit or an onshore VAT filing.
Decision Criteria for Evaluating an ERP Vendor
Pulling this together, a UAE or wider GCC inspection company evaluating ERP options should be asking vendors specific, answerable questions rather than accepting general compliance claims:
- Can the system track separate document expiry calendars per operator vendor portal (Aramco, ADNOC, and others), with renewal alerts tuned to each portal's actual notice window?
- Where is our data physically hosted, and can that be confirmed in writing rather than asserted verbally?
- Who has administrative access to our data, and is that access role-based and auditable?
- Does the system support multi-currency invoicing (AED, SAR, USD, and others) with UAE VAT-compliant formatting built in?
- Does report generation natively support bilingual Arabic/English output, or does that require a manual translation step on every job?
- Can the chart of accounts support multiple legal entities (free zone plus onshore, for example) with entity-level statutory reporting?
None of this replaces a company's own legal and compliance review of any specific operator's third-party cybersecurity requirements, and no ERP vendor, Atlantis included, should be treated as a substitute for that review. What an ERP can and should do is remove the operational drag that makes multi-operator, multi-jurisdiction compliance harder than it needs to be, so the people running the business are managing exceptions instead of chasing spreadsheets.
Companies weighing an ERP transition alongside broader digital maturity, including asset-level visualization for client-facing reporting, may also find it useful to look at how a digital twin platform complements inspection data management on longer-running GCC asset integrity contracts, where operators increasingly expect inspection history tied directly to a visual asset model rather than delivered as a standalone PDF archive.
Atlantis NDT Products & Services
Atlantis NDT pairs field expertise with software: NDT inspection management software - Atlantis ERP, a digital twin platform for asset integrity, and NDT reporting software. Build your team with NDT training & certification (ASNT SNT-TC-1A) and ASNT certification pathways, or bring in ASNT Level III consulting. Affordable, accessible, fully customizable - book a free consultation.
When report turnaround is the bottleneck
Most inspection companies lose more hours to report formatting than to inspection. NDT reporting software compares the options for issuing the same dataset in several client formats without re-keying, the NDT inspection software buyer’s guide separates the four product categories that all get called “NDT software”, and the free evaluation checklist sets out the tests that actually separate marketing from capability.
Atlantis NDT Products & Services
Atlantis NDT pairs field expertise with software: NDT inspection management software — Atlantis ERP (certification tracking, work orders, method-specific reporting on every business app you need), a digital twin platform for asset integrity (3D corrosion mapping and inspection-data overlay), and NDT reporting software. Build your team with NDT training & certification (ASNT SNT-TC-1A) and ASNT certification pathways, or bring in ASNT Level III consulting for written practices, procedures and audits — plus independent inspection data review on API 510/570/653-governed assets. Capture as-built reality with 3D laser scanning services. Affordable, accessible, fully customizable — book a free consultation.