Over eighteen months I ran technical due diligence on fourteen development agencies operating in Dubai and the wider UAE, on behalf of companies about to commit between 180 000 and 2.4 million AED. Nine did not pass.
None of the nine were fraudulent. All of them build software, have offices, and have delivered projects. They failed on things that are entirely visible before signature and almost never checked — because the standard selection process in this market weighs a portfolio, a price and a meeting, and none of those three predict delivery.
Here is the method, in seven numbered checks, with what each one caught.
Why the usual selection process fails
The conventional shortlist looks at three things. The portfolio, which shows work that may have been delivered by people who left, or subcontracted entirely. The price, which correlates with delivery quality far more weakly than buyers assume. And the meeting, which selects for the quality of the sales team.
Not one of those three tells you the only thing that matters: who will write your code, and what happens when it goes wrong. The seven checks below exist to answer exactly that.
Check 1: verify the named team, not the company
This is the highest-yield check in the list and it costs two hours.
Require the CVs of the specific engineers who will be assigned, with their availability dates, and insist on interviewing at least two of them before signature. Not the technical director. Not the delivery manager. The people who will write the code.
Five of the nine eliminations came from this check alone, and in all five cases the finding was identical: the senior profiles presented in the proposal were not actually available, and the work would be staffed after signature with more junior engineers. In two cases the named engineer had left the company months earlier and was still in the deck.
What a good answer looks like: named engineers, available for interview, who can discuss the specifics of a project on their own CV in technical depth. What a bad answer sounds like: “we allocate resources after kick-off based on availability”. That sentence is not a process description — it is a warning that you are buying a company, not a team.
The one hour that changes the negotiation
Ask for the assigned engineers’ interviews before discussing price, not after. Agencies that intend to substitute staff will resist at this point, when resisting costs them nothing. Once you have negotiated a rate, the same request reads as bad faith and you lose the signal entirely.
Check 2: read real code from a comparable project
Ask for a repository from a project of similar scope and technology. Not a showcase site, not a demo — a repository from real delivered work.
How the agency handles this request is itself informative. A competent one offers a client repository with documented consent, an anonymised extract, or an internal project of comparable complexity. All three are acceptable. Two things should worry you: having nothing to show at all, and offering a client’s repository without evidence of that client’s permission. The second is the more serious, because they will treat your code exactly the same way.
Read against a written rubric rather than impressions. Mine has six lines: does it build from the README on a clean machine, is there a lock file, are secrets absent from the history, do the tests fail when you break a function, is there deployment and rollback documentation, and is the commit history coherent enough to reconstruct decisions.
Two eliminations here. One repository could not be built at all without a call to the original developer. The other contained live third-party credentials in its commit history — for a client who was, at that moment, still a client.
Check 3: check delivery history with unhappy references
Every agency provides three delighted references. They are worth roughly nothing, and everyone in the room knows it.
Ask instead: “Give me a client whose project went badly, and let me call them.”
The response splits into three. Some agencies refuse, which tells you what you need. Some claim no project ever went badly, which after enough projects is not credible and tells you more. And some hand you a name and a number — which is the answer you want, because a project that went wrong and was recovered is far more informative than three that went smoothly.
On the call, ask exactly one thing: what did they do when it went wrong? You are not assessing whether the agency makes mistakes. You are assessing what happens after one.
Selecting an agency for a UAE build?
We run the full seven-check assessment on your shortlist and deliver a scored rubric with a recommended contingency percentage per candidate.
Get started todayCheck 4: test the security and intellectual property posture
Four questions, asked before a single line of code is written, answered in writing.
- How are secrets handled? Where do API keys live during development, who can read them, and how are they rotated when someone leaves the project.
- How is access granted and revoked? Specifically: what is the process when an engineer rolls off, and how quickly does it run.
- What is the IP assignment chain? The chain runs engineer to agency to you. If it breaks at any link — including for subcontractors — you may not own what you paid for.
- Where is the code stored and under whose account? A repository under the agency’s organisation is a dependency on that agency’s continued goodwill and solvency.
One elimination here, on the third question: the agency could not produce any written assignment for the subcontracted engineers who had delivered two of its three showcased projects.
Check 5: force disclosure of subcontracting
This check eliminates nobody and it is still essential. Subcontracting is normal and often sensible. Undisclosed subcontracting is the problem.
Establish three facts in writing: which work is delivered by employees versus subcontractors, in which jurisdictions the subcontractors sit, and whether the IP assignment chain from check 4 holds under the law of those jurisdictions rather than under UAE law alone.
In the Dubai market specifically, a locally registered entity may legitimately front delivery performed across several other countries. That is fine — provided you know it, priced it, and your assignment chain survives it.
Check 6: test the exit path before you need it
Ask a question that sounds impolite and is entirely reasonable: “If we part ways in eight months, what exactly do we receive, and how long does it take?”
A sufficient answer is written into the contract and covers four points: all repositories and accounts are in the client’s name, the code and its configuration are exportable, documentation adequate for a third party to take over is a contractual deliverable rather than a courtesy, and a notice period of at least 30 days includes a priced knowledge-transfer engagement.
The best signal of all is an agency that already has this clause drafted. It means someone has left before, and they built the process instead of pretending it will not happen.
Check 7: score against a risk-priced rubric
Convert everything above into a weighted score and, critically, into a contingency percentage you add to the quoted price.
My weights: named team verification 30 %, code review 25 %, delivery history 15 %, security and IP 15 %, subcontracting transparency 10 %, exit path 5 %. The exit path carries the lowest weight and is still non-negotiable — a missing exit provision caps the total score regardless of everything else.
The contingency percentage is what makes this usable in a procurement meeting. An agency scoring 65 is not disqualified; it is 20 to 25 % more expensive than it quoted, because that is what its risk profile costs in expectation. Two of my five surviving agencies won their engagements this way — they were not the cheapest quote, but they were the cheapest once risk was priced.
You are not choosing a company. You are choosing four or five specific people and a set of behaviours that appear only when something breaks. Every check that does not tell you about those two things is decoration. — William, HireDeveloper.ae
What the 5 survivors had in common
Three traits, and none of them were price, size or portfolio quality.
They produced named engineers within 48 hours and made them available for interview without renegotiating. They had a written reversibility clause already drafted before being asked. And when asked for a project that went badly, they named one specifically and explained what changed afterwards.
That third trait turned out to be the most predictive of the eventual working relationship, which surprised me. An agency that can describe its own failure precisely has a functioning internal review process — and that is the capability you will actually depend on.
If you are comparing sourcing models across the region before committing to an agency at all, HireDeveloper.sg covers the equivalent vetting standard in Singapore, and JapanDev documents how the same checks play out in Tokyo, where subcontracting chains are typically longer and disclosure norms differ.
For the build-side decisions that precede agency selection, our guides on building a fintech app in the UAE and building a CRM system in the UAE set out the scope definitions that make these seven checks meaningful.
Run check 1 this week
Before you discuss price with anyone on your shortlist, ask for the named engineers and request two interviews. It costs two hours and it is the check that eliminated five of nine.
Get started todayFAQ: technical due diligence on a development agency
How long should technical due diligence on an agency take?
Ten to twelve working days above roughly 200 000 AED, about half that below. The largest time cost is scheduling interviews with the named engineers — which is also the check producing the most information. Budget the calendar time explicitly, because compressing it always means dropping the code review, the second most predictive check.
Is it reasonable to ask an agency for real client code?
Yes, and the response is itself a signal. Acceptable answers: a consented client repository, an anonymised extract, or a comparable internal project. Concerning answers: nothing at all to show, or a client repository offered without evidence of permission — they will treat your code the same way.
What is the single most predictive check?
Interviewing the named engineers who will be assigned. It eliminated five of fourteen agencies on its own, every time for the same reason: senior profiles in the proposal, junior staff after signature. It is trivially detectable by asking to speak to the people on the CVs.
Should due diligence differ for a UAE agency versus an offshore one?
The checks are the same, but two carry more weight offshore. Subcontracting disclosure matters more because delivery chains are longer. And the IP assignment chain matters more because it must hold under the employment law of wherever the code is written, not where the contract is signed.
