CodeX71 brand markCodeX71CodeX71Better business. Built together.
العربيةWorkshop

The 5-Year
Audit Warranty.

For projects with an agreed warranty schedule, we correct defects in CodeX71-delivered controls that cause a NESA, ADHICS or DESC ISR audit finding, at no charge for five years, subject to the agreed scope and terms.

A defined engineering commitment, backed by a control register, acceptance evidence and an agreed warranty schedule.

CODEX71 / YEARSDefined controls. Agreed terms.

Applies to controls and framework versions listed in the signed warranty schedule. Coverage, exclusions, acceptance date and claim handling are agreed before delivery. Existing signed commitments remain governed by their terms.

What the warranty covers

01

Named controls and requirements

The signed schedule identifies the control, system, framework version, acceptance test and delivery owner. Only those controls are covered.

02

A recorded five-year period

Coverage starts on the written acceptance date recorded for the covered controls and ends five years later. Phased deliveries record their own dates.

03

Corrective engineering and evidence

Covered remediation includes correcting the delivered defect, retesting the affected control and updating its evidence, without an additional remediation fee.

04

Direct and partner-led projects

The schedule identifies the contracting parties, claim contact and CodeX71 responsibility. A partner may represent this commitment only for the agreed scope.

The auditor decides the overall audit outcome. That assessment can also include your organisation’s policies, people, processes and systems beyond the controls CodeX71 delivers.

Coverage, conditions and exclusions

Agree this schedule before delivery. These boundaries apply to new agreements that adopt them; they do not amend an existing signed contract.

Systems and responsibilities outside scope

Organisation-wide policies, staff behaviour, customer-operated processes and systems not listed in the control register.

Changes that cause the finding

Customer or third-party changes, disabled controls or unsupported dependencies where they cause the failure. A change does not remove cover for an unrelated CodeX71-delivered defect.

Requirements beyond the agreed baseline

New or revised regulatory requirements, additional controls and expanded environments require a separate impact assessment and scope.

Costs beyond corrective engineering

External audit or certification fees, penalties, third-party licences and new functionality are outside the free corrective-work commitment.

What the signed schedule must record

An ongoing managed-service contract is separate. Its service levels and fees must be agreed explicitly; the warranty itself does not promise 24/7 operations or incident recovery.

Evidence for the controls we deliver

  1. 01

    Agree the controls

    Map the relevant requirements to the application, AI or cloud work in scope.

  2. 02

    Build and test them

    Include access controls, secure configuration and other agreed safeguards in the delivery plan.

  3. 03

    Hand over the evidence

    Record the implemented controls, test results, owners and warranty dates with the project handover.

Relevant to your organisation.

We identify the applicable framework and version with your team. The project scope connects its requirements to the controls we deliver.

01

NESA / UAE Information Assurance

Information assurance requirements relevant to your organisation and the systems in the agreed scope.

Official reference
02

ADHICS

Abu Dhabi Healthcare Information and Cyber Security Standard. The Department of Health’s AAMEN programme publishes ADHICS V2.

Official reference
03

DESC ISR

Dubai’s Information Security Regulation for Dubai Government Entities and those handling their information, as applicable.

Official reference

These links explain the frameworks. CodeX71’s warranty is its own commercial commitment; it does not imply endorsement by a regulator.

How to raise a warranty claim

  1. 01

    Register the finding

    Provide the written audit finding, control ID, project reference and available evidence during the coverage period through the named claim contact.

  2. 02

    Confirm cause and agree timing

    Map the finding to the accepted baseline, review any changes and agree safe access, severity, corrective scope and timing. Disputed coverage follows the contract escalation process.

  3. 03

    Correct, retest and document

    For covered defects, complete corrective work and provide updated test evidence. The audit body decides whether the finding is closed.

What you need to know.

What makes a project eligible?

A signed warranty schedule covering identified controls, agreed framework versions, acceptance evidence and five-year dates. Eligibility and delivery responsibilities are agreed before the project starts.

What is excluded?

Out-of-scope systems and organisational controls; findings caused by third-party or customer changes; new requirements beyond the agreed baseline; and audit fees, penalties, licences or new features. Exclusions must be recorded in the signed schedule and do not excuse defects in our own covered delivery.

Is this a full audit-pass or ongoing support guarantee?

It covers corrective work on defined delivered-control defects. The auditor determines overall compliance. Operational support, incident response and service levels require their own agreed scope.

How are claims and contractual terms handled?

The warranty schedule records notice, evidence, access, severity, response and remediation targets, escalation, responsibilities and exclusions. The signed agreement governs liability and dispute terms; no universal liability cap or fixed response SLA is promised on this site.

Discuss your application
or AI use case.

Start with a free workshop. Customers and partners can define the problem, the intended outcome and a practical next step.

Book a free workshop