Civil Law And Uae Multi-Factor Liability Attribution Frameworks
Civil Law and UAE Multi-Factor Liability Attribution Frameworks
1. Introduction
Multi-factor liability attribution means determining who should legally bear responsibility for a particular loss when several causes, persons, companies, technologies, contractual relationships, or events contribute to the same harm.
This issue is increasingly important in the UAE because modern transactions may involve:
platforms;
banks and payment processors;
software developers;
cloud providers;
data providers;
merchants;
logistics companies;
directors and employees;
insurers;
AI systems;
customers and users;
several interconnected corporate entities.
The legal question is therefore not simply:
“Who caused the damage?”
It is often:
“Which actor owed which duty, what did that actor do or fail to do, did that conduct contribute to the damage, and what portion of the legally recoverable loss can be attributed to that actor?”
The UAE's new Civil Transactions Law, Federal Decree-Law No. 25 of 2025, repealed the 1985 Civil Transactions Law and entered into force on 1 June 2026, so current mainland analysis should primarily refer to the new law. (UAE Legislation)
2. Meaning of Multi-Factor Liability Attribution
A traditional civil-liability analysis can be represented as:
Duty → Breach → Causation → Damage → Remedy
A multi-factor framework adds further questions:
Duty + Conduct + Fault + Causation + Contribution + Attribution + Damage + Defences + Risk Allocation → Liability
Thus:
Multi-Factor Liability Formula
Liability Attribution = Duty + Breach/Fault + Causal Contribution + Foreseeability + Damage + Legal Attribution − Defences
This does not necessarily mean that every person who contributed factually becomes legally liable.
There is an important distinction between:
Factual causation
Whether an actor's conduct contributed to the event.
Legal causation
Whether the law treats that contribution as sufficiently connected to the recoverable damage.
Attribution
Whether the damage should legally be assigned to that particular defendant.
3. Why Multi-Factor Attribution Is Important in UAE Civil Law
Modern commercial disputes frequently contain multiple potential causes.
For example:
A customer makes a payment through:
Customer → Platform → Payment Gateway → Bank → Merchant
A fraud occurs.
Possible questions include:
Did the customer act negligently?
Did the platform have an appropriate security system?
Did the payment gateway detect an abnormal transaction?
Did the bank have an independent contractual duty?
Was the fraud caused by an external hacker?
Was the loss foreseeable?
Did contractual exclusions allocate the risk?
Did the victim fail to mitigate the loss?
Therefore, liability attribution requires a factor-by-factor analysis, rather than simply identifying the last person in the chain.
4. Main Factors in the UAE Liability Attribution Framework
Factor 1 — Existence of a Legal Duty
The first question is:
Did the defendant owe a legally recognized duty?
The duty may arise from:
contract;
statute;
professional relationship;
ownership;
agency;
employment;
mandate;
tortious/harmful conduct;
consumer relationship;
regulatory obligations;
undertaking or representation.
A person normally cannot be held responsible merely because they were geographically or commercially connected with the transaction.
5. Factor 2 — Nature of the Defendant's Conduct
The court examines what the actor actually did.
Possible conduct includes:
positive action;
omission;
failure to warn;
failure to verify;
negligent supervision;
defective performance;
unauthorized transaction;
inaccurate information;
failure to maintain security;
breach of contractual obligation.
The analysis should identify the precise conduct, rather than using broad allegations such as “the company caused the loss.”
6. Factor 3 — Fault
Depending upon the applicable legal rule, the court may consider:
intention;
negligence;
lack of reasonable care;
recklessness;
bad faith;
breach of professional standards;
unauthorized conduct.
Fault is particularly important where several actors participated in the same transaction.
For example:
If a software provider supplied a system, but the user deliberately disabled its security controls, responsibility cannot automatically be placed entirely upon the software provider.
7. Factor 4 — Causation
Causation asks whether the defendant's conduct sufficiently contributed to the damage.
A useful analytical chain is:
Conduct → Event → Immediate consequence → Financial/physical harm
The claimant must generally connect the defendant's conduct to the claimed loss.
Example
A cloud provider experiences a temporary outage.
A merchant loses AED 100,000.
The claimant still has to establish:
Outage → inability to process transactions → lost transactions → legally recoverable loss
The mere existence of an outage does not automatically establish the entire claimed amount.
8. Factor 5 — Concurrent Causes
Several causes may operate simultaneously.
For example:
defective software;
employee negligence;
cyberattack;
inadequate authentication;
customer negligence.
The court may therefore ask:
Would the loss have occurred without the particular defendant's conduct?
and:
Was the defendant's conduct sufficiently connected with the ultimate damage to justify legal attribution?
This is particularly important in digital-economy disputes.
9. Factor 6 — Foreseeability and Remoteness
Even where factual causation exists, the law may distinguish between:
foreseeable consequences; and
unusually remote consequences.
For example:
A supplier delivers equipment late.
The immediate loss may be production delay.
But the claimant may additionally allege that the delay caused:
loss of a major international contract;
reputational damage;
future investment losses.
Each category may require separate proof of causation, foreseeability and recoverability.
10. Factor 7 — Contribution of the Claimant
Multi-factor attribution also examines the claimant's own conduct.
Possible factors include:
failure to follow security procedures;
failure to mitigate;
unauthorized use;
failure to disclose relevant information;
contributory conduct;
unreasonable continuation of a known risk.
Therefore:
Defendant's conduct + Claimant's conduct → Allocation of legal responsibility
This prevents the liability analysis from becoming one-sided.
11. Factor 8 — Contractual Allocation of Risk
Commercial parties frequently allocate risks through:
indemnities;
warranties;
representations;
limitation clauses;
exclusion clauses;
insurance;
guarantees;
escrow;
force-majeure provisions;
service-level agreements;
cybersecurity provisions.
The court must therefore distinguish:
Who factually contributed to the event
from
Who contractually assumed the relevant risk.
A contractual allocation may significantly affect the final liability analysis, subject to mandatory rules and public policy.
12. Factor 9 — Intervening Events
An intervening event can complicate attribution.
Examples include:
hacking;
natural disaster;
government action;
independent third-party fraud;
subsequent contractual breach;
deliberate misconduct by another actor.
The key question is whether the intervening event:
merely contributed to the original risk; or
became sufficiently independent to affect legal attribution.
13. Factor 10 — Damage
The claimant must establish the legally recoverable damage.
Damage may include:
Material damage
property loss;
financial loss;
repair expenses;
business losses;
additional costs.
Moral/non-economic damage
Where recognized under applicable UAE law:
injury to reputation;
dignity;
personal interests;
emotional or other legally protected non-economic interests.
Digital damage
Modern disputes can additionally involve:
data loss;
unauthorized disclosure;
account compromise;
interruption of digital services;
loss arising from fraudulent electronic transactions.
14. Factor 11 — Evidence
Multi-factor liability requires strong evidence because several actors may give different explanations for the same event.
Relevant evidence may include:
contracts;
emails;
WhatsApp communications;
system logs;
transaction records;
metadata;
audit trails;
cybersecurity reports;
expert reports;
bank records;
access logs;
blockchain records;
server records;
digital signatures.
The 2026 Jonathan Lau v Qashio Holding Company Limited & Armin Moradi Tosarvandani [2026] DIFC CFI 058 proceedings illustrate the importance of targeted production of corporate, banking, SAFE and accounting documents, including native electronic documents with associated metadata. (DIFC Courts)
This is particularly relevant to multi-factor attribution because attribution often depends upon reconstructing who performed which act and when.
15. Factor 12 — Expert Evidence
Technical disputes frequently require experts.
Experts may address:
software architecture;
cybersecurity;
accounting;
banking transactions;
construction defects;
engineering;
medical causation;
valuation;
digital forensics.
The expert does not normally decide the ultimate legal question.
Instead:
Expert evidence → establishes technical facts → Court applies legal attribution rules.
16. Multi-Actor Digital Economy Example
Suppose a fraudulent AED 500,000 transaction occurs through a digital platform.
There are five actors:
| Actor | Possible contribution |
|---|---|
| Customer | weak password / negligent conduct |
| Platform | inadequate authentication |
| Software provider | coding vulnerability |
| Payment gateway | failure to detect abnormal transaction |
| Bank | transaction processing |
The court could examine each separately.
Attribution matrix
| Factor | Customer | Platform | Developer | Gateway | Bank |
|---|---|---|---|---|---|
| Duty | Yes/No | Yes | Yes/No | Yes | Yes |
| Breach | Possible | Possible | Possible | Possible | Possible |
| Causation | Possible | Possible | Possible | Possible | Possible |
| Foreseeability | Relevant | Relevant | Relevant | Relevant | Relevant |
| Damage | Indirect | Direct/indirect | Indirect | Direct/indirect | Direct/indirect |
| Contractual allocation | Yes | Yes | Yes | Yes | Yes |
| Evidence | Logs/account | System logs | Code/audit | transaction logs | banking records |
The result cannot safely be determined merely by counting how many actors were involved.
17. Multi-Factor Attribution in AI Systems
AI creates an especially complicated attribution problem.
Consider:
Data Provider → Model Developer → AI Platform → Integrator → Human User → Customer
An AI-generated decision causes economic loss.
Potential questions include:
Was the training data defective?
Was the model improperly designed?
Was the model deployed outside its intended purpose?
Did the integrator configure it incorrectly?
Did the human decision-maker blindly rely on the output?
Was the output reasonably foreseeable?
Was there human review?
Did the claimant independently contribute to the damage?
Therefore:
AI Attribution Formula
AI Liability = Data Responsibility + Model Responsibility + Deployment Responsibility + Human Oversight + Causation + Damage
Importantly, the existence of an AI system does not itself create automatic liability for every participant.
18. Platform Liability
Digital platforms often occupy an intermediate position.
They may:
provide infrastructure;
connect buyers and sellers;
process data;
facilitate payments;
rank information;
authenticate users;
host content;
provide recommendation systems.
The legal analysis should distinguish between:
Platform's own conduct
and
Conduct of independent users.
A platform may have contractual, statutory or other legal duties depending upon the specific relationship and applicable regulatory framework.
19. Corporate Group Attribution
Another important issue is the difference between:
Company A
and
Parent Company B
and
Subsidiary Company C.
A corporate group does not automatically mean that every company is liable for every act of another company.
The court should examine:
separate legal personality;
contractual obligations;
agency;
guarantees;
actual control;
representations;
statutory responsibility;
misuse of corporate structure where legally established.
Thus:
Corporate connection ≠ automatic liability.
20. Important UAE/DIFC Authorities
Because the precise doctrine of “multi-factor liability attribution framework” is not a single codified UAE cause of action, the following authorities are best used as illustrative or analogous authorities, rather than claiming that they establish one unified doctrine.
Case 1 — NMC Healthcare Ltd (in Administration) v Dubai Islamic Bank PJSC [2023] ADGM CFI 042
This dispute involved complex financial and contractual relationships.
Its relevance to a multi-factor framework lies in the need to identify:
the contractual relationship;
applicable UAE-law principles;
the parties' respective obligations;
evidence;
the legal consequences of the relevant conduct.
Principle for study: liability should be analysed by reference to the actual legal relationship and obligations of each participant.
Case 2 — DNB Bank ASA v Gulf Eyadah Corporation & Gulf Navigation Holding PJSC
The DNB litigation is principally associated with cross-border judgment recognition and enforcement, rather than a standalone multi-factor tort doctrine.
Its importance here is analogical: complex commercial disputes can involve several jurisdictions, contractual relationships and enforcement mechanisms, making identification of the relevant legal obligation and forum essential.
The DIFC Courts have treated DNB as an important authority in the development of cross-border enforcement jurisprudence. (DIFC Courts)
Case 3 — Credit Suisse (Switzerland) Limited v Ashok Kumar Goel & Others [2020] DIFC CFI 066
This case involved guarantees and complex financing arrangements involving UAE-connected corporate structures.
The DIFC Court analysed the relevant contractual provisions and, importantly, considered UAE-law principles concerning contractual construction. The judgment records the principle that contractual interpretation focuses on intention and meaning rather than merely formal wording. (DIFC Courts)
Relevance
In a multi-factor liability dispute, the court must first identify:
What obligation did each participant actually undertake?
Only then can breach and attribution be analysed.
Case 4 — ICICI Bank Ltd v Bavaguthu Raghuram Shetty [2022] DIFC CFI 034
This case is relevant to electronic contracting, attribution and digital evidence.
Relevance to multi-factor attribution
Where a digital transaction involves:
electronic communications;
electronic signatures;
authentication;
contractual authority;
banking transactions,
the court may need to determine which actor's electronic conduct can legally be attributed to that actor.
Thus:
Digital act → attribution → legal obligation → liability
rather than simply:
Digital act → liability.
Case 5 — GFH Capital Ltd v David Lawrence Haigh [2014] DIFC CFI 020
This authority is useful for examining electronic communications and contractual authority.
Relevance
Where multiple individuals act for a company, attribution requires examination of:
authority;
capacity;
communications;
corporate relationship;
contractual context.
The case therefore provides an analogy for separating individual conduct from corporate responsibility.
Case 6 — Jonathan Lau v Qashio Holding Company Limited & Armin Moradi Tosarvandani [2026] DIFC CFI 058
This is particularly useful for modern digital-commercial disputes.
The Court ordered production of specified corporate, banking, SAFE and accounting materials and required native electronic documents to be produced with associated metadata where specifically requested. (DIFC Courts)
Relevance
Multi-factor attribution often depends upon proving:
Actor → transaction → timing → authority → consequence.
Digital metadata and native records can help reconstruct this chain.
Case 7 — Standard Chartered Bank v Investment Group Private Limited [2014] DIFC CFI 026
This financing authority is useful for understanding obligations arising from sophisticated lending arrangements.
Relevance
Where several contractual actors participate in financing, liability depends upon:
the precise undertaking;
contractual interpretation;
default;
guarantees/security;
evidence;
resulting loss.
It illustrates why liability should be attributed according to the legal relationship of each participant, rather than simply their commercial association.
Case 8 — IDBI Bank Limited v Amira C Foods International DMCC & Karan A. Chanana [2020] DIFC CFI 022
This is another useful financing authority involving multiple parties.
Relevance
It illustrates the importance of separating:
principal borrower;
guarantor;
corporate entity;
individual;
contractual undertaking.
The broader lesson for multi-factor attribution is:
Different legal roles produce different potential sources of liability.
21. Relationship Between Contract and Tortious/Civil Responsibility
A single event may produce both:
Contractual responsibility
For example:
failure to perform a service agreement.
and:
Non-contractual/civil responsibility
For example:
damage caused independently by wrongful conduct.
The court should identify the legal basis of each claim separately.
Framework
Contract → contractual duty → breach → contractual remedy
Harmful act → wrongful conduct → causation → damage → compensation
The two analyses may overlap but should not automatically be merged.
22. Contribution Between Multiple Responsible Parties
Where several persons are legally responsible for the same loss, another question arises:
How should responsibility between them ultimately be allocated?
This may involve:
contribution;
indemnity;
contractual allocation;
insurance;
guarantees;
settlement arrangements.
For example:
Platform pays claimant → platform seeks contribution from responsible service provider.
This creates two separate relationships:
Claimant vs platform
Platform vs service provider
The court should analyse them separately.
23. Proportionality in Attribution
A useful conceptual model is:
Attribution Weight
Attribution Weight = Duty × Breach × Causal Contribution × Foreseeability × Damage Connection
This is not a statutory UAE mathematical formula.
It is an analytical tool for legal reasoning.
It helps prevent the simplistic assumption:
“The actor who appears closest to the loss is automatically responsible for everything.”
24. Defences and Limiting Factors
A multi-factor framework must also consider:
force majeure;
claimant's own conduct;
intervening third-party conduct;
contractual exclusions;
limitation clauses;
limitation periods;
lack of causation;
remoteness;
mitigation;
absence of duty;
lack of authority;
illegality/public policy where relevant.
The defendant should therefore be analysed through the same structured framework as the claimant.
25. Evidence Architecture
A strong multi-factor case can be organized as:
Stage 1 — Identity
Who are the actors?
Stage 2 — Relationship
What legal relationship existed?
Stage 3 — Duty
What did each actor owe?
Stage 4 — Conduct
What did each actor actually do?
Stage 5 — Breach
Was the duty violated?
Stage 6 — Causation
Did the conduct contribute to the damage?
Stage 7 — Attribution
Should the law assign that damage to the actor?
Stage 8 — Quantum
What amount of damage is legally recoverable?
Stage 9 — Defences
Is liability reduced or excluded?
Stage 10 — Remedy
What relief is appropriate?
26. Digital-Economy Attribution Chain
For digital disputes, the following model is particularly useful:
Design
↓
Data
↓
Development
↓
Deployment
↓
Operation
↓
Decision
↓
Harm
↓
Evidence
↓
Legal Attribution
↓
Remedy
This approach prevents the court from treating a complex technological system as if it had only one responsible participant.
27. Difference Between Causation and Attribution
This distinction is extremely important for examination purposes.
| Causation | Attribution |
|---|---|
| Did the conduct contribute to the event? | Should the law assign responsibility to that actor? |
| Mainly causal question | Legal/normative question |
| Looks at connection | Looks at legal responsibility |
| May involve several causes | Determines relevant responsibility |
| Precedes final liability determination | Helps establish final liability |
Example
A software defect contributes to a fraudulent transaction.
That establishes a possible causal connection.
But attribution additionally requires asking:
Was the software provider responsible for that function?
Was the defect foreseeable?
Was the software used as intended?
Did another actor alter the system?
Did the user ignore security warnings?
Thus:
Causation ≠ automatic liability.
28. Multi-Factor Attribution and Good Faith
Good faith is particularly important in continuing commercial relationships.
Courts may need to examine:
cooperation;
disclosure;
contractual performance;
exercise of contractual rights;
prevention of opportunistic conduct;
compliance with agreed procedures.
Good faith does not mean that every commercially unfair result automatically creates liability.
It operates within the applicable legal and contractual framework.
29. Practical UAE Example
Suppose a UAE fintech platform suffers a cyber incident.
Actors:
fintech company;
cloud provider;
software developer;
cybersecurity vendor;
payment processor;
bank;
customer.
A customer loses AED 200,000.
Step 1
Identify each actor's contractual/legal role.
Step 2
Determine each actor's security obligations.
Step 3
Establish what actually happened.
Step 4
Examine system logs and metadata.
Step 5
Determine the technical cause.
Step 6
Determine whether each actor breached a relevant duty.
Step 7
Separate direct and consequential losses.
Step 8
Consider customer conduct.
Step 9
Consider contractual risk allocation.
Step 10
Determine legally attributable damage.
This produces a much stronger analysis than simply alleging:
“The fintech company is responsible because the loss occurred on its platform.”
30. Short Exam Table
| Factor | Core question |
|---|---|
| Duty | Did the defendant owe a duty? |
| Relationship | What legal relationship existed? |
| Conduct | What did the defendant do? |
| Fault | Was the conduct wrongful/negligent? |
| Breach | Was a legal or contractual duty violated? |
| Causation | Did the conduct contribute to the loss? |
| Foreseeability | Was the consequence sufficiently foreseeable? |
| Attribution | Should the loss legally be assigned to defendant? |
| Claimant conduct | Did claimant contribute? |
| Contract | Who assumed the relevant risk? |
| Evidence | Can the causal chain be proved? |
| Damage | What legally recoverable loss occurred? |
| Defences | Is liability excluded/reduced? |
| Remedy | What compensation or other relief follows? |
31. Key Case-Law Revision List
NMC Healthcare Ltd (in Administration) v Dubai Islamic Bank PJSC [2023] ADGM CFI 042 — complex contractual/financial relationships; UAE-law analysis.
DNB Bank ASA v Gulf Eyadah Corporation & Gulf Navigation Holding PJSC — cross-border commercial relationships and enforcement.
Credit Suisse (Switzerland) Ltd v Ashok Kumar Goel & Others [2020] DIFC CFI 066 — contractual interpretation and UAE-law principles. (DIFC Courts)
ICICI Bank Ltd v Bavaguthu Raghuram Shetty [2022] DIFC CFI 034 — electronic transactions and attribution.
GFH Capital Ltd v David Lawrence Haigh [2014] DIFC CFI 020 — authority and electronic communications.
Jonathan Lau v Qashio Holding Company Ltd & Armin Moradi Tosarvandani [2026] DIFC CFI 058 — document production, native electronic documents and metadata in complex corporate disputes. (DIFC Courts)
Standard Chartered Bank v Investment Group Private Limited [2014] DIFC CFI 026 — financing obligations and contractual responsibility.
IDBI Bank Ltd v Amira C Foods International DMCC & Karan A. Chanana [2020] DIFC CFI 022 — multi-party financial obligations.
Important: The DIFC and ADGM authorities above should be treated as persuasive/illustrative within this topic, not automatically as binding mainland-UAE precedents. UAE mainland civil law is principally governed by federal legislation and the jurisprudence of the competent UAE courts.
32. Critical Legal Principle
The central principle can be summarized as:
A person should not be treated as legally responsible merely because that person's conduct forms part of a factual chain. The court must identify the applicable duty, breach or wrongful conduct, causal connection, legally attributable damage, contractual allocation of risk, claimant contribution, and applicable defences.
Thus:
Multi-Factor Liability Attribution
Legal Relationship
↓
Duty
↓
Conduct/Breach
↓
Fault
↓
Causation
↓
Foreseeability/Remoteness
↓
Attribution
↓
Damage
↓
Defences/Contribution
↓
Remedy
33. Conclusion
Multi-factor liability attribution frameworks are particularly useful for UAE civil-law disputes involving digital platforms, fintech, AI, banking, cybersecurity, corporate groups, construction projects, supply chains and complex commercial contracts.
The principal lesson is that liability is not determined merely by identifying the last actor in the causal chain. A court should examine the separate legal position and contribution of each participant.
The most useful examination formula is:
Multi-Factor Liability = Duty + Conduct/Breach + Fault + Causation + Foreseeability + Attribution + Damage − Defences/Claimant Contribution
For digital disputes, an even more useful formula is:
Actor → Role → Duty → Action/Omission → Evidence → Causal Contribution → Legal Attribution → Damage → Remedy
This framework allows UAE civil-law analysis to deal systematically with situations where many people and technologies contribute to one legally significant harm, without automatically treating every participant as jointly responsible.

comments