Introduction

In 2026, Astana Hub participants, for the first time on a large scale, were required to demonstrate compliance with Clause 33 of the Rules of the Autonomous Cluster Fund «Astana Hub». For many companies, this represented an entirely new regulatory requirement, while for auditors it provided an opportunity to establish the first practical experience in applying these new requirements.

During the year, the Moore Kazakhstan team performed a number of Agreed-Upon Procedures engagements for Astana Hub participants operating across various sectors of the IT industry, including IT platforms, SaaS solutions, financial monitoring systems, digital services, corporate information systems and bespoke software development projects. Although these companies operated under different business models, many of the practical issues encountered were remarkably similar.

One of our first observations was that the majority of customer contracts had originally been drafted to regulate commercial relationships between the parties rather than to demonstrate compliance with Astana Hub requirements. As a result, contract subject matters frequently contained broad descriptions such as “provision of services,” “information services,” “educational services,” “technical support,” or “maintenance services.” In reality, however, the companies were granting access to proprietary software products, enhancing software functionality, modifying software, or licensing their own software solutions. While such distinctions may appear insignificant from a commercial perspective, the underlying contract becomes one of the key documents enabling users of the report to understand how the relevant income was generated and whether it is connected with the participant’s declared priority ICT activities.

Another notable observation was the diversity of business models employed by Astana Hub participants. Throughout our engagements, we encountered companies that:

  • license proprietary software products;
  • provide software under a Software-as-a-Service (SaaS) model;
  • develop bespoke software solutions based on customers’ technical specifications;
  • maintain and continuously enhance existing software products; and
  • simultaneously combine several of these business models.

In many cases, a single company may own proprietary software, develop customised software solutions for clients, and at the same time provide implementation, integration and technical support services for previously developed products. Such flexibility is a natural feature of today’s IT industry; however, it also requires more comprehensive disclosure when preparing documentation for Astana Hub compliance purposes.

Our practical experience also demonstrated that contracts with seemingly similar subject matters may have fundamentally different legal characteristics. In some cases, companies generate income from exploiting their own intellectual property. In others, revenue arises from software development or software modification services. Quite often, a single contract combines software licensing, implementation, user training, technical support, ongoing maintenance and the development of new functionality. Accordingly, analysing such contracts cannot be limited to their title or contractual subject alone. A proper assessment requires consideration of the contractual terms as a whole, the actual scope of work performed, the existence of intellectual property rights and the company’s underlying business model.

Another important feature of the first year was that the contracts themselves did not always contain all the information necessary for users of the report. In many cases, companies prepared supplementary explanations describing the software products involved, ownership of intellectual property rights, software development arrangements, the rationale for classifying particular contracts and the manner in which revenue was generated. Our experience has shown that these additional explanations significantly improve the transparency of the report and enable its users to better understand the nature of the participant’s business activities.

In our view, the first year of applying Clause 33 demonstrated that users derive value not only from the agreed-upon procedures performed, but also from consistent and transparent disclosure of supporting information. Structured appendices to the report (including contract registers, electronic VAT invoice registers, ICT revenue calculations and management explanations) greatly enhance transparency and allow users to clearly trace the relationship between contracts, business activities and revenue streams. For this reason, throughout our engagements we placed particular emphasis on preparing comprehensive appendices that enable report users to independently understand the rationale behind contract classification and revenue allocation without reviewing extensive volumes of primary documentation.

The first year of practical implementation has confirmed that the concept of verifying compliance with Astana Hub requirements is both timely and necessary. At the same time, our experience suggests that further development of a consistent reporting methodology would benefit both participants and the regulator. In our opinion, future discussions between the professional community and Astana Hub could focus on the following matters:

  • developing a recommended structure for Agreed-Upon Procedures reports;
  • establishing minimum disclosure requirements and standard appendices;
  • introducing consistent approaches to the classification of hybrid contracts combining software licensing and service components;
  • providing guidance on the disclosure of intellectual property and ownership rights; and
  • developing practical recommendations on documenting the connection between revenue streams and priority ICT activities.

The development of a consistent reporting framework would improve comparability between engagements, enhance transparency for both Astana Hub participants and the regulator, and reduce the number of follow-up questions arising during the review of submitted reports.

If you require an Astana Hub compliance review, please contact our team


To enable us to process your enquiry, please fill out the form as fully as possible and upload completed questionnaire, and we will contact you.

Download the questionnaire:

Preliminary Agreed-Upon Procedures Engagement Planning Questionnaire

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Country selector*
Revenue in USD
Do you have operations in more than one continent?*
Max. file size: 10 MB.