PHII Labs
2026-10-13Real Estate AI11 min read

Ejari, SPA and NOC documents with AI: Dubai pipelines

A document pipeline for Dubai brokerages: reading Ejari, SPA, NOC and title deeds, extracting fields, and flagging risks before they reach an agent

Sergei Suvorin · Co-founder, PHII Labs

AI document pipeline reading Ejari, SPA and NOC files for Dubai brokerages

A Dubai brokerage can automate Ejari certificates, SPAs, developer NOCs and DLD title deeds with one pipeline: intake from email or WhatsApp, OCR, field extraction, validation against your CRM, and an exception queue where a named person approves anything uncertain. The AI reads and checks. A human signs off before anything is filed, sent or written to a deal record

Most AI automation pitches in Dubai stop at lead response. A brokerage loses more hours on paperwork: a tenant's Ejari expires next month and nobody noticed, an SPA lists a unit number that does not match the developer's inventory, a resale stalls because the NOC request went out without the service-charge clearance. Below is the pipeline spec we use, with the field map, the checks and the places where we deliberately keep a person in charge

Can AI read Ejari and title deeds reliably?

Yes for printed, system-generated documents; less so for scans, stamps and handwriting. An Ejari certificate or a DLD title deed comes out of a government system with a fixed layout, so OCR plus a language model extracts parties, unit, dates and amounts with high consistency. Photographed SPAs with handwritten amendments are where confidence drops and a human has to look

Document types behave very differently, and the pipeline should treat them differently:

  • Ejari certificates and DLD title deeds are templated. Layout barely changes, so extraction is mostly a parsing problem
  • SPAs are long, developer-specific contracts. Emaar's SPA does not look like a smaller developer's SPA, and the clauses you care about (payment plan, handover date, delay penalties, assignment rights) sit in different places
  • NOCs vary by developer and by purpose. A transfer NOC, a fit-out NOC and a mortgage NOC carry different fields, and some developers still issue them as scanned letters on letterhead
  • Supporting KYC documents (Emirates ID, passport, visa page) arrive as phone photos with glare and cropped edges

We have built this kind of reading before. On our inventory CRM for a Dubai real estate team, around 8,000 units were tracked in Excel and developer PDFs. An AI assistant now reads incoming updates and proposes status changes, and a person approves each one. Status accuracy went from about 60% to about 98%, and finding a free unit dropped from roughly two hours a day to about ten seconds. The same proposal-then-approve pattern carries straight over to Ejari, SPA and NOC files. On a separate UAE visa platform we run passport scans through PaddleOCR and a Gemini model, which is the same OCR-plus-extraction stack the KYC step here uses

On the 8,000-unit inventory build, status accuracy went from about 60% to about 98% once a person approved every proposed change before it saved.
Sergei Suvorin · Co-founder, PHII Labs

What does the pipeline look like?

The pipeline has six stages, and each one has an owner and a defined output. Documents enter once and get read once. Every extracted field carries a confidence score and a link back to the page it came from

  1. Intake. Files arrive from a shared inbox, a WhatsApp number on the official Business Platform, a portal upload or a drag-and-drop in the CRM. The pipeline hashes each file, detects duplicates and attaches it to a deal or contact if a reference already exists
  2. Classification. A small model labels the document type (Ejari, SPA, Oqood, NOC, title deed, Form F, Emirates ID, passport) and the language. Arabic-only pages get routed to an Arabic-capable OCR path
  3. OCR and layout. Text plus coordinates, so every value can be highlighted on the original page during review. Stamps and signatures are detected as regions; we flag their presence and never try to "read" them
  4. Extraction. A language model fills a typed schema per document type. Fields it cannot find stay null. We never let the model guess a missing value
  5. Validation. Deterministic rules run against the extracted record and against your CRM: dates in order, amounts consistent, unit exists, party names match the KYC record. Validation is plain code, written and tested like any other code
  6. Exception queue and write-back. Records that pass every rule above the confidence threshold write to the CRM as a draft. Everything else lands in a review queue with the reason attached. Nothing goes to DLD, a developer or a client without a human click

Diagram: document intake through classification, extraction and validation into a CRM

The field map

This table is the core of the spec. It is what we agree with a brokerage before writing code, because it decides what the system checks and what it escalates

DocumentFields extractedValidation checksFlagged to a human
Ejari certificateEjari number, landlord, tenant, unit and building, plot number, DEWA premise number, contract start and end, annual rent (AED), security depositEnd date after start date; rent matches the signed tenancy contract; unit exists in CRM inventory; tenant name matches Emirates IDExpiry within 60 days; rent mismatch against the contract; landlord name differs from title deed owner
SPADeveloper, buyer(s), unit, project, total price (AED), payment plan instalments, anticipated completion date, delay and termination clauses, assignment clauseInstalments sum to total price; unit and price match developer inventory; buyer names match KYCAny instalment total mismatch; assignment restricted before a percentage paid; handwritten amendments; missing signature page
Developer NOCNOC type (transfer, mortgage, fit-out), developer, unit, issue date, validity, conditions, service-charge statusUnit matches the deal; NOC still valid on the planned transfer date; type matches the transactionNOC expired or expiring before the DLD appointment; conditions text present; outstanding dues mentioned
DLD title deedDeed number, issue date, owner(s) and shares, property type, community, plot, building, unit, area (sq m), mortgage statusOwners match seller KYC; area matches listing; unit matches Form FMortgage registered; co-owner not party to the deal; area differs from the listing by more than 2%
Emirates ID / passportFull name (English and Arabic), ID number, nationality, date of birth, expiryExpiry after the transaction date; name consistent across documentsExpired ID; name transliteration mismatch between Emirates ID and SPA

The thresholds (60 days, 2%) are examples. Each brokerage sets its own during the audit, and we store them as configuration so an operations manager can change them without a deploy

A redacted Ejari record

Here is the shape of one extracted Ejari record, values redacted. Every field carries its value, a confidence score and the page region it came from, so a reviewer can click straight to the source

{
  "doc_type": "ejari_certificate",
  "source_file": "sha256:[REDACTED]",
  "extracted_at": "2026-09-14T08:42:11+04:00",
  "fields": {
    "ejari_number": { "value": "XXXXXXXXXXXXX", "confidence": 0.99, "page": 1, "bbox": [412, 118, 640, 140] },
    "landlord_name": { "value": "[REDACTED]", "confidence": 0.97, "page": 1 },
    "tenant_name": { "value": "[REDACTED]", "confidence": 0.96, "page": 1 },
    "tenant_emirates_id": { "value": "784-XXXX-XXXXXXX-X", "confidence": 0.98, "page": 1 },
    "building": { "value": "[REDACTED] Tower", "confidence": 0.95, "page": 1 },
    "unit": { "value": "1204", "confidence": 0.99, "page": 1 },
    "plot_number": { "value": "XXX-XXXX", "confidence": 0.93, "page": 1 },
    "dewa_premise_number": { "value": "XXXXXXXXX", "confidence": 0.91, "page": 1 },
    "contract_start": { "value": "2026-01-01", "confidence": 0.99, "page": 1 },
    "contract_end": { "value": "2026-12-31", "confidence": 0.99, "page": 1 },
    "annual_rent_aed": { "value": 95000, "confidence": 0.98, "page": 1 },
    "security_deposit_aed": { "value": null, "confidence": 0.0, "page": null }
  },
  "validation": [
    { "rule": "end_after_start", "status": "pass" },
    { "rule": "unit_in_inventory", "status": "pass", "crm_ref": "unit_8812" },
    { "rule": "tenant_matches_kyc", "status": "pass" },
    { "rule": "rent_matches_contract", "status": "fail", "detail": "contract shows 92,000 AED" },
    { "rule": "expiry_window_days", "status": "warn", "detail": "expires in 108 days" }
  ],
  "route": "review_queue",
  "route_reason": ["rule_fail:rent_matches_contract", "null_field:security_deposit_aed"]
}

Two details in this record matter. The security deposit is null with zero confidence because the model did not find it; a guessed value would be worse than a blank. The record also goes to review because one deterministic rule failed, even though every extracted field scored above 0.9. Model confidence and business validity are separate signals, and the pipeline routes on both

Where does a human stay in the loop?

At every external action and at every low-confidence or failed-validation record. The AI drafts and checks; a named reviewer approves before anything is filed with DLD, sent to a developer, shared with a client or written as final to the CRM

In practice that means four approval points:

  • Extraction review: any field under the confidence threshold, any null on a required field, any handwritten or amended page
  • Validation failures: a rent mismatch, an expired NOC, a co-owner missing from the deal, an Emirates ID that expires before transfer
  • External actions: requesting a developer NOC, booking a DLD trustee appointment, sending documents to a buyer's mortgage bank
  • Legal judgment: whether an SPA clause is acceptable is a lawyer's or a senior agent's call. The pipeline highlights the delay-penalty and assignment clauses and quotes them; it does not interpret them

The review screen shows the original page with the field highlighted, the extracted value, the rule that failed and the CRM record it would update. A reviewer fixes the value or approves it, and the correction is logged so we can see which document types and which developers cause the most rework. That log is what tells you, after a month, where the pipeline needs better extraction and where it needs a different rule

We do not automate RERA submissions or the DLD transfer itself. Those run through government systems and trustee offices with their own identity checks, and the cost of a wrong filing is far higher than the minutes saved. The pipeline prepares a complete, validated packet; your team submits it

What about Emirates ID data and PDPL?

Emirates ID numbers, passport scans and tenancy details are personal data under the UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021. A compliant pipeline documents where files are stored, which subprocessors (OCR, model provider, hosting) see them, how long they are kept and how they are deleted.

Our default setup keeps original files and extracted records in one storage region chosen with the client, sends only the pages needed for extraction to the model provider, and deletes raw scans on a retention schedule while the validated record stays in the CRM. KYC images are the most sensitive part, so we keep them out of chat tools and email threads once they enter the pipeline. The full data-flow map and retention design is its own topic, covered in how to build a PDPL-compliant AI CRM in the UAE

How does this connect to leads and the CRM?

Documents are the second half of the deal. Leads from Property Finder, Bayut and Dubizzle start the record; Ejari, Form F, SPA, NOC and title deed files fill it in until the deal closes or the tenancy renews

When intake and qualification already run on WhatsApp (the flow in WhatsApp bots for Property Finder and Bayut leads), the same number can accept documents. A tenant sends a photo of their Emirates ID, the pipeline extracts it, attaches it to the contact and asks for the missing page if one is absent. Extracted fields write back to HubSpot, Salesforce, Zoho or Odoo through their APIs: renewal dates become tasks, SPA payment plans become scheduled reminders, NOC validity becomes a blocker on the transfer stage

The highest-value output we see in rentals is the renewal calendar. Once every active Ejari is extracted, the CRM knows every expiry date in the portfolio, and agents get a list 60 or 90 days out instead of finding out from an angry landlord

What does this cost a Dubai brokerage?

A pipeline for one document type, such as Ejari intake with renewal tracking, starts in the low five figures AED. A multi-document pipeline covering Ejari, SPA, NOC, title deed and KYC, with validation rules and CRM write-back, is mid five figures AED and up. Expect 6 to 10 weeks for the multi-document build

What moves the price:

FactorLower costHigher cost
Document typesOne (Ejari or title deed)Five or more, including SPAs from many developers
Source qualitySystem-generated PDFsPhone photos, scans, Arabic-only pages
ValidationFormat and date checksCross-checks against CRM inventory and KYC
CRMOne CRM with a clean APILegacy CRM or spreadsheets that need a data model first
VolumeHundreds of documents a monthThousands, with SLA on review turnaround

Running costs after launch are model and OCR usage, hosting, and a maintenance retainer for new developer templates and rule changes. Developers change their SPA and NOC formats every so often, and someone has to update the extraction schema when they do. For a broader view of AED budgets across WhatsApp, document and agent builds, see how much AI automation costs in Dubai

Start with the document that hurts most. For rental-heavy brokerages that is usually Ejari and renewals. For off-plan and resale teams it is the SPA-to-NOC-to-title-deed chain, where one expired NOC can push a DLD appointment by a week. More on how we scope these systems sits on our AI real estate systems page

The takeaway

Document automation for a Dubai brokerage is a field map plus validation rules plus an approval queue. The model reads Ejari certificates, SPAs, NOCs, title deeds and Emirates IDs; deterministic checks compare them against each other and against your CRM; a named person approves anything uncertain and every external action. Begin with one document type, measure the hours it saves for a month, then extend the same pipeline to the next one

If you want the field map drawn for your own document mix, book a free automation audit. In 30 minutes we map where your documents come from and what your team checks by hand, then send a written plan with a fixed price

FAQ

Can it read Ejari, SPA, NOC and title-deed documents and flag risks?

Yes. OCR plus extraction models pull parties, dates, financials and clause flags. A human reviews flagged fields before anything is filed

Can a human approve AI replies, document actions and high-value lead routing?

Approval queues are the default pattern: low-confidence extractions and all external actions route to a named reviewer with full context

Where is customer and Emirates ID data stored, and is the system UAE/PDPL compliant?

Storage region and subprocessor list are configurable. A PDPL-compliant setup documents the data-flow map, retention and deletion paths per Federal Decree-Law 45/2021

How much does AI document automation cost in Dubai?

Single-document-type pipelines start in the low five figures AED. Multi-document pipelines with validation and CRM write-back are mid five figures and up

Does it work with our existing HubSpot, Salesforce, Zoho or Odoo setup?

Extracted fields write back to any CRM with an API. Mapped fields and attachment sync are part of the pipeline spec, not a rebuild

Sources

Want systems like this?

We build and ship AI systems for real operations