UAE Business Portal
Brent 82.4 ▲0.6% Gold $2 415 USD/AED 3.6725
UAE

CBUAE enacts new operational risk regulation for banks

On 14 September 2026 a new Operational Risk Management Regulation from the Central Bank of the UAE came into force. It replaces the 2018 standards, makes boards approve disruption tolerance for each critical operation, mandates a 4-hour notification of significant incidents and keeps banks responsible for outsourced activity. Here is what changes for banks, insurers, fintech and corporate customers.

On 14 September 2026 the Central Bank of the UAE (CBUAE) put into force a new Operational Risk Management Regulation for banks, insurers, reinsurers and other CBUAE-licensed financial institutions. It replaces the 2018 standards and shifts the focus from having recovery plans to demonstrating measurable operational resilience. Each supervised entity’s board must approve strategies, policies and risk appetite for operational resilience, set clearly defined disruption tolerance levels for every critical operation and test the ability to stay within those limits under severe but plausible scenarios. CBUAE lists key critical operations: transfers and payments, account access, salary processing, card operations. Significant incidents must be notified to the regulator within four hours. The master system of record must be kept inside the UAE, including outsourced arrangements. Before outsourcing activity that could materially affect critical operations, institutions must obtain CBUAE no-objection. Responsibility for the security and continuity of services stays with the institution itself.

Common questions on this topic

What is the new CBUAE Operational Risk Management Regulation?

It is the Central Bank of the UAE regulation on operational risk management for banks, insurers, reinsurers and other CBUAE-licensed financial institutions. The regulation came into force on 14 September 2026 and replaces the 2018 standards. The key change: the approach moves from formally having recovery plans to demonstrating measurable operational resilience — with clear board-level accountability, defined disruption tolerance for every critical operation and a mandatory 4-hour notification of significant incidents.

When does the new regulation take effect?

The regulation is effective from 14 September 2026. It was published in the official CBUAE Rulebook (rulebook.centralbank.ae). Some obligations — updating internal policies, having the board approve tolerance limits, setting up 4-hour incident notification — take time to implement, but the regulator expects supervised entities to start bringing themselves into compliance immediately.

How quickly must a bank notify CBUAE of a significant incident?

Within 4 hours of the moment a significant incident affecting critical operations is identified. Significant events include material outages of critical services, cyberattacks with customer-facing impact, and data incidents. The regulation requires institutions to have an internal incident-qualification procedure and named officers responsible for regulator communication.

Who does the regulation apply to — banks only?

Not only banks. Per CBUAE, the regulation applies to banks (including Islamic banks), insurers, reinsurers and other financial institutions licensed by the regulator. Critical operations explicitly include transfers and payments, account access, salary processing and card operations. Fintechs licensed by CBUAE — payment service providers, e-money issuers — are also covered.

Is the bank responsible for incidents at an outsourced provider?

Yes. The regulation is explicit: the institution remains responsible for the security and continuity of its services even when parts of the operation are outsourced (cloud providers, payment gateways, KYC verification, contact centres). In addition, before outsourcing activity that could materially affect critical operations, the institution must obtain CBUAE no-objection, and the master system of record must be kept inside the UAE — including outsourced arrangements. In practice this means reviewing existing outsourcing contracts for audit rights, SLAs and exit strategies.

On 14 September 2026 the Central Bank of the UAE (CBUAE) put into force a new Operational Risk Management Regulation covering banks, insurers, reinsurers and other CBUAE-licensed financial institutions. It replaces the 2018 standards: boards now approve disruption tolerance for each critical operation, significant incidents must be disclosed to the regulator within four hours, and outsourcing activity that could materially affect critical operations now requires prior CBUAE no-objection.

The regulation is published in the official CBUAE Rulebook and takes effect from the date of publication — 14 September 2026. International law firm Pinsent Masons and business outlets Gulf News and Bazaar Times describe it as the most substantial upgrade to the operational-risk regime of the UAE banking sector in eight years. The predecessor standards date from 2018, and the market has changed radically since: online banking is now the default channel, payment infrastructure has become critical, and the number of cyber and fraud incidents has grown noticeably.

Key innovations of the regulation

  • Board responsibility. The board of every supervised entity must approve strategies, policies and risk appetite for operational resilience. This is no longer only a risk-function question — it is board-level accountability.
  • Disruption tolerance per critical operation. The institution must document how much and how long a disruption is acceptable — for each critical operation separately. CBUAE explicitly lists transfers and payments, account access, salary processing and card operations as critical.
  • Testing under severe but plausible scenarios. Institutions must not simply have a plan on paper — regular exercises must demonstrate the ability to remain within tolerance during core-system failures, provider outages, cyberattacks and fraud scenarios.
  • 4 hours for significant-incident notification. Material outages of critical services, serious cyberattacks, data incidents — the institution must disclose them to the regulator within four hours of the incident being qualified as significant.
  • Master system of record inside the UAE. The core operational data record must be physically kept in the UAE, including cases where processing is outsourced abroad.
  • No-objection for outsourcing critical operations. Before outsourcing activity that could materially affect critical operations, the institution must obtain CBUAE no-objection. Responsibility for the security and continuity of services stays with the institution itself.

The key shift: from "plans on paper" to measurable resilience

The 2018 standards required institutions to "identify, assess and mitigate" operational risks but did not set concrete time limits and left considerable room for interpretation. The 2026 regulation turns operational resilience into a measurable obligation: how many minutes of downtime are acceptable for each critical service, how quickly the service is restored in confirmed exercises, how quickly the regulator learns of an incident. Gulf News frames the shift as moving "from simply having plans to restore systems to demonstrating service continuity within predefined timeframes".

Why this matters now

The UAE’s financial infrastructure is going digital fast — the unified Jaywan national payment card, the CBUAE Open Finance framework, mandatory B2B e-invoicing and a policy push toward cashless payments. The more services and data concentrate in the banking core, the more expensive each hour of downtime becomes and the higher the reputational cost of an incident. The regulation does two things at once: it brings the UAE regime closer to international peers (the EU’s DORA, APRA, MAS and BoE requirements) and creates a competitive advantage as a jurisdiction for institutional clients, for whom operational resilience is a hygiene factor.

What it means for fintechs and corporate customers

Fintechs operating under CBUAE licences — payment service providers, e-money issuers, neobanks — are fully within scope. Fast-cycle product startups will need to build operational resilience into the roadmap: replication, a business continuity plan (BCP), incident management and a mandatory incident channel to CBUAE.

Bank partners — cloud providers, KYC/AML outsourcers, integrators, core-banking vendors — will feel it indirectly: banks will start rewriting standard contracts, adding audit rights, requiring SLAs with real penalties and checking data-hosting geography. For corporate customers — companies with operating accounts, trading counterparties, importers and exporters — the medium-term effect is more resilient operational channels: fewer online-banking "hangs", faster response to cyber incidents, more transparent communication during outages. This fits the broader vector of UAE regulatory change in 2026 — the market is becoming stricter but more predictable.

What banks and licensed FIs should do

Some requirements are technically already met by large players — they have long worked to international norms (Basel, DORA-like frameworks, ISO 22301). But the new timelines, the board’s role, the mandatory exercises and the outsourcing no-objection will require formalisation:

  • update the operational-risk policy and internal incident-management regulations;
  • define and have the board approve disruption tolerance limits for each critical operation;
  • assemble a register of critical operations, dependencies, IT systems and external providers;
  • document the 4-hour CBUAE notification procedure and assign named responsible officers;
  • plan and run the first exercises under typical scenarios (core-system failure, DDoS, ransomware, key-provider outage);
  • review outsourcing contracts for responsibility, SLAs, audit rights, exit strategies and the requirement to keep the master system of record inside the UAE;
  • prepare a process for obtaining CBUAE no-objection before outsourcing critical activity.

Pinsent Masons’ view: for most large banks this is more of an upgrade to existing processes than a build from scratch. For mid-tier banks, insurers, finance companies and licensed fintechs, implementation will require significant work and noticeable compliance spend over the next 6–12 months.

Based on the official CBUAE Rulebook (rulebook.centralbank.ae, in force from 14 September 2026), Gulf News (Banking, 14–15 September 2026), Pinsent Masons Out-Law (10 August 2026) and Bazaar Times (15 September 2026). This article is for information only and does not constitute legal advice.

Topics:UAECBUAEBankingRegulationOperational RiskCybersecurityComplianceFintech