UAE Business Portal
Brent 82.4 ▲0.6% Gold $2 415 USD/AED 3.6725
UAE

UAE KYC Platform 2026: 30-day cure window, CBUAE penalties

UAE Cabinet Resolutions No. 55 and No. 56 of 2026 activate the national KYC digital platform's operating rules and its schedule of administrative penalties. The Central Bank of the UAE (CBUAE) is given broad supervisory powers — including the right to suspend business dealings with any confirmed violator — while a "justice before punishment" principle grants a written notice of up to 30 days to remedy a breach. Underlying Federal Decree-Law No. 30 of 2024 keeps a criminal track: at least two years of imprisonment and a fine from AED 50,000 for unauthorised disclosure or fraudulent acquisition of platform data. Below: who is now in scope, what Norbloc AB is doing, and what banks, fintechs, insurers and designated data providers should get in order.

UAE, 29 August 2026 — the UAE Cabinet has issued two key acts that activate the operating framework of the national KYC digital platform. Cabinet Resolution No. 55 of 2026 is issued as the Executive Regulations of Federal Decree-Law No. 30 of 2024 and sets out how the platform works: collection, management and sharing of verified KYC data across authorised users. Cabinet Resolution No. 56 of 2026 establishes the schedule of administrative violations and sanctions for breaches of the law and its Executive Regulations. The Central Bank of the UAE (CBUAE) is granted broad supervisory powers: the authority to suspend business dealings with any confirmed violator and to impose administrative sanctions. At the same time a "justice before punishment" principle is introduced — a written notice of up to 30 days to remedy a violation may be issued to the offender. The underlying Federal Decree-Law No. 30 of 2024 keeps a criminal track: a minimum of two years of imprisonment and a fine from AED 50,000 for unauthorised disclosure or fraudulent acquisition of protected platform data. CBUAE's technology partner for building the platform is Sweden-based Norbloc AB. The initiative is part of the Central Bank's Financial Infrastructure Transformation (FIT) Programme. Primary sources: uaelegislation.gov.ae (Cabinet Resolution No. 56 of 2026); legal analysis by Kashwani Law Firm, HLA UAE and Comsure Group briefings.

Common questions on this topic

What are Cabinet Resolutions 55 and 56 of 2026 and how are they connected?

They are two linked acts of the UAE Cabinet issued in 2026 that activate the operating framework of the national KYC digital platform. Cabinet Resolution No. 55 of 2026 issues the Executive Regulations of Federal Decree-Law No. 30 of 2024 on the "Know Your Customer" Digital Platform — it defines how the platform collects, manages and shares verified KYC data among authorised users. Cabinet Resolution No. 56 of 2026 sets out the schedule of administrative violations and sanctions for breaches of the law and the Executive Regulations. The first act writes the rulebook; the second sets the price of breaking those rules.

Who is in scope of the new KYC platform rules?

The perimeter covers all CBUAE-regulated participants and designated data providers. Based on legal analysis by Kashwani Law Firm and Comsure Group, it includes: banks; investment and finance companies; insurance companies and insurance-related professions licensed by CBUAE; payment and money services operators; designated data providers (including government identity sources); and authorised users of the platform. The Central Bank of the UAE (CBUAE) supervises the platform and defines the categories of customer data requested.

What does "up to 30 days to fix" mean in practice?

Cabinet Resolution No. 56 of 2026 enshrines a "justice before punishment" principle. In practice, once a breach is detected, the regulator may issue a written notice to the offender granting a period not exceeding 30 days to remedy the violation. This is not an automatic amnesty: CBUAE retains the authority to impose sanctions even after remediation in order to ensure the violation does not recur. The grace period is a procedural safeguard giving a chance to cure, not a blanket indulgence.

What penalties apply for breaches?

There are two sanction tracks. The administrative track, set by Cabinet Resolution No. 56 of 2026: CBUAE can impose an administrative fine and suspend business dealings with any confirmed violator — potentially cutting them off from the platform. The criminal track is set by the underlying Federal Decree-Law No. 30 of 2024: at least two years of imprisonment and a fine from AED 50,000 for unauthorised disclosure of protected data or fraudulent acquisition of access to the platform. For technology providers and designated data providers this materially changes the personal-accountability model for staff with KYC-perimeter access.

What is the KYC Digital Platform and why was it created?

The KYC Digital Platform is a single national hub of verified customer data (for individuals and companies), built on a privacy-by-design model with explicit customer consent. The initiative is part of the CBUAE's Financial Infrastructure Transformation (FIT) Programme. The technology partner is Sweden-based Norbloc AB. The goal is to eliminate duplicate customer due diligence across banks during onboarding, speed up account opening, and raise AML/CFT quality through integration with UAE government identity sources. For the customer, it means a single reusable KYC profile; for regulated entities, lower operating cost — and a strict accountability perimeter for data quality and protection.

The UAE Cabinet has issued two key acts that activate the operating framework of the national KYC digital platform. Cabinet Resolution No. 55 of 2026 is issued as the Executive Regulations of Federal Decree-Law No. 30 of 2024 and sets out how the platform works: the collection, management and sharing of verified KYC data among authorised users. Cabinet Resolution No. 56 of 2026 establishes the schedule of administrative violations and sanctions. The Central Bank of the UAE (CBUAE) is granted broad supervisory powers — including the right to suspend business dealings with a violator — while a "justice before punishment" principle gives the offender up to 30 days to remedy a breach.

What has been activated

The two acts work in tandem. Cabinet Resolution No. 55 of 2026 issues the Executive Regulations of Federal Decree-Law No. 30 of 2024 on the "Know Your Customer" Digital Platform — that is, it sets the operating rules of the single national KYC hub: collection, management and sharing of verified customer data among authorised users. Cabinet Resolution No. 56 of 2026 is the schedule of administrative violations and sanctions for breaches of the law and the Executive Regulations. The primary source for both acts is the government portal uaelegislation.gov.ae. Legal analysis is provided by Kashwani Law Firm, HLA UAE and Comsure Group.

Who is in scope

The regulated perimeter covers all CBUAE-licensed participants of the KYC platform and designated data providers. Per Kashwani Law Firm and Comsure Group, this includes banks; investment and finance companies; insurance companies and insurance-related professions licensed by CBUAE; payment and money services operators; designated data providers — including UAE government identity sources; and authorised users of the platform. For many firms this means more than a new compliance document on the shelf — it means embedding the platform into the actual onboarding flow, from opening a corporate bank account in the UAE to launching a new payments product.

CBUAE powers: suspending business dealings

Under Cabinet Resolution No. 56 of 2026 the Central Bank of the UAE is granted broad supervisory powers. It can impose administrative sanctions and — importantly — suspend business dealings with any confirmed violator. For regulated institutions and technology providers this is a structural shift: being placed under such a suspension effectively paralyses the licensed activity, because access to the KYC platform becomes part of the financial sector's base infrastructure. The penalty schedule complements the acts already in force — first of all the new Central Bank Law (Federal Decree-Law No. 6 of 2025), which itself raised the administrative fine ceiling to AED 1 billion.

Justice before punishment: up to 30 days to cure

Cabinet Resolution No. 56 of 2026 enshrines a "justice before punishment" principle. In operational terms, once a breach is detected, the regulator can issue a written notice to the offender granting up to 30 days to remedy the violation. This is a procedural safeguard — a chance to fix before enforcement — but not an indulgence: CBUAE retains the right to impose administrative sanctions even after the breach is remedied, if it considers this necessary to prevent recurrence. Kashwani Law Firm frames it as a balance between the incentive to self-correct and a firm regulatory line.

The criminal track — from the underlying law

Beyond the administrative layer, sanctions build on the underlying Federal Decree-Law No. 30 of 2024. The law provides for a minimum of two years of imprisonment and a fine from AED 50,000 for offences such as unauthorised disclosure of protected platform information or fraudulent acquisition of access to the data. For regulated entities this means the internal access model to the KYC perimeter has to be tightened: employees with view or export rights over KYC data need to understand their personal criminal exposure. For technology providers and designated data providers, the accountability model for staff and contractors changes materially.

How the platform is built

The KYC Digital Platform is a single national hub of verified customer data (for individuals and companies). It is built on a privacy-by-design model and operates on explicit customer consent: data is shared with authorised users only with the customer's permission. The initiative is part of the CBUAE's Financial Infrastructure Transformation (FIT) Programme. The technology partner is Sweden-based Norbloc AB, responsible for rolling out the e-KYC infrastructure. The platform covers both Know Your Customer (KYC) and Know Your Business (KYB), integrates with UAE government identity sources, and eliminates duplicate due diligence between banks and fintechs. Participation is set to become mandatory for all regulated financial entities as the system is rolled out.

What it means for business

For a bank, an investment firm, a fintech startup, an insurer or a designated data provider, the practical takeaways are concrete. First: audit the internal access policy to the KYC perimeter — roles, logging, incident-response steps. Second: refresh the consent mechanics for customer data — the platform runs on explicit consent, and it has to be properly captured. Third: redesign onboarding around the future integration with the platform, to avoid reworking contract templates on every release. Fourth: map the overlaps with the Jaywan national payment infrastructure and the other FIT Programme components — they are being wired into a single perimeter, and compliance standards will converge. Fifth: run internal training for staff with KYC-data access, spelling out personal criminal exposure under Federal Decree-Law No. 30 of 2024.

This material is for information only. The current text of Cabinet Resolution No. 56 of 2026 is available on uaelegislation.gov.ae. Before taking business decisions, verify requirements against the latest circulars and guidance from the Central Bank of the UAE (CBUAE) and obtain legal advice on your specific activity.

Topics:UAECBUAEKYCAMLComplianceBankingFintechInsuranceRegulationCabinet Resolution