The UAE Cabinet has issued two key acts that activate the operating framework of the national KYC digital platform. Cabinet Resolution No. 55 of 2026 is issued as the Executive Regulations of Federal Decree-Law No. 30 of 2024 and sets out how the platform works: the collection, management and sharing of verified KYC data among authorised users. Cabinet Resolution No. 56 of 2026 establishes the schedule of administrative violations and sanctions. The Central Bank of the UAE (CBUAE) is granted broad supervisory powers — including the right to suspend business dealings with a violator — while a "justice before punishment" principle gives the offender up to 30 days to remedy a breach.
What has been activated
The two acts work in tandem. Cabinet Resolution No. 55 of 2026 issues the Executive Regulations of Federal Decree-Law No. 30 of 2024 on the "Know Your Customer" Digital Platform — that is, it sets the operating rules of the single national KYC hub: collection, management and sharing of verified customer data among authorised users. Cabinet Resolution No. 56 of 2026 is the schedule of administrative violations and sanctions for breaches of the law and the Executive Regulations. The primary source for both acts is the government portal uaelegislation.gov.ae. Legal analysis is provided by Kashwani Law Firm, HLA UAE and Comsure Group.
Who is in scope
The regulated perimeter covers all CBUAE-licensed participants of the KYC platform and designated data providers. Per Kashwani Law Firm and Comsure Group, this includes banks; investment and finance companies; insurance companies and insurance-related professions licensed by CBUAE; payment and money services operators; designated data providers — including UAE government identity sources; and authorised users of the platform. For many firms this means more than a new compliance document on the shelf — it means embedding the platform into the actual onboarding flow, from opening a corporate bank account in the UAE to launching a new payments product.
CBUAE powers: suspending business dealings
Under Cabinet Resolution No. 56 of 2026 the Central Bank of the UAE is granted broad supervisory powers. It can impose administrative sanctions and — importantly — suspend business dealings with any confirmed violator. For regulated institutions and technology providers this is a structural shift: being placed under such a suspension effectively paralyses the licensed activity, because access to the KYC platform becomes part of the financial sector's base infrastructure. The penalty schedule complements the acts already in force — first of all the new Central Bank Law (Federal Decree-Law No. 6 of 2025), which itself raised the administrative fine ceiling to AED 1 billion.
Justice before punishment: up to 30 days to cure
Cabinet Resolution No. 56 of 2026 enshrines a "justice before punishment" principle. In operational terms, once a breach is detected, the regulator can issue a written notice to the offender granting up to 30 days to remedy the violation. This is a procedural safeguard — a chance to fix before enforcement — but not an indulgence: CBUAE retains the right to impose administrative sanctions even after the breach is remedied, if it considers this necessary to prevent recurrence. Kashwani Law Firm frames it as a balance between the incentive to self-correct and a firm regulatory line.
The criminal track — from the underlying law
Beyond the administrative layer, sanctions build on the underlying Federal Decree-Law No. 30 of 2024. The law provides for a minimum of two years of imprisonment and a fine from AED 50,000 for offences such as unauthorised disclosure of protected platform information or fraudulent acquisition of access to the data. For regulated entities this means the internal access model to the KYC perimeter has to be tightened: employees with view or export rights over KYC data need to understand their personal criminal exposure. For technology providers and designated data providers, the accountability model for staff and contractors changes materially.
How the platform is built
The KYC Digital Platform is a single national hub of verified customer data (for individuals and companies). It is built on a privacy-by-design model and operates on explicit customer consent: data is shared with authorised users only with the customer's permission. The initiative is part of the CBUAE's Financial Infrastructure Transformation (FIT) Programme. The technology partner is Sweden-based Norbloc AB, responsible for rolling out the e-KYC infrastructure. The platform covers both Know Your Customer (KYC) and Know Your Business (KYB), integrates with UAE government identity sources, and eliminates duplicate due diligence between banks and fintechs. Participation is set to become mandatory for all regulated financial entities as the system is rolled out.
What it means for business
For a bank, an investment firm, a fintech startup, an insurer or a designated data provider, the practical takeaways are concrete. First: audit the internal access policy to the KYC perimeter — roles, logging, incident-response steps. Second: refresh the consent mechanics for customer data — the platform runs on explicit consent, and it has to be properly captured. Third: redesign onboarding around the future integration with the platform, to avoid reworking contract templates on every release. Fourth: map the overlaps with the Jaywan national payment infrastructure and the other FIT Programme components — they are being wired into a single perimeter, and compliance standards will converge. Fifth: run internal training for staff with KYC-data access, spelling out personal criminal exposure under Federal Decree-Law No. 30 of 2024.
This material is for information only. The current text of Cabinet Resolution No. 56 of 2026 is available on uaelegislation.gov.ae. Before taking business decisions, verify requirements against the latest circulars and guidance from the Central Bank of the UAE (CBUAE) and obtain legal advice on your specific activity.


