The Central Bank of the UAE introduced the new Operational Risk Management Regulation to replace standards issued in 2018, with the framework taking effect on September 14, 2026. The regulation applies to all licensed financial institutions with legal personality and sets minimum requirements for operational risk management alongside operational resilience. A Central Bank assessment found that expanding use of mobile banking applications, instant transfers, digital wallets and payment cards has raised the potential impact of any technical failure on customers who increasingly rely on electronic channels for daily transactions. The Central Bank data places total banking sector assets at more than AED 5.5 trillion in early 2026, underscoring the scale of operations now dependent on digital infrastructure.
Under the regulation the Central Bank requires institutions to identify critical operations whose disruption could harm customers, the firm or the wider financial system. Those operations include transfers and payments, access to accounts including salary processing, and the functioning of all types of payment cards along with other essential services. Institutions must define clear disruption tolerance levels for each critical operation, specifying the maximum acceptable duration of any interruption and the tolerable level of impact. The Central Bank further directs firms to develop comprehensive contingency plans that address technology failures, cyberattacks, fraud and reliance on third-party service providers.
The updated rules place fresh emphasis on building resilience rather than simply preventing operational losses, according to the Central Bank framework. Financial institutions now face tighter obligations to report major incidents, with notification required within four hours when an event significantly affects the continuity or safety of critical operations. The regulation grants the Central Bank authority to impose additional requirements on individual institutions when necessary and to issue further standards or guidelines as the sector evolves. Central Bank figures show financial transfers through the UAE system reached 14.4 trillion dirhams in the first half of 2026, a 25 percent increase from the previous year, highlighting the volume of activity that could be exposed to disruption.
The new framework reflects the growing complexity of modern financial services that depend on interconnected digital networks, cloud solutions and specialised providers. Institutions must integrate risk identification, business continuity and recovery capabilities that align with international standards while addressing local market conditions. The Central Bank has circulated the requirements to management teams across banks and licensed firms, signalling a shift toward proactive resilience testing and continuous learning from any incidents. Recent sector data from the Central Bank also records strong capital adequacy and liquidity ratios well above regulatory thresholds, providing a stable base for implementing the enhanced controls.
Implementation of the regulation coincides with sustained expansion in the UAE’s digital banking adoption, where customer demand for seamless app-based services has accelerated since the pandemic years. The Central Bank expects institutions to map their reliance on external vendors and establish robust oversight mechanisms to prevent third-party failures from cascading into customer harm. Regulators will monitor compliance through regular assessments, with the potential for supervisory action where tolerance levels or reporting obligations are not met. This step forms part of the Central Bank’s broader programme to modernise financial infrastructure and safeguard public confidence in electronic payment systems.
ع