The Central Bank of the UAE issued Regulation No. C 1/2026 on operational risk management, which took effect on September 14, 2026 and applies to all licensed financial institutions with legal personality. The framework moves beyond preventing losses to building the ability to continue operations, adapt, recover and learn from disruptions, a Gulf News report stated. It also empowers the Central Bank to impose additional requirements or issue further guidelines where necessary.
This regulation repeals Circular No. 163 from 2018 and its standards, addressing evolving risks tied to digital transformation, reliance on technology, third-party providers and complex interconnections. An ADGM Academy research paper identified ransomware, phishing, DDoS attacks and supply chain incidents as the leading cyber threats to the UAE financial sector. The updated rules integrate information and communications technology risk management and cybersecurity as core elements of the operational risk framework.
Financial institutions must identify critical operations that, if disrupted, could significantly harm customers, the institution or the financial system, according to the Central Bank. Examples include transfers and payments, account access with salary processing, and card operations along with other essential services. The regulation requires clearly defined tolerance levels for each, specifying the maximum acceptable interruption duration and impact.
Institutions face a four-hour deadline to notify the Central Bank of any event likely to affect the continuity or safety of critical operations, the new rules specify. Comprehensive contingency planning, business continuity arrangements, disaster recovery testing and vulnerability monitoring form additional obligations. Cybersecurity measures must cover risk assessment, mitigation, incident response, patch management and change controls.
Central Bank of the UAE data places bank assets at 5,593.8 billion dirhams by the end of June 2026, a 12.5 percent rise from the prior year. Expanding use of mobile applications, instant transfers, digital wallets and electronic payments has heightened the impact of any technical outage on customers. Khaleej Times reporting has highlighted the evolution of threats including AI-facilitated phishing and triple extortion ransomware tactics in the banking sector.
The standards demand protection of systems and data while ensuring regular testing of recovery plans. By implementing these requirements, the regulation seeks to shorten potential disruption periods and reinforce overall sector stability. Customers should see improved data safeguards and quicker restoration of services during incidents.
ع