The Central Bank of the UAE activated its Operational Risk Management Regulation on September 14, 2026, introducing stricter requirements for banks and licensed financial institutions to protect service continuity. The framework targets risks from technology outages, cyberattacks, fraud, internal system failures and disruptions at third-party service providers on which institutions increasingly depend. Gulf News reported that the regulation was circulated to bank management teams and replaces an earlier 2018 standard with a stronger emphasis on measurable resilience outcomes.
Critical operations must be identified by each institution based on its business model, according to the Central Bank of the UAE. These typically include payment and funds transfers, account access and salary processing, card operations and other essential customer services whose interruption could inflict significant harm. Institutions are required to set explicit disruption tolerance levels that specify both the maximum acceptable outage duration and the impact threshold for each such operation.
A Crowe UAE assessment of the regulation found that the rules shift the focus from merely confirming the existence of controls to proving that critical operations can continue functioning within the defined tolerances during disruptions. The Central Bank of the UAE expects boards and senior executives to maintain direct oversight rather than delegating the issue solely to information technology teams. This governance layer forms part of a connected approach that links risk management, business continuity and third-party dependencies.
The regulation mandates robust information and communications technology risk management alongside cybersecurity programs that encompass system and data protection, vulnerability monitoring, and regular testing of business continuity and disaster recovery plans. Licensed financial institutions must maintain a master system of record continuously within the UAE, even when activities are outsourced, subject to limited exceptions and prior approval. Crowe UAE noted that significant operational risk events affecting critical operations must be reported to the Central Bank of the UAE within four hours.
The new requirements build on earlier Central Bank of the UAE initiatives, including the May 2026 launch of an Anti-Fraud Operations Centre designed for real-time monitoring and rapid response to fraudulent activity. That platform was accompanied by guidance urging reduced reliance on single-factor authentication methods such as SMS-based one-time passwords in favor of stronger, multi-layered controls. Legal analyses of the broader 2025 banking law, which the regulation supports, indicate that maximum penalties for violations have risen to one billion dirhams, reflecting heightened supervisory expectations.
Regional cyber threats have intensified in recent years, prompting the Central Bank of the UAE to integrate these resilience standards across the financial sector. The rules also align with the Federal Decree-Law No. 6 of 2025 on the Central Bank and financial institutions, which expanded the regulatory perimeter to cover technology service providers facilitating financial activities. A one-year transitional window under the 2025 law allows entities to align operations, with the operational risk measures now forming an immediate compliance priority for institutions.
ع