UAE Overhauls Bank Risk Rules With Four-Hour Reporting, Cyber Tests and Tougher Penalties

Date:

New UAE Rules Require Financial Institutions to Strengthen Cybersecurity and Incident Reporting.

The Central Bank of the UAE’s new Operational Risk Management Regulation came into effect on September 14, 2026, marking a significant shift in how the country’s financial sector manages risk. The framework moves beyond the traditional focus on preventing operational losses to building institutions capable of maintaining operations, adapting to disruptions, recovering effectively and learning from incidents.

Known as Regulation No. C 1/2026, the framework applies to all licensed financial institutions with legal personality and is not limited to banks. It sets minimum requirements for operational risk management and resilience, while giving the Central Bank authority to impose additional requirements where necessary and issue further standards or detailed guidance.

New regulation replaces previous rules and circulars

The regulation repeals and replaces Circular No. 163/2018 on Operational Risk Management and its associated standards.

The change moves the UAE financial sector from a regulatory framework introduced around eight years ago to a broader system designed to address evolving risks linked to digital transformation, growing dependence on technology and third-party service providers, rising cyber threats and increasingly complex connections between financial institutions and digital infrastructure.

Three lines of defence against risk

Under the new Operational Risk Management Regulation, financial institutions are required to reinforce the three-lines-of-defence model for managing operational risk.

The first line comprises business units, which are responsible for continuously identifying, assessing and controlling risks within their day-to-day operations.

The second line consists of risk management and compliance functions, which provide relatively independent oversight and challenge decisions made by business units where necessary.

The third line is internal audit, which provides independent assurance on the effectiveness of the institution’s risk management framework and internal controls.

Financial institutions must also maintain an independent operational risk management function with sufficient resources, headed by the Chief Risk Officer (CRO).

The function is responsible for developing an independent assessment of material risks, evaluating the effectiveness of internal controls and reviewing the institution’s operational risk profile. It must also identify threats and vulnerabilities that could affect critical operations, while providing training and promoting greater risk awareness across the institution.

Cybersecurity moves to the heart of operational risk management

As the financial sector becomes increasingly reliant on digital services, the new framework places information and communications technology (ICT) risk management and cybersecurity at the centre of operational risk management.

Financial institutions are required to establish an effective ICT and cybersecurity risk framework covering risk identification and assessment, mitigation measures, incident response and recovery, change management, data and technology services, patch management, business continuity and disaster recovery planning.

These frameworks must be reviewed regularly to ensure they remain aligned with industry standards and best practices, while keeping pace with emerging threats and technological developments.

In practical terms, cybersecurity can no longer operate as a standalone technical function separate from broader risk management. Instead, it becomes a core part of a financial institution’s ability to maintain essential services during disruptions.

Stress testing and penetration testing

The regulation requires financial institutions to conduct periodic operational risk stress tests, including assessments of their control environments and penetration testing.

For critical functions, periodic assessments must include penetration testing carried out by an independent external party, with the results presented to the board of directors.

The requirement marks a shift from assessing risks primarily on paper to testing how effectively institutions can respond to real-world disruption scenarios.

A financial institution may have a comprehensive contingency plan in place, but if it cannot effectively implement that plan during a real crisis, it may fall short of the operational resilience standards set out under the new framework.

Business continuity: From plans to testing

The regulation requires financial institutions to maintain business continuity and disaster recovery plans for critical operations and integrate them into their broader operational risk management and resilience frameworks.

However, the requirements go beyond simply having plans in place. Institutions must also conduct exercises to test their business continuity and disaster recovery capabilities under severe but plausible scenarios, demonstrating their ability to maintain critical operations during major disruptions.

This reinforces a fundamental principle underpinning the regulation: operational readiness is measured not simply by the existence of a plan, but by an institution’s ability to execute it effectively when disruption occurs.

Four-hour deadline for reporting major incidents

One of the regulation’s key requirements introduces tighter deadlines for reporting significant operational incidents. If an event has, or is likely to have, a significant impact on the continuity and safety of critical operations, the financial institution must notify the Central Bank within four hours and identify the critical operations affected.

Within 24 hours, the institution must submit a brief report detailing the nature of the incident, the measures taken in response, its potential impact and the expected timeframe for restoring normal operations.

Once normal operations have resumed, the institution must notify the Central Bank and provide any additional information or notifications requested by the regulator on a case-by-case basis.

Financial institutions must also notify the Central Bank within 72 hours of any high-severity incident, in line with the institution’s incident classification criteria.

Customer protection becomes part of risk management

The regulation goes beyond protecting financial institutions by placing greater emphasis on the impact of operational disruptions on customers. If operational changes result in customers receiving materially inaccurate information — including payment confirmations, debit or credit transactions, or account balances — institutions must clearly explain how their accounts or transactions have been affected.

Financial institutions are also responsible for losses suffered by customers as a result of institutional errors, in accordance with the Central Bank’s consumer protection regulations.

The requirement reflects a broader regulatory shift towards directly linking operational resilience and continuity of financial services with customer protection.

Internal and external fraud

Fraud is also incorporated into the new operational risk framework, with financial institutions required to identify and manage risks arising from both internal and external fraud, including incidents and ongoing threats affecting customers.

This means fraud management is no longer treated solely as a security or compliance matter. Instead, it forms part of the wider operational risk framework and must be identified, assessed, monitored, reported and mitigated accordingly.

Penalties can extend to management and boards

The requirements are enforceable regulatory obligations rather than voluntary guidelines.

The Central Bank states that violations of any provision of the regulation or its accompanying standards may result in supervisory measures as well as administrative or financial sanctions considered appropriate by the regulator.

These measures may include removing or replacing senior management or board members, restricting their powers, placing the institution under temporary management, imposing financial penalties, or prohibiting individuals from operating within the UAE financial sector.

The provisions significantly raise the level of accountability, extending responsibility beyond the institution itself to senior management and the highest levels of corporate governance.

Why the new framework now?

The new regulation comes amid a major transformation of the financial sector in recent years and the emergence of increasingly complex operational risks.

Risks no longer stem solely from employee errors or failures in internal procedures. Modern financial institutions depend on complex digital networks, data centres, cloud-based solutions, specialised service providers, payment platforms, banking applications, artificial intelligence systems and data analytics, while operating within increasingly interconnected institutions and markets.

As a result, the failure of a single technology provider, a cyberattack, disruption to a payment system or an error during a system update can quickly spread from one part of an institution to its customers, other financial institutions and potentially the wider financial system.

This is why operational resilience now extends beyond managing risks within an individual institution to safeguarding the continuity of critical financial functions across the broader system.

From the 2018 framework to the 2026 regime

A comparison between the new regulation and the framework introduced in 2018 highlights the scale of the regulatory shift.

The previous framework focused primarily on establishing policies, processes, procedures, systems and controls to identify, monitor and mitigate operational risks, while placing ultimate responsibility for oversight with the board of directors.

The new regulation introduces several more sophisticated layers to the UAE’s operational risk framework, most notably:

  • Operational resilience
  • Identification of critical operations
  • Mapping of interdependencies
  • Cybersecurity
  • Third-party risk management
  • Stress testing and penetration testing
  • Four-hour incident reporting
  • Change management
  • Customer protection
  • Data governance
  • Public disclosure

The changes therefore amount to more than a technical update of the previous framework. They represent a broader redefinition of what it means for a financial institution to effectively manage risk in a highly interconnected digital economy.

What does this mean for financial institutions?

In practical terms, financial institutions will need to conduct a comprehensive review of their internal frameworks rather than simply updating existing risk management policies and documents.

Key priorities are expected to include:

  1. Reviewing governance frameworks and responsibilities to ensure clear roles and authority for boards, senior management, risk management and internal audit functions.
  2. Reassessing critical operations and identifying the assets and resources on which they depend.
  3. Reviewing dependency maps covering systems, data, employees and third-party service providers.
  4. Testing business continuity and disaster recovery plans rather than simply maintaining them on paper.
  5. Strengthening cybersecurity preparedness and integrating it directly into operational resilience frameworks.
  6. Reassessing third-party service providers, particularly those supporting critical operations.
  7. Enhancing internal reporting systems to ensure material incidents can be rapidly escalated to senior management, boards and the Central Bank.
  8. Developing stronger data and analytics capabilities to monitor risk indicators and provide early warnings of potential disruptions.
  9. Strengthening change management processes to ensure digital transformation projects do not themselves become sources of operational risk.
  10. Building a stronger risk culture in which managing risk becomes a shared institutional responsibility rather than the sole responsibility of the risk management function.

A broader perspective: Protecting the financial system from a ‘chain of disruption’

The significance of the new regulation extends beyond individual financial institutions. Today’s financial sector operates as a highly interconnected network, with institutions relying on technology providers that may themselves depend on other infrastructure. Payment systems can rely on shared networks, while customers are increasingly dependent on digital applications and services.

In such an environment, an incident that begins as a relatively small problem within one institution can quickly develop into a wider disruption if it affects an essential service, compromises data or interrupts payment operations.

This appears to reflect a central principle underpinning the new framework: it is no longer enough for a financial institution to remain sound when everything is operating normally. It must also demonstrate that it can continue delivering critical services when conditions deteriorate.

This is where the shift from traditional operational risk management towards a broader framework combining operational risk management and operational resilience becomes particularly significant.

Share post:

Subscribe

spot_imgspot_img

Popular

More like this
Related

ADX Expands Into On-Chain Investing With Digital Wallet and Tokenisation Capabilities

ADX and DFNS Team Up to Advance Digital Asset...

Shabab Al Ahli Hold Talks Over Richarlison Move as Tottenham Tensions Grow

Richarlison Linked with Shabab Al Ahli as Tottenham Future...

SpiceJet Passengers Heading to Dubai Protest After More Than 24-Hour Delay

Delays to Two Dubai-Bound SpiceJet Flights Spark Protest by...

flydubai Expands Fleet to 100 Aircraft, Adds Lie-Flat Business Class to 21 Jets

Airline Welcomes 11 MAX Jets in 2026 and Boosts...