New UAE Central Bank rules target outages, fraud and cyberattacks
The UAE Central Bank’s new Operational Risk Management Regulation came into force yesterday, September 14, 2026, establishing a more stringent framework to safeguard the continuity of services provided by banks and licensed financial institutions, particularly against technology failures, cyberattacks, fraud, system failures and disruptions involving third-party companies on which institutions…
The UAE Central Bank has introduced new Operational Risk Management Regulation as of September 14, 2026, aiming to enhance the resilience of banks and financial institutions against various risks, including technology failures, cyberattacks, fraud, and disruptions from third-party service providers. This regulation supersedes the previous operational risk management standards set in 2018 and holds significant implications for customers as more financial services transition to digital channels.
To comply with the new regulations, financial institutions are required to develop comprehensive contingency plans identifying operations deemed critical to their functioning. Such critical operations encompass transfers and payments, access to accounts, salary processing, and the functionality of all types of cards and essential services.
The Central Bank mandates the establishment of clearly defined disruption tolerance levels for each critical operation, specifying the maximum tolerable duration of interruptions and acceptable impacts.
Under this regulation, the institution's board of directors now bears direct responsibility for overseeing operational risk and resilience, covering strategy approval, risk appetite definition, and ensuring the availability of necessary systems and personnel. Senior management is tasked with implementing these strategies effectively.
This shift in responsibility signifies a broader recognition that service disruptions are not solely a technical issue but a matter requiring comprehensive business strategy and management oversight.
Key aspects of the regulation include stringent requirements for information technology risk management and cybersecurity, emphasizing the protection of systems and data, monitoring for vulnerabilities, and conducting regular testing of business continuity and disaster recovery plans. The institution must also maintain a robust incident management system covering the lifecycle of incidents, from detection to resolution, root-cause analysis, and preventive measures.
Institutions must promptly notify the Central Bank of any significant deviations from compliance or major incidents, providing the additional regulatory data and reports requested by the supervisory authority. The regulation applies even to outsourced operations, ensuring that institutions remain accountable for the security and continuity of their services, regardless of external service providers involved.
For customers, the introduction of this regulation is anticipated to mitigate the frequency and duration of service disruptions, expedite service recovery, enhance data protection, and improve the overall preparedness of institutions to respond to cyberattacks. However, it is important to note that the regulation does not guarantee the impossibility of service disruptions nor does it inherently entitle customers to compensation for any interruptions.
Written by urgent.news from Gulf News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.