The Central Bank of the UAE (CBUAE) issued Circular No. 1/2026 on 3 February 2026, introducing a new Operational Risk Management Regulation (the Regulation) which replaces the Operational Risk Regulation and Operational Risk Standards that have been in force since August 2018. The Regulation took effect on 14 September 2026.
The Regulation applies to all Licensed Financial Institutions (LFIs) that are juridical persons, including banks, (re)insurance companies, and other financial institutions licensed under the Federal Decree-Law No.(6) of 2025 Regarding the Central Bank, Regulation of Financial Institutions and Activities, and Insurance Business, whether incorporated in the UAE or operating through a branch or subsidiary.
The Regulation represents a fundamental shift in supervisory expectations, moving the emphasis from managing operational risk to demonstrating operational resilience during disruption.
The key changes
1. Operational resilience: a new standalone obligation
The most significant development is the introduction of a dedicated operational resilience framework. LFIs must establish an "Operational Resilience" framework capable of supporting Critical Operations during disruption and enabling effective response and recovery (Operational Resilience). To do so, LFIs must identify their Critical Operations and map the people, technology, data, facilities and third-party dependencies required to deliver them, with each operation supported by a mapping document.
At a minimum, Critical Operations must include the operation of payment systems and time-critical services, the maintenance of accurate and up-to-date financial records, the timely measurement and management of solvency and liquidity, and any operation deemed critical by the CBUAE.
2. Stronger board and senior management accountability
The LFI's board of directors (Board) bear ultimate responsibility for the LFI's Operational Resilience frameworks and frameworks to mitigate any risk of loss resulting from inadequate or failed internal processes, people and systems or from external events – this includes legal risks but excludes strategic and reputational risks (Operational Risk), regardless of any Board committees being set up.
The Board must approve and review at least annually, the LFI's Operational Risk appetite and tolerance, disruption tolerances and any comprehensive written plan of action that sets out the procedures and systems necessary to continue or restore the operation of the LFIs in the event of a disruption.
The executive management of a LFI responsible for the day-to-day operations of the LFI (Senior Management) must report actual or anticipated breaches of Operational Risk limits directly to the Board. Banks and (re)insurance companies must also submit an annual report on internal controls to both the Board and the CBUAE.
3. Information and Communications Technology (ICT), cybersecurity and data localisation
LFIs must maintain appropriate ICT and cybersecurity infrastructure to ensure the integrity, confidentiality and availability of systems and data.
The Regulation also introduces data localisation requirements, requiring an LFI's Master System of Record to be maintained within the UAE, including where functions are outsourced. Branches of foreign financial institutions may, subject to CBUAE approval, comply by maintaining an up-to-date copy of the Master System of Record in the UAE.
LFIs must also have a strategy and timeline for the timely replacement or retirement of obsolete and unsupported hardware and software systems.
4. Strict incident notification timelines
The Regulation introduces a tiered notification regime requiring LFIs to promptly notify the CBUAE of material Operational Risk events affecting Critical Operations.
The required timelines are:
- Within 4 hours: notify the CBUAE of the event, including which Critical Operations are affected;
- Within 24 hours: provide the CBUAE with a summary report of the nature of the event, the actions being taken, the likely impact, and the expected recovery timeframe; and
- Within 72 hours: notify the CBUAE of any high-risk Incident, in accordance with Board-approved classification criteria.
5. Outsourcing and change management
LFIs must retain sufficient in-house expertise and oversight and cannot rely excessively on outsourcing. The CBUAE may require the termination of third-party arrangements, or Critical Operations that are overly dependent on them, where it considers this necessary.
For material changes to Critical Operations, LFIs must notify the CBUAE at least 30 calendar days before implementation, provide an external expert's report and obtain the CBUAE's written no-objection before proceeding.
What should LFIs do now?
Institutions should act promptly. In particular, we recommend:
- Identifying and mapping Critical Operations, including the people, technology, data and third-party dependencies required to support them;
- Reviewing governance arrangements to ensure Board oversight and accountability align with the Regulation;
- Assessing data localisation and outsourcing arrangements, including compliance with CBUAE requirements and any activities requiring regulatory no-objection; and
- Updating incident escalation procedures to meet the new notification timelines.
How can we help?
Our financial services regulatory team advises banks, insurers and other financial institutions on regulatory compliance, operational resilience programmes, governance and risk management frameworks, outsourcing arrangements and regulatory engagement with the CBUAE. We can support institutions in conducting gap analyses, reviewing critical operations mapping, assessing data localisation requirements and developing practical implementation strategies to meet the Regulation's requirements. Please reach out to our international banking and finance team for specific queries or advice.