The Central Bank of the United Arab Emirates (UAE) has introduced a new Operational Risk Management Regulation that came into effect on Monday, aiming to enhance the resilience and continuity of services provided by banks and licensed financial institutions. The updated framework replaces the previous standards set in 2018 and addresses growing concerns around technology failures, cyberattacks, fraud, system disruptions, and risks tied to third-party vendors.
The regulation is designed to safeguard customers as the use of digital channels—including mobile banking apps, instant transfers, digital wallets, and payment cards—continues to rise. Interruptions in service could prevent account access, delay transactions, or render payment cards unusable at critical times. To mitigate such risks, the regulation requires institutions to identify “critical operations” whose disruption could inflict significant harm on customers, the institution itself, or the broader financial system. These operations typically include transfers and payments, account access, salary processing, and the functioning of various card services.
Under the new rules, banks and financial institutions must establish defined disruption tolerance levels for each critical operation. These levels specify the maximum allowable duration of an interruption and the acceptable impact threshold. This represents a shift from merely having recovery plans to demonstrating the ability to maintain or promptly restore essential services within predefined timeframes and impact limits.
Responsibility for managing operational risk and ensuring resilience is explicitly placed on the institution’s board of directors, which must approve relevant strategies, policies, and risk appetites. Senior management is tasked with implementing these strategies and ensuring the availability of appropriate systems, resources, and qualified personnel. This approach moves risk management beyond technical teams, emphasizing its strategic importance.
The regulation also clarifies that outsourcing does not absolve institutions of their accountability. Even when operations are delegated to technology providers, cloud services, or payment processors, the financial institution remains responsible for the continuity and security of its services.
In addition, the regulation enforces strict reporting requirements for operational disruptions. If an event occurs—or is likely to occur—that significantly affects critical operations, institutions must notify the Central Bank within four hours, specifying the operations involved. A brief report detailing the incident, mitigation efforts, potential impacts, and recovery timelines is required within 24 hours. Notification is also mandated once normal operations resume and for any high-severity incidents within 72 hours.
The regulation reinforces the established principle of the three lines of defence within financial institutions: business units manage risks daily; risk management and compliance functions provide independent oversight; and internal audit offers assurance on the overall effectiveness of risk management.
Financial institutions must also maintain an independent operational risk management function, typically led by a Chief Risk Officer, and implement comprehensive ICT and cybersecurity frameworks. These frameworks must cover risk identification, mitigation, incident response, and recovery, including regular testing of business continuity and disaster recovery plans against severe but plausible scenarios.
While the new regulation is expected to reduce the likelihood and duration of service disruptions, accelerate recovery times, and strengthen data protection, it does not guarantee the complete elimination of such events, nor does it automatically create a right to compensation for all service interruptions.
