Key takeaways (for fintech firms) from the CBUAE’s new Operational Risk Management Regulation
On 24 July 2026, the Central Bank of the UAE (CBUAE) issued Notice No. 4047/2026 (Public) to all Licensed Financial Institutions. The notice introduces a new Operational Risk Management Regulation that repeals the 2018 Operational Risk Regulation, which applied only to banks.
The notice sets a compliance timeline of one month, so here are some of the key aspects and themes of the new regulation that are critical for fintech firms who may be in a rush to implement it:
1. Not just for banks: Expanded perimeter to all Licensed Financial Institutions It would be imprecise to say that the UAE fintech space did not have to comply with operational risk management obligations before this new regulation. However, the the previous regime was very fragmented and not abundant in detail: Almost every sector-specific regulation, including the retail payment services regulation (RPSCS) and the Stored Value regulation, included sections pertaining to governance and risk management. The important change is not only that the perimeter of the operational risk regulation has been expanded, but also that there is now a consolidated bank-level set of regulatory expectations for all CBUAE licensees with regards to operational risk management. It will be interesting to see how the CBUAE will enforce this new regime alongside the sectorial regulatory frameworks (such as RPSCS) that will remain in force.
2. Data localization is the rule, with possible CBUAE-approved exemptions: In principle, the licensee’s collection of all data required to conduct critical operations including the provision of services to clients, managing all risks and complying with legal and regulatory requirements (the Master System of Record) must be kept and stored within the UAE. However, the new regulation explicitly opens the door for CBUAE-approved exemptions that allow branches of foreign entities to comply with this obligation by keeping up to date copies of the Master System of Record in the UAE. How the CBUAE will exercise this exemption remains to be seen, but the provision will be important for multinational groups that rely on data-processing and hosting infrastructure that is difficult to replicate in the UAE.
3. “Integration” is a key theme: Many sections of the regulation insist on the expectation that operational risk management arrangements are integrated with each other and with the overarching operational risk management framework. For example, cyber-security risk management arrangements should not be in a silo. This will require CROs and CISOs to become real partners in ensuring that their respective risk management arrangements are well articulated, for instance by ensuring that all operational risk subtypes (including cybersecurity and continuity risk) are assessed by using a consistent methodology set out in the firm’s risk management framework. The key challenge for CROs will be to identify any areas where certain risk subtypes are not managed in harmony with the overall risk management framework and set out actionable plans to achieve a more integrated approach.
4. “Tone from the top”: a new emphasis on board and senior management duties. A recurring theme in the new regulation is that boards and senior management are responsible and accountable for establishing sound operational risk management frameworks. Firms that have treated operational risk as a compliance-office exercise, or have relied on pro-forma policies with limited board engagement, may now be vulnerable to adversarial supervisory scrutiny. The regulation appears to embed the idea that boards should steward risk culture, while senior management should operationalize the framework in day-to-day business decisions. CROs should treat this as a training and governance challenge: how to ensure that the board and senior management understand their respective roles in the operational risk management framework.
5. A new focus on resilience: The new regulation puts a lot of emphasis on operational resilience, which seems to show the influence of recent DORA-like regulatory trends. In substance, the expectation is that licensees demonstrate the ability to keep their critical operations running in scenarios of severe but plausible operational disruptions. In turn, this requires firms to identify (and document) their key operations and functions and map them with the assets, processes, people and third parties that must be covered by continuity and disaster recovery planning. In other words, pro-forma BCPs and DRPs will not be enough: to withstand supervisory scrutiny, firms will need to show that continuity and recovery planning is anchored in the realities of their business.
6. Stricter notification requirements and timelines: The regulation introduces a four-hour timeline for notifying the CBUAE of an operational risk event that affects, or is likely to affect, critical operations or triggers business continuity or disaster recovery plans. This is followed by a summary report within 24 hours, covering root causes, estimated impact and actions taken. High-risk incidents, as defined in board-approved policies, must also be reported to the CBUAE within 72 hours. The practical challenge for risk managers will be calibrating high-risk and criticality thresholds so they are neither so high that they look like a device to avoid reporting, nor so low that they turn routine incidents into regulatory notifications.
7. Strict change management is now a must, and material changes require CBUAE non-objection. CBUAE licensees are expected to procure external experts to provide independent assurance at key steps in the change management process when introducing material changes to critical operations or to operations that may materially affect customers. Those reports must be submitted as part of a non-objection request to the CBUAE at least 30 calendar days before implementation. Risk managers will therefore need documented, actionable criteria for deciding what constitutes a notifiable material change that should be subject to external expert assurance.
8. Firm liability for change errors in the event of customer damage: If operational change results in any customer damage, licensees will be held liable. This creates an additional incentive to keep customers at the heart of change management processes. Risk managers should design these processes so that the risk of bad customer outcomes is identified, assessed and effectively mitigated before change implementation.
9. Notification of material third party arrangements: In this aspect, the CBUAE seems to be nodding directly to a policy position that is well established in the UK and Europe: A third-party arrangement that may impact critical operations should be submitted for regulatory scrutiny even if it does not fulfill the traditional definition of “outsourcing”. That is, regardless of whether it is a function or process that would normally be expected to be kept inhouse by the licensee. In practice, this means that “outsourcing ledgers” should now follow a criterion of materiality as opposed to simply focusing on the traditional definition of outsourcing. It is worth mentioning that this policy stance is somewhat of a reaction to the realization that certain critical services such as cloud hosting infrastructure cannot be reasonably expected to be maintained inhouse by all firms but could still result in severe business disruption if they fail. Therefore, the reasoning goes, they should be subject to special attention in firms’ resilience strategies as well as more proactive regulatory scrutiny.
10. Overall stricter rules on third party risk management: This includes obligations that are familiar in other jurisdictions such as ensuring that critical third-party vendors demonstrate a resilience posture at least equivalent to the LFI’s as well as the requirement to put in place robust outsourcing agreements with critical vendors, including (inter-alia) subcontracting clauses and ample CBUAE supervision stipulations.
11. Regular reporting on Internal Controls: The new regulation requires senior management to make a written assessment of the internal control environment and to present it to the board and the CBUAE. This is another example of the senior-management and board-involvement ethos mentioned in numeral 4 above. Operational risk management should not be treated as a back-office compliance exercise.
12. Public Disclosure of Operational Risk Management arrangements: Firms are now required to make appropriate disclosures about their operational risk management and resilience arrangements. This will require risk managers to develop documented criteria for deciding which aspects of the framework are suitable for public disclosure, which should be shared with key stakeholders such as customers, and which should remain confidential. Risk managers should conceive these disclosures as an opportunity to earn trust from customers and other key stakeholders by documenting the key aspects of their risk management arrangements in a very didactic manner.
The regulation is lengthy, and this note does not attempt to catalogue every requirement. However, the 11 themes above are sufficient indication that the CBUAE has materially raised its expectations for operational risk management. Given the one-month compliance timeline, CROs should start with a prioritized gap assessment and focus first on the foundations: identifying critical operations, mapping them to processes, people, assets and third parties, and testing whether governance and reporting lines can support timely escalation. The message is clear: operational risk management is now a very serious matter for all CBUAE licensees.
Disclaimer: This article does not constitute legal advice. The views expressed in this text are my own and do not represent the views of my employers or any other third party.