The Central Bank of the UAE has introduced a new regulatory framework requiring licensed financial institutions to strengthen how they prepare for and respond to operational disruptions, cyber incidents, fraud and failures affecting critical financial services.
The Operational Risk Management Regulation, C 1/2026, came into force on September 14, 2026. It applies to licensed financial institutions and establishes minimum requirements for managing operational risk and operational resilience.
The regulation replaces the Central Bank’s previous 2018 Operational Risk Regulation and related standards. Its scope goes beyond conventional banking-system failures, covering risks involving people, processes, technology, data, facilities and third-party service providers.
Banks must prepare for disruption, not simply recover from it
One of the central requirements is operational resilience — the ability of a financial institution to continue delivering critical operations during a disruption.
Financial institutions must identify their critical operations and map the resources needed to keep them functioning. These include people, technology, processes, data, facilities and third-party providers.
The Central Bank specifically identifies the continued operation of payment systems, payment services and other time-sensitive customer services as critical operations. Institutions must also be able to maintain accurate financial records and manage their liquidity and solvency during periods of disruption.
This means resilience planning must cover the full chain supporting essential banking services rather than focusing solely on individual IT systems.
Cybersecurity and incident response receive greater emphasis
The new framework requires licensed financial institutions to maintain a robust ICT and cybersecurity risk-management framework.
That framework must cover risk identification, mitigation, monitoring and testing, while institutions must maintain systems capable of protecting the integrity, confidentiality and availability of their information and technology infrastructure.
Financial institutions are also required to maintain incident-response and recovery plans for disruptions, including cybersecurity incidents.
The Central Bank requires these plans to be regularly reviewed and tested. Institutions must investigate the root causes of material incidents and take steps to reduce the likelihood of similar incidents happening again.
Fraud risks form part of operational risk management
Fraud is also explicitly included within the operational-risk framework.
The regulation requires licensed financial institutions to address internal and external fraud risks, including incidents or ongoing threats that affect customers.
The Central Bank’s wider regulatory framework separately requires licensed financial institutions to maintain mechanisms designed to prevent and detect unauthorised transactions, social engineering, identity theft and other fraudulent activity.
The Central Bank has also been strengthening its wider anti-fraud infrastructure. Its 2025 annual report said it had begun establishing the Central Bank Anti-Fraud Operations Center (CAFOC) as a central operational and intelligence hub for monitoring fraudulent activity and coordinating responses with financial institutions and other stakeholders.
Business continuity plans must be tested
The new regulation places specific requirements on business continuity and disaster recovery.
Licensed financial institutions must maintain plans covering critical operations and test them regularly. For critical operations, the plans must be reviewed and tested at least annually, including relevant third-party service providers where appropriate.
The plans must also establish measurable recovery targets and define when they should be activated. Institutions are expected to test their ability to operate under severe but plausible disruption scenarios.
Third-party technology providers are also covered
The rules recognise that financial institutions increasingly depend on external technology and service providers.
Under the new framework, institutions must assess third-party risks and conduct due diligence before entering relevant arrangements. Where an external provider supports critical operations, the financial institution must verify that the provider has an appropriate level of operational resilience.
This is particularly relevant to digital banking services that depend on interconnected technology, cloud infrastructure, payment systems and other external providers.
Greater responsibility for boards
The regulation also places ultimate responsibility for operational risk management on the board of the financial institution.
Boards must approve and review key operational-risk and resilience strategies and policies at least annually, including the institution’s risk appetite and tolerance for disruption.
The framework therefore treats operational resilience as a governance issue rather than solely an IT or cybersecurity function.
For UAE customers, the practical objective is straightforward: financial institutions should be better prepared to keep essential services operating, respond faster when disruptions occur and limit the impact of fraud, cyber incidents and other operational failures.
The new regulation is now in force as of September 14, 2026.
What are the new UAE Central Bank rules?
The Central Bank’s Operational Risk Management Regulation C 1/2026 establishes minimum requirements for licensed financial institutions to manage operational risk and maintain resilience during disruptions. It took effect on September 14, 2026.
Who is affected by the new UAE banking rules?
The regulation applies to licensed financial institutions that fall within its scope, rather than only traditional banks.
What do the rules say about banking outages?
Financial institutions must identify critical operations and maintain plans to continue or restore them during disruption. Payment systems and other time-critical customer services are specifically included among critical operations.
Do the new rules cover cyberattacks?
Yes. Financial institutions must maintain ICT and cybersecurity risk frameworks, including measures for protection, detection, response and recovery, with regular testing.
Do the rules address banking fraud?
Yes. Internal and external fraud risks must be managed as part of the operational-risk framework.
Are third-party technology providers covered?
Yes. Financial institutions must assess and manage third-party risks, with additional resilience expectations where providers support critical operations.
When did the new regulation take effect?
The Operational Risk Management Regulation C 1/2026 came into force on September 14, 2026.
What does this mean for UAE banking customers?
The rules are intended to strengthen financial institutions’ ability to maintain critical services and respond to disruptions, cyber incidents and other operational risks. The regulation does not mean customers should expect banking outages; rather, it sets requirements for institutions to prepare for and manage them.

