Tuesday, September 15, 2026

UAE Banking Risk Rules: Central Bank Tightens Measures to Prevent App and Card Disruptions

3 hours ago
4 mins read
UAE banking risk rules
FILE PHOTO: A man enters the main branch of UAE Central Bank in Abu Dhabi, January 29, 2013. REUTERS/Ben Job

The Central Bank of the UAE has introduced tougher operational risk and resilience requirements for financial institutions, putting greater emphasis on preventing disruptions to critical banking services.

The new UAE banking risk rules cover operational failures, cyber incidents, technology problems, fraud and risks arising from third-party service providers. The regulation took effect on September 14, 2026, replacing the Central Bank’s previous operational risk standards introduced in 2018.

For customers, the changes are particularly relevant as banking apps, payment systems and card services become increasingly important to everyday financial activity.

UAE banking risk rules focus on service continuity

The new regulation requires licensed financial institutions to establish comprehensive frameworks for managing operational risk and maintaining operational resilience.

The Central Bank defines operational resilience around an institution’s ability to continue delivering critical operations during disruptions, recover from problems and learn from disruptive events.

This means banks are expected to prepare for failures rather than simply respond after a disruption has already occurred.

Banking apps face greater resilience requirements

Mobile banking applications have become essential channels for customers to manage accounts and make payments.

A major technology failure can prevent customers from accessing their accounts, transferring funds or completing other financial transactions.

Under the new framework, banks must identify vulnerabilities affecting critical operations and maintain systems capable of responding to and recovering from disruptions. Their ICT and cybersecurity frameworks must also address risk identification, mitigation, incident management, response and recovery.

The objective is to make important digital banking services more resilient when technology problems occur.

Card and payment services are also covered

The Central Bank’s rules specifically identify the continued operation of payment systems, payment services and other time-critical customer services as critical operations that financial institutions must consider.

This brings payment disruptions into the wider operational resilience framework.

For customers, stronger resilience could help reduce the impact of problems affecting card payments, digital transfers and other time-sensitive financial services.

Cyberattacks are a major risk

Cybersecurity is another important part of the new requirements.

The regulation requires licensed financial institutions to maintain robust ICT and cybersecurity risk frameworks within their broader operational risk and resilience programmes. These frameworks must include measures for protecting systems, detecting threats, responding to incidents and recovering from disruptions.

Financial institutions must also regularly test their risk-mitigation measures and keep senior management informed about significant technology and cybersecurity exposures.

Banks must prepare for third-party failures

Banks increasingly rely on external technology and service providers for important parts of their operations.

A failure at an external provider can therefore affect a bank’s ability to deliver services to its customers.

The new UAE banking risk rules require institutions to consider risks associated with material products, activities, processes and systems, including those outsourced to or dependent on third-party service providers.

This makes third-party resilience an important part of the regulatory framework.

Faster reporting of serious disruptions

The new rules also introduce clear reporting requirements for significant operational risk events.

If an event significantly affects, or is likely to significantly affect, the continuity or integrity of critical operations, the financial institution must notify the Central Bank within four hours. A summary report must then be provided within 24 hours, covering the nature of the incident, actions being taken, likely impact and expected recovery timeframe.

High-risk incidents must also be reported within 72 hours under the regulation.

These requirements give the regulator greater visibility into major disruptions while they are still unfolding.

What the new rules mean for bank customers

Customers may not immediately notice the regulatory changes because much of the work will happen behind the scenes.

Banks will need to strengthen their risk-management systems, contingency plans, disaster recovery arrangements and incident-response procedures.

The intended result is greater reliability when customers use banking apps, payment services and other critical financial channels.

If a serious disruption occurs, institutions are expected to have plans for maintaining or restoring critical services.

Financial institutions must test their resilience

The new framework goes beyond simply creating policies.

Financial institutions must maintain incident-response, business-continuity and disaster-recovery arrangements for critical operations. These plans are intended to help institutions detect incidents, respond to them and restore important services following disruptions.

Regular testing is also required for ICT and cybersecurity risk controls.

This creates a more proactive approach to operational risk.

UAE strengthens its digital financial infrastructure

The new regulation reflects the growing importance of technology to the UAE’s financial sector.

As more customers use digital banking, payment cards and electronic payment services, the potential impact of technology failures also increases.

The Central Bank’s framework therefore focuses on ensuring that financial institutions can continue providing critical services even when they face significant operational challenges.

New regulation replaces 2018 standards

The new Operational Risk Management Regulation replaces Circular No. 163/2018, which introduced the previous Operational Risk Regulation and standards.

The updated framework brings operational risk and operational resilience together under a more comprehensive regulatory structure.

It also gives the Central Bank the ability to impose additional requirements where necessary and issue further standards or guidelines.

What banks need to do next

Licensed financial institutions will need to ensure that their operational risk frameworks comply with the new requirements.

This includes identifying critical operations, assessing vulnerabilities, setting risk limits, managing third-party risks, maintaining contingency arrangements and strengthening incident reporting.

Boards and senior management also have an important role in overseeing operational and technology risks.

The Central Bank requires senior leadership to receive regular information about ICT and cybersecurity exposures, incidents and weaknesses identified through testing and assessments.

Conclusion

The UAE’s tougher banking risk rules mark a significant move towards stronger operational resilience across the country’s financial sector.

By focusing on technology failures, cyberattacks, fraud, third-party risks and disruptions to critical payment services, the Central Bank is seeking to ensure that financial institutions are better prepared when problems occur.

For customers, the goal is ultimately greater reliability when using banking apps, payment cards and other digital financial services.

The new framework took effect on September 14, 2026, replacing the UAE’s previous 2018 operational risk standards and establishing new minimum requirements for operational risk management and resilience.

Categories

Previous Story

Abu Dhabi-Backed Alpha Wave Joins $1 Billion Adani Airports Investment

Syria economy reforms
Next Story

Syria Economy Reforms: Al-Sharaa Targets $200 Billion Economy With Regional Trade Push

Read Magazine