OUT-LAW NEWS 2 min. read

UAE financial institutions face tougher resilience and outsourcing requirements under new rules

Dubai International Financial District skyscrapers at sunset

The regulation is relevant to banks, insurers, reinsurers and other regulated institutions. Oksana Chaun/iStock


regulation represents a substantial evolution in the UAE's prudential framework and brings the Central Bank of the UAE's (CBUAE) expectations closer to leading international approaches to operational resilience and operational risk management, experts have said.

Marie Chowdhry and Jessa White, financial regulation experts at Pinsent Masons, were commenting on the CBUAE’s new Operational Risk Management Regulation. The new regulation introduces a comprehensive framework for operational risk and operational resilience across all licensed financial institutions in the UAE.

The regulation also requires firms to define board-approved "tolerance for disruption" levels for critical operations and to test their ability to operate within those tolerances under severe but plausible scenarios.

“The regulation is relevant to banks, insurers, reinsurers and other CBUAE-regulated financial institutions and is likely to drive significant operational resilience, governance and technology-related compliance activity across the UAE financial services sector”, said Chowdhry.

The regulation replaces the previous operational risk regime, introduced in 2018, and reflects the increasing regulatory focus on operational resilience, cyber security, third-party risk management and governance of critical business functions which may have been driven as a result of the Middle East conflict which kicked off in February.

The new framework under the regulation significantly expands regulatory expectations beyond traditional operational risk management. Financial institutions are now expected not only to identify, assess and mitigate operational risks, but also to maintain the resilience of their critical operations during periods of disruption. The regulation introduces detailed requirements around identifying and mapping critical operations and their supporting assets; maintaining business continuity and disaster recovery plans; managing operational incidents; and overseeing third-party service providers whose services support critical functions.

Chowdhry said: “Regulated financial institutions will need to identify critical operations, map the people, systems, data and third-party providers supporting those operations, and demonstrate their ability to continue delivering them during periods of disruption. The emphasis on operational resilience reflects a broader shift away from focusing solely on preventing disruptions towards ensuring firms can withstand and recover from them.

“The outsourcing and third-party risk provisions are also noteworthy. Firms should assess existing outsourcing arrangements, governance structures and contractual frameworks to determine whether additional controls, reporting mechanisms and contingency planning are required. The ongoing requirement that firms obtain a no-objection from the CBUAE before outsourcing activities that could materially affect critical operations remains in place and should always be factored into implementation timelines for strategic projects.”

The regulation also places considerable emphasis on governance and accountability. Boards of directors are given ultimate responsibility for operational risk and resilience frameworks, while senior management must ensure those frameworks are effectively embedded across the organisation. New requirements also address ICT and cybersecurity risk management, including expectations around testing, incident response, cyber resilience and data governance. Notably, the regulation requires an institution's ‘Master System of Record’ to be maintained within the UAE, including where services are outsourced.

In addition, the CBUAE has introduced prescriptive incident reporting obligations, including requirements to notify the regulator of significant operational risk events affecting critical operations within specified timeframes. The regulation also strengthens oversight of outsourcing arrangements.

White said: “The enhanced incident reporting obligations, including a four-hour notification timeline for significant operational risk events affecting critical operations, underscore the importance of robust incident response and escalation procedures. Boards and senior management should ensure governance frameworks, reporting lines and operational resilience testing programmes are sufficiently developed to meet the new expectations.”

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.