Preparing only what matters to you
whatmatters.ae

New UAE Central Bank Rules Target Outages, Fraud and Cyberattacks

New UAE Central Bank Rules Target Outages, Fraud and Cyberattacks
New UAE Central Bank Rules Target Outages, Fraud and Cyberattacks

By Thasmiya

The UAE Central Bank has introduced new rules aimed at making the country’s financial sector better prepared for bank outages, cyberattacks, fraud and other disruptions that could affect customers.

The new **Operational Risk Management Regulation**, issued by the ⁠Central Bank of the UAE (CBUAE), came into force on **September 14, 2026** and applies to licensed financial institutions covered by the regulation.

The rules require financial institutions to strengthen how they identify operational risks, protect critical services and recover when something goes wrong.

## **Why has the UAE introduced the new rules?**

Banking in the UAE has become increasingly digital.

Customers now depend on mobile banking apps, instant transfers, digital cards, online payments and other technology-driven financial services every day.

That convenience also means technology failures can have a greater impact. A cyberattack, system outage, fraud incident or failure involving an external technology provider could potentially prevent thousands of customers from accessing important financial services.

The CBUAE says licensed financial institutions must now maintain comprehensive frameworks covering both **operational risk and operational resilience**.

## **Banks must keep critical services running**

One of the most important parts of the regulation is the requirement for financial institutions to identify their **critical operations**.

These include the continued operation of payment systems and payment services, maintaining accurate customer financial records, and the institution’s ability to monitor its own liquidity, solvency and material risks.

Institutions must identify the people, technology, data, facilities, processes and third-party providers needed to keep these services functioning during a disruption.

In practical terms, banks cannot simply wait for an outage to happen and then decide how to respond.

They need plans in place beforehand.

## **Stronger protection against cyberattacks**

Cybersecurity is specifically addressed under the new regulation.

Financial institutions must maintain a robust ICT and cybersecurity risk framework covering risk identification, assessment, mitigation, monitoring and testing.

They must also proactively manage cybersecurity threats and maintain technology infrastructure capable of supporting their operations during both normal conditions and periods of stress.

This is particularly relevant as customers increasingly depend on mobile apps and online platforms to manage their money.

## **Banks must prepare for outages**

The rules also focus heavily on business continuity.

Institutions must maintain contingency arrangements covering their critical operations, including **incident response plans, business continuity plans and disaster recovery plans**.

These plans are intended to help financial institutions respond when important systems become unavailable and restore services as quickly as possible.

The regulation therefore covers more than cyberattacks. Technology failures, infrastructure problems, third-party disruptions and other events capable of interrupting financial services also fall within the broader operational resilience framework.

## **Fraud is also part of the new risk framework**

Financial institutions are required to address risks associated with both **internal and external fraud**, including incidents and ongoing threats affecting customers.

Separate provisions under UAE Central Bank law already require licensed financial institutions to maintain fraud-prevention and detection mechanisms covering risks including unauthorised transactions, social engineering and identity theft.

Institutions must also promptly inform affected customers about security breaches or fraudulent incidents and take corrective measures to limit damage.

## **What happens after a cyberattack or major incident?**

Banks and other affected financial institutions must have formal **Incident Response and Recovery Plans**.

These plans must specifically account for ICT and cybersecurity incidents.

Institutions are also required to regularly test and update their response plans. After a material incident, they must identify its root cause and introduce measures designed to prevent the same type of failure from happening again.

This creates a cycle of preparation, response, recovery and improvement rather than treating each outage as an isolated event.

## **Third-party technology providers are also important**

Modern financial institutions rely heavily on external companies for cloud services, payment technology, software, data processing and other infrastructure.

Under the new framework, institutions must map the third-party service providers involved in delivering their critical operations and understand the dependencies between those providers and their own systems.

This means outsourcing an important service does not remove the financial institution’s responsibility for operational resilience.

## **What does this mean for UAE bank customers?**

Customers do not need to register or apply for anything because of the new regulation.

The requirements are primarily directed at financial institutions.

However, customers could ultimately benefit from stronger systems designed to reduce the impact of outages, improve recovery after cyber incidents and strengthen protections around financial operations.

The rules are particularly significant for services people increasingly expect to work around the clock, including digital payments, transfers and access to accurate account information.

## **UAE is also strengthening its fight against financial fraud**

The operational resilience regulation forms part of a broader effort to strengthen the UAE financial system.

The CBUAE said in its 2025 annual report that it had begun establishing the **Central Bank Anti-Fraud Operations Center (CAFOC)**.

The centre is intended to become a central intelligence and operational hub supporting real-time fraud monitoring, incident response and collaboration between licensed financial institutions and relevant authorities.

The Central Bank has also been progressing its **Financial Institutions Resilience Package**, which is designed to strengthen resilience across the UAE financial sector.

## **When did the new rules take effect?**

The Operational Risk Management Regulation, identified as **C 1/2026**, came into force on **September 14, 2026**.

Its objective is to establish minimum requirements for licensed financial institutions in managing operational risk and operational resilience.

## **Why this matters**

Banking outages and cyber incidents can quickly affect everyday life when people depend on digital payments, cards and mobile banking.

The UAE Central Bank’s new framework requires financial institutions to think beyond simply preventing failures. They must also be prepared to continue critical services during disruption, recover effectively and learn from incidents afterwards.

For UAE customers, the goal is a financial system that is more resilient when technology, fraud or cyber threats put essential banking services under pressure.

## Related Reads - [UAE Visa Overstay Fines and Grace Period in 2026: What Residents and Visitors Need to Know](/post/uae-visa-overstay-fines-grace-period-2026-residents) - [UAE Work Permit Guide 2026: Rules, Costs, Types and Application Process](/post/uae-work-permit-guide-2026-rules-costs-types) - [What Is Not Allowed in the UAE? Important Rules Residents and Tourists Should Know](/post/not-allowed-uae-important-rules-residents-tourists-should) - [UAE Labour Law Explained: Leave, Gratuity and Resignation Rules](/post/uae-labour-law-explained-leave-gratuity-resignation-rules) - [More stories like this](/category/news)

What Matters — UAE news, events and guides