The Central Bank of the UAE (CBUAE) overhauled operational risk requirements for financial institutions, introducing stricter incident reporting timelines, mandatory resilience testing and greater accountability for senior management.
The new Operational Risk Management Regulation, C 1/2026, came into effect on September 14. It applies to all licensed financial institutions that are juridical persons and replaces the earlier operational risk framework issued in 2018.
One of the most significant changes is the introduction of a four-hour reporting deadline. Financial institutions must notify the CBUAE within four hours if an operational risk event significantly affects, or could significantly affect, the continuity or integrity of critical operations. The notification must identify the critical operations affected.
A summary report must follow within 24 hours. It must outline the nature of the incident, steps being taken, likely impact, and expected timeline for restoring normal operations.
Institutions must also notify the regulator within 72 hours of high-risk incidents based on board-approved classification criteria.
The new framework places technology and cybersecurity risks firmly within operational risk management. Financial institutions must establish systems to identify, assess, monitor and mitigate operational risks across their businesses, including risks linked to third-party service providers.
The regulation also requires institutions to maintain an adequately resourced and sufficiently independent operational risk function. The chief risk officer will be responsible and accountable for the function, which must report its findings and recommendations regularly to the board.
Also Read: OpenAI Acquires Glass Imaging in USD 300 Million Deal