Cybersecurity, Resilience in Focus as UAE Central Bank Revamps Operational Risk Rules

The UAE Central Bank has tightened operational risk rules, requiring four-hour incident reporting, independent penetration tests, stronger cyber controls and greater board-level accountability across licensed financial institutions.
Cybersecurity, Resilience in Focus as UAE Central Bank Revamps Operational Risk Rules
Written By:
Published on

The Central Bank of the UAE (CBUAE) overhauled operational risk requirements for financial institutions, introducing stricter incident reporting timelines, mandatory resilience testing and greater accountability for senior management.

The new Operational Risk Management Regulation, C 1/2026, came into effect on September 14. It applies to all licensed financial institutions that are juridical persons and replaces the earlier operational risk framework issued in 2018.

Four-Hour Deadline for Critical Incidents

One of the most significant changes is the introduction of a four-hour reporting deadline. Financial institutions must notify the CBUAE within four hours if an operational risk event significantly affects, or could significantly affect, the continuity or integrity of critical operations. The notification must identify the critical operations affected.

A summary report must follow within 24 hours. It must outline the nature of the incident, steps being taken, likely impact, and expected timeline for restoring normal operations.

Institutions must also notify the regulator within 72 hours of high-risk incidents based on board-approved classification criteria.

Cybersecurity at Focus

The new framework places technology and cybersecurity risks firmly within operational risk management. Financial institutions must establish systems to identify, assess, monitor and mitigate operational risks across their businesses, including risks linked to third-party service providers.

The regulation also requires institutions to maintain an adequately resourced and sufficiently independent operational risk function. The chief risk officer will be responsible and accountable for the function, which must report its findings and recommendations regularly to the board.

Also Read: OpenAI Acquires Glass Imaging in USD 300 Million Deal

Analytics Insight UAE: Top Tech News Website in UAE, Dubai & Middle East
www.analyticsinsight.ae