

The Central Bank of the UAE introduced tighter operational-risk rules for financial institutions, placing greater emphasis on resilience, cybersecurity, incident reporting, and fraud prevention. The new Operational Risk Management Regulation, C 1/2026, came into force on September 14, 2026. It applies to all licensed financial institutions with legal personality and replaces the earlier 2018 operational-risk framework.
One of the major changes is faster reporting of serious disruptions. Financial institutions must notify the Central Bank within four hours when an incident has, or could have, a significant impact on critical operations.
A brief report should be filed within 24 hours. It should explain the nature of the incident, actions taken, potential impact, and expected recovery timeline. Institutions must also notify the regulator when normal operations resume. High-alert incidents must be reported within 72 hours under the institution’s incident-classification framework.
The move gives regulators earlier visibility into disruptions that could affect customers or financial stability.
The regulation requires financial institutions to establish a robust ICT and cybersecurity risk framework. This must cover risk assessment, mitigation, incident response, recovery, change management, patch management and ongoing monitoring.
Boards and senior management must receive regular information about cybersecurity exposures, incidents and weaknesses identified through testing. Institutions must also maintain systems that protect data integrity, confidentiality and availability during both normal operations and periods of stress.
Also Read: Cybersecurity, Resilience in Focus as UAE Central Bank Revamps Operational Risk Rules