
New UAE Central Bank Rules Target Outages, Fraud and Cyberattacks
The UAE Central Bank’s new Operational Risk Management Regulation came into force on September 14, 2026, replacing previous standards from 2018 to establish a much stricter framework for banking continuity. Financial institutions must now maintain clear disruption tolerance levels and comprehensive contingency plans specifically designed to withstand technology failures, fraud, cyberattacks, and third-party service disruptions.
As mobile banking apps, digital wallets, instant transfers, and payment cards become the backbone of daily commerce, system outages carry immediate friction for account holders. The updated requirements force banks to look past basic IT disaster recovery and instead prove they can keep vital services running, or restore them rapidly, within pre-approved impact limits.
Critical Operations and Board Accountability
Institutions must now formally identify critical operations whose failure could harm customers or the wider financial system, covering core functions like account access, salary processing, fund transfers, and card operations. Responsibility for managing these risks sits squarely with executive leadership. The board of directors must approve risk appetites and resilience strategies, while senior management handles day-to-day execution.
The mandate extends deep into IT risk management, data protection, cybersecurity monitoring, and disaster recovery testing. Banks must manage the entire lifecycle of any technical incident, stretching from initial detection and containment to service recovery, root-cause analysis, and preventative updates. Furthermore, institutions must notify the UAE Central Bank promptly if they experience a major incident or significant compliance deviation, and they remain fully accountable for service security even when relying on third-party cloud or technology providers.
While the new rules aim to cut down the frequency and length of digital outages and improve defenses against cyber threats, they do not entirely eliminate the possibility of technical glitches, nor do they grant customers an automatic right to compensation for every service interruption.



