The Central Bank of the UAE (CBUAE), through Notice No. CBUAE/BIS-RD/2026/4047 dated 24 July 2026, has communicated the Operational Risk Management Regulation issued under Circular No. 1/2026. Applicable to Licensed Financial Institutions (LFIs), the Regulation establishes minimum requirements for managing Operational Risk and strengthening Operational Resilience across the UAE financial sector.
For UAE financial institutions, the Regulation represents more than an update to operational risk requirements. The fundamental shift is from demonstrating that controls exist to demonstrating that Critical Operations can continue through disruption within defined tolerances.
This brings governance, technology, cybersecurity, business continuity and third-party dependencies into a more connected approach to resilience.
LFIs must establish an appropriate Operational Risk management framework covering the identification, assessment, evaluation, monitoring, reporting and mitigation of Operational Risk. Importantly, this framework must be fully integrated into the institution's broader risk management and governance framework.
This encourages institutions to view resilience as a connected system rather than a collection of individual controls. A weakness in people, processes, technology, data or an external provider can ultimately affect an entire Critical Operation.
The question is therefore not simply whether individual controls are working, but whether the institution can respond, adapt and recover while continuing to deliver its most important services.
The Regulation places clear accountability at Board and Senior Management level. The Board retains ultimate responsibility for ensuring an adequate Operational Risk management framework is established and incorporates Operational Resilience. It must also approve and review, at least annually, key strategies and policies, including Risk Appetite and tolerance for disruption.
Senior Management is responsible for translating the framework into effective policies, processes, controls and systems.
For Boards, the challenge is moving beyond conventional operational risk metrics towards information that demonstrates whether Critical Operations can remain within tolerance during disruption. Operational Resilience therefore becomes an enterprise-wide governance priority.
A defining requirement is the identification and mapping of Critical Operations and the resources required to deliver them.
LFIs must consider people, technology, processes, data, facilities, third-party service providers, intragroup entities and the interconnections and interdependencies between them.
This should extend beyond creating another process inventory. Effective mapping can reveal concentration risks, hidden dependencies and points of vulnerability where the failure of one component could affect an important financial service.
The key management question becomes: Can we continue delivering our Critical Operations within our approved tolerance for disruption when a critical dependency fails?
Operational Resilience is increasingly difficult to separate into technology, cybersecurity and business continuity disciplines. Restoring an individual system does not necessarily mean the underlying Critical Operation has recovered.
The Regulation requires appropriate ICT and cybersecurity risk management capabilities, supported by protection, detection, response and recovery programmes.
It also contains an important UAE-specific requirement: an LFI's Master System of Record must be continuously maintained and stored within the UAE, including where activities are outsourced, subject to specific provisions for branches of foreign financial institutions and CBUAE approval.
Business Continuity and Disaster Recovery Plans must connect to Critical Operations mapping, with plans and procedures tested regularly and at least annually for Critical Operations.
The practical implication is clear: technology recovery alone does not demonstrate resilience if the end-to-end Critical Operation cannot be restored within acceptable limits.
LFIs must maintain a Board-approved strategy for managing third-party risk and undertake appropriate risk assessments and due diligence. Where an arrangement relates to or affects Critical Operations, the LFI must verify that the provider has at least an equivalent level of Operational Resilience.
Viable contingency and exit plans are also required for third-party arrangements material to Critical Operations.
As financial institutions become increasingly dependent on external technology and specialist providers, the principle is straightforward: outsourcing a service does not outsource responsibility for resilience.
For Operational Risk events that significantly impact, or may significantly impact, the continuity or integrity of Critical Operations, LFIs must notify the CBUAE within four hours, identifying the affected Critical Operations. A summary report must follow within 24 hours, covering the event, actions being taken, likely impact and expected timeframe for returning to normal operations.
Meeting these timelines requires tested escalation pathways, clear decision rights and reliable information, not simply documented incident procedures.
The Regulation replaces the previous 2018 Operational Risk Regulation and Standards and will take effect one month from its publication in the Official Gazette.
For UAE financial institutions, CBUAE Notice No. 4047/2026 provides an opportunity to look beyond compliance and test whether resilience works in practice. Three questions should focus Board and management attention: Do we understand what must continue? Do we know what could prevent it from continuing? Can we demonstrate that our response works under pressure?
Effective Operational Risk management is increasingly measured not simply by the controls an institution has in place, but by its ability to maintain critical financial services when its people, systems or providers are under pressure.
In an increasingly interconnected financial system, Operational Resilience is not simply about recovering from disruption. It is about protecting customers, maintaining trust and ensuring that critical financial services remain available when they are needed most.
The author is Director – GRC Advisory at Crowe UAE and can be reached at +971 52 373 4662 or [email protected].