Rajeev Nanda

UAE CBUAE Regulations 2026

AML, Conduct Risk, Three Lines Model & GRC

Reading Time: 5 Minutes
Rajeev Nanda
7/9/2026
Rajeev Nanda

The Central Bank of the UAE (CBUAE), along with the Insurance Authority (now integrated under the CBUAE), continues to reinforce its regulatory expectations for financial institutions. As the regulatory landscape becomes more stringent, organizations across banking, insurance, and financial services must enhance their Governance, Risk, and Compliance (GRC) frameworks.

Key focus areas include the implementation of the Three Lines Model, effective management of conduct risk, robust AML/CFT controls, and strong model validation practices. Together, these elements form the foundation of a resilient and compliant financial ecosystem.

Three Lines Model: Enhancing Governance Structures

The Three Lines Model remains central to regulatory expectations in the UAE. It provides a structured approach to risk management and accountability:

  • First Line: Business units responsible for identifying and managing risks.
  • Second Line: Risk and compliance functions providing oversight and guidance.
  • Third Line: Internal audit ensuring independent assurance.

Regulators expect clear role definitions, independence between functions, and effective coordination. Any overlap or ambiguity can weaken governance and expose institutions to regulatory scrutiny.

Conduct Risk: Promoting Ethical Practices

Conduct risk has become a key priority for UAE regulators, emphasizing the need for ethical behavior and customer-centric practices. Financial institutions are expected to move beyond policy frameworks and actively embed a culture of integrity.

Core expectations include:

  • Transparent communication.
  • Fair treatment of customers.
  • Responsible sales practices.
  • Effective whistleblowing mechanisms.
  • Monitoring employee behavior and ensuring accountability at all levels.

A strong conduct risk framework not only supports compliance but also enhances customer trust and brand reputation.

AML/CFT Controls: Strengthening Financial Crime Prevention

AML and CFT compliance continue to be critical focus areas under CBUAE supervision. Institutions must adopt a risk-based approach aligned with UAE regulations and international standards such as FATF.

Key components of an effective AML/CFT framework include:

  • Comprehensive customer due diligence (CDD) and enhanced due diligence (EDD).
  • Ongoing transaction monitoring and timely suspicious activity reporting.
  • Sanctions screening and name filtering systems.
  • Regular training programs and independent audits.

Regulators are increasingly assessing the effectiveness and responsiveness of these controls, rather than their mere existence.

UAE CBUAE Regulations 2026

Model Validation: Managing Model Risk Effectively

With the increasing use of data analytics and automated decision-making, model risk management has gained significant importance. Financial institutions rely on models for credit assessment, risk measurement, and fraud detection.

The CBUAE expects institutions to implement:

  • Independent model validation processes.
  • Continuous performance monitoring and periodic recalibration.
  • Comprehensive documentation and governance frameworks.
  • Clear ownership and accountability for model risks.

Effective model validation ensures accuracy, reduces bias, and supports sound decision-making.

Aligning with Regulatory Expectations

To meet these evolving regulatory requirements, financial institutions must adopt a proactive and integrated approach to GRC. This includes strengthening internal controls, leveraging technology for monitoring, and conducting regular compliance assessments.

Board and senior management involvement is essential to ensure that risk management practices are embedded across the organization. Institutions that align early with regulatory expectations are better positioned to manage risks and sustain long-term growth.

Conclusion

The UAE regulatory environment continues to evolve, with increased emphasis on governance, transparency, and accountability. By strengthening the Three Lines Model, enhancing conduct risk frameworks, implementing effective AML/CFT controls, and ensuring robust model validation, financial institutions can meet regulatory expectations while building operational resilience.

Staying ahead in this landscape requires continuous improvement, strategic alignment, and a strong commitment to compliance excellence.

The author is Partner – Internal Audit & Governance Risk Compliance at Crowe UAE and can be reached at +971 52 373 4662 or [email protected]

Dawn Thomas
Dawn Thomas
Senior Partner - Governance Risk & Compliance
Ahmed Ali Bin Haider
Ahmed Ali Bin Haider
Partner - GRC Technology
Rajeev Nanda
Rajeev Nanda
Partner – Internal Audit & Governance Risk Compliance