UAE · Central Bank of the United Arab Emirates

Central Bank of the UAE regulatory framework

Supervisory expectations for licensed financial institutions in the United Arab Emirates, covering information security, resilience and outsourcing.

Who it applies to

Banks, finance companies, payment service providers and other institutions licensed by the Central Bank of the United Arab Emirates.

What it requires

  • Board-level accountability for technology and cyber risk
  • Operational resilience, including tested continuity and recovery capability
  • Governance of outsourcing and third party dependencies
  • Incident reporting to the regulator within expected timeframes

What preparing for it involves

Financial supervision differs from certification in an important respect: the regulator is not a one-time examiner but a continuing supervisor. Preparation therefore emphasises evidence that governance operates continuously, and that the board is genuinely engaged rather than nominally informed.

How it concludes

Continuing supervisory compliance, examined through regulatory review rather than concluded by a certificate.

SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.

Cross-framework reuse

Control mappings for this framework are not yet published in the library. It is carried in full for assessment and preparation, and cross-framework reuse will follow as the mapping matures. We would rather state that plainly than imply reuse that does not exist.