15 September 2026Established 2026 · English edition
MENA ReviewWhat the regulators published

GazetteRecord

UAE Central Bank issues operational risk regulation C 1/2026

Regulation effective September 14, 2026 sets cybersecurity and incident reporting requirements for licensed financial institutions.

Geometric pattern showing interconnected security framework structuresPhotograph by Anni Roenkae on Pexels

The Central Bank of the UAE issued Regulation No. C 1/2026 on operational risk management, effective September 14, 2026. The regulation applies to licensed financial institutions with legal personality and establishes minimum requirements for operational risk management and operational resilience. It cancels Circular No. 163/2018 concerning the Operational Risk Management Regulation along with its accompanying standards. Circular 163/2018 was introduced approximately eight years prior to the new regulation.

Three lines of defence structure#

Financial institutions must maintain three lines of defence under the regulation. Business units form the first line and must continuously identify and control risks. Risk management and compliance functions constitute the second line, providing independent oversight and challenging decisions made by business units. Internal audit forms the third line, delivering independent assurance regarding the effectiveness of risk management frameworks and control systems. Institutions must establish a standalone operational risk management function with sufficient resources, led by the Chief Risk Officer. The CRO's duties cover forming an independent assessment of material risks, evaluating how well internal controls function, examining the operational risk profile, pinpointing threats and vulnerabilities that affect critical operations, and delivering training while building risk awareness.

ICT and cybersecurity framework obligations#

The regulation requires financial institutions to implement an ICT and cybersecurity risk framework. Required elements are identifying and assessing risk, implementing mitigation measures, responding to and recovering from incidents, managing change, handling data and technology services, managing patches, and maintaining business continuity and disaster recovery plans. Institutions must review these frameworks regularly to ensure alignment with industry standards, best practices, and new and emerging threats. The framework addresses risks arising from digital transformation, reliance on technology and third-party service providers, cyber threats and interconnections between financial institutions and digital infrastructure.

Authority and additional requirements#

The Central Bank retains authority to impose additional requirements on institutions when deemed necessary. The regulator may issue further standards or detailed guidelines under the regulation. The regulation is not limited to banks and extends to all licensed financial institutions with legal personality.

Sources1 source across 1 domain

  1. gulfnews.comGulf NewsRegulation C 1/2026 effective September 14, 2026, applies to licensed financial institutions, requires three lines of defence, ICT and cybersecurity frameworks, cancels Circular 163/2018

Each source above carries the claim it supports. Links open the publisher's own page; their text is not reproduced here beyond what the claim requires, and their rights remain theirs.

Filed underoperational riskuae central bankcybersecurityfinancial regulationregulation c 1/2026ict risk

MENA Review is published by Arabian Media Network. Pieces are produced by the Gazette Desk with AI-assisted synthesis of the cited sources and automated verification against the network's editorial policy. Every piece carries a desk rather than a reporter. Corrections are recorded on the piece and on the corrections page.

More from the Gazette Desk

The desk