Cybersecurity, GRC, Operational Risk and Operational Resilience Requirements

Banks and Licensed Financial Institutions (LFIs) operating in the UAE are subject to a comprehensive regulatory framework established by the Central Bank of the UAE (CBUAE).

CBUAE requirements address key areas including Governance, Risk and Compliance (GRC), Operational Risk, Operational Resilience, ICT and Cybersecurity, Information Assurance, Internal Controls, Business Continuity, Third-Party Risk and Outsourcing.

A major development is the CBUAE Operational Risk Management Regulation C 1/2026, effective from 14 September 2026, which establishes requirements for Operational Risk Management and Operational Resilience across applicable LFIs.

Financial institutions therefore need to consider cybersecurity, technology, resilience, third-party dependencies and internal controls as interconnected components of their overall regulatory compliance programme.

CBUAE Compliance Requirements for Banks and Licensed Financial Institutions in the UAE

1. Operational Risk Management

CBUAE requires LFIs to establish an appropriate Operational Risk Management Framework containing strategies, policies, procedures, systems, controls and processes to identify, assess, evaluate, monitor, report and control or mitigate Operational Risk.

The framework must be integrated into the institution’s broader risk-management and governance arrangements.

Key areas include:

  • Operational Risk governance
  • Risk identification and assessment
  • Risk and Control Self-Assessment (RCSA)
  • Risk Appetite and Risk Tolerance
  • Inherent and residual risk
  • Key Risk Indicators (KRIs)
  • Risk Limits and thresholds
  • Operational loss management
  • Control assessment
  • Risk monitoring and reporting
  • Risk treatment and mitigation
  • Three Lines of Defence
  • Internal and external fraud risk
  • Third-party dependencies

Official CBUAE Reference: CBUAE Article 2 – Operational Risk Management Framework

2. Operational Resilience

Operational Resilience focuses on an LFI’s ability to continue delivering Critical Operations during disruptive events.

CBUAE requires LFIs to identify their Critical Operations and understand the assets and dependencies required to deliver those operations.

This includes dependencies on:

  • People
  • Technology
  • Processes
  • Data
  • Facilities
  • Third-Party Service Providers
  • Intragroup arrangements

LFIs should establish appropriate tolerance for disruption and maintain arrangements to respond to, adapt to, recover from and learn from operational disruptions.

This should be supported by Incident Response, Business Continuity and Disaster Recovery capabilities.

Official CBUAE Reference: CBUAE Article 3 – Operational Resilience

3. ICT and Cybersecurity Risk Management

Cybersecurity is explicitly incorporated into CBUAE’s Operational Risk and Operational Resilience framework.

LFIs must establish a robust ICT and cybersecurity risk-management framework addressing the identification, assessment, mitigation, monitoring and testing of ICT and cybersecurity risks.

Key areas include:

  • ICT and cybersecurity risk assessment
  • Cybersecurity governance
  • Access control and identity management
  • Critical Information Asset protection
  • Network security
  • Vendor security
  • Physical and environmental security
  • Vulnerability management
  • Information classification
  • Data management
  • Patch management
  • ICT operations
  • Change management
  • Cybersecurity monitoring
  • Cyber threat and vulnerability intelligence
  • Incident response and recovery
  • Business Continuity and Disaster Recovery
  • Secure systems development and acquisition
  • Technology lifecycle management

Cybersecurity risk and resilience must also be reflected within the LFI’s Risk Appetite and Tolerance.

LFIs must maintain appropriate ICT and cybersecurity infrastructure under normal and stressed conditions and proactively manage obsolete or unsupported technologies.

Official CBUAE Reference: CBUAE Article 8 – ICT and Cybersecurity Management

4. UAE Information Assurance Requirements

UAE Information Assurance requirements form another important part of the cybersecurity regulatory landscape.

Applicability should be determined based on the institution’s licence, activities and applicable national and sector-specific requirements rather than assuming that every UAE IA requirement automatically applies to every CBUAE-regulated LFI.

For example, CBUAE explicitly requires Payment Service Providers to meet applicable UAE Information Assurance requirements as a minimum cybersecurity baseline.

Relevant Information Assurance areas can include:

  • Information-security governance
  • Information-security risk management
  • Asset management
  • Access control
  • Information classification
  • Human-resource security
  • Physical and environmental security
  • Network and communications security
  • Secure operations
  • Vulnerability management
  • Incident management
  • Business Continuity
  • Third-party security
  • Compliance monitoring

Banks should also consider UAE Information Assurance requirements in the outsourcing context. CBUAE requires outsourcing agreements to establish data-protection standards that include nationally recognised information-assurance standards in the UAE.

Official CBUAE Reference: CBUAE Technology Risk and Information Security Requirements

Bank Outsourcing Reference: CBUAE Article 5 – Outsourcing Agreements

The remaining regulatory requirements will be covered in Part 2 of this article.

An Integrated Approach to CBUAE Compliance

CBUAE compliance should not be approached as a collection of isolated regulatory exercises.

Operational Risk, Cybersecurity, Operational Resilience, Business Continuity, Third-Party Risk, Information Assurance, Internal Controls and Compliance are interconnected.

For example, a Critical Operation delivered through a third-party cloud provider may simultaneously introduce:

Operational Risk → Cybersecurity Risk → Third-Party Risk → Data Risk → Business Continuity Risk → Operational Resilience Risk → Regulatory Compliance Risk

An integrated GRC approach enables financial institutions to map overlapping regulatory requirements to common controls, reduce duplication and establish a consolidated view of regulatory risk.

A structured assessment can follow:

CBUAE Requirement → Applicability → Existing Control → Compliance Status → Gap → Risk → Recommendation → Remediation → Evidence → Validation → Closure.

 

How MAST Consulting Can Support Banks and LFIs

MAST Consulting supports banks and Licensed Financial Institutions in understanding, assessing and addressing applicable CBUAE cybersecurity, GRC, Operational Risk and Operational Resilience requirements.

Our support can cover the complete compliance lifecycle, from initial regulatory applicability and gap assessment through framework development, implementation, independent assessment, remediation and readiness for regulatory or internal assurance activities.

MAST Consulting’s services include:

  • CBUAE Regulatory Gap Assessment
  • Cybersecurity and ICT Risk Assessment
  • UAE Information Assurance Gap Assessment
  • Operational Risk Management Assessment
  • RCSA and Risk Register Development
  • Operational Resilience Assessment
  • Critical Operations and Dependency Mapping
  • Risk Appetite, Risk Tolerance and KRI Development
  • Vulnerability Assessment and Penetration Testing
  • Cyber Incident Response and Readiness Assessment
  • Business Continuity and Disaster Recovery Assessment
  • Third-Party Risk Management
  • Vendor Cybersecurity Assessment
  • Outsourcing Compliance Assessment
  • Cloud and Technology Risk Assessment
  • System Migration Assurance
  • Internal Control Assessment and Testing
  • Compliance and Internal Audit Support
  • Policy and Procedure Development
  • Regulatory Remediation and Corrective Action Support
  • Board and Management Risk Reporting
  • Compliance Evidence and Audit Readiness

Rather than treating each CBUAE requirement separately, MAST Consulting can develop a consolidated regulatory control framework that maps applicable CBUAE and UAE Information Assurance requirements against the organization’s existing controls.

This approach helps reduce duplicated assessments, identify common control gaps and create a prioritized compliance roadmap.

CBUAE Compliance Gap Assessment

A CBUAE compliance engagement can begin with a comprehensive gap assessment covering the applicable regulatory requirements based on the institution’s licence, activities, technology environment and third-party dependencies.

The assessment can provide management with a clear view of:

What applies to us? → What controls do we already have? → Where are the gaps? → What are the risks? → What needs to be implemented? → What evidence is required? → How do we demonstrate compliance?

The resulting remediation roadmap can identify responsible owners, priorities, timelines, required controls and evidence necessary to demonstrate compliance.

Strengthen Your CBUAE Compliance Programme

As CBUAE regulatory expectations continue to evolve, banks and Licensed Financial Institutions need to demonstrate that cybersecurity, Operational Risk, Operational Resilience and regulatory compliance are embedded within their overall governance and risk-management environment.

MAST Consulting helps financial institutions translate regulatory requirements into practical controls, measurable risk-management processes and sustainable compliance programmes.

Whether your organization requires a targeted cybersecurity assessment, UAE IA assessment, Operational Resilience review, outsourcing assessment or a comprehensive CBUAE GRC gap assessment, MAST Consulting can provide independent support across the compliance lifecycle.

Looking for CBUAE compliance consulting in the UAE?

Contact MAST Consulting to discuss a CBUAE Cybersecurity, GRC, Operational Risk, Operational Resilience or Information Assurance assessment.

Contact Us for More details