2026-07-27
Added · Updated
The Central Bank of the UAE establishes minimum requirements for Licensed Financial Institutions to implement a comprehensive framework for managing operational risk and operational resilience. The regulation mandates the integration of operational risk strategies with the institution's broader governance, risk appetite, and capital strength, requiring regular reviews and updates. It defines key terms such as critical operations, incidents, and third-party risk, and outlines specific obligations for the Board of Directors, senior management, and control functions. The document further details requirements for internal controls, ICT and cybersecurity management, incident reporting, business continuity planning, and disclosure obligations.