2026-07-27
Added · Updated
The Central Bank of the UAE establishes minimum requirements for Licensed Financial Institutions to implement a comprehensive framework for managing operational risk and operational resilience. The regulation mandates the integration of operational risk strategies with the institution's broader governance, risk appetite, and capital strength, requiring regular reviews and updates. It defines key terms such as critical operations, incidents, and third-party risk, and outlines specific obligations for the Board of Directors, senior management, and control functions. The document further details requirements for internal controls, ICT and cybersecurity management, incident reporting, business continuity planning, and disclosure obligations.
CBUAE published 1 document in the last 30 days — get each new one by email the day it lands.
CBUAE Classification: Public Operational Risk Management Regulation
CBUAE Classification: Public CONTENTS
Page Subject
مقدمـــة 3 Introduction
النطـاق 3 Scope
الهــدف 3 Objective
المادة )1( تعريفـــات 4 Definitions) 1 (Article Management Risk Operational المادة )2( إطار إدارة المخاطر التشغيلية 8 Framework Article (2) المادة )3( المـــرونة التشـــغيلية 10 Resilience Operational) 3 (Article
Article (4) Role of the Board of Directors 12 اإلدارة مجلس دور( 4 )المادة
Article (5) Role of Senior Management 14 العليا اإلدارة دور( 5 )المادة
Management Risk Operational المادة )6( وظيفة إدارة المخاطر التشغيلية 16 Function Article (6) المادة )7( نظــام الضــبط الداخــلي 17 System Control Internal) 7 (Article ICT and Cybersecurity Management Article (8) المادة )9( إدارة الحوادث 24 Management Incident) 9 (Article
Article (10) Risk Data and Systems 26 المخاطــر ونظــم بيانات( 10 )المادة
Business Continuity
Planning Article (11) and Management Change المادة )12( إدارة التغيير والتغييرات في العمليات 29 Changes in Operations Article (12) Third Party Risk Management Article (13) Compliance-Non ah’Shari المادة )14( مخاطر عدم االمتثال ألحكام الشريعة 34 Risk Article (14) Reporting and Notification المادة )15( متطلبات اإلبالغ ورفع التقارير 36 Requirements Article (15) المادة )16( متطلبات اإلفصـــاح 37 Requirements Disclosure) 16 (Article المادة )17( اإلنفـــاذ والجزاءات 38 Sanctions & Enforcement) 17 (Article
Article (18) Interpretation of Regulation 39 النظــام تفسير( 18 )المادة
Previous of Cancellation المادة )19( إلغاء إشعارات سابقة 39 Notices Article (19) المادة )20( النشر وتاريخ النفــاذ 39 Date Effective & Publication) 20 (Article الملحق 1 40 1 Annex
CBUAE Classification: Public /2026 .:No Circular تعميم رقم: 2026/1 1 /02/2026 :Date التاريخ: 2026/02/03 03 Institutions ial :To ال ُم Financ Licensed All إلى: كافة المنشآت الماليَّة رخصة الموضوع: نظــام إدارة المخاطــر التشغيلية Management Risk Operational Regulation Subject:
مقدمــــــة Introduction The Central Bank of the UAE seeks to promote the continuous development of an effective and efficient financial system. This regulation is issued pursuant to the powers vested under the Federal Decree-law No. (6) of 2025 Regarding the Central Bank, Regulation of Financial Institutions and Activities, and Insurance Business. All Licensed Financial Institutions are required to implement a comprehensive framework to manage Operational Risk and Operational Resilience. This regulation establishes the minimum requirements in this regard. Where this regulation includes requirements to provide specific information, to take specific measures or to address a specific list of items ‘at a minimum’, the Central Bank reserves the right to impose additional requirements to those articulated in this regulation. The Central Bank may issue standards or guidelines that further elaborate on the requirements of this regulation. النطــــاق Scope This regulation applies to all Licensed Financial Institutions that are juridical persons. الهــــدف Objective The objective of this regulation is to set out the minimum requirements for Licensed Financial Institutions with regard to managing their Operational Risk and Operational Resilience.
CBUAE Classification: Public المـــادة )1(: تعريفــات Definitions Bank: Any juridical person licensed in accordance with the provisions of the Central Bank Law and the regulations issued in implementation thereof, to primarily carry on the activity of taking deposits in addition to any other financial activities. 1.1. Board: the LFI’s board of directors or board of managers. 1.2. Business Continuity Plan: a comprehensive written plan of action that sets out the procedures and systems necessary to continue or restore the operation of the LFI in the event of a disruption. 1.3. Central Bank: The Central Bank of the United Arab Emirates. 1.4. Central Bank Law: Federal Decree-Law No. (6) of 2025 Regarding the Central Bank, Regulation of Financial Institutions and Activities, and Insurance Business. 1.5. Changes in Operations: changes in activities, processes and systems, including the introduction of new operations, and changes to or the discontinuation of existing operations. 1.6. Control Functions: the LFI’s functions that have a responsibility independent from management to provide objective assessment, reporting and/or assurance; this includes the risk management function, the compliance function and the internal audit function. 1.7. Critical Functions: Activities, services or operations the discontinuance of which is likely to lead to the disruption of financial stability, or of services that are essential to the economy due to the size, market share, external and internal interconnectedness, complexity, cross-border activities of an LFI, with particular regard to the substitutability of those activities, services, or operations. 1.8.
CBUAE Classification: Public Critical Information Assets: data assets whose confidentiality, integrity or availability is critical to the Critical Operations of the LFI or to the LFI’s compliance with legal and regulatory requirements, including in particular the prudential requirements applicable to the LFI and those related to the protection of Personal Data. 1.9. ّ Critical Operations: includes an LFI’s Critical Functions and all activities, processes, services and their relevant supporting assets, the disruption of which would impact the continued operation of the LFI, its role in the financial system, or its customers. Whether a particular operation is critical depends on the nature of the LFI and its role in the financial system. The Central Bank can indicate if a particular operation must be deemed critical. 1.10. Incident: an event that has or could potentially have an adverse effect on Critical Operations, or on Critical Information Assets. 1.11. ICT: Information and communication technology. 1.12. Islamic Finance Institution (‘IFI’): Banks, Takaful Insurance Companies, and Other Licensed Financial Institutions in accordance with the provisions of the Central Bank Law and the regulations issued in implementation thereof, to carry on the whole or a part of their activities and business in accordance with the rules and principles of the Islamic Shari`ah. 1.13. Insurance Company: Any juridical person, licensed in accordance with the provisions of the Central Bank Law and the regulations issued in implementation thereof to carry on insurance business and activities in the State. 1.14. Licensed Financial Activity: The financial activities subject to Central Bank licensing and supervision, which are specified in the Central Bank Law and the regulations issued in implementation thereof. 1.15.
CBUAE Classification: Public Licensed Financial Institution (‘LFI’):
Banks, (Re)Insurance Companies, and Other Financial Institutions licensed in accordance with the provisions of the Central Bank Law and the regulations issued in implementation thereof, to carry on a Licensed Financial Activity or more, including those which carry on the whole or a part of their activities and business in accordance with the rules and principles of Islamic Shari`ah. These institutions shall be either incorporated inside the State or a branch or subsidiary inside the State of a financial institution incorporated outside the State or in Financial Free Zones. 1.16. Master System of Record: the collection of all data, including Personal Data, required to conduct all Critical Operations of an LFI, including the provision of services to clients, managing all risks, and complying with all legal and regulatory requirements. 1.17. Operational Resilience: the ability of an LFI to deliver Critical Operations through disruption, including by identifying and protecting itself from threats and potential failures, by responding and adapting to, and recovering and learning from disruptive events to minimise their impact on delivering Critical Operations through disruption. 1.18. Operational Risk: the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. This includes legal risk, but excludes strategic and reputational risk. 1.19. Other Financial Institutions: Any Person, except Banks and (Re)Insurance Companies, licensed in accordance with the provisions of the Central Bank Law and the regulations issued in implementation thereof, to carry on a Licensed Financial Activity or more. 1.20. Outsourcing: an agreement between an LFI and a Third-Party Service Provider whereby that Third-Party Service Provider performs a process, service or activity that would otherwise be undertaken by the LFI itself. 1.21.
CBUAE Classification: Public Personal Data: as defined under Federal Decree-Law No. (45) of 2021 on Personal Data Protection. 1.22. Reinsurance Company: Any juridical person licensed in accordance with the provisions of the Central Bank Law and the regulations issued in implementation thereof to carry on reinsurance business and activities. 1.23. (Re)Insurance Company: an Insurance Company and/or Reinsurance Company. 1.24. Risk Appetite: The aggregate level and types of risk an LFI is willing to assume, decided in advance and within its risk capacity, to achieve its strategic objectives and business plan. 1.25. Risk Limits: Quantitative measures based on forward looking assumptions that allocate the financial institution’s aggregate Risk Appetite statement (e.g. measure of loss or negative events) to business lines, legal entities as relevant, specific risk categories, concentrations, and as appropriate, other levels. 1.26. Risk Tolerance: The variation around the prescribed Risk Appetite that the LFI is willing to tolerate. 1.27. Senior Management: The executive management of the LFI responsible and accountable to the Board for the sound and prudent day-to-day management of the LFI, generally including, but not limited to, the chief executive officer, chief financial officer, chief risk officer, and heads of the compliance and internal audit functions. 1.28. Shari’ah Non-Compliance Risk (‘SNCR’):
risk of financial loss or reputational risk that 1.29.
CBUAE Classification: Public an LFI might incur or suffer for not complying with Islamic Shari’ah. Takaful Insurance Company: An Insurance Company that carries on insurance business and activities in accordance with the rules and principles of Islamic Shari`ah, and the Central Bank Law and the regulations issued in implementation thereof. 1.30. Third-Party Service Provider: a natural or legal person that performs services, activities, functions, processes or tasks directly for an LFI, including in the form of Outsourcing but excluding employment as staff of the LFI. 1.31. المــادة )2(: إطــار إدارة المخاطــر التشغيلية Management Risk Operational Framework An LFI must have in place an appropriate Operational Risk management framework that includes strategies, policies, procedures, systems, controls and processes to identify, assess, evaluate, monitor, report and control or mitigate Operational Risk on a timely basis. 2.1. The Operational Risk management framework must be fully integrated into the broader risk management and governance framework of the LFI. 2.2. The LFI must ensure that its Operational Risk strategy, policies and processes are consistent with its risk profile, systemic importance, Risk Appetite, tolerance for disruption and capital strength, and take into account market and macroeconomic conditions. To this end, these must be reviewed and revised as appropriate, in particular whenever a material change in the Operational Risk profile occurs. 2.3. The Operational Risk management framework must be comprehensive and address all material aspects of Operational Risk prevalent in the business of the LFI, considering in particular the risks inherent in 2.4.
CBUAE Classification: Public all material products, activities, processes and systems, including those Outsourced to or relying on Third Party Service Providers. ّ The Operational Risk management framework must be well documented and address the following at a minimum:
2.5.
The governance framework to manage Operational Risk in the form of a clear governance structure, including reporting lines, responsibilities and accountabilities, and a clear delegation of authority, including for the Operational Risk committee where applicable; 2.5.1. Operational Risk management policies and procedures, including in particular the Operational Risk Appetite and Tolerance; 2.5.2. The tools that will be used to identify and assess risks and controls and how they will be used, including in particular by the three lines of defence, and how their effective design, implementation and operation will be ensured. These may include but are not limited to the tools listed in Annex 1 to this regulation; 2.5.3. Common terminology and standards that ensure consistency of risk identification and assessment throughout the LFI and, where applicable, group; 2.5.4. The establishment and calibration of thresholds or Risk Limits for inherent and residual Operational Risk exposure, consistent with the LFI’s Risk Appetite and Risk Tolerance, including what is considered a material operational loss; 2.5.5.
CBUAE Classification: Public The requirements for the ongoing monitoring and regular reporting against the thresholds and Risk Limits referred to in Article 2.5.5 above, including the content and frequency appropriate for the various recipients and the management information system, and any notification requirements; and 2.5.6. The approved risk mitigation strategies and instruments. 2.5.7. LFIs must address and manage the risks related to internal and external fraud as part of its Operational Risk management framework, including Incidents or ongoing threats affecting their customers. 2.6. المــادة )3(: المـــرونة التشـــغيلية Resilience Operational An LFI must have an effective Operational Resilience strategy and associated policies, procedures, systems and controls that enable it to respond to, adapt to, recover from and learn from, disruptive events to minimise the impact of such events on delivering Critical Operations through disruption. This strategy must be well integrated into the LFI’s Operational Risk management framework. 3.1. An LFI’s Operational Resilience strategy must leverage the Operational Risk management framework to identify internal and external threats and potential failures in people, processes and systems on an ongoing basis, promptly assess the vulnerabilities of Critical Operations and manage the resulting risks. 3.2. The Operational Resilience strategy, policies and processes must set out the circumstances in which Senior Management must alert the Board of incidents of disruption or potential disruption, in particular disruption or potential disruption of Critical Operations. 3.3.
CBUAE Classification: Public LFIs must identify their Critical Operations and all assets required to deliver them, including in particular the people, technology, processes, data, facilities and Third-Party Service Providers, including any intragroup entities, and the interconnections and interdependencies among them that are necessary for the delivery of Critical Operations through disruption. This must be formalized in a mapping for each of the Critical Operations and updated as part of change management. 3.4. At a minimum, the following must be considered as part of Critical Operations:
3.5.
The continued operation of payment systems, payment services and other time-critical services for the LFI’s customers; 3.5.1. The ability of the LFI to maintain accurate and up to date financial records for its customers and itself; 3.5.2. The ability of the LFI to measure and manage its solvency and liquidity in a timely manner, including its exposure to all material risks; and 3.5.3. Any operation deemed to be critical by the Central Bank. 3.5.4. An LFI must proactively develop, maintain and regularly review plans to manage contingencies and disruption for all Critical Operations, consisting of at least the following:
3.6.
Incident response plans: a set of processes to detect, respond to and recover from Incidents, including in particular but not limited to cyber security Incidents. 3.6.1. Business continuity plan: a comprehensive written plan of action that sets out the procedures and systems necessary to continue or restore the operation of an 3.6.2.
CBUAE Classification: Public organisation in the event of a disruption. Disaster recovery plan: a comprehensive plan to manage disaster incidents affecting Critical Operations, in particular in the form of prolonged or permanent unavailability of assets. 3.6.3. Role of the Board of Directors اإلدارة مجلس دور :(4 )المــادة The members of the Board bear ultimate responsibility for ensuring that the LFI has an adequate Operational Risk management framework in place that is fully integrated into the LFI’s broader risk management framework and that includes the management of Operational Resilience. This ultimate responsibility is retained by the members of the Board regardless of any Board committees set up. 4.1. The Board, and not a Board committee, must approve and review at least annually the LFI’s key Operational Risk and Operational Resilience strategies and policies, in particular:
4.2.
The LFI’s Risk Appetite and Tolerance statement for Operational Risk, articulating the nature, types and levels of Operational Risk the LFI is willing to assume, and that sets appropriate Risk Limits and thresholds within which the LFI must operate; 4.2.1. The LFI’s tolerance for disruption, considering its operational capabilities in a broad range of severe but plausible scenarios that would affect its Critical Operations. The Board’s policies must also address instances where the LFI’s capabilities are insufficient to meet its stated tolerance for disruption; and 4.2.2.
CBUAE Classification: Public The LFI’s Business Continuity and Disaster Recovery Plans. 4.2.3. This review must consider current and expected circumstances and changes in the external environment and in the operations of the LFI. The Board may delegate the annual review of the Business Continuity and Disaster Recovery Plans to one of its committees, but the Board must itself approve the initial plans and subsequently review the plans at least every three (3) years. The Board must have in place a formal process to oversee Senior Management and ensure that the strategies and policies it has approved are implemented effectively at all decision levels, including the Operational Risk Appetite and tolerance for disruption and the associated limits and thresholds. 4.3. The Board must approve, oversee and ensure the effectiveness of the LFI’s ICT and cybersecurity risk management framework. 4.4. The Board must ensure that the Operational Risk management framework is subject to an effective independent review by internal audit. 4.5. The Board must ensure that the LFI establishes and maintains a strong Operational Risk culture and control environment that supports and provides appropriate standards and incentives for professional and responsible behaviour. To this end, it must also ensure that its approach to Operational Risk and Resilience is clearly communicated to all relevant parties, including its staff, third parties and intragroup entities. 4.6.
CBUAE Classification: Public The Board is responsible for determining its own risk reporting requirements, and must be aware of any limitations in the data it receives. 4.7. The Board must remain informed, responsible and the highest authority to take decisions regarding Operational Risk management of the LFI. Within these limitations, the Board may set up one or more Board committees to conduct oversight, receive reporting and take decisions at a more granular level. 4.8. All LFIs designated as systemically important by the Central Bank must have a Board Operational Risk committee or other designated Board committee that addresses Operational Risk. The Central Bank may at its discretion require other LFIs to establish a Board Operational Risk committee, taking into account, among others, LFI size and complexity. 4.9. المــادة )5(: دور اإلدارة العلــيا Management Senior of Role Senior Management must ensure that the Operational Risk management framework, including the Operational Resilience strategy, as approved by the Board is translated into effective, well-implemented policies, processes, controls and systems throughout the LFI. 5.1. Senior Management must regularly monitor the Operational Risk profile and material operational exposures of the LFI, and implement robust processes and reporting mechanisms that enable proactive management of Operational Risk and Resilience by the Board, Senior Management including in particular the three lines of defence, and the business units. 5.2. Senior Management must report to the Board about the Operational Risk and Resilience of 5.3.
CBUAE Classification: Public the LFI on a regular, timely and proactive basis. Senior Management must report to the Board, and not to a Board committee, in a timely manner any breaches or expected breaches of the LFI’s Operational Risk Appetite and Tolerance, and the associated thresholds and Risk Limits. 5.4. Senior Management must develop and maintain an internal control system that clearly assigns authority, responsibility and reporting relationships to encourage and maintain accountability throughout the LFI. 5.5. Senior Management must regularly, and at least annually for Banks and (Re)Insurance Companies, conduct an assessment of the LFI’s internal control system, formalized in the form of a ‘report on internal control’. The assessment must be presented to the Board and the report provided to the Board and the Central Bank. The report must contain a description of the key internal control measures for all material processes related to Critical Operations, the assessment, and an overview of the measures taken or planned to be taken to improve the Internal Control System. 5.6. Senior Management must regularly evaluate the design, implementation and effectiveness of the LFI’s ICT and cybersecurity risk management. 5.7. Senior Management must ensure that sufficient resources are available at all levels of seniority and across all business lines in line with the LFI’s Operational Risk Appetite and Tolerance, proportionate to each business unit’s activities. 5.8. This includes ensuring that the LFI’s activities are conducted by a sufficient number of staff with sufficient experience, technical capabilities and access to resources, and with
CBUAE Classification: Public an appropriate amount of resources with sufficient authority dedicated to internal control, change management, and risk management activities. Senior Management must oversee that staff is subject to regular and appropriate training. Senior Management must ensure that the corporate culture reflects and inspires a culture of strong Operational Risk management, and ensure that it sets standards and incentives for professional and responsible behaviour throughout the LFI. 5.9. المــادة )6(: وظيفة إدارة المخاطر التشغيلية Function Management Risk Operational Within its risk management function, an LFI must have an Operational Risk management function that is adequately resourced, enjoys a sufficient degree of independence, and for which the Chief Risk Officer is responsible and accountable. 6.1. The Operational Risk management function must be responsible for the following at a minimum:
6.2.
Developing an independent view regarding the business units’ identified material Operational Risks, the design and effectiveness of internal controls, and the Risk Tolerance; 6.2.1. Challenging the relevance and consistency of the business units’ implementation of the Operational Risk management tools, measurement activities and reporting systems, and providing actionable recommendations; 6.2.2. Developing and maintaining the Operational Risk management and measurement policies, standards and guidelines; 6.2.3.
CBUAE Classification: Public Reviewing and contributing to the monitoring and reporting of the Operational Risk profile; 6.2.4. Identifying external and internal threats and potential failures in processes, people and systems on an ongoing basis; 6.2.5. Assessing vulnerabilities of Critical Operations and managing the resulting risks; and 6.2.6. Designing and providing Operational Risk training and raising awareness on Operational Risk among relevant stakeholders. 6.2.7. The Operational Risk management function must regularly report its findings and recommendations to the Board. 6.3. System Control Internal المــادة )7(: نظــام الضــــبط الداخلي The Operational Risk management framework must foster a strong control environment supported by an effective internal control system. 7.1. The internal control system must address the following components:
7.2.
1-2-7 تقييم المخاطر؛ ;assessment risk 7.2.1. 2-2-7 أنشطة الضـــبط؛ ;activities control 7.2.2.
7.2.3. monitoring activities; and المراقبة؛ أنشطة 3-2-7
7.2.4. information and communication. .واالتصال والمعلومات 4-2-7
The internal control system must cover all activities of the LFI, including those that rely in full or in part on Third-Party Service Providers. 7.3. An effective internal control system consists of policies, processes and systems, and the control measures they include to mitigate, reduce the likelihood, or limit the impact of associated risks. Control measures may include, but are not limited to:
7.4.
CBUAE Classification: Public 1-4-7 صلحيات وعمليات واضحة للموافقات؛ and authorities established Clearly processes for approval; 7.4.1. 2-4-7 فصل بين الواجبات؛ ;duties of Segregation 7.4.2. Dual control, whereby the process or system is designed such that two or more independent units (usually persons) operate in concert to protect sensitive functions or information; 7.4.3. Systematic monitoring of adherence to risk thresholds and Risk Limits, including those prescribed in the Risk Appetite and Tolerance; 7.4.4. Safeguards for access to and use of the LFI’s assets or those entrusted to the LFI, including data, and measures for the early detection and reporting of unauthorized access or misuse of assets; 7.4.5. Ongoing processes to identify business lines or products where returns or other indicators appear to be out of line with reasonable expectations; 7.4.6. Regular verification and reconciliation of transactions, accounts, and risk indicators; and 7.4.7. A vacation policy that requires officers and employees to take a minimum leave of absence determined by the LFI. 7.4.8. Risk transfer and mitigation tools such as insurance may be used as complementary to, but not as a replacement for internal Operational Risk management and controls. 7.5. The internal control system must address Operational Resilience and must itself be resilient by accounting for potential contingencies in processes, procedures and systems, including the availability of key assets. 7.6. As part of the periodic review of processes and control measures, LFIs must identify processes and controls that involve manual interventions and evaluate whether these can 7.7.
CBUAE Classification: Public be automated, for example through integration into and enforcement by ICT systems. Conversely, for processes and controls that are automated, the effectiveness and accuracy of the automation must form part of periodic assessments and a LFI must identify, measure, monitor and manage the related technology risks. An LFI must maintain a register of its processes (a ‘process universe’) that lists all processes with the process owner and risk owner. 7.8. The internal control system must incorporate the “three lines of defence” approach, distinguishing responsibilities and accountability between:
7.9.
Business line management responsible for identification and control of risks on an ongoing basis; 7.9.1. Control functions of risk management and compliance; and 7.9.2. Internal audit to provide independent assurance. 7.9.3. An LFI’s internal control system must include effective processes and systems to regularly monitor Operational Risk profiles and material Operational Risk exposures. This must include reporting mechanisms to report to the Board, Senior Management, business units and the Control Functions. The reporting mechanisms must ensure that reports:
7.10. are comprehensive, accurate,
consistent and actionable; 7.10.1. are timely in both normal and stressed conditions, and at a frequency that reflects the nature of and pace at which risks may develop; and 7.10.2.
CBUAE Classification: Public provide aggregate information with appropriate supporting detail to enable the recipients to understand and assess the LFI’s Operational Risk exposures. 7.10.3. Operational Risk reports must describe the Operational Risk profile of the LFI through internal and external indicators and insights relevant to decision making. To this end, Operational Risk reports must contain:
7.11. a description of the Operational Risk
profile that refers to internal and external financial, operational and compliance indicators, events and conditions relevant to decision making; 7.11.1. an overview of the LFI’s Operational Risk Limits, thresholds and other indicators relevant to its Risk Appetite and Tolerance; 7.11.2. clear statements on residual Operational Risks, control deficiencies, any non-compliance with Operational Risk or Resilience Tolerances, and Operational Risk events; 7.11.3. an overview and assessment of key and emerging risks; 7.11.4. details of recent significant internal Operational Risk and Resilience events and losses, including a root cause analysis; 7.11.5. relevant external events and indicators, regulatory changes and any potential impact on the LFI; and 7.11.6. relevant recommendations, including by the second line of defence, internal audit and external audit functions, in particular those 7.11.7.
CBUAE Classification: Public relating to the accuracy, comprehensiveness or consistency of the report. Operational Risk reports must be regularly reviewed to ensure they are comprehensive, accurate, consistent and actionable, and capture and reflect any changes in the activities or the environment of the LFI. The results of such reviews should be reported to the Board and Senior Management. 7.12. An LFI must periodically conduct stress-tests related to Operational Risk, including through exercises that challenge the LFI’s control environment, for example through penetration testing. This includes but is not limited to ICT systems, physical controls, controls relying on people, and any other risk vectors. 7.13. At least for Critical Functions, the periodic testing referred to in Article 7.13 above must include penetration testing by an independent third party. The results must be presented to the Board. 7.14. ICT and Cybersecurity Management An LFI must implement a robust ICT and cybersecurity risk framework within its Operational Risk management framework and Operational Resilience approach, and have appropriate policies, processes and systems that address:
8.1.
ICT risk identification and assessment; 8.1.1. ICT risk mitigation measures consistent with the assessed risk level, such as policies, processes and systems addressing cybersecurity, response and recovery, change management, and incident management; 8.1.2.
CBUAE Classification: Public Regular monitoring and testing of mitigating measures; and 8.1.3. Ongoing, proactive management of ICT and cybersecurity risks. 8.1.4. An LFI’s Risk Appetite and Tolerance must address ICT and cybersecurity risk and Resilience, including clear expectations in terms of performance, Resilience and tolerance for disruption. 8.2. An LFI must maintain appropriate ICT and cybersecurity infrastructure to meet its current and projected business requirements under normal circumstances and in periods of stress. This infrastructure must ensure data and system integrity, confidentiality and availability and, support integrated and comprehensive risk management. 8.3. The Board and Senior Management must be regularly informed about the LFI’s ICT and cybersecurity risk exposures, including about incidents and weaknesses identified in assessments and testing of its risk mitigating measures or ICT Resilience. 8.4. An LFI must ensure resilient ICT and cybersecurity that is subject to protection, detection, response and recovery programmes. 8.5. These programmes must be regularly tested, incorporate situational awareness, and convey timely information for risk management and decision-making processes that support and facilitate the delivery of Critical Operations. At a minimum, the ICT and cybersecurity policy must address the following in support and alignment of the LFI’s business objectives:
8.6.
8.6.1. Governance and oversight controls; واإلشراف؛ الحوكمة ضوابط 1-6-8
CBUAE Classification: Public 2-6-8 مسؤولية المخاطر، والمساءلة، واالمتثال؛ and accountability ,ownership Risk compliance; 8.6.2. ICT security measures such as access controls, identity management, Critical Information Asset protection, network security, vendor management security, physical and environmental security, vulnerability testing, and information classification; 8.6.3. Regular evaluation and monitoring of ICT controls and policy thresholds and limits, including risk Appetite and Tolerance thresholds; 8.6.4. 5-6-8 إدارة البيانات؛ ;management Data 8.6.5. ICT operations and service management, such as change management and patch management; 8.6.6. Incident Response and Recovery Plans, Business Continuity Plans, and Disaster Recovery Plans; 8.6.7. 8-6-8 إدارة مشاريع تقنية المعلومات واالتصال؛ and; management project ICT 8.6.8. 9-6-8 وتطـــوير النظم واقتنائها. and development Systems acquisition. 8.6.9. An LFI’s ICT and cybersecurity risk management and the related processes must:
8.7.
Be reviewed regularly to remain compliant with relevant industry standard and best practices, and to address new and evolving technologies and threats; 8.7.1. Be regularly tested to identify gaps against its Risk Tolerance and to review and improve ICT and cybersecurity risk identification, 8.7.2.
CBUAE Classification: Public protection, detection and event management; and Make use of actionable intelligence to continuously enhance the LFI’s cybersecurity posture, situational awareness of vulnerabilities to ICT systems, networks and applications and to support effective decision making in risk and change management. 8.7.3. LFIs must proactively manage their ICT and cybersecurity systems, including those operated or made available by Third-Party Service Providers, and have a strategy and timeline for the timely renewal or discontinuation of obsolete and unsupported hardware and software systems. 8.8. An LFI’s Master System of Record must be continuously maintained and stored within the UAE, including in the case of Outsourcing. LFIs that are branches of foreign financial institutions may, subject to Central Bank approval, comply with this requirement by maintaining an up-to-date copy of the Master System of Record in the UAE. 8.9. An LFI must comply with the regulations regarding ICT, cyber and information security issued by the relevant authorities in the UAE. 8.10. Management Incident المــــادة )9(: إدارة الحوادث An LFI must develop and implement Incident Response and Recovery Plans to manage Incidents that could disrupt the delivery or Resilience of Critical Operations in line with its Risk Appetite and tolerance for disruption. 9.1. For the avoidance of doubt, this includes but is not limited to ICT and cybersecurity Incidents.
CBUAE Classification: Public An LFI must regularly review, test and update its Incident Response and Recovery Plans, based on lessons learned from previous Incidents. In particular, an LFI must identify and address the root cause of all material Incidents and implement measures to prevent them or reduce the likelihood of further similar Incidents occurring. 9.2. The effectiveness of this process must be measured and periodically reviewed. An LFI must maintain an inventory of all relevant resources required for supporting its response and recovery capabilities, including internal and third-party resources. 9.3. Incident management must cover the full life cycle of an Incident, including at a minimum:
9.4.
Classification of an Incident’s severity based on predefined criteria, such as the impact and expected time to return to normal operation, that permits appropriate prioritisation and assignment of resources to respond to the Incident; 9.4.1. Incident response and recovery procedures, and how they relate to other contingency measures such as the Business Continuity Plan; 9.4.2. Roles and responsibilities of staff and external parties with regard to the recording, analysis, escalation, decision-making, resolution and monitoring of Incidents; 9.4.3. Communication plans to report incidents to internal and external stakeholders, including to the Central Bank and other authorities where required, that include reporting relevant performance metrics for ongoing Incidents and an analysis with lessons learned after an Incident has been resolved; and 9.4.4.
CBUAE Classification: Public Documentation of all Incidents in a register, including the nature of the Incident, the actions taken and the outcomes. 9.4.5. An LFI’s incident management must cover all Critical Operations and address all relevant resources required to maintain their Resilience and continuity, as per the mapping required under Article 3.4 of this Regulation. 9.5. المــــادة )10(: بيانات ونظــم المخاطر Systems and Data Risk An LFI’s risk information systems must deliver the capabilities and performance necessary, reflecting the LFI’s risk profile, complexity and systemic importance, including during stressed circumstances or a crisis. 10.1. An LFI must have in place adequate governance arrangements and internal controls to effectively manage and protect data. 10.2. An LFI’s ICT systems must enable the LFI to effectively:
10.3. monitor Operational Risk and
Resilience on a timely and ongoing basis; 10.3.1. reliably and accurately compile and analyse risk data and Operational Risk event data, including comprehensive internal and external loss data; and, 10.3.2. meet all necessary reporting requirements, including internally to the Board, Senior Management and business lines, and externally to customers and relevant authorities including the Central Bank, including ad hoc reporting 10.3.3.
CBUAE Classification: Public requirements during an ongoing disruption or crisis. The aggregation and reporting processes must be subject to high standards of validation and periodic review by the internal audit function. 10.4. For an LFI that is part of a group, effective and timely risk data aggregation must not be hindered by the group structure or the jurisdictions in which subsidiaries and branches are located, or by the systems and processes used by them. 10.5. المــــادة )11(: تخطيط استمرارية األعمــال Planning Continuity Business An LFI must maintain Business Continuity and Disaster Recovery Plans for its Critical Operations that are well-integrated into the LFI’s Operational Risk and Operational Resilience framework. 11.1. The Business Continuity and Disaster Recovery Plans must leverage and refer to the mapping of Critical Operations and related assets as required under Article 3.4 of this Regulation. 11.2. The LFI’s second and third lines of defence, in particular the Operational Risk management function and internal audit function, must regularly review the Business Continuity and Disaster Recovery Plans. This should be at least once per year for Critical Operations. 11.3. The Business Continuity and Disaster Recovery Plans must identify relevant potential disruption scenarios and how these would affect the LFI’s Critical Operations, taking into account internal or external interdependencies. The plans must address potential contingencies to ensure their swift implementation is not compromised, for example due to unavailability of key staff. 11.4. The range of disruption scenarios must range from scenarios where a return to normal operations is possible with the same assets, to 11.5.
CBUAE Classification: Public scenarios where major assets are rendered unavailable for prolonged periods or permanently without being recoverable. Each scenario must be subject to a quantitative and qualitative impact assessment or a business impact analysis, distinguishing between financial, operational, legal and reputational impact. 11.6. Business Continuity and Disaster Recovery Plans must include clear, unambiguous triggers for their activation, such as defined thresholds for the maximum tolerable disruption or outage. 11.7. Business Continuity and Disaster Recovery Plans must address the actions that will be taken in case of a disruption to business continuity, and establish clear, measurable targets in the form of recovery time objectives and recovery point objectives, that reflect the tolerance for disruption as approved by the Board. 11.8. Business Continuity and Disaster Recovery Plans must include communications guidelines and arrangements for key relevant stakeholders, including the Board, Senior Management, staff, relevant authorities including but not limited to the Central Bank, customers and the wider public, and ThirdParty Service Providers. 11.9. Business Continuity and Disaster Recovery Plans and procedures must be reviewed and tested regularly to ensure that the recovery and resumption objectives and timeframes can be met. This must be at least annually for Critical Operations. Where relevant, testing should include key Third-Party Service Providers. The results must be reported to the Board and Senior Management. 11.10. An LFI must conduct Business Continuity and Disaster Recovery exercises under a range of severe but plausible scenarios to assess its 11.11.
CBUAE Classification: Public ability to deliver Critical Operations through disruption. Change Management and Changes in Operations LFIs must have a well-resourced change management process in place to proactively plan for, manage and approve Changes in Operations, including the introduction of, discontinuation of, or changes to products, activities, processes and systems. 12.1. The Operational Risk management function must be involved throughout the change management process to ensure the implementation of appropriate controls and to ensure the involvement of the relevant Control Functions. 12.2. LFIs must have change management policies and procedures that address the process for identifying, managing, challenging, approving and monitoring changes in operations, considering at a minimum:
12.3.
Inherent risks, including but not limited to legal, financial, compliance, model and ICT risks; 12.3.1. Changes in the LFI’s risk profile, both due to the change itself and due to its impact on other related activities, and compliance with its Risk Appetite and Tolerance; 12.3.2. Necessary controls, risk management processes and risk mitigation strategies; 12.3.3. 4-3-12 المخاطر المتبقية؛ ;risk Residual 12.3.4. Additions or changes to relevant Risk Limits or thresholds; 12.3.5.
CBUAE Classification: Public Procedures and metrics to measure, monitor and manage the risk of the Changes in Operations; 12.3.6. The available and required capacity in terms of resources, including in particular in terms of technology infrastructure, staffing and expertise in all relevant roles, including at the level of the Board, Senior Management, and all three lines of defence; 12.3.7. The participation and roles of the three lines of defence in the change management process; 12.3.8. The impact and required additions or changes to the mapping of interdependencies of Critical Operations, the business continuity and disaster recovery plans, and other relevant aspects of the Operational Risk management framework; 12.3.9. The impact on risk data and systems or the scope of data that has to be captured; 12.3.10. Proactive communication with all relevant internal and external stakeholders, including, where applicable, third-party service providers; and 12.3.11. For each of the above, how these would apply in case of urgent or emergency Changes in Operation. 12.3.12. LFIs must monitor the changes in operations after their implementation to identify and manage any material differences to the expected Operational Risk profile. 12.4. Changes in Operations that are material to Critical Operations or operations that may materially affect customers must be subject to 12.5.
CBUAE Classification: Public a high degree of oversight and control measures. In this regard, LFIs must:
Ensure thorough testing of Changes in Operation prior to their implementation, and review and approval of the results by the relevant stakeholders; 12.5.1. Establish plans to recover from failures during implementation, including in particular a rollback plan and, where one ICT system is replaced by another, a parallel run of the old and new systems for a predefined minimum period long enough to ensure that the new system is functional and resilient; 12.5.2. Procure an external expert to provide independent assurance at key steps in the process, including a report assessing the proposed Changes in Operations and the change management controls and measures; 12.5.3. Senior Management is responsible to review, endorse and respond to the external expert report prior to providing the report to the Central Bank; 12.5.4. Notify the Central Bank and provide it with the external expert’s report at a minimum 30 calendar days prior to the proposed implementation of the Changes in Operation; and 12.5.5. Obtain the written no-objection of the Central Bank prior to implementation of the Changes in Operation. 12.5.6. LFIs must ensure that their customers are not negatively affected by changes in their operations. In particular, where Changes in Operations result in material erroneous information being provided to customers, such as payment confirmations, debit or credit 12.6.
CBUAE Classification: Public transactions and balances, LFIs must provide customers with clear information on how their accounts or transactions were affected as a result, including as part of efforts to address the errors. LFIs are liable for any damages incurred by the customer due to the LFI’s error, consistent with the Central Bank’s consumer protection regulations. المــــادة )13(: إدارة مخاطـــر مزودي الخدمات الخارجيين Management Risk Party Third LFIs must have a Board-approved strategy and associated policies and processes for the assessment, monitoring and management of third-party risk, integrated into their Operational Risk management framework. 13.1. As a general principle, LFIs must not overly rely on Outsourcing and maintain sufficient staff, expertise, and resources of its own to effectively perform and manage the activities for which it is licensed. 13.2. An LFI must not enter into an arrangement with a Third-Party Service Provider without first performing a risk assessment of the arrangement and conducting appropriate due diligence on the Third-Party Service Provider. 13.3. For arrangements that relate to or have an impact on Critical Operations, the LFI must verify that the Third-Party Service Provider has at least an equivalent level of Operational Resilience to safeguard the Critical Operations in both normal circumstances and in the event of disruption. 13.4. An LFI must obtain a notice of non-objection from the Central Bank prior to Outsourcing any activity that has the potential, if disrupted, to have a significant impact on the LFI’s Critical Operations. 13.5. Third-Party Service Provider arrangements must be governed by legally binding, written contracts that clearly set out the rights and 13.6.
CBUAE Classification: Public obligations, responsibilities and expectations of all parties to the arrangement, including regarding ownership and confidentiality of data and termination rights, and, for arrangements that relate to or have an impact on the LFI’s Critical Operations, the LFI’s right to inspect the Third-Party Service Provider’s records, to request and receive reporting such as audit and risk reports. The contract must include a requirement for the Third-Party Service Provider to comply with Central Bank requests and requirements, including notification and reporting requirements and, for Outsourcing arrangements that could impact the LFI’s Critical Operations, the right of the Central Bank to conduct on-site examinations related to the services they provide to the LFI. 13.7. For arrangements that involve or may involve the LFI’s or its customers’ data being shared by the Third-Party Service Provider with further subcontractors, the provisions of Articles 13.6 and 13.7 above must apply and be legally enforceable through contract against those subcontractors. 13.8. An LFI must maintain adequate resources to manage and monitor Third-Party Service arrangements, and its internal control system must address the related control measures, including at a minimum:
13.9.
Maintaining an updated register of Outsourced activities and ThirdParty Service arrangements relating to Critical Operations; 13.9.1. Metrics to measure and monitor performance and risks related to Third-Party Service arrangements on an ongoing basis; 13.9.2. Assessments of and reporting on the performance of and risks related to Third-Party Service Provider arrangements on an ongoing basis, 13.9.3.
CBUAE Classification: Public including the financial condition of Third-Party Service Providers; and Management of dependencies on Third-Party Service Provider arrangements for Critical Operations. 13.9.4. Within its Operational Risk and Operational Resilience framework, an LFI must address any reliance on Third-Party Service Providers, in particular in its Business Continuity Plan, and in its mapping of assets and resources related to Critical Operations. 13.10. An LFI must maintain viable contingency and exit plans for its Third-Party Service Provider arrangements that are material to its Critical Operations. 13.11. In particular, such plans must demonstrate the LFI’s Operational Resilience in the event of a failure or disruption at a Third-Party Service Provider impacting the provision of Critical Operations. The Business Continuity Plan must assess the substitutability of arrangements with ThirdParty Service Providers, highlighting any instances where a sufficiently timely substitution of the Third-Party Service Provider, including by the LFI itself, is very costly, carries high risks, or is impossible. The Central Bank may, at its discretion, require the discontinuation of one or more arrangements with a Third-Party Service Provider or the discontinuation of a Critical Operation that is overly reliant on one or more arrangements with Third-Party Service Providers. 13.12. المــــادة )14(: مخاطر عدم االمتثال ألحكام الشريعة Risk Compliance-Non ah’Shari An Islamic Finance Institution must have in place adequate systems and controls, including the implementation of a Shari’ah 14.1.
CBUAE Classification: Public governance framework, and ensure compliance with the Higher Shari’ah Authority’s resolutions. This includes policies and procedures for the approval of Islamic finance products, contracts and activities. An Islamic Financial Institution must have in place an appropriate framework, adequate systems, controls and limits for Shari’ah NonCompliance Risk management, that are comprehensive and address the specific risks associated with Shari’ah compliant businesses and activities, including Shari’ah Non-Compliance Risk and risks related to its fiduciary responsibilities. 14.2. An Islamic Finance Institution must understand and test the interlinkages and impacts of Shari’ah Non-Compliance Risk on other risks throughout the life cycle of the contract, including formation, termination and any other aspects that affect the contract’s performance, such as fraud and misrepresentation. 14.3. An Islamic Finance Institution must maintain a formal record of income not recognized arising from Shari’ah Non-Compliance and report this regularly to the internal Shari’ah supervision committee. 14.4. The risk management function must proactively identify potential risk areas of Shari’ah non-compliance, evaluate the likelihood and severity of Shari’ah noncompliance events occurring, identify any profits that may not be recognized as eligible Islamic finance profits, and disclose these findings to the internal Shari’ah supervision committee. 14.5. Where such Shari’ah Non-Compliance Risk materializes, the Islamic Finance Institution must review the adequacy and, where necessary, improve its internal control framework related to Shari’ah NonCompliance Risk. The internal Shari’ah supervision committee is the body who has the authority to determine whether a Shari’ah
CBUAE Classification: Public Non-Compliance Risk has materialized or not. An Islamic Finance Institution must manage risk in accordance with accepted Shari’ah principles, and in accordance with the level and type of risk allocated to it pursuant to contracts entered into with its customers. An Islamic Finance Institution must not seek to circumvent risk it has contractually acceded to (including asset and ownership risk). Such risk may however be mitigated under the direction of the internal Shari’ah supervision committee. 14.6. An Islamic Finance Institution must maintain separate accounts in respect of the IFI’s operations, for restricted and unrestricted investment accounts, Takaful funds or any other funds that are attributed to specific clients under different contracts and ensure proper allocation of expenses, recognition of profit or loss and must maintain records for all relevant transactions. 14.7. المــــادة )15(: متطلبات اإلبالغ ورفــــع التقارير Reporting and Notification Requirements An LFI must promptly notify the Central Bank when it becomes aware of a significant deviation from its Board-approved Operational Risk Appetite statement, policies or procedures, including the Board-approved tolerance for disruption, or becomes aware that a material Operational Risk has not been adequately addressed. 15.1. An LFI must notify the Central Bank of any Operational Risk events that significantly impact or may significantly impact the continuity or integrity of Critical Operations. This includes in particular any event that triggers, or is likely to trigger its business continuity or disaster recovery plans, or has, or is likely to have, a material impact on the LFI’s customers, operations, profitability or capital. In particular, the LFI must:
15.2.
CBUAE Classification: Public Within 4 hours: notify the Central Bank of the events, including what Critical Operations are affected; 15.2.1. Within 24 hours: provide the Central Bank with a summary report of the nature of the event, the actions being taken, the likely impact and the timeframe for returning to normal operations; 15.2.2. Upon return to normal operations:
notify the Central Bank upon returning to normal operations; and 15.2.3. Any other notifications, information requirements and timeframes as specified by the Central Bank on a case-by-case basis. 15.2.4. An LFI must notify the Central Bank within 72 hours of any high-risk Incident. The criteria for categorisation of an Incident as high risk must be defined in Board-approved policies. 15.3. An LFI must provide, upon request, any specific information with respect to Operational Risk that the Central Bank may require. 15.4. An LFI must comply with regular reporting requirements on Operational Risk and Operational Resilience as prescribed by the Central Bank. 15.5. An LFI must comply with the notification requirements which the Central Bank may set and vary from time to time. The Central Bank will inform LFIs of such changes through a notice. 15.6. المــــادة )16(: متطلبات اإلفصـــاح Requirements Disclosure An LFI must have a policy on public disclosures related to Operational Risk and 16.1.
CBUAE Classification: Public associated internal controls setting out how it determines what information is disclosed and what information should not be disclosed. An LFI must publicly disclose key information about its approach to Operational Risk and Operational Resilience management, and its Operational Risk exposure, commensurate with its size, risk profile, the complexity of its operations, its systemic importance and role in the financial system, and evolving industry practices. 16.2. The disclosed information must allow stakeholders to assess to which extent the LFI identifies, assesses, monitors, controls and mitigates Operational Risk effectively. 16.3. The disclosed information must provide insight into the practices of the LFI with regard to the protection of Personal Data. 16.4. LFIs that are branches or subsidiaries of foreign firms with a similar license may largely rely on the disclosures of the group they belong to, but must publish at least a summary of the Operational Risk management framework in place for their UAE operations on their public website. 16.5. LFIs that are subsidiaries of other LFIs in the UAE may largely rely on the disclosures of the group they belong to, but the group disclosures must sufficiently address the disclosures required for the LFI. 16.6. المادة )17(: اإلنفاذ والجزاءات Sanctions & Enforcement Violation of any provision of this regulation and any accompanying Standards may be subject to supervisory action and administrative & financial sanctions as deemed appropriate by the Central Bank. 17.1. Supervisory action and administrative & financial sanctions by the Central Bank may 17.2.
CBUAE Classification: Public include withdrawing, replacing or restricting the powers of Senior Management or members of the Board, providing for the interim management of the LFI, imposition of fines or barring individuals from the UAE financial sector. المــــادة )18(: تفســـير النظــام Regulation of Interpretation The Regulatory Development Department of the Central Bank shall be the reference for interpretation of the provisions of this regulation. المــــادة )19(: إلغـــاء إشعــارات سابقــة Notices Previous of Cancellation This regulation cancels and replaces the following Central Bank Circulars and Notices:
Circular No. 163/2018, the ‘Operational Risk Regulation’ and the ‘Operational Risk Standards’ issued on 29 August 2018. 19.1. المــــادة )20(: النشر وتاريخ النفـــاذ Date Effective & Publication This regulation shall be published in the Official Gazette in both Arabic and English and shall come into effect one month from the date of publication. 20.1. Khaled Mohamed Balama Governor of the Central Bank of the UAE
CBUAE Classification: Public الملحق 1 1 Annex Examples of tools used for identifying and assessing Operational Risk a. Event management – A pre-determined set of processes followed when an LFI experiences an Operational Risk event, including the processes of identification, analysis, end-to-end management and reporting of the event. These processes include analysis of events to understand the underlying causes and control weaknesses, the identification of new Operational Risks, and the formulation of an appropriate response to prevent, mitigate or control similar events. The outcomes are an input to the self-assessment and in particular to the assessment of control effectiveness. b. Internal Operational Risk event data collection and analysis – Internal operational loss data provides meaningful information for assessing an LFI's exposure to Operational Risk and the effectiveness of internal controls. Analysis of loss events can provide insight into the causes of large losses and information on whether control failures are isolated or systematic. The data and analysis should also cover near misses and generally aim to capture risk exposures, not only those that result in financial losses. An LFI may also find it useful to capture and monitor Operational Risk contributions to credit, market and other financial risk related losses in order to obtain a more complete view of its Operational Risk exposure.
c. External Operational Risk event data
collection and analysis – External data elements consist of gross operational loss amounts, dates, recoveries and relevant causal information for operational loss events occurring at organizations other than the LFI. External loss data can be compared with internal loss data, or used to explore possible weaknesses in the control environment or
CBUAE Classification: Public consider previously unidentified risk exposures. Such data may be informative of risks that are common across the industry, or that are rare but have a high impact. d. Self-assessments – the LFI performs a selfassessment of its Operational Risks and controls on various levels, typically evaluating the inherent risk (assessing the risk before controls are considered), the effectiveness of the control environment, and the resulting residual risk (the risk exposure after controls are considered), based on both quantitative and qualitative elements. Qualitative elements may include consideration of both the likelihood and the consequences of the risk event when determining the inherent and the residual ratings. Assessments typically rely on process mapping to identify all key steps and dependencies in the processes, and any associated risks or areas with weaker controls in place. The assessments should contain sufficiently detailed information on the business environment, Operational Risks, underlying causes, controls and evaluation of control effectiveness to enable an independent reviewer to determine how the LFI reached its ratings. A risk register collates this information to form a meaningful view of the overall effectiveness of controls and to facilitate oversight by the Board, Senior Management and other internal stakeholders. e. Business process mapping – business process maps identify the key steps in business processes, activities and organizational functions. They also identify the key risk points in the overall business process. Process maps can reveal individual risks, risk interdependencies and areas of control or risk management weakness. They
CBUAE Classification: Public can help prioritize subsequent management action. f. Control monitoring and assurance framework – Incorporating an appropriate control monitoring and assurance framework facilitates a structured approach to the evaluation, review and ongoing monitoring and testing of key controls. The analysis of controls ensures these are suitably designed for the identified risks and operating effectively. The analysis should also consider the sufficiency of control coverage, including adequate prevention, detection and response strategies. The control monitoring and testing should be appropriate for the different Operational Risks and key controls across business areas. g. Risk and performance indicators – risk and performance indicators are risk metrics and/or statistics that provide insight into an LFI’s risk exposure. Risk indicators provide insight into the status of operational processes, which in turn may provide insight into operational weaknesses, failures and potential losses. Risk and performance indicators are often paired with escalation triggers to warn when risk levels approach or exceed thresholds or limits and prompt mitigation plans. Monitoring metrics and related trends through time against agreed thresholds or limits provides valuable information for risk management and reporting purposes, and may provide early warning information on the performance of the business and the control environment. h. Scenario analysis – Scenario analysis is a method to identify, analyse and measure a range of scenarios, including low probability and high severity events, some of which could result in severe Operational Risk losses. Scenario analysis typically involves workshop meetings of subject matter experts including senior management, business management and senior Operational Risk
CBUAE Classification: Public staff and other functional areas such as compliance, human resources and IT risk management, to develop and analyse the drivers and range of consequences of potential events. Inputs to the scenario analysis would typically include relevant internal and external loss data, information from selfassessments, the control monitoring and assurance framework, forward-looking metrics, root-cause analyses and the process framework, where used. The scenario analysis process could be used to develop a range of consequences of potential events, including impact assessments for risk management purposes, supplementing other tools based on historical data or current risk assessments. It could also be integrated with disaster recovery and business continuity plans, for use within testing of Operational Resilience. Given the subjectivity of the scenario process, a robust governance framework and independent review are important to ensure the integrity and consistency of the process.
i. Models – LFIs may find it useful to quantify
their exposure to Operational Risk by using the output of the risk assessment tools as inputs into a model that estimates Operational Risk exposure. The results of the model can be used in an economic capital process and can be allocated to business lines to link risk and return. j. Benchmarking and comparative analysis – Benchmarking and comparative analysis are comparisons of the outcomes of different risk measurement and management tools deployed within the LFI, as well as comparisons of metrics from the LFI to other firms in the industry. Such comparisons can be performed to enhance understanding of the LFI’s Operational Risk profile. For example, comparing the frequency and severity of internal losses with self-assessments can help the LFI determine whether its self-assessment processes are functioning effectively. Scenario data can be compared to internal and external loss data to gain a better
CBUAE Classification: Public understanding of the severity of the LFI’s exposure to potential risk events. k. Audit findings – while audit findings primarily focus on control weaknesses and vulnerabilities, they can also provide insight into inherent risk due to internal or external factors. LFIs must not solely rely on internal audit to identify Operational Risks.
Read the rest free
Source: Central Bank of UAE — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CBUAE
CBUAE published 1 document in the last 30 days. We email you each new one the day it's published.