2026-07-27

Added · Updated

Operational Risk Management Regulation

The Central Bank of the UAE establishes minimum requirements for Licensed Financial Institutions to implement a comprehensive framework for managing operational risk and operational resilience. The regulation mandates the integration of operational risk strategies with the institution's broader governance, risk appetite, and capital strength, requiring regular reviews and updates. It defines key terms such as critical operations, incidents, and third-party risk, and outlines specific obligations for the Board of Directors, senior management, and control functions. The document further details requirements for internal controls, ICT and cybersecurity management, incident reporting, business continuity planning, and disclosure obligations.

Central Bank of UAE logo

United Arab Emirates

Central Bank of UAE

Click to view thumbnail

CBUAE Classification: Public نظــام إدارة المخاطـــــر التشــغيلية Operational Risk Management Regulation

2 CBUAE Classification: Public المحتويـــــات CONTENTS الصفحة الموضوع Page Subject مقدمـــة 3 Introduction النطـاق 3 Scope الهــدف 3 Objective المادة )1( تعريفـــات 4 Definitions) 1 (Article Management Risk Operational المادة )2( إطار إدارة المخاطر التشغيلية 8 Framework Article (2) المادة )3( المـــرونة التشـــغيلية 10 Resilience Operational) 3 (Article Article (4) Role of the Board of Directors 12 اإلدارة مجلس دور( 4 )المادة Article (5) Role of Senior Management 14 العليا اإلدارة دور( 5 )المادة Management Risk Operational المادة )6( وظيفة إدارة المخاطر التشغيلية 16 Function Article (6) المادة )7( نظــام الضــبط الداخــلي 17 System Control Internal) 7 (Article إدارة تقنية المعلومات واالتصال واألمن المادة )8( 21 السيبراني ICT and Cybersecurity Management Article (8) المادة )9( إدارة الحوادث 24 Management Incident) 9 (Article Article (10) Risk Data and Systems 26 المخاطــر ونظــم بيانات( 10 )المادة المادة )11( تخطيط استمرارية األعمال 27 Business Continuity Planning Article (11) and Management Change المادة )12( إدارة التغيير والتغييرات في العمليات 29 Changes in Operations Article (12) إدارة مخاطر مزودي الخدمات المادة )13( 32 الخارجيين Third Party Risk Management Article (13) Compliance-Non ah’Shari المادة )14( مخاطر عدم االمتثال ألحكام الشريعة 34 Risk Article (14) Reporting and Notification المادة )15( متطلبات اإلبالغ ورفع التقارير 36 Requirements Article (15) المادة )16( متطلبات اإلفصـــاح 37 Requirements Disclosure) 16 (Article المادة )17( اإلنفـــاذ والجزاءات 38 Sanctions & Enforcement) 17 (Article Article (18) Interpretation of Regulation 39 النظــام تفسير( 18 )المادة Previous of Cancellation المادة )19( إلغاء إشعارات سابقة 39 Notices Article (19) المادة )20( النشر وتاريخ النفــاذ 39 Date Effective & Publication) 20 (Article الملحق 1 40 1 Annex

3 CBUAE Classification: Public /2026 .:No Circular تعميم رقم: 2026/1 1 /02/2026 :Date التاريخ: 2026/02/03 03 Institutions ial :To ال ُم Financ Licensed All إلى: كافة المنشآت الماليَّة رخصة الموضوع: نظــام إدارة المخاطــر التشغيلية Management Risk Operational Regulation Subject: مقدمــــــة Introduction يسعى المصرف المركزي إلى تعزيز التطوير المستمر الذي من شأنه أن يضمن عمل النظام المالي على نحو كفء وفعّــال. وقد تم إصدار هذا النظام عمًل بالصلحيات الممنوحة للمصرف المركزي بموجب أحكام المرسوم بقانون اتحادي رقم )6( لسنة 2025 في شأن المصرف المركزي وتنظيم المنشآت واألنشطة الماليَّة وأعمال التأمين. The Central Bank of the UAE seeks to promote the continuous development of an effective and efficient financial system. This regulation is issued pursuant to the powers vested under the Federal Decree-law No. (6) of 2025 Regarding the Central Bank, Regulation of Financial Institutions and Activities, and Insurance Business. ُمرخصة تطبيق إطــار يجب على كافــة المنشآت الماليَّة ال شامــل إلدارة المخاطـــر التشغيلية والمرونــة التشغيلية، ويضــع هــذا النظام الحـد األدنى من المتطلبات في هــذا الصدد. All Licensed Financial Institutions are required to implement a comprehensive framework to manage Operational Risk and Operational Resilience. This regulation establishes the minimum requirements in this regard. وحيثما يتضمن هذا النظام متطلبات بتقديـــم معلومات أو اتخاذ إجراءات، أو التعامل مع قائمة بنــود بعينهــا، مشار د أدني"، يظل المصرف المركزي محتف ا بالحق ًظ إليها "كحـــ في أن يفرض متطلبات تكون إضافة للمتطلبات المنصوص عليها في هـــذا النظــام. Where this regulation includes requirements to provide specific information, to take specific measures or to address a specific list of items ‘at a minimum’, the Central Bank reserves the right to impose additional requirements to those articulated in this regulation. كما قد يُصدر المصرف المركزي معايير أو إرشادات تضيف مزيدً ا من التو ّسع والتفصيل حول المتطلبات المنصوص عليها في هذا النظام. The Central Bank may issue standards or guidelines that further elaborate on the requirements of this regulation. النطــــاق Scope ُمرخصة تنطبق أحكام هذا النظـام على كافة المنشآت الماليَّة ال التي هي أشخاص اعتباريين. This regulation applies to all Licensed Financial Institutions that are juridical persons. الهــــدف Objective يهــدف هـذا النظام إلى وضــع الحــد األدنى من المتطلبات ال ، فيما يتعلق بإدارة مخاطرها ُم للمنشآت الماليَّة رخصة التشغيلية ومرونتهـــا التشغيلية. The objective of this regulation is to set out the minimum requirements for Licensed Financial Institutions with regard to managing their Operational Risk and Operational Resilience.

4 CBUAE Classification: Public المـــادة )1(: تعريفــات Definitions 1-1 بنــك: أي شخص اعتبــاري مر ّخص بموجــب أحكام قــانون المصــرف المركزي واألنظمة الصادرة له تنفيذا ليمارس، بصورة رئيســية، نشـــاط تلقي ً الودائع، باإلضافة إلى أي أنشــطة مالية أخــرى. Bank: Any juridical person licensed in accordance with the provisions of the Central Bank Law and the regulations issued in implementation thereof, to primarily carry on the activity of taking deposits in addition to any other financial activities. 1.1. 2-1 مجلس اإلدارة: مجلس إدارة أو مجلس مديرين ال . ُم المنشأة الماليَّة رخصة Board: the LFI’s board of directors or board of managers. 1.2. 3-1 خطة استمرارية األعمـال: خطة عمل مكتوبة وشاملة تحــدد اإلجراءات والنظـــم اللزمـــة لمواصلــة أو ال عند ُم استعـــادة عمليــات المنشأة الماليَّة رخصة تعطلها أو اضطرابها. Business Continuity Plan: a comprehensive written plan of action that sets out the procedures and systems necessary to continue or restore the operation of the LFI in the event of a disruption. 1.3. 4-1 المصرف المركزي: مصرف اإلمارات العربية المتحدة المركزي. Central Bank: The Central Bank of the United Arab Emirates. 1.4. 5-1 قانون المصرف المركزي: المرسوم بقانون اتحادي رقم )6( لسنة 2025 في شأن المصرف المركزي وتنظيم المنشآت واألنشطة الماليَّة وأعمال التأمين. Central Bank Law: Federal Decree-Law No. (6) of 2025 Regarding the Central Bank, Regulation of Financial Institutions and Activities, and Insurance Business. 1.5. 6-1 التغييرات في العمليات: التغييرات في األنشطة والعمليات والنظم، بما في ذلك إدخال عمليات جديدة، وإدخــال تغيـــيرات علـى عمليات قائمـــة، أو وقفها. Changes in Operations: changes in activities, processes and systems, including the introduction of new operations, and changes to or the discontinuation of existing operations. 1.6. ُمرخصة 7-1 وظائف الضبط: وظائف المنشأة الماليَّة ال التي لها مهام مستقلة عن اإلدارة لتقديم تقييم موضوعي و/أو رفع التقارير و/أو التدقيق؛ ويشمل ذلك وظيفة إدارة المخاطر، ووظيفة االمتثال، ووظيفة التدقيق الداخلي. Control Functions: the LFI’s functions that have a responsibility independent from management to provide objective assessment, reporting and/or assurance; this includes the risk management function, the compliance function and the internal audit function. 1.7. 8-1 الوظائف بالغة األهمية: األنشطة أو الخدمــات أو العمليــات التي يرجح أن يؤدي انقطاعها إلى اإلخلل باالستقرار المالي، أو تعطيل أو اضطراب خدمات أساسية للقتصاد بسبب حجم المنشأة الماليَّة ُمرخصة، وحصتها في السوق وارتباطاتها الداخلية ال والخارجية، أو درجة تعقد أنشطتها عبر الحدود، مع اخذ اعتبار خاص إلمكانية استبدال تلك األنشطة أو الخدمــات أو العمليــات. Critical Functions: Activities, services or operations the discontinuance of which is likely to lead to the disruption of financial stability, or of services that are essential to the economy due to the size, market share, external and internal interconnectedness, complexity, cross-border activities of an LFI, with particular regard to the substitutability of those activities, services, or operations. 1.8.

5 CBUAE Classification: Public 9-1 األصول المعلوماتية بالغة األهمية: األصول البياناتية التي تكون سريتها أو سلمتها أو توفرها ً أمرا بالغ األهمية للعمليات الحيوية للمنشأة الماليَّة ُ ة المرخصة ُ المرخصة، أو المتثال المنشأة الماليَّ للمتطلبات القانونية والرقابية، بما في ذلك، على وجه الخصوص، المتطلبات االحترازية المطبّقة على ُ ة المرخصة، وتلك التي تتعلق بحمايــة المنشأة الماليَّ البيانات الشخصيــة. Critical Information Assets: data assets whose confidentiality, integrity or availability is critical to the Critical Operations of the LFI or to the LFI’s compliance with legal and regulatory requirements, including in particular the prudential requirements applicable to the LFI and those related to the protection of Personal Data. 1.9. 10-1 العمليات الحيوية: تتضمن الوظائف بالغة األهمية ُ ة المرخصة، وكافـــة األنشـــطة للمنشأة الماليَّ والعمليات والخدمـــات، واألصول ذات الصلة ِّر تعطلها أو اضطرابه ّ الداعمة لها، والتي سيؤث ا على ُ ة المرخصة، ودورها في استمرار عمل المنشأة الماليَّ النظـــام المالي، أو عمـــلئها. ويعتمــد ما إذا كانت عملية بعينها حيوية على طبيعـــة المنشأة الماليَّة ُ المرخصة، ودورها في النظــام المــالي ككل. للمصرف المركزي أن يحدد ما إذا كان يجب اعتبار عملية بعينها حيوية. Critical Operations: includes an LFI’s Critical Functions and all activities, processes, services and their relevant supporting assets, the disruption of which would impact the continued operation of the LFI, its role in the financial system, or its customers. Whether a particular operation is critical depends on the nature of the LFI and its role in the financial system. The Central Bank can indicate if a particular operation must be deemed critical. 1.10. 11-1 حادث: حدث يكون له، أو من الممكن أن يكون له، تأثير ضار على العمليات الحيوية، أو على األصول المعلوماتية بالغة األهمية. Incident: an event that has or could potentially have an adverse effect on Critical Operations, or on Critical Information Assets. 1.11. 12-1 تقنية المعلومات واالتصال : تقنية المعلومات واالتصال. ICT: Information and communication technology. 1.12. 13-1 مؤسسة مالية إسالمية: البنوك وشركات التأمين التكافلي والمؤسسات الماليَّة ُ األخرى المرخص لها، وفقا المصرف المركزي واألنظمة ً ألحكام قانون لممارسة كافة أو جزءاً الصادرة تنفيذا ، من ً له أنشطتها وأعمالها وفقاً ألحكام ومبادئ الشريعة اإلسلمية. Islamic Finance Institution (‘IFI’): Banks, Takaful Insurance Companies, and Other Licensed Financial Institutions in accordance with the provisions of the Central Bank Law and the regulations issued in implementation thereof, to carry on the whole or a part of their activities and business in accordance with the rules and principles of the Islamic Shari`ah. 1.13. 14-1 شركة التأميــن: ُ أي شخص اعتباري مرخص له، وفقا المصرف المركزي واألنظمة ً ألحكام قانون الصادرة تنفيذاً له، بممارسة أعمال وأنشطة التأمين في الدولة. Insurance Company: Any juridical person, licensed in accordance with the provisions of the Central Bank Law and the regulations issued in implementation thereof to carry on insurance business and activities in the State. 1.14. 15-1 األنشطة الماليَّة ُ المرخصة : األنشطة الماليَّة الخاضعة لترخيص ورقابة المصرف المركزي ُ والمحددة في قانون المصرف المركزي، واألنظمة الصادرة تنفيذا . ً له Licensed Financial Activity: The financial activities subject to Central Bank licensing and supervision, which are specified in the Central Bank Law and the regulations issued in implementation thereof. 1.15.

6 CBUAE Classification: Public 16-1 المنشأة الماليَّة ال ُمرخصة: البنوك وشركات التأمين وشركات إعادة التأمين والمؤسسات الماليَّة األخرى ال ، ألحكام قانون ُمرخصة وفقا المصرف المركزي ً له واألنظمة الصادرة تنفيذا ، لممارسة نشاط أو أكثر ً ُمرخصة، وتشمل تلك التي من األنشطة الماليَّة ال تُمارس كافة أو جزء من أعمالها وأنشطتها وفقاً لمبادئ وأحكام الشريعة اإلسلمية، وتكون تلك أو شركة المنشآت إما مؤسسة داخل الدولة، أو فرعاً تابعة داخل الدولة لمنشأة مالية مؤسسة خارج الدولة أو في المناطق الحرة الماليَّة. Licensed Financial Institution (‘LFI’): Banks, (Re)Insurance Companies, and Other Financial Institutions licensed in accordance with the provisions of the Central Bank Law and the regulations issued in implementation thereof, to carry on a Licensed Financial Activity or more, including those which carry on the whole or a part of their activities and business in accordance with the rules and principles of Islamic Shari`ah. These institutions shall be either incorporated inside the State or a branch or subsidiary inside the State of a financial institution incorporated outside the State or in Financial Free Zones. 1.16. 17-1 نظـام السجالت الرئيس: تجميع كل البيانات، بما في ذلك البيانات الشخصية، المطلوبة إلجراء كافة ُمرخصة، بما في العمليات الحيوية للمنشأة المالَّية ال ذلك تقديم الخدمات للعملء، وإدارة جميع المخاطر، واالمتثال لكافة المتطلبات القانونية والرقابية. Master System of Record: the collection of all data, including Personal Data, required to conduct all Critical Operations of an LFI, including the provision of services to clients, managing all risks, and complying with all legal and regulatory requirements. 1.17. ُمرخصة 18-1 المرونــة التشغيلية: قدرة المنشأة الماليَّة ال على توفير العمليات الحيوية خلل حاالت التعطل أو االضطراب، بما في ذلك تحديد وحماية نفسها من التهديدات واألعطال المحتملة، من خلل االستجابة والتكّيف مع أحداث التع ّطل واالضطراب والتعافي من تأثيراتها والتعلم منها، لتقليل تأثيرها على توفير العمليات الحيوية في حاالت التعطل أو االضطراب. Operational Resilience: the ability of an LFI to deliver Critical Operations through disruption, including by identifying and protecting itself from threats and potential failures, by responding and adapting to, and recovering and learning from disruptive events to minimise their impact on delivering Critical Operations through disruption. 1.18. 19-1 المخاطر التشغيلية: مخاطر الخسائر الناجمة عن عدم كفاية، أو إخفاق العمليات أو األشخاص أو النظم الداخلية، أو عن أحداث خارجية. ويشمل هذا التعريف المخاطر القانونية، ولكنه ال يتضمن المخاطر االستراتيجية أو مخاطر السمعــة. Operational Risk: the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. This includes legal risk, but excludes strategic and reputational risk. 1.19. 20-1 المؤسسات الماليَّة األخرى: أي شخص، فيما عدا البنوك وشركات التأمين وشركات إعادة التأمين، ُمرخص له وفقا المصرف المركزي ً ألحكام قانون له واألنظمة الصادرة تنفيذا ، بممارسة نشاط مالي أو ً ال . ُم أكثر من األنشطة الماليَّة رخصة Other Financial Institutions: Any Person, except Banks and (Re)Insurance Companies, licensed in accordance with the provisions of the Central Bank Law and the regulations issued in implementation thereof, to carry on a Licensed Financial Activity or more. 1.20. 21-1 التعهــــيد: اتفاقـــــية بين منشأة مالية مرخصة ومــزّود خدمة خارجــي، يقـــوم بموجبها مزّود الخدمة الخارجي بأداء عملــــية أو خدمــــة أو Outsourcing: an agreement between an LFI and a Third-Party Service Provider whereby that Third-Party Service Provider performs a process, service or activity that would otherwise be undertaken by the LFI itself. 1.21.

7 CBUAE Classification: Public نشـــاط كان من الممـــكن أن تقـــوم به المنشأة الماليَّة ُمرخصة بنفســـها. ال 22-1 البيانات الشخصية: حسبما ورد تعريفها في المرسوم بقانون اتحادي رقم )45( لسنة 2021 بشأن حماية البيانات الشخصية. Personal Data: as defined under Federal Decree-Law No. (45) of 2021 on Personal Data Protection. 1.22. 23-1 شركة إعادة التأميـن: أي شخص اعتباري ُمرخص له، وفقا المصرف المركزي واألنظمة ً ألحكام قانون له، بممارسة أعمال وأنشطة إعادة الصادرة تنفيذاً التأمين. Reinsurance Company: Any juridical person licensed in accordance with the provisions of the Central Bank Law and the regulations issued in implementation thereof to carry on reinsurance business and activities. 1.23. 24-1 شركة التأمين وشركة إعادة التأمين: شركة التأمين و/أو شركة إعادة التأمين. (Re)Insurance Company: an Insurance Company and/or Reinsurance Company. 1.24. 25-1 تقبل المخاطر: المستوى اإلجمالي وأنواع المخاطر المنشأة الماليَّة ال على استعداد ُم التي تكون رخصة لتحملها، والتي تقررها مسبقا، ضمن قدرتها على تحمل المخاطر، بهدف تحقيق أهدافها االستراتيجية وخطة عملها. Risk Appetite: The aggregate level and types of risk an LFI is willing to assume, decided in advance and within its risk capacity, to achieve its strategic objectives and business plan. 1.25. 26-1 حدود المخاطر: تدابير كمية تستند على افتراضات ّي مستقبلية تُو ّزع إجمال بيان تقبل المخاطر للمنشأة الماليَّة )على سبيل المثال، قياس الخسائر أو األحداث السلبية( على خطوط أعمال أو كيانات قانونية، حسب االقتضاء، وفئات المخاطر الخاصة، والتركزات والمستويات األخرى، حيثما يكون مناسباً. Risk Limits: Quantitative measures based on forward looking assumptions that allocate the financial institution’s aggregate Risk Appetite statement (e.g. measure of loss or negative events) to business lines, legal entities as relevant, specific risk categories, concentrations, and as appropriate, other levels. 1.26. 27-1 درجة تح مل المخاطر: الفرق بينه وبين تقبل المخاطر ال تكون ُم المذكور أعله، أن المنشأة الماليَّة رخصة راغبة في تح ّمل المخاطر. Risk Tolerance: The variation around the prescribed Risk Appetite that the LFI is willing to tolerate. 1.27. 28-1 اإلدارة العليا: اإلدارة التنفيذية للمنشأة الماليَّة ال لمساءلة أمام مجلس اإلدارة ُمرخصة، المسؤولة وا عن اإلدارة اليومية السليمة واالحترازية للمنشأة ُمرخصة، وتشمل بصورة عامة، على سبيل الماليَّة ال المثال ال الحصر، الرئيس التنفيذي، والمسؤول المالي الرئيسي، ومسؤول المخاطر الرئيسي، ورؤساء وظائف االمتثــال والتدقيق الداخلي. Senior Management: The executive management of the LFI responsible and accountable to the Board for the sound and prudent day-to-day management of the LFI, generally including, but not limited to, the chief executive officer, chief financial officer, chief risk officer, and heads of the compliance and internal audit functions. 1.28. 29-1 مخاطر عدم االمتثال ألحكام الشريعة: مخاطر الخسائر المالية أو مخاطر السمعة التي قد تتكبدها أو Shari’ah Non-Compliance Risk (‘SNCR’): risk of financial loss or reputational risk that 1.29.

8 CBUAE Classification: Public تعاني منها منشأة مالية مرخصة بسبب عدم امتثالها ألحكام الشريعة اإلسلمية. an LFI might incur or suffer for not complying with Islamic Shari’ah. 30-1 شركة التأمين التكافلي: شركة تأمين تُمارس أعمال وأنشطة التأمين وفقاً ألحكام ومبادئ الشريعة اإلسلمية وقانون المصرف المركزي واألنظمة له الصادرة تنفيذا . ً Takaful Insurance Company: An Insurance Company that carries on insurance business and activities in accordance with the rules and principles of Islamic Shari`ah, and the Central Bank Law and the regulations issued in implementation thereof. 1.30. 31-1 مز ود الخدمة الخارجي: الشخص الطبيعي أو االعتباري الذي يؤدي خدمات أو أنشطة أو وظائف ُمرخصة بصورة أو عمليات أو مهام للمنشأة الماليَّة ال مباشرة، بما في ذلك في هيئة تعهــيد، ولكن باستثناء ُمرخصة. العمل كموظف لدى المنشأة الماليَّة ال Third-Party Service Provider: a natural or legal person that performs services, activities, functions, processes or tasks directly for an LFI, including in the form of Outsourcing but excluding employment as staff of the LFI. 1.31. المــادة )2(: إطــار إدارة المخاطــر التشغيلية Management Risk Operational Framework ُمرخصة إطــار 1-2 يجب أن يكون لدى المنشأة الماليَّة ال ملئم إلدارة المخاطر التشغيلية، يتضمن استراتيجيات وسياسات وإجراءات ونظم وضوابط وعمليات لتحديد المخاطر التشغيلية وتقديرها وتقييمها ومراقبتها ورفـع تقارير بشأنها وضبطها أو تخفيفها في المواقيت الملئمة. An LFI must have in place an appropriate Operational Risk management framework that includes strategies, policies, procedures, systems, controls and processes to identify, assess, evaluate, monitor, report and control or mitigate Operational Risk on a timely basis. 2.1. 2-2 يجب أن يتم دمج إطار إدارة المخاطر التشغيلية بالكامل في اإلطار العام إلدارة المخاطر والحوكمة ال . ُم لدى المنشأة الماليَّة رخصة The Operational Risk management framework must be fully integrated into the broader risk management and governance framework of the LFI. 2.2. ُمرخصة التحقق من أن 3-2 يجب على المنشأة الماليَّة ال استراتيجية وسياسات وعمليات المخاطر التشغيلية لديها تتسق مع ملف مخاطرها وأهميتها النظامية وتقبلها للمخاطر ودرجة تح ّملها لألعطال واالضطرابات ومتانة رأس مالها، وتأخذ أوضاع السوق وأوضاع االقتصاد الكلي في االعتبار. ولتحقيق هذه الغاية، ال بد من مراجعة هذه العوامل وتعديلها حسبما يكون ملئ ًما، وعلى وجه الخصوص، عندما يحدث تغيير جوهري في ملف المخاطر التشغيلية. The LFI must ensure that its Operational Risk strategy, policies and processes are consistent with its risk profile, systemic importance, Risk Appetite, tolerance for disruption and capital strength, and take into account market and macroeconomic conditions. To this end, these must be reviewed and revised as appropriate, in particular whenever a material change in the Operational Risk profile occurs. 2.3. 4-2 يجب أن يكون إطار إدارة المخاطر التشغيلية شامًل ويتناول كافة الجوانب الجوهرية للمخاطر التشغيلية ُم السائدة في أعمال المنشأة الماليَّة رخصة ، وآخذًا ال في االعتبار، بوجه خاص، المخاطر المتأصلة في The Operational Risk management framework must be comprehensive and address all material aspects of Operational Risk prevalent in the business of the LFI, considering in particular the risks inherent in 2.4.

9 CBUAE Classification: Public جميع المنتجات واألنشطة والعمليات والنظم الجوهرية، بما في ذلك تلك التي تم تعهيدها أو فيها على مزّو خدمة خارجي. االعتماد د all material products, activities, processes and systems, including those Outsourced to or relying on Third Party Service Providers. 5-2 ويجـب أن يكـون إطــار إدارة المخاطــر التشغيلية قً ّ ّد، ويتناول ما يأتي، كحــد موث ــا على نحــو جيــ أدنى: The Operational Risk management framework must be well documented and address the following at a minimum: 2.5. 1-5-2 إطار الحوكمـــة إلدارة المخاطر التشغيلية في شـــكل هيكل حوكمة واضح، متضمنًا التبعية اإلدارية، والمســــؤوليات، والمســـاءلة، وتفويض واضـــح للسلـــطة، بما في ذلك تفويض السلطات للجنة المخاطــر التشغيلية، حيثما ينطبق ذلك؛ The governance framework to manage Operational Risk in the form of a clear governance structure, including reporting lines, responsibilities and accountabilities, and a clear delegation of authority, including for the Operational Risk committee where applicable; 2.5.1. 2-5-2 سياسات وإجــراءات إدارة المخاطــر التشغيلية، بما في ذلك، على وجه الخصوص، تقبــل المخاطــر التشغيلية ودرجة تح ّملها؛ Operational Risk management policies and procedures, including in particular the Operational Risk Appetite and Tolerance; 2.5.2. 3-5-2 األدوات التي سيتم استخدامها لتحديد وتقييم المخاطر والضوابط وكيفية استخدامها، بما في ذلك، على وجه الخصوص، من قِّبل خطوط الدفاع الثلث، وكيف يمكن ضمان تصميمها وتطبيقها وتشغيلها بشكل فعّال. وقد يتضّمن ذلك، على سبيل المثال ال الحصر، األدوات الواردة في الملحــق )1( لهذا النظام؛ The tools that will be used to identify and assess risks and controls and how they will be used, including in particular by the three lines of defence, and how their effective design, implementation and operation will be ensured. These may include but are not limited to the tools listed in Annex 1 to this regulation; 2.5.3. 4-5-2 المصطلحات والمعايير المشتركة التي تضمن االتساق في تحديد وتقييم المخاطر ُمرخصة، على مستوى المنشأة الماليَّة ال وكذلك في المجموعة ككل حيثما ينطبق ذلك؛ Common terminology and standards that ensure consistency of risk identification and assessment throughout the LFI and, where applicable, group; 2.5.4. 5-5-2 وضــع ومعايرة سقــوف أو حـــدود للتعرض للمخاطـــر التشغيلية المتأصلة والمتبقــــية، بما يتوافـــق مع مستويات تقبل المخاطر ودرجة تح ّملها لدى المنشأة ال ، بما في ذلك ما يعتبر ُم الماليَّة رخصة خسائر تشغيلية كبيرة؛ The establishment and calibration of thresholds or Risk Limits for inherent and residual Operational Risk exposure, consistent with the LFI’s Risk Appetite and Risk Tolerance, including what is considered a material operational loss; 2.5.5.

10 CBUAE Classification: Public 6-5-2 متطلـــبات المراقبة المســـتمرة ورفع التقارير بشكل منتظــــم عن سقوف ُمشار إليها في المادة وحــدود المخاطر ال 5-5-2 أعله، بما في ذلك المحتـــوى ين والتواتر المـــلئمين لمختلف المتلقّ ولنظـــام المعلومــــات اإلدارية، وأي متطلبات لإلخطار؛ The requirements for the ongoing monitoring and regular reporting against the thresholds and Risk Limits referred to in Article 2.5.5 above, including the content and frequency appropriate for the various recipients and the management information system, and any notification requirements; and 2.5.6. 7-5-2 واالستراتيجيات واألدوات المعتمــدة لتخفيف المخاطــر. The approved risk mitigation strategies and instruments. 2.5.7. ُمرخصة معالجـة 6-2 يتو ّجــب على المنشآت المالَّية ال وإدارة المخاطر المتعلقـــة باالحتــيال الداخلي والخـــارجي، كجزء من إطار إدارة المخاطر التشغيلية، بمــا في ذلك الحوادث أو التهـــديدات المســتمرة التي تؤثــر على عمـــلئهم. LFIs must address and manage the risks related to internal and external fraud as part of its Operational Risk management framework, including Incidents or ongoing threats affecting their customers. 2.6. المــادة )3(: المـــرونة التشـــغيلية Resilience Operational ُمرخصة 1-3 يجب أن تكون لدى المنشأة الماليَّة ال استراتيجية فعّالة للمرونة التشغيلية، وسياسات وإجراءات ونظم وضوابط مرتبطة بذلك، والتي مع ّط تمكنها من االستجابة لألحداث ال لة والتكيّف م منها لتقليل تأثير مثل معها، والتعافي منها والتعل هذه ّ األحداث على توفير العمليات الحيوية خلل فترات ّطل التع أو االضطراب. ويجب دمج هذه االستراتيجية بشكل جيد في إطار إدارة المخاطر التشغيلية للمنشأة ال . ُم الماليَّة رخصة An LFI must have an effective Operational Resilience strategy and associated policies, procedures, systems and controls that enable it to respond to, adapt to, recover from and learn from, disruptive events to minimise the impact of such events on delivering Critical Operations through disruption. This strategy must be well integrated into the LFI’s Operational Risk management framework. 3.1. 2-3 يجب أن تسـتفيد اســتراتيجية المرونة التشــغيلية ال من إطـــار إدارة ُم للمنشأة الماليَّة رخصة المخاطـــر التشغيلية لتحـــديد التهديدات الداخلية والخــارجية، واإلخفاقات المحتملة لألفـــراد والعمليات والنظــم، على أساس مستمر، وتقييم نقــاط الضعف في العمليات الحيوية وإدارة المخاطر الناتجــة، فــو ًرا. An LFI’s Operational Resilience strategy must leverage the Operational Risk management framework to identify internal and external threats and potential failures in people, processes and systems on an ongoing basis, promptly assess the vulnerabilities of Critical Operations and manage the resulting risks. 3.2. 3-3 يجب أن تحــدد استراتيجية المــرونة التشغيلية وسيــاساتها وعملياتها الظـــروف التي يجب فيها على اإلدارة العليا أن تنبّه مجلس اإلدارة لتعطل أو ِّ ّط اضطراب قائم ل أو محتمل، خاصة تع أو اضطراب قائم أو محتمل للعمليات الحيوية. The Operational Resilience strategy, policies and processes must set out the circumstances in which Senior Management must alert the Board of incidents of disruption or potential disruption, in particular disruption or potential disruption of Critical Operations. 3.3.

11 CBUAE Classification: Public 4-3 يجب على المنشآت الماليَّة ُ المرخصة تحديد عملياتها الحيوية وكافة األصول اللزمة لتقديمها، بما في ذلك بصفة خاصة، األشخاص والتقنيات والعمليات والبيانات والمرافق ومزودي الخدمات الخارجيين، بما في ذلك أي كيانات داخل المجموعة، والترابطات والتبعيات المتبادلة بينهم والتي تعتبر الزمة ألداء العمليات الحيوية خلل فترات التعطل أو االضطراب. ويجب إضفاء الطابع الرسمي على ذلك برسم تخطيطي لكل واحدة من العمليات الحيوية، وتحديثه كجزء من عملية إدارة التغيير. LFIs must identify their Critical Operations and all assets required to deliver them, including in particular the people, technology, processes, data, facilities and Third-Party Service Providers, including any intragroup entities, and the interconnections and interdependencies among them that are necessary for the delivery of Critical Operations through disruption. This must be formalized in a mapping for each of the Critical Operations and updated as part of change management. 3.4. 5-3 كما يجب، كحد أدنى، اعتبار ما يلي ً جزءا من العمليات الحيوية: At a minimum, the following must be considered as part of Critical Operations: 3.5. 1-5-3 التشغيل المستمر ل نظم الدفع وخدمات الدفع والخدمات األخرى التي يكون فيها الوقت ً عنصرا م ًهما لعملء المنشأة الماليَّة ُ المرخصة؛ The continued operation of payment systems, payment services and other time-critical services for the LFI’s customers; 3.5.1. 2-5-3 قـــدرة المنشأة الماليَّة ُ المرخصة على االحتفاظ بســـجلت مالية دقـــيقة ومحـــدّثة لعملئها، ولنفسها؛ The ability of the LFI to maintain accurate and up to date financial records for its customers and itself; 3.5.2. 3-5-3 قدرة المنشأة الماليَّة ُ المرخصة على قياس وإدارة ملءتها وسيولتها في المواقيت الملئمة، بما في ذلك تعرضاتها لكافة المخاطر الجوهرية؛ The ability of the LFI to measure and manage its solvency and liquidity in a timely manner, including its exposure to all material risks; and 3.5.3. 4-5-3 وأي عملية يعتبرها المصرف المركزي حيوية. Any operation deemed to be critical by the Central Bank. 3.5.4. 6-3 يجــب على المنشأة الماليَّة ُ المرخصة أن ّ تطـــور وتحافظ وتراجع بانتظ ــام خطــط إدارة الطوارئ والتعطل واالضطرابات لكـــافة العمليات الحيوية، والتي تتألف من اآلتي ، كحــد أدني: An LFI must proactively develop, maintain and regularly review plans to manage contingencies and disruption for all Critical Operations, consisting of at least the following: 3.6. 1-6-3 خطط اال ستجابة للحوادث: مجموعة من العمليات للكشف عن الحوادث واالستجابة لها والتعــافي منها، بمــا في ذلك، على سبيل المثال ال الحصر، حوادث األمن السيبراني. Incident response plans: a set of processes to detect, respond to and recover from Incidents, including in particular but not limited to cyber security Incidents. 3.6.1. 2-6-3 خطــة استمرارية األعمال: خطـــة عمل مكتوبة شــــاملة، تحـــدد اإلجــراءات والنظــم اللزمة الستمــــرار واستعــــادة Business continuity plan: a comprehensive written plan of action that sets out the procedures and systems necessary to continue or restore the operation of an 3.6.2.

12 CBUAE Classification: Public ّط تشـــغيل المؤسســة في حالة حدوث تع ل أو اضطراب. organisation in the event of a disruption. 3-6-3 خطة التعافي من الكوارث: خطــة شاملة إلدارة حوادث الكوارث التي تؤثـــر على العمليات الحيوية، وتحديدً ا تلك التي تتخذ شكل عـدم توفـــر األصول لفــترة ممتــدة أو بشـــكل دائم. Disaster recovery plan: a comprehensive plan to manage disaster incidents affecting Critical Operations, in particular in the form of prolonged or permanent unavailability of assets. 3.6.3. Role of the Board of Directors اإلدارة مجلس دور :(4 )المــادة 1-4 تقـــع على عاتق مجلس اإلدارة المســـؤولية النهائية عـــن التحـــقق من توفــــر إطار ملئم إلدارة ال ، ُم المخاطـــر التشغيلية لدى المنشأة الماليَّة رخصة مدمج بالكامـــل في اإلطار العام إلدارة المخاطــر ال ، والذي يتضمن إدارة ُم لدى المنشأة الماليَّة رخصة المـرونــة التشغيلية. وتظـل هذه المسؤولية النهائية على عاتق أعضاء مجلس اإلدارة بغض النظــر عـن أي لجــان تابعة لمجلس اإلدارة يتم تشكيلها. The members of the Board bear ultimate responsibility for ensuring that the LFI has an adequate Operational Risk management framework in place that is fully integrated into the LFI’s broader risk management framework and that includes the management of Operational Resilience. This ultimate responsibility is retained by the members of the Board regardless of any Board committees set up. 4.1. 2-4 يجب على مجلس اإلدارة، وليس أي لجنة تابعة لمجلس اإلدارة، أن يعتمـد ويراجع، على األقل سنويًا، كافة استراتيجيات وسياسات المخاطر التشغيلية والمرونة التشغيلية الرئيسية المعتمدة لدى ال ، وعلى وجه الخصوص: ُم المنشأة الماليَّة رخصة The Board, and not a Board committee, must approve and review at least annually the LFI’s key Operational Risk and Operational Resilience strategies and policies, in particular: 4.2. 1-2-4 بيان تقبل المخاطر ودرجة تح ّمل المخاطر ال ، ُم التشغيلية لدى المنشأة الماليَّة رخصة والذي يو ّضح طبيعة وأنواع ومستويات المخاطر التشغيلية التي تكون المنشأة ال مستعدة ألخذها، ويضع ُم الماليَّة رخصة حدود وسقوف المخاطر الملئمـة التي ُمرخصة يجــب على المنشأة الماليَّة ال العمل ضمنهـــا؛ The LFI’s Risk Appetite and Tolerance statement for Operational Risk, articulating the nature, types and levels of Operational Risk the LFI is willing to assume, and that sets appropriate Risk Limits and thresholds within which the LFI must operate; 4.2.1. ُمرخصة 2-2-4 درجة تح ّمل المنشأة الماليَّة ال ّط للتع ل واالضطرابات، مع األخذ في االعتبار قدراتها التشغيلية في مجموعة واسعة من السيناريوهات الشديدة ولكنها معقولة، التي قد توثر على عملياتها الحيوية. كما يجب أن تتناول سياسات مجلس اإلدارة أي ًضا الحاالت التي تكون ُمرخصة غير فيها قدرات المنشأة الماليَّة ال The LFI’s tolerance for disruption, considering its operational capabilities in a broad range of severe but plausible scenarios that would affect its Critical Operations. The Board’s policies must also address instances where the LFI’s capabilities are insufficient to meet its stated tolerance for disruption; and 4.2.2.

13 CBUAE Classification: Public ّط كافية لمقابلة درجة تح ّمل التع ل واالضطرابات التي تم تحديدها؛ ُمرخصة 3-2-4 وخطط المنشأة الماليَّة ال الستمرارية األعمال والتعافي من الكوارث. The LFI’s Business Continuity and Disaster Recovery Plans. 4.2.3. يجب أن تأخذ هذه المراجعة في االعتبار الظروف والتغيرات الحالية والمتوقعة في البيئة الخارجية، ُمرخصة. وفي عمليات المنشأة الماليَّة ال This review must consider current and expected circumstances and changes in the external environment and in the operations of the LFI. ويجوز لمجلس اإلدارة أن يفّوض المراجعة السنوية لخطط استمرارية األعمال والتعافي من الكوارث لواحدة من لجانه، ولكن يجب على مجلس اإلدارة نفسه أن يعتمد الخطط األولية، وأن يراجع الخطط الحقًا كل ثلث )3( سنوات على األقل. The Board may delegate the annual review of the Business Continuity and Disaster Recovery Plans to one of its committees, but the Board must itself approve the initial plans and subsequently review the plans at least every three (3) years. 3-4 يجب أن تكون لدى مجلس اإلدارة عملية رسمية لإلشراف على اإلدارة العليا والتحقق من تنفيذ االستراتيجيات والسياسات التي اعتمدها على نحو فعّال على كافة مستويات القرار، بما في ذلك مستويات تقبل المخاطر التشغيلية ودرجة تح ّمل التعطل واالضطرابات، والحدود والسقوف المرتبطة بذلك. The Board must have in place a formal process to oversee Senior Management and ensure that the strategies and policies it has approved are implemented effectively at all decision levels, including the Operational Risk Appetite and tolerance for disruption and the associated limits and thresholds. 4.3. 4-4 يجب على مجلس اإلدارة أن يعتمد إطار إدارة مخاطر تقنية المعلومات واالتصال واألمن السيبراني للمنشأة ال ، واإلشراف عليها والتحقق من ُم الماليَّة رخصة فعاليتها. The Board must approve, oversee and ensure the effectiveness of the LFI’s ICT and cybersecurity risk management framework. 4.4. 5-4 يجب على مجلس اإلدارة التحقق من أن إطار إدارة المخاطر التشغيلية يخضع لمراجعة مستقلة فعّالة من قِّبل التدقيق الداخلي. The Board must ensure that the Operational Risk management framework is subject to an effective independent review by internal audit. 4.5. 6-4 يجب على مجلس اإلدارة أن يتحقق من أن المنشأة ال تنشئ وتحافظ على ثقافة مخاطر ُم الماليَّة رخصة تشغيلية قوية وبيئة ضبط تدعم وتوفر المعايير والحوافز الملئمة للسلوك المهني والمسؤول. ولتحقيق ذلك، يجب عليه أي ًضا التحقق من أن منهجيته في التعامل مع المخاطر والمرونة التشغيلية قد تم إبلغها بوضوح تام لكافة األطراف المعنية، بما في ذلك الموظفــين، ومزودي الخدمات الخارجيين والكيانات األخرى داخل المجموعــة. The Board must ensure that the LFI establishes and maintains a strong Operational Risk culture and control environment that supports and provides appropriate standards and incentives for professional and responsible behaviour. To this end, it must also ensure that its approach to Operational Risk and Resilience is clearly communicated to all relevant parties, including its staff, third parties and intragroup entities. 4.6.

14 CBUAE Classification: Public 7-4 يكون مجلس اإلدارة مسؤوًال عن تحديد متطلباته الخاصة برفع التقارير عن المخاطر، ويجب أن يكون على دراية بأي قصور في البيانات التي يتسلمها. The Board is responsible for determining its own risk reporting requirements, and must be aware of any limitations in the data it receives. 4.7. 8-4 يجـــب أن يظل مجلس اإلدارة مطلعًا على إدارة ُم المخاطر التشغيلية للمنشأة الماليَّة رخصة ال ومسؤوًال عنها، وأن يكون أعلى سلطة التخـــــاذ القرارات بشأنها. وفي إطــار هذه القيـــود، يجوز لمجلس اإلدارة إنشـــاء لجــــنة أو أكثر من لجان مجلس اإلدارة لتولي مهـــام اإلشـــراف واستلم التقارير واتخاذ القرارات على مستوى أكثر تفصـــي . ًل The Board must remain informed, responsible and the highest authority to take decisions regarding Operational Risk management of the LFI. Within these limitations, the Board may set up one or more Board committees to conduct oversight, receive reporting and take decisions at a more granular level. 4.8. ُمرخصة 9-4 يجب أن يكون لدى جميع المنشآت الماليَّة ال المصنفة من قبل المصرف المركزي على أنها ذات أهمية نظامية لجنة مخاطر تشغيلية تابعة لمجلس اإلدارة، أو لجنة أخرى معّينة من قِّبــل مجلس اإلدارة للتعامــل مع المخاطــر التشغيلية. وللمصرف ا لتقديره، أن يُلزم منشآت ماليَّة المركزي، وفقً مرخصة أخرى بإنشاء لجان مخاطــر تشغيلية تابعة لمجلس اإلدارة، مع مراعاة، من بين أمور أخرى، حجم المنشأة الماليَّة المرخصة ودرجة تعقيدها. All LFIs designated as systemically important by the Central Bank must have a Board Operational Risk committee or other designated Board committee that addresses Operational Risk. The Central Bank may at its discretion require other LFIs to establish a Board Operational Risk committee, taking into account, among others, LFI size and complexity. 4.9. المــادة )5(: دور اإلدارة العلــيا Management Senior of Role 1-5 يجب على اإلدارة العليا أن تتحقق من أن إطار إدارة المخاطر التشغيلية، متضمنًا استراتيجية المرونة التشغيلية، حسبما تم اعتماده من قِّبل مجلس اإلدارة، قد تمت ترجمته إلى سياسات وعمليات وضوابط ونظم فعّالة ومطبقة بشكل جيد على مستوى المنشأة الماليَّة ال . ُمرخصة Senior Management must ensure that the Operational Risk management framework, including the Operational Resilience strategy, as approved by the Board is translated into effective, well-implemented policies, processes, controls and systems throughout the LFI. 5.1. 2-5 يجب على اإلدارة العليا أن تراقـب، بانتظام، ملف المخاطـــر التشـــغيلية والتعرضات التشغيلية ال ، وأن تطبق ُم الجوهرية للمنشأة الماليَّة رخصة عمليات وآليات إعـــداد تقارير فعالة ومتقنة، تمّكن من اإلدارة االستباقية للمخاطــر والمــرونة التشغيلية من قِّــبل مجلس اإلدارة واإلدارة العـليا، بما في ذلك، على وجـــه الخصــوص، خطوط الدفاع الثلثة، ووحدات األعمال. Senior Management must regularly monitor the Operational Risk profile and material operational exposures of the LFI, and implement robust processes and reporting mechanisms that enable proactive management of Operational Risk and Resilience by the Board, Senior Management including in particular the three lines of defence, and the business units. 5.2. 3-5 يجب على اإلدارة العليا أن ترفع تقاري ًرا لمجلس اإلدارة حول المخاطر والمرونة التشغيلية للمنشأة Senior Management must report to the Board about the Operational Risk and Resilience of 5.3.

15 CBUAE Classification: Public ال ، على أساس منتظم، وفي المواقيت ُم الماليَّة رخصة الملئمة، وعلى نحو استباقي. the LFI on a regular, timely and proactive basis. 4-5 يجب على اإلدارة العليا أن تقدم، في الوقت المناسب، تقارير لمجلس اإلدارة، وليس إلى لجنة تابعة لمجلس اإلدارة، بشــأن أي خروقات أو خروقات متوقعة لمستويات تقبل وتح ّمل المخاطر التشغيلية للمنشأة ال ، وحدود وسقوف المخاطر ُم الماليَّة رخصة المرتبطة بذلك. Senior Management must report to the Board, and not to a Board committee, in a timely manner any breaches or expected breaches of the LFI’s Operational Risk Appetite and Tolerance, and the associated thresholds and Risk Limits. 5.4. 5-5 يجب على اإلدارة العليا تطوير نظام للضوابط الداخلية والحفاظ عليه، يحدد بوضوح تــام السلطات والمسؤوليات وعلقـــات التبعــية اإلدارية، لتشجيع وتعــزيز المساءلة على مستوى المنشأة الماليَّة ال . ُمرخصة Senior Management must develop and maintain an internal control system that clearly assigns authority, responsibility and reporting relationships to encourage and maintain accountability throughout the LFI. 5.5. 6-5 يجــب على اإلدارة العليا أن تقــوم، بانتظـــام، وســـنويًا على األقــــل بالنســـبة للبنــوك وشركـــات التأمـــين وشركـــات إعادة التأمـــين، بإجـراء تقييم لنظام الضوابط الداخلية لدى المنشأة الماليَّة ال بشكل رسمي، في هـــيئة "تقرير حول ُمرخصة الضوابط الداخلية". ويجـــب عـرض التقـــييم على مجلس اإلدارة، وتقـــديم التقرير لمجلس اإلدارة والمصرف المركـــزي. ويجــب أن يحــتوي التقــرير وصفًا لتدابير الضوابط الداخلية الرئيسية لكـــافة العمليات الجوهرية ذات الصلة بالعمليات الحيوية، والتقــييم، باإلضافة إلى نظـــرة عامــة على ، أو ال ، بغرض ُم التدابيــر المتخـــذة خطــط اتخــاذهــا تحســين نظــام الضوابط الداخليــة. Senior Management must regularly, and at least annually for Banks and (Re)Insurance Companies, conduct an assessment of the LFI’s internal control system, formalized in the form of a ‘report on internal control’. The assessment must be presented to the Board and the report provided to the Board and the Central Bank. The report must contain a description of the key internal control measures for all material processes related to Critical Operations, the assessment, and an overview of the measures taken or planned to be taken to improve the Internal Control System. 5.6. 7-5 يجب على اإلدارة العليا أن تقّيم بانتظام تصميم وتنفيذ وفعالية إطار إدارة مخاطر تقنية المعلومات واالتصال ومخاطر األمن السيبراني لدى المنشأة ال . ُم الماليَّة رخصة Senior Management must regularly evaluate the design, implementation and effectiveness of the LFI’s ICT and cybersecurity risk management. 5.7. 8-5 يجب على اإلدارة العليا أن تتحقق من توفر موارد كافية في جميع المستويات الوظيفية وفي كافة فروع األعمال، وبما يتماشى مع تقبل وتح ّمل المخاطر ال ، وبما يتناسب مع ُم التشغيلية للمنشأة الماليَّة رخصة أنشطة كل وحدة أعمال. Senior Management must ensure that sufficient resources are available at all levels of seniority and across all business lines in line with the LFI’s Operational Risk Appetite and Tolerance, proportionate to each business unit’s activities. 5.8. ويشمل ذلك التحقــق من أن أنشــطة المنشأة الماليَّة ال يتم إجـــراؤها من قِّبل عـــدد كا ف من ُمرخصة الموظفــين ممن لديهم خبرات كـــافية وقــدرات فنية وإمكانية وصــــول للموارد، ولديهـــم قدر ملئم من This includes ensuring that the LFI’s activities are conducted by a sufficient number of staff with sufficient experience, technical capabilities and access to resources, and with

16 CBUAE Classification: Public الموارد باإلضافة إلى سلطــــات كافـــية مكّرســة للضبط الداخلي وإدارة التغـــيير وأنشـــطة إدارة المخـــاطر. an appropriate amount of resources with sufficient authority dedicated to internal control, change management, and risk management activities. ويجب على اإلدارة العليا أن تشرف على التدريب المنتظم والمناســب للموظفين. Senior Management must oversee that staff is subject to regular and appropriate training. 9-5 وعلى اإلدارة العليا أن تتحقـــق من أن الثقافة المؤســـسية تعكس وتش ّجع ثقافة إدارة مخاطــر تشــــغيلية قوية وفعّالة، وتتحقق من أنهــا تضع معايير ومحفّ على ـــزات للســـلوك المهني والمسؤول ُمرخصة. مستوى المنشأة الماليَّة ال Senior Management must ensure that the corporate culture reflects and inspires a culture of strong Operational Risk management, and ensure that it sets standards and incentives for professional and responsible behaviour throughout the LFI. 5.9. المــادة )6(: وظيفة إدارة المخاطر التشغيلية Function Management Risk Operational ُمرخصة، ضمن 1-6 يجب أن تكون لدى المنشأة الماليَّة ال وظيفة إدارة المخاطر، وحدة إلدارة المخاطر تشغيلية مزّو كافية ال دة بموارد كافية، وتتمتع بدرجة من االستقللية، ويكون مسؤول المخاطر الرئيسي مسؤوًال عنها. Within its risk management function, an LFI must have an Operational Risk management function that is adequately resourced, enjoys a sufficient degree of independence, and for which the Chief Risk Officer is responsible and accountable. 6.1. 2-6 يجب أن تكون وظيفة إدارة المخاطر التشغيلية مسؤولة عن اآلتي، كحـــد أدنـى: The Operational Risk management function must be responsible for the following at a minimum: 6.2. 1-2-6 تطـــوير وجهة نظــر مستقلة بشأن المخاطـر التشغيلية الجوهرية التي تم تحديدهــا في وحــــدات األعمال، وبشأن تصميم وفعاليّة الضوابط الداخلية، ودرجة تح ّمل المخــاطر؛ Developing an independent view regarding the business units’ identified material Operational Risks, the design and effectiveness of internal controls, and the Risk Tolerance; 6.2.1. 2-2-6 التأ ّكـــد من ملءمـــة واتـــساق تطبيق وحــــدات األعمال ألدوات إدارة المخاطـــر التشغيلية وأنشـــطة القياس ونظـــم رفع التقاريــر، وتقديــم توصيــات قابلــة للتطبيق؛ Challenging the relevance and consistency of the business units’ implementation of the Operational Risk management tools, measurement activities and reporting systems, and providing actionable recommendations; 6.2.2. 3-2-6 تطويـــر، والحفاظ على، ســياسات ومعاييــر وإرشــادات إلدارة وقياس المخاطــر التشغيلية؛ Developing and maintaining the Operational Risk management and measurement policies, standards and guidelines; 6.2.3.

17 CBUAE Classification: Public 4-2-6 مراجعــة ملف المخاطر التشغيليــة، والمساهمــة في مراقبــته ورفع التقارير بشأنه؛ Reviewing and contributing to the monitoring and reporting of the Operational Risk profile; 6.2.4. 5-2-6 تحديد المهددات الخارجية والداخلية واإلخفاقات المحتملــة في العملــــيات واألفــراد والنظــم، على أساس مســـتمر؛ Identifying external and internal threats and potential failures in processes, people and systems on an ongoing basis; 6.2.5. 6-2-6 تقــييم نقــاط الضعـف في العمليات الحيوية، وإدارة المخاطـــر الناتجـــة عن ذلك؛ Assessing vulnerabilities of Critical Operations and managing the resulting risks; and 6.2.6. 7-2-6 وتصميــم وإتاحة برامج تدريب حول المخاطر التشغيلية، ورفع الوعــي حول المخاطر التشغيلية في أوســاط أصحاب المصلحة ذوي الصلة. Designing and providing Operational Risk training and raising awareness on Operational Risk among relevant stakeholders. 6.2.7. 3-6 يجب على وظيفة إدارة المخاطر التشغيلية أن ترفع لمجلس اإلدارة، بشكل منتظم، تقارير بشأن نتائج عملها وتوصيــاتها. The Operational Risk management function must regularly report its findings and recommendations to the Board. 6.3. System Control Internal المــادة )7(: نظــام الضــــبط الداخلي 1-7 يجـــب أن يشجع إطــار إدارة المخاطر التشغيلية على إرســاء بيئــة ضـــبط متينة، مدعومـــة بنظــام ضــبط داخلـــي فعّـــال. The Operational Risk management framework must foster a strong control environment supported by an effective internal control system. 7.1. 2-7 ويجــب أن يتناول نظـــام الضــبط الداخلي المكـــ اآلتية: ّونات The internal control system must address the following components: 7.2. 1-2-7 تقييم المخاطر؛ ;assessment risk 7.2.1. 2-2-7 أنشطة الضـــبط؛ ;activities control 7.2.2. 7.2.3. monitoring activities; and المراقبة؛ أنشطة 3-2-7 7.2.4. information and communication. .واالتصال والمعلومات 4-2-7 3-7 يجــب أن يغطي نظـــام الضبط الداخلي كافــة ال ة، بما في ذلك ُم أنشــطة المنشأة الماليَّة رخص ا على مزّودي األنشـطة التي تعتمد بالكــامل أو جزئيً خدمات خارجيين. The internal control system must cover all activities of the LFI, including those that rely in full or in part on Third-Party Service Providers. 7.3. 4-7 يتألف نظام الضبط الداخلي الفعّال من سياسات وعمليات ونظم، بجانب تدابير الضبط المتضمنة فيها لتخفيف أو تقليل احتمالية أو الحد من تأثير المخاطر ذات الصلة. وقد تتضمن تدابير الضبط ما يأتي، على سبيل المثال ال الحصر: An effective internal control system consists of policies, processes and systems, and the control measures they include to mitigate, reduce the likelihood, or limit the impact of associated risks. Control measures may include, but are not limited to: 7.4.

18 CBUAE Classification: Public 1-4-7 صلحيات وعمليات واضحة للموافقات؛ and authorities established Clearly processes for approval; 7.4.1. 2-4-7 فصل بين الواجبات؛ ;duties of Segregation 7.4.2. 3-4-7 ضبط مزدوج، يتم بموجبه تصميم العملية أو النظام بحيث تعمل وحدتان مستقلتان أو أكثر )عادةً أشخاص( بانسجام لحماية الوظائف أو المعلومـــات الح ّساسة؛ Dual control, whereby the process or system is designed such that two or more independent units (usually persons) operate in concert to protect sensitive functions or information; 7.4.3. 4-4-7 مراقبة نظامية لللتزام بحدود وسقوف المخاطــر، بما في ذلك حدود وسقوف المخاطر المنصوص عليها في بيان تقبّل وتحمـــ ؛ ّل المخاطر Systematic monitoring of adherence to risk thresholds and Risk Limits, including those prescribed in the Risk Appetite and Tolerance; 7.4.4. 5-4-7 إجراءات وقائية للتحكم في الوصول إلى ال ة أو تلك ُم أصول المنشأة الماليَّة رخص المعهد بها إليها واستخدامها، بما في ذلك كشف المب ّك البيانات، وتدابير ال ر واإلبلغ عن الوصول غير المص ّرح به أو إساءة استخدام األصول؛ Safeguards for access to and use of the LFI’s assets or those entrusted to the LFI, including data, and measures for the early detection and reporting of unauthorized access or misuse of assets; 7.4.5. 6-4-7 عمليات مستمرة لتحـديد فروع األعمال أو المنتجــات التي يبدو أن عائداتها أو مؤشــراتها األخرى غير متوافقة مع التوقعــات المعقولة؛ Ongoing processes to identify business lines or products where returns or other indicators appear to be out of line with reasonable expectations; 7.4.6. 7-4-7 تحقق ومطابقة منتظمة للمعاملت، والحسابات، ومؤشــرات المخاطــر؛ Regular verification and reconciliation of transactions, accounts, and risk indicators; and 7.4.7. 8-4-7 وسياسة إجازات تُلزم المسؤولين والموظفين بأخـــذ حــد أدنى من اإلجازة يتم تحــديده من ِّقــبل المنشأة الماليَّة ال . ُمرخصة A vacation policy that requires officers and employees to take a minimum leave of absence determined by the LFI. 7.4.8. 5-7 يجــوز استخـدام أدوات نقـــل وتخفيف المخاطر، مثل التأمين، كوسائل تكميلية لإلدارة والضوابط الداخلية للمخاطــر التشـــغيلية، ولكـــن ليس كبديـــل لها. Risk transfer and mitigation tools such as insurance may be used as complementary to, but not as a replacement for internal Operational Risk management and controls. 7.5. 6-7 يجــب أن يتناول نظــام الضــــبط الداخلي المرونــة التشـــغيليـة، ويجب أن يكون هو نفسه مرنًــا من خلل مراعاة الطوارئ المحتملة في العمليات واإلجراءات والنظــم، بما في ذلك توفّر األصول الرئيسية. The internal control system must address Operational Resilience and must itself be resilient by accounting for potential contingencies in processes, procedures and systems, including the availability of key assets. 7.6. 7-7 كجزء من المراجعة الدورية للعمليات وتدابير ال تحديد ُم الضبط، يجب على المنشآت الماليَّة رخصة العمليات والضوابط التي تتضمن تدخلت يدوية، As part of the periodic review of processes and control measures, LFIs must identify processes and controls that involve manual interventions and evaluate whether these can 7.7.

19 CBUAE Classification: Public وتقييم ما إذا كان من الممكن أتمتتها، على سبيل المثال من خلل دمجها في، وإنفاذها من خلل، نظــم تقنية المعلومات واالتصال. be automated, for example through integration into and enforcement by ICT systems. وبالمقابل، وبالنسبة للعمليات والضوابط المؤتمتة، يجب أن تش ّكل فعالية ودقة األتمتة جز ًءا من التقييمات ال أن ُم الدورية، ويجب على المنشأة الماليَّة رخصة تتولى مهمة تحديد وقياس ومراقبة وإدارة مخاطـر التقنية ذات الصلة. Conversely, for processes and controls that are automated, the effectiveness and accuracy of the automation must form part of periodic assessments and a LFI must identify, measure, monitor and manage the related technology risks. ُمرخصة االحتفاظ بسجل 8-7 يجب على المنشأة الماليَّة ال لعملياتها )"الحصر الشامل للعمليات"( يتضمن قائمة ِّ بكافة العمليات وي بيّن مالك العملية ومالك المخاطر. An LFI must maintain a register of its processes (a ‘process universe’) that lists all processes with the process owner and risk owner. 7.8. 9-7 يجب أن يتضمن نظام الضبط الداخلي منهجية "خطوط الدفاع الثلثة"، مع تمييز المسؤوليات والمســــاءلة بيـن: The internal control system must incorporate the “three lines of defence” approach, distinguishing responsibilities and accountability between: 7.9. 1-9-7 إدارة فرع األعمال المسؤولة عن تحديد وضبط المخاطر على أساس مستمر؛ Business line management responsible for identification and control of risks on an ongoing basis; 7.9.1. 2-9-7 وظائف التحكم في إدارة المخاطر واالمتثـــال؛ Control functions of risk management and compliance; and 7.9.2. 3-9-7 والتدقيــق الداخلي، لتوفــير التأكيدات المستقلة. Internal audit to provide independent assurance. 7.9.3. 10-7 يجب أن يتضمن نظام الضبط الداخلي للمنشأة الماليَّة ال عمليات فعّالة ونظم لمراقبة ملفات ُمرخصة المخاطر التشغيلية والتعرضات الجوهرية للمخاطر التشغيلية بشكل منتظم. ويجب أن يتضمن ذلك آلية لرفع التقارير لمجلس اإلدارة واإلدارة العليا ووحدات األعمــال ووظائــف الضبط. ويجب أن تضمــن آليـــات رفـع التقــــارير مــا يأتي: An LFI’s internal control system must include effective processes and systems to regularly monitor Operational Risk profiles and material Operational Risk exposures. This must include reporting mechanisms to report to the Board, Senior Management, business units and the Control Functions. The reporting mechanisms must ensure that reports: 7.10. 1-10-7 أن التقارير شاملــة ودقيقــة ومتّسقــة وقابلة للتنفيــذ؛ are comprehensive, accurate, consistent and actionable; 7.10.1. 2-10-7 وأنها تُرفع في المواقيت المحددة، في الظروف العادية وفي ظروف الضغط، وبتواتر يعكس طبيعة المخاطر والسرعة التي قد تتطّور بهــا؛ are timely in both normal and stressed conditions, and at a frequency that reflects the nature of and pace at which risks may develop; and 7.10.2.

20 CBUAE Classification: Public 3-10-7 وأنها توفر معلومات إجمالية، مع تفاصيل داعمة وملئمة لتمكين متلقيها من فهـم وتقـــييم تعّرضــات المنشأة الماليَّة ال للمخاطــر التشغيلية. ُمرخصة provide aggregate information with appropriate supporting detail to enable the recipients to understand and assess the LFI’s Operational Risk exposures. 7.10.3. 11-7 يجب أن تقدم تقارير المخاطر التشغيلية وصفًا لملف ال من ُم المخاطر التشغيلية للمنشأة الماليَّة رخصة خلل مؤشرات داخلية وخارجية، ومرئيات ذات صلة باتخاذ القرارات. ولتحقيق هذه الغاية، يجب أن تحتوي تقارير المخاطر التشغيلية ما يأتي: Operational Risk reports must describe the Operational Risk profile of the LFI through internal and external indicators and insights relevant to decision making. To this end, Operational Risk reports must contain: 7.11. 1-11-7 وصفًا لملف المخاطر التشغيلية الذي يشير إلى المؤشرات المالية والتشغيلية واالمتثالية، الداخلية والخارجية، واألحداث والظروف ذات الصلة بعملية اتخاذ القرار؛ a description of the Operational Risk profile that refers to internal and external financial, operational and compliance indicators, events and conditions relevant to decision making; 7.11.1. 2-11-7 نظرة عامة على سقوف وحدود المخاطر ال ، ُم التشغيلية للمنشأة الماليَّة رخصة والمؤشرات األخرى ذات الصلة بتقبلها وتح ّملها للمخاطــر؛ an overview of the LFI’s Operational Risk Limits, thresholds and other indicators relevant to its Risk Appetite and Tolerance; 7.11.2. 3-11-7 بيانات واضحة عــن المخاطر التشغيلية المتبقية، وأي أوجـــه قصور في ضبطها، أو عـــدم امتثال لحدود تح ّمل المخاطــر أو المـرونة التشغيلية، وأحداث المخاطــر التشغيلية؛ clear statements on residual Operational Risks, control deficiencies, any non-compliance with Operational Risk or Resilience Tolerances, and Operational Risk events; 7.11.3. 4-11-7 نظرة عامة وتقييم للمخاطــر الرئيسية والناشئة؛ an overview and assessment of key and emerging risks; 7.11.4. 5-11-7 تفاصيل عن آ ِّخر األحداث والخسائر الداخلية الكبيرة المتعلقة بالمخاطر والمرونة التشغيلية، بما في ذلك تحلي ًل للسبب الجذري؛ details of recent significant internal Operational Risk and Resilience events and losses, including a root cause analysis; 7.11.5. 6-11-7 األحداث والمؤشرات الخارجية ذات الصلة، والتغييرات الرقابية وأي تأثير ُمرخصة؛ محتمل لها على المنشأة الماليَّة ال relevant external events and indicators, regulatory changes and any potential impact on the LFI; and 7.11.6. 7-11-7 والتوصيات ذات الصلة، بما في ذلك من خلل خط الدفاع الثاني، ووظائف التدقيق الداخلي والخارجي، وباألخص تلك relevant recommendations, including by the second line of defence, internal audit and external audit functions, in particular those 7.11.7.

21 CBUAE Classification: Public المتعلقة بدقة أو شمولية أو اتســـاق التقرير. relating to the accuracy, comprehensiveness or consistency of the report. 12-7 تجــب مراجعة تقـــارير المخاطــــر التشغيلية بصورة منتظمة للتحقــق من أنها شاملة ودقــيقة ومتّسقة وقابلة للتنفـــيذ، وأنها تلتقــط وتعكس أي ُمرخصة. تغيرات في أنشطة أو بيئة المنشأة الماليَّة ال ويجب رفع تقارير حـول نتائج هذه المراجعــة إلى مجلس اإلدارة واإلدارة العليــا. Operational Risk reports must be regularly reviewed to ensure they are comprehensive, accurate, consistent and actionable, and capture and reflect any changes in the activities or the environment of the LFI. The results of such reviews should be reported to the Board and Senior Management. 7.12. ُمرخصة القيام بصورة 13-7 يجب على المنشأة الماليَّة ال دورية بإجراء اختبارات ضغط تتعلق بالمخاطر التشغيلية، بما في ذلك من خلل ممارسات تختبر بيئة ال ، على سبيل ُم الضبط لدى المنشأة الماليَّة رخصة المثال من خلل اختبار االختراق. ويتضمن ذلك، على سبيل المثال ال الحصر، نظم تقنية المعلومات واالتصال، والضوابط العينية، والضوابط التي تعتمد على األشخاص، وأي عوامل أخرى تشكل المخاطر. An LFI must periodically conduct stress-tests related to Operational Risk, including through exercises that challenge the LFI’s control environment, for example through penetration testing. This includes but is not limited to ICT systems, physical controls, controls relying on people, and any other risk vectors. 7.13. 14-7 وبالنسبة للوظائف بالغة األهمية على األقل، يجب أن يتضمن االختبار الدوري المشار إليه في المادة 13-7 أعله اختبار اختراق من قِّبل طرف خارجي مستقل. ويجب عرض النتيجة على مجلس اإلدارة. At least for Critical Functions, the periodic testing referred to in Article 7.13 above must include penetration testing by an independent third party. The results must be presented to the Board. 7.14. المادة )8(: إدارة تقنية المعلومات واالتصال واألمن السيبراني ICT and Cybersecurity Management ُمرخصة أن تطبق إطا ًرا 1-8 يجب على المنشأة الماليَّة ال فعّا ومتقنًا لمخاطر تقنية المعلومات واالتصال ًال واألمن السيبراني ضمن إطار إدارة المخاطر التشغيلية ومنهجية إدارة المرونة التشغيلية، وتكون لديها سياسات وعمليات ونظــم ملئمــة، لتتولى معالجة: An LFI must implement a robust ICT and cybersecurity risk framework within its Operational Risk management framework and Operational Resilience approach, and have appropriate policies, processes and systems that address: 8.1. 1-1-8 تحديد وتقييم مخاطر تقنية المعلومات واالتصال؛ ICT risk identification and assessment; 8.1.1. 2-1-8 وضع تدابير تخفيف لمخاطر تقنية المعلومات واالتصال، تتسق مع مستويات المخاطر التي تم تقييمها، مثل السياسات والعمليات والنظم الخاصة باألمن السيبراني، واالستجابة والتعافي، وإدارة التغيير، وإدارة الحوادث؛ ICT risk mitigation measures consistent with the assessed risk level, such as policies, processes and systems addressing cybersecurity, response and recovery, change management, and incident management; 8.1.2.

22 CBUAE Classification: Public 3-1-8 المراقبــة واالختــبارات المنتظمة لتدابير التخفيف؛ Regular monitoring and testing of mitigating measures; and 8.1.3. 4-1-8 واإلدارة المستمرة واالستباقية لمخاطر تقنية المعلومات واالتصال واألمن السيبراني. Ongoing, proactive management of ICT and cybersecurity risks. 8.1.4. 2-8 يجب أن يتناول ملف تقبل المخاطر وتح ّمل المخاطر ال مخاطر ومرونة تقنية ُم لدى المنشأة الماليَّة رخصة المعلومات واالتصال واألمن السيبراني، بما في ذلك توقعات واضحة من حيث األداء والمرونة والتح ّمل ّط لحاالت التع ل واالضطرابات. An LFI’s Risk Appetite and Tolerance must address ICT and cybersecurity risk and Resilience, including clear expectations in terms of performance, Resilience and tolerance for disruption. 8.2. ُمرخصة االحتفاظ ببنيـة 3-8 يجب على المنشأة الماليَّة ال أساسية ملئمـة لتقنية المعلومات واالتصال واألمن السيبراني لتلبية متطلبات أعمالها الحالية والمتوقعة في ظل الظروف العادية وفي فترات الضغط. ويجب أن تضمن هذه البنية الحيوية سلمة وسرية وتوفـر البيانات والنظم، وأن تدعم اإلدارة المتكاملة والشاملة للمخاطــر. An LFI must maintain appropriate ICT and cybersecurity infrastructure to meet its current and projected business requirements under normal circumstances and in periods of stress. This infrastructure must ensure data and system integrity, confidentiality and availability and, support integrated and comprehensive risk management. 8.3. 4-8 يجب إبلغ مجلس اإلدارة واإلدارة العليا بانتظام بمخاطر تقنية المعلومات واالتصال واألمن السيبراني التي تتعرض لها المنشأة الماليَّة ال ، بما في ذلك الحوادث ونقـاط الضعف التي ُمرخصة تم تحديدها في تقييمات واختبارات تدابير التخفيف من المخاطر أو مرونة تقنية المعلومات واالتصال. The Board and Senior Management must be regularly informed about the LFI’s ICT and cybersecurity risk exposures, including about incidents and weaknesses identified in assessments and testing of its risk mitigating measures or ICT Resilience. 8.4. ُمرخصة ضمـان مرونة 5-8 يجــب على المنشأة الماليَّة ال تقنية المعلومـــات واالتصال واألمن السيبراني الخاضعة لبرامج الحماية والكشف واالستجابة والتعافـــي. An LFI must ensure resilient ICT and cybersecurity that is subject to protection, detection, response and recovery programmes. 8.5. يجب اختبار هذه البرامج بانتظام، والتي يجب أن تتضمن الوعي الظـرفي، وأن تنقل المعلومات في الوقت المناسب إلدارة المخاطر وعمليات صنع القرار التي تدعم وتسهل تنفيذ العمليات الحيوية. These programmes must be regularly tested, incorporate situational awareness, and convey timely information for risk management and decision-making processes that support and facilitate the delivery of Critical Operations. 6-8 ولدعــم ومواءمة األهداف التجــارية للمنشأة الماليَّة ال ، يجــب أن تتناول سياســة تقنية المعلومات ُمرخصة واالتصال واألمــن السيبراني مــا يأتي، كحـد أدنى: At a minimum, the ICT and cybersecurity policy must address the following in support and alignment of the LFI’s business objectives: 8.6. 8.6.1. Governance and oversight controls; واإلشراف؛ الحوكمة ضوابط 1-6-8

23 CBUAE Classification: Public 2-6-8 مسؤولية المخاطر، والمساءلة، واالمتثال؛ and accountability ,ownership Risk compliance; 8.6.2. 3-6-8 تدابير أمن تقنية المعلومات واالتصال، مثل ضوابط الوصول، وإدارة الهوية، وحماية األصول المعلوماتية بالغة األهمية، وأمن الشبكة، وإدارة أمن المو ّردين، واألمن المادي والبيئي، واختبار نقاط الضعف، وتصنيف المعلومات؛ ICT security measures such as access controls, identity management, Critical Information Asset protection, network security, vendor management security, physical and environmental security, vulnerability testing, and information classification; 8.6.3. 4-6-8 التقييم والمراقبة المنتظمة لضوابط تقنية المعلومات واالتصال، وسياسة الحدود القصوى والسقوف، بما في ذلك سقوف تقبل وتح ّمل المخاطر؛ Regular evaluation and monitoring of ICT controls and policy thresholds and limits, including risk Appetite and Tolerance thresholds; 8.6.4. 5-6-8 إدارة البيانات؛ ;management Data 8.6.5. 6-6-8 إدارة عمليات وخدمات تقنية المعلومات واالتصال، مثل إدارة التغيير وإدارة حزم التصحيح؛ ICT operations and service management, such as change management and patch management; 8.6.6. 7-6-8 خطط االستجابة للحوادث والتعافي، وخطط استمرارية األعمال، وخطط التعافي من الكوارث؛ Incident Response and Recovery Plans, Business Continuity Plans, and Disaster Recovery Plans; 8.6.7. 8-6-8 إدارة مشاريع تقنية المعلومات واالتصال؛ and; management project ICT 8.6.8. 9-6-8 وتطـــوير النظم واقتنائها. and development Systems acquisition. 8.6.9. 7-8 وفيما يخص إدارة مخاطر تقنية المعلومات واالتصال واألمن السيبراني، والعمليات ذات الصلة، لدى ال ، فيجب: ُم المنشأة الماليَّة رخصة An LFI’s ICT and cybersecurity risk management and the related processes must: 8.7. 1-7-8 أن تتم مراجعتها بشكل منتظم لتظل متوافقة مع معايير الصناعة ذات الصلة وأفضل الممارسات، ولتتعامل مع التقنيات والتهديدات الجديدة والناشئة؛ Be reviewed regularly to remain compliant with relevant industry standard and best practices, and to address new and evolving technologies and threats; 8.7.1. 2-7-8 وأن يتم اختبارها بشكل منتظم للتعّرف على الفجوات في تح ّمل المخاطر، ولمراجعة وتحسين تحديد مخاطر تقنية Be regularly tested to identify gaps against its Risk Tolerance and to review and improve ICT and cybersecurity risk identification, 8.7.2.

24 CBUAE Classification: Public المعلومات واالتصال واألمن السيبراني والحماية منها وكشفها، وإدارة األحداث؛ protection, detection and event management; and 3-7-8 وأن تتم االستفادة من المعلومات القابلة للتنفيذ، لتعزيز وضع األمن السيبراني لدى ال بشكل مستمر، ُم المنشأة الماليَّة رخصة والوعي الظرفي بالثغرات في نظم وشبكات وتطبيقات تقنية المعلومات واالتصال، ودعم اتخاذ القرارات الفعالة في إدارة المخاطر والتغيير. Make use of actionable intelligence to continuously enhance the LFI’s cybersecurity posture, situational awareness of vulnerabilities to ICT systems, networks and applications and to support effective decision making in risk and change management. 8.7.3. ُمرخصة إدارة نظم تقنية 8-8 يجب على المنشآت الماليَّة ال المعلومات واالتصال واألمن السيبراني الخاصة بها بشكل استباقي، بما في ذلك تلك التي يتم تشغيلها أو توفيرها من قِّبل مزّودي خدمات خارجيين، وأن يكون لديها استراتيجية وجدول زمني لتجديد نظم األجهزة والبرامج القديمة وغير المدعومة أو إيقاف تشغيلها، في الوقت المناسب. LFIs must proactively manage their ICT and cybersecurity systems, including those operated or made available by Third-Party Service Providers, and have a strategy and timeline for the timely renewal or discontinuation of obsolete and unsupported hardware and software systems. 8.8. 9-8 يجب االحتفاظ بنظام السجلت الرئيس للمنشأة الماليَّة ال وتخزينه بشكل مستمر داخل دولة ُمرخصة اإلمارات العربية المتحدة، بما في ذلك في حاالت ال التي هي ُم التعهيد. ويجوز للمنشآت المالَّية رخصة فروع لمؤسسات مالية أجنبية االمتثال لهذا المطلب من خلل االحتفاظ بنسخة محدثة من نظام السجلت الرئيس في دولة اإلمارات العربية المتحدة، بشرط موافقة المصرف المركزي. An LFI’s Master System of Record must be continuously maintained and stored within the UAE, including in the case of Outsourcing. LFIs that are branches of foreign financial institutions may, subject to Central Bank approval, comply with this requirement by maintaining an up-to-date copy of the Master System of Record in the UAE. 8.9. ُمرخصة االمتثال لألنظمة 10-8 يجب على المنشأة الماليَّة ال الصادرة عن السلطات المختصة بدولة اإلمارات العربية المتحدة، بشأن تقنية المعلومات واالتصال واألمن السيبراني وأمن المعلومات. An LFI must comply with the regulations regarding ICT, cyber and information security issued by the relevant authorities in the UAE. 8.10. Management Incident المــــادة )9(: إدارة الحوادث ُمرخصة أن تطّور وتطبّق 1-9 يجب على المنشأة الماليَّة ال خطط استجابة للحوادث والتعافي، إلدارة الحوادث ّطل التي يمكن أن تع أو تُربك أداء أو مرونة العمليات الحيوية، بما يتماشى مع مستويات تقبلها للمخاطــر ومدى تح ّملها للتعطل واالضطرابات. An LFI must develop and implement Incident Response and Recovery Plans to manage Incidents that could disrupt the delivery or Resilience of Critical Operations in line with its Risk Appetite and tolerance for disruption. 9.1. ولتفادي أي شكوك، يشمل ذلك، على سبيل المثال ال الحصر، حوادث تقنية المعلومات واالتصال واألمن السيبراني. For the avoidance of doubt, this includes but is not limited to ICT and cybersecurity Incidents.

25 CBUAE Classification: Public ُمرخصة أن تقوم بمراجعة 2-9 يجب على المنشأة الماليَّة ال واختبار وتحديث خطـط االستجابة للحوادث والتعافي، بنا على الدروس المستفادة من الحوادث ًء السابقة. وعلى وجه الخصوص، يجب على المنشأة ال تحديد ومعالجـة السبب الجذري ُم الماليَّة رخصة لجميع الحوادث الجوهرية، وتطبيق تدابير لمنعها أو تقليل احتمالية وقوع حوادث أخرى مماثلة لها. An LFI must regularly review, test and update its Incident Response and Recovery Plans, based on lessons learned from previous Incidents. In particular, an LFI must identify and address the root cause of all material Incidents and implement measures to prevent them or reduce the likelihood of further similar Incidents occurring. 9.2. ويجب قياس فعالية هذه العملية ومراجعــتها بشــكل دوري. The effectiveness of this process must be measured and periodically reviewed. ُمرخصة االحتفاظ 3-9 يجب على المنشأة الماليَّة ال بمخزون لجميع الموارد ذات الصلة المطلوبة لدعم قدرات االستجابة والتعافي، بما في ذلك الموارد الداخلية وموارد الجهات الخارجية. An LFI must maintain an inventory of all relevant resources required for supporting its response and recovery capabilities, including internal and third-party resources. 9.3. 4-9 يجب أن تغطي إدارة الحوادث كامل دورة حياة الحادث، بما في ذلك، كحد أدنى: Incident management must cover the full life cycle of an Incident, including at a minimum: 9.4. 1-4-9 تصنيف شدة الحـــادث بناء على معايير محــددة مسبقًا، مــثل التأثير والوقت المتوقــع للعــودة إلى التشغيل العادي، بما يتيح إمكانية تحــديد األولويات المناسبة، وتخصيص الموارد للستجابة للحــادث؛ Classification of an Incident’s severity based on predefined criteria, such as the impact and expected time to return to normal operation, that permits appropriate prioritisation and assignment of resources to respond to the Incident; 9.4.1. 2-4-9 إجراءات االستجابة للحادث والتعافي، وكيــفية ارتباطها بتدابير طــوارئ أخــرى، مثل خطــة استمراريـة األعمــال؛ Incident response and recovery procedures, and how they relate to other contingency measures such as the Business Continuity Plan; 9.4.2. 3-4-9 أدوار ومسؤوليات الموظفين ومزودي الخدمات الخارجيين فيما يتعلق بتسجيل الحوادث وتحليلها وتصعيدها واتخاذ القرارات بشأنها وحلها ومراقبتهــا؛ Roles and responsibilities of staff and external parties with regard to the recording, analysis, escalation, decision-making, resolution and monitoring of Incidents; 9.4.3. 4-4-9 خطـط اتصال لإلبلغ عــن الحوادث ألصحاب المصلحة الداخليين والخارجيين، بما في ذلك المصرف المركــزي والسلطات األخرى عندما يكون ذلك مطلوبًا، والتي تتضمن اإلبلغ عن مقاييس األداء ذات الصلة للحــوادث الجارية وتحــليل الدروس المســتفادة بعد أن يتم حل ومعالجة الحــادث؛ Communication plans to report incidents to internal and external stakeholders, including to the Central Bank and other authorities where required, that include reporting relevant performance metrics for ongoing Incidents and an analysis with lessons learned after an Incident has been resolved; and 9.4.4.

26 CBUAE Classification: Public 5-4-9 وتوثيق كافة الحوادث في سجل، بما في ذلك طبيعة الحادث واإلجراءات المتخذة والنتائج. Documentation of all Incidents in a register, including the nature of the Incident, the actions taken and the outcomes. 9.4.5. 5-9 يجب أن تغطي إدارة الحوادث لدى المنشأة الماليَّة ال كافة العمليات الحيوية، وتتناول كافة ُمرخصة الموارد ذات الصلة المطلوبة للحفاظ على مرونة هذه واستمراريتها، وفقًا للرسم التخطــيطي العمليات المطلوب بموجب أحكام المادة 4-3 من هذا النظــام. An LFI’s incident management must cover all Critical Operations and address all relevant resources required to maintain their Resilience and continuity, as per the mapping required under Article 3.4 of this Regulation. 9.5. المــــادة )10(: بيانات ونظــم المخاطر Systems and Data Risk 1-10 يجب أن توفر نظم مخاطر المعلومات لدى المنشأة ال ، القدرات واألداء اللزمين، بما ُم الماليَّة رخصة ُمرخصة، يعكس ملف مخاطــر المنشأة الماليَّة ال قــد عملياتها، وأهميتها النظامية، بما في ودرجــة تعّ ذلك خلل ظــروف الضــغط أو األزمـات. An LFI’s risk information systems must deliver the capabilities and performance necessary, reflecting the LFI’s risk profile, complexity and systemic importance, including during stressed circumstances or a crisis. 10.1. ُمرخصة ترتيبات 2-10 يجب أن تكون لدى المنشأة الماليَّة ال حوكمة وضوابط داخلية كافية إلدارة وحماية البيانات على نحو فعّال. An LFI must have in place adequate governance arrangements and internal controls to effectively manage and protect data. 10.2. 3-10 يجب على نظم تقنية المعلومات واالتصال لدى أن تُمّك من القيام بما يأتي ال ِّن ُم المنشأة الماليَّة رخصة بشكل فعّال: An LFI’s ICT systems must enable the LFI to effectively: 10.3. 1-3-10 مراقبة المخاطر والمرونـة التشغيلية على أساس زمني منتظم وبشكل مستمر؛ monitor Operational Risk and Resilience on a timely and ongoing basis; 10.3.1. 2-3-10 تجميع وتحليل بيانات المخاطر وبيانات أحداث المخاطر التشغيلية بشكل موثوق ودقيق، بما في ذلك بيانات الخسائر الداخلية والخارجية الشاملة؛ reliably and accurately compile and analyse risk data and Operational Risk event data, including comprehensive internal and external loss data; and, 10.3.2. 3-3-10 وتلبية جميع متطلبات رفع التقارير، بما في ذلك داخليًا لمجلس اإلدارة واإلدارة العليا وفروع األعمال، وخارجًيا للعملء والسلطات ذات الصلة، بما في ذلك المصرف المركزي، بما يشمل متطلبات ّ إعداد التقارير الوقتية أثناء ل تعطــ أو اضطراب أو أزمة جاريــة. meet all necessary reporting requirements, including internally to the Board, Senior Management and business lines, and externally to customers and relevant authorities including the Central Bank, including ad hoc reporting 10.3.3.

27 CBUAE Classification: Public requirements during an ongoing disruption or crisis. 4-10 يجب أن تخضع عمليات التجميع ورفع التقارير لمعايير تحقق عالية، ومراجعة دورية من ِّقبل وظيفــة التدقيق الداخلي. The aggregation and reporting processes must be subject to high standards of validation and periodic review by the internal audit function. 10.4. ُمرخصة التي هي جزء من 5-10 وفي حالة المنشأة الماليَّة ال مجموعة، يجب أال يكون هيكل المجموعة أو مناطق االختصاص التي تقع فيها الشركات التابعة والفروع، بلهم، عائقًا أو النظم والعمليات المستخدمة من قِّ للتجميع الفعّال، وفي المواقيت المناسبة، لبيانات المخاطر. For an LFI that is part of a group, effective and timely risk data aggregation must not be hindered by the group structure or the jurisdictions in which subsidiaries and branches are located, or by the systems and processes used by them. 10.5. المــــادة )11(: تخطيط استمرارية األعمــال Planning Continuity Business ُمرخصة االحتفاظ بخطط 1-11 يجب على المنشأة الماليَّة ال استمرارية أعمال وتعافي من الكوارث لعملياتها الحيوية. ويجب أن يتم دمجها بشكل جيد في إطار المخاطر التشغيلية والمرونة التشغيلية للمنشأة الماليَّة ال . ُمرخصة An LFI must maintain Business Continuity and Disaster Recovery Plans for its Critical Operations that are well-integrated into the LFI’s Operational Risk and Operational Resilience framework. 11.1. 2-11 يجب على خطط استمرارية األعمال والتعافي من الكوارث أن تستفيد من، وترجع إلى، الرسم التخطيطي للعمليات الحيوية واألصول ذات الصلة، كما هو مطلوب بموجب المادة 4-3 من هذا النظام. The Business Continuity and Disaster Recovery Plans must leverage and refer to the mapping of Critical Operations and related assets as required under Article 3.4 of this Regulation. 11.2. 3-11 يجب على خ َّطي الدفاع الثاني والثالث للمنشأة الماليَّة ال ، وبخاصة وظيفة إدارة المخاطر التشغيلية ُمرخصة ووظيفة التدقيق الداخلي، مراجعة خطط استمرارية األعمال والتعافي من الكوارث بانتظام. ويجب أن يكون ذلك مرة واحدة في السنة على األقل بالنسبة للعمليات الحيوية. The LFI’s second and third lines of defence, in particular the Operational Risk management function and internal audit function, must regularly review the Business Continuity and Disaster Recovery Plans. This should be at least once per year for Critical Operations. 11.3. 4-11 يجب أن تحــدد خطط استمرارية األعمال والتعافي ّط من الكـــوارث سيناريوهات ا لتع ــل أو االضطراب المحتملة ذات الصلة، وكيف ستؤثر على العمليات ال ، مع األخذ في ُم الحيوية للمنشأة الماليَّة رخصة االعتبار الترابطات الداخلية والخارجية. ويجب أن تعالج الخطط الطوارئ المحتملة لضمان عدم التأثير على سرعة تنفيذها، على سبيل المثال، بسبب عدم توفــر موظفيــن رئيسيين. The Business Continuity and Disaster Recovery Plans must identify relevant potential disruption scenarios and how these would affect the LFI’s Critical Operations, taking into account internal or external interdependencies. The plans must address potential contingencies to ensure their swift implementation is not compromised, for example due to unavailability of key staff. 11.4. 5-11 يجب أن يتراوح نطـاق سيناريوهات التع ّطل أو االضطراب من سيناريوهات تكون فيها العودة إلى The range of disruption scenarios must range from scenarios where a return to normal operations is possible with the same assets, to 11.5.

28 CBUAE Classification: Public العمليات العاديــة ممكنة بنفس األصول، إلى سيناريوهات تصبح فيها األصول الجوهرية غير متاحـة لفترات طويلــة، أو بشكل دائم دون أن تكون قابلة للستعادة. scenarios where major assets are rendered unavailable for prolonged periods or permanently without being recoverable. 6-11 يجب أن يخضع كل سيناريو لتقييم األثر الكمي والنوعي، أو لتحليل التأثير على األعمال، مع التمييز بيــن التأثير المالي والتشغيلي والقانوني وعلى السمعة. Each scenario must be subject to a quantitative and qualitative impact assessment or a business impact analysis, distinguishing between financial, operational, legal and reputational impact. 11.6. 7-11 يجب أن تتضمن خطط استمرارية األعمال والتعافي من الكوارث مؤشرات واضحة وال لبس فيها لتفعيل هذه الخطــط، مثل سـقوف محددة ألقصى تع ّطل أو اضطراب أو انقطاع يمكن تحمله. Business Continuity and Disaster Recovery Plans must include clear, unambiguous triggers for their activation, such as defined thresholds for the maximum tolerable disruption or outage. 11.7. 8-11 يجب أن تتناول خطـط استمرارية األعمــال والتعافي من الكــوارث اإلجراءات التي سيتم اتخاذها في حال انقطاع أو اضطراب استمرارية األعمـــال، وتضع دافًا واضحة وقابلة للقــياس في شــكل أهداف أهــ زمنية للتعافي وأهــداف نقطـــة التعافي، والتي تعكس درجة تحــ ّمل التعطل واالضطرابات حسبما تم اعتمــاده من ِّقبل مجلس اإلدارة. Business Continuity and Disaster Recovery Plans must address the actions that will be taken in case of a disruption to business continuity, and establish clear, measurable targets in the form of recovery time objectives and recovery point objectives, that reflect the tolerance for disruption as approved by the Board. 11.8. 9-11 يجـب أن تتضــمن خطط استمرارية األعمال والتعافي من الكوارث إرشادات وترتيبات اتصال ألصحاب المصلحة الرئيسيين ذوي الصلة، بما في ذلك، مجلس اإلدارة واإلدارة العليا والموظفين والسلطات ذات الصلة، بما في ذلك، على سبيل المثال ال الحصر، المصرف المركــزي، وكذلك العمــلء والجمهور بوجـــه عام، ومزودي الخدمــات الخارجيين. Business Continuity and Disaster Recovery Plans must include communications guidelines and arrangements for key relevant stakeholders, including the Board, Senior Management, staff, relevant authorities including but not limited to the Central Bank, customers and the wider public, and Third￾Party Service Providers. 11.9. 10-11 تجب مراجعة واختبار خطط وإجراءات استمرارية األعمال والتعافي من الكوارث بانتظام لضمان إمكانية تحقيق أهداف التعافي واستئناف األعمال واألطر الزمنية. ويجب أن يكون ذلك سنويًا على األقل بالنسبة للعمليات الرئيسية. ويجب، عند االقتضاء، أن يشمل االختبار مزودي الخدمات الخارجيين الرئيسيين. ويجب رفع تقارير عن النتائج إلى مجلس اإلدارة واإلدارة العليا. Business Continuity and Disaster Recovery Plans and procedures must be reviewed and tested regularly to ensure that the recovery and resumption objectives and timeframes can be met. This must be at least annually for Critical Operations. Where relevant, testing should include key Third-Party Service Providers. The results must be reported to the Board and Senior Management. 11.10. ُمرخصة أن تقوم بإجراء 11-11 يجب على المنشأة الماليَّة ال تمرينات استمرارية أعمال وتعا ف من الكوارث تحت مجموعة من السيناريوهات الشديدة، ولكنها معقولة، An LFI must conduct Business Continuity and Disaster Recovery exercises under a range of severe but plausible scenarios to assess its 11.11.

29 CBUAE Classification: Public لتقييم قدرتها على أداء العمليات الحيوية خلل فترات ّطل التع أو االضطرابات. ability to deliver Critical Operations through disruption. المــــادة )12(: إدارة التغيـــيــر والتغـــييرات في العمليــــات Change Management and Changes in Operations ُمرخصة عملية 1-12 يجب أن تتوفر لدى المنشأة الماليَّة ال زّو بموارد كافية للتخطيط بشكل إدارة تغيير م دة استباقي إلدارة واعتمـــاد التغييرات في العمليات، بما في ذلك إدخـال أو إيقاف أو إجــراء تغيــيرات على المنتجــات واألنشــطة والعمليات والنظـم. LFIs must have a well-resourced change management process in place to proactively plan for, manage and approve Changes in Operations, including the introduction of, discontinuation of, or changes to products, activities, processes and systems. 12.1. 2-12 يجب أن تشــارك وظيفــة إدارة المخاطر التشغيلية خلل عملية إدارة التغيير للتحقق من تنفــيذ الضـوابط الملئمـة، وضمان مشـــاركة وظــائف الضــبط ذات الصـــلة. The Operational Risk management function must be involved throughout the change management process to ensure the implementation of appropriate controls and to ensure the involvement of the relevant Control Functions. 12.2. ُمرخصة 3-12 يجب أن تتوفـر لدى المنشآت الماليَّة ال سياســات وإجــراءات إدارة تغيير تتناول عملـــية تحــديد وإدارة، واختبار واعتمـــاد ومراقبـــة التغييرات في العمليات، مع مراعاة ما يأتي، كحــد أدنى: LFIs must have change management policies and procedures that address the process for identifying, managing, challenging, approving and monitoring changes in operations, considering at a minimum: 12.3. 1-3-12 المخاطر المتأصلة، بما في ذلك، على سبيل المثال ال الحصر، المخاطر القانونية والمخاطر المالية ومخاطر االمتثال ومخاطر النماذج ومخاطر تقنية المعلومات واالتصال؛ Inherent risks, including but not limited to legal, financial, compliance, model and ICT risks; 12.3.1. 2-3-12 التغييرات في ملف مخاطر المنشأة الماليَّة ال ، بسبب التغيير نفسه أو بسبب ُمرخصة تأثيره على األنشطة األخرى ذات الصلة، واالمتثال لتقبلها للمخاطر ولدرجة تح ّمل المخاطر؛ Changes in the LFI’s risk profile, both due to the change itself and due to its impact on other related activities, and compliance with its Risk Appetite and Tolerance; 12.3.2. 3-3-12 الضوابط اللزمـــة، وعمليات إدارة المخاطـــر، واستراتيجيات التخفيف من المخاطــر؛ Necessary controls, risk management processes and risk mitigation strategies; 12.3.3. 4-3-12 المخاطر المتبقية؛ ;risk Residual 12.3.4. 5-3-12 اإلضافات أو التغييرات على سقوف أو حدود المخاطر ذات الصلة؛ Additions or changes to relevant Risk Limits or thresholds; 12.3.5.

30 CBUAE Classification: Public 6-3-12 إجراءات ومعايير لقياس ومراقبة وإدارة مخاطر التغييرات في العمليات؛ Procedures and metrics to measure, monitor and manage the risk of the Changes in Operations; 12.3.6. 7-3-12 القدرات المتاحة والمطلوبة من حيث الموارد، بما في ذلك بوجه خاص، من حيث البنية التحتية التقنيّة، والموظفين والخبراء في كافة األدوار ذات الصلة، بما في ذلك على مستوى مجلس اإلدارة واإلدارة العليا وجميع خطــوط الدفــاع الثلثة؛ The available and required capacity in terms of resources, including in particular in terms of technology infrastructure, staffing and expertise in all relevant roles, including at the level of the Board, Senior Management, and all three lines of defence; 12.3.7. 8-3-12 مشاركـة خطـوط الدفــاع الثلثة وأدوارها في عملية إدارة التغيير؛ The participation and roles of the three lines of defence in the change management process; 12.3.8. 9-3-12 التأثير واإلضافات أو التغييرات المطلوبة على الرسم التخطيطي للعتماد المتبادل بين العمليات الحيوية وخطط استمرارية األعمال وخطط التعافي من الكوارث، وغيرها من الجوانب ذات الصلة بإطــار إدارة المخاطــر التشـــغيلية؛ The impact and required additions or changes to the mapping of interdependencies of Critical Operations, the business continuity and disaster recovery plans, and other relevant aspects of the Operational Risk management framework; 12.3.9. 10-3-12 التأثيــر على بيـــانات ونظــم المخاطــر، أو نطــاق البـــيانات التي يجب جمعها أو التقاطهـــا؛ The impact on risk data and systems or the scope of data that has to be captured; 12.3.10. 11-3-12 التواصل االستباقي مع كافة أصحاب المصلحة الداخليين والخارجيين، بما في ذلك، عند االقتضـــاء، مزودي الخدمــات الخارجيين؛ Proactive communication with all relevant internal and external stakeholders, including, where applicable, third-party service providers; and 12.3.11. 12-3-12 وبالنسبة لما سبق أعله، كيفية تطبيقه في حالة حدوث تغييرات عاجلــة أو طارئة في العمليات. For each of the above, how these would apply in case of urgent or emergency Changes in Operation. 12.3.12. ُمرخصة مراقبة 4-12 يجب على المنشآت الماليَّة ال التغييرات في العمليات بعد تنفيذها لتحديد وإدارة أي اختلفات جوهرية في ملف المخاطر التشغيلية المتوقع. LFIs must monitor the changes in operations after their implementation to identify and manage any material differences to the expected Operational Risk profile. 12.4. 5-12 يجب أن تخضع التغييرات في العمليات التي تكون جوهرية بالنسبة إلى العمليات الحيوية، أو العمليات التي قد تؤثر بشكل جوهري على العملء، لدرجة Changes in Operations that are material to Critical Operations or operations that may materially affect customers must be subject to 12.5.

31 CBUAE Classification: Public عالية من تدابير اإلشراف والضبط. وفي هذا الصدد، ُمرخصة: يجب على المنشآت الماليَّة ال a high degree of oversight and control measures. In this regard, LFIs must: 1-5-12 التحقق من إجراء اختبار دقيق للتغييرات في العمليات قبل تطبيقها، ومراجعة واعتماد النتائج من ِّقبل أصحاب المصلحة ذوي الصلة؛ Ensure thorough testing of Changes in Operation prior to their implementation, and review and approval of the results by the relevant stakeholders; 12.5.1. 2-5-12 وضع خطط للتعافي من اإلخفاقات خلل التطبيق، بما في ذلك، بوجه خاص، خطة لسحب التغييرات، وفي حال استبدال نظام تقنية المعلومات واالتصال بنظام آخر، ز للنظ مين إجراء تشغيل موا ا القديم والجديد، لمـــدة زمنية محددة مسبقًا وتكون طويلة بما يكفي للتحقـق من أن النظام الجديد يعمــل بشــكل جيد ومــرن؛ Establish plans to recover from failures during implementation, including in particular a rollback plan and, where one ICT system is replaced by another, a parallel run of the old and new systems for a predefined minimum period long enough to ensure that the new system is functional and resilient; 12.5.2. 3-5-12 التعاقد مع خبير خارجي لتقديم تأكيد مستقل في مراحل رئيسية من العملية، بما في ذلك تقري ًرا يقّيم التغييرات المقترحــة في العمليات، وضوابــط وتدابيــر إدارة التغيير؛ Procure an external expert to provide independent assurance at key steps in the process, including a report assessing the proposed Changes in Operations and the change management controls and measures; 12.5.3. 4-5-12 تكون اإلدارة العليا مسؤولة عن مراجعة ومصادقة تقرير الخبير الخارجي والرد عليه، قبل تزويد المصرف المركــزي بالتقرير؛ Senior Management is responsible to review, endorse and respond to the external expert report prior to providing the report to the Central Bank; 12.5.4. 5-5-12 إخطار المصرف المركزي وتزويده بتقرير الخبير الخارجي، قبل 30 يو ًما تقويميًا على األقل من تنفيذ التغييرات في العمليـات؛ Notify the Central Bank and provide it with the external expert’s report at a minimum 30 calendar days prior to the proposed implementation of the Changes in Operation; and 12.5.5. 6-5-12 والحصول على عدم ممانعة كتابية من المصرف المركزي قبل الشروع في تنفيذ التغييرات في العمليات. Obtain the written no-objection of the Central Bank prior to implementation of the Changes in Operation. 12.5.6. ُمرخصة التحــقق من 6-12 يجب على المنشآت الماليَّة ال عدم تأثر عملئها سلبًا بالتغييـرات في عملياتها. وبصفة خاصة، عندمـــا تؤدي التغييرات في العمليات إلى تقديم معلومات جوهــرية خاطئة للعملء، مثل تأكــيدات الدفع، أو معاملت اإلضافة LFIs must ensure that their customers are not negatively affected by changes in their operations. In particular, where Changes in Operations result in material erroneous information being provided to customers, such as payment confirmations, debit or credit 12.6.

32 CBUAE Classification: Public أو الخصم، واألرصدة الدائنة والمدينة، فيجب على ال تزويد العملء بمعلومات ُم المنشآت الماليَّة رخصة واضحة حول كيفية تأثر حساباتهم أو معاملتهم نتيجة لذلك، بما في ذلك كجزء من الجهود المبذولة لمعالجة ُم األخطاء. وتتحمل المنشآت الماليَّة رخصة ال المسؤولية عن أي أضرار يتكبدها العميل بسبب خطأ ال ، بما يتوافق مع أنظمة حماية ُم المنشأة الماليَّة رخصة المستهلك الصادرة عن المصرف المركزي. transactions and balances, LFIs must provide customers with clear information on how their accounts or transactions were affected as a result, including as part of efforts to address the errors. LFIs are liable for any damages incurred by the customer due to the LFI’s error, consistent with the Central Bank’s consumer protection regulations. المــــادة )13(: إدارة مخاطـــر مزودي الخدمات الخارجيين Management Risk Party Third ُمرخصة 1-13 يجب أن تكون لدى المنشآت الماليَّة ال اســتراتيجية معتمدة من مجلس اإلدارة، وسياسات وعمليات مرتبطة بها، ألغراض تقييم ومراقبة وإدارة مخاطر مزودي الخدمات الخارجيين، مدمجة في إطار إدارة المخاطر التشغيلية. LFIs must have a Board-approved strategy and associated policies and processes for the assessment, monitoring and management of third-party risk, integrated into their Operational Risk management framework. 13.1. ُمرخصة عدم 2-13 كمبدأ عام، يجب على المنشآت الماليَّة ال االعتماد بشكل مفرط على التعهيد، بل الحفاظ على عدد كا ف من الموظفين والخبرات والموارد الخاصة بها لضمان أداء وإدارة األنشطة التي ُرخصوا لها، بشكل فعال. As a general principle, LFIs must not overly rely on Outsourcing and maintain sufficient staff, expertise, and resources of its own to effectively perform and manage the activities for which it is licensed. 13.2. ُمرخصة الدخـــول في 3-13 ال يجـــوز للمنشأة الماليَّة ال قبل القيام أوًال ترتيبات مع مزود خدمة خارجي بإجراء تقييم مخاطر هذه الترتيبات، وتطبيق إجراءات عناية واجبة ملئمة بشـــأن مزود الخدمة الخارجي. An LFI must not enter into an arrangement with a Third-Party Service Provider without first performing a risk assessment of the arrangement and conducting appropriate due diligence on the Third-Party Service Provider. 13.3. 4-13 بالنسبة للترتيبات المتعلقة بالعمليات الحيوية أو التي ُمرخصة تؤثر عليها، يجب على المنشأة الماليَّة ال تو ًى التحقق من أن لدى مزود الخدمة الخارجي مســ مكافئًا من المرونة التشغيلية على األقل، لحماية العمليات الحيوية في الظـروف العادية وفي حالة ّط حدوث تع ل أو اضطراب. For arrangements that relate to or have an impact on Critical Operations, the LFI must verify that the Third-Party Service Provider has at least an equivalent level of Operational Resilience to safeguard the Critical Operations in both normal circumstances and in the event of disruption. 13.4. ُمرخصة الحصول على 5-13 يجب على المنشأة الماليَّة ال إشعار بعدم الممانعة من المصرف المركزي قبل تعهيد أي نشاط تكون لديه، في حال تعطله أو حدوث اضطراب فيه، إمكانية إحداث تأثير كبير على ال . ُم العمليات الحيوية للمنشأة المالَّية رخصة An LFI must obtain a notice of non-objection from the Central Bank prior to Outsourcing any activity that has the potential, if disrupted, to have a significant impact on the LFI’s Critical Operations. 13.5. 6-13 يجــب أن تخضع ترتيبات مزود الخدمة الخارجي ِّز لعقــود كتابية مل مة قانونًا، تحــدد بوضوح حقوق والتزامات ومسؤوليات وتوقعات جميع األطراف في Third-Party Service Provider arrangements must be governed by legally binding, written contracts that clearly set out the rights and 13.6.

33 CBUAE Classification: Public الترتيبات، بما في ذلك فيما يتعلق بملكية وســرية البيـــانات، وحقوق اإلنهــاء، وبالنسبة للترتيبات التي ُمرخصة أو تتعلق بالعمليات الحيوية للمنشأة الماليَّة ال ُمرخصة في فحص تؤثر عليها، حق المنشأة الماليَّة ال سجــلت مزود الخدمة الخارجي، وطلب واستلم التقـــارير، مثل تقـــارير التدقـــيق والمخاطر. obligations, responsibilities and expectations of all parties to the arrangement, including regarding ownership and confidentiality of data and termination rights, and, for arrangements that relate to or have an impact on the LFI’s Critical Operations, the LFI’s right to inspect the Third-Party Service Provider’s records, to request and receive reporting such as audit and risk reports. ًما لمزود الخدمة الخارجي 7-13 يجب أن يتضمن العقد إلزا باالمتثال لطلبات ومتطلبات المصــرف المركزي، بما في ذلك متطلبات اإلخطار ورفع التقارير، وبالنسبة لترتيبات التعهيد التي قد تؤثر على العمليات ال ، حق المصــرف ُم الحيوية للمنشأة الماليَّة رخصة المركزي في إجراء عمليات تفتيش ميداني تتعلق ُمرخصة. بالخدمــات التي يقدمها للمنشأة الماليَّة ال The contract must include a requirement for the Third-Party Service Provider to comply with Central Bank requests and requirements, including notification and reporting requirements and, for Outsourcing arrangements that could impact the LFI’s Critical Operations, the right of the Central Bank to conduct on-site examinations related to the services they provide to the LFI. 13.7. 8-13 بالنسبة للترتيبات التي تنطوي أو قد تنطوي على ُمرخصة أو عملئها مشاركة بيانات المنشأة الماليَّة ال من قِّبل مزود الخدمة الخارجي مع متعهدين فرعيين آخــرين، يجب تطبيق أحكـــام المادتين 6-13 و-13 7 أعله وأن تكون قابلة للتنفـــيذ قانونًا من خلل عقد، ضد أولئك المتعهدين الفرعيين. For arrangements that involve or may involve the LFI’s or its customers’ data being shared by the Third-Party Service Provider with further subcontractors, the provisions of Articles 13.6 and 13.7 above must apply and be legally enforceable through contract against those subcontractors. 13.8. ُمرخصة االحتفاظ بموارد 9-13 يجب على المنشأة الماليَّة ال كافية إلدارة ومراقبة ترتيبات الخدمات المقدمة من مزودي الخدمات الخارجيين، ويجب أن يتناول نظام الضوابط الداخلية الخاص بها تدابير الضوابط ذات الصلة، بما في ذلك، كحـد أدنى: An LFI must maintain adequate resources to manage and monitor Third-Party Service arrangements, and its internal control system must address the related control measures, including at a minimum: 13.9. 1-9-13 االحتفاظ بسجل محدّث لألنشطة المعهد بها لمزودي الخدمات الخارجيين، وترتيبات الخدمات المقدمة من قِّبل مزودي الخدمات الخارجيين المتعلقة بالعمليات الحيوية؛ Maintaining an updated register of Outsourced activities and Third￾Party Service arrangements relating to Critical Operations; 13.9.1. 2-9-13 مؤشرات لقياس ومراقبة األداء والمخاطر ذات الصلة بترتيبات الخدمات المقدمة من مزودي الخدمات الخارجيين، على أساس مستمر؛ Metrics to measure and monitor performance and risks related to Third-Party Service arrangements on an ongoing basis; 13.9.2. 3-9-13 تقييمات ورفع تقارير بشأن أداء ترتيبات الخدمة المقدمة من مزودي الخدمات الخارجيين والمخاطر المتعلقة بها على Assessments of and reporting on the performance of and risks related to Third-Party Service Provider arrangements on an ongoing basis, 13.9.3.

34 CBUAE Classification: Public أساس مستمر، بما في ذلك الوضع المالي لمزودي الخدمات الخارجيين؛ including the financial condition of Third-Party Service Providers; and 4-9-13 وإدارة حاالت االعتماد على ترتيبات الخدمات التي يقدمها مزودي الخدمات الخارجيين فيما يتعلق بالعمليات الحيوية. Management of dependencies on Third-Party Service Provider arrangements for Critical Operations. 13.9.4. ُمرخصة، في إطار 10-13 يجب على المنشأة الماليَّة ال المخاطر التشغيلية والمرونة التشغيلية، أن تعالج أي اعتماد على مزودي الخدمات الخارجيين، وخاصة في خطة استمرارية األعمال، وفي الرسم التخطيطي لألصول والموارد المتعلقة بالعمليات الحيوية. Within its Operational Risk and Operational Resilience framework, an LFI must address any reliance on Third-Party Service Providers, in particular in its Business Continuity Plan, and in its mapping of assets and resources related to Critical Operations. 13.10. ُمرخصة أن تحتفــظ 11-13 يجــب على المنشأة الماليَّة ال بخطط طوارئ وخـروج قابلة للتطــبيق فيما يخص ترتيبات مزودي الخدمات الخارجيين التي تعتبر هامــة لعملياتها الحيوية. An LFI must maintain viable contingency and exit plans for its Third-Party Service Provider arrangements that are material to its Critical Operations. 13.11. وعلى وجه الخصوص، يجب أن تثبت هذه الخطط ال في حالة ُم المرونة التشغيلية للمنشأة المالَّية رخصة حــدوث إخفاق أو تع ّطل أو اضطراب لدى مزود خدمة خارجي يؤثر على أداء العمليات الحيوية. In particular, such plans must demonstrate the LFI’s Operational Resilience in the event of a failure or disruption at a Third-Party Service Provider impacting the provision of Critical Operations. يجب أن تقيم خطة استمرارية األعمال إمكانية استبدال الترتيبات مع مزودي الخدمات الخارجيين، مع تسليط الضوء على أي حاالت يكون فيها استبدال مزود الخدمة الخارجي في الوقت المناسب، بما في ُمرخصة نفسها، مكلفًا ذلك من قِّبل المنشأة الماليَّة ال للغاية، أو ينطوي على مخاطر عالية، أو مستحيل التنفيذ. The Business Continuity Plan must assess the substitutability of arrangements with Third￾Party Service Providers, highlighting any instances where a sufficiently timely substitution of the Third-Party Service Provider, including by the LFI itself, is very costly, carries high risks, or is impossible. 12-13 للمصــرف المركزي، وفقًا لتقـديره، أن يطلب إيقــاف واحــد أو أكثر من الترتيبات مـــع مزود خدمة خارجي، أو إيقاف عملية حيوية تعتمد بشــكل مفرط على ترتيب واحـــد أو أكثر مع مزودي خدمات خارجيين. The Central Bank may, at its discretion, require the discontinuation of one or more arrangements with a Third-Party Service Provider or the discontinuation of a Critical Operation that is overly reliant on one or more arrangements with Third-Party Service Providers. 13.12. المــــادة )14(: مخاطر عدم االمتثال ألحكام الشريعة Risk Compliance-Non ah’Shari 1-14 يجب أن تكون لدى المؤسسة المالية اإلسلمية نظـم وضوابط كافــية، بما في ذلك تطبيــق إطار حوكمة شرعية، وضــمان االمتثال لقــرارات الهيئة العليا An Islamic Finance Institution must have in place adequate systems and controls, including the implementation of a Shari’ah 14.1.

35 CBUAE Classification: Public الشـــرعية. ويشــمل ذلك السياسات واإلجراءات الخاصة بالموافقة على منتجــات وعقــــود وأنشطة التمـــويل اإلسلمي. governance framework, and ensure compliance with the Higher Shari’ah Authority’s resolutions. This includes policies and procedures for the approval of Islamic finance products, contracts and activities. 2-14 يجب أن يكــون لدى المؤســـسة الماليَّة اإلسلمية إطار مناسب ونظم وضوابط وحدود كافية إلدارة مخاطر عدم االمتثال ألحكام الشريعة، والتي تكــون شاملة وتعالج المخاطر المحددة المرتبطة باألعمال واألنشطة المتوافقـــة مع أحكام الشريعة، بما في ذلك مخاطر عدم االمتثال ألحكام الشريعة والمخاطر المتعلقة بمسؤولياتها االتئمانية. An Islamic Financial Institution must have in place an appropriate framework, adequate systems, controls and limits for Shari’ah Non￾Compliance Risk management, that are comprehensive and address the specific risks associated with Shari’ah compliant businesses and activities, including Shari’ah Non-Compliance Risk and risks related to its fiduciary responsibilities. 14.2. 3-14 يجــب على المؤسسة الماليَّة اإلسلمية أن تفهم وتختبر االرتباطـات المتبادلة وتأثيــرات مخاطر عدم االمــتثال ألحكــام الشريعة على المخاطر األخرى طوال مـــدة العقد، بما في ذلك صياغة وإنهاء العقد وأي جوانب أخرى تؤثر على الوفاء به، مثل االحتيال وتقديم معلومات مضللة. An Islamic Finance Institution must understand and test the interlinkages and impacts of Shari’ah Non-Compliance Risk on other risks throughout the life cycle of the contract, including formation, termination and any other aspects that affect the contract’s performance, such as fraud and misrepresentation. 14.3. 4-14 يجـــب على المؤسسة المالَّية اإلسلمية االحتفاظ بسجل رسمي للدخـــل غير المعترف به الذي ينشأ عن عــدم االمتثال ألحكـام الشريعة، واإلبلغ عنه بانتظام إلى لجنة الرقابة الشرعية الداخلية. An Islamic Finance Institution must maintain a formal record of income not recognized arising from Shari’ah Non-Compliance and report this regularly to the internal Shari’ah supervision committee. 14.4. 5-14 يجــب على وظيفــة إدارة المخاطــر أن تحــدد بشكل استباقي مجاالت المخاطـــر المحتملة لعدم االمتثال ألحكــام الشريعة، وتقييم احتمالية وقــوع حاالت عدم امتثال ألحكــام الشريعة وشدتها، وتحديد أي أرباح قد ال يتم االعتراف بها كأرباح تمويل إسلمي مؤهلة، واإلفصاح عن هذه النتائج للجنة الرقابة الشرعية الداخلية. The risk management function must proactively identify potential risk areas of Shari’ah non-compliance, evaluate the likelihood and severity of Shari’ah non￾compliance events occurring, identify any profits that may not be recognized as eligible Islamic finance profits, and disclose these findings to the internal Shari’ah supervision committee. 14.5. وفي حال تحــقق مخاطـــر عدم االمتثال ألحكـام الشــريعة، يجب على المؤسسة الماليَّة اإلسلمية مراجعة كفــاية إطــار الضوابط الداخلية المتعلق بمخاطر عدم االمتثال ألحكام الشــريعة، وتحسينه عـــند الضرورة. ولجنة الرقــــابة الشــرعية الداخلية هي الهـــيئة التي لديها الســـلطة لتحـــديد ما إذا كانت Where such Shari’ah Non-Compliance Risk materializes, the Islamic Finance Institution must review the adequacy and, where necessary, improve its internal control framework related to Shari’ah Non￾Compliance Risk. The internal Shari’ah supervision committee is the body who has the authority to determine whether a Shari’ah

36 CBUAE Classification: Public مخاطر عــدم االمتثال ألحكــام الشــريعة قــد تحققت أم ال. Non-Compliance Risk has materialized or not. 6-14 يجب على المؤسسة الماليَّة اإلسلمية إدارة المخاطر ا لمستوى ـــا لمبادئ الشـــريعة المقبولة، ووفقً وفقً ونوع المخاطر المخصصة لها بموجب العقود المبرمة مع عملئها. وال يجوز للمؤسسة الماليَّة اإلســـلمية أن تســعى إلى االلتفاف على المخاطر التي قبلتها بموجب العقد )بما في ذلك مخاطر األصول والملكية(. ومع ذلك، يمكن التخفيف من مثل هذه المخاطر تحت إشراف لجنة الرقابة الشرعية الداخلية. An Islamic Finance Institution must manage risk in accordance with accepted Shari’ah principles, and in accordance with the level and type of risk allocated to it pursuant to contracts entered into with its customers. An Islamic Finance Institution must not seek to circumvent risk it has contractually acceded to (including asset and ownership risk). Such risk may however be mitigated under the direction of the internal Shari’ah supervision committee. 14.6. 7-14 يجب على المؤسسة الماليَّة اإلسلمية االحتفاظ بحسابات منفصلة حول عمليات المؤسسة الماليَّة اإلسلمية فيما يتعلق بحسابات االستثمار المقيدة وغير المقيدة، وصناديق التكافل أو أي أموال أخرى تُنسب إلى عملء محددين بموجب عقود مختلفة، وضمان التعامل السليم مع تخصيص النفقات، واالعتراف بالربح أو الخسارة، ويجب عليها االحتفاظ بسجلت لجميع المعاملت ذات الصلة. An Islamic Finance Institution must maintain separate accounts in respect of the IFI’s operations, for restricted and unrestricted investment accounts, Takaful funds or any other funds that are attributed to specific clients under different contracts and ensure proper allocation of expenses, recognition of profit or loss and must maintain records for all relevant transactions. 14.7. المــــادة )15(: متطلبات اإلبالغ ورفــــع التقارير Reporting and Notification Requirements ُمرخصة إبلغ المصرف 1-15 يجب على المنشأة الماليَّة ال المركزي على الفور عندما تعلم بوجود انحراف كبير عن بيان تقبــل المخاطر التشغيلية أو السياسات أو اإلجراءات المعتمدة من مجلس اإلدارة، بما في ذلك درجة تحمــل التعطل واالضطراب المعتمدة من مجلس اإلدارة، أو عندما تدرك أن مخاطر تشغيلية جوهرية لم تتم معالجتها بشكل كا ف. An LFI must promptly notify the Central Bank when it becomes aware of a significant deviation from its Board-approved Operational Risk Appetite statement, policies or procedures, including the Board-approved tolerance for disruption, or becomes aware that a material Operational Risk has not been adequately addressed. 15.1. ُمرخصة إخطار المصرف 2-15 يجب على المنشأة الماليَّة ال المركزي بأي أحداث مخاطر تشغيلية تؤثر بشـــكل كبير، أو قد تؤثر بشـــكل كبير، على استــمرارية وسلمة العمليات الحيوية. ويشـــمل ذلك بوجه خــاص أي حــدث يؤدي إلى، أو من المرجح أن يؤدي إلى، تفعــيل خطـــط استمرارية األعمــال أو التعافي مـــن الكوارث، أو له، أو من المرجح أن يكون له، تأثير ملموس على عملء المنشأة الماليَّة ال أو عملياتها أو ربحــيتها أو رأس مالها. ُمرخصة ُمرخصة: وبوجــه خاص، يجب على المنشأة الماليَّة ال An LFI must notify the Central Bank of any Operational Risk events that significantly impact or may significantly impact the continuity or integrity of Critical Operations. This includes in particular any event that triggers, or is likely to trigger its business continuity or disaster recovery plans, or has, or is likely to have, a material impact on the LFI’s customers, operations, profitability or capital. In particular, the LFI must: 15.2.

37 CBUAE Classification: Public 1-2-15 في غضون 4 ساعات: إخطار المصرف المركزي باألحداث، بما في ذلك إيضاح العمليات الحيوية المتأثرة؛ Within 4 hours: notify the Central Bank of the events, including what Critical Operations are affected; 15.2.1. 2-2-15 في غضون 24 ساعة: تزويد المصرف المركزي بتقرير موجز حول طبيعة الحدث، واإلجراءات التي يتم اتخاذها، والتأثير المحتمل، واإلطار الزمني للعــودة إلى العمليات العاديـــة؛ Within 24 hours: provide the Central Bank with a summary report of the nature of the event, the actions being taken, the likely impact and the timeframe for returning to normal operations; 15.2.2. 3-2-15 عند العودة إلى العمليات العادية: إخطار المصرف المركزي عند استئناف العمليات العاديــة؛ Upon return to normal operations: notify the Central Bank upon returning to normal operations; and 15.2.3. 4-2-15 وأي إخطارات أخرى، ومتطلبات معلومات، وأطر زمنية يحددها المصرف المركزي على أساس كل حالة على حدة. Any other notifications, information requirements and timeframes as specified by the Central Bank on a case-by-case basis. 15.2.4. ُمرخصة إخطار 3-15 يجب على المنشأة الماليَّة ال المصــرف المركزي في غضون 72 ساعة من وقوع أي حادث عالي الخطورة. ويجب تحديد معايير تصنيف الحادث على أنه عالي الخطورة في السياسات المعتمدة من مجلس اإلدارة. An LFI must notify the Central Bank within 72 hours of any high-risk Incident. The criteria for categorisation of an Incident as high risk must be defined in Board-approved policies. 15.3. ُمرخصة أن تقدم، عند 4-15 يجــب على المنشأة الماليَّة ال الطلب، أي معلومات محددة فيما يتعلق بالمخاطر التشغيلية قد يطلبها المصــرف المركزي. An LFI must provide, upon request, any specific information with respect to Operational Risk that the Central Bank may require. 15.4. ُمرخصة االمتثال 5-15 يجب على المنشأة الماليَّة ال لمتطلبات رفع التقارير المنتظمة بشأن المخاطر التشغيلية والمرونة التشغيلية كما يحددها المصــرف المركزي. An LFI must comply with regular reporting requirements on Operational Risk and Operational Resilience as prescribed by the Central Bank. 15.5. ُمرخصة االمتثــــال 6-15 يجب على المنشأة الماليَّة ال لمتطلبات اإلخطـــار التي قد يحــددها المصــرف المركزي والتي تختلف من وقت آلخر. وسيُبلغ ال بهذه ُم المصـرف المركزي المنشآت الماليَّة رخصة التغييرات من خلل إشعار. An LFI must comply with the notification requirements which the Central Bank may set and vary from time to time. The Central Bank will inform LFIs of such changes through a notice. 15.6. المــــادة )16(: متطلبات اإلفصـــاح Requirements Disclosure ُمرخصة سياسة 1-16 يجب أن تكون لدى المنشأة الماليَّة ال بشأن اإلفصاحات العامة المتعلقة بالمخاطر التشغيلية An LFI must have a policy on public disclosures related to Operational Risk and 16.1.

38 CBUAE Classification: Public والضوابط الداخلية المرتبطة بها والتي تحدد كيفية تحديد المعلومات التي يتم الكشف عنها والمعلومات التي ال ينبغي الكشف عنها. associated internal controls setting out how it determines what information is disclosed and what information should not be disclosed. ُمرخصة اإلفصاح علنًا 2-16 يجـــب على المنشأة الماليَّة ال عن المعلومات الرئيســـية حول منهجـــيتها في إدارة المخاطر التشغيلية والمرونة التشغيلية، وتعرضها للمخاطــر التشغيلية، بما يتناسب مع حجم أعمالــها وملف مخاطرها ودرجة تعقد عملياتها، وأهميتها النظامية، ودورها في النظام المالي وممارسات الصـــناعة المتغيرة. An LFI must publicly disclose key information about its approach to Operational Risk and Operational Resilience management, and its Operational Risk exposure, commensurate with its size, risk profile, the complexity of its operations, its systemic importance and role in the financial system, and evolving industry practices. 16.2. 3-16 يجب أن تتيح المعلومات المفصح عنها ألصحاب المصلحة إمكانية تقييــم مـــدى فعالية تحديد المنشأة ال للمخاطر التشغيلية وتقييمها ُم الماليَّة رخصة ومراقبتها وضبطها وتخفيفها. The disclosed information must allow stakeholders to assess to which extent the LFI identifies, assesses, monitors, controls and mitigates Operational Risk effectively. 16.3. 4-16 يجب أن توفر المعلومات المفصح عنها فهًما أعمق ال فيما يتعلق ُم لممارسات المنشأة الماليَّة رخصة بحماية البيانات الشخصية. The disclosed information must provide insight into the practices of the LFI with regard to the protection of Personal Data. 16.4. ُمرخصة التي هي فروع أو 5-16 يجوز للمنشآت الماليَّة ال شركات تابعة لشركات أجنبية لديها ترخيص مماثل، االعتماد إلى حد كبير على إفصاحات المجموعة التي تنتمي إليها، ولكن يجب عليها نشر ملخص على األقل إلطار إدارة المخاطر التشغيلية المعمول به لعملياتها في دولة اإلمارات العربية المتحدة، على موقعها اإللكتروني العام. LFIs that are branches or subsidiaries of foreign firms with a similar license may largely rely on the disclosures of the group they belong to, but must publish at least a summary of the Operational Risk management framework in place for their UAE operations on their public website. 16.5. ُمرخصة التي هي شركات 6-16 يجوز للمنشآت الماليَّة ال تابعة لمنشآت ماليَّة مرخصة أخرى في دولة اإلمارات العربية المتحدة االعتماد إلى حد كبير على إفصاحات المجموعة التي تنتمي إليها، ولكن يجب أن تتناول إفصاحات المجموعة، بشكل كا ف، ال . ُم اإلفصاحات المطلوبة للمنشأة الماليَّة رخصة LFIs that are subsidiaries of other LFIs in the UAE may largely rely on the disclosures of the group they belong to, but the group disclosures must sufficiently address the disclosures required for the LFI. 16.6. المادة )17(: اإلنفاذ والجزاءات Sanctions & Enforcement 1-17 تخضع المخالفة ألي من أحكام هذا النظام وأي معايير مصاحبة له إلى اإلجراءات الرقابية والجزاءات اإلدارية والمالية التي يراها المصرف المركزي ملئمة. Violation of any provision of this regulation and any accompanying Standards may be subject to supervisory action and administrative & financial sanctions as deemed appropriate by the Central Bank. 17.1. 2-17 قد تتضمن اإلجراءات الرقابية والجزاءات اإلدارية والمالية التي يتخذها المصرف المركزي سحب أو Supervisory action and administrative & financial sanctions by the Central Bank may 17.2.

39 CBUAE Classification: Public استبدال أو تقييد صلحيات اإلدارة العليا أو أعضاء مجلس اإلدارة، أو إجراء ترتيبات لإلدارة المؤقتة ال ، أو فرض غرامات، أو ُم للمنشأة الماليَّة رخصة حظر أفراد من القطاع المالي بدولة اإلمارات العربية المتحدة. include withdrawing, replacing or restricting the powers of Senior Management or members of the Board, providing for the interim management of the LFI, imposition of fines or barring individuals from the UAE financial sector. المــــادة )18(: تفســـير النظــام Regulation of Interpretation تكـــون إدارة تطـــوير األنظمــة الرقابية بالمصرف المركزي هي المرجــع لتفســير أحكــام هذا النظــام. The Regulatory Development Department of the Central Bank shall be the reference for interpretation of the provisions of this regulation. المــــادة )19(: إلغـــاء إشعــارات سابقــة Notices Previous of Cancellation يُل ِّغــي هذا النظام ويحل محـل تعاميم وإشعارات المصرف المركزي اآلتية: This regulation cancels and replaces the following Central Bank Circulars and Notices: 1-19 التعميم رقم ،2018/163 "نظام المخاطر التشغيلية" و"معايير المخاطر التشغيلية"، الصادر بتاريخ 29 أغسطس .2018 Circular No. 163/2018, the ‘Operational Risk Regulation’ and the ‘Operational Risk Standards’ issued on 29 August 2018. 19.1. المــــادة )20(: النشر وتاريخ النفـــاذ Date Effective & Publication 1-20 يُنشــر هذا النظــام في الجـريدة الرسمية باللغتين العربية واإلنجليزية، ويدخل حيز التنفيذ بعد شهــر واحد من تاريخ النشـــر. This regulation shall be published in the Official Gazette in both Arabic and English and shall come into effect one month from the date of publication. 20.1. خالد محمد بالعمى محافظ مصرف اإلمارات العربية المتحدة المركزي Khaled Mohamed Balama Governor of the Central Bank of the UAE

40 CBUAE Classification: Public الملحق 1 1 Annex Examples of tools used for identifying and assessing Operational Risk أمثلـــة لألدوات المســـتخدمة في تحــديد وتقييـم المخاطر التشغيلية a. Event management – A pre-determined set of processes followed when an LFI experiences an Operational Risk event, including the processes of identification, analysis, end-to-end management and reporting of the event. These processes include analysis of events to understand the underlying causes and control weaknesses, the identification of new Operational Risks, and the formulation of an appropriate response to prevent, mitigate or control similar events. The outcomes are an input to the self-assessment and in particular to the assessment of control effectiveness. ُم إدارة األحـــداث - حددة مجموعة من العمليات ال مسبقً يتم اتباعها عند مواجهة المنشأة الماليَّة ا التي ال لحـدث مخاطر تشغيلية، وتشـــمل ُمرخصة العمليات التي يتم من خللها تحــديد الحدث وتحليله وإدارته الشاملة ورفع التقارير بشأنه. وتشمل هذه العمليات تحليل األحداث لفهم األسباب التي أدت إليها ونقاط ضعف الضوابط، وتحــديد المخاطـر التشغيلية الجــديدة، وصياغة استجابة ملئمـــة لتجنب أو تخفيف أو السيطرة على أحــداث مماثلة. وتُعــدّ النتائج ُمد خـــ لتقييم فعالية لت للتقييم الذاتي، وخاصةً الضوابط. أ. b. Internal Operational Risk event data collection and analysis – Internal operational loss data provides meaningful information for assessing an LFI's exposure to Operational Risk and the effectiveness of internal controls. Analysis of loss events can provide insight into the causes of large losses and information on whether control failures are isolated or systematic. The data and analysis should also cover near misses and generally aim to capture risk exposures, not only those that result in financial losses. An LFI may also find it useful to capture and monitor Operational Risk contributions to credit, market and other financial risk related losses in order to obtain a more complete view of its Operational Risk exposure. جمع وتحليل بيانات أحداث المخاطر التشغيلية توفر بيانات الخسائر التشغيلية الداخلية ّ الداخلية - ِّ معلومات مفيدة لتقييم تعرض المنشأة الماليَّة ال للمخاطر التشغيلية، وفعالية الضوابط ُمرخصة الداخلية. كما أن من الممكن لتحليل أحداث الخسائر أن يوفر فهًما أعمق ألسباب الخسائر الكبيرة، ومعلومات حول ما إذا كانت حاالت إخفاق الضوابط معزولة أم نظامية. وينبغي أن تغطي البيانات والتحليلت أي ًضا الحوادث التي كادت أن تتحقق، وأن تهدف بشكل عام إلى رصد التعرضات للمخاطــر، وليس فقط تلك التي تنجــم عنها خســـائر مالية. وقد ُمرخصة أي ًضـــا أن من المفيد تجــد المنشأة الماليَّة ال رصـــد ومراقــبة مساهمات المخاطــــر التشغيلية في الخســائر المتعلقة بمخاطر االئتمان، والسوق، وغيرها من الخسائر المتعلقة بالمخاطر المالية، وذلك للحصول على رؤية أشمل لتعرضها للمخاطر التشغيلية. ب. c. External Operational Risk event data collection and analysis – External data elements consist of gross operational loss amounts, dates, recoveries and relevant causal information for operational loss events occurring at organizations other than the LFI. External loss data can be compared with internal loss data, or used to explore possible weaknesses in the control environment or جمع وتحليل بيانات أحداث المخاطر التشغيلية الخارجية - تتألف عناصر البيانات الخارجية من إجمالي مبالغ الخسائر التشغيلية، وتواريخها، وعمليات االسترداد، والمعلومات السببية ذات الصلة ألحداث الخسائر التشغيلية التي تحدث في مؤسسات ال . ويمكن مقارنة ُم أخرى غير المنشأة الماليَّة رخصة بيانات الخسائر الخارجية ببيانات الخسائر الداخلية، أو استخدامها الستكشاف نقاط الضعف المحتملة في ج.

41 CBUAE Classification: Public consider previously unidentified risk exposures. Such data may be informative of risks that are common across the industry, or that are rare but have a high impact. بيئة الضبط، أو لدراسة تعرضات مخاطر لم تُحدد ا. وقد تُفيد هذه البيانات في تحديد المخاطر مسبقً الشائعة في جميع مؤسسات القطاع، أو تلك النادرة ولكنها ذات تأثير كبير. d. Self-assessments – the LFI performs a self￾assessment of its Operational Risks and controls on various levels, typically evaluating the inherent risk (assessing the risk before controls are considered), the effectiveness of the control environment, and the resulting residual risk (the risk exposure after controls are considered), based on both quantitative and qualitative elements. التقييمات الذاتيـــة – تقـــوم المنشأة الماليَّة ال بإجـــراء تقييم ذاتــي لمخاطـــرها ُمرخصة التشغيلية وضـــوابطها على مســـتويات مختلفة، وغالبًا ما تُقيّـــم المخاطـــر الكـامنة )تقييـــم المخاطـــر قبل األخذ بالضوابط في االعتبار(، وفعالية بيئة الضــبط، والمخاطر المتبقية الناتجــة )التعرض للمخــاطر بعد األخـــذ بالضوابط في االعتـبار(، استنادً ا إلى عناصــر كمية ونوعـــية معًا. د. Qualitative elements may include consideration of both the likelihood and the consequences of the risk event when determining the inherent and the residual ratings. قد تتضمن العناصر النوعية األخذ في االعتبار باحتمالية وعواقب حدث المخاطر، عند تحديد التصنيفات الكامنة والمتبقية. Assessments typically rely on process mapping to identify all key steps and dependencies in the processes, and any associated risks or areas with weaker controls in place. تعتمد التقييمات، في الغالب، على الرسم التخطيطي للعمليات لتحديد جميع الخطوات الرئيسية والتبعيات في العمليات، وأي مخاطر مصاحبة، أو أماكن وجود ضوابط ضعيفة. The assessments should contain sufficiently detailed information on the business environment, Operational Risks, underlying causes, controls and evaluation of control effectiveness to enable an independent reviewer to determine how the LFI reached its ratings. يجب أن تتضمن التقييمات معلومات مفصلة بدرجة كافية عن بيئة العمل، والمخاطر التشغيلية، واألسباب الكامنة، والضوابط، وتقييم فعالية الضوابط، لتمكين ُمراجع مستقل من تحديد كيفية تو ّصل ة المنشأة الماليَّ ال إلى تقييماتها. ُمرخصة A risk register collates this information to form a meaningful view of the overall effectiveness of controls and to facilitate oversight by the Board, Senior Management and other internal stakeholders. يج ّمع سجل المخاطر هذه المعلومات لتكوين رؤية واضحة للفعالية العامة للضوابط، ولتسهيل اإلشراف من قِّبل مجلس اإلدارة واإلدارة العليا وأصحاب المصلحة الداخليين اآلخرين. e. Business process mapping – business process maps identify the key steps in business processes, activities and organizational functions. They also identify the key risk points in the overall business process. Process maps can reveal individual risks, risk interdependencies and areas of control or risk management weakness. They تخطيط عمليات األعمال – تُحدد مخططات عمليات األعمال الخطوات الرئيسية في عمليات األعمال، واألنشطة والوظائف التنظيمية. كما تُحدد نقاط المخاطر الرئيسية في عملية األعمال ككل. كما تكشف مخططات العمليات عن المخاطر الفردية، واالعتماد المتبادل بينها، وأماكن وجود ضعف في هـ.

42 CBUAE Classification: Public can help prioritize subsequent management action. الضوابط أو إدارة المخاطر. كما تُساعد في تحديد أولويات اإلجراءات اللحقة من قِّبل اإلدارة. f. Control monitoring and assurance framework – Incorporating an appropriate control monitoring and assurance framework facilitates a structured approach to the evaluation, review and ongoing monitoring and testing of key controls. The analysis of controls ensures these are suitably designed for the identified risks and operating effectively. The analysis should also consider the sufficiency of control coverage, including adequate prevention, detection and response strategies. The control monitoring and testing should be appropriate for the different Operational Risks and key controls across business areas. إطار مراقبة الضوابط والتدقيق عليها – يمــكن لدمج إطار عمل مناسب لمراقــبة الضوابط والتدقيق عليها، ّظمة لتقييم الضوابط أن ي س ِّّهل اتباع منهجية من الرئيسية ومراجعتها ومراقبتها بشكل مستمر. ويضمن تحليل الضـــوابط أن هذه الضوابط قد تم تصميمها بشكل ملئم لمواجهة المخاطر المحددة، وتعمل بشكل فعّال. كما ينبغي أن يُراعي التحليل مدى كفاية تغطية الضوابط، بما في ذلك استراتيجيات الوقاية والكشف واالستجابة الكافية. ويجب أن تكون مراقبة واختـــبار الضوابط ملئمـــة لمختلف المخاطــر التشغيلية والضـــوابط الرئيســية في مختلف قطاعات األعمال. و. g. Risk and performance indicators – risk and performance indicators are risk metrics and/or statistics that provide insight into an LFI’s risk exposure. Risk indicators provide insight into the status of operational processes, which in turn may provide insight into operational weaknesses, failures and potential losses. Risk and performance indicators are often paired with escalation triggers to warn when risk levels approach or exceed thresholds or limits and prompt mitigation plans. مؤشــرات المخاطـــر واألداء – مؤشـــرات المخاطــر واألداء هي مقاييس و/أو إحصاءات ا دقيقًا لتعرض المنشأة الماليَّة للمخاطر تُقدم فهًم ُمرخصة ـر. وتُقدم هذه المؤشرات فهًما ال للمخاطـ أعمق لوضعية العمليات التشغيلية، والتي قد تُقدم، بدورها، فهًما أعمق لنقـــاط الضعف التشغيلية، واإلخفاقات والخســائر المحتملة. وغالبًا ما تُرفق مؤشرات المخاطر واألداء بمؤشرات للتصعيد وذلك للتحـــذير عـند اقتراب مستويات المخاطر من الحدود أو السقوف أو تجاوزها، من أجل وضع خطط للتخفيف من المخاطر. ز. Monitoring metrics and related trends through time against agreed thresholds or limits provides valuable information for risk management and reporting purposes, and may provide early warning information on the performance of the business and the control environment. توفر مقارنة المقاييس والتوجهــات ذات الصلة على ، بالحدود أو الســقوف المتفق عليها مر الزمن مقارنةً معلومات قيّمــة ألغـــراض إدارة المخاطـــر وإعــداد التقــارير، وقد توفـــر معلومات إنذار مبكـــر حــــول أداء العمــل وبيئة الضـــبط. h. Scenario analysis – Scenario analysis is a method to identify, analyse and measure a range of scenarios, including low probability and high severity events, some of which could result in severe Operational Risk losses. Scenario analysis typically involves workshop meetings of subject matter experts including senior management, business management and senior Operational Risk تحليل السيناريوهات – يُعد تحليل السيناريوهات أسلوبًا لتحديد، وتحـليل، وقياس مجمــوعة من السيناريوهات، بما في ذلك األحــداث منخفضة االحتمالية وعــالية الشدة، والتي قد تنجــم عــن بعضها خســائر فادحـــة متعلقة بالمخاطـــر التشغيلية. ويتضمن تحليل السيناريوهات، في الغالب، ورش عمــل لخبراء متخصصين في الموضوع، بما في ذلك اإلدارة العليا، وإدارة األعمال، وكبار موظفي ح.

43 CBUAE Classification: Public staff and other functional areas such as compliance, human resources and IT risk management, to develop and analyse the drivers and range of consequences of potential events. Inputs to the scenario analysis would typically include relevant internal and external loss data, information from self￾assessments, the control monitoring and assurance framework, forward-looking metrics, root-cause analyses and the process framework, where used. The scenario analysis process could be used to develop a range of consequences of potential events, including impact assessments for risk management purposes, supplementing other tools based on historical data or current risk assessments. It could also be integrated with disaster recovery and business continuity plans, for use within testing of Operational Resilience. Given the subjectivity of the scenario process, a robust governance framework and independent review are important to ensure the integrity and consistency of the process. المخاطــر التشــغيلية، ومجـــاالت وظيفية أخرى مثل االمــتثال، والمـــوارد البشرية، وإدارة مخاطـــر تقنية المعلومـــات، وذلك لتطــوير وتحليل مح ّركــات األحداث المحتملة ونطـــاق عواقبها. وغالبًا ما تتضمن مدخـــلت تحليل الســـيناريوهات بيانات الخســائر الداخلية والخارجية ذات الصلة، ومعلومـــات من التقييمـــات الذاتية، وإطــار مراقبة الضوابــط والتدقيق عليها، والمقاييس االستشرافية، وتحليلت األســباب الجــذرية، وإطار العملية، حيثما يكــون مستخدًما. ويمكــن استخدام عملية تحـليل السيناريوهات لتطـــوير مجمـــوعة من عواقــب األحداث المحتملة، بما في ذلك تقييمــات تأثير ألغراض إدارة المخاطر، ُمكملةً ألدوات أخـــرى تستند إلى البيانات التاريخية أو تقييمات المخاطـــر الحالية. كما يمكن دمجها مع خطـــط التعافي من الكوارث واستمرارية األعمـــال، الستخدامها في اختبار المرونة التشغيلية. ونظـــ ًرا ألن عمـــلية الســــيناريوهات ذاتــــية بطبيعتها، فإن وجـــود إطــار حوكمة متين وفعال، ومراجعة مستقلة، أمــران مهمـــان لضــــمان سلمة واتســــاق العملية. i. Models – LFIs may find it useful to quantify their exposure to Operational Risk by using the output of the risk assessment tools as inputs into a model that estimates Operational Risk exposure. The results of the model can be used in an economic capital process and can be allocated to business lines to link risk and return. ال أنه من ُم النماذج – قد تجد المنشآت الماليَّة رخصة المفيد تحديد مدى تعرضها للمخاطر التشغيلية باستخدام مخرجات أدوات تقييم المخاطر كمدخلت في نموذج يُقدّر مدى تعرضها للمخاطر التشغيلية. يمكن استخدام نتائج النموذج في عملية رأس المال االقتصادي، ويمكن تخصيصها لفروع األعمال لربط المخاطر بالعائدات. ط. j. Benchmarking and comparative analysis – Benchmarking and comparative analysis are comparisons of the outcomes of different risk measurement and management tools deployed within the LFI, as well as comparisons of metrics from the LFI to other firms in the industry. Such comparisons can be performed to enhance understanding of the LFI’s Operational Risk profile. For example, comparing the frequency and severity of internal losses with self-assessments can help the LFI determine whether its self-assessment processes are functioning effectively. Scenario data can be compared to internal and external loss data to gain a better القياس المقارن والتحليل المقـــارن – القياس المقارن والتحليل المقارن همــــا مقارنات لنتائج ُمستخدمة لدى مختلف أدوات قياس وإدارة المخاطر ال ال ، باإلضافة إلى مقارنات بين ُم المنشأة الماليَّة رخصة ُمرخصة مع شركات مقاييس من المنشأة الماليَّة ال أخرى في القطاع. يمكن إجراء هذه المقارنات لتعزيز فهم ملف المخاطر التشغيلية لدى المنشأة الماليَّة ال . على سبيل المثال، يمكن أن تساعد مقارنة ُمرخصة وتيرة وشـــدة الخسائر الداخلية مع التقييمات الذاتية ال في تحديد ما إذا كانت ُم المنشأة الماليَّة رخصة عمليات التقييم الذاتي الخاصة بها تعمل بفعالية. ويمكن مقــارنة بيانات الســـيناريوهات ببيانات الخســائر الداخلية والخارجية للحصول على فهم ُم أفضل لمــدى تعرض المنشأة الماليَّة رخصة ال ألحداث مخاطر محتملة. ي.

44 CBUAE Classification: Public understanding of the severity of the LFI’s exposure to potential risk events. k. Audit findings – while audit findings primarily focus on control weaknesses and vulnerabilities, they can also provide insight into inherent risk due to internal or external factors. LFIs must not solely rely on internal audit to identify Operational Risks. نتائج التدقيق – على الرغم من أن نتائج التدقيق تُركز بشكل أساسي على نقاط ضعف الضوابط وثغراتها، إال أنها تُقدم أي ًضا فهًما أعمق للمخاطر الكامنة الناجمة عن عوامل داخلية أو خارجية. ويجب ال على التدقيق ُم أال تعتمد المنشآت الماليَّة رخصة الداخلي وحده لتحديد المخاطر التشغيلية. ك.