Skip to content
Monday, 14 September 2026 Dubai · GST
UAE, UNFILTERED
Trend Analysis

Your UAE Bank Can Outsource the Tech. It Cannot Outsource the Risk

A new CBUAE operational-risk regime is in force from September 14. The useful part for customers is simple: outsourced technology does not outsource a licensed financial institution's responsibility for resilience.

Share this story

A bank app goes down. A payment service stops working. The first explanation is often some version of the same sentence: a third-party provider had a problem.

From September 14, the Central Bank of the UAE has a new operational-risk regime in force for licensed financial institutions that are juridical persons. It covers much more than app outages, but one principle is particularly useful for customers: outsourcing a system does not outsource the financial institution’s responsibility for managing the risk around it.

The Robius Action Brief
Important
Why it matters

UAE banks and other covered institutions must manage the resilience of critical services even when technology, cloud infrastructure or other operations are outsourced.

Who should care

UAE bank customers, payment users, SMEs, fintech operators and technology teams should understand what the new resilience obligations do and do not guarantee.

Opportunities

Customers and business users may gain more useful visibility as institutions publish regulatory disclosures explaining how they manage operational risk and resilience.

Risks or limitations

The rules do not guarantee zero downtime, instant recovery or automatic compensation, and they do not directly regulate every technology vendor used by a bank.

What happens next

Covered institutions must operate under the new regime from September 14, including critical-operation mapping, resilience testing, incident planning and third-party risk management.

What you can do

After a material outage, keep transaction evidence and check the licensed institution's explanation, recovery steps and complaint route rather than focusing only on the vendor.

Who benefits

Customers benefit from stronger governance around critical services, while regulated institutions gain a clearer framework for managing outages, cybersecurity and third-party dependencies.

Who can participate

The regulation applies to covered CBUAE-licensed financial institutions that are juridical persons; third-party technology providers are managed through the institution's risk framework.

What readers should monitor

Watch banks' operational-risk disclosures, outage communications, recovery performance and whether repeated incidents reveal weaknesses in critical-service or third-party resilience.

The regulation requires institutions to map critical operations, manage third-party dependencies, maintain incident-response and recovery plans, test resilience and keep the board accountable for the framework. Payment systems and payment services are expressly included among the operations that must be considered critical.

The Rule Starts With the Service, Not the Server

The CBUAE’s Operational Risk Management Regulation, C 1/2026, is effective from September 14, 2026. Its stated objective is to set minimum requirements for operational risk and operational resilience across covered licensed financial institutions.

The important phrase is operational resilience. The regulation defines that around the ability to keep critical operations running through disruption, respond and adapt when something fails, recover and learn from the event.

That moves the regulatory question away from “did the bank’s own server fail?” and toward “could the bank continue delivering the critical service?” For customers, that is the more useful question anyway.

Payment Services Are Explicitly Critical

The regulation requires institutions to identify their critical operations and map the people, technology, processes, data, facilities and third-party providers needed to deliver them.

At a minimum, that critical-operations list includes the continued operation of payment systems, payment services and other time-critical customer services. It also includes the ability to maintain accurate, up-to-date financial records for customers and the institution itself.

So this is not an abstract back-office rule. The framework reaches directly into the systems customers notice when something breaks: payments, records and the infrastructure underneath them.

A Vendor Problem Is Still a Bank Risk

The third-party rules are unusually clear. A covered institution must have a board-approved strategy for assessing, monitoring and managing third-party risk. Before entering an arrangement, it must perform a risk assessment and due diligence on the provider.

For arrangements that affect critical operations, the institution must verify that the provider has an equivalent level of operational resilience. It also must not become so dependent on outsourcing that it no longer maintains enough internal staff, expertise and resources to perform and manage its licensed activities effectively.

That is especially relevant as banking gets embedded inside other products. Robius has already looked at what happens when a payment-terminal provider becomes a route into business banking. The customer interface may be supplied through one company while the regulated financial service sits with another. The regulatory responsibilities underneath that interface still matter.

Cybersecurity Is Now Part of the Resilience Test

The regulation requires a robust ICT and cybersecurity risk framework covering identification, mitigation, monitoring, testing, response and recovery. Boards and senior management must be kept informed about exposures, incidents and weaknesses found through testing.

It also requires institutions to manage systems operated or made available by third parties and to plan the renewal or retirement of obsolete and unsupported hardware and software.

There is a useful parallel with our recent analysis of AI agents and operational permissions. The technology can change. The control question does not: what can the system touch, what happens when it fails, and who remains accountable?

The Bank Has to Plan for the Bad Day

Covered institutions must maintain incident response, business continuity and disaster recovery plans for critical operations. Incident management must cover the full life cycle of an event, and institutions must identify the root cause of material incidents and take measures to prevent or reduce the chance of similar failures happening again.

The internal control framework also has to cover activities that rely partly or fully on third-party providers. Periodic stress testing is required, and for critical functions the regulation requires independent third-party penetration testing.

None of that means outages disappear on September 14. Resilience regulation is not an uptime guarantee. It creates minimum governance, testing, mapping and recovery obligations around the failure instead.

Customers May Eventually See More of the Resilience Story

The regulation also contains public-disclosure requirements. Covered institutions must have a policy for operational-risk disclosures and publish key information about how they manage operational risk and resilience, proportionate to their size, risk profile and importance.

The disclosure must be sufficient for stakeholders to assess the institution’s approach, and it must provide insight into practices for protecting personal data. Foreign-bank branches can rely substantially on group disclosures, but must publish at least a summary of the framework used for UAE operations.

That is worth watching. A glossy cybersecurity page is marketing. A regulatory disclosure that explains the actual resilience framework is a different kind of document.

What This Does Not Give You

The new rules do not promise zero downtime, instant recovery or automatic compensation every time a service fails. They also do not make every technology company used by a bank directly regulated by the CBUAE.

The regulated institution is the important layer. It has to understand the dependency, assess the provider, build resilience around critical services and remain responsible for its own risk-management framework.

That distinction matters as UAE finance becomes more modular. Our analysis of Zand’s planned dirham-to-USDC infrastructure showed how one customer journey can involve several regulated and technical roles. Operational resilience is the other side of the same map: a clean interface does not make the dependencies disappear.

The Robius Layer

The most useful sentence in the new regime is not “banks need better cybersecurity.” Everyone already knows that.

The useful change is that the CBUAE has made the dependency chain part of the resilience obligation. Critical services must be mapped through the people, systems, data, facilities and outside providers that make them work. The institution cannot point at an outsourced provider and treat the dependency as somebody else’s operational problem.

For customers, the test after the next outage is therefore more precise: not simply who went down, but how the licensed institution had prepared to keep the critical service running, recover it and stop the same failure from becoming normal.

Sources

  • Central Bank of the UAE Rulebook: Operational Risk Management Regulation C 1/2026, effective September 14, 2026 — CBUAE Rulebook
  • CBUAE Rulebook: Operational Resilience, including critical operations and payment services — CBUAE Rulebook
  • CBUAE Rulebook: ICT and Cybersecurity Management — CBUAE Rulebook
  • CBUAE Rulebook: Third Party Risk Management — CBUAE Rulebook
  • CBUAE Rulebook: Disclosure Requirements — CBUAE Rulebook

This is not financial advice. Checked 14 September 2026.

Robius.news — Dubai, UAE — 2026 | Built to be first. Built to be trusted.