The regulation contains detailed requirements for how UAE banks identify, manage and govern operational risk. Yet the most interesting aspect is not any individual provision, it’s what the regulation tells us about the direction of travel for operational resilience across the region.
We’re seeing regulators placing greater emphasis on resilience, continuity and the risks associated with increasingly complex technology ecosystems. That shift can be seen within a range of recent developments, from Saudi Arabia's CST Software Escrow Guideline through to broader international frameworks such as DORA.
The CBUAE regulation offers another clear indication of how expectations are evolving and what regulated organisations, and the suppliers that support them, should be preparing for.
One thing that stands out is the way that operational risk is defined. The regulation takes a broad view, covering failures arising from people, processes, systems and external events. So, whilst cybersecurity remains an important component of resilience, it is no longer being treated as the whole story, and in fact the regulations repeatedly call out the need to look beyond cybersecurity.
For many years, resilience discussions were often dominated by cyber threats and data security. Those risks remain important, but regulators are increasingly focused on a broader question: can critical services continue to operate when disruption occurs, regardless of the cause?
Technology failures, supplier outages, operational errors and external events can all have a significant impact on service delivery. The organisations best positioned to manage those risks are likely to be those that view resilience as a business-wide capability rather than a purely technical function.
The CBUAE's approach reinforces that operational resilience should not be treated as a standalone compliance exercise. It forms part of a wider risk-management framework alongside the regulator's broader Risk Management Regulation and reflects a more integrated view of risk, governance and continuity.
A second theme running throughout the regulation is accountability; it’s the Board that are explicitly responsible for ensuring that an appropriate operational risk framework exists and remains effective. This isn’t a requirement that can simply be delegated and revisited periodically; resilience must be governed and overseen at the highest levels of the organisation.
The regulation also applies on both a solo and group-wide basis. UAE banks with international branches or subsidiaries are expected to ensure that operational risk standards are applied consistently across the wider organisation, not solely within the parent entity. For many institutions, this will mean building greater visibility of operational dependencies, governance arrangements and resilience capabilities across multiple jurisdictions.
Transparency is another notable feature. The regulation requires that firms disclose sufficient information for stakeholders to assess their approach to operational risk, with expectations scaled according to the size and complexity of the institution.
Together these requirements point towards the same conclusion: the regulators expect resilience to be governed, measurable and visible.
Perhaps the most significant trend reflected in the regulation is the growing attention being paid to third-party providers. As financial institutions continue to digitise their operations, resilience must include third-party dependency risk. For many critical services, the ability to maintain operations is now directly linked to the resilience of external technology providers.
The CBUAE regulation takes a practical approach by requiring firms to assess and monitor risks associated with third-party arrangements, including the financial condition of service providers.
The shift to assessment of resilience going beyond the boundaries of the regulated institute is not unique to the UAE. From Saudi Arabia's CST Software Escrow Guideline to the UK’s Critical Third-Parties regime and the Federal Financial Institutions Examination Council (FFIEC) Guidelines in the US, regulators across the globe are increasingly recognising that critical business services often depend on software vendors, cloud platforms, managed service providers and specialist technology partners, and bringing additional attention around software continuity and supplier dependency risk.
A bank may have strong internal controls, but if a critical third-party service experiences disruption, customers are unlikely to distinguish between the institution and the supplier supporting it. From a resilience perspective, both become part of the same service-delivery chain.
Historically, many organisations have focused significant effort on selecting suppliers through procurement processes, due diligence exercises and contractual reviews. The regulation suggests that regulators are becoming equally interested in what happens after those decisions have been made. In particular, the requirements relating to contingency planning, exit planning and operational continuity stand out.
The expectation goes beyond identifying risks and requires that they can answer how critical services would continue if a material supplier experienced disruption, deterioration or failure. This extends to the concept of substitutability. Organisations are expected to consider circumstances where replacing a provider would be costly, high risk or difficult to achieve within an acceptable timeframe.
For many financial institutions, this represents a practical challenge. Core banking platforms, specialised applications and deeply integrated technology services are not always easy to replace. In some cases, replacement may take considerable time to procure and implement, requiring substantial investment and introducing additional operational risk. Additionally, a failure in one area of the supply chain has the potentially to have a wider impact
And that’s the reason regulators are paying closer attention to these dependencies. The focus is shifting from identifying suppliers to understanding and mitigating the risks of losing their services.
Whilst the regulation applies directly to UAE banks, its influence is likely to extend much further. As resilience expectations increase, banks will inevitably ask more questions of the technology providers, software vendors, cloud platforms and fintech partners that support critical services. The result is that resilience requirements increasingly flow through the wider supply chain.
For fintech and technology businesses operating within the Gulf financial sector, regulations such as this help define what compliant infrastructure looks like. They shape expectations around continuity, governance, dependency management and operational risk, even where those organisations sit outside the regulatory perimeter themselves.
This is perhaps the most important takeaway from the CBUAE regulation.
Beyond the specific requirements, it offers another indication of where regulatory expectations are heading. Operational resilience is being treated as a strategic capability, governance is becoming more important, third-party dependencies are receiving greater scrutiny and firms are increasingly expected to demonstrate that continuity arrangements will work in practice.
These topics may not attract the same attention as emerging technologies or headline-grabbing regulatory initiatives but they are increasingly forming the foundation upon which modern financial services are built. And that's why this regulation deserves attention.

“Escode’s technical verification process, gives Vision Bank additional confidence in the recoverability of a business-critical application in the event of supplier failure. This forms part of our wider focus on operational resilience, continuity planning and responsible digital banking.”
– Parag Singhal, Chief Technology Officer, Vision Bank
About the Author
Alex McCulloch is Escode's Director of Market Development for the Middle East, leading regional strategy and developing long-term partnerships with key clients and stakeholders.
Alex has over 20 years of experience in software escrow and third-party risk management, combining global expertise with regional insight.