Both regulations are issued under Federal Decree-Law No. 6 of 2025, the new Central Bank law covering the regulation of financial institutions, activities and insurance business. Read together, they mark a visible shift in supervisory philosophy: away from asking whether a policy document exists, and towards asking whether governance, controls and risk management demonstrably work in practice, with the Board and Senior Management personally accountable for the answer.
C 2/2026: from market conduct to customer protection
The renaming is the message. The 2021 instrument regulated market conduct; the 2026 instrument protects customers. SMEs, including sole proprietors, are now treated as a class requiring active protection, with the stated objective of promoting a culture of acting in the SME customer's best interest. The regulation applies to all banks and finance companies licensed by the CBUAE, including Islamic institutions, in relation to financial products and services provided to SME customers.
The SME definition follows the Federal tiers by sector: micro enterprises up to roughly AED 2 to 3 million in annual revenues depending on sector, small enterprises up to AED 20 to 50 million, with employee-count alternatives. The practical consequence is that a large share of an institution's business banking book now sits inside a prescriptive protection regime.
What institutions must now do
- Governance of the product lifecycle. Article 2 requires a strong governance framework over the design, development, promotion, sale and distribution of products, with monitoring, controls and management oversight, and the Board and Senior Management setting the tone from the top.
- Dual-language disclosure. Information disclosed to customers through any channel, digital channels included, must be available in both English and Arabic, in plain language, with warning statements for key characteristics, fees, rates and locked terms.
- Key Facts Statement. Before providing any financial product or service, the institution must give the customer a Key Facts Statement, and the customer must acknowledge receipt before entering into the contract. Institutions must also present reasonable options and comparisons and keep applicants informed of the process and timeline.
- Responsible financing. Products must be assessed for appropriateness, suitability and affordability for the customer, staff must be trained and verified against that duty, and remuneration policies must not incentivise mis-selling. A financing file that cannot show a documented affordability assessment is now a visible compliance gap.
- Independent complaints function. Complaints must be free of charge, acknowledged in writing within two business days with a unique tracking reference, and managed by an independent complaints function reporting directly to Senior Management, empowered to resolve complaints independently of the business lines.
- Financial difficulty framework. Institutions must proactively engage when payment irregularities first appear, maintain mechanisms for restructuring, product modification and adjusted payment plans, and provide impartial credit counselling to customers struggling with debt.
C 1/2026: operational risk becomes operational resilience
The operational risk side is the larger structural change. The 2018 framework applied to banks and focused on preventing operational losses. C 1/2026 applies to all licensed financial institutions that are juridical persons, insurers, finance companies, exchange houses and payment service providers included, and is built around Operational Resilience: the ability to deliver critical operations through disruption, not merely to avoid it.
The architecture
- Critical operations mapping. Institutions must identify their critical operations and map every asset needed to deliver them: people, technology, processes, data, facilities and third-party providers, including intragroup arrangements, kept current through change management.
- Board ownership. The Board itself, not a committee, must approve and review at least annually the operational risk appetite, the tolerance for disruption and the associated limits. Systemically important institutions must maintain a Board-level operational risk committee.
- Annual report on internal control. Senior Management must assess the internal control system regularly, at least annually for banks and insurers, and formalise it in a report provided to both the Board and the Central Bank.
- Independent penetration testing. Stress-testing of the control environment is mandatory, and for critical functions periodic penetration testing must be performed by an independent third party, with results presented to the Board.
- Third-party risk. Outsourcing anything that could significantly impact critical operations requires prior CBUAE non-objection, contracts must give the Central Bank inspection and reporting rights enforceable down to subcontractors, and the regulator can order an institution to exit a third-party arrangement altogether.
- Change control with teeth. Changes material to critical operations require thorough pre-implementation testing, rollback plans, an independent external expert report, notification to the CBUAE at least 30 calendar days before implementation, and the Central Bank's written no-objection before go-live.
- Data localisation. The Master System of Record, the collection of all data required to run critical operations, must be continuously maintained and stored within the UAE, including where outsourced; foreign branches may hold an up-to-date UAE copy subject to CBUAE approval.
The reporting clock
Article 15 is where the new regime will be felt first. For any operational risk event that significantly impacts, or may significantly impact, the continuity or integrity of critical operations, the institution must:
| Deadline | Obligation |
|---|---|
| Within 4 hours | Notify the Central Bank of the event, including which critical operations are affected |
| Within 24 hours | Provide a summary report: nature of the event, actions being taken, likely impact, timeframe to normal operations |
| On recovery | Notify the Central Bank upon returning to normal operations |
| Within 72 hours | Notify any high-risk incident, against criteria defined in Board-approved policies |
A 4-hour clock is not met by a well-drafted policy. It is met by detection tooling, a rehearsed escalation path, pre-agreed severity classifications and someone with authority available at 2am. That is precisely the outcomes-based shift both regulations embody.
Enforcement is personal
Both regulations carry supervisory, administrative and financial sanctions, and both spell out that these may include withdrawing, replacing or restricting the powers of Senior Management or Board members, interim management of the institution, and barring individuals from the UAE financial sector. Directors and executives of CBUAE licensees should read these instruments as being addressed to them personally, not to their compliance departments.
What to do now
Institutions in scope should be running a gap assessment against both instruments: mapping critical operations and third-party dependencies, testing whether the incident escalation path can actually hit 4 and 24 hours, reviewing SME onboarding and credit files for Key Facts Statements and documented affordability assessments, standing up or repositioning the independent complaints function, and confirming the Master System of Record sits in the UAE. Where outsourcing or system changes touching critical operations are planned, the 30-day notification and written no-objection requirements need to be built into project timelines now.
Neo Legal advises CBUAE-licensed banks, finance companies, exchange houses and payment institutions on regulatory gap assessments, remediation programmes and supervisory engagement, alongside our payment services licensing and payment token practices. For institutions also holding or seeking virtual asset permissions, see our analysis of CBUAE Resolution No. 16 of 2026, which admits banks and PSPs into CMA-regulated virtual asset activity.
Frequently asked questions
This article is general information as at 17 September 2026, based on the texts of Circulars No. 1/2026 and 2/2026 as published on the CBUAE Rulebook, and is not legal advice. Institutions should assess their position against the full regulatory texts and any standards or guidelines the Central Bank issues under them.
