Both regulations are issued under Federal Decree-Law No. 6 of 2025, the new Central Bank law covering the regulation of financial institutions, activities and insurance business. Read together, they mark a visible shift in supervisory philosophy: away from asking whether a policy document exists, and towards asking whether governance, controls and risk management demonstrably work in practice, with the Board and Senior Management personally accountable for the answer.

C 2/2026: from market conduct to customer protection

The renaming is the message. The 2021 instrument regulated market conduct; the 2026 instrument protects customers. SMEs, including sole proprietors, are now treated as a class requiring active protection, with the stated objective of promoting a culture of acting in the SME customer's best interest. The regulation applies to all banks and finance companies licensed by the CBUAE, including Islamic institutions, in relation to financial products and services provided to SME customers.

The SME definition follows the Federal tiers by sector: micro enterprises up to roughly AED 2 to 3 million in annual revenues depending on sector, small enterprises up to AED 20 to 50 million, with employee-count alternatives. The practical consequence is that a large share of an institution's business banking book now sits inside a prescriptive protection regime.

What institutions must now do

  • Governance of the product lifecycle. Article 2 requires a strong governance framework over the design, development, promotion, sale and distribution of products, with monitoring, controls and management oversight, and the Board and Senior Management setting the tone from the top.
  • Dual-language disclosure. Information disclosed to customers through any channel, digital channels included, must be available in both English and Arabic, in plain language, with warning statements for key characteristics, fees, rates and locked terms.
  • Key Facts Statement. Before providing any financial product or service, the institution must give the customer a Key Facts Statement, and the customer must acknowledge receipt before entering into the contract. Institutions must also present reasonable options and comparisons and keep applicants informed of the process and timeline.
  • Responsible financing. Products must be assessed for appropriateness, suitability and affordability for the customer, staff must be trained and verified against that duty, and remuneration policies must not incentivise mis-selling. A financing file that cannot show a documented affordability assessment is now a visible compliance gap.
  • Independent complaints function. Complaints must be free of charge, acknowledged in writing within two business days with a unique tracking reference, and managed by an independent complaints function reporting directly to Senior Management, empowered to resolve complaints independently of the business lines.
  • Financial difficulty framework. Institutions must proactively engage when payment irregularities first appear, maintain mechanisms for restructuring, product modification and adjusted payment plans, and provide impartial credit counselling to customers struggling with debt.

C 1/2026: operational risk becomes operational resilience

The operational risk side is the larger structural change. The 2018 framework applied to banks and focused on preventing operational losses. C 1/2026 applies to all licensed financial institutions that are juridical persons, insurers, finance companies, exchange houses and payment service providers included, and is built around Operational Resilience: the ability to deliver critical operations through disruption, not merely to avoid it.

The architecture

  • Critical operations mapping. Institutions must identify their critical operations and map every asset needed to deliver them: people, technology, processes, data, facilities and third-party providers, including intragroup arrangements, kept current through change management.
  • Board ownership. The Board itself, not a committee, must approve and review at least annually the operational risk appetite, the tolerance for disruption and the associated limits. Systemically important institutions must maintain a Board-level operational risk committee.
  • Annual report on internal control. Senior Management must assess the internal control system regularly, at least annually for banks and insurers, and formalise it in a report provided to both the Board and the Central Bank.
  • Independent penetration testing. Stress-testing of the control environment is mandatory, and for critical functions periodic penetration testing must be performed by an independent third party, with results presented to the Board.
  • Third-party risk. Outsourcing anything that could significantly impact critical operations requires prior CBUAE non-objection, contracts must give the Central Bank inspection and reporting rights enforceable down to subcontractors, and the regulator can order an institution to exit a third-party arrangement altogether.
  • Change control with teeth. Changes material to critical operations require thorough pre-implementation testing, rollback plans, an independent external expert report, notification to the CBUAE at least 30 calendar days before implementation, and the Central Bank's written no-objection before go-live.
  • Data localisation. The Master System of Record, the collection of all data required to run critical operations, must be continuously maintained and stored within the UAE, including where outsourced; foreign branches may hold an up-to-date UAE copy subject to CBUAE approval.

The reporting clock

Article 15 is where the new regime will be felt first. For any operational risk event that significantly impacts, or may significantly impact, the continuity or integrity of critical operations, the institution must:

DeadlineObligation
Within 4 hoursNotify the Central Bank of the event, including which critical operations are affected
Within 24 hoursProvide a summary report: nature of the event, actions being taken, likely impact, timeframe to normal operations
On recoveryNotify the Central Bank upon returning to normal operations
Within 72 hoursNotify any high-risk incident, against criteria defined in Board-approved policies

A 4-hour clock is not met by a well-drafted policy. It is met by detection tooling, a rehearsed escalation path, pre-agreed severity classifications and someone with authority available at 2am. That is precisely the outcomes-based shift both regulations embody.

Enforcement is personal

Both regulations carry supervisory, administrative and financial sanctions, and both spell out that these may include withdrawing, replacing or restricting the powers of Senior Management or Board members, interim management of the institution, and barring individuals from the UAE financial sector. Directors and executives of CBUAE licensees should read these instruments as being addressed to them personally, not to their compliance departments.

What to do now

Institutions in scope should be running a gap assessment against both instruments: mapping critical operations and third-party dependencies, testing whether the incident escalation path can actually hit 4 and 24 hours, reviewing SME onboarding and credit files for Key Facts Statements and documented affordability assessments, standing up or repositioning the independent complaints function, and confirming the Master System of Record sits in the UAE. Where outsourcing or system changes touching critical operations are planned, the 30-day notification and written no-objection requirements need to be built into project timelines now.

Neo Legal advises CBUAE-licensed banks, finance companies, exchange houses and payment institutions on regulatory gap assessments, remediation programmes and supervisory engagement, alongside our payment services licensing and payment token practices. For institutions also holding or seeking virtual asset permissions, see our analysis of CBUAE Resolution No. 16 of 2026, which admits banks and PSPs into CMA-regulated virtual asset activity.

Frequently asked questions

What new regulations did the CBUAE issue in September 2026?
Two regulations took effect in mid September 2026: the SME Customer Protection Regulation (Circular No. 2/2026), effective 13 September 2026, which replaces the 2021 SME Market Conduct Regulation, and the Operational Risk Management Regulation (Circular No. 1/2026), effective 14 September 2026, which cancels and replaces the 2018 Operational Risk Regulation and Standards (Circular No. 163/2018). Both are issued under Federal Decree-Law No. 6 of 2025, the new Central Bank Law.
Who is in scope of the CBUAE Operational Risk Management Regulation (C 1/2026)?
All Licensed Financial Institutions that are juridical persons, not only banks. That includes banks, insurance and reinsurance companies, finance companies, exchange houses, payment service providers and other CBUAE licensees, including institutions operating under Islamic Shari'ah. The 2018 framework it replaces applied to banks; the widened scope is one of the most significant changes.
What are the new CBUAE incident reporting deadlines?
Under Article 15 of C 1/2026, an institution must notify the CBUAE within 4 hours of an operational risk event that significantly impacts or may significantly impact critical operations, identifying the operations affected; provide a summary report within 24 hours covering the nature of the event, actions taken, likely impact and the timeframe for returning to normal operations; and notify the CBUAE again on return to normal operations. Separately, any high-risk incident must be notified within 72 hours.
What does the SME Customer Protection Regulation require before financing is extended?
Banks and finance companies must assess the appropriateness, suitability and affordability of a product for the SME customer, provide a Key Facts Statement before providing any financial product or service and obtain the customer's acknowledgment of receipt before contracting, present reasonable options and comparisons, and disclose all key features, fees, rates and locked terms in plain language in both English and Arabic.
What complaints handling does C 2/2026 require for SME customers?
Financial institutions must operate a free, accessible complaints process and establish an independent complaints management function reporting directly to Senior Management, empowered to resolve complaints independently of business lines. Receipt of a complaint must be acknowledged in writing within two business days with a unique tracking reference, and institutions must support customers in financial difficulty with restructuring mechanisms and impartial credit counselling.
What are the penalties for breaching the new CBUAE regulations?
Both regulations carry supervisory, administrative and financial sanctions at the Central Bank's discretion. These expressly include withdrawing, replacing or restricting the powers of Senior Management or Board members, placing the institution under interim management, imposing fines, and barring individuals from the UAE financial sector. Neo Legal assists institutions with gap assessments and remediation before supervisory attention arrives.

This article is general information as at 17 September 2026, based on the texts of Circulars No. 1/2026 and 2/2026 as published on the CBUAE Rulebook, and is not legal advice. Institutions should assess their position against the full regulatory texts and any standards or guidelines the Central Bank issues under them.