Operational resilience becomes a firm-wide obligation
CBUAE Circular C 1/2026, issued on 3 February 2026, replaces the UAE's 2018 Operational Risk Regulation and Standards. The change is more than a refresh of operational risk terminology. It brings operational risk management, internal control, technology resilience, third-party dependency and business continuity into a single framework centred on the continued delivery of critical operations.
The Operational Risk Management Regulation applies to licensed financial institutions that are juridical persons. It expects each institution to understand how disruption could affect its customers, operations, profitability and capital, and to demonstrate how it will continue delivering critical operations through severe but plausible events.
That shifts the question from whether individual systems can be recovered to whether the institution can preserve the operation that customers and the financial system rely on. Technology recovery remains essential, but it is only one part of the answer.
Critical-operations mapping is the foundation
Institutions must identify their critical operations and map the assets needed to deliver them. The required view includes people, technology, processes, data, facilities and third-party service providers, together with the interconnections and dependencies among them.
This is important because weaknesses often sit between organisational boundaries. A payment operation may rely on several applications, a cloud provider, telecommunications connectivity, manual reconciliation, specialist staff and intragroup support. Looking at each component separately can conceal the point at which the end-to-end service becomes vulnerable.
The regulation also requires a process universe that identifies process and risk owners. For many institutions, this will expose gaps between existing business continuity documentation, technology inventories, outsourcing registers and operational-risk assessments. Those records must ultimately describe the same operating model.
From recovery objectives to tolerance for disruption
The Board must approve and review, at least annually, the institution's operational risk and resilience strategies, its risk appetite and its tolerance for disruption. Tolerance should reflect the institution's ability to deliver critical operations under a range of severe but plausible scenarios.
This introduces a more demanding management discipline than setting recovery-time objectives for individual applications. A credible tolerance must be measurable at the critical-operation level, supported by evidence and connected to escalation thresholds. Where testing shows that an operation cannot remain within tolerance, the institution needs a funded remediation decision rather than another entry on a risk register.
Senior management must translate the Board's expectations into effective policies, controls and systems. Banks and insurers must also conduct at least an annual assessment of the internal control system, including key controls over material processes supporting critical operations, and provide the resulting report to the Board and the CBUAE.
Technology and third-party resilience cannot be separated
The regulation requires a robust ICT and cybersecurity risk framework that covers identification, mitigation, monitoring, testing, incident management and recovery. Technology capacity and availability must support current and projected requirements during normal conditions and periods of stress.
Third-party arrangements receive equally direct attention. Institutions must perform risk assessment and due diligence before entering an arrangement, maintain enough internal capability to manage outsourced activities and avoid excessive reliance on outsourcing. Where a provider supports a critical operation, the institution must verify that the provider has an equivalent level of operational resilience.
This makes concentration and substitutability practical governance issues. Contractual protections are useful, but they do not prove that a service can be recovered, transferred or operated through a provider failure. Institutions need current dependency data, tested communication routes, access to relevant incident information and realistic contingency or exit options.
Testing and incident reporting raise the standard of readiness
Business continuity and disaster recovery plans must be integrated with critical-operations mapping and tested under severe but plausible scenarios. Testing should challenge the control environment, including technology, physical controls and controls dependent on people. At least for critical functions, penetration testing must include an independent third party, with results presented to the Board.
The notification timetable is also materially tighter than the framework it replaces. An event that significantly affects, or may affect, the continuity or integrity of critical operations must be notified to the CBUAE within four hours. A summary report follows within 24 hours, and the institution must notify the regulator again when normal operations resume. High-risk incidents are separately subject to a 72-hour notification requirement.
Meeting those timelines requires more than an incident template. Classification criteria, decision authority, escalation routes, regulatory reporting ownership and access to reliable operational information must all work while the institution is under pressure.
What institutions should be able to demonstrate
A strong implementation should show a traceable line from critical operations to dependencies, disruption tolerances, controls, testing and investment decisions. It should also connect operational loss events and root-cause analysis to risk assessments, control improvements and changes in resilience priorities.
The three lines of defence remain explicit. Business management owns and controls operational risk, risk and compliance provide independent challenge, and internal audit provides assurance over the effectiveness of the framework. The point is not to distribute responsibility so widely that no one owns the outcome. Each critical operation needs clear executive ownership and timely escalation when resilience falls outside tolerance.
For institutions still relying on separate operational risk, continuity, technology and outsourcing programmes, C 1/2026 is a reason to bring them together around one view of how critical operations are delivered and protected.