HomeFrameworksCBUAE Tech & Cyber Risk
Central Bank of the UAE (CBUAE) · United Arab Emirates

CBUAE Operational Risk, Technology and Cyber Regulations compliance software

The Central Bank of the UAE's operational-risk, technology and cyber obligations for licensed financial institutions — the ORM Regulation article by article, plus the technology-risk articles for stored value facilities and payment service providers.

At a glance
  • RegulatorCentral Bank of the UAE
  • InstrumentsOperational Risk Management Regulation · SVF Regulation (C 6/2020) Art 12 · Retail Payment Services Regulation (C 15/2021) Art 13
  • Structure15 domains — ORM Articles 2–13 and 15, plus SVF and RPS technology-risk articles
  • Controls220 obligations; licence-type articles shown only to the tenants they bind
CBUAE Tech & Cyber RiskAvailable
Overview

What CBUAE Tech & Cyber Risk requires

Who it applies to

  • Banks and finance companies licensed by the CBUAE
  • Insurers, now supervised by the CBUAE
  • Stored Value Facility licensees (SVF Regulation Article 12)
  • Retail Payment Service Providers and card schemes (RPS Regulation Article 13)

The Central Bank of the UAE supervises banks, finance companies, exchange houses, insurers, stored value facility licensees and retail payment service providers. Its Operational Risk Management Regulation binds every licensed financial institution and sets out the operational risk framework, operational resilience, the roles of the board and senior management, the risk function, internal control, ICT and cybersecurity management, incident management, risk data, business continuity, change management, third-party risk and notification to the Central Bank.

Two licence types carry additional technology-risk articles of their own: Article 12 of the Stored Value Facilities Regulation (C 6/2020) and Article 13 of the Retail Payment Services and Card Schemes Regulation (C 15/2021). Those obligations are detailed and specific to the licence, and an assessment that shows them to a bank — or hides them from a payment provider — is wrong for both.

GRCLens carries the regulation as one framework with the licence-type articles scoped to the tenants they bind: 220 obligations, transcribed paragraph by paragraph from the CBUAE Rulebook, with the ORM articles applying to all and the SVF and RPS articles applying by sector.

In the platform

How GRCLens supports CBUAE Tech & Cyber Risk

CBUAE Tech & Cyber Risk runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Articles as domains

The ORM Regulation's articles are the dashboard's sections — board, senior management, risk function, ICT and cyber, incidents, BCP, change, third parties, notification — so the posture reads in the regulator's own order.

Scoped by licence

SVF and payment-provider articles apply only to tenants that declare the licence. A bank never sees them; a payment provider always does.

Indicators for what the CBUAE notifies about

Notification and reporting readiness, third-party risk, ICT and cybersecurity management and business continuity as counts of unmet articles, with thresholds set for a supervised institution.

One evidence base with ISO and PCI

A bank running ISO/IEC 27001 and a payment provider running PCI DSS reuse that evidence wherever the CBUAE article asks for the same control.

Questions

CBUAE Tech & Cyber Risk frequently asked questions

Which CBUAE instruments does the framework cover?

The Operational Risk Management Regulation for all licensed financial institutions, Article 12 of the Stored Value Facilities Regulation for SVF licensees, and Article 13 of the Retail Payment Services and Card Schemes Regulation for payment service providers.

We hold an SVF licence. Do we assess the ORM Regulation too?

Yes. The ORM Regulation binds every licensed financial institution; the SVF technology-risk article applies on top of it. The tenant's licence type decides which additional articles appear.

Are the DFSA and FSRA regimes part of this?

No. DIFC and ADGM firms are regulated by the DFSA and the FSRA respectively, and GRCLens carries those as separate frameworks. An onshore bank with a DIFC branch runs both.

Talk to us about CBUAE Tech & Cyber Risk

Security Solution Consultants provides CBUAE operational and cyber risk advisory alongside the platform, so you can combine tooling with hands-on expertise.