CBUAE Operational Risk, Technology and Cyber Regulations compliance software
The Central Bank of the UAE's operational-risk, technology and cyber obligations for licensed financial institutions — the ORM Regulation article by article, plus the technology-risk articles for stored value facilities and payment service providers.
- RegulatorCentral Bank of the UAE
- InstrumentsOperational Risk Management Regulation · SVF Regulation (C 6/2020) Art 12 · Retail Payment Services Regulation (C 15/2021) Art 13
- Structure15 domains — ORM Articles 2–13 and 15, plus SVF and RPS technology-risk articles
- Controls220 obligations; licence-type articles shown only to the tenants they bind
What CBUAE Tech & Cyber Risk requires
Who it applies to
- Banks and finance companies licensed by the CBUAE
- Insurers, now supervised by the CBUAE
- Stored Value Facility licensees (SVF Regulation Article 12)
- Retail Payment Service Providers and card schemes (RPS Regulation Article 13)
The Central Bank of the UAE supervises banks, finance companies, exchange houses, insurers, stored value facility licensees and retail payment service providers. Its Operational Risk Management Regulation binds every licensed financial institution and sets out the operational risk framework, operational resilience, the roles of the board and senior management, the risk function, internal control, ICT and cybersecurity management, incident management, risk data, business continuity, change management, third-party risk and notification to the Central Bank.
Two licence types carry additional technology-risk articles of their own: Article 12 of the Stored Value Facilities Regulation (C 6/2020) and Article 13 of the Retail Payment Services and Card Schemes Regulation (C 15/2021). Those obligations are detailed and specific to the licence, and an assessment that shows them to a bank — or hides them from a payment provider — is wrong for both.
GRCLens carries the regulation as one framework with the licence-type articles scoped to the tenants they bind: 220 obligations, transcribed paragraph by paragraph from the CBUAE Rulebook, with the ORM articles applying to all and the SVF and RPS articles applying by sector.
How GRCLens supports CBUAE Tech & Cyber Risk
CBUAE Tech & Cyber Risk runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Articles as domains
The ORM Regulation's articles are the dashboard's sections — board, senior management, risk function, ICT and cyber, incidents, BCP, change, third parties, notification — so the posture reads in the regulator's own order.
Scoped by licence
SVF and payment-provider articles apply only to tenants that declare the licence. A bank never sees them; a payment provider always does.
Indicators for what the CBUAE notifies about
Notification and reporting readiness, third-party risk, ICT and cybersecurity management and business continuity as counts of unmet articles, with thresholds set for a supervised institution.
One evidence base with ISO and PCI
A bank running ISO/IEC 27001 and a payment provider running PCI DSS reuse that evidence wherever the CBUAE article asks for the same control.
CBUAE Tech & Cyber Risk frequently asked questions
Which CBUAE instruments does the framework cover?
The Operational Risk Management Regulation for all licensed financial institutions, Article 12 of the Stored Value Facilities Regulation for SVF licensees, and Article 13 of the Retail Payment Services and Card Schemes Regulation for payment service providers.
We hold an SVF licence. Do we assess the ORM Regulation too?
Yes. The ORM Regulation binds every licensed financial institution; the SVF technology-risk article applies on top of it. The tenant's licence type decides which additional articles appear.
Are the DFSA and FSRA regimes part of this?
No. DIFC and ADGM firms are regulated by the DFSA and the FSRA respectively, and GRCLens carries those as separate frameworks. An onshore bank with a DIFC branch runs both.
One platform, many obligations

Talk to us about CBUAE Tech & Cyber Risk
Security Solution Consultants provides CBUAE operational and cyber risk advisory alongside the platform, so you can combine tooling with hands-on expertise.