CBUAE's Operational Risk Regulation: A Guide for Financial Institutions

The CBUAE’s 2026 Operational Risk Management Regulation draws Operational Risk Management and Operational Resilience into a single framework, extending its reach across governance, Critical Operations, ICT and cybersecurity, incident management, data, business continuity, third-party risk, and material change.

For Financial Institutions, the discussion centred on how these requirements may influence the way risk, disruption, and continuity are governed across the institution.

 

During the session, we explored the CBUAE’s Operational Risk Management Regulation, considered its implications for Financial Institutions, and examined the areas that may warrant attention as institutions assess the new framework. 


Key discussion areas included:
 

  • How the Regulation brings Operational Risk Management and Operational Resilience together 
  • Why Critical Operations are central to the framework, and the dependencies that support them across people, processes, technology, data, facilities, and third parties 
  • What the Regulation expects from the Board, Senior Management, and the three lines of defence 
  • How requirements for ICT, incident management, risk data, business continuity, and disaster recovery may reshape the operational risk framework 


For many Financial Institutions, the more immediate task is understanding how these requirements fit with the structures and processes already in place.


The discussion therefore examined the transition with particular attention to existing arrangements, and to the way institutions currently understand

Event Details

Reserve your seat and join the conversation with us.

09 September, 2026

Meet Our Speaker