The Central Bank of the UAE has brought a new Operational Risk Management Regulation into force for Licensed Financial Institutions, adding a demanding reporting timetable to a broader shift toward demonstrable Operational Resilience.
The regulation, C 1/2026, became effective on 14 September 2026. Article 15.2 requires an institution to notify the Central Bank within four hours of an Operational Risk event that significantly impacts, or may significantly impact, the continuity or integrity of Critical Operations. A summary report is then required within 24 hours.
The reporting window is significant because it changes what good Operational Risk management has to look like in practice. A financial institution cannot meet a four-hour requirement if it does not have timely visibility into incidents, clear escalation paths, well-defined Critical Operations and the ability to assemble evidence quickly.

The regulation also makes clear that Incident Response and Recovery Plans cover, but are not limited to, ICT and cyber security incidents, and its broader framework addresses third-party dependencies and operational failures. For institutions deploying AI into critical processes, that raises a practical question about how an AI-related failure would be detected, classified and escalated if it threatened a Critical Operation.
This is part of a wider supervisory direction away from treating resilience as a collection of recovery plans. The regulation requires institutions to identify threats and vulnerabilities affecting Critical Operations and to manage disruption within an integrated Operational Risk and Operational Resilience framework.
The four-hour requirement will also place pressure on supplier and third-party arrangements. Financial institutions may depend on cloud providers, cyber security vendors, identity platforms, data processors and AI systems that sit outside their direct operational control. Contracts and technical integrations therefore need to support rapid incident notification and evidence gathering rather than only periodic assurance.
For vendors selling into UAE financial services, the regulation creates a practical test of 'regulated-industry readiness'. Products that claim to improve visibility, resilience or AI governance will increasingly need to show what evidence they can produce during an incident and how quickly that evidence can be delivered.
The broader lesson is that Operational Resilience is becoming measurable. Policies and recovery plans still matter, but supervisors are asking whether institutions can identify disruption quickly, protect Critical Operations and explain what happened on a timetable measured in hours rather than days.
