Frameworks · Middle East
CBUAE Risk Management Regulation
The Central Bank of the UAE issued its Risk Management Regulation, Circular No. 153/2018, on 27 May 2018. The Regulation and its accompanying Risk Management Standards require every licensed bank to run a comprehensive risk management framework. The board and senior management oversee the framework, and it applies on a solo and group-wide basis.
Who it applies to
It applies to all banks licensed by the Central Bank of the UAE. Banks with significant group relationships, including subsidiaries, affiliates and international branches, apply the Regulation and Standards on a solo and group-wide basis.
Main requirements
Governance
The board oversees risk and sets a risk appetite statement. Banks have an independent risk management function, and senior management is accountable.
Framework
Banks identify, measure, monitor and control risks across the bank, using systems and tools to assess and measure them.
Reporting
Risk is reported internally to the board, and to the Central Bank as required.
Group application
The framework is applied consistently across subsidiaries, affiliates and branches.
How xmodo supports it
- 1
xmodo sets up the Regulation and Standards as the parent risk framework. Technology and information security requirements sit beneath it as a separate pack.
- 2
Board risk reports are generated from the current status of your controls and the risk register.
- 3
Groups set up each subsidiary as a separate entity within one account, with a consolidated view of the whole group.
Related frameworks
CBUAE Risk Management Regulation shares requirements with the frameworks below. Controls you already run for any of them count towards CBUAE Risk Management Regulation as well.
Frequently asked questions
Is there a "CBUAE Cybersecurity Framework"?
No single document has that title. The Central Bank sets risk governance through the Risk Management Regulation and Standards. It sets technology and information security requirements through articles in its regulations for each licence type. xmodo sets these up as two separate packs and does not use an umbrella title that does not exist.
Does the Regulation cover technology risk?
It sets the overall governance. The technology risk and information security obligations are in the licence-specific regulations. xmodo sets them up in the CBUAE Technology Risk & Information Security pack, which sits beneath this one.