[codicts-css-switcher id=”346″]

Global Law Experts Logo
uae central bank law

Our Expert in United Arab Emirates

The UAE Central Bank Law and Financial-sector Regularisation: What In-scope Firms Must Do

By Global Law Experts
– posted 2 hours ago

The UAE’s financial-sector regulatory framework is anchored in the Central Bank Law, Federal Decree-Law No. 14 of 2018 Concerning the Central Bank & Organisation of Financial Institutions and Activities, as subsequently amended, which gives the Central Bank of the UAE (CBUAE) broad supervisory authority over banks, finance companies, insurers and payment service providers. For any bank, finance company, insurer or payment service provider operating in the UAE, being properly licensed and “regularised” under the applicable CBUAE framework and transitional arrangements is not a formality: it determines whether a firm continues to operate lawfully or faces administrative sanctions, licence suspension or revocation, and, in serious cases, criminal liability.

This article sets out what regularisation requires, who is affected, and the practical steps and remediation planning that in-scope entities should have in place.

Note on dates and instrument references: financial-sector legislation in the UAE is periodically amended, and specific transitional deadlines are set by the relevant law, Cabinet decision or CBUAE regulation and circular. Firms should confirm the exact instrument, article numbers and any current transitional deadline applicable to their activity directly with the CBUAE or through qualified legal counsel before acting, as these can change.

In brief: If your entity is a bank, finance company, insurer or payment service provider operating in the UAE, you must complete your licensing, governance and reporting obligations, or file a remediation plan acceptable to the CBUAE, within any transitional window applicable to your activity. This guide explains what “regularised” means, the categories of enforcement risk, and a step-by-step action plan to present to the Central Bank.

Executive summary, priorities and immediate actions (TL;DR)

Where a transitional period applies to your firm, you must either be fully regularised, holding valid licences or registered transitional permissions, with compliant governance, AML/CFT frameworks and reporting in place, or have a remediation plan accepted by the CBUAE with fixed milestones, before the applicable deadline.

Firms that have not yet acted should treat this as an urgent matter. The single most important step is to engage with the regulator rather than allow a deadline to pass in silence. A voluntary, well-documented disclosure accompanied by a credible remediation timeline demonstrates good faith and can materially reduce enforcement risk. Entities that do nothing expose themselves to compliance notices, escalating fines, and in the most serious cases criminal referral. Appoint a senior responsible officer, assemble your compliance documentation, and seek legal counsel to confirm the exact requirements and any deadline applicable to your activity.

Who is in scope?

The Central Bank Law draws a wide perimeter. It consolidates supervision of much of the financial sector under the CBUAE, meaning that a broad range of licensed and regulated entities fall within scope of the framework and any transitional arrangements. In practice, the categories most clearly captured are:

  • Banks. Licensed banks operating domestically, including branches of foreign banks authorised in the UAE.
  • Finance companies. Licensed finance and lending institutions offering credit and financing products.
  • Insurers. Insurance and reinsurance companies, supervised by the CBUAE following the integration of the former Insurance Authority into the Central Bank.
  • Payment service providers. PSPs, stored-value facility operators and other participants in the payments ecosystem regulated under the CBUAE’s retail payment services and related frameworks.
  • Other financial intermediaries. Exchange houses, money service businesses and further categories of regulated financial firms.

Financial firms established in the Dubai International Financial Centre (DIFC) or the Abu Dhabi Global Market (ADGM) are regulated by those centres’ respective regulators (the Dubai Financial Services Authority and the Financial Services Regulatory Authority) rather than by the CBUAE, and are outside the scope of this guidance.

Scope boundaries and examples

The practical test is whether an entity carries on a licensed financial activity supervised by the CBUAE. A fintech offering payment services onshore, for example, generally sits within scope even if it previously operated under a legacy authorisation. Similarly, insurers now sit under CBUAE supervision and must satisfy the applicable requirements. Firms operating under earlier permissions should not assume those authorisations survive automatically where a transitional regime applies, the purpose of such arrangements is typically to migrate legacy licences and permissions onto the current regime. If you are uncertain whether your activity is captured, the safe course is to assume it is and confirm your position formally with the regulator.

What “regularised” means, licensing, governance and reporting

“Regularised” is best understood as a composite state rather than a single act: an entity is regularised when its licensing status, its governance and control environment, and its reporting and disclosure obligations all satisfy the requirements of the applicable framework, or when a remediation plan addressing any outstanding gaps has been accepted by the CBUAE. The three pillars below break the concept down into practical tests.

Licensing and authorisation

The first pillar is licensing. Every in-scope entity must hold a valid licence or authorisation under the applicable CBUAE framework, or a properly registered transitional permission that carries the entity through until full authorisation is granted. It is not enough merely to have applied, regularisation turns on the licence or permission being registered and documented, with evidence of filing retained.

Practical steps to satisfy this pillar include:

  • Confirm your current licence category. Map your existing authorisation against the current licence categories and identify any migration required.
  • File or renew as required. Where a fresh application or renewal is needed, submit it with the full supporting file and retain proof of submission and any acknowledgement from the CBUAE.
  • Register transitional permissions. If your firm relies on a transitional permission, ensure it is formally registered rather than merely assumed. An unregistered permission offers no protection at a deadline.
  • Document the chain. Keep a clear evidence trail, application dates, correspondence, acknowledgements, so that you can demonstrate exactly where you stand at any given time.

The distinction between a transitional permission and a full authorisation matters. A transitional permission is a bridge, not a destination; entities relying on one should maintain a documented path to full authorisation before any transitional period ends.

Governance and fit-and-proper

The second pillar is governance. The CBUAE framework sets expectations for board composition, senior management and internal control, including through its corporate governance regulations and standards for banks and other financial institutions. Regularisation requires that directors and key persons meet fit-and-proper standards, and that these assessments are documented rather than assumed. Boards must be able to evidence that their composition, oversight and control functions meet the applicable requirements.

Key governance actions include:

  • Board and key-person assessments. Confirm that directors, the CEO and other key persons satisfy fit-and-proper criteria, and retain the documentary evidence supporting each assessment.
  • Internal controls. Ensure risk management, compliance and internal audit functions are properly resourced, independent and documented.
  • AML/CFT frameworks. Implement and evidence anti-money-laundering and counter-terrorist-financing systems, including customer due diligence, KYC procedures, transaction monitoring and suspicious-transaction reporting through the Financial Intelligence Unit’s goAML platform, consistent with Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and its implementing regulations. AML/CFT gaps are among the most heavily penalised failings, so this is a priority area.
  • Governance documentation. Maintain up-to-date policies, delegations of authority, and board minutes demonstrating active oversight.

Reporting, disclosures and transitional statements

The third pillar is reporting. Regularisation requires that all periodic and event-driven reports required under the framework have been filed, that financial statements are current and compliant, and that risk reporting is in place. Where a firm cannot fully meet its obligations by an applicable deadline, a documented remediation plan filed with and accepted by the CBUAE can function as the transitional equivalent, provided it sets out concrete dates and responsible officers.

Reporting priorities include:

  • Required regulatory returns. Confirm all prudential and conduct returns are filed and up to date.
  • Financial statements. Ensure audited financial statements meet the applicable standards.
  • Risk reporting. Provide risk reports covering credit, operational, market and financial-crime risk as applicable to your activity.
  • Documented remediation plans. Where gaps remain, submit a remediation plan with milestones, this is the mechanism that converts an incomplete position into a managed one.
Requirement Regularised Not regularised Likely regulator response
Licence / authorisation Valid licence or transitional permission registered and documented No licence or incomplete registration Compliance notice → fines → suspension/revocation
Governance Fit-and-proper directors and documented internal controls Missing fit-and-proper documentation Investigations; potential administrative fines
Reporting Required reports filed or remediation plan accepted No filings and no plan Sanction risk; criminal referral in the most serious cases
AML/CFT AML framework implemented and evidenced AML gaps or missing KYC Heavy fines; possible criminal investigation

Step-by-step compliance checklist and action plan

The difference between a controlled outcome and an enforcement exposure often comes down to organisation. The checklist below structures the work into a phased timeline relative to any applicable deadline. Adapt the dates to your own position, but do not leave the substantive work to the final week.

  1. 60 days out. Complete a full gap analysis across licensing, governance and reporting. Identify every outstanding item, assign an owner, and set an internal completion date for each.
  2. 30 days out. File any outstanding licence applications, renewals or transitional-permission registrations. Finalise fit-and-proper documentation for all key persons. Close out AML/CFT gaps.
  3. 14 days out. Submit all outstanding regulatory returns and financial statements. Where any item cannot be completed in time, draft the remediation plan now.
  4. 7 days out. Confirm your evidence file is complete and retrievable. If gaps remain, file the remediation plan and a disclosure with the CBUAE rather than waiting.

Immediate (within 7 days) actions

If you are reading this close to a deadline, prioritise the following: appoint a senior responsible officer to own the process; assemble your licensing, governance and reporting evidence into a single file; identify the specific gaps that cannot be closed in time; and prepare a disclosure to the CBUAE. Filing something credible is far better than filing nothing.

If you need more time, how to structure a remediation plan

A remediation plan converts an incomplete compliance position into a managed one. It should be specific, dated and owned. Vague commitments to “improve controls” carry little weight; the regulator expects concrete milestones tied to named officers. The template in the remediation section below sets out the fields to include. The core principle is transparency: disclose the gap, explain the cause, and commit to a fixed completion date.

Penalties and enforcement

The enforcement architecture under the Central Bank Law is deliberately robust, reflecting the significance the UAE attaches to financial-sector integrity. Firms that treat compliance as optional expose themselves to a spectrum of consequences ranging from administrative measures to criminal proceedings.

Administrative sanctions

The Central Bank Law equips the CBUAE with a graduated toolkit of administrative sanctions. At the lower end sit compliance notices and directions to remedy. Escalating measures include administrative fines, restrictions on business, suspension of activities, replacement of board members or senior management, and ultimately licence revocation. The specific amounts and ranges of administrative fines are set by the Central Bank Law and the CBUAE’s regulations and are subject to the schedules and thresholds in force at the relevant time; firms should confirm the applicable figures with the CBUAE or counsel rather than rely on any single headline number.

In practice, the sanction applied is calibrated to the seriousness of the failing, the harm caused or risked, the entity’s cooperation, and whether the firm self-reported. This calibration is precisely why voluntary disclosure and a credible remediation plan matter: they position a firm at the cooperative, mitigated end of the range rather than the punitive end. An entity that discloses a reporting gap and commits to fixing it within a defined period generally presents very differently to the regulator than one discovered to have concealed the same gap.

Criminal exposure

Beyond administrative sanctions, the Central Bank Law creates the potential for criminal liability in respect of certain breaches, for example carrying on a licensed financial activity without authorisation, or obstructing supervision. Criminal exposure elevates the stakes considerably: it can attach to individuals as well as entities, and a criminal referral carries reputational and personal consequences that no administrative fine matches. The precise elements and penalties are defined in the criminal provisions of the Central Bank Law, and their application should be assessed with qualified counsel.

The practical defence against criminal exposure is the same discipline that protects against administrative sanction, demonstrable good faith, prompt disclosure, and a documented effort to comply. Entities should ensure that decisions taken during any transitional period are recorded, that any breach is disclosed rather than concealed, and that senior officers can evidence the steps they took to bring the firm into compliance. Concealment, by contrast, is the factor most likely to convert a remediable failing into a more serious matter. Where there is any doubt about potential criminal exposure, legal advice should be taken before communicating with the regulator.

Can the CBUAE extend a transitional period? A practical and legal view

A common question is whether the CBUAE can extend a deadline. As a matter of regulatory discretion, the CBUAE may in appropriate cases grant additional time, phase requirements, or accept a remediation timeline. But there is a critical distinction between legal possibility and prudent planning: the existence of a discretion is not a substitute for compliance, and no firm should build its strategy around an informal or assumed extension.

The realistic position is that any accommodation is likely to be granted selectively, on the facts, and typically to entities that have already engaged constructively with the regulator. Additional time is far more likely to follow a filed remediation plan than to be handed to a firm that has taken no action. In other words, the route to more time runs through disclosure and engagement, not through silence.

When more time may be granted, indicators

Indicators that make an accommodation more plausible include early and voluntary engagement, a substantially complete compliance position with only limited residual gaps, a credible and dated remediation plan already submitted, and evidence of active board-level oversight. Firms exhibiting these features present a cooperative profile; firms that have done nothing present the opposite.

Practical remediation plan, how to file and what to include

If your firm cannot achieve full regularisation before an applicable deadline, the decisive action is to file a remediation plan. A well-constructed plan tells the regulator exactly what remains outstanding, how you will fix it, by when, and who is accountable. The structure below provides a model.

Field What to include
Entity details Legal name, licence category, registration number and regulated activities
Outstanding items Each specific gap in licensing, governance, AML/CFT or reporting
Remediation steps The concrete action that will close each gap
Target completion date A fixed date for each item, not a range
Responsible officer The named senior individual accountable for delivery
Monitoring and reporting How progress will be tracked and reported back to the CBUAE

Drafting a remediation filing and timeline

The covering disclosure should be candid and businesslike. Identify the entity and its status, acknowledge the specific areas where regularisation is not yet complete, and set out the remediation plan with dates. Sample wording might read: “The entity confirms that it has completed [X] and that the following items remain outstanding: [list]. The entity commits to completing each outstanding item by the dates set out in the attached plan, under the responsibility of [named officer], and will report progress to the Central Bank on a [frequency] basis. ” The tone throughout should be one of transparent cooperation.

A remediation plan that is specific, dated and owned is among the most effective tools for reducing enforcement risk when full compliance cannot be achieved in time.

Likely enforcement approach and scenarios

Enforcement does not fall uniformly on every non-compliant firm. The likely practical effect is a risk-based approach in which the regulator prioritises the most serious failings. Firms can usefully assess their own profile:

  • High risk. No licence, no filings and no engagement, expect early compliance notices, fines and, in serious cases, referral. These firms should file a disclosure and remediation plan immediately.
  • Medium risk. Substantially compliant but with documented gaps and a filed remediation plan, more likely to be managed through supervisory engagement than punitive action.
  • Low risk. Fully regularised with a complete evidence file, routine supervision only.

Supervisory practice in the UAE generally rewards cooperation and reserves the heaviest sanctions for concealment and inaction. The recommended next step for any firm still short of full compliance is the same regardless of profile: engage now, document everything, and take legal advice.

Key takeaways and recommended next steps

Compliance with the UAE Central Bank Law and any transitional arrangements applicable to your activity is essential, and the consequences of inaction can be severe, administrative fines, licence suspension or revocation, and potential criminal liability. Being regularised means valid licensing, compliant governance and AML/CFT frameworks, and complete reporting, or a remediation plan accepted by the CBUAE. If your firm is not yet fully compliant, confirm the precise requirements and any deadline that applies to you, engage with the regulator, disclose transparently, and present a dated remediation plan with a named responsible officer. Do not rely on an informal extension. Taking timely legal advice is the surest way to protect your firm, your board and your senior officers.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Arsen Khachikian at AKTA, a member of the Global Law Experts network.

Sources

  1. Central Bank of the UAE
  2. UAE Government Official Portal (u.ae)
  3. UAE Legislation Portal
  4. UAE Ministry of Justice
  5. UAE Ministry of Finance

FAQs

What law governs financial-sector regularisation in the UAE?
The principal instrument is the Central Bank Law, Federal Decree-Law No. 14 of 2018 Concerning the Central Bank & Organisation of Financial Institutions and Activities, as amended, supplemented by CBUAE regulations, standards and circulars. Specific transitional deadlines are set by the applicable law, Cabinet decision or CBUAE regulation and should be confirmed with the regulator or counsel.
Banks, licensed finance companies, insurers and payment service providers, together with other in-scope financial firms supervised by the CBUAE, must be properly licensed and regularised. Firms in the DIFC and ADGM are regulated by those centres’ own regulators instead.
Regularisation means holding a valid licence or a registered transitional permission, having updated governance and fit-and-proper documentation and AML/CFT frameworks in place, and having filed the required reports, or having a remediation plan accepted by the CBUAE with clear dates.
Administrative measures including fines (in amounts set by the Central Bank Law and CBUAE regulations in force), business restrictions, suspension or revocation of licences, and, in certain cases, criminal liability under the Central Bank Law.
The CBUAE has discretion to grant additional time or phase requirements in appropriate cases, but relying on an extension is risky. Entities should engage early and, if additional time is needed, request it within a documented remediation plan rather than assuming an extension will be granted.
Engage the regulator immediately, attach a remediation plan with fixed milestones and completion dates, appoint a senior contact, and seek legal counsel without delay.
By A&M Consulting Co.

posted 2 hours ago

By A&M Consulting Co.

posted 2 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

The UAE Central Bank Law and Financial-sector Regularisation: What In-scope Firms Must Do

Send welcome message

Custom Message