Our Expert in United Arab Emirates
No results available
The UAE’s financial-sector regulatory framework is anchored in the Central Bank Law, Federal Decree-Law No. 14 of 2018 Concerning the Central Bank & Organisation of Financial Institutions and Activities, as subsequently amended, which gives the Central Bank of the UAE (CBUAE) broad supervisory authority over banks, finance companies, insurers and payment service providers. For any bank, finance company, insurer or payment service provider operating in the UAE, being properly licensed and “regularised” under the applicable CBUAE framework and transitional arrangements is not a formality: it determines whether a firm continues to operate lawfully or faces administrative sanctions, licence suspension or revocation, and, in serious cases, criminal liability.
This article sets out what regularisation requires, who is affected, and the practical steps and remediation planning that in-scope entities should have in place.
Note on dates and instrument references: financial-sector legislation in the UAE is periodically amended, and specific transitional deadlines are set by the relevant law, Cabinet decision or CBUAE regulation and circular. Firms should confirm the exact instrument, article numbers and any current transitional deadline applicable to their activity directly with the CBUAE or through qualified legal counsel before acting, as these can change.
In brief: If your entity is a bank, finance company, insurer or payment service provider operating in the UAE, you must complete your licensing, governance and reporting obligations, or file a remediation plan acceptable to the CBUAE, within any transitional window applicable to your activity. This guide explains what “regularised” means, the categories of enforcement risk, and a step-by-step action plan to present to the Central Bank.
Where a transitional period applies to your firm, you must either be fully regularised, holding valid licences or registered transitional permissions, with compliant governance, AML/CFT frameworks and reporting in place, or have a remediation plan accepted by the CBUAE with fixed milestones, before the applicable deadline.
Firms that have not yet acted should treat this as an urgent matter. The single most important step is to engage with the regulator rather than allow a deadline to pass in silence. A voluntary, well-documented disclosure accompanied by a credible remediation timeline demonstrates good faith and can materially reduce enforcement risk. Entities that do nothing expose themselves to compliance notices, escalating fines, and in the most serious cases criminal referral. Appoint a senior responsible officer, assemble your compliance documentation, and seek legal counsel to confirm the exact requirements and any deadline applicable to your activity.
The Central Bank Law draws a wide perimeter. It consolidates supervision of much of the financial sector under the CBUAE, meaning that a broad range of licensed and regulated entities fall within scope of the framework and any transitional arrangements. In practice, the categories most clearly captured are:
Financial firms established in the Dubai International Financial Centre (DIFC) or the Abu Dhabi Global Market (ADGM) are regulated by those centres’ respective regulators (the Dubai Financial Services Authority and the Financial Services Regulatory Authority) rather than by the CBUAE, and are outside the scope of this guidance.
The practical test is whether an entity carries on a licensed financial activity supervised by the CBUAE. A fintech offering payment services onshore, for example, generally sits within scope even if it previously operated under a legacy authorisation. Similarly, insurers now sit under CBUAE supervision and must satisfy the applicable requirements. Firms operating under earlier permissions should not assume those authorisations survive automatically where a transitional regime applies, the purpose of such arrangements is typically to migrate legacy licences and permissions onto the current regime. If you are uncertain whether your activity is captured, the safe course is to assume it is and confirm your position formally with the regulator.
“Regularised” is best understood as a composite state rather than a single act: an entity is regularised when its licensing status, its governance and control environment, and its reporting and disclosure obligations all satisfy the requirements of the applicable framework, or when a remediation plan addressing any outstanding gaps has been accepted by the CBUAE. The three pillars below break the concept down into practical tests.
The first pillar is licensing. Every in-scope entity must hold a valid licence or authorisation under the applicable CBUAE framework, or a properly registered transitional permission that carries the entity through until full authorisation is granted. It is not enough merely to have applied, regularisation turns on the licence or permission being registered and documented, with evidence of filing retained.
Practical steps to satisfy this pillar include:
The distinction between a transitional permission and a full authorisation matters. A transitional permission is a bridge, not a destination; entities relying on one should maintain a documented path to full authorisation before any transitional period ends.
The second pillar is governance. The CBUAE framework sets expectations for board composition, senior management and internal control, including through its corporate governance regulations and standards for banks and other financial institutions. Regularisation requires that directors and key persons meet fit-and-proper standards, and that these assessments are documented rather than assumed. Boards must be able to evidence that their composition, oversight and control functions meet the applicable requirements.
Key governance actions include:
The third pillar is reporting. Regularisation requires that all periodic and event-driven reports required under the framework have been filed, that financial statements are current and compliant, and that risk reporting is in place. Where a firm cannot fully meet its obligations by an applicable deadline, a documented remediation plan filed with and accepted by the CBUAE can function as the transitional equivalent, provided it sets out concrete dates and responsible officers.
Reporting priorities include:
| Requirement | Regularised | Not regularised | Likely regulator response |
|---|---|---|---|
| Licence / authorisation | Valid licence or transitional permission registered and documented | No licence or incomplete registration | Compliance notice → fines → suspension/revocation |
| Governance | Fit-and-proper directors and documented internal controls | Missing fit-and-proper documentation | Investigations; potential administrative fines |
| Reporting | Required reports filed or remediation plan accepted | No filings and no plan | Sanction risk; criminal referral in the most serious cases |
| AML/CFT | AML framework implemented and evidenced | AML gaps or missing KYC | Heavy fines; possible criminal investigation |
The difference between a controlled outcome and an enforcement exposure often comes down to organisation. The checklist below structures the work into a phased timeline relative to any applicable deadline. Adapt the dates to your own position, but do not leave the substantive work to the final week.
If you are reading this close to a deadline, prioritise the following: appoint a senior responsible officer to own the process; assemble your licensing, governance and reporting evidence into a single file; identify the specific gaps that cannot be closed in time; and prepare a disclosure to the CBUAE. Filing something credible is far better than filing nothing.
A remediation plan converts an incomplete compliance position into a managed one. It should be specific, dated and owned. Vague commitments to “improve controls” carry little weight; the regulator expects concrete milestones tied to named officers. The template in the remediation section below sets out the fields to include. The core principle is transparency: disclose the gap, explain the cause, and commit to a fixed completion date.
The enforcement architecture under the Central Bank Law is deliberately robust, reflecting the significance the UAE attaches to financial-sector integrity. Firms that treat compliance as optional expose themselves to a spectrum of consequences ranging from administrative measures to criminal proceedings.
The Central Bank Law equips the CBUAE with a graduated toolkit of administrative sanctions. At the lower end sit compliance notices and directions to remedy. Escalating measures include administrative fines, restrictions on business, suspension of activities, replacement of board members or senior management, and ultimately licence revocation. The specific amounts and ranges of administrative fines are set by the Central Bank Law and the CBUAE’s regulations and are subject to the schedules and thresholds in force at the relevant time; firms should confirm the applicable figures with the CBUAE or counsel rather than rely on any single headline number.
In practice, the sanction applied is calibrated to the seriousness of the failing, the harm caused or risked, the entity’s cooperation, and whether the firm self-reported. This calibration is precisely why voluntary disclosure and a credible remediation plan matter: they position a firm at the cooperative, mitigated end of the range rather than the punitive end. An entity that discloses a reporting gap and commits to fixing it within a defined period generally presents very differently to the regulator than one discovered to have concealed the same gap.
Beyond administrative sanctions, the Central Bank Law creates the potential for criminal liability in respect of certain breaches, for example carrying on a licensed financial activity without authorisation, or obstructing supervision. Criminal exposure elevates the stakes considerably: it can attach to individuals as well as entities, and a criminal referral carries reputational and personal consequences that no administrative fine matches. The precise elements and penalties are defined in the criminal provisions of the Central Bank Law, and their application should be assessed with qualified counsel.
The practical defence against criminal exposure is the same discipline that protects against administrative sanction, demonstrable good faith, prompt disclosure, and a documented effort to comply. Entities should ensure that decisions taken during any transitional period are recorded, that any breach is disclosed rather than concealed, and that senior officers can evidence the steps they took to bring the firm into compliance. Concealment, by contrast, is the factor most likely to convert a remediable failing into a more serious matter. Where there is any doubt about potential criminal exposure, legal advice should be taken before communicating with the regulator.
A common question is whether the CBUAE can extend a deadline. As a matter of regulatory discretion, the CBUAE may in appropriate cases grant additional time, phase requirements, or accept a remediation timeline. But there is a critical distinction between legal possibility and prudent planning: the existence of a discretion is not a substitute for compliance, and no firm should build its strategy around an informal or assumed extension.
The realistic position is that any accommodation is likely to be granted selectively, on the facts, and typically to entities that have already engaged constructively with the regulator. Additional time is far more likely to follow a filed remediation plan than to be handed to a firm that has taken no action. In other words, the route to more time runs through disclosure and engagement, not through silence.
Indicators that make an accommodation more plausible include early and voluntary engagement, a substantially complete compliance position with only limited residual gaps, a credible and dated remediation plan already submitted, and evidence of active board-level oversight. Firms exhibiting these features present a cooperative profile; firms that have done nothing present the opposite.
If your firm cannot achieve full regularisation before an applicable deadline, the decisive action is to file a remediation plan. A well-constructed plan tells the regulator exactly what remains outstanding, how you will fix it, by when, and who is accountable. The structure below provides a model.
| Field | What to include |
|---|---|
| Entity details | Legal name, licence category, registration number and regulated activities |
| Outstanding items | Each specific gap in licensing, governance, AML/CFT or reporting |
| Remediation steps | The concrete action that will close each gap |
| Target completion date | A fixed date for each item, not a range |
| Responsible officer | The named senior individual accountable for delivery |
| Monitoring and reporting | How progress will be tracked and reported back to the CBUAE |
The covering disclosure should be candid and businesslike. Identify the entity and its status, acknowledge the specific areas where regularisation is not yet complete, and set out the remediation plan with dates. Sample wording might read: “The entity confirms that it has completed [X] and that the following items remain outstanding: [list]. The entity commits to completing each outstanding item by the dates set out in the attached plan, under the responsibility of [named officer], and will report progress to the Central Bank on a [frequency] basis. ” The tone throughout should be one of transparent cooperation.
A remediation plan that is specific, dated and owned is among the most effective tools for reducing enforcement risk when full compliance cannot be achieved in time.
Enforcement does not fall uniformly on every non-compliant firm. The likely practical effect is a risk-based approach in which the regulator prioritises the most serious failings. Firms can usefully assess their own profile:
Supervisory practice in the UAE generally rewards cooperation and reserves the heaviest sanctions for concealment and inaction. The recommended next step for any firm still short of full compliance is the same regardless of profile: engage now, document everything, and take legal advice.
Compliance with the UAE Central Bank Law and any transitional arrangements applicable to your activity is essential, and the consequences of inaction can be severe, administrative fines, licence suspension or revocation, and potential criminal liability. Being regularised means valid licensing, compliant governance and AML/CFT frameworks, and complete reporting, or a remediation plan accepted by the CBUAE. If your firm is not yet fully compliant, confirm the precise requirements and any deadline that applies to you, engage with the regulator, disclose transparently, and present a dated remediation plan with a named responsible officer. Do not rely on an informal extension. Taking timely legal advice is the surest way to protect your firm, your board and your senior officers.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Arsen Khachikian at AKTA, a member of the Global Law Experts network.
posted 13 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message