[codicts-css-switcher id=”346″]

Global Law Experts Logo
corporate governance uae

How to Comply with UAE Corporate Governance Rules for Banks & Insurers (2026)

By Global Law Experts
– posted 2 hours ago

Corporate governance UAE requirements for banks and insurers have entered a more demanding phase, and boards, general counsel and compliance leads now face concrete implementation expectations rather than aspirational principles. The Central Bank of the UAE (CBUAE) applies its Corporate Governance Standards to licensed banks and its Corporate Governance Regulation to insurance companies, and both frameworks emphasise board accountability, director independence, robust internal controls and demonstrable evidence of oversight. This guide translates those rulebook obligations into a practical, step-by-step implementation programme: it sets out who is responsible for what, which documents a regulator will typically inspect, how long each phase realistically takes, and the direction of travel for recent updates.

For neutral, regulator-aligned support you can also consult the UAE Corporate Law practice page (Corporate practice, UAE) or Find a UAE corporate lawyer, GLE directory (filtered: UAE, Corporate). This article is provided for guidance only and does not constitute legal advice; consult qualified counsel and check the current CBUAE rulebook before acting.

Overview: the regulatory framework and key standards

Corporate governance UAE obligations for regulated financial institutions flow primarily from two CBUAE instruments: the Corporate Governance Standards for Banks and the Corporate Governance Regulation for Insurance Companies. Both are published on the Central Bank’s rulebook and carry supervisory force, non-compliance is not merely a documentation gap but a regulatory breach capable of triggering enforcement.

At the heart of both frameworks is a single principle: the board of directors is ultimately responsible for the sound and prudent management of the institution. The rulebook translates that principle into specific obligations covering board composition and independence, the establishment of specialised board committees, a documented risk appetite, effective internal controls, an independent internal audit function, controls over related-party transactions (RPTs), and transparent disclosure to the regulator.

What practitioners consistently find is that the regulator’s pages state what must exist without prescribing in full detail how to build it. This is the gap this guide fills. Readers will get a numbered compliance programme, a roles and accountability matrix, a required-documents checklist, a realistic implementation timeline mapped to typical durations, an indicative costs breakdown, and a plain-language summary of recent supervisory trends. The CBUAE standards are broadly consistent with international benchmarks, notably the Basel Committee’s corporate governance principles for banks, the IAIS insurance core principles, and the G20/OECD Principles of Corporate Governance, so an institution that builds to these standards will generally be well-positioned to meet both domestic supervisory and cross-border expectations.

Eligibility & scope: which institutions must comply

In-scope entities: banks, Islamic banks and insurers

The corporate governance UAE regime administered by the CBUAE applies to banks licensed by the Central Bank, including conventional banks and Islamic banks. Islamic banks carry an additional governance layer, Shari’ah governance, including an internal Shari’ah supervision arrangement and the Higher Shari’ah Authority framework, which sits alongside, not instead of, the general corporate governance requirements. Insurance companies fall within scope of the Corporate Governance Regulation for Insurance Companies, which imposes broadly parallel board and control obligations with sector-specific emphasis on actuarial oversight, reserving and underwriting controls. Note that responsibility for insurance supervision transferred to the CBUAE following the dissolution of the former Insurance Authority.

Out-of-scope entities and parallel frameworks (DIFC / ADGM)

Financial institutions established in the Dubai International Financial Centre (DIFC) or the Abu Dhabi Global Market (ADGM) are regulated under separate legal and regulatory regimes and are not subject to the CBUAE rulebook. A financial firm operating in the DIFC must comply with the applicable Dubai Financial Services Authority (DFSA) rules and DIFC companies legislation, and an ADGM entity with the Financial Services Regulatory Authority (FSRA) framework. Groups with entities in both the onshore UAE and a financial free zone must run parallel governance programmes calibrated to each authority. Statutory director duties and company-law context for onshore entities derive from UAE federal corporate legislation, principally the Federal Decree-Law concerning Commercial Companies, which should be read together with the sector rulebooks.

Step-by-step corporate governance UAE compliance programme

The following seven steps convert the CBUAE standards into an executable project. Each step identifies the lead owner, the deliverables, and the evidence a supervisor will typically expect to see during inspection. Documenting that evidence trail is as important as the underlying activity, regulators assess governance by what an institution can demonstrate, not what it asserts.

Step 1, Conduct a governance diagnostic and gap analysis

Begin by mapping every existing policy, charter and control against the current CBUAE rulebook requirements for your sector. The objective is a clause-by-clause gap register that distinguishes quick wins (for example, updating a committee terms of reference) from larger projects (for example, rebuilding an RPT monitoring capability).

  • Lead owner. Head of Compliance, supported by the General Counsel.
  • Actions. Inventory current documents; map each rulebook obligation to a control or policy; rate compliance status; prioritise gaps by supervisory risk.
  • Deliverables. A gap-analysis report, a prioritised remediation plan, and a board-approved implementation timeline.

Present the diagnostic to the board rather than absorbing it at management level. Board endorsement of the remediation plan is itself governance evidence and establishes the accountability chain the regulator expects.

Step 2, Update board duties, composition and charters

The board charter is a foundational corporate governance UAE document and among the first things a supervisor requests. It should define the board’s collective responsibilities, the matters reserved to the board, delegated authority limits, and the mandate of each committee. Under both the banking standards and the insurance regulation, institutions are expected to establish specialised committees, typically including Audit, Risk, Nomination and Remuneration functions, each with its own written terms of reference (TOR). Institutions should confirm the exact committee requirements against the current rulebook clauses applicable to their sector.

Director independence requires particular care. Apply the independence tests set out in the rulebook, document the assessment for each director, and refresh the assessment periodically. A defensible independence file contains a signed declaration, a checklist against each independence criterion, and evidence of verification (for example, confirmation of no material commercial relationships).

  • Lead owner. The board, acting through the Nomination Committee and Board Secretary.
  • Deliverables. Updated board charter; committee TORs for Audit, Risk, Nomination and Remuneration; individual director independence declarations.

A sample reserved-matters clause for a charter might read: “The Board reserves to itself approval of the Corporate Governance Policy, the Risk Appetite Statement, the appointment and removal of the Head of Internal Audit and the Chief Risk Officer, and any related-party transaction exceeding the thresholds set by the Board.” For detailed drafting support see Drafting a Board Charter for UAE Banks: Required Clauses & Practical Templates and Board Committee TORs (Audit, Risk, Remuneration, Nomination), UAE templates & best practice.

Step 3, Draft or revise governance policies and codes

With the charter fixed, build out the policy suite that operationalises it. The CBUAE frameworks expect a coherent set of documented policies, each formally approved and version-controlled.

  • Corporate governance policy. The high-level framework aligning the institution’s structure with the rulebook.
  • Conflicts of interest and related-party transactions. Definitions, thresholds, approval routes and a maintained register.
  • Whistleblowing policy. Confidential reporting channels, protection for reporters and a complaint log.
  • Remuneration policy. Incentive structures aligned to risk, with clawback and deferral where appropriate.
  • Risk appetite statement. Board-approved quantitative and qualitative limits.

Each policy should record its approval date, approving body and review cycle. Approval records, board or committee minutes evidencing adoption, are the proof point a supervisor checks.

Step 4, Strengthen internal controls, risk and internal audit

Corporate governance UAE compliance is only credible where controls are tested, not merely designed. Map the control universe against the institution’s principal risks, test control effectiveness on a scheduled basis, and confirm that the internal audit (IA) function is genuinely independent with a direct reporting line to the Audit Committee.

  • Lead owner. Chief Risk Officer for risk and controls; Head of Internal Audit for assurance.
  • Actions. Build a control matrix; run effectiveness testing; confirm IA independence and resourcing; secure independent assurance over high-risk areas.
  • Deliverables. Control matrix, Internal Audit Charter, risk-based annual IA plan, and independent assurance reports.

For insurers, the control universe must extend to underwriting, reserving and reinsurance arrangements, with actuarial oversight embedded in the risk governance structure. See How to Update Internal Controls & Policies to Meet Central Bank Governance Standards for a detailed controls uplift methodology.

Step 5, Reporting, disclosures and supervisory engagement

Boards can only exercise oversight if they receive the right information. Standardise the board reporting pack so it maps directly to rulebook items, risk appetite utilisation, RPT summaries, IA findings, compliance breaches and remediation status. Appoint a regulatory liaison responsible for supervisory correspondence, filings and public disclosures.

  • Lead owner. General Counsel and the designated Regulatory Liaison.
  • Deliverables. Standardised board packs, regulatory filings, minuted board decisions, and disclosure records.

Proactive engagement matters. Where an institution identifies a material gap, notifying the supervisor with a credible remediation timeline is generally viewed more favourably than waiting for the gap to surface during inspection.

Step 6, Remediation, testing and training

Close the identified gaps through short, tracked implementation sprints, and build governance capability at the top. The rulebook expects directors and senior executives to be, and to remain, competent (fit and proper), so training is a continuing obligation, not a one-off induction.

  • Actions. Deliver board and executive training on the current standards; run mock supervisory interviews; test newly implemented controls.
  • Deliverables. Training logs, test reports and updated evidence files.

Step 7, Final assurance and documentation pack

Assemble a single, well-indexed compliance pack: charter, TORs, policies, independence files, IA charter and plan, risk appetite statement, board packs, minutes and training records. This pack is the artefact you place in front of a supervisor. A clean, complete pack signals a mature control environment; a fragmented one invites deeper scrutiny.

Roles and accountability matrix

Step Accountable owner Key evidence for regulator
Governance diagnostic Head of Compliance / General Counsel Gap report, board-approved remediation plan
Board duties & charters Board / Nomination Committee Signed charter, committee TORs, independence declarations
Policies & codes Board / CEO / Compliance Approved policies, minuted approval records
Internal controls & risk Chief Risk Officer Control matrix, risk register, risk appetite statement
Internal audit Head of Internal Audit IA charter, annual plan, assurance reports
Reporting & disclosure General Counsel / Regulatory Liaison Board packs, filings, minutes
Training & culture HR / Compliance Training logs, attendance records

Banks vs insurers: how the obligations differ

Although the corporate governance UAE frameworks for banks and insurers share a similar architecture, the emphasis differs by sector. The table below highlights the key distinctions; institutions should verify the specific requirements against the current rulebook.

Area Banks (CBUAE rulebook) Insurers (CBUAE regulation)
Supervisory regime Central Bank of the UAE, Corporate Governance Standards for Banks Central Bank of the UAE, Corporate Governance Regulation for Insurance Companies
Board independence Prescriptive independence tests and composition expectations Similar tests, with emphasis on actuarial and underwriting oversight
Committees expected Audit, Risk, Nomination, Remuneration Audit, Risk and Remuneration functions, plus actuarial oversight arrangements
Internal audit independence High threshold; direct reporting line to the Audit Committee/board High threshold; emphasis on underwriting and reserving controls
Related-party transactions Strict RPT controls and disclosure Insurer-specific RPT risks, reinsurance and broker relationships

Required documents and templates

Regulators assess corporate governance UAE compliance through documentary evidence. The table below lists the core records supervisors typically expect, what each demonstrates, and who owns it. Institutions should maintain these as living documents with clear version control and approval trails, and retain board packs and minutes in line with applicable record-keeping requirements.

Document / record Purpose / what the regulator checks Owner
Board Charter (signed) Defines board duties, committees and limits of authority Board Secretary / GC
Committee TORs (Audit, Risk, Nomination, Remuneration) Demonstrates delegated oversight and specialised governance Board Secretary
Director appointment paperwork & independence declarations Evidence of fit-and-proper and independence assessments HR / Compliance
Corporate governance policy High-level framework aligned with the rulebook Board / CEO
Conflict of interest register & RPT policy Controls over related-party transactions Compliance / Finance
Internal Audit Charter & annual plan Independence and coverage of key risks Internal Audit
Risk appetite statement & risk register Risk governance and risk limits CRO
Board packs & minutes Evidence of oversight and decision-making Board Secretary
Remuneration policy & approval records Alignment of incentives with risk Remuneration Committee
Whistleblowing policy & complaint logs Reporting lines, protection and follow-up Compliance / HR
Regulatory filings / supervisory correspondence Evidence of disclosure and engagement Regulatory Liaison / GC
Training records (board & senior exec) Evidence of capability and continuous competence HR / Compliance

Sector-specific checklists accelerate assembly of this pack, see the Corporate Governance Compliance Checklist for UAE Insurance Companies for insurer-tailored evidence requirements.

Timeline and deadlines

Where the CBUAE prescribes a specific compliance date in the applicable rulebook clause, that date governs and must be honoured, always confirm the current deadline directly in the rulebook. Absent a fixed date, the timeline below reflects realistic durations for building corporate governance UAE compliance from a partial baseline. Institutions with major gaps should plan for a six-to-nine-month programme; those requiring only targeted remediation can often complete within three months.

Step Lead (who) Typical duration
Governance diagnostic & gap analysis Head of Compliance / GC 4–6 weeks
Draft remediation plan & board approval GC / CEO / Board Secretary 2–4 weeks
Update board charter & TORs; appoint committee members Board / Nomination Committee 3–6 weeks
Revise core policies (conflicts, RPT, whistleblowing) Compliance / Legal 4–8 weeks
Strengthen internal controls & IA plan CRO / Head of Internal Audit 6–12 weeks
Training & culture change programme HR / Compliance Ongoing (2–4 weeks initial intensive)
Testing, assurance & regulator engagement Internal Audit / Compliance 4–8 weeks
Final sign-off & documentation pack Board Secretary / GC 1–2 weeks

Several workstreams can run in parallel, policy drafting can proceed while controls testing is designed, which is how disciplined programmes compress an apparent nine-month total into a shorter elapsed period. Sequencing board charter approval early is critical, because it unblocks committee appointments and downstream policy adoption.

Costs, fees and resourcing

Budgeting for a corporate governance UAE compliance programme means balancing internal redeployment against external specialist support. The table gives high-level, indicative cost buckets only; actual figures vary significantly with institution size, the scale of gaps, and how much drafting and controls testing is outsourced. Obtain current quotes from advisers before budgeting.

Item Indicative cost driver Notes
Internal staff time (project management) Internal budget Estimate 0.5–2 FTE for 3–6 months
External legal advice Scope-dependent Depends on scope and bespoke drafting
Consultancy (controls / risk assessment) Scope-dependent Control testing and internal audit uplift
Training workshops (board & exec) Per session Varies with attendee numbers
IT / compliance tooling Scale-dependent Disclosure, control testing, RPT monitoring
Filing / regulatory fees As per regulator’s current schedule Usually administrative

Recent supervisory direction of travel

Recent revisions and supervisory practice within the corporate governance UAE framework have tightened several areas that were previously treated more as guidance. Institutions should read the precise current clauses in the CBUAE rulebook, but the direction of travel is consistent and demands a documented response.

  • Stricter board independence. Independence criteria are increasingly prescriptive, and institutions are expected to maintain a documented, refreshed assessment for each director rather than a one-time declaration.
  • Expanded board reporting. Boards are expected to receive richer, standardised information covering risk appetite utilisation, RPTs and internal audit findings, with evidence that the board acted on it.
  • Explicit related-party transaction oversight. RPT controls, thresholds and disclosure are more clearly mandated, a particular focus for insurers given reinsurance and broker relationships.
  • Enhanced internal audit independence. Reporting lines, resourcing and independence expectations for the IA function are reinforced.
  • Clearer supervisory powers. The regulator’s ability to intervene and sanction for governance breaches remains explicit under the CBUAE’s governing legislation.

The practical implications are immediate: charters and TORs need reviewing against the current rulebook, remediation timetables should be realistic, and every governance action should leave an auditable evidence trail. Supervisory inspections increasingly probe the operation of governance, testing whether committees genuinely challenge management, rather than merely confirming that documents exist. The likely practical effect is that institutions relying on paper compliance will be exposed, while those that can demonstrate active oversight will fare better.

Common pitfalls and remediation

  • Treating governance as paperwork. Policies without tested controls fail inspection. Remediation: implement evidence-based controls and schedule effectiveness testing.
  • Weak director independence evidence. Undocumented independence is treated as non-compliance. Remediation: adopt standard declaration templates and a documented verification process.
  • Inadequate board packs. Sparse reporting undermines demonstrable oversight. Remediation: introduce standardised reporting templates mapped to rulebook items.
  • Failure to test controls. Design without assurance is a recurring finding. Remediation: build a risk-based internal audit plan and obtain third-party assurance over high-risk areas.
  • Poor regulatory engagement. Surprising the supervisor damages credibility. Remediation: appoint a regulatory liaison and disclose material gaps early with a remediation timeline.

Conclusion and next steps

Corporate governance UAE compliance for banks and insurers rewards institutions that treat governance as an operating discipline rather than a documentation exercise. Follow the seven-step programme, assign clear accountability through the roles matrix, assemble the required-documents pack, and align the timeline to any CBUAE-mandated deadlines. Recent supervisory direction raises the bar on independence, reporting, RPT oversight and internal audit, so build an auditable evidence trail into every action from the outset. For a compliance review of your framework, contact a UAE corporate lawyer through the Find a UAE corporate lawyer, GLE directory (filtered: UAE, Corporate), and explore the supporting templates for board charters, committee TORs and controls updates linked throughout this guide.

This article is for general guidance only; obtain tailored legal advice and check the current CBUAE rulebook before implementing changes.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Mohammed Haitham A. Salman at Middle East Alliance Legal Consultancy (ME-Alliance), a member of the Global Law Experts network.

Sources

  1. Central Bank of the UAE, Corporate Governance Standards for Banks
  2. Central Bank of the UAE, Corporate Governance Regulation for Insurance Companies
  3. UAE Federal Legislation Portal
  4. Securities & Commodities Authority (SCA)
  5. Basel Committee on Banking Supervision
  6. International Association of Insurance Supervisors (IAIS)
  7. OECD, G20/OECD Principles of Corporate Governance
  8. Dubai International Financial Centre (DIFC)

FAQs

What corporate governance standards must UAE banks comply with?
Licensed banks must comply with the CBUAE Corporate Governance Standards for Banks. These cover board composition and independence, the establishment of specialised committees (typically Audit, Risk, Nomination and Remuneration), a documented risk appetite, effective internal controls, an independent internal audit function, RPT oversight and regulatory disclosure.
The board of directors is ultimately responsible. Operational delivery is shared: the CEO drives execution, the Head of Compliance runs the diagnostic and policy programme, the Chief Risk Officer owns risk and controls, Internal Audit provides independent assurance, and the General Counsel manages regulatory engagement and documentation.
Core evidence includes a signed board charter, committee TORs, director independence declarations, the corporate governance policy, conflicts-of-interest and RPT policies, the Internal Audit Charter and plan, the risk appetite statement, board packs and minutes, the remuneration policy, the whistleblowing policy, and training records. See the required-documents table above.
Where the rulebook prescribes a specific date, that date binds, confirm it directly in the CBUAE rulebook. Otherwise, a full programme from a partial baseline typically runs six to nine months, and targeted remediation often completes within three months. If gaps cannot be closed in time, notify the regulator with a credible remediation timeline.
No. DIFC and ADGM are separate legal and regulatory regimes. Financial institutions in those free zones follow the rules of the DFSA or FSRA respectively, not the CBUAE rulebook. Groups spanning both onshore and free-zone entities must run parallel governance programmes.
The CBUAE holds supervisory powers that can include financial penalties, business restrictions, conditions on the licence, and action against individuals where governance failings are attributable to them. The precise enforcement provisions derive from the CBUAE’s governing legislation and the relevant rulebook pages.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Comply with UAE Corporate Governance Rules for Banks & Insurers (2026)

Send welcome message

Custom Message