Our Expert in United Arab Emirates
Corporate governance UAE requirements for banks and insurers have entered a more demanding phase, and boards, general counsel and compliance leads now face concrete implementation expectations rather than aspirational principles. The Central Bank of the UAE (CBUAE) applies its Corporate Governance Standards to licensed banks and its Corporate Governance Regulation to insurance companies, and both frameworks emphasise board accountability, director independence, robust internal controls and demonstrable evidence of oversight. This guide translates those rulebook obligations into a practical, step-by-step implementation programme: it sets out who is responsible for what, which documents a regulator will typically inspect, how long each phase realistically takes, and the direction of travel for recent updates.
For neutral, regulator-aligned support you can also consult the UAE Corporate Law practice page (Corporate practice, UAE) or Find a UAE corporate lawyer, GLE directory (filtered: UAE, Corporate). This article is provided for guidance only and does not constitute legal advice; consult qualified counsel and check the current CBUAE rulebook before acting.
Corporate governance UAE obligations for regulated financial institutions flow primarily from two CBUAE instruments: the Corporate Governance Standards for Banks and the Corporate Governance Regulation for Insurance Companies. Both are published on the Central Bank’s rulebook and carry supervisory force, non-compliance is not merely a documentation gap but a regulatory breach capable of triggering enforcement.
At the heart of both frameworks is a single principle: the board of directors is ultimately responsible for the sound and prudent management of the institution. The rulebook translates that principle into specific obligations covering board composition and independence, the establishment of specialised board committees, a documented risk appetite, effective internal controls, an independent internal audit function, controls over related-party transactions (RPTs), and transparent disclosure to the regulator.
What practitioners consistently find is that the regulator’s pages state what must exist without prescribing in full detail how to build it. This is the gap this guide fills. Readers will get a numbered compliance programme, a roles and accountability matrix, a required-documents checklist, a realistic implementation timeline mapped to typical durations, an indicative costs breakdown, and a plain-language summary of recent supervisory trends. The CBUAE standards are broadly consistent with international benchmarks, notably the Basel Committee’s corporate governance principles for banks, the IAIS insurance core principles, and the G20/OECD Principles of Corporate Governance, so an institution that builds to these standards will generally be well-positioned to meet both domestic supervisory and cross-border expectations.
The corporate governance UAE regime administered by the CBUAE applies to banks licensed by the Central Bank, including conventional banks and Islamic banks. Islamic banks carry an additional governance layer, Shari’ah governance, including an internal Shari’ah supervision arrangement and the Higher Shari’ah Authority framework, which sits alongside, not instead of, the general corporate governance requirements. Insurance companies fall within scope of the Corporate Governance Regulation for Insurance Companies, which imposes broadly parallel board and control obligations with sector-specific emphasis on actuarial oversight, reserving and underwriting controls. Note that responsibility for insurance supervision transferred to the CBUAE following the dissolution of the former Insurance Authority.
Financial institutions established in the Dubai International Financial Centre (DIFC) or the Abu Dhabi Global Market (ADGM) are regulated under separate legal and regulatory regimes and are not subject to the CBUAE rulebook. A financial firm operating in the DIFC must comply with the applicable Dubai Financial Services Authority (DFSA) rules and DIFC companies legislation, and an ADGM entity with the Financial Services Regulatory Authority (FSRA) framework. Groups with entities in both the onshore UAE and a financial free zone must run parallel governance programmes calibrated to each authority. Statutory director duties and company-law context for onshore entities derive from UAE federal corporate legislation, principally the Federal Decree-Law concerning Commercial Companies, which should be read together with the sector rulebooks.
The following seven steps convert the CBUAE standards into an executable project. Each step identifies the lead owner, the deliverables, and the evidence a supervisor will typically expect to see during inspection. Documenting that evidence trail is as important as the underlying activity, regulators assess governance by what an institution can demonstrate, not what it asserts.
Begin by mapping every existing policy, charter and control against the current CBUAE rulebook requirements for your sector. The objective is a clause-by-clause gap register that distinguishes quick wins (for example, updating a committee terms of reference) from larger projects (for example, rebuilding an RPT monitoring capability).
Present the diagnostic to the board rather than absorbing it at management level. Board endorsement of the remediation plan is itself governance evidence and establishes the accountability chain the regulator expects.
The board charter is a foundational corporate governance UAE document and among the first things a supervisor requests. It should define the board’s collective responsibilities, the matters reserved to the board, delegated authority limits, and the mandate of each committee. Under both the banking standards and the insurance regulation, institutions are expected to establish specialised committees, typically including Audit, Risk, Nomination and Remuneration functions, each with its own written terms of reference (TOR). Institutions should confirm the exact committee requirements against the current rulebook clauses applicable to their sector.
Director independence requires particular care. Apply the independence tests set out in the rulebook, document the assessment for each director, and refresh the assessment periodically. A defensible independence file contains a signed declaration, a checklist against each independence criterion, and evidence of verification (for example, confirmation of no material commercial relationships).
A sample reserved-matters clause for a charter might read: “The Board reserves to itself approval of the Corporate Governance Policy, the Risk Appetite Statement, the appointment and removal of the Head of Internal Audit and the Chief Risk Officer, and any related-party transaction exceeding the thresholds set by the Board.” For detailed drafting support see Drafting a Board Charter for UAE Banks: Required Clauses & Practical Templates and Board Committee TORs (Audit, Risk, Remuneration, Nomination), UAE templates & best practice.
With the charter fixed, build out the policy suite that operationalises it. The CBUAE frameworks expect a coherent set of documented policies, each formally approved and version-controlled.
Each policy should record its approval date, approving body and review cycle. Approval records, board or committee minutes evidencing adoption, are the proof point a supervisor checks.
Corporate governance UAE compliance is only credible where controls are tested, not merely designed. Map the control universe against the institution’s principal risks, test control effectiveness on a scheduled basis, and confirm that the internal audit (IA) function is genuinely independent with a direct reporting line to the Audit Committee.
For insurers, the control universe must extend to underwriting, reserving and reinsurance arrangements, with actuarial oversight embedded in the risk governance structure. See How to Update Internal Controls & Policies to Meet Central Bank Governance Standards for a detailed controls uplift methodology.
Boards can only exercise oversight if they receive the right information. Standardise the board reporting pack so it maps directly to rulebook items, risk appetite utilisation, RPT summaries, IA findings, compliance breaches and remediation status. Appoint a regulatory liaison responsible for supervisory correspondence, filings and public disclosures.
Proactive engagement matters. Where an institution identifies a material gap, notifying the supervisor with a credible remediation timeline is generally viewed more favourably than waiting for the gap to surface during inspection.
Close the identified gaps through short, tracked implementation sprints, and build governance capability at the top. The rulebook expects directors and senior executives to be, and to remain, competent (fit and proper), so training is a continuing obligation, not a one-off induction.
Assemble a single, well-indexed compliance pack: charter, TORs, policies, independence files, IA charter and plan, risk appetite statement, board packs, minutes and training records. This pack is the artefact you place in front of a supervisor. A clean, complete pack signals a mature control environment; a fragmented one invites deeper scrutiny.
| Step | Accountable owner | Key evidence for regulator |
|---|---|---|
| Governance diagnostic | Head of Compliance / General Counsel | Gap report, board-approved remediation plan |
| Board duties & charters | Board / Nomination Committee | Signed charter, committee TORs, independence declarations |
| Policies & codes | Board / CEO / Compliance | Approved policies, minuted approval records |
| Internal controls & risk | Chief Risk Officer | Control matrix, risk register, risk appetite statement |
| Internal audit | Head of Internal Audit | IA charter, annual plan, assurance reports |
| Reporting & disclosure | General Counsel / Regulatory Liaison | Board packs, filings, minutes |
| Training & culture | HR / Compliance | Training logs, attendance records |
Although the corporate governance UAE frameworks for banks and insurers share a similar architecture, the emphasis differs by sector. The table below highlights the key distinctions; institutions should verify the specific requirements against the current rulebook.
| Area | Banks (CBUAE rulebook) | Insurers (CBUAE regulation) |
|---|---|---|
| Supervisory regime | Central Bank of the UAE, Corporate Governance Standards for Banks | Central Bank of the UAE, Corporate Governance Regulation for Insurance Companies |
| Board independence | Prescriptive independence tests and composition expectations | Similar tests, with emphasis on actuarial and underwriting oversight |
| Committees expected | Audit, Risk, Nomination, Remuneration | Audit, Risk and Remuneration functions, plus actuarial oversight arrangements |
| Internal audit independence | High threshold; direct reporting line to the Audit Committee/board | High threshold; emphasis on underwriting and reserving controls |
| Related-party transactions | Strict RPT controls and disclosure | Insurer-specific RPT risks, reinsurance and broker relationships |
Regulators assess corporate governance UAE compliance through documentary evidence. The table below lists the core records supervisors typically expect, what each demonstrates, and who owns it. Institutions should maintain these as living documents with clear version control and approval trails, and retain board packs and minutes in line with applicable record-keeping requirements.
| Document / record | Purpose / what the regulator checks | Owner |
|---|---|---|
| Board Charter (signed) | Defines board duties, committees and limits of authority | Board Secretary / GC |
| Committee TORs (Audit, Risk, Nomination, Remuneration) | Demonstrates delegated oversight and specialised governance | Board Secretary |
| Director appointment paperwork & independence declarations | Evidence of fit-and-proper and independence assessments | HR / Compliance |
| Corporate governance policy | High-level framework aligned with the rulebook | Board / CEO |
| Conflict of interest register & RPT policy | Controls over related-party transactions | Compliance / Finance |
| Internal Audit Charter & annual plan | Independence and coverage of key risks | Internal Audit |
| Risk appetite statement & risk register | Risk governance and risk limits | CRO |
| Board packs & minutes | Evidence of oversight and decision-making | Board Secretary |
| Remuneration policy & approval records | Alignment of incentives with risk | Remuneration Committee |
| Whistleblowing policy & complaint logs | Reporting lines, protection and follow-up | Compliance / HR |
| Regulatory filings / supervisory correspondence | Evidence of disclosure and engagement | Regulatory Liaison / GC |
| Training records (board & senior exec) | Evidence of capability and continuous competence | HR / Compliance |
Sector-specific checklists accelerate assembly of this pack, see the Corporate Governance Compliance Checklist for UAE Insurance Companies for insurer-tailored evidence requirements.
Where the CBUAE prescribes a specific compliance date in the applicable rulebook clause, that date governs and must be honoured, always confirm the current deadline directly in the rulebook. Absent a fixed date, the timeline below reflects realistic durations for building corporate governance UAE compliance from a partial baseline. Institutions with major gaps should plan for a six-to-nine-month programme; those requiring only targeted remediation can often complete within three months.
| Step | Lead (who) | Typical duration |
|---|---|---|
| Governance diagnostic & gap analysis | Head of Compliance / GC | 4–6 weeks |
| Draft remediation plan & board approval | GC / CEO / Board Secretary | 2–4 weeks |
| Update board charter & TORs; appoint committee members | Board / Nomination Committee | 3–6 weeks |
| Revise core policies (conflicts, RPT, whistleblowing) | Compliance / Legal | 4–8 weeks |
| Strengthen internal controls & IA plan | CRO / Head of Internal Audit | 6–12 weeks |
| Training & culture change programme | HR / Compliance | Ongoing (2–4 weeks initial intensive) |
| Testing, assurance & regulator engagement | Internal Audit / Compliance | 4–8 weeks |
| Final sign-off & documentation pack | Board Secretary / GC | 1–2 weeks |
Several workstreams can run in parallel, policy drafting can proceed while controls testing is designed, which is how disciplined programmes compress an apparent nine-month total into a shorter elapsed period. Sequencing board charter approval early is critical, because it unblocks committee appointments and downstream policy adoption.
Budgeting for a corporate governance UAE compliance programme means balancing internal redeployment against external specialist support. The table gives high-level, indicative cost buckets only; actual figures vary significantly with institution size, the scale of gaps, and how much drafting and controls testing is outsourced. Obtain current quotes from advisers before budgeting.
| Item | Indicative cost driver | Notes |
|---|---|---|
| Internal staff time (project management) | Internal budget | Estimate 0.5–2 FTE for 3–6 months |
| External legal advice | Scope-dependent | Depends on scope and bespoke drafting |
| Consultancy (controls / risk assessment) | Scope-dependent | Control testing and internal audit uplift |
| Training workshops (board & exec) | Per session | Varies with attendee numbers |
| IT / compliance tooling | Scale-dependent | Disclosure, control testing, RPT monitoring |
| Filing / regulatory fees | As per regulator’s current schedule | Usually administrative |
Recent revisions and supervisory practice within the corporate governance UAE framework have tightened several areas that were previously treated more as guidance. Institutions should read the precise current clauses in the CBUAE rulebook, but the direction of travel is consistent and demands a documented response.
The practical implications are immediate: charters and TORs need reviewing against the current rulebook, remediation timetables should be realistic, and every governance action should leave an auditable evidence trail. Supervisory inspections increasingly probe the operation of governance, testing whether committees genuinely challenge management, rather than merely confirming that documents exist. The likely practical effect is that institutions relying on paper compliance will be exposed, while those that can demonstrate active oversight will fare better.
Corporate governance UAE compliance for banks and insurers rewards institutions that treat governance as an operating discipline rather than a documentation exercise. Follow the seven-step programme, assign clear accountability through the roles matrix, assemble the required-documents pack, and align the timeline to any CBUAE-mandated deadlines. Recent supervisory direction raises the bar on independence, reporting, RPT oversight and internal audit, so build an auditable evidence trail into every action from the outset. For a compliance review of your framework, contact a UAE corporate lawyer through the Find a UAE corporate lawyer, GLE directory (filtered: UAE, Corporate), and explore the supporting templates for board charters, committee TORs and controls updates linked throughout this guide.
This article is for general guidance only; obtain tailored legal advice and check the current CBUAE rulebook before implementing changes.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Mohammed Haitham A. Salman at Middle East Alliance Legal Consultancy (ME-Alliance), a member of the Global Law Experts network.
posted 17 minutes ago
posted 25 minutes ago
posted 40 minutes ago
posted 47 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message