United Arab Emirates - Financial Institutions Guidelines

Guidelines for Financial Institutions Adopting Enabling Technologies

Guidelines for Financial Institutions Adopting Enabling Technologies (joint UAE regulators)

United Arab Emirates

RAI-AE-NA-GFIAEXX-2021
Effective: 15 Nov 2021
In Force(In Force)As published at assets.adgm.com · checked 9 Sep 2026

United Arab Emirates - Financial Institutions Guidelines is In Force in United Arab Emirates as of 9 Sep 2026, according to assets.adgm.com.

GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

The Guidelines for Financial Institutions Adopting Enabling Technologies guides licensed UAE financial firms on governance and risk controls for AI and emerging tech. Issued in 2021 by CBUAE, SCA, DFSA, and FSRA, compliance is supervised by these authorities. The guideline is in force as of 15 November 2021.

Summary

The “Guidelines for Financial Institutions Adopting Enabling Technologies” were jointly issued by the Central Bank of the UAE (CBUAE), the Securities and Commodities Authority (SCA), the Dubai Financial Services Authority (DFSA) and the Financial Services Regulatory Authority (FSRA) of Abu Dhabi Global Market (ADGM) and published on 15 November 2021. The document provides a principles-based, cross-sectoral framework for institutions licensed and supervised by any of the four Supervisory Authorities that are using or intend to use key enabling technologies: Application Programming Interfaces (APIs), Cloud Computing, Biometrics, Big Data Analytics & Artificial Intelligence (AI), and Distributed Ledger Technology (DLT). The Guidelines are explicitly non-binding; they complement and are additional to binding laws, regulations and rules issued by each Supervisory Authority, which retain precedence over the Guidelines. The objectives are to promote safe and sound adoption of enabling technologies, to help institutions proactively manage technology-related risks, to limit systemic risks, and to encourage innovation in a manner that preserves financial stability and protects customers.

Core elements include: governance and oversight expectations (board and senior management accountability, documented governance frameworks and appropriate technical and business expertise); risk management and materiality assessments (institutions must assess materiality and risk profile of technology arrangements and calibrate controls accordingly); lifecycle practices for APIs and models (conception, development, publishing, operation, retirement) with requirements for versioning, audit logging and archival of datasets and model versions; model validation and testing (pre-launch validation, ongoing monitoring, performance metrics and retraining controls, and retention of records for a minimum of five years where applicable); data protection and privacy compliance (encryption, access control, secure channels, and alignment with applicable data protection laws); outsourcing and third-party management (due diligence, contractual terms that include access for supervisors, sub-contracting disclosure, transition and exit arrangements and continuity planning); cybersecurity and resilience (robust controls, incident detection and response, business continuity plans and exit/resolution planning for material arrangements); transparency and documentation (maintain design documentation, decision justifications, audit trails and consumer-facing disclosures where relevant); and supervisory engagement (institutions should engage the relevant Supervisory Authority for material arrangements and comply with any applicable approval or notification requirements).

The Guidelines also include technology-specific guidance covering APIs (design, security, lifecycle management), Cloud Computing (materiality, outsourcing, contractual expectations, exit planning, regulatory access), Biometrics (identity proofing, lifecycle management, false-acceptance/rejection monitoring), Big Data & AI (materiality assessments, governance, explainability/auditability and recordkeeping), and DLT (recordkeeping, on-chain/off-chain mapping, code/versioning and auditability).

While the Guidelines do not themselves create new enforcement powers, they make clear that compliance expectations sit alongside existing binding rules and supervisory powers; failure to meet supervisory expectations can lead to regulatory action under the applicable laws and rules of each Supervisory Authority. Institutions are expected to apply the Guidelines proportionately to the size, complexity and materiality of the activity. The joint issuance and public consultation process (launched 1 June 2021; finalized November 2021) reflect a coordinated UAE approach to enabling-technology risk management in the financial sector.

Full article

Read full text ↗

Overview

The joint "Guidelines for Financial Institutions adopting Enabling Technologies" were published on 15 November 2021 by the Central Bank of the UAE, the Securities and Commodities Authority (SCA), the Dubai Financial Services Authority (DFSA) and the ADGM Financial Services Regulatory Authority (FSRA). The document provides cross-sectoral, principles-based guidance for licensed financial institutions that deploy or plan to deploy enabling technologies such as APIs, Cloud, Biometrics, Big Data/AI and DLT. The Guidelines are non-binding and intended to complement applicable laws and binding rules issued by the Supervisory Authorities, while promoting safe and proportionate adoption of innovation to protect customers and financial stability. They apply to institutions licensed or supervised by any of the Supervisory Authorities and are expected to be applied proportionately according to the size, complexity and materiality of the activities.

Definitions

The Guidelines set out standardised definitions for core terms used throughout the text, including "Application Programming Interface (API)", "API lifecycle", "Artificial Intelligence (AI)", "Big Data Analytics", "Biometrics", "Cloud Computing", "Distributed Ledger Technology (DLT)", "Institution", "Customer", "Credential Service Provider", "Identity Lifecycle" and "Materiality". Materiality is central: Institutions must assess the criticality of a given enabling technology arrangement to determine the required level of controls, monitoring and, where appropriate, supervisory engagement. The document emphasises record-keeping, version control and auditability for material applications, and clarifies that the Guidelines sit alongside but do not override binding regulations issued by each Authority.

Governance and Institutional Framework

The Guidelines emphasise clear board-level and senior management accountability for enabling technologies. Institutions must establish an approved and documented governance framework covering roles, responsibilities, escalation, and decision-making. The Governing Body and Senior Management are expected to ensure appropriate expertise is available — including technical specialists (e.g., AI engineers, cloud architects) and domain experts (e.g., credit risk modellers) — and that staff are trained. The framework should include policies on model development and validation, procurement, vendor due diligence, outsourcing, data governance, information security, and business continuity. Institutions are required to maintain enterprise-wide registries of material applications, maintain design and version documentation, and ensure internal audit and compliance functions can effectively review enabling-technology use. For material Cloud Computing and outsourcing arrangements, institutions should engage the relevant Supervisory Authority early in the design process and comply with any approval/outsourcing rules applicable to their supervisor (see ADGM announcement).

Key Focus Areas

The Guidelines organise guidance into cross-cutting expectations and technology-specific sections. Key focus areas include: risk management (materiality assessments, KRI metrics, scenario analysis); safety, testing and validation (pre-launch validation, back-testing, calibration and periodic revalidation); transparency and documentation (audit trails, model cards, decision-justifications and customer disclosures where consumer impact is material); data protection and privacy (encryption, secure channels, anonymisation where appropriate and compliance with applicable personal data laws); cybersecurity and model security (secure design, access controls, monitoring and incident response); outsourcing and third-party risk (contractual clauses, access for supervisors, sub-contracting disclosure and exit/transition planning); and operational resilience (business continuity, recovery objectives and testing). For Big Data/AI, the Guidelines require auditable models, archival of datasets, versioning and a minimum recommended retention period for core model artifacts; for Biometrics they set out identity-proofing, lifecycle and false-acceptance/rejection monitoring requirements; for APIs they set lifecycle, security and performance management guidance; and for DLT they require comprehensive on-chain/off-chain mapping and recordkeeping to support audit and accounting requirements.

Implementation Framework

Institutions are expected to implement the Guidelines proportionately. Implementation steps include: (1) conducting an inventory and materiality review of enabling-technology applications; (2) establishing or updating governance, policy and procedures; (3) performing risk assessments (including KRI and performance indicators); (4) instituting testing and independent validation regimes for models and applications prior to deployment; (5) embedding continuous monitoring, logging and incident detection; (6) ensuring vendor due diligence and robust contractual protections (including supervisory access and exit clauses); and (7) maintaining documentation and records (design docs, version history, datasets, audit logs). Material Cloud Computing plans should be discussed with the relevant Supervisory Authority prior to implementation and may require formal approval under existing outsourcing rules. The Guidelines provide checklists and concrete examples to support institution-level implementation and supervisory engagement (see the full Guidelines PDF).

Monitoring and Evaluation

On-going monitoring and performance evaluation are central. Institutions must define key performance and risk indicators, implement audit logging and traceability, track model outcomes and drift, report security events, and periodically recalibrate models. Monitoring should detect degradation in accuracy, fairness or security and trigger remediation, retraining or retirement. Internal audit and independent validation functions are expected to periodically review governance, technical controls and vendor arrangements. Regulators retain the right to review and audit material arrangements; institutions should preserve evidence and records to support supervisory reviews and external audits. The Guidelines recommend retention of model artifacts, datasets and version history for a minimum of five years (or as required by the relevant Supervisory Authority).

Penalties, Liability, and Appeals

The Guidelines themselves are non-binding guidance; they do not create new sanctions. However, they explicitly sit alongside binding laws and regulations of the respective Supervisory Authorities. Non-compliance with binding regulatory requirements referenced in the Guidelines (e.g., outsourcing rules, data protection laws, prudential requirements) can lead to supervisory action under the applicable legal frameworks — including remediation directives, administrative fines, license sanctions, restrictions on activities, and other enforcement measures. Institutions are also reminded to document liability allocation in outsourcing contracts and maintain redress mechanisms for customers. Where institutions disagree with supervisory findings or decisions, existing appeals and dispute resolution routes under each Authority’s legal framework apply.

Relationship to Other Instruments

The Guidelines reference statutory bases and existing regulatory instruments: the CBUAE’s enabling powers under Decretal Federal Law No. (14) of 2018, the SCA under Federal Law No. (4) of 2000, the DFSA under DIFC Law No. (1) of 2004, and the FSRA under ADGM Law No. (4) of 2013. They are intended to complement — not replace — existing supervisory rules on outsourcing, AML/KYC, data protection and prudential supervision. The document encourages institutions to apply other relevant regulator-specific guidance (for example, DFSA rules on outsourcing and cloud, and ADGM/FSRA guidance on innovation/virtual assets) when implementing enabling technologies.

International Alignment

The Supervisory Authorities state that the Guidelines were developed with reference to international standards and industry best practice. They reflect global themes found in model-risk guidance (e.g., from the Basel Committee and other international bodies), international data protection principles and recognized cybersecurity practices. The cross-jurisdictional coordination also aligns UAE supervisory expectations across onshore and financial free-zone regulators to reduce fragmentation for firms operating across jurisdictions within the UAE.

Implementation Timeline

EventDate
Public consultation launched2021-06-01
Consultation close (deadline for comments)2021-06-30
Final Guidelines published2021-11-15
Supervisory engagement for material Cloud plans (ongoing)As required when implementing material arrangements

Sources and References

SourceType
Guidelines for Financial Institutions adopting Enabling Technologies (PDF)Primary Source
ADGM - Joint issuance announcementPrimary Source
DFSA - Consultation announcementPrimary Source
Central Bank of the UAE - Consultation noticePrimary Source
SCA - Consultation announcementPrimary Source

Requirements for a company

What an organisation has to do under United Arab Emirates - Financial Institutions Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

0

Nothing in this category.

Must not do

0

Nothing in this category.

Should do

7
  • Establish a documented governance framework covering roles, responsibilities, escalation, and decision-making for enabling technologies.UAE licensed financial institutions adopting enabling technologies
  • Maintain an enterprise-wide registry of material applications, along with detailed design and version documentation.UAE licensed financial institutions adopting enabling technologies
  • Engage the relevant supervisory authority early in the design process for material cloud computing and outsourcing plans.UAE licensed financial institutions adopting material cloud computing
  • Conduct pre-launch validation, back-testing, and periodic revalidation for AI models before and after deployment.UAE licensed financial institutions deploying AI models
  • Provide customer disclosures and decision justifications whenever enabling technology applications materially impact consumers.UAE licensed financial institutions deploying consumer-impacting technologies
  • Retain AI model artifacts, core datasets, and version history for at least five years.UAE licensed financial institutions using AI technologies
  • +1 more in the table below

Should not do

1
  • Do not deploy material enabling-technology models or applications without pre-launch testing and independent validation.UAE licensed financial institutions deploying enabling technologies

Who must do what

The obligations under United Arab Emirates - Financial Institutions Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1UAE licensed financial institutions adopting enabling technologiesEstablish a documented governance framework covering roles, responsibilities, escalation, and decision-making for enabling technologies.
“Institutions must establish an approved and documented governance framework covering roles, responsibilities, escalation, and decision-making.”
Before deploymentGovernance and Institutional FrameworkRecommended
2UAE licensed financial institutions adopting enabling technologiesMaintain an enterprise-wide registry of material applications, along with detailed design and version documentation.
“Institutions are required to maintain enterprise-wide registries of material applications, maintain design and version documentation”
OngoingGovernance and Institutional FrameworkRecommended
3UAE licensed financial institutions adopting material cloud computingEngage the relevant supervisory authority early in the design process for material cloud computing and outsourcing plans.
“institutions should engage the relevant Supervisory Authority early in the design process and comply with any approval/outsourcing rules”
Prior to implementationGovernance and Institutional FrameworkRecommended
4UAE licensed financial institutions deploying AI modelsConduct pre-launch validation, back-testing, and periodic revalidation for AI models before and after deployment.
“safety, testing and validation (pre-launch validation, back-testing, calibration and periodic revalidation)”
Prior to deployment and periodicallyKey Focus AreasRecommended
5UAE licensed financial institutions deploying consumer-impacting technologiesProvide customer disclosures and decision justifications whenever enabling technology applications materially impact consumers.
“transparency and documentation (audit trails, model cards, decision-justifications and customer disclosures where consumer impact is material)”
OngoingKey Focus AreasRecommended
6UAE licensed financial institutions using AI technologiesRetain AI model artifacts, core datasets, and version history for at least five years.
“The Guidelines recommend retention of model artifacts, datasets and version history for a minimum of five years”
Minimum 5 yearsMonitoring and EvaluationRecommended
7UAE licensed financial institutions deploying AI systemsImplement continuous monitoring to detect degradation in model accuracy, fairness, or security, and trigger retraining or retirement.
“Monitoring should detect degradation in accuracy, fairness or security and trigger remediation, retraining or retirement.”
OngoingMonitoring and EvaluationRecommended
8UAE licensed financial institutions deploying enabling technologiesDo not deploy material enabling-technology models or applications without pre-launch testing and independent validation.
“instituting testing and independent validation regimes for models and applications prior to deployment”
Prior to deploymentImplementation FrameworkRecommended

© Regulations.AI · updated on 20 Sep 2026 · reviewed against official sources on 9 Sep 2026 using Gemini 3.6 Flash