We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / UAE compliance

UAE compliance

CBUAE Cyber Rules for Fintechs and the Suppliers Who Serve Banks

CBUAE cybersecurity framework explained for a small fintech or bank supplier: which regulations reach you, why the bank's questionnaire exists, and what to fix.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

Ninety questions, fourteen days, one sponsoring bank

The founder of a 20-person payments startup in Dubai has a stored-value licence, a working app and a sponsoring bank that has just sent a supplier security questionnaire. Ninety questions. Fourteen days. The covering email says the bank's third-party risk team "requires completion before the next settlement cycle can be confirmed."

She opens the spreadsheet on a Sunday night. Question 7 asks for the date of the last independent penetration test and the report reference. Question 19 asks which staff hold privileged access to production and how that access is reviewed. Question 33 asks for the retention period of authentication logs. Question 58 asks for a copy of the incident response plan and evidence of the last exercise.

The CTO built the platform himself and can answer most of the technical questions from memory. The problem is the word "evidence." The pen test was done by a friend's company in 2024 and the report is a PDF somewhere in Slack. Privileged access is "the two of us and the DevOps contractor in Lahore." The logs go back as far as the free tier of the logging tool allows, which turns out to be seven days. The incident response plan is a Notion page with three bullet points.

Fourteen days is enough to answer ninety questions. It is not enough to make the answers true.

What the heck does this mean

The Central Bank of the UAE does not write to a 20-person fintech's suppliers. It writes to the licensed institution, and the institution passes the requirement down. That is why the questionnaire exists, and why it is not negotiable.

The rules arrive through several documents, and knowing the names helps when a bank quotes them at you.

Information Security Regulation: the Central Bank's baseline for how a licensed institution protects data and systems, including the systems its suppliers run.

Operational Risk Standard: the wider rulebook covering outsourcing, business continuity and third-party risk; your questionnaire comes from here.

Stored Value Facilities and Retail Payment Services: the licensing frameworks for wallets, payment providers and similar businesses, each with its own security expectations.

Open Finance framework: the rules for sharing customer-permissioned bank data and initiating payments through the Central Bank's platform.

Third-party risk: the bank's duty to know that the companies it relies on will not become the bank's breach.

Privileged access: accounts that can change production, see everything or delete logs; the ones the bank asks about first.

A supplier questionnaire is a bank showing its regulator that it checked. Your answers become part of the bank's evidence file, and a wrong answer is the bank's problem the day something goes wrong, which is why the bank will not accept "mostly."

The numbers that matter

CBUAE requirements reach a fintech through the Information Security Regulation, the Operational Risk Standard, the Stored Value Facilities framework, the Retail Payment Services framework and the Open Finance framework, issued between 2024 and 2026 by the Central Bank of the UAE. In February 2026 the Central Bank added guidance on the use of AI, so the questionnaire now asks about that too.

Banks and financial services were the target of 21% of regional cyber incidents, according to the State of the UAE Cybersecurity Report 2025. That is one incident in five aimed at the sector your customers sit in, which is why their risk teams have grown teeth.

Among leading fintechs, 41.8% of breaches originated with a third-party vendor, per SecurityScorecard's 2025 research. From the bank's chair, you are the third party.

What to do this week

  1. Build the supplier file the bank is really asking for: a list of every vendor and contractor that touches production, with contract, access level, and the security evidence they have given you. Include the DevOps contractor. (CIS 15 Service Provider Management)
  2. Name every privileged account in production, remove the ones that belong to people who have left or to shared logins, and put MFA on all of them. Write the review date on the calendar, quarterly. (CIS 6 Access Control Management)
  3. Fix log retention before the questionnaire is due. Move authentication, admin and transaction logs to storage that keeps at least twelve months, and record who reviews them. (CIS 8 Audit Log Management)
  4. Get a fresh independent penetration test scoped to the payment flows and the customer-facing app, and put the report in the evidence folder with a remediation tracker beside it. (CIS 18 Penetration Testing)
  5. Turn the Notion page into a one-page incident plan with names, numbers, the bank's notification contact and the order of calls, then run a 30-minute tabletop with the whole team and keep the notes. (CIS 15 Service Provider Management)

Where AccuSights fits

Our assessment maps your controls against the CBUAE frameworks your licence sits under and the bank's questionnaire, and gives you a ranked gap list with the evidence each answer needs. The read-only compliance agent then keeps the file honest between questionnaires: read-only insight into where the gaps are, so you prioritise and keep an eye on them. We have no access to your platform and we do not remediate; you or your IT partner fix, we show you where. A falcon does not chase everything that moves. It fixes on one target, and so should the next fourteen days.

Questions people ask

Does CBUAE regulate my company if a bank is my customer? Not directly, unless you hold a CBUAE licence yourself. What reaches you is the bank's own obligation: the Central Bank requires licensed institutions to manage the risk of their outsourcing and technology suppliers, so the bank passes the requirements down through contracts and questionnaires. In practice that means you are held to the standard even though the regulator never writes to you.

What is Al Tareq? Al Tareq is the name of the CBUAE's Open Finance platform, the trust framework and technical layer through which licensed participants share customer-permissioned data and initiate payments. If your product connects to bank accounts through it, you sit inside the Open Finance framework's security, consent and participant rules. Ask your sponsoring bank which of those rules flow to you before you build the integration.

Is PCI DSS required for a UAE fintech? If you store, process or transmit card data, yes, alongside the CBUAE rules. The Central Bank's frameworks govern your licence; PCI DSS v4 governs the card data itself and is applied through the card schemes and your acquiring bank. The cleanest answer for a small fintech is to keep card numbers out of your own systems entirely by using a tokenising processor, which shrinks the PCI scope to almost nothing.

The bank is not testing your patience. It is testing if you would survive being its problem. Answer the ninety questions as if you will be asked to prove each one, because you will.

Questions people ask

Does CBUAE regulate my company if a bank is my customer?

Not directly, unless you hold a CBUAE licence yourself. What reaches you is the bank's own obligation: the Central Bank requires licensed institutions to manage the risk of their outsourcing and technology suppliers, so the bank passes the requirements down through contracts and questionnaires. In practice that means you are held to the standard even though the regulator never writes to you.

What is Al Tareq?

Al Tareq is the name of the CBUAE's Open Finance platform, the trust framework and technical layer through which licensed participants share customer-permissioned data and initiate payments. If your product connects to bank accounts through it, you sit inside the Open Finance framework's security, consent and participant rules. Ask your sponsoring bank which of those rules flow to you before you build the integration.

Is PCI DSS required for a UAE fintech?

If you store, process or transmit card data, yes, alongside the CBUAE rules. The Central Bank's frameworks govern your licence; PCI DSS v4 governs the card data itself and is applied through the card schemes and your acquiring bank. The cleanest answer for a small fintech is to keep card numbers out of your own systems entirely by using a tokenising processor, which shrinks the PCI scope to almost nothing.

Controls this post maps to

CIS 15 Service Provider ManagementCIS 6 Access Control ManagementCIS 8 Audit Log Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.