Security & compliance · United Arab Emirates

Edrak and the Central Bank of the UAE

The CBUAE sets what licensed financial institutions must do about technology risk, outsourcing and consumer protection. Edrak is built for those conversations: your permissions, your data location, a full record, and contracts written for regulated outsourcing.

CBUAE
Financial regulator. Sets technology risk, outsourcing and consumer protection requirements for licensed institutions.
Applies to
Banks, insurers, finance companies and payment providers licensed by the CBUAE. Sector-specific requirements.
Where Edrak stands
Edrak supports licensed institutions as a technology provider. We map our controls to the CBUAE's technology risk and outsourcing regulations and structure contracts to fit them. The CBUAE does not certify vendors.

The CBUAE regulations

Four instruments shape what a licensed institution needs from a technology provider. They bind the licensed institution.

  • Outsourcing

    Outsourcing Regulation and Standards

    Materiality, due diligence, contract terms, data location and regulator notification.

  • Tech risk

    Information Assurance and Technology Risk

    Cybersecurity governance, controls and incident reporting for licensed institutions.

  • Consumer

    Consumer Protection Regulation

    Fair treatment, disclosure and complaint handling, including for automated decisions.

  • Open finance

    Open Finance and Digital Payments

    Data-sharing, API and security requirements for digital financial services.

How Edrak supports your CBUAE obligations

The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.

  • Outsourcing and materiality

    Edrak: Contract terms, exit and data-return provisions, and audit rights are written to fit financial-sector outsourcing rules.

    You: Materiality assessment and any regulator notification or approval.

  • Identity and access

    Edrak: Signs in through your identity provider and inherits the permissions people already hold. It cannot see data a user could not see.

    You: Identities, roles, and joiner, mover and leaver processes.

  • Data location

    Edrak: Runs in Edrak Cloud in your chosen region, in your own cloud account, or on-premises. Your data is used for your business only.

    You: Choosing the deployment that meets CBUAE data-location expectations.

  • Records

    Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.

    You: Retention aligned to CBUAE requirements and audit access.

  • Resilience

    Edrak: Defined availability targets, tested recovery, and workflows that pause safely when something goes wrong.

    You: Business-continuity plans and recovery objectives.

  • Incidents

    Edrak: A named security contact, notification commitments and support for your investigation, agreed in contract.

    You: Incident handling and CBUAE notification.

For your security and compliance teams

We share a requirement-by-requirement mapping to the CBUAE frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.

Talk to our team

The CBUAE issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Requirements apply to institutions licensed by the regulator. Edrak supports your obligations as a technology provider to a regulated institution. Confirm applicability with your compliance team.