Security & compliance · United Arab Emirates
Edrak and the Central Bank of the UAE
The CBUAE sets what licensed financial institutions must do about technology risk, outsourcing and consumer protection. Edrak is built for those conversations: your permissions, your data location, a full record, and contracts written for regulated outsourcing.
- CBUAE
- Financial regulator. Sets technology risk, outsourcing and consumer protection requirements for licensed institutions.
- Applies to
- Banks, insurers, finance companies and payment providers licensed by the CBUAE. Sector-specific requirements.
- Where Edrak stands
- Edrak supports licensed institutions as a technology provider. We map our controls to the CBUAE's technology risk and outsourcing regulations and structure contracts to fit them. The CBUAE does not certify vendors.
The CBUAE regulations
Four instruments shape what a licensed institution needs from a technology provider. They bind the licensed institution.
Outsourcing
Outsourcing Regulation and Standards
Materiality, due diligence, contract terms, data location and regulator notification.
Tech risk
Information Assurance and Technology Risk
Cybersecurity governance, controls and incident reporting for licensed institutions.
Consumer
Consumer Protection Regulation
Fair treatment, disclosure and complaint handling, including for automated decisions.
Open finance
Open Finance and Digital Payments
Data-sharing, API and security requirements for digital financial services.
How Edrak supports your CBUAE obligations
The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.
Outsourcing and materiality
Edrak: Contract terms, exit and data-return provisions, and audit rights are written to fit financial-sector outsourcing rules.
You: Materiality assessment and any regulator notification or approval.
Identity and access
Edrak: Signs in through your identity provider and inherits the permissions people already hold. It cannot see data a user could not see.
You: Identities, roles, and joiner, mover and leaver processes.
Data location
Edrak: Runs in Edrak Cloud in your chosen region, in your own cloud account, or on-premises. Your data is used for your business only.
You: Choosing the deployment that meets CBUAE data-location expectations.
Records
Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.
You: Retention aligned to CBUAE requirements and audit access.
Resilience
Edrak: Defined availability targets, tested recovery, and workflows that pause safely when something goes wrong.
You: Business-continuity plans and recovery objectives.
Incidents
Edrak: A named security contact, notification commitments and support for your investigation, agreed in contract.
You: Incident handling and CBUAE notification.
For your security and compliance teams
We share a requirement-by-requirement mapping to the CBUAE frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.
Talk to our teamThe CBUAE issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Requirements apply to institutions licensed by the regulator. Edrak supports your obligations as a technology provider to a regulated institution. Confirm applicability with your compliance team.

