← Insights

Banking Technology in UAE: Core Banking and Digital Transformation

The Central Bank's requirements reach the platform, the cloud vendor and the boardroom

What Circular No. 32 of 2016 requires of a core banking system, how the Personal Data Protection Law shapes its design, and what Circular No. 18/2019 requires of cloud outsourcing. Then the cybersecurity duties under Circular No. 24/2019, the penalties for failing them, the governance duties placed on the board, and the questions fintech and blockchain leave open.

Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant

A bank changing its core banking platform is not only buying software. It is taking on duties the Central Bank has already written down: how transactions are processed, where customer data sits, who may reach it, and what happens when the system stops. Those duties sit on the bank, whoever builds or hosts the system.

What Circular No. 32 of 2016 asks of a core banking platform

Core banking systems process transactions, manage accounts and keep banking operations running in real time. The Central Bank's framework mandates that banks run systems meeting rigorous security, data integrity and operational continuity standards. Circular No. 32 of 2016 gives detailed guidelines on how such a system is implemented.

Banks must ensure their platforms support real-time processing and data accuracy, so that reconciliation and reporting can be done quickly. Failure to meet these requirements can expose a bank to regulatory sanctions, reputational damage and legal liabilities stemming from operational failures or data breaches.

The same framework mandates segregation of duties and rigorous internal controls against fraud or internal manipulation. Banks are required to build audit trails and access controls that hold up against attempts to compromise data integrity. Where those controls are missing, an internal fraud can bring a regulatory investigation, administrative penalties, mandatory remediation orders, and civil claims from customers for breach of data protection laws.

Where the Personal Data Protection Law meets system design

The Central Bank's interest in these systems rests on data protection, operational risk management and consumer rights. Banks must comply with the UAE's Personal Data Protection Law (PDPL) when they handle customer information inside a core banking system. That means data minimisation, purpose limitation and consent mechanisms written into the design of the system.

Continuity plans, and the liability clause with the vendor

The Central Bank requires vendors and banks to maintain safeguards, including disaster recovery and business continuity plans. Those plans must be legally documented and regularly tested, so the bank stays operational through a systemic shock or an attack.

The contract carries part of the same work. Banks must agree clear liability clauses with their technology providers to address potential breaches or failures.

Outsourcing to the cloud under Circular No. 18/2019

The Central Bank's Regulatory Framework for Outsourcing Activities, Circular No. 18/2019, governs the outsourcing of critical banking functions, including cloud services. It requires banks to structure outsourcing arrangements that maintain full control over the outsourced functions, and to ensure service providers comply with applicable laws and security standards.

A bank moving a core banking system to the cloud must conduct due diligence on the vendor, ensuring data residency within the UAE or in jurisdictions with equivalent legal protections. The framework puts weight on what the contract says: service-level agreements, data confidentiality clauses, and the right to audit the cloud service provider.

Outsourcing arrangements must also deal with contingency plans and exit strategies. Circular No. 18/2019 requires banks to ensure that outsourcing does not undermine operational resilience or continuity. That translates into an obligation to write contracts specifying termination rights, transition services and data retrieval procedures.

Which data may sit outside the bank, and where

Banks must also set data classification policies to decide which categories of data may be stored or processed on cloud infrastructure. Sensitive customer data, for instance, often requires enhanced encryption and access controls under both Central Bank regulations and the PDPL. Jurisdictional challenges may arise where a provider runs data centres outside the UAE, which makes detailed contractual safeguards and compliance audits necessary.

On a live migration that work shows up in recognisable places. The service-level agreement carries uptime commitments, data encryption standards and audit rights. A further term stipulates that all customer data must reside within the UAE to comply with data residency rules. An oversight committee then monitors the vendor's performance and compliance.

Circular No. 24/2019 and the duty to report an incident

Cyber threats aimed at financial institutions keep cybersecurity near the top of the Central Bank's requirements. Circular No. 24/2019 on cybersecurity sets out mandatory requirements for banks to put frameworks in place that build resilience and protect sensitive customer data. Banks must implement multi-layered security controls, including encryption, intrusion detection systems and incident response plans.

Reporting is an obligation in its own right. Banks are under strict obligations to report cyber incidents promptly to the Central Bank and to cooperate with investigations. After a ransomware attack, that means activating the incident response plan, notifying the Central Bank within the stipulated timeframe, and having counsel work with security experts to contain the breach, preserve evidence and communicate transparently with affected customers. Controls and staff training paid for before the attack are what mitigates the regulatory penalties and the reputational damage after it.

What failing those requirements can cost

Failure to comply with the cybersecurity mandates can result in severe penalties, including fines, licence revocation and potential criminal liabilities for negligent management. Separately, the UAE's Cybercrime Law criminalises unauthorised access, data breaches and cyber fraud. Regulatory and criminal law interact here, and a bank's cybersecurity strategy has to answer to both.

Who answers for a technology project

The Central Bank's guidelines place direct legal responsibilities for technology governance on board members and senior management. They must ensure that banking technology initiatives comply with applicable laws and internal policies. A failure in those duties can result in administrative actions or personal liabilities, particularly where negligence leads to material breaches or financial loss.

Banks are required to establish dedicated committees to oversee technology risks, and those committees must hold the expertise the work needs. On a project such as a mobile banking expansion, that means legal, compliance and IT people assessing each new feature from legal and operational angles before it goes live.

Cybersecurity governance belongs in the same structure, with board-level oversight and continuous risk assessments. The regulations also require training programmes to build staff awareness and reduce vulnerabilities arising from human error. Continuous penetration testing and vulnerability assessments are legally recommended, to identify emerging threats.

Governance must also answer to rapid technological change and evolving regulatory requirements. That means anticipatory scenario planning, compliance audits and continuous monitoring, with periodic review and updating of policies on emerging technologies such as blockchain and artificial intelligence.

The questions the rules have not answered yet

The legal framework governing banking technology in the UAE is evolving rapidly to accommodate digital transformation while maintaining systemic stability. The hardest questions concern emerging technologies such as blockchain, artificial intelligence and open banking APIs.

The UAE government is actively developing regulations tailored to fintech and digital banking, including frameworks for digital identity, smart contracts and regulatory sandboxes. Banks will need new compliance models to meet them.

Cross-border data flows and international regulatory coordination are becoming more important at the same time. Contractual and governance arrangements have to address jurisdictional conflicts, data privacy laws and international cybersecurity standards, across several legal regimes at once.

Blockchain shows the gap most clearly. A bank looking at blockchain for transaction processing faces uncertainty about the legal recognition of smart contracts and about data immutability. Our advice is to build compliance controls into such a project from the start, including auditability and dispute resolution clauses.

We advise banks on these questions through our banking disputes team, alongside our corporate and business law, contract drafting and arbitration practices.

This article is for informational purposes only and does not constitute legal advice.

Additional Resources

Explore more of our insights on related topics:

Call Us NowChat With Our Team On WhatsApp