CBUAE Open Finance Regulation, Explained
The CBUAE Open Finance Regulation is the Central Bank of the UAE's framework that lets consumers and businesses securely share their banking data and initiate payments through licensed third parties, with explicit consent. Operated via Al Etihad Payments, it standardises how banks in the UAE open access under supervision, replacing informal screen-scraping with governed, permissioned data.
- Regulator: Central Bank of the UAE (CBUAE), which authorises and supervises Open Finance participants. Source: CBUAE Rulebook.
- Operator: Al Etihad Payments (AEP), a CBUAE subsidiary that also runs Aani, Jaywan and UAEDDS. Source: AEP.
- Consent-based: access to accounts and payment initiation requires the customer's explicit, revocable consent.
- Two capabilities: data sharing (read access) and payment initiation (instructing a payment on the customer's behalf).
- Data protection: overlaps with the UAE PDPL (Federal Decree-Law 45/2021) and the CBUAE Consumer Protection Regulation.
What is Open Finance and why does the UAE need a regulation for it?
Open Finance lets a customer authorise a licensed third party to read their financial data or initiate a payment directly from their account, rather than handing over login credentials or relying on manual statements. In the UAE, this matters because the market is unusually intermediated: an expatriate majority moves between banks as jobs and salary-transfer arrangements change, small businesses juggle mainland and free-zone accounts, and Islamic and conventional products run on parallel tracks. Before a common standard, data moved through fragile screen-scraping or paper. The CBUAE Open Finance Regulation replaces that with a supervised, consent-driven layer so that a resident with an Emirates ID can share their banking data with a budgeting app, a lender or an insurer under clear rules, and revoke it at any time.
Who does the CBUAE Open Finance Regulation apply to?
The framework covers the institutions that hold data and those that want to use it. Banks and other licensed financial institutions in the UAE that hold customer accounts must expose their data and payment-initiation functions through standardised interfaces when a customer consents. Third-party providers that want to consume those interfaces must themselves be authorised. Because Al Etihad Payments operates the central Open Finance platform, participation runs through a single, supervised rail rather than a patchwork of bilateral bank-by-bank integrations.
Role | Who it is | What they do under Open Finance |
|---|---|---|
Regulator | CBUAE | Authorises participants, sets standards, supervises conduct |
Platform operator | Al Etihad Payments (AEP) | Runs the shared Open Finance infrastructure |
Data holder | Banks and licensed FIs (e.g. Emirates NBD, FAB, ADCB) | Expose account data and payment initiation on consent |
Third-party provider | Authorised fintechs and service providers | Consume data or initiate payments for the customer |
Customer | UAE residents and businesses | Grant, review and revoke consent |
Real fintechs such as Lean Technologies have built in the UAE's open-banking space, and the regulation is what moves that activity from ad hoc arrangements onto a licensed footing.
What are the two core capabilities: data sharing and payment initiation?
The regulation is best understood as two distinct services sitting on the same consent model.
Data sharing is read access. With the customer's permission, a third party can retrieve account information — balances, transactions, product details — to power services such as account aggregation, affordability checks or bookkeeping. This is the layer most relevant to lending: instead of a customer emailing PDF statements, a lender can pull verified transaction data directly, subject to consent.
Payment initiation is write access to movement of money. A third party can, on the customer's instruction, initiate a payment from the customer's account — for example to settle a bill or fund a wallet — without the customer re-entering card details. In the UAE this dovetails with Aani, the instant-payments service operated by Al Etihad Payments, so initiated payments can clear in real time.
Both capabilities are gated by the same principle: nothing happens without explicit, informed, revocable consent from the account holder.
How does consent work, and how does it sit with the UAE's data-protection rules?
Consent under Open Finance is specific and time-bound: the customer authorises a named party, for a defined purpose, for a defined period, and can withdraw it. This is deliberately aligned with the wider UAE regime. The UAE Personal Data Protection Law (Federal Decree-Law 45/2021) governs how personal data is processed across the country, while the CBUAE Consumer Protection Regulation and its Standards impose fair-treatment, disclosure and conduct duties on licensed institutions. Firms operating in the financial free zones face parallel obligations — for instance, DIFC's Data Protection Law No. 5 of 2020 addresses autonomous decision-making at Article 10.
For banks, the practical implication is that Open Finance is not only a technical integration but a governance exercise. Consent records must be auditable, purposes must be honoured, and revocation must actually stop data flowing. The CBUAE supervises this conduct, and its February 2026 guidance on the use of AI and machine learning by licensed financial institutions — which stresses explainability, human oversight and third-party AI risk — is directly relevant when Open Finance data feeds automated decisions.
What does Open Finance change for banks and consumers in the UAE?
For consumers and businesses, the change is control and portability. A resident can let a personal-finance app read across multiple banks in one place; a small business on a free-zone licence can share its transaction history with a lender to support a credit application; and switching providers becomes less painful when data can move on request. For banks, the regulation reframes proprietary data as a shared, consented asset and raises the bar on interface reliability, security and consent handling.
Before Open Finance | Under the CBUAE Open Finance Regulation |
|---|---|
Screen-scraping or shared credentials | Standardised, supervised interfaces |
Manual PDF statements for lending | Consented, verified data pulled directly |
Bilateral, bank-by-bank integrations | Central rail via Al Etihad Payments |
Unclear consent and revocation | Explicit, time-bound, revocable consent |
None of this displaces existing prudential rules. Affordability still runs against the Debt Burden Ratio — monthly debt repayments capped at 50% of gross monthly income — and lenders continue to reference the AECB credit report and AECB score (which ranges 300–900). Open Finance simply changes how the underlying data reaches the decision, not the thresholds the decision must meet.
How AI helps
Open Finance produces a richer, consented stream of financial data — but data only creates value if an institution can ingest, verify and act on it responsibly. The YuVerse Suite brings together document AI, bank-statement analysis, credit assessment and conversational engagement so a bank in the UAE can turn consented Open Finance data into faster, more consistent decisions while keeping a human in the loop. Used well, that means an affordability or onboarding decision that would have waited on manual statement collection can be prepared in a single, auditable workflow — with explainability and oversight aligned to the CBUAE's expectations for AI in financial services.
Frequently asked questions
Is Open Finance the same as open banking in the UAE? Open banking generally refers to sharing bank-account data and payments; Open Finance is broader, extending the consent-based model across a wider set of financial products. The CBUAE framework is designed to scale beyond payments into that wider scope.
Who regulates Open Finance in the UAE? The Central Bank of the UAE (CBUAE) authorises and supervises participants, and Al Etihad Payments — a CBUAE subsidiary — operates the shared Open Finance platform.
Do I have to share my banking data? No. Data sharing and payment initiation only happen with your explicit consent, and you can review and revoke that consent. Nothing is shared automatically.
Does Open Finance replace the AECB credit report? No. The AECB credit report and AECB score (300–900) remain central to credit decisions. Open Finance can add consented transaction data alongside them, but it does not remove existing checks or the 50% Debt Burden Ratio cap.
How does Open Finance connect to instant payments like Aani? Payment initiation under Open Finance can instruct payments that clear through Aani, the instant-payments service operated by Al Etihad Payments, enabling real-time settlement on the customer's instruction.
Is my data protected? Processing is governed by the UAE Personal Data Protection Law (Federal Decree-Law 45/2021) and, for licensed institutions, the CBUAE Consumer Protection Regulation and Standards, with additional regimes such as DIFC's Data Protection Law for free-zone entities.
This is a general explainer, not legal advice. Verify the current requirements against the primary sources before acting.
Explore more UAE banking and regulation explainers on the YuVerse UAE hub.
References
- Central Bank of the UAE — CBUAE Rulebook: https://rulebook.centralbank.ae/
- CBUAE Rulebook — Consumer Protection Regulation: https://rulebook.centralbank.ae/en/rulebook/consumer-protection-regulation
- CBUAE Rulebook — Article (3) Important Ratios (Debt Burden Ratio): https://rulebook.centralbank.ae/en/rulebook/article-3-important-ratios
- Al Etihad Payments (AEP): https://aep.ae/en/
- Al Etihad Credit Bureau (AECB): https://aecb.gov.ae/en
- The UAE Government portal (UAE PDPL, Federal Decree-Law 45/2021): https://u.ae/