CBUAE Outsourcing Regulation: An AI Vendor Due-Diligence Checklist
The CBUAE Outsourcing Regulation governs how a licensed financial institution in the UAE hands work to a third party, including AI vendors. It requires board-approved policy, risk assessment, contractual safeguards, audit and exit rights, and continued CBUAE oversight of any material arrangement. This checklist turns those duties into questions you can ask before signing.
- Primary supervisor: The Central Bank of the UAE (CBUAE), which retains oversight of outsourced functions even after they leave the bank. Source: CBUAE Rulebook.
- Newer overlay: CBUAE issued AI/ML guidance for licensed financial institutions in February 2026, covering governance, explainability, human oversight and third-party AI risk. Source: CBUAE Rulebook.
- Data law in scope: The UAE Personal Data Protection Law, Federal Decree-Law 45/2021, applies wherever the vendor processes personal data.
- Free-zone parallel: Institutions in the DIFC (DFSA) and ADGM (FSRA) sit under their own outsourcing and data regimes, not the federal CBUAE Rulebook.
- Accountability rule: Responsibility cannot be outsourced. The board and senior management remain answerable for an outsourced AI service.
The UAE context for outsourcing AI
The UAE's banking sector runs on a mix of large local groups such as Emirates NBD, FAB and ADCB alongside digital challengers and a fast-growing fintech layer, and almost every one of them now buys AI capability rather than building it in-house. Because the customer base is an expat majority served in Arabic and English, and because salary-transfer lending, WPS payroll data and Emirates ID checks all touch sensitive personal data, an AI vendor in the UAE is rarely a peripheral supplier. It is often processing exactly the information the CBUAE and the UAE Personal Data Protection Law care about most, which is why due diligence has to be treated as a regulated activity, not a procurement formality.
What is the CBUAE Outsourcing Regulation?
The CBUAE Outsourcing Regulation is the Central Bank's framework for when and how a licensed financial institution may delegate a business function, process or service to an external provider. Its core principle is simple: a bank may outsource the activity, but it can never outsource the accountability. Senior management stays responsible for the outsourced service, the customers affected by it, and the institution's compliance with all applicable UAE law.
In practice the regulation expects a documented outsourcing policy approved at board level, a risk assessment before each arrangement, written contracts that preserve the bank's rights, and ongoing monitoring of the provider's performance and financial health. Crucially, it preserves the CBUAE's own right of access, so the supervisor can examine an outsourced function as if it were still inside the bank.
Why do AI vendors count as outsourcing?
Many teams assume "we just bought a tool" sits outside the regulation. It usually does not. When an AI vendor scores credit, screens transactions, transcribes and analyses calls, or extracts data from an Emirates ID or trade licence, the vendor is performing a function that would otherwise be done inside the bank, on the bank's data. That is outsourcing.
The February 2026 CBUAE AI/ML guidance sharpens this point. It asks licensed institutions to manage third-party AI risk specifically, including model explainability, human oversight of automated decisions, and clarity over who is accountable when a model is wrong. So an AI vendor is assessed twice over: once under the general Outsourcing Regulation, and once under the AI-specific expectations. A due-diligence checklist has to answer both.
What is "material" outsourcing, and why does it matter?
The regulation draws a line between routine outsourcing and material outsourcing — arrangements whose failure would seriously disrupt the bank's operations, breach the law, or harm customers. Material arrangements attract heavier obligations: closer board attention, stricter contracts, and in defined cases prior notification to or engagement with the CBUAE.
Most AI that touches lending decisions, financial-crime screening, or large volumes of personal data will read as material. The practical test is not the size of the invoice; it is the consequence of the vendor failing, leaking data, or producing a decision the bank cannot explain. Classify the arrangement first, because everything else in the checklist scales with materiality.
The AI vendor due-diligence checklist
Use the table below as a structured pre-signing review. Each row maps a CBUAE expectation to a concrete question and the evidence you should collect and file.
Area | Question to ask the vendor | Evidence to obtain |
|---|---|---|
Materiality | Would this service's failure disrupt operations, breach law, or harm customers? | Written materiality assessment, board sign-off |
Accountability | Who is answerable when the model is wrong — and does that leave us accountable to the CBUAE? | Contract clause preserving the bank's responsibility |
Data & PDPL | Where is data processed and stored, and how do you meet Federal Decree-Law 45/2021? | Data-flow diagram, processing agreement, residency terms |
Explainability | Can each automated decision be explained to a customer and a supervisor? | Model documentation, decision-logic summary |
Human oversight | Where does a human review or override the AI's output? | Documented human-in-the-loop controls |
Audit & access | Can we and the CBUAE audit the service and its models? | Audit-rights clause, right-of-access clause |
Sub-outsourcing | Do you rely on further sub-processors, and are they disclosed and controlled? | Sub-processor register, approval rights |
Business continuity | What happens to service and data if you fail or we exit? | Continuity plan, exit and data-return clause |
Financial crime | How does the tool support obligations under Federal Decree-Law 20/2018 and goAML? | Screening logic, reporting integration notes |
Standards | Do you hold recognised AI governance certification? | ISO/IEC 42001 or equivalent certificate |
Two areas deserve extra weight in the UAE. First, data residency and the UAE Personal Data Protection Law: confirm where personal data physically sits and how cross-border transfer is handled, because customer data here frequently includes Emirates ID and salary details. Second, the exit and continuity clause: a material AI arrangement must have a written path to bring the function back in-house or move it, with data returned in a usable form, so that a vendor's failure never becomes the bank's outage.
How does the free-zone position differ?
If your entity is licensed in the DIFC or ADGM rather than onshore, the CBUAE Outsourcing Regulation is not your primary rulebook. DIFC firms answer to the DFSA and to DIFC Data Protection Law — whose Article 10 speaks directly to autonomous and AI-assisted decision-making — while ADGM firms answer to the FSRA and ADGM's data regime. The due-diligence logic is the same: assess materiality, preserve audit and exit rights, and control third-party AI risk. Only the named authority and the specific rule references change. Confirm your licensing jurisdiction before you map obligations.
How AI helps
Assessing AI vendors is easier when your own AI stack is already built for this scrutiny. The YuVerse Suite is designed for UAE financial institutions with governance in mind — clear data handling, human-in-the-loop controls, explainable outputs, and documentation you can put in front of an internal auditor or the CBUAE. The practical outcome is a shorter, cleaner due-diligence cycle: instead of chasing a vendor for evidence after the fact, you start the relationship with the artefacts the Outsourcing Regulation and the February 2026 AI/ML guidance expect you to hold on file.
Frequently asked questions
Does the CBUAE Outsourcing Regulation apply to buying an AI SaaS tool? Usually yes, if the tool performs a function the bank would otherwise do on its own data — such as credit scoring, transaction screening or document extraction. That is outsourcing, regardless of how the contract is labelled.
What makes an AI outsourcing arrangement "material"? Materiality turns on consequence: whether the vendor's failure would seriously disrupt operations, breach UAE law, or harm customers. Most AI touching lending decisions, financial-crime screening or large volumes of personal data will be treated as material.
Can a bank outsource responsibility to the AI vendor? No. Under the CBUAE Outsourcing Regulation, the board and senior management remain accountable for the outsourced service. The contract can allocate work, but not regulatory responsibility.
How does the UAE Personal Data Protection Law affect AI vendor selection? Federal Decree-Law 45/2021 applies wherever the vendor processes personal data, so due diligence must confirm data residency, cross-border transfer controls and a proper processing agreement before signing.
Do DIFC and ADGM firms follow the same outsourcing rules? No. DIFC firms sit under the DFSA and DIFC Data Protection Law, and ADGM firms under the FSRA. The due-diligence approach is similar, but the governing authority and specific rules differ from the onshore CBUAE Rulebook.
Is ISO/IEC 42001 required for an AI vendor in the UAE? It is not a blanket legal requirement, but recognised AI governance certification such as ISO/IEC 42001 is strong supporting evidence of the controls the CBUAE's AI/ML guidance expects.
This is a general explainer, not legal advice. For jurisdiction-specific guidance, consult a UAE-qualified adviser and the current CBUAE Rulebook.
Explore more UAE banking and regulation explainers at the YuVerse UAE hub.
References
- CBUAE Outsourcing Regulation — CBUAE Rulebook: https://rulebook.centralbank.ae/
- CBUAE Guidance on the use of AI & ML by Licensed Financial Institutions (February 2026) — CBUAE Rulebook: https://rulebook.centralbank.ae/
- UAE Personal Data Protection Law, Federal Decree-Law 45/2021 — u.ae: https://u.ae/
- DIFC Data Protection Law No. 5 of 2020 (Article 10) — DIFC: https://www.difc.com/