What we do
01  Advanced Infrastructure 02  Applied AI & Data 03  AI Cybersecurity 04  AI Assurance
Engagements
AI estate inventory Assurance review
Industries
Financial Services Government & Public Sector Energy & Utilities Telecommunications Healthcare & Life Sciences Transport & Logistics Industrial & Manufacturing Retail, Hospitality & Real Estate
Research
The Trust Maturity Model The GCC Assurance Index Readiness self-assessment Case studies Perspectives Sector briefings Technology evaluations
Company
About us Partners Events Careers Contact العربية Talk to our team
Industry

Prove Your Controls Before the Regulator Asks.

Since 11 February 2026 the CBUAE holds your board accountable for every AI system in the bank. Does your framework know about the model your collections team switched on last quarter?

01

What is Already Due

Each one below is dated, named, and set by someone other than us. Read them against what you could show this week, not what you plan to build.

DateRegulatorObligationWhat you must show
In forceCBUAE Fraud-liability transfer for entities retaining OTP-based authentication (since July 2025)Migration off OTP; 24/7/365 fraud monitoring with device, location and behaviour analysis
27 Nov 2025UAE Cyber Security Council National Encryption Policy approvedFormally approved post-quantum transition plans; automated cryptographic inventory; crypto-agility
During 2026UAE Mandatory submission of PQC migration plansA migration plan resting on an inventory you can defend
1 Jan 2026DIFC Commissioner of Data Protection Regulation 10 in full enforcementDocumented pre-processing risk assessments, transparency notices, human-oversight design, and either certification or a named Autonomous Systems Officer
11 Feb 2026CBUAE Guidance Note on Consumer Protection and Responsible AI AdoptionBoard and senior-management accountability for every AI system deployed; human oversight of high-impact decisions
Sep 2025UAE Central Bank Decree-Law No. 6 (2025) extends oversight to fintech and crypto firmsStatutory fraud-prevention capability, prompt breach reporting; criminal liability attaches to management negligence
Jul 2025DIFC Data Protection Amendment No. 1Private right of action including for distress; processors carry direct liability
From 2026KSA — NCA NCNICC-1:2025 brings private-sector entities into mandatory scopeGovernance, audit, third-party and cloud-provider controls
2024KSA — SAMA Cyber Security Framework and e-KYC frameworkBiometric identity proofing for licensed digital banks and payment service providers
2027SWIFT SwiftNet 8.0 expected to be PQC-enabledParticipant migration inside a 15-month window
2028CBUAE PQC readiness expectation for banksMigration executed on critical systems
02

Three Changes for Banks

I

The Board is Now the Accountable Party.

The CBUAE guidance names board and senior management for every AI system deployed, with no exemption for third-party systems. Look at your last board pack: does it list the models running in the bank, or does it describe the governance framework that is supposed to cover them?

II

The Liability Has Already Moved.

Since July 2025 the fraud liability for entities retaining OTP authentication sits with the entity. That is not a deadline to plan for. Count the months since, and that is how long the exposure has been on your balance sheet.

III

The 2027 SWIFT Date Does Not Move.

SwiftNet 8.0 is expected to be PQC-enabled in 2027, opening a fifteen-month migration window. Before any of that is plannable you need to know what cryptography you actually run. Does anyone in the bank hold that list today?

03

The Assessments

Fixed fee, fixed duration, delivered remotely. We publish the bands so you know before you call whether this is your size of problem.

AssessmentDurationIndicative feeWhat you receive
Cryptographic discovery & inventory4–6 weeks USD 40–90K A risk-ranked inventory of your cryptographic estate and a migration-plan skeleton: where the keys are, what algorithms sit under the payment and messaging rails, and what must move before the SWIFT window opens
AI governance gap assessment6 weeks USD 35–75K A gap report against ISO/IEC 42001 and the CBUAE guidance, with a remediation roadmap your board committee can act on
DIFC AI readiness review3–4 weeks USD 20–40K Regulation 10 readiness: system inventory, risk-assessment documentation, transparency and human-oversight design, and the evidence pack behind them
Identity & fraud control review4 weeks USD 25–50K Control and documentation gap analysis across authentication and onboarding, mapped to the CBUAE circular and PAD-level expectations
Annual assurance retainer12 months USD 60–150K Recurring review and regulatory-change monitoring, so the evidence stays current between audits
04

Common Questions

Who is accountable for AI systems deployed in a UAE bank?

The board and senior management, under the CBUAE Guidance Note of 11 February 2026, with no exemption for third-party systems.

What is the deadline for post-quantum cryptography in UAE banking?

Migration-plan submission is mandatory during 2026, SwiftNet 8.0 is expected to be PQC-enabled in 2027, and the CBUAE has signalled a 2028 readiness expectation.

Does the CBUAE fraud-liability transfer apply to us?

If your institution still relies on OTP-based authentication, yes — the liability has sat with the entity since July 2025.

What is DIFC Regulation 10?

The rule governing personal data processed through autonomous systems in the DIFC, in full enforcement since 1 January 2026.

Can you assess a single business line rather than the whole bank?

Yes, and we recommend it — one business line assessed properly is worth more than an estate covered shallowly.

05

One Method, Different Evidence

Start here

Start With the Evidence.

A fixed-scope assurance review of your AI estate — inventory, control mapping against the frameworks that apply to you, and a written evidence package your board and your regulator can read. Defined price, defined duration, no obligation beyond it.


The people who bring us in are usually the ones who saw it coming.