Operational Readiness for AI in UAE Banks and Insurers
The CBUAE's February 2026 Guidance Note connects responsible AI and machine learning to consumer protection, governance, fairness, transparency, data, human oversight, third parties and continuing monitoring. For a licensed financial institution, the practical task is to embed these principles into existing model, conduct, risk and operating arrangements.
The Guidance is centred on consumer outcomes
The Central Bank of the UAE issued its Guidance Note on the Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions in February 2026. Its scope includes licensed financial institutions and insurance providers, with particular attention to AI or machine learning that may affect consumers.
The Guidance addresses transparency, bias, ethics, accountability, explainability and data privacy. It should be read with relevant CBUAE regulations and standards, including the Model Management Standards and the earlier Guidelines for Financial Institutions adopting Enabling Technologies. The implementation question is therefore how AI fits into the institution's existing responsibilities, not how to create a separate policy that sits beside them.
Build an inventory around real uses and decisions
The Guidance calls for an inventory of AI models, systems or technologies with material metadata including name, purpose and risk rating. Third-party models belong in that view. A useful inventory should also identify the business owner, consumer process, decision affected, data, model or provider, operating status, human role, validation evidence, controls and monitoring.
The unit should be the use as well as the technology. One platform may assist internal research, communicate with customers and support a high-impact decision. Those uses can have different consequences and need different evidence. The inventory should connect each use to the institution's model, outsourcing, data, conduct and operational-risk records rather than create incompatible registers.
Make governance operational
The Guidance expects documented governance proportionate to the size, nature and complexity of the institution. Senior management and the Board are described as responsible and accountable for AI and ML systems and outcomes, with regular reporting on performance and risk. It also states that institutions should not employ AI models over which they have no control.
Governance therefore needs lifecycle decisions and evidence. The institution should specify who can propose a use, classify it, approve data and vendors, design the evaluation, accept residual risk, release the system, approve material changes, respond to incidents and cease operation. Control functions need the knowledge and information required to challenge, while the business remains accountable for the consumer and operating outcome.
Identify high-impact consumer decisions
The Guidance defines a high-impact decision as a determination using AI that materially affects a customer's access to financial products or services, with a loan application and insurance claim given as examples. Institutions should trace where AI informs, recommends or makes such decisions and what happens when the output is wrong or disputed.
Risk rating should consider data quality and sensitivity, system capability, controls, impact and dependence on AI or third parties. The result should determine the approval route, independent challenge, testing, disclosure, human authority and monitoring required. A broad model category or vendor assurance report cannot replace the use-specific assessment.
Test fairness in the population and process
The Guidance expects AI and ML not to produce discriminatory or manipulative outcomes and says training data should be sufficiently accurate, relevant and representative of the customer population to which the model is applied. It also addresses periodic testing, including when a model is upgraded, materially changed or newly introduced.
A fairness review should define the consumer outcome, relevant groups, decision thresholds, error costs and process surrounding the model. It should examine representation, performance differences, approval or service outcomes, overrides and downstream effects. An overall accuracy figure can conceal a material disparity. A statistical difference, however, still requires investigation of context, data, process and possible explanation before a remediation decision is made.
Design transparency for the consumer decision
The Guidance addresses transparency where consumers interact with AI and particularly for high-impact decisions. It calls for understandable, accurate plain-language disclosures in Arabic and English and says institutions should consider measures to check understandability. It also raises opt-out rights for consideration, especially for high-impact decisions, in light of risk, fairness and feasibility.
The institution needs more than a general notice that AI is used. It should determine what the customer needs to know at each stage, how the decision can be explained accurately, how questions or disputes are handled and whether a different route is available. The explanation must reflect the real system and decision. One technical feature-importance method is not a complete consumer explanation.
Connect data quality, privacy, security and resilience
The Guidance covers accurate, relevant and current data, provenance and audit trails, personal-data requirements, privacy and security by design, stress testing, validation, contingency planning and incident response. These concerns meet in the workflow. Data may be suitable for one purpose but not another, and a technically accurate model can still create consumer harm through unsuitable access, stale information or a failed hand-off.
The review should map data from collection and transformation through model use, output, action and retention. Qualified privacy, cybersecurity, legal and regulatory specialists should address their respective requirements. Model evaluation should use operating scenarios, including degraded inputs, unavailable services, attempted misuse and the fallback route.
Make human oversight meaningful
The Guidance distinguishes human-in-the-loop, human-on-the-loop and human-out-of-the-loop arrangements. It says the level of involvement should be commensurate with consumer risk and describes human-out-of-the-loop use as appropriate only for low-risk, non-material processes with controls.
The institution should test whether the person has time, information, competence, authority and a usable path to challenge or stop the output. An approval click does not create effective oversight when staff cannot understand the basis, are penalised for overriding or receive the case too late. Overrides, disagreements, escalations and consumer appeals should be recorded as operating evidence.
Control providers and automatic change
The Guidance retains institutional responsibility for outsourced AI. It addresses provider due diligence, access to relevant information, audit rights, data protection, cybersecurity, performance, termination, pre-deployment checks and third-party models in the inventory. It also expects institutions to understand and test automatic updates before implementation.
Procurement should establish the evidence needed throughout operation, not only at selection. Contracts and technical arrangements need to support notification of material changes, version visibility, evaluation, incident investigation, data and log access, concentration management and exit. A provider's general certification or benchmark does not establish fitness for the institution's consumer use.
Monitor outcomes and retain the ability to stop
The Guidance calls for continuing monitoring of reliability, relevance and consumer-protection outcomes, taking account of changes in data, markets and customer behaviour. It also addresses mechanisms to detect, report and remediate performance issues, bias and unintended consequences and the clear, immediate ability to cease use through human intervention.
Monitoring should connect technical behaviour to the customer and business process. Measures can include error types, subgroup outcomes, overrides, complaints, appeals, service completion, provider changes, drift, incidents and control failures. Thresholds should state who investigates, who can restrict or stop the system and what evidence is required before use resumes.
How Marketways supports an implementation review
Marketways can translate the Guidance into a use inventory, responsibility map, risk-classification method, control and evidence matrix, evaluation plan, monitoring design, vendor-review requirements and prioritised remediation programme. We connect the work to the institution's existing model-risk, consumer-protection, conduct, data, outsourcing, operational-risk and internal-assurance arrangements.
AI Governance and Model Risk provides the underlying service. AI Evaluation and Assurance tests system behaviour and controls for a defined use. AI Inventory and Shadow AI Audit helps establish coverage, while AI Impact Assessment and Risk Classification provides the general assessment method. Marketways does not provide legal or regulatory advice, certify compliance or replace the institution's authorised control functions and qualified advisers.
What to bring to the first discussion
Useful starting material includes AI and model inventories, consumer-process maps, materiality and risk-rating methods, governance and committee terms, validation and monitoring standards, provider contracts, data and privacy records, disclosures and explanations, human-review procedures, complaint and appeal data, incident records, internal audit findings and the institution's current interpretation of applicable CBUAE requirements.
Independence and scope
Marketways is an independent management, analytics and AI consultancy. It is not affiliated with, appointed by or representing the UAE Government, the Government of Dubai, the Dubai Centre for Artificial Intelligence or any regulator or public initiative mentioned on this page. This article interprets public sources for workflow, implementation, evaluation and governance planning. It is not legal advice, regulatory approval, certification or an official statement of policy. Readers should confirm current requirements with the responsible authority and obtain specialist advice where needed.
Official sources
References
- CBUAE Guidance Note on AI and ML
- CBUAE Governance and Accountability
- CBUAE Transparency, Data, Fairness and Security sections
- CBUAE Human Oversight and Consumer Protection
- CBUAE Continuous Monitoring and Review
- CBUAE Integration with Existing Frameworks
- CBUAE Model Management Standards, Model Governance
