← Insights

Banking Governance in UAE: Board and Risk Management Framework

Supervisors ask for the minutes, the limits and the audit findings. Governance is what those documents show.

What a UAE bank board is expected to have in place and be able to evidence: board and committee composition, real independence, directors' duties under Federal Decree-Law No. 32 of 2021, a risk appetite statement that binds decisions, the reporting lines for risk, audit and compliance, and outsourcing oversight.

Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant

Bank governance is assessed by what an institution can show, not by what it intends. When a supervisor examines governance, the request is for documents: the board and committee minutes, the risk appetite statement and the reports measuring performance against it, the terms of reference of each committee, the internal audit plan and the responses to its findings, the record of who was told what and when. A bank with sound instincts and thin records is in a weaker position than one with ordinary instincts and a complete file.

That is the practical frame for everything below. The Central Bank of the UAE sets the expectations through its corporate governance regulations and standards for banks, and the Commercial Companies Law, Federal Decree-Law No. 32 of 2021, which replaced Federal Law No. 2 of 2015, supplies the underlying duties owed by directors of a UAE company. The two operate together: company law says what a director owes and to whom, and the banking rules say what a bank's board must have in place to discharge it.

Related: Our corporate governance advisory team drafts board charters, committee terms of reference and delegated authority frameworks.

Composition, and what independence actually means

Board composition rules exist to make the board capable of disagreeing with management. The Central Bank's framework expects directors to hold the expertise the institution's business actually requires — credit, markets, risk, technology, financial crime.

Independence in this context is a factual test rather than a label. A director is not independent because the board minutes describe them that way. Recent employment with the bank, a material commercial relationship with it, a family connection to a significant shareholder or to senior management, and remuneration arrangements that link the director's income to the bank's short-term results all bear on the question. Banks should assess independence formally, in writing, at appointment and again each year, and record the assessment. Where a director's circumstances change, the assessment should change with it.

The pressure point in this market is concentrated ownership. Where a small group of shareholders holds a large proportion of the capital, the risk is not that they behave improperly but that related-party lending, procurement from connected businesses and appointments to senior roles pass through a board that has no one in the room whose position is genuinely separate from theirs. Independent directors are the answer to that, but only if the related-party process actually routes decisions to them, and only if the minutes show what they asked.

Directors' duties are owed personally

The Commercial Companies Law imposes duties of loyalty and care on directors and requires them to act in the company's interest rather than the interest of whoever nominated them. Conflicts must be disclosed and managed rather than assumed away. These are personal obligations, and they do not evaporate because a decision was taken collectively or because management recommended it.

Two practices follow. First, disclosure of interests should be a standing item with a maintained register, updated when circumstances change rather than once a year. Second, a director who disagrees should ensure the minutes record the disagreement and the reasons for it. Minutes that read as a series of unanimous approvals tell a supervisor either that the board never disagrees or that the minutes do not record what happened, and neither reading helps.

The Central Bank also has authority over who holds senior positions in a licensed institution. Fitness and propriety is therefore a continuing condition of the role, not a gate passed once at appointment.

Related: Our corporate law team advises on directors' duties, appointments and the company law side of bank governance.

A risk appetite statement that changes decisions

The Central Bank's risk management requirements expect a board-approved statement of the risks the institution is prepared to take and the limits within which it will take them, covering credit, market, liquidity, operational, conduct and financial crime risk. Writing the statement is not the hard part. Making it bind is.

A risk appetite statement is working when three things are true. Limits are expressed in figures that can be measured from the bank's own systems, not in adjectives. Breaches are reported to the board within a defined period, with an explanation and a remediation plan, rather than surfacing in a quarterly pack after they have been resolved. And the statement is visible in front-line decisions — in credit approval criteria, in product approval, in concentration limits by sector and counterparty — so that a business unit cannot approve something the board has said it does not want.

Stress testing and scenario analysis are where the statement is tested against something other than the current environment. The useful discipline is to run scenarios the bank finds uncomfortable rather than plausible-sounding ones it will survive, and to require management to say what it would actually do in each case — which facilities would be drawn, which assets sold, which capital actions taken. A scenario exercise that produces a number but no action plan has not told the board anything it can use.

Concentration deserves separate treatment. Exposure concentrated in one sector, one group of connected borrowers or one funding source is the risk that most often turns a manageable downturn into a capital event, and it is easy to lose sight of when each individual exposure is within limit.

Three functions, and the reporting lines that make them work

Risk management, internal audit and compliance are expected to be independent of the businesses they oversee. Independence here is mostly about reporting lines, budget and the ability to say something unwelcome without professional consequence.

Risk management should be led by a chief risk officer with direct access to the board risk committee and the ability to escalate without going through the chief executive. Where the risk function reports through the business it is supposed to challenge, its findings are moderated before the board sees them.

Internal audit reports to the audit committee. Its plan should be risk-based and approved by the committee rather than by management, and the committee should track the closure of findings. Overdue audit findings are one of the clearest early indicators available to a board: a growing list of unremediated issues says more about the control environment than any individual report.

Compliance covers regulatory obligations, conduct, financial crime and data. The compliance officer should report to the board or a board committee, and should be involved before products launch rather than asked to assess them afterwards.

All three functions need enough resource to do the work. A board that approves a control function's plan and then declines the headcount to deliver it has approved nothing.

Financial crime and data sit at board level

Anti-money laundering and counter-terrorist financing obligations arise under Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing and the regulations made under it, and they are supervised actively. Customer due diligence, beneficial ownership identification, sanctions screening, transaction monitoring and the reporting of suspicious transactions are operational processes, but the board's responsibility for them is direct: approving the framework, ensuring the money laundering reporting officer has the standing and independence to do the job, and receiving meaningful reporting rather than a count of alerts.

Data protection has moved into the same category. The DIFC and the ADGM each have their own data protection regimes. For a bank the practical questions are where customer data is stored and processed, which third parties can access it, what happens on a breach and who decides whether to notify. These belong in the board's oversight of operational risk, not solely in the technology function.

Tax governance is a newer addition. Corporate tax under Federal Decree-Law No. 47 of 2022 applies for financial years starting on or after 1 June 2023, at 0% on the portion of taxable income not exceeding the amount specified in a Cabinet decision and 9% above it, and VAT applies at 5% to taxable supplies. A bank's tax position and its filing obligations are matters the audit committee should be able to speak to.

Related: Our banking and finance practice advises institutions on regulatory obligations and on the disputes that follow from them.

Banks and branches in the DIFC and ADGM

The DIFC and the ADGM are common-law jurisdictions with their own courts and their own financial services regulators. An entity licensed in either is supervised there, under that jurisdiction's rulebook.

For a group with a mainland bank and a subsidiary or branch in one of the financial centres, the governance question is how the two fit together. Group policies have to be capable of meeting both sets of requirements, the local board or governing body needs real authority rather than a formal existence, and reporting to the parent must not undercut the local entity's own accountability to its regulator. Where a single individual holds senior roles in both, the potential for conflict should be addressed openly in the terms of appointment.

Outsourcing and third parties

Most of the operational risk in a modern bank sits with people the bank does not employ: core banking providers, cloud infrastructure, payment processors, outsourced collections, agents distributing products. Responsibility for an outsourced function is not outsourced with it.

The governance work is contractual and ongoing. Agreements should address service levels, audit and inspection rights for the bank and its regulator, data location and access, business continuity, breach notification and an exit plan that can actually be executed. Concentration matters here as well — several critical services with one provider is a single point of failure, however sound the provider. Our contract drafting team prepares and reviews outsourcing agreements against these requirements.

Where an outsourcing relationship fails, the dispute clause determines how quickly the bank can get relief, and disputes of this kind often suit arbitration for reasons of confidentiality and technical expertise. Our arbitration and dispute resolution team advises on those clauses and runs the proceedings.

What a board should be able to produce on request

  • A board charter and terms of reference for each committee, with the composition and independence requirements stated and met.
  • Minutes that record what was discussed, what was challenged and what was decided — not only the resolutions passed.
  • A current risk appetite statement, with limits expressed numerically and a report showing performance against each.
  • A delegated authority framework showing who may commit the bank to what, reconciled to the mandates actually held at the banks and systems concerned.
  • A register of directors' interests and a record of related-party transactions with evidence of how each was approved.
  • The internal audit plan, the findings, and the status of remediation with owners and dates.
  • An annual assessment of each director's independence and fitness, and a record of the board's own effectiveness review.
  • Evidence of training delivered to the board on financial crime, data protection and the institution's principal risks.

A board that can hand over that set without a scramble is, in practical terms, well governed. One that cannot will spend an examination explaining why the documents do not exist rather than discussing the substance of its decisions.

Related Services: Explore our Corporate Governance services for practical legal support in this area. To discuss a governance review of your institution, get in touch.

Disclaimer

This article is for informational purposes only and does not constitute legal advice. Readers should take advice on their own circumstances before acting on anything set out above.

Additional Resources

Explore more of our insights on related topics:

Call Us NowChat With Our Team On WhatsApp