Guide

Outsourcing AI at a UAE bank: what the CBUAE regulation requires in the contract

The Central Bank of the UAE’s Outsourcing Regulation for Banks (C 14/2021), in force since 15 July 2021 with its Outsourcing Standards, treats any agreement for another party to perform, on a continuing basis, an activity a bank does or could do itself as outsourcing, which covers most AI services a bank buys. Every arrangement goes on the bank’s outsourcing register, material or not, and a material one needs the Central Bank’s prior non-objection. Article 5 sets the contract: the bank and its customers keep full ownership of their data, the bank has unfettered access to it during the agreement and on termination, no other party gets access to Confidential Data without the bank’s specific authorisation, the contract states how far subcontracting is allowed, breaches are notified without undue delay, and the Central Bank can visit the provider and obtain information from it directly. Article 6 keeps the Master System of Record, including all Confidential Data, in the UAE, and customer Confidential Data leaves the country only with Central Bank approval and the customer’s prior written consent.

CBUAE Outsourcing Regulation for Banks. The Central Bank of the UAE’s Outsourcing Regulation for Banks (circular C 14/2021), effective 15 July 2021, with the accompanying Outsourcing Standards for Banks, which set how banks in the UAE assess, approve, contract, register, audit and report outsourcing arrangements.

Checked . The Outsourcing Regulation for Banks and the Outsourcing Standards for Banks (C 14/2021, both shown as in force), the Regulation’s Arabic page, the AI guidance note’s web text and section 4.7 of the Model Management Standards were read on rulebook.centralbank.ae on this date. The CBUAE revises its Rulebook, so check the current text before you rely on it. This page is not legal advice.

When an AI service is outsourcing, and why the answer is usually yes

The Central Bank of the UAE issued the Outsourcing Regulation for Banks as circular C 14/2021, in force since 15 July 2021, together with Outsourcing Standards that expand on it and that the Central Bank says it will enforce [1, 2]. The Arabic Rulebook lists it as نظام التعهيد للبنوك [3]. It applies to every bank operating in the UAE, on a solo and a group-wide basis, and agreements signed before it took effect had to comply by 31 December 2023 [1]. No AI contract a bank holds today sits outside it on age.

Outsourcing is defined as an agreement with another party, inside or outside the UAE and including a related party, “to perform on a continuing basis an activity which currently is, or could be, undertaken by the Bank itself” [1]. The words that matter for AI are “could be”. A vendor that extracts data from trade finance documents, screens names, answers customers in the app or drafts credit memos is doing work the bank could do with its own staff or its own systems. That is outsourcing, whether the vendor sells it as software, a platform or an API.

The harder case is a model called from the bank’s own application. A hosted model that processes the bank’s requests every day is, on my reading, performing an activity on a continuing basis that the bank could run itself, so I would treat it as outsourcing and put it on the register. The register has to hold non-material arrangements as well as material ones [1], so caution costs one row, while a missing row costs an audit finding. That is a reading of the text, and the Central Bank’s Regulatory Development Division is the reference for interpreting it [1].

Materiality decides how much follows. The bank’s Board-approved policy sets how it is assessed, and the Standards list what the assessment must consider, including the effect on the bank’s ability to manage its risks and meet its legal duties, and the nature of the data shared [1, 2]. An AI service that sees customer data or sits inside a credit, fraud or complaints process will usually come out material.

Material AI outsourcing needs the Central Bank’s non-objection first

Before a bank outsources any material activity, it must obtain a prior notice of non-objection from the Central Bank, and the arrangement needs approval by the Board or a Board committee [1]. The Standards set the minimum the request carries: a brief explanation of the activity, summaries of the materiality assessment, the risk assessment and the due diligence, confirmation that internal audit and compliance agree, an overview of closely related outsourcing agreements, confirmation of compliance with the Regulation, and evidence of the Board’s approval [2]. The Central Bank either grants it or asks for more, and it encourages banks to raise material plans early so the process does not hold them up [2].

For an AI programme this is a timing problem more than a legal one. A pilot that runs on real customer data with an outside vendor is already an arrangement. I would put the non-objection on the project plan at the same moment as the vendor shortlist, because the due diligence summary it asks for is work the bank has to do anyway.

Article 8 also says what the Central Bank will not generally allow: outsourcing core banking activities and key management and control functions, including Senior Management oversight, risk management, compliance, internal audit, and the management of risk-taking functions such as credit, investment and treasury management [1]. That line shapes AI design. A vendor’s model can score, summarise and recommend for a credit officer. A vendor that makes the credit decision is performing a function the Central Bank does not generally let a bank hand over. I would build every AI system in those functions so that the decision, and the named person accountable for it, stay inside the bank, and the vendor supplies a tool rather than the function.

The clauses the contract must carry

Article 5 of the Regulation and section 5 of the Standards set the contract’s content, and the CBUAE’s AI guidance note adds what it expects of contracts with AI providers [1, 2, 4]. The table reads each clause for an AI service: what the text requires, and what it means once the vendor runs a model. The deliverables themselves, evaluation included, belong in the statement of work under the agreement, and the guide to what an AI statement of work should name covers that layer.

CBUAE outsourcing contract requirements, read for an AI service
DimensionClauseWhat the text requiresWhat it means for an AI service
Data ownership (Articles 4.2 and 5.1)The bank keeps full ownership of the data it shares, its customers keep full ownership of theirs, and the Central Bank can access the data on requestPrompts, uploaded documents, retrieved passages, outputs and logs are the bank’s data. A vendor term allowing their use to train or improve its models sits badly with that, and I would strike it or limit it to what the bank specifically authorises
Access for the bank (Article 5.2)Unfettered access to all of its data for the duration of the agreement, including upon terminationLogs, conversation history, evaluation results and any fine-tuning data exportable in a usable format on request and at exit, rather than viewable only in the vendor’s console
Confidentiality and destruction (Article 5.3)Provisions to protect the data, including non-disclosure agreements and the destruction of the data after terminationDestruction has to reach every copy: caches, vector indexes, backups, logs and anything the model provider retains, with written confirmation of what was deleted and when
Data protection standards (Article 5.4)Standards for data protection set out in the agreement, including any nationally recognised information assurance standards in the UAEThe standard named in the contract itself, not a link to the vendor’s security page, which can change without notice
Access by other parties (Article 5.5)Neither the provider nor any subcontractor gives any other party access to Confidential Data without first obtaining the specific authorisation of the bank, or the customer, as the case may beA vendor that sends prompts containing customer data to a model provider is giving another party access, so that provider needs the bank’s specific authorisation, in writing
Subcontracting (Articles 4.3 and 5.6)The extent to which subcontracting is allowed and on what conditions; a subcontractor handling Confidential Data complies fully with the law and the RegulationThe model provider, the cloud host and any labelling or support firm named with their regions, and notice and approval before any of them changes
Central Bank access (Article 5.7 and Standards 5.2)An explicit right for the Central Bank and any agent it appoints to access the provider, visit on site and obtain any data or information needed for supervision, with access to data and staff as if the bank did the work itselfThe clause I would expect large platform vendors to push back on hardest. It has to be in the contract, and it has to reach the part of the service that handles Confidential Data
Breach notice (Article 5.8)The provider notifies the bank without undue delay of any breach of the bank’s data, in particular of Confidential DataA breach defined to include a prompt injection or a misrouted answer that shows one customer’s data to another, as well as an intrusion
Minimum content (Standards 5.1)Certainty on scope, fees, service levels, audit and monitoring, business continuity, termination including early termination, liability, indemnity and insurance, anti-money laundering compliance, dates, dispute resolution and governing jurisdictionService levels that cover answer quality on the bank’s own test set, not only uptime
AI provider terms (AI guidance note, 6(e) and 9(a))Provisions for access to relevant information, audit rights and compliance with CBUAE requirements; notice of material developments at the provider; termination or cease provisions; performance guaranteesA notice period before any model version change, so the bank can test the update before customers see it, as section 6(c) of the note expects

Middle column: the Rulebook text, summarised [1, 2, 4]. Third column: my reading for an AI service, not legal advice; the drafting belongs with the bank’s counsel.

The model behind the vendor is a subcontractor, and a concentration risk

A bank buying an AI product rarely buys from one supplier. The product vendor calls a model provider, which runs on a cloud, which may use subprocessors of its own. Each of those that touches Confidential Data must meet the Regulation’s requirements, and none of them may be given access to Confidential Data without the bank’s specific authorisation [1]. Due diligence therefore has to cover the whole chain, and the vendor has to be able to show it link by link.

The Standards name a risk that AI makes very real. Concentration risk includes “reliance by different outsourcing providers on the same subcontractor” [2]. A bank with separate vendors for its chatbot, its document extraction and its complaints triage may find all three calling the same model provider in the same region. On the register that looks like three suppliers. In an outage, or when a provider withdraws a model, it behaves like one. The AI guidance note makes the same point from the other side when it asks institutions to consider a range of AI providers where feasible [4].

The register can show this if it is built to. The Regulation asks for the provider’s details, the dates, a description of the service, whether Confidential Data is involved and whether the arrangement is material, and the Standards ask that it show what type of data is shared and distinguish levels of risk [1, 2]. I would add the model provider and its region to every AI row, so the concentration shows up in a query rather than in an incident review.

Where the vendor’s model feeds a modelling decision the bank relies on, the Model Management Standards add their own rule: the bank must remain the owner of its models at all times, must fully understand what a third party contributes, and must transfer knowledge from that third party to its own staff within a given time frame [5]. How the AI guidance note carries those standards into day-to-day AI governance is set out in what the CBUAE’s AI guidance note expects of banks.

Where the data sits: Article 6 and the Master System of Record

Article 6 is the rule most AI architectures run into. The Master System of Record, defined as all the data, including Confidential Data, a bank needs to conduct its core activities, manage its risks and comply with the law, must be continuously maintained and stored within the UAE [1]. A branch of a foreign bank may, with Central Bank approval, instead keep a copy in the UAE updated at least daily [1].

Confidential Data is data about a customer who is or can be identified, from that data alone or together with other information the recipient holds or is likely to get [1]. It must not be shared outside the UAE without Central Bank approval and the customer’s prior written consent, and the customer must also acknowledge in writing that the data may be accessed under legal proceedings abroad [1]. A bank may not outsource to a provider in a jurisdiction that cannot safeguard Confidential Data to the standard that would apply in the UAE, a test that covers every jurisdiction relevant to the agreement, and it may not store data where bank secrecy or other laws would restrict the Central Bank’s access [1].

Read with an AI system in mind, a prompt carrying a customer’s name, account details or a scanned document is Confidential Data, and sending it to a model hosted outside the UAE shares it outside the UAE. That leaves three workable designs: run the model in a UAE region, remove anything that identifies the customer before a request leaves the country, or collect the approval and consents Article 6.3 asks for, which does not scale to a customer-facing service. The identification test is broad, so redaction of free text has to be tested rather than assumed. Whether a UAE cloud region actually runs the model you want is a separate question, and the guide to which Gulf cloud regions actually run AI models works through it.

Articles 6.7 and 6.8 add that a bank must consider how changes in economic, political, social, legal or regulatory conditions could affect a provider abroad, and the operational, legal and reputational risks of using one [1]. AI vendors change their terms, models and regions often, so that assessment needs repeating each time they do.

Audit, breach reporting and the way out

Outsourced activities stay fully inside the bank’s internal audit and compliance scope [1]. The Standards add that internal audit must be able to obtain all the information it needs, and to demand that audits performed by third parties are extended in scope where necessary [2]. A vendor’s independent assurance report that stops short of the model pipeline is exactly the case for that right.

A breach travels in two steps. The vendor tells the bank without undue delay [1]. The bank must then notify the Central Bank immediately when it becomes aware of a material breach of an outsourcing agreement, or of another development in an outsourced Material Business Activity that has, or is likely to have, a significant impact on its operations, reputation or financial condition [1]. A vendor clause that allows days of internal investigation before any notice leaves the bank unable to meet its own duty.

Exit is the part of an AI contract I would check hardest. The Central Bank can require a bank to end an arrangement that is no longer compliant or presents undue risk [1], and the Standards treat vendor lock-in as a risk to manage, asking for arrangements that let an outsourced activity move to another provider or back in-house without undue delay, with contingency plans to do it [2]. For an AI service, the exit pack is the bank’s data, the prompts and configuration, the evaluation set and its results, and any model trained on the bank’s data where the contract gives the bank rights to it. If those cannot be moved, the exit plan is a hope.

A bank offering Islamic financial services carries one more duty: its outsourcing must stay consistent with Shari’ah rules and principles, and the Standards warn that providers may be unfamiliar with them [1, 2]. An assistant that explains Islamic finance products to customers sits squarely in that risk, and its test set should include the questions the bank’s Shari’ah function would ask.

If you sell AI to UAE banks: the pack to bring

The bank’s due diligence has a fixed shape. The Standards list the provider’s financial capacity, experience, governance and internal control, security including cyber security, staffing and country risk [2], and the AI guidance note adds the provider’s reputation in AI, its governance, security and data-protection practices, and an annual cybersecurity review by an independent, suitably qualified third party [4]. A vendor that brings the answers saves the bank asking for them one at a time.

A data-flow diagram with regions
Every place the bank’s data goes, from upload to model call to log store, with the country and cloud region of each, and where Confidential Data can appear.
A named subcontractor list
The model provider, the cloud host and any support or labelling firm, what each one touches, and the notice and approval process before any of them changes (Articles 4.3, 5.5 and 5.6).
A clause schedule mapped to Article 5
Draft wording for each Article 5 clause, the Central Bank access and on-site visit right included, so the two legal teams start from agreement rather than from a redline.
A model change policy
How much notice the bank gets before a model version changes, and how it can hold the current version while it tests the new one.
A breach process for AI
Who tells whom, how fast, and what counts as a breach in an AI system, cross-customer exposure included.
An exit plan
The export format for data, logs, prompts and evaluation results, the deletion confirmation, and how long the vendor supports a transition.
The independent security review
The latest annual review by a qualified third party and its scope, so the bank can see whether it covers the AI pipeline or stops at the web application.

Where 1AYM fits

This is architecture before it is paperwork. The clauses are only true if the system behind them keeps Confidential Data in the UAE, logs every model call, pins model versions and can hand everything back at exit. That is the work we sell as production AI systems when we build the service, and as AI governance implementation when the controls have to go into systems a bank already runs. For a vendor selling to UAE banks, the same work produces the pack above from the system itself. We work in financial services, with clients across the UK, the US and the Gulf, and UAE clients can contract locally through our UAE entity. We have built Arabic-language AI, including bilingual Arabic and English search and Arabic document OCR.

We are an outsourcing provider in this picture too, and the same terms apply to us. Our engineers work under identities the client issues, nothing we deliver depends on a system only we can reach, and a fixed-scope statement of work keeps our access as narrow as the scope. We do not resell model licences, so the bank chooses its model provider on the evidence and holds that contract itself. Our closest published work in the region is the production estate of a government-accredited EdTech in the Middle East, whose database we replatformed into Google Cloud’s Doha region, me-central1, to meet Gulf data-residency requirements. It is education rather than banking, and I mention it for the method. A fixed-scope build can start within a day of the scope being signed, and if you already have a scoped job, we can resource it on contract from the collective of associates who work with us, held to the same standard. Whether a contract satisfies the Central Bank stays with your compliance function and counsel. The call is booked from the end of this page.

For engineers: residency enforcement, redaction tests, version pins and exit exports

The Regulation in engineering terms. Each item is something a bank’s auditor, or the Central Bank, could check in configuration, code or logs rather than by asking someone.

Region enforced at one gateway
Route every model call through one gateway that knows each endpoint’s region and refuses a request carrying Confidential Data to an endpoint outside the UAE. Residency written in a policy but not enforced in the request path fails the first time someone picks a default endpoint.
Redaction tested against Article 1.6
If requests leave the UAE after redaction, test the redaction against the Confidential Data definition: could the recipient identify the customer from the text together with information it holds or is likely to get? Names are easy. Account numbers in free text, addresses and scanned documents are where redaction fails, so keep the test set and the miss rate.
Register rows from configuration
Generate the register’s AI rows from deployment configuration: vendor, model provider, model version, region, data categories and materiality. A new endpoint without a register entry should fail the deployment.
Pinned versions and change notice
Call models by pinned version identifiers, watch for provider deprecation notices, and run the evaluation suite on a new version before promotion, so the contract’s notice period has a test run behind it.
Keys and support access
Article 4.4 asks for data secured from unauthorised access, including by the provider’s own staff. Encryption keys the bank controls, and provider support access that needs the bank’s approval each time and is logged, are the usual ways to evidence it.
Logs the bank owns
Keep prompt and response logs, retrieval traces and evaluation results in a UAE store the bank owns, in an open format, so Article 5.2’s unfettered access and the exit export are a query rather than a request to the vendor.
Deletion you can show
At termination, delete from primary stores, caches, vector indexes, backups and the model provider’s retention, and record each deletion with a timestamp, so Article 5.3’s destruction clause has evidence behind it.
Breach signals for AI
Alert on retrieval across customers or tenants, on outputs containing account identifiers that were not in the request, and on injected instructions that reach a tool, and route those alerts into the breach process the contract names.

Sources

  1. [1]CBUAE Rulebook, Outsourcing Regulation for Banks (C 14/2021), effective 15/7/2021, status in force, read 30 September 2026
  2. [2]CBUAE Rulebook, Outsourcing Standards for Banks (C 14/2021 STA), effective 15/7/2021, status in force, read 30 September 2026
  3. [3]CBUAE Rulebook, نظام التعهيد للبنوك, the Regulation’s Arabic page, read 30 September 2026
  4. [4]CBUAE Rulebook, Guidance Note on the Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions in the U.A.E., issued 11/2/2026, sections 6 and 9, read 30 September 2026
  5. [5]CBUAE Rulebook, Model Management Standards, 4.7 Third Party Provider, read 30 September 2026

Questions vendor risk and procurement teams ask

What is the CBUAE Outsourcing Regulation for Banks?

Circular C 14/2021 of the Central Bank of the UAE, in force since 15 July 2021, with accompanying Outsourcing Standards. It sets how banks operating in the UAE assess, approve, contract, register, audit and report outsourcing, and it requires the Master System of Record, including all Confidential Data, to be maintained and stored in the UAE. Outsourcing agreements signed before it took effect had to comply by 31 December 2023. This is not legal advice.

Is an AI vendor an outsourcing provider under CBUAE rules?

Usually. The Regulation defines outsourcing as another party performing, on a continuing basis, an activity the bank does or could do itself, and most AI services a bank buys fit that. Every arrangement goes on the bank’s outsourcing register, material or not, and a material one needs the Central Bank’s prior non-objection.

Can a UAE bank use an AI model hosted outside the UAE?

Not with customer Confidential Data, unless the Central Bank approves and the customer gives prior written consent, under Article 6.3, and the Master System of Record must stay in the UAE. In practice banks run the model in a UAE region, or remove anything that identifies the customer before a request leaves the country.

What must a CBUAE outsourcing contract include?

Article 5 requires data ownership for the bank and its customers, the bank’s unfettered access to its data including on termination, non-disclosure and destruction provisions, named data protection standards, no access to Confidential Data for other parties without the bank’s specific authorisation, the terms for subcontracting, Central Bank access to the provider including on-site visits, and breach notice without undue delay. Section 5.1 of the Standards adds service levels, continuity, termination, liability, anti-money laundering compliance and dispute resolution.

Is the model provider behind an AI product a subcontractor?

Where it processes the bank’s Confidential Data, treat it as one. The contract must say how far subcontracting is allowed, the subcontractor must meet the Regulation’s requirements, and no other party may access Confidential Data without the bank’s specific authorisation (Articles 4.3, 5.5, 5.6 and 6.12). That is a reading of the text, not legal advice.

Does a UAE bank need Central Bank approval to use an AI vendor?

For a material arrangement, yes: a prior notice of non-objection from the Central Bank, with Board or Board committee approval. The Central Bank will not generally permit the outsourcing of core banking activities or key management and control functions, such as risk management, compliance, internal audit and the management of credit.

Does the CBUAE Outsourcing Regulation apply to insurers?

Its scope is banks operating in the UAE. The CBUAE’s AI guidance note, which does cover insurers, points to the Outsourcing Regulation for Banks “to the extent applicable” when an institution relies on third-party AI vendors, so check the rules for your own licence type.

More in this topic

  • For a firm licensed in Dubai’s financial centre, where AI on personal data answers to the DIFC’s own data protection rules.

  • Reading Arabic documents with AI, one of the services a bank most often buys from an outside vendor.

Further

  • AI governance implementation · Version pins, residency checks and a register fed from configuration, added to the AI systems a bank already runs.
  • Production AI systems · An AI service built with its region, logging and exit export designed in, so the contract clauses are true of the system.
  • Engagement file D-02 · A government-accredited EdTech in the Middle East, its database replatformed into a named Gulf cloud region.

We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.

Last reviewed · 1AYM