CBUAE authentication and app-security requirements.
How financial institutions in United Arab Emirates meet them with Fortanixor — banks, exchange houses, payment providers, microfinance and fintechs supervised by the Central Bank of the UAE.
The UAE is the clearest of the seven markets on where data may live. Article 6.1.6.3 of the Consumer Protection Standards states that all Licensed Financial Institutions must hold and store all consumer and transaction data within the UAE as prescribed by the Central Bank, and must keep a secure backup in a separate location for the retention period. There is no risk-assessment escape hatch and no approval route around it, which is a stricter position than SAMA's cloud rule and far more explicit than anything in the Pakistani or Bangladeshi frameworks.
On authentication CBUAE is principle-based rather than prescriptive. Article 6.1.1.7 requires more than one evidence of identity verification wherever a consumer's identity is verified online, and 6.1.1.8 requires institutions to secure digital transaction processing, implement detailed activity monitoring and enhance consumer identification methods in line with the Central Bank's requirements for strengthening digital channels. CBUAE does not name the mechanism, so a passkey is not mandated — but it satisfies 6.1.1.7 in a single gesture, and the per-ceremony event log is the kind of detailed activity monitoring 6.1.1.8 asks for. The Standards also carry an obligation most frameworks leave implicit: under 6.1.1.10, logs of who accessed consumer data and when must be produced to the Central Bank on request. Two further points come from reading the full Standards rather than Article 6 alone: personal data, documents and records must be retained for a minimum of five years under Article 6.1.6.1, and the complaint management function must itself be situated in the UAE under Article 8.1.1.1. And one caution worth stating plainly — Article 5.1.1.10 prohibits marketing loans and other services to individual consumers by telephone, so an AI voice agent belongs on servicing and consented contact here, not on acquisition calling.
What Central Bank of the UAE requires
01 / 06
More than one evidence of identity verification online
Where a consumer's identity verification is conducted online, the institution must apply more than one evidence of identity verification for electronic services. Consumers must also be advised about directed and repeated online fraud attempts on their accounts so they can take additional precautions.
Secure digital transaction processing and stronger identification
Institutions must secure digital transaction processing and controls, implement detailed activity monitoring, and enhance consumer identification methods in accordance with the Central Bank's requirements for strengthening digital channels.
All consumer and transaction data held within the UAE
Two instruments say this. Under the Consumer Protection Standards all Licensed Financial Institutions must hold and store all consumer and transaction data within the UAE, with a secure backup in a separate location. The Outsourcing Regulation goes further for banks: the Master System of Record, which includes all Confidential Data, must be continuously maintained and stored within the UAE, and customers' Confidential Data must not be shared outside the UAE without Central Bank approval and the customer's prior written consent.
A safe and confidential environment across every delivery channel
Institutions must provide a safe, secure and confidential environment in all of their delivery channels to ensure a high level of confidentiality and privacy of personal data, and remain responsible for data protection and confidentiality where new technologies are used to deliver financial services.
A data control framework, with access logs producible to the Central Bank
Institutions must operate a data management control framework with policies, procedures, system controls and checks and balances that protect consumer data and identify and resolve information security breaches, backed by monitoring and preventive controls that detect unauthorised or accidental loss, misuse, modification, access, disclosure or destruction. Access to personal data must be limited to authorised business lines and their staff, and logs recording who accessed consumer databases and when must be provided to the Central Bank as and when requested.
Five-year retention, and complaint handling inside the UAE
All personal data, documents, records and files must be securely retained for a minimum of five years, running from termination of the business relationship, closure of the account, or completion of a casual transaction. Separately, the consumer complaint management function must be situated in the UAE and independent of retail operations management.
A FIDO2 passkey ceremony supplies two independent evidences in one gesture: possession of the device holding the private key, and the biometric or PIN that unlocks it inside the secure element. Neither is a shared secret, so neither can be phished from the consumer or breached from the institution.
Every authentication ceremony is logged with its result and the reason it was challenged, giving a per-transaction record rather than a session-level one, and Secure Payment Confirmation binds amount and payee into the signature so the record shows what was actually authorised. One passkey credential covers the mobile app, web through cross-device QR sign-in, cardless ATM and 3-D Secure, so identification is strengthened uniformly across channels instead of each falling back to something weaker.
All three products deploy on-premise, into in-region cloud, or hybrid, and Fortanixor has an office in the UAE. An in-country deployment keeps authentication data, speech processing and call records inside the UAE, so it does not create the cross-border flow Article 6 restricts — and it avoids Article 6.3's chain of Central Bank approval plus written customer consent, which is a per-customer obligation an offshore service would otherwise impose on the bank.
FortVoice processes speech in the bank's own region rather than shipping audio to a global endpoint, which matters here because a voice recording of a consumer instructing a payment is both consumer data and transaction data under this article.
Credentials are origin-bound and device-held, so a spoofed channel cannot complete a sign-in. On the automated channel, FortAgent discloses that the caller is speaking to an AI agent and can hand off to a person at any point.
Every FortAgent call is transcribed, scored and summarised with a full audit trail, and every authentication ceremony carries its own record — so an access request can be answered with the actual interaction rather than a reconstruction.
FortAgent handles routine calls under allow-listed tools and policy controls, so fewer interactions require a person to open a consumer record at all, and those that do are reached through the bank's existing access controls after the caller has been verified.
Optional device fingerprinting and VPN or anonymiser detection surface anomalous sign-in attempts, and the per-ceremony log gives the data-protection function a feed it can monitor rather than a periodic report.
Authentication ceremony records and call transcripts, scores and summaries export into the institution's own retention estate, so the five-year clock is served by the systems the institution already controls rather than by a vendor's retention policy.
FortAgent deploys in-country and hands off to a person at any point, so a complaint raised on an automated servicing call reaches the institution's own UAE-situated complaint function with a full transcript attached, rather than being handled offshore or lost between channels.
Where a requirement belongs to the bank’s own operations, or where the regulator has published no rule to map to, we say so rather than stretch a row to cover it. This is the boundary of the table above, not a gap in it.
Outbound marketing calls — prohibited, and this constrains how FortAgent may be used in the UAEArticle 5.1.1.10 prohibits Licensed Financial Institutions from marketing loans, financing and other services to individual consumers through direct contact by telephone. Article 5.1.1.72 prohibits unsolicited marketing calls by any means without the consumer's express consent, and Article 5.1.1.9 treats consumers as opted out unless they have expressly opted in. FortAgent's outbound calling must therefore be confined to servicing and consented contact in this market — not acquisition or cross-sell. Inbound servicing is unaffected.
Consent, disclosure and consumer notification obligationsArticle 6.1.1.1 and 6.1.1.5. Consumers must be informed in writing how their personal information will be processed, and disclosure requires the consumer's express consent. These are the institution's own consent and communications processes.
Designating a senior data management and protection functionArticle 6.1.2.1. The Board must assign this responsibility to a senior manager. An organisational obligation, not something a vendor can discharge.
Backup of consumer data in a separate location for the retention periodArticle 6.1.6.3. Our products export their records into the bank's own retention and backup estate; the backup obligation itself remains the institution's.
A specific AI-disclosure obligation for customer-facing automationNot established, and now checked across the whole instrument. The complete 162-page Consumer Protection Standards was searched for artificial intelligence, machine learning, algorithm, chatbot, robo and voice-bot terms: the only matches are 'Automated Teller Machine'. CBUAE has published no AI governance or AI-disclosure obligation in this instrument. FortAgent discloses to callers regardless; we do not claim CBUAE requires it.
Central Bank non-objection before outsourcing a material activityOutsourcing Regulation for Banks (Circular 14/2021), Article 8.1 — banks must obtain a prior notice of non-objection from the Central Bank before outsourcing any material activity, including to a related party. Whether a given deployment is a material outsourcing, and obtaining the non-objection if it is, is the bank's determination and the bank's filing. An on-premise deployment inside the bank's own estate is the shape least likely to raise the question.
Sources
Every clause cited on this page was read in the document below, on the regulator’s own site.
Consumer Protection Standards ↗Central Bank of the UAE (CBUAE) · Regulatory Standards forming part of the Consumer Protection Regulation · 2020 · Circular No. 8 of 2020 — mandatory and enforceable in the same manner as the Regulation
Outsourcing Regulation for Banks ↗Central Bank of the UAE (CBUAE) · Regulation and accompanying Standards · 2021 · Circular No. 14/2021, dated 31/5/2021
This mapping is provided for guidance and must be validated by the bank's compliance function against the current version of each framework.
Deployment options in United Arab Emirates
Fortanixor has an office in the UAE and deploys on-premise, into in-region cloud, or as a hybrid of the two.
Deployment shapes
On-premiseIn-region cloudHybrid
Runs on
Microsoft AzureGoogle Cloud
Deployed into your own account and your own region on any of the three, or on-premise where the data must not leave your estate at all.
CBUAE questions, answered.
CBUAE is principle-based here rather than prescriptive. Article 6.1.1.7 requires more than one evidence of identity verification wherever a consumer is verified online, and a FIDO2 passkey ceremony supplies two in one gesture — possession of the device holding the private key, and the biometric or PIN that unlocks it. Article 6.1.1.8 additionally requires enhanced consumer identification methods and detailed activity monitoring for digital channels, which the per-ceremony event log provides. CBUAE does not name passkeys, so this is a mapping rather than a mandate, and it must be validated by your compliance function against the current version of the Standards.
You have to, and two instruments say so. Article 6.1.6.3 of the Consumer Protection Standards requires all consumer and transaction data to be held and stored within the UAE, with a secure backup in a separate location. The Outsourcing Regulation for Banks (Circular 14/2021) is sharper still: Article 6.1 requires the Master System of Record, including all Confidential Data, to be continuously maintained and stored within the UAE, and Article 6.3 forbids sharing customers' Confidential Data outside the UAE without Central Bank approval AND the customer's prior written consent. Fortanixor has an office in the UAE and all three products deploy on-premise, into in-region cloud, or hybrid, so authentication data, speech and call records stay in country. This matters most for voice: a recording of a consumer instructing a payment is both consumer data and transaction data.
It can, and CBUAE leaves the choice to you. Unlike Turkey, where SMS OTP is prohibited once the mobile app is active, the Consumer Protection Standards do not name any specific mechanism — they require more than one evidence of identity and identification methods that are strengthened in line with the Central Bank's digital channels requirements. Institutions here typically enrol passkeys alongside the existing OTP, move sign-in first, then higher-value transactions, and retire the SMS path once enrolment is high enough.
It cites CBUAE's own article numbering, links to the Rulebook, and separates what the product does from what stays with the institution. The downloadable CBUAE mapping covers Article 6.1.1 through 6.1.6 plus the retention and complaint provisions in 6.1.6.1 and 8.1.1.1, and it names what is outside our scope — consent and disclosure processes, the designated data protection function, the backup obligation. It also records two things we deliberately do not claim: there is no AI-disclosure clause anywhere in the 162-page Standards, so FortAgent's disclosure is not presented as satisfying one; and Article 5.1.1.10 prohibits telephone marketing of loans and services to individual consumers, which bounds outbound use of an AI voice agent in this market.
Get the CBUAE control mapping
The full control-by-control mapping for FortAuth, FortVoice and FortAgent, as a document your compliance function can review.