- The transitional period ended 16 September 2026 with no extension announced.
- The law consolidates supervision over banks, insurers, finance companies, exchange houses, PSPs, and technology enablers.
- Maximum administrative fines reach AED 1 billion; unlicensed activity carries criminal liability.
- Businesses that missed the deadline should open active regulatory dialogue immediately rather than staying silent.
The Central Bank Law’s one-year transitional period closed on 16 September 2026. Entities still out of compliance now face administrative fines of up to AED 1 billion, and unlicensed financial activity carries criminal liability.
No extension to this transitional period was ever announced, and none has arrived. A business that assumed more time would materialize is now operating past a deadline that has already passed.
This guide covers what this deadline actually required, which entities fall within its scope, and what a business still catching up should do right now.
Why this law reshaped supervision across an unusually wide range of entities
The Central Bank Law, which came into force on 16 September 2025, consolidated supervisory authority across banks, insurers, finance companies, exchange houses, payment service providers, and technology enablers under one framework.
This consolidation gave the Central Bank a considerably broader supervisory reach than it held previously, extending scrutiny to categories of business that may not have previously considered themselves squarely under Central Bank oversight.
A founder running any business touching payments, exchange services, or financial technology should confirm directly whether this consolidated scope now captures an activity that sat in a lighter regulatory position before.
| Detail | What applies |
|---|---|
| Law effective date | 16 September 2025 |
| Transitional period closed | 16 September 2026 |
| Scope | Banks, insurers, finance companies, exchange houses, PSPs, and technology enablers |
| Maximum administrative fine | AED 1 billion |
| Unlicensed activity consequence | Criminal liability, not just an administrative penalty |
“No extension was announced. A business still working through its compliance checklist is not working ahead of a deadline anymore. It is working after one.”
Why a technology enabler might not have realized this law applied to it at all
The phrase technology enablers captures a genuinely broad range of businesses supporting financial activity indirectly, payment infrastructure providers, certain fintech platforms, and similar technology-layer businesses that do not directly hold customer funds themselves.
A founder running this kind of supporting infrastructure business should not assume the absence of direct customer fund custody automatically places the business outside this law’s scope.
Confirming this scope question directly with the Central Bank, rather than assuming based on a narrow reading of the business model, is the only reliable way to know for certain.
Consider a payment infrastructure startup providing backend processing services to several licensed merchants, which had assumed its role as a technical intermediary, rather than a direct payment service provider, placed it outside the Central Bank’s direct supervisory scope.
A compliance review ahead of a funding round flagged that the business’s specific function fell within the law’s technology enabler category, prompting an urgent engagement with the Central Bank in the final weeks before the transitional deadline closed, rather than the calmer, better-paced conversation that earlier awareness would have allowed.
Why regularizing under this law is a genuine process, not a single form to submit
A business bringing itself into compliance needs to demonstrate genuine alignment with the law’s licensing, governance, and reporting requirements, not simply file a one-time acknowledgment that the law exists.
This typically involves confirming licensing category, reviewing governance structures against Central Bank expectations, and ensuring reporting mechanisms are actually in place and functioning, not merely described in a policy document.
A business only beginning this process now should expect a genuinely active, ongoing regulatory dialogue rather than a quick retroactive fix.
Why active engagement now still matters even after the deadline has passed
A business that missed the 16 September 2026 deadline should not interpret this as a lost cause. Active, good-faith engagement with the Central Bank still matters considerably more than continued silence.
Regulators generally distinguish between a business demonstrating genuine effort to regularize, even belatedly, and one that has made no visible effort at all, and this distinction can meaningfully affect how enforcement discretion gets applied.
A founder in this position should prioritize opening that regulatory dialogue immediately, rather than waiting for a more convenient moment that a live deadline no longer allows for.
Why this consolidation connects directly to the separate Operational Risk Management Regulation
See our guide on how operational risk management obligations were formalized in 2026 for a related framework many entities newly captured by this broader consolidation are managing simultaneously alongside their Central Bank Law compliance work.
Why insurance-adjacent businesses specifically feel this consolidation’s reach
See our guide on why insurance brokers now answer to the Central Bank directly for a related example of exactly the kind of sector-specific supervision this broader Central Bank Law consolidation now formally encompasses.
Why ordinary SME banking relationships sit inside this same broader framework too
See our guide on how SME banking customers gained new protections in 2026 for a related, customer-facing regulation that reflects the same consolidated Central Bank authority behind this broader transitional deadline.
Why a fintech testing under a sandbox arrangement should confirm its own eventual scope here
See our guide on what a fintech gains from testing inside the DIFC or ADGM sandbox for how a sandbox-stage fintech should plan its eventual transition into full Central Bank compliance, since this consolidated law is exactly the kind of framework a sandbox graduate needs to satisfy fully.
Why this deadline deserves a permanent line in a business’s compliance calendar going forward
See our guide on what belongs on a genuinely complete UAE compliance calendar for how a major legislative deadline like this one should be tracked going forward, since the Central Bank has shown a genuine willingness to consolidate and expand supervisory scope with real enforcement teeth behind it.
Why keeping a written record of every compliance step taken protects a business later
A founder working through regularization after this deadline should keep a clear, dated record of every step taken, every communication with the Central Bank, every internal policy update, and every governance change made.
This record becomes genuinely valuable evidence of good-faith effort if enforcement discretion ever needs to be argued for specifically, a considerably stronger position than relying on a verbal account of compliance progress.
A founder who treats this documentation as optional risks having no clear evidence to point to if the business’s compliance timeline is ever formally questioned.
Why even a licensed financial institution’s own payroll still runs through the same national systems
See our guide on what MoHRE Resolution No. 340 of 2026 actually changed for payroll for a related, unrelated-sector compliance requirement that still applies to a licensed financial institution’s own internal staff exactly as it does to any other UAE employer.

Why board-level governance review needs to happen alongside, not after, the technical compliance work
A founder or executive at an in-scope institution should ensure the board itself is genuinely briefed on this consolidation’s requirements, not just the compliance team working through the technical detail in isolation.
A board that understands the actual stakes behind this deadline, including the scale of potential fines and the criminal liability attached to unlicensed activity, is considerably more likely to allocate the resources a genuine regularization process actually needs.
Treating this as purely a compliance department task, without board-level visibility, risks under-resourcing an effort that genuinely needs organization-wide priority.

Why third-party vendors and partners deserve their own scope review under this consolidation
A founder should also confirm whether any third-party vendor or technology partner supporting the business’s own financial activity might itself fall within this law’s expanded scope, since a vendor’s own compliance gap can create downstream exposure for the business relying on that vendor’s services.
This vendor-level review is easy to overlook when a business focuses purely on its own direct licensing status, but it represents exactly the kind of indirect exposure this broad consolidation was designed to capture.
Why front-line staff need genuine awareness of this law, not just senior management
A founder should ensure staff handling day-to-day customer interactions, not just senior compliance and legal teams, understand at least the basic shape of this law’s requirements, since front-line staff are often the first to notice a practical gap between policy and actual operations.
A brief, accessible training session covering the practical implications relevant to each specific role, rather than the full legal text, gives staff enough context to flag concerns upward when something does not look right.
This distributed awareness considerably strengthens a business’s actual compliance posture, since gaps are more likely to surface early when more people across the organization understand what genuine compliance is supposed to look like in practice.
Common mistakes when approaching the Central Bank Law reconciliation deadline
- Assuming a technology-layer business sits outside the law’s scope without confirming this directly.
- Treating regularization as a single form rather than a genuine governance and reporting review.
- Going quiet after missing the deadline instead of opening active regulatory dialogue immediately.
- Failing to keep a documented record of compliance steps taken during a belated regularization process.
When professional help is worth it
A business confident in its licensing category and already engaged with the Central Bank can often manage remaining steps directly. Where guidance is worth the cost is any business genuinely uncertain whether its specific activity now falls within this consolidated scope, or one that has not yet opened a regulatory dialogue and needs help structuring that conversation properly.
the e.zone team behind financial regulatory matters can help assess your exposure under this consolidated law and structure a genuine regularization plan. See e.zone’s guide on why a bank’s compliance team asks where the money originated for a related compliance area worth reviewing alongside this broader consolidation.
A business genuinely uncertain about its own scope status benefits most from an early, direct conversation with a specialist familiar with how the Central Bank has been applying this consolidated law in practice, since published guidance alone rarely resolves every edge case a specific business model might raise.
A founder managing a group of related entities across different licence categories should also confirm whether the group as a whole, not just each individual entity, faces any consolidated reporting obligation under this law, since group-level structures sometimes trigger obligations that would not apply to any single entity reviewed in isolation.
A founder who has already opened a regulatory dialogue with the Central Bank should keep that channel genuinely active, with regular status updates volunteered proactively, rather than going quiet again once the initial conversation concludes, since sustained engagement tends to be viewed more favorably than a single early contact followed by extended silence.
Why an independent external review often strengthens a business’s own internal compliance assessment
A founder who has completed an internal compliance self-assessment should still consider an independent external review before finalizing any regularization submission to the Central Bank, since a genuinely fresh set of eyes often catches a gap an internal team, close to its own systems, can overlook entirely.
This external review is particularly valuable for a business uncertain whether its own governance and reporting mechanisms would satisfy an examiner’s specific expectations, since a specialist familiar with recent Central Bank enforcement patterns can flag a weakness before it becomes a formal finding.
Treating this external review as a genuine investment in getting the regularization process right the first time, rather than an unnecessary added cost, reflects the real financial stakes this consolidated law now carries.
Frequently asked questions
What happens if my business missed the 16 September 2026 deadline?
Missing the deadline does not mean the situation is unrecoverable. Active, documented engagement with the Central Bank matters considerably more than continued silence, and enforcement discretion often reflects genuine good-faith effort.
Does my technology platform fall under the Central Bank Law even though we don't hold customer funds?
Possibly. The law's technology enabler category is broad and does not require direct custody of customer funds. Confirm scope directly with the Central Bank rather than assuming based on your business model.
What is the maximum penalty for non-compliance?
Administrative fines can reach AED 1 billion, and unlicensed financial activity carries criminal liability, not just an administrative penalty.
Should third-party vendors be reviewed too?
Yes. A vendor or technology partner supporting your financial activity may itself fall within the law's scope, creating downstream exposure for your business.
Talk to a setup advisor
Free 20-minute call to confirm the right structure for your business.

