Proud of UAE  [email protected]       [email protected]        +97142500251 97142500251+       +971507869887 971507869887+      WhatsApp

How Does Internal Audit Work in UAE Banks and What Should It Cover?

Why Internal Audit in UAE Banks Is Distinct From General Corporate Internal Audit

Internal audit functions in UAE banks operate within a regulatory framework that imposes requirements well beyond those applicable to general commercial businesses. UAE-licensed banks are supervised by the Central Bank of the UAE (CBUAE), which has issued specific prudential standards, consumer protection regulations, and AML/CFT requirements governing how banks must manage risk, protect customers, and maintain internal controls. The internal audit function in a UAE bank must provide independent assurance across all of these regulatory dimensions, not just financial accuracy and operational efficiency.

The CBUAE’s Standards for Internal Audit Function of Licensed Financial Institutions set out the minimum requirements for internal audit in UAE banks, covering the function’s mandate, independence, scope, staffing, methodology, and reporting requirements. These standards are binding on all CBUAE-licensed banks and financial institutions and establish a level of internal audit requirement that exceeds what most non-banking businesses are expected to maintain.

The Core Regulatory Framework Governing UAE Bank Internal Audit

A UAE bank’s internal audit programme must address compliance with the following primary regulatory frameworks:

  • CBUAE prudential standards: capital adequacy, liquidity, large exposure limits, and related reporting requirements. Internal audit reviews whether the bank’s calculation and reporting of these metrics is accurate and whether any breaches are escalating appropriately to management and the CBUAE
  • CBUAE Consumer Protection Regulation: the Consumer Protection Standards issued by the CBUAE require banks to treat customers fairly, provide accurate product information, resolve complaints within prescribed timelines, and maintain transparent pricing. Internal audit reviews whether the bank’s customer-facing processes, fee disclosures, and complaint management function comply with these standards
  • AML/CFT framework: under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, all UAE banks are financial institutions with mandatory AML obligations: Customer Due Diligence, Enhanced Due Diligence for high-risk relationships, transaction monitoring, STR filing through goAML, and semi-annual MLRO reporting. Internal audit provides independent assurance that these obligations are being discharged correctly and that the bank’s AML programme is effective
  • CBUAE Standards for Retail Banking: covering the conduct of retail banking operations, product suitability, and the bank’s obligations to individual consumers
  • UAE Federal laws: including the Commercial Companies Law, the Civil Transactions Law, and financial crime provisions under the UAE Penal Code

Need Expert Advice?

Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.

What a UAE Bank Internal Audit Programme Should Cover

Credit Risk and Lending Controls

Credit risk is typically the largest risk category in a UAE bank’s risk profile. Internal audit reviews the bank’s credit origination processes, credit assessment methodologies, credit committee governance, documentation completeness for facilities approved, and compliance with the bank’s own credit policy. It also reviews the accuracy of loan classification and provisioning, assessing whether non-performing loans are being identified and provided for in line with IFRS 9 and CBUAE guidance.

AML Compliance

AML internal audit in a UAE bank examines whether the Compliance Officer’s programme is functioning as designed, not merely whether policies exist. The audit reviews a sample of customer onboarding files to assess CDD quality, examines the transaction monitoring system’s alert logic and investigation quality, reviews STR files to confirm that reporting decisions are appropriately documented, and tests whether the bank’s risk rating methodology is consistent and current. Given the extended personal liability of MLROs under FDL No. 10 of 2025, the quality of the internal audit function’s AML coverage directly affects the bank’s regulatory exposure.

Consumer Protection and Complaints Management

Under the CBUAE Consumer Protection Standards, banks must maintain a formal complaints management function, acknowledge complaints within defined timelines, and provide substantive responses within 30 calendar days. Internal audit reviews whether the complaints function is adequately resourced, whether complaints are being resolved within the required timelines, whether unresolved complaints are escalating to the CBUAE Consumer Protection Department where required, and whether complaint data is being analysed for systemic issues that require management action.

Treasury and Market Risk Controls

For banks with significant treasury operations, internal audit reviews the controls over market risk positions, whether trading limits are being observed and breaches are being reported promptly, the quality of the valuation methodology for financial instruments, and the accuracy of the bank’s market risk reporting to the CBUAE.

IT and Cybersecurity Controls

UAE banks are increasingly targeted by cyber threats, and the CBUAE has issued specific guidance on information security governance. Internal audit reviews access controls to core banking systems, the bank’s vulnerability management programme, the effectiveness of its business continuity arrangements, and whether the IT control environment is consistent with the CBUAE’s Information Technology Risk Management Standards.

Financial Reporting Controls

Internal audit reviews the controls over financial reporting, including the general ledger integrity, month-end close processes, accuracy of regulatory financial submissions to the CBUAE, and the adequacy of IFRS 9 expected credit loss models and their governance. The accuracy of the bank’s financial statements directly affects the Corporate Tax position under Federal Decree-Law No. 47 of 2022, making financial reporting controls relevant to both regulatory and tax compliance.

Independence and Reporting in UAE Bank Internal Audit

The CBUAE’s standards require the internal audit function of a UAE bank to be independent of the activities it audits. The Head of Internal Audit must report directly to the Board Audit Committee, not to executive management. The Audit Committee must have the authority to direct the internal audit programme, approve the internal audit charter, and receive internal audit reports without management filtering or interference.

This reporting line requirement is more stringent than what applies in most non-banking businesses. It reflects the systemic importance of banking sector internal audit in the UAE’s broader financial stability framework. A bank whose internal audit function reports to the CFO or CEO rather than the Audit Committee is in breach of CBUAE requirements.

Technology and Data Analytics in UAE Bank Internal Audit

The volume and complexity of transaction data in a UAE bank makes traditional sample-based testing increasingly inadequate for the highest-risk audit areas. Modern bank internal audit functions use data analytics to examine entire transaction populations rather than samples, running automated tests to identify outliers, duplicate payments, threshold manipulation, and patterns inconsistent with a customer’s expected activity. In AML audit specifically, the ability to analyse the complete population of transaction monitoring alerts and test whether alert thresholds are appropriately calibrated requires data analytics capability that goes beyond manual workpaper review.

A Governance, Risk, and Compliance (GRC) platform that centralises audit workflows, tracks findings remediation, and maps controls across regulatory frameworks allows the internal audit function to demonstrate to the CBUAE that its programme is comprehensive, current, and integrated with the bank’s wider risk management framework.

Also Check: Internal Audit Services

Frequently Asked Questions (FAQs)

What regulatory body governs internal audit requirements for UAE banks?

The Central Bank of the UAE (CBUAE) governs internal audit requirements for UAE-licensed banks and financial institutions through its Standards for Internal Audit Function of Licensed Financial Institutions. These standards set out minimum requirements for internal audit mandate, independence, scope, staffing, and reporting that all CBUAE-licensed institutions must comply with.

Who must the Head of Internal Audit report to in a UAE bank?

The CBUAE’s standards require the Head of Internal Audit to report directly to the Board Audit Committee, independently of executive management. A bank where internal audit reports to the CFO or CEO rather than the Audit Committee does not meet CBUAE requirements for internal audit independence.

What AML obligations must UAE bank internal audit cover?

Internal audit must provide independent assurance that the bank’s AML programme is functioning effectively: CDD quality at onboarding, transaction monitoring alert logic and investigation quality, STR filing completeness, MLRO reporting under FDL No. 10 of 2025, and the accuracy of risk ratings across the customer portfolio. Given extended MLRO personal liability under the 2025 law, the quality of AML internal audit coverage is a significant regulatory concern.

How does UAE bank internal audit differ from general corporate internal audit?

UAE bank internal audit operates under binding CBUAE prudential standards, consumer protection regulations, and AML requirements that impose specific coverage, independence, and reporting obligations not applicable to general businesses. The scope is broader, the regulatory stakes are higher, and the reporting line requirements are more stringent. Banks also face systemic risk considerations that make internal audit deficiencies a matter of financial stability as well as institutional governance.

What role does data analytics play in UAE bank internal audit?

Data analytics allows bank internal auditors to test entire transaction populations rather than samples, identify anomalies in transaction monitoring alert coverage, assess AML risk rating consistency across the portfolio, and detect control failures that sampling-based audit would miss. In AML audit specifically, full-population testing of alerts and thresholds is increasingly the standard expected by the CBUAE rather than a differentiator.

Need Expert Advice?

Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.

How Farahat & Co. Can Help

Farahat & Co. provides internal audit services to UAE banks and financial institutions, covering AML compliance audit, consumer protection controls, credit risk audit, financial reporting controls, and regulatory compliance assessments against CBUAE prudential standards. Our team conducts internal audit engagements in accordance with the CBUAE’s Standards for Internal Audit Function of Licensed Financial Institutions and the International Standards for the Professional Practice of Internal Auditing.

Contact Farahat & Co. today to discuss your bank internal audit requirements.

Ervee is a CPA with international experience in Tax and Accounting. He has over 12 years of experience in accounting and bookkeeping and over a year in VAT implementation, registration, and accounting in UAE. He regularly drives out inefficiencies in company operations and loves the challenge of helping clients find additional ways for an easier and improved compliance and verification of transactions.
×

Hold On!

Business decisions are easier with the right guidance.