Why Internal Audit in UAE Banks Is Distinct From General Corporate Internal Audit
Internal audit functions in UAE banks operate within a regulatory framework that imposes requirements well beyond those applicable to general commercial businesses. UAE-licensed banks are supervised by the Central Bank of the UAE (CBUAE), which has issued specific prudential standards, consumer protection regulations, and AML/CFT requirements governing how banks must manage risk, protect customers, and maintain internal controls. The internal audit function in a UAE bank must provide independent assurance across all of these regulatory dimensions, not just financial accuracy and operational efficiency.
The CBUAE’s Standards for Internal Audit Function of Licensed Financial Institutions set out the minimum requirements for internal audit in UAE banks, covering the function’s mandate, independence, scope, staffing, methodology, and reporting requirements. These standards are binding on all CBUAE-licensed banks and financial institutions and establish a level of internal audit requirement that exceeds what most non-banking businesses are expected to maintain.
The Core Regulatory Framework Governing UAE Bank Internal Audit
A UAE bank’s internal audit programme must address compliance with the following primary regulatory frameworks:
- CBUAE prudential standards: capital adequacy, liquidity, large exposure limits, and related reporting requirements. Internal audit reviews whether the bank’s calculation and reporting of these metrics is accurate and whether any breaches are escalating appropriately to management and the CBUAE
- CBUAE Consumer Protection Regulation: the Consumer Protection Standards issued by the CBUAE require banks to treat customers fairly, provide accurate product information, resolve complaints within prescribed timelines, and maintain transparent pricing. Internal audit reviews whether the bank’s customer-facing processes, fee disclosures, and complaint management function comply with these standards
- AML/CFT framework: under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, all UAE banks are financial institutions with mandatory AML obligations: Customer Due Diligence, Enhanced Due Diligence for high-risk relationships, transaction monitoring, STR filing through goAML, and semi-annual MLRO reporting. Internal audit provides independent assurance that these obligations are being discharged correctly and that the bank’s AML programme is effective
- CBUAE Standards for Retail Banking: covering the conduct of retail banking operations, product suitability, and the bank’s obligations to individual consumers
- UAE Federal laws: including the Commercial Companies Law, the Civil Transactions Law, and financial crime provisions under the UAE Penal Code
Need Expert Advice?
Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.
What a UAE Bank Internal Audit Programme Should Cover
Credit Risk and Lending Controls
Credit risk is typically the largest risk category in a UAE bank’s risk profile. Internal audit reviews the bank’s credit origination processes, credit assessment methodologies, credit committee governance, documentation completeness for facilities approved, and compliance with the bank’s own credit policy. It also reviews the accuracy of loan classification and provisioning, assessing whether non-performing loans are being identified and provided for in line with IFRS 9 and CBUAE guidance.
AML Compliance
AML internal audit in a UAE bank examines whether the Compliance Officer’s programme is functioning as designed, not merely whether policies exist. The audit reviews a sample of customer onboarding files to assess CDD quality, examines the transaction monitoring system’s alert logic and investigation quality, reviews STR files to confirm that reporting decisions are appropriately documented, and tests whether the bank’s risk rating methodology is consistent and current. Given the extended personal liability of MLROs under FDL No. 10 of 2025, the quality of the internal audit function’s AML coverage directly affects the bank’s regulatory exposure.
Consumer Protection and Complaints Management
Under the CBUAE Consumer Protection Standards, banks must maintain a formal complaints management function, acknowledge complaints within defined timelines, and provide substantive responses within 30 calendar days. Internal audit reviews whether the complaints function is adequately resourced, whether complaints are being resolved within the required timelines, whether unresolved complaints are escalating to the CBUAE Consumer Protection Department where required, and whether complaint data is being analysed for systemic issues that require management action.
Treasury and Market Risk Controls
For banks with significant treasury operations, internal audit reviews the controls over market risk positions, whether trading limits are being observed and breaches are being reported promptly, the quality of the valuation methodology for financial instruments, and the accuracy of the bank’s market risk reporting to the CBUAE.
IT and Cybersecurity Controls
UAE banks are increasingly targeted by cyber threats, and the CBUAE has issued specific guidance on information security governance. Internal audit reviews access controls to core banking systems, the bank’s vulnerability management programme, the effectiveness of its business continuity arrangements, and whether the IT control environment is consistent with the CBUAE’s Information Technology Risk Management Standards.
Financial Reporting Controls
Internal audit reviews the controls over financial reporting, including the general ledger integrity, month-end close processes, accuracy of regulatory financial submissions to the CBUAE, and the adequacy of IFRS 9 expected credit loss models and their governance. The accuracy of the bank’s financial statements directly affects the Corporate Tax position under Federal Decree-Law No. 47 of 2022, making financial reporting controls relevant to both regulatory and tax compliance.
Independence and Reporting in UAE Bank Internal Audit
The CBUAE’s standards require the internal audit function of a UAE bank to be independent of the activities it audits. The Head of Internal Audit must report directly to the Board Audit Committee, not to executive management. The Audit Committee must have the authority to direct the internal audit programme, approve the internal audit charter, and receive internal audit reports without management filtering or interference.
This reporting line requirement is more stringent than what applies in most non-banking businesses. It reflects the systemic importance of banking sector internal audit in the UAE’s broader financial stability framework. A bank whose internal audit function reports to the CFO or CEO rather than the Audit Committee is in breach of CBUAE requirements.
Technology and Data Analytics in UAE Bank Internal Audit
The volume and complexity of transaction data in a UAE bank makes traditional sample-based testing increasingly inadequate for the highest-risk audit areas. Modern bank internal audit functions use data analytics to examine entire transaction populations rather than samples, running automated tests to identify outliers, duplicate payments, threshold manipulation, and patterns inconsistent with a customer’s expected activity. In AML audit specifically, the ability to analyse the complete population of transaction monitoring alerts and test whether alert thresholds are appropriately calibrated requires data analytics capability that goes beyond manual workpaper review.
A Governance, Risk, and Compliance (GRC) platform that centralises audit workflows, tracks findings remediation, and maps controls across regulatory frameworks allows the internal audit function to demonstrate to the CBUAE that its programme is comprehensive, current, and integrated with the bank’s wider risk management framework.
Also Check: Internal Audit Services
Frequently Asked Questions (FAQs)
What regulatory body governs internal audit requirements for UAE banks?
Who must the Head of Internal Audit report to in a UAE bank?
What AML obligations must UAE bank internal audit cover?
How does UAE bank internal audit differ from general corporate internal audit?
What role does data analytics play in UAE bank internal audit?
Need Expert Advice?
Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.
How Farahat & Co. Can Help
Farahat & Co. provides internal audit services to UAE banks and financial institutions, covering AML compliance audit, consumer protection controls, credit risk audit, financial reporting controls, and regulatory compliance assessments against CBUAE prudential standards. Our team conducts internal audit engagements in accordance with the CBUAE’s Standards for Internal Audit Function of Licensed Financial Institutions and the International Standards for the Professional Practice of Internal Auditing.
Contact Farahat & Co. today to discuss your bank internal audit requirements.
