Regulatory clocks. What is due, by when, from now.
Two clocks that started this year. The incident notification timeline under the CBUAE Operational Risk Management Regulation, in force from 14 September 2026, and the e-invoicing wave your revenue places you in. Times are computed in your browser from your own clock.
| Who | Appoint ASP by | Live by |
|---|---|---|
| Pilot and voluntary | 1 July 2026 (opened) | 1 July 2026 |
| Revenue of AED 50 million or more | 30 October 2026 | 1 January 2027 |
| Revenue below AED 50 million | 31 March 2027 | 1 July 2027 |
| Government entities | 31 March 2027 | 1 October 2027 |
Two clocks, read straight from the instruments.
- Incident notification. From the detection time, the calculator adds 4 hours (notify, naming the Critical Operations affected), 24 hours (summary of nature, actions, impact and time to normal) and, where the Board's high-risk criteria are met, 72 hours (incident report). Return to normal operations triggers a further notification with no fixed clock. A significant deviation from appetite, policy or tolerance for disruption is reported promptly. Each deadline is shown with the time remaining or the time overdue against your browser's clock.
- E-invoicing wave. Revenue at or above AED 50 million places a business in wave one; below it, wave two; government entities have their own dates. The days remaining are counted to midnight at the start of each deadline date in your local time.
Sources: CBUAE Operational Risk Management Regulation, Circular 1 of 2026, Article 15, effective 14 September 2026; UAE Ministry of Finance, Ministerial Decision 244 of 2025 (roll-out and thresholds) and Ministerial Decision 243 of 2025 (scope and exclusions). Riskweise articles: Operational resilience under the 2026 regulation and Electronic invoicing in the UAE.
The two regulations, asked and answered.
What are the incident notification deadlines under the CBUAE Operational Risk Management Regulation?
Article 15 of Circular 1 of 2026, effective 14 September 2026, sets four clocks. Within 4 hours of an event that significantly affects Critical Operations, is likely to trigger the business continuity or disaster recovery plan, or materially affects customers, operations, profit or capital, the institution notifies the Central Bank and names the Critical Operations affected. Within 24 hours it provides a summary of the nature of the event, the actions taken, the impact and the expected time to return to normal. On return to normal operations it notifies the Central Bank again. Separately, any high-risk incident, as defined by criteria the Board sets in policy, is reported within 72 hours. A significant deviation from Board-approved appetite, policy or tolerance for disruption must be reported promptly.
Does the 4-hour clock start at the incident or at its detection?
The regulation frames the obligation around the event. In practice the defensible position is to run the clock from the moment the institution became aware, and to keep the detection timestamp as evidence, because a supervisor will ask when the event started, when it was detected, and why the gap between the two was what it was. The calculator takes the detection time as its input and labels it that way. An institution whose monitoring detects incidents late has a detection problem, not a notification problem, and Article 7 expects the notification path to have been rehearsed.
Which e-invoicing wave is my business in?
Under Ministerial Decision 244 of 2025, businesses with annual revenue of AED 50 million or more must appoint an accredited service provider by 30 October 2026 and issue e-invoices from 1 January 2027. Businesses below AED 50 million appoint by 31 March 2027 and go live on 1 July 2027. Government entities appoint by 31 March 2027 and go live on 1 October 2027. The pilot and voluntary phase opened on 1 July 2026. The first appointment deadline was extended from 31 July 2026 after the Ministry of Finance guidelines were published; the go-live date did not move.
Are banks and financial institutions excluded from e-invoicing?
Not at entity level. The exclusion in Ministerial Decision 243 of 2025 applies to supplies of financial services that are exempt from VAT under Article 42 of the VAT Executive Regulation. Standard-rated financial services supplied to resident customers stay in scope, so a bank has to classify its revenue line by line rather than assume it is out. The scope test is doing business in the UAE regardless of VAT registration status.
Is the 4-hour path rehearsed?
Critical Operations register, Board tolerance for disruption, the report on internal control, and a notification path that has been tested before it is needed.
Talk to us