Calibrated to GCC central bank frameworks · CBUAE · SAMA · CBB · QCB · CBK · CBO
Governance, risk appetite and policy
How does a Board turn risk appetite into policy that actually binds? The risk appetite statement as a living document, the deep refresh of risk policies, and what a fintech in the DIFC or ADGM needs in place.
3 articles in this topic
Read in this order.
- 18 Sept 2026 The risk appetite statement as a living document — beyond the board binder The CBUAE Risk Management Regulation requires a board-approved RAS with limits for all material risk categories. The FSB 2013 Principles set the international baseline. Supervisors increasingly test the gap between stated appetite and how it actually constrains daily decisions.
- 12 Jun 2026 When risk policies stop protecting — the case for periodic deep refresh Risk policies not substantively updated since before the pandemic are common and increasingly a supervisory concern. Risk vectors have evolved materially. The policies governing them often have not. What a serious refresh covers, and where the gap sits in practice.
- 8 Jun 2026 Risk policies for fintechs — between the framework of a bank and the speed of a product Fintechs in DIFC and ADGM face a structural tension. Copying a bank's risk policies will paralyse the business. Ignoring regulatory frameworks won't survive supervisory dialogue. What right-sized risk governance actually looks like for fintechs and NBFCs at scale.
Where this becomes work