Security Quotient
🏦

CBUAE — General

Overview of Central Bank UAE mandatory training requirements for licensed financial institutions.

What training does the Central Bank of UAE mandate for banks and financial institutions?

The CBUAE mandates training across two broad areas.

The first is financial crime compliance — covering AML/CFT under Federal Decree Law No. 20/2018, sanctions screening under Cabinet Decision 74, customer due diligence, correspondent banking, trade-based money laundering, and tax reporting under FATCA and CRS.

The second is institutional compliance and conduct — covering fraud prevention under Federal Decree Law No. 6/2025, consumer protection, complaints management, operational risk, business continuity, anti-bribery and anti-corruption, and code of conduct under the CBUAE Fitness and Propriety Standards (Circular C 4/2024).

All training must be role-based, documented, and generate audit-ready evidence demonstrating employee comprehension.

To know more, please visit the CBUAE Course Hub.

Are your courses aligned to the CBUAE Rulebook?

Yes. Each course in our UAE library is mapped to specific regulations, circulars, and guidance documents published in the CBUAE Rulebook. For example, our AML/CFT course references Federal Decree Law No. 20/2018, Notice 74/2019, and the Role-Based AML/CFT/CPF Training Best Practices issued in November 2025.

We may not include heavy legalese in the course content in order to reduce the cognitive load of the course on the learners.

To know more, please visit the CBUAE Course Hub.

How many courses do I need to cover all CBUAE training requirements?

Security Quotient maps 17 courses to the CBUAE Rulebook — 8 covering financial crime compliance (Tier 1) and 9 covering institutional compliance and conduct (Tier 2).

Not every course applies to every employee. The CBUAE expects a risk-based, role-specific approach — front-line staff, compliance officers, senior management, and IT teams each have different training obligations.

We can help you identify which courses apply to which roles in your institution.

To know more, please visit the CBUAE Course Hub.

Can we deploy these courses on our own LMS?

Yes. If you'd prefer to run our courses on your own LMS rather than ours, we can licence them to you as SCORM/xAPI packages under a perpetual-use license. If instead you'd like us to host and manage everything for you — on a dedicated, audit-ready platform in your own region — that's our Enterprise plan. Talk to us and we'll help you choose the right fit.

Can courses be customised with our organisation's policies and branding?

Yes. We offer two levels of customisation.

The first is platform-level — your organisation's logo, colours, and a senior leadership welcome message can be applied across the LMS without changing course content. Please note that this feature is only available for Dedicated Instances (See White-labelled LMS)

The second is content-level — internal policies, procedures, or UAE-specific scenarios can be embedded into the learning path. Please note that we do not customise inside the SCORM module itself.

Learning path customisation is available for institutions deploying white-labelled LMS solutions with 5 or more courses.

Speak to our team to discuss the right option for your institution.

Do your courses generate audit-ready compliance evidence?

Yes. Every course completion generates a timestamped record including the employee name, course title, completion date, assessment score, and certificate of completion.

These records are exportable as compliance reports and are formatted to satisfy CBUAE examiner requests. Because our courses include knowledge assessments rather than simple click-through completion, the evidence demonstrates actual comprehension — not just attendance.

To know more, please visit the CBUAE Course Hub.

How often should CBUAE-mandated training be refreshed?

The CBUAE expects annual enterprise-wide AML/CFT/CPF training as a baseline, with additional role-based training triggered by regulatory changes, audit findings, or employees moving into new roles.

As a general rule, financial crime compliance training (AML/CFT, sanctions, CDD) should be refreshed annually. Conduct and governance training (code of conduct, ABAC) is typically refreshed every one to two years.

We recommend reviewing your training calendar whenever the CBUAE issues new guidance or circulars.

To know more, please visit the CBUAE Course Hub.

Are your courses available in Arabic?

English narration is standard across all courses. Arabic narration and translation are available on request for any course in our UAE library. We also support other languages on request. If your institution requires a bilingual deployment — English and Arabic — we can accommodate that within the same LMS instance. Contact our sales team to discuss your language requirements.

To know more, please check our translation feature.

What are the specific Shari’ah governance training requirements for Licensed Financial Institutions?

The CBUAE Shari’ah Governance Framework requires Licensed Financial Institutions (LFIs) offering Islamic financial services to ensure that all relevant staff, including those in support functions, possess a competent understanding of Shari’ah rules and principles. Training must cover the role of the Internal Shari’ah Supervision Committee (ISSC), the boundaries of Shari’ah compliance, and the mandatory nature of Fatwas issued by the Higher Shari’ah Authority (HSA).

How does this course align with the CBUAE Shari’ah Governance Framework and AAOIFI standards?

This course is mapped to the CBUAE Shari’ah Governance Framework (Circular No. 10/2018) and the CBUAE Islamic Banking Standards. It incorporates the Accounting and Auditing Organization for Islamic Financial Institutions (AAOIFI) standards for Shari’ah auditing and governance. Key modules include Shari’ah non-compliance risk management, Islamic product structures (Murabaha, Ijarah, Mudarabah), and the specific disclosure requirements for Islamic windows.

What are the responsibilities of staff regarding Shari’ah non-compliance risk?

Staff must be able to identify potential Shari’ah non-compliance incidents and understand the mandatory escalation process to the Internal Shari’ah Control Department. CBUAE standards dictate that any income derived from Shari’ah non-compliant sources must be identified, recorded, and disposed of to Shari’ah-compliant charities. Training ensures staff can prevent "purification" issues and maintain the integrity of the institution's Islamic license.

How must staff handle the disclosure of Shari’ah-compliant products to consumers?

Under CBUAE Consumer Protection Standards, staff must clearly explain the Shari’ah basis of a product and ensure customers understand that it is distinct from conventional interest-based products. This includes disclosing the specific Fatwa supporting the product and ensuring that all marketing materials have been pre-approved by the ISSC to prevent misleading consumers regarding the product's religious compliance.

Which employees need Islamic Banking training under CBUAE regulations?

Training is required for all employees involved in the design, sale, or processing of Islamic products. This includes front-line relationship managers, product development teams, and legal counsel. Furthermore, control functions such as Internal Audit, Risk Management, and Compliance must receive specialized training to effectively monitor Shari’ah non-compliance risk, as mandated by the CBUAE "Three Lines of Defense" model for Islamic institutions.

Still have questions?

Our success team is ready to assist you with enterprise deployments.