UAE Central Bank IT Audit: The Complete Guide for UAE-Based Banks
For a bank operating in the United Arab Emirates, an IT audit is much more than a review of firewalls and antivirus software. The Central Bank of the UAE (CBUAE) expects banks to demonstrate strong governance, secure technology, operational resilience, reliable internal controls, and effective cybersecurity.
This guide explains the main areas covered by a UAE Central bank IT Audit for UAE based Bank, what regulators and auditors typically examine, and how physical infrastructure monitoring: including AKCP: can support audit evidence and business continuity.
Important: Regulatory requirements may change. Banks should always confirm the latest CBUAE Rulebook, circulars, regulations, and supervisory instructions with qualified compliance and legal professionals.
What is a UAE Central Bank IT audit?
A CBUAE IT audit is a structured assessment of whether a bank’s technology environment is secure, reliable, governed, and capable of supporting critical banking services.
The audit may be performed by internal audit, external auditors, specialist cybersecurity firms, or supervisory teams. It normally forms part of a wider risk-based audit programme approved by the Board or Board Audit Committee.
The audit looks at both:
- Technology controls: systems, applications, networks, cloud services, databases, access, logging, and security tools.
- Governance and operating controls: policies, accountability, risk management, vendor oversight, incident response, business continuity, and evidence of management review.
The CBUAE Rulebook includes requirements related to internal audit, internal controls, information security, technology risk, operational risk, and testing. Banks must translate these requirements into practical controls and maintain evidence that those controls operate effectively.
The main CBUAE requirements banks should understand
1. Independent and risk-based internal audit
A bank should have an independent internal audit function with:
- A Board-approved internal audit charter
- Clear reporting to the Board Audit Committee
- Adequate authority, resources, and skilled personnel
- A documented risk-based annual audit plan
- Defined coverage of IT, cybersecurity, data, cloud, and third-party risks
- Formal tracking and closure of audit findings
Internal audit should not simply confirm that policies exist. It should test whether controls work in practice and whether identified weaknesses are remediated within agreed deadlines.
The CBUAE Internal Audit Regulation and Standards should be reviewed when designing the audit methodology.
2. Internal control and segregation of duties
The CBUAE internal control framework focuses on accountability, checks and balances, and protection of assets. In an IT environment, auditors commonly examine:
- Separation between development, testing, approval, and production deployment
- Dual control for sensitive transactions and privileged changes
- Independent administration of security tools
- Access approval and periodic access recertification
- Joiner, mover, and leaver processes
- Protection of servers, network devices, databases, and backup media
- Evidence of management review and exception handling
A single administrator with unrestricted access to production systems, security logs, and audit records creates a serious control weakness. Banks should use role-based access, privileged access management, multi-factor authentication, and independent review.
3. Cybersecurity governance and risk management
Cybersecurity must be managed as an enterprise risk, not only as an IT department responsibility. A CBUAE IT audit may review whether the bank has:
- A Board-approved cybersecurity policy
- A defined cyber-risk appetite
- A named CISO or equivalent security leader
- A current cyber-risk register
- Asset classification and ownership
- Threat intelligence and vulnerability management
- Security awareness training
- Security metrics reported to senior management
- Documented exceptions and risk acceptance approvals
The CBUAE Cybersecurity Regulation and the CBUAE cyber-risk and operational-resilience expectations provide important reference points for banks.
What regulators and auditors typically check
Identity and access management
Access control is one of the most important areas of a bank’s IT security audit. Auditors may request evidence of:
- Multi-factor authentication for critical applications and remote access
- Privileged access management
- Strong password and authentication policies
- Quarterly or periodic access reviews
- Timely removal of terminated-user access
- Controlled service accounts
- Monitoring of administrator activity
- Segregation of duties for sensitive banking operations
The auditor will often compare the approved access list with actual system privileges. Any unexplained access should be investigated and documented.
Network and infrastructure security
Banks are expected to protect critical systems through layered controls. The review may include:
- Network segmentation between user, server, database, payment, and management zones
- Firewalls and secure configuration baselines
- Intrusion detection and prevention
- Secure remote access
- Endpoint protection
- Network device hardening
- Secure wireless configuration
- DNS, email, and web security
- Monitoring of unusual traffic and unauthorised connections
A network audit should also identify unsupported devices, unpatched systems, weak configurations, single points of failure, and undocumented connections.
Vulnerability assessment and penetration testing
Testing must be planned, documented, and followed by remediation. Depending on the bank’s risk profile and applicable CBUAE requirements, auditors may expect evidence of:
- Internal and external vulnerability scanning
- Web and mobile application security testing
- Network penetration testing
- Configuration reviews
- Secure code assessment
- Annual or periodic independent testing
- Risk-rated remediation plans
- Retesting after critical findings are closed
The CBUAE Audit and Testing requirements should be considered when developing the bank’s annual testing schedule.
A test report alone is not enough. Auditors want to see ownership, deadlines, management escalation, and proof that the weakness was actually corrected.
Data protection and encryption
Banks manage highly sensitive customer, payment, financial, and identity data. The audit should cover:
- Data classification and ownership
- Encryption at rest and in transit
- Encryption-key management
- Data loss prevention
- Database activity monitoring
- Backup protection
- Secure data disposal
- Cloud data controls
- Retention and deletion requirements
- Data-sharing and third-party arrangements
Where cloud services are used, the bank should be able to explain where data is stored, who can access it, how it is encrypted, and how the bank will obtain evidence from the cloud provider.
The CBUAE Guidelines for Financial Institutions Adopting Enabling Technologies are relevant for banks using cloud, AI, analytics, and other technology platforms.

IT security audit checklist for UAE-based banks
Use the following checklist as a starting point for a UAE Central bank IT Audit for UAE based Bank:
Governance
- Is the IT audit charter approved by the Board Audit Committee?
- Is the internal audit function independent?
- Does the annual plan cover IT and cyber risks?
- Are risk owners and escalation procedures clearly defined?
- Are audit findings tracked to closure?
Technology risk
- Is there a current technology and cybersecurity risk register?
- Are critical systems and assets identified?
- Are unsupported systems tracked and addressed?
- Are changes approved, tested, and reviewed?
- Are cloud and AI risks included in the assessment?
Access management
- Is MFA enabled for critical and privileged access?
- Are privileged accounts monitored?
- Are access reviews completed on schedule?
- Is leaver access removed promptly?
- Are service accounts controlled and documented?
Security operations
- Are security logs centrally collected and protected?
- Are alerts monitored and investigated?
- Are vulnerability scans and penetration tests performed?
- Are security patches managed according to risk?
- Are incident-response procedures tested?
Resilience and continuity
- Are backups protected from ransomware?
- Are recovery time and recovery point objectives defined?
- Are disaster-recovery exercises documented?
- Are critical suppliers included in continuity planning?
- Is physical data-centre availability monitored?
Third-party risk
- Has each critical vendor undergone due diligence?
- Do contracts include security, confidentiality, incident-reporting, and audit rights?
- Are outsourced services reviewed regularly?
- Can the bank obtain evidence from cloud and technology providers?
- Are supplier risks reported to management?
How AKCP monitoring supports CBUAE audit readiness
Cybersecurity tools protect the logical environment, but banks must also protect the physical infrastructure that keeps systems available.
A cooling failure, water leak, UPS battery problem, power fluctuation, or unauthorised cabinet opening can interrupt critical banking services. This is why environmental and infrastructure monitoring should be included in a bank’s resilience and data-centre audit programme.

AKCP solutions can help banks monitor:
- Temperature and humidity
- Rack-level thermal conditions
- Water leaks
- Smoke and air quality
- Power availability and electrical conditions
- UPS and battery status
- Cabinet doors and physical access
- Airflow and pressure
- Environmental trends and alarm events
AKCP does not replace a CBUAE audit, cybersecurity framework, penetration test, or internal control programme. Instead, it can provide useful operational evidence that supports availability, physical security, incident response, and business continuity controls.
For example, when an auditor asks how the bank detects abnormal server-room conditions, the IT team can provide:
- Sensor configuration records
- Alarm thresholds and escalation rules
- Historical temperature and humidity reports
- Power and battery event logs
- Door-access alerts
- Incident tickets linked to environmental alarms
- Evidence of monitoring tests and maintenance
This helps move the bank from “we monitor the data centre” to “here is the evidence showing what was monitored, when an exception occurred, who responded, and how it was resolved.”

Why battery and power monitoring matter
A bank may have excellent firewalls and redundant servers, but a failed UPS battery can still cause a serious outage.
Battery monitoring helps identify:
- Weak or failing battery cells
- Abnormal voltage
- Battery temperature changes
- Loss of backup availability
- Degradation before a planned maintenance window
Power monitoring can also help IT and facilities teams understand load, identify abnormal consumption, and improve energy efficiency. Better visibility supports sustainability goals while reducing the risk of unexpected downtime.
A practical preparation plan for CIOs and IT Heads
Start preparing at least several months before the audit:
- Map requirements to controls. Link CBUAE requirements to policies, procedures, systems, and control owners.
- Build an evidence register. Record what evidence exists, where it is stored, its owner, and its review frequency.
- Run a readiness assessment. Identify gaps in access, logging, patching, vendor management, resilience, and physical monitoring.
- Prioritise critical findings. Address weaknesses that could affect customer data, payment services, availability, or regulatory reporting.
- Test your response. Conduct incident-response, disaster-recovery, backup-restoration, and environmental-alarm exercises.
- Report clearly to leadership. The Board should understand the bank’s most important technology risks, not only the number of open findings.
Final thoughts
A successful UAE Central Bank IT audit depends on more than producing documents. It requires a working control environment that protects data, systems, people, facilities, and customers.
For UAE-based banks, the strongest approach combines independent internal audit, effective cybersecurity, secure cloud and third-party governance, tested resilience, and continuous data-centre visibility.
If you need guidance on a UAE Central bank IT Audit for UAE based Bank, an IT security audit checklist, cybersecurity, cloud security, network audit, data-centre audit, or AKCP monitoring for your bank, contact Shelesh for guidance.
Nicholas Barrowclough #ServerRoom #datacenter #serverroom #monitoring #uptime #modbus #remotemanagement #datacenterPUE #datacenteroperations #datacenterhealth #ThermalOptimization #uptime