The UAE's New SME Banking Rules Reach Far Beyond Disclosure
The UAE's new SME customer-protection regime is now in force. The bigger change is not another disclosure requirement: it pushes SME protection into product design, fees, account opening, complaints, data governance and board oversight.
The important change is not a new brochure standard. CBUAE's replacement regime now treats SME protection as a governance and operating-system issue for banks and finance companies, reaching product design, sales conduct, fees, account opening, complaints, customer data and responsible lending.
A small-business banking rule has become a board-level issue.
Since September 13, the Central Bank of the UAE's Small to Medium Sized Enterprises Customer Protection Regulation, C 2/2026, has been in force, replacing the SME Market Conduct Regulation introduced in 2021.
The headline sounds narrow. The operating impact is not.
The new framework applies to banks and finance companies licensed by the Central Bank when they provide financial products or services to SME customers. It keeps familiar themes such as disclosure and responsible financing, but pushes them into a more explicit customer-protection architecture built around governance, product suitability, complaints, data handling and management accountability.
That is a material change because it moves compliance closer to how SME products are designed and run, not only how they are explained at the point of sale.
Product design is part of customer protection
The regulation places direct responsibility on boards and senior management to establish governance around the design, development, promotion, sale and distribution of products and services offered to SME customers.
That matters because it changes the compliance question.
A bank cannot treat a problem purely as a frontline-sales issue if the underlying product was designed badly for the customer segment. The regulation requires institutions to assess suitability, adapt their treatment to different SME categories and prevent abusive sales, marketing and pricing practices.
It also prohibits tied selling and bundling where the sale of one financial product or service is conditioned on another.
For SME customers, that is more consequential than another disclosure form. It reaches the commercial architecture of the relationship.
Account opening gets a measurable clock
The new regime also puts a measurable clock on some SME account-opening cases.
Where an institution assesses an applicant as presenting low money-laundering and terrorist-financing risk and is satisfied with the standard customer due-diligence documentation, the account-opening process must be completed within three business days from the completed request.
Financial-crime compliance can override that deadline, but the institution must document the reason for the exception, report it to senior management and inform the customer in writing. Institutions must also track account-opening applications and cases where the three-business-day requirement was not met.
Fees get a proportionality test
The regulation also puts more explicit pressure on fees.
Financial institutions must ensure fees are fair, reasonable and proportionate. The rule says institutions should consider both the cost borne by the institution and the size and financial capacity of the SME customer. Institutions must provide fee schedules in writing and comply with any Central Bank caps.
There is also a notable restriction: institutions should not charge customers for activities that the institution needs to perform because of its own legal compliance obligations, such as updating identification-document details.
The practical effect will depend on implementation and supervision. The rule does not publish a universal price list for SME banking. It creates a standard against which pricing and fee practices can be assessed.
That shifts some conduct questions from "was the fee disclosed?" to "was the fee reasonable and proportionate in the first place?"
Complaints become an independent function
The complaint rules are similarly operational.
Banks and finance companies must provide an accessible complaint process free of charge. More importantly, they must establish an independent complaints-management function that reports directly to senior management and is empowered to resolve complaints independently of other business operations.
The timetable is also explicit: institutions must acknowledge a complaint in writing within two business days and provide a final written response within 30 business days, unless the Central Bank prescribes another time limit.
Complaint data is not meant to sit in a service queue. Institutions are expected to use it to identify trends, investigate root causes and build new controls.
The Central Bank can also require reporting on complaint data, fee schedules and the financial products and services offered to SME customers.
That creates a feedback loop between individual customer problems and supervisory data.
Data protection gets its own organizational responsibility
C 2/2026 also makes data governance more explicit.
Financial institutions must collect only the minimum amount of customer data needed for their licensed activities and establish a function responsible for data management and protection. Significant data-management violations and breaches must be reported internally to senior management and the board.
For a market moving rapidly toward automated onboarding, AI-assisted underwriting and data-driven customer service, that detail matters.
The regulation is not an AI rule. But it raises the governance baseline around the data that automated systems depend on.
Responsible financing remains a hard boundary
The new framework keeps a clear responsible-financing obligation.
Institutions must assess an SME's ability to service credit, examine credit records and avoid granting or extending credit without a written request from the customer. They must also monitor credit-granting and sales representatives for inappropriate activity.
That is a useful reminder that "access to finance" and "more credit" are not the same objective.
The Central Bank states that the regulation is intended both to protect SMEs and to enhance access to financial products and services. The mechanism is not simply to increase lending. It is to improve the conditions under which financial products are offered and managed.
The real test starts with implementation
The old SME Market Conduct Regulation has been cancelled and replaced by the new regime.
September 13 was a clean regulatory state change, but not the end of the story.
The important evidence will come from implementation: revised product governance, fee practices, bilingual disclosures, complaints structures, data controls and the way institutions handle SMEs in financial difficulty.
For businesses, the most useful change may be that several issues previously experienced as "bank policy" now sit inside a more detailed regulatory framework.
For banks and finance companies, the burden moves in the opposite direction. They will need to demonstrate that customer protection is not confined to a disclosure checklist.
It has to be visible in the product, the process and the governance around both.
The 2021 SME Market Conduct Regulation already set expectations around disclosure, responsible conduct, financing and complaints.
Since September 13, C 2/2026 has replaced that regime with a Customer Protection Regulation tied to the newer Central Bank law and a broader governance, data-protection and board-accountability framework.
Banks and finance companies now need to show how the requirements operate in practice: account opening, fee setting, product suitability, complaint independence, data minimization, staff controls and reporting to the Central Bank.
Show the record behind the claim.
Claims stay source-linked, with limits recorded.
The regulatory change and requirements are established by the Central Bank of the UAE Rulebook. The sources confirm the legal framework and effective date, but do not establish how consistently individual banks and finance companies have implemented the requirements in practice.
Material reporting is designed to retain the evidence behind the published claim.
Companies, regulators and projects can link back to persistent records.
Automation can assist discovery and extraction; publication authority remains editorial.
Open the evidence record.
5 linked sourcesSupport + limitations recorded.
01Core evidenceCBUAE Rulebook - SME Customer Protection Regulation
Central Bank of the UAE
+
CBUAE Rulebook - SME Customer Protection Regulation
Central Bank of the UAE
Establishes scope, effective date, cancellation of the 2021 regime, objectives, reporting and sanctions.
Does not show how individual banks have implemented the rules in practice.
02Core evidenceCBUAE Rulebook - Responsible Conduct
Central Bank of the UAE
+
CBUAE Rulebook - Responsible Conduct
Central Bank of the UAE
Establishes suitability, anti-abusive-sales, tied-selling, fee, switching and qualifying low-risk account-opening requirements, including the three-business-day rule.
Does not establish that any named bank previously breached these standards.
03Core evidenceCBUAE Rulebook - Complaint Management and Resolution
Central Bank of the UAE
+
CBUAE Rulebook - Complaint Management and Resolution
Central Bank of the UAE
Establishes free complaint access, an independent complaints-management function, written acknowledgment within two business days and a final written response within 30 business days.
Does not establish how quickly every complaint will be resolved.
04Core evidenceCBUAE Rulebook - Customer Data Protection
Central Bank of the UAE
+
CBUAE Rulebook - Customer Data Protection
Central Bank of the UAE
Establishes data minimization and dedicated data-management responsibilities.
Does not create a separate AI-specific regulatory regime.
05ContextCBUAE Rulebook - 2021 SME Market Conduct Regulation
Central Bank of the UAE
+
CBUAE Rulebook - 2021 SME Market Conduct Regulation
Central Bank of the UAE
Shows the previous C 1/2021 SME Market Conduct framework and its transition notice that C 2/2026 would replace it on September 13.
The legacy page still displays "Status: In-Force"; the current cancellation is established by C 2/2026 Article 10 rather than that legacy status label.
The story keeps moving.
Watch for bank implementation notices, changes to SME terms, fee schedules, account-opening flows and complaint processes, plus Central Bank reporting requirements and early supervisory or enforcement signals under the new regime.
