ARABIAN CURRENTUAEREPORTING

The UAE's New SME Banking Rules Reach Far Beyond Disclosure

The UAE's new SME customer-protection regime is now in force. The bigger change is not another disclosure requirement: it pushes SME protection into product design, fees, account opening, complaints, data governance and board oversight.

Published 16 Sept 2026 · 17:31 GST5 min readHigh significance
FEATURE IMAGEUAE
Two banking professionals meeting in a Dubai office overlooking the skyline
KEY TAKEAWAY

The important change is not a new brochure standard. CBUAE's replacement regime now treats SME protection as a governance and operating-system issue for banks and finance companies, reaching product design, sales conduct, fees, account opening, complaints, customer data and responsible lending.

A small-business banking rule has become a board-level issue.

Since September 13, the Central Bank of the UAE's Small to Medium Sized Enterprises Customer Protection Regulation, C 2/2026, has been in force, replacing the SME Market Conduct Regulation introduced in 2021.

The headline sounds narrow. The operating impact is not.

The new framework applies to banks and finance companies licensed by the Central Bank when they provide financial products or services to SME customers. It keeps familiar themes such as disclosure and responsible financing, but pushes them into a more explicit customer-protection architecture built around governance, product suitability, complaints, data handling and management accountability.

That is a material change because it moves compliance closer to how SME products are designed and run, not only how they are explained at the point of sale.

Product design is part of customer protection

The regulation places direct responsibility on boards and senior management to establish governance around the design, development, promotion, sale and distribution of products and services offered to SME customers.

That matters because it changes the compliance question.

A bank cannot treat a problem purely as a frontline-sales issue if the underlying product was designed badly for the customer segment. The regulation requires institutions to assess suitability, adapt their treatment to different SME categories and prevent abusive sales, marketing and pricing practices.

It also prohibits tied selling and bundling where the sale of one financial product or service is conditioned on another.

For SME customers, that is more consequential than another disclosure form. It reaches the commercial architecture of the relationship.

Account opening gets a measurable clock

The new regime also puts a measurable clock on some SME account-opening cases.

Where an institution assesses an applicant as presenting low money-laundering and terrorist-financing risk and is satisfied with the standard customer due-diligence documentation, the account-opening process must be completed within three business days from the completed request.

Financial-crime compliance can override that deadline, but the institution must document the reason for the exception, report it to senior management and inform the customer in writing. Institutions must also track account-opening applications and cases where the three-business-day requirement was not met.

Fees get a proportionality test

The regulation also puts more explicit pressure on fees.

Financial institutions must ensure fees are fair, reasonable and proportionate. The rule says institutions should consider both the cost borne by the institution and the size and financial capacity of the SME customer. Institutions must provide fee schedules in writing and comply with any Central Bank caps.

There is also a notable restriction: institutions should not charge customers for activities that the institution needs to perform because of its own legal compliance obligations, such as updating identification-document details.

The practical effect will depend on implementation and supervision. The rule does not publish a universal price list for SME banking. It creates a standard against which pricing and fee practices can be assessed.

That shifts some conduct questions from "was the fee disclosed?" to "was the fee reasonable and proportionate in the first place?"

Complaints become an independent function

The complaint rules are similarly operational.

Banks and finance companies must provide an accessible complaint process free of charge. More importantly, they must establish an independent complaints-management function that reports directly to senior management and is empowered to resolve complaints independently of other business operations.

The timetable is also explicit: institutions must acknowledge a complaint in writing within two business days and provide a final written response within 30 business days, unless the Central Bank prescribes another time limit.

Complaint data is not meant to sit in a service queue. Institutions are expected to use it to identify trends, investigate root causes and build new controls.

The Central Bank can also require reporting on complaint data, fee schedules and the financial products and services offered to SME customers.

That creates a feedback loop between individual customer problems and supervisory data.

Data protection gets its own organizational responsibility

C 2/2026 also makes data governance more explicit.

Financial institutions must collect only the minimum amount of customer data needed for their licensed activities and establish a function responsible for data management and protection. Significant data-management violations and breaches must be reported internally to senior management and the board.

For a market moving rapidly toward automated onboarding, AI-assisted underwriting and data-driven customer service, that detail matters.

The regulation is not an AI rule. But it raises the governance baseline around the data that automated systems depend on.

Responsible financing remains a hard boundary

The new framework keeps a clear responsible-financing obligation.

Institutions must assess an SME's ability to service credit, examine credit records and avoid granting or extending credit without a written request from the customer. They must also monitor credit-granting and sales representatives for inappropriate activity.

That is a useful reminder that "access to finance" and "more credit" are not the same objective.

The Central Bank states that the regulation is intended both to protect SMEs and to enhance access to financial products and services. The mechanism is not simply to increase lending. It is to improve the conditions under which financial products are offered and managed.

The real test starts with implementation

The old SME Market Conduct Regulation has been cancelled and replaced by the new regime.

September 13 was a clean regulatory state change, but not the end of the story.

The important evidence will come from implementation: revised product governance, fee practices, bilingual disclosures, complaints structures, data controls and the way institutions handle SMEs in financial difficulty.

For businesses, the most useful change may be that several issues previously experienced as "bank policy" now sit inside a more detailed regulatory framework.

For banks and finance companies, the burden moves in the opposite direction. They will need to demonstrate that customer protection is not confined to a disclosure checklist.

It has to be visible in the product, the process and the governance around both.

WHAT CHANGED
BEFORE

The 2021 SME Market Conduct Regulation already set expectations around disclosure, responsible conduct, financing and complaints.

NOW

Since September 13, C 2/2026 has replaced that regime with a Customer Protection Regulation tied to the newer Central Bank law and a broader governance, data-protection and board-accountability framework.

NEXT

Banks and finance companies now need to show how the requirements operate in practice: account opening, fee setting, product suitability, complaint independence, data minimization, staff controls and reporting to the Central Bank.

02 / EVIDENCE & TRANSPARENCY

Show the record behind the claim.

Claims stay source-linked, with limits recorded.

EVIDENCE BOUNDARY

The regulatory change and requirements are established by the Central Bank of the UAE Rulebook. The sources confirm the legal framework and effective date, but do not establish how consistently individual banks and finance companies have implemented the requirements in practice.

01
Primary claimsSource-linked

Material reporting is designed to retain the evidence behind the published claim.

02
Entity contextConnected

Companies, regulators and projects can link back to persistent records.

03
Editorial statusHuman review

Automation can assist discovery and extraction; publication authority remains editorial.

03 / SOURCE LEDGER

Open the evidence record.

5 linked sourcesSupport + limitations recorded.

01
Core evidence

CBUAE Rulebook - SME Customer Protection Regulation

Central Bank of the UAE

RegulatorChecked 16 Sept 2026
SUPPORTS

Establishes scope, effective date, cancellation of the 2021 regime, objectives, reporting and sanctions.

DOES NOT PROVE

Does not show how individual banks have implemented the rules in practice.

OPEN ORIGINAL SOURCE ↗
02
Core evidence

CBUAE Rulebook - Responsible Conduct

Central Bank of the UAE

RegulatorChecked 16 Sept 2026
SUPPORTS

Establishes suitability, anti-abusive-sales, tied-selling, fee, switching and qualifying low-risk account-opening requirements, including the three-business-day rule.

DOES NOT PROVE

Does not establish that any named bank previously breached these standards.

OPEN ORIGINAL SOURCE ↗
03
Core evidence

CBUAE Rulebook - Complaint Management and Resolution

Central Bank of the UAE

RegulatorChecked 16 Sept 2026
SUPPORTS

Establishes free complaint access, an independent complaints-management function, written acknowledgment within two business days and a final written response within 30 business days.

DOES NOT PROVE

Does not establish how quickly every complaint will be resolved.

OPEN ORIGINAL SOURCE ↗
04
Core evidence

CBUAE Rulebook - Customer Data Protection

Central Bank of the UAE

RegulatorChecked 16 Sept 2026
SUPPORTS

Establishes data minimization and dedicated data-management responsibilities.

DOES NOT PROVE

Does not create a separate AI-specific regulatory regime.

OPEN ORIGINAL SOURCE ↗
05
Context

CBUAE Rulebook - 2021 SME Market Conduct Regulation

Central Bank of the UAE

RegulatorChecked 16 Sept 2026
SUPPORTS

Shows the previous C 1/2021 SME Market Conduct framework and its transition notice that C 2/2026 would replace it on September 13.

DOES NOT PROVE

The legacy page still displays "Status: In-Force"; the current cancellation is established by C 2/2026 Article 10 rather than that legacy status label.

OPEN ORIGINAL SOURCE ↗
How Arabian Current handles sources →
04 / WHAT TO WATCH NEXT

The story keeps moving.

Watch for bank implementation notices, changes to SME terms, fee schedules, account-opening flows and complaint processes, plus Central Bank reporting requirements and early supervisory or enforcement signals under the new regime.

Arabian Current
ARABIAN CURRENT NEWSROOM

Reporting with a visible evidence trail.

Arabian Current reporting is built around human editorial authority, source-linked claims and visible evidence trails.

Author profile →Editorial standards →
CONTINUE THE CURRENT

Related reporting

Open reporting →