Jurisdiction · United Arab Emirates

Sovereignty here is not
a preference. It is a
location requirement.

The Central Bank requires the Master System of Record holding all Confidential Data to be continuously maintained and stored within the UAE. Every architecture that puts it somewhere else spends the rest of its life explaining why.

§ 01

The record stays. Everything else is a submission.

CBUAE OUTSOURCING — ARTICLE 6 — WITHIN THE UAE MASTER SYSTEM OF RECORD ALL CONFIDENTIAL DATA · ART. 6.1 CONTINUOUSLY MAINTAINED AND STORED. OWNERSHIP PERPETUAL · ART. 6.5 CENTRAL BANK INSPECTION ON REQUEST TO CROSS 1 · CENTRAL BANK APPROVAL 2 · EXPLICIT WRITTEN CUSTOMER CONSENT 3 · CUSTOMER ACKNOWLEDGES THE DATA MAY BE REACHED BY FOREIGN LEGAL PROCESS ART. 6.3 — AND JURISDICTIONS WHOSE SECRECY LAWS BLOCK SUPERVISORY ACCESS ARE EXCLUDED · ART. 6.6 FIG. — DEPLOYED INSIDE THE BANK, THE DASHED ARROW IS NEVER DRAWN. THERE IS NO CROSSING TO APPROVE, CONSENT TO, OR DISCLOSE.

A foreign branch may hold a daily-refreshed copy instead, with Central Bank approval (Art. 6.2). Providers must sit in jurisdictions offering the same standard of safeguarding (6.4), and the institution remains accountable for everything a provider does. Self-hosted inside the perimeter does not answer these requirements well. It removes the question.

§ 02

And the AI guideline already landed. In 2021.

The Guidelines for Financial Institutions Adopting Enabling Technologies have been in force since November 2021. Institutions still treating AI governance as a forthcoming obligation are already four years into one.

Five-year audit trail
Audit logs and traceability of decisions and outcomes, design documentation, records of every version including code, and the original datasets used to develop, re-train or calibrate the model — retained a minimum of five years. That is not a logging requirement. It is a requirement that the record still means something in year five. Clause 3.97.
No black box
Material models must be reliable, transparent and explainable; technical processes and decisions easily interpreted and explained. A conclusion nobody can reconstruct is not evidence of a decision, whatever it is stored in. Clauses 2.27, 3.98.
Independent validation
Rigorous, independent validation and testing before deployment; periodic post-deployment review including fairness and unintentional bias. Independent means the record must hold up for someone who did not build it. Clauses 3.102, 3.106.
Version records
Robust versioning, with each version's new data, revised documentation, algorithm changes, variable modifications and expected outcomes recorded. The version history is the only thing that lets a five-year-old decision be re-derived rather than re-asserted. Clause 3.108.
Accountable regardless
The institution always remains responsible and accountable for the actions of an outsourcing service provider, and access must be controlled, monitored, reviewed and audited by internal control functions and regulators. A vendor's assurance transfers no accountability. Clause 3.96.
§ 03

Four people, one record.

Governing body
Accountable for the outcomes and decisions of AI applications, including those deciding autonomously, under a documented framework it has approved. Needs to know what was deployed, on whose approval, and on what basis. Clauses 3.94, 3.95, 3.115.
Model owner
Holds the design documentation, the data-quality position, the assumptions and their justifications, and the versioning record. Needs those produced as the work happens, not assembled ahead of a review. Clauses 3.99, 3.103, 3.108.
CISO · cloud owner
Materiality assessment, due diligence covering data-centre locations, contracts carrying audit rights for internal functions and regulators, and security and penetration testing at least annually. Clauses 3.24, 3.31–3.34, 3.61.
Internal audit
Formal independent review, at a frequency set by materiality, with the expertise to assess the control environment rather than accept a description of it. Needs a record it can verify without relying on the function that produced it. Clauses 2.2, 2.3.
§ 04

Where these claims stop.

The boundaries on the main page apply here without amendment. Three more are specific to this jurisdiction.

Mapping is not approval
Obligations from published CBUAE regulations, standards and guidelines are represented as controls. Nothing here is endorsed, reviewed or approved by the Central Bank of the UAE, and no representation is made that it has been.
Not model assurance
Deployment inside the institution answers a data-location requirement. It does not establish that a model is accurate, fair or fit for purpose — that determination rests on validation and testing the institution performs.
Not advice
Nothing here substitutes for the institution's own reading of the Rulebook. Clause references are to the text as published at the date below; where our reading and yours differ, yours governs.

SOURCES — CENTRAL BANK OF THE UAE RULEBOOK:
Outsourcing Regulation for Banks — Article 6, Outsourcing Outside the UAE
Guidelines for Financial Institutions Adopting Enabling Technologies, 15 November 2021, in force

§ 05 · Begin

Bring the model you would least like to re-derive in year five.

A diligence call covers where the Master System of Record sits, what the five-year retention obligation actually requires, and what the evidence does and does not establish. Thirty minutes. With the founder.