Central Bank of the UAE
The moment you take deposits, move funds, issue a wallet or hold customer float onshore in the UAE, you are inside the Central Bank's perimeter — and it is the strictest in the country. We map your model to the right licence category, structure the capital and controls it demands, and carry the application through to authorisation.
Confidential & non-binding · Same-day response in UAE hours
ACTIVITIES
The Central Bank of the UAE (CBUAE) is the federal authority for banking, monetary policy and the payments system across all of the UAE outside the DIFC and ADGM financial free zones.
It doesn't licence by label; the activities you carry out — taking deposits, lending, exchanging currency, holding float, moving payments or issuing tokens — determine which licence category you fall into, and the heavier the activity, the heavier the capital and scrutiny. Picking the right category, then evidencing the controls behind it, is where most applications succeed or fail.
Accepting deposits and the full banking permission — consumer and corporate lending, wholesale, retail and/or Islamic banking.
Offering retail and/or corporate lending, consumer credit and financing without taking demand deposits.
Currency exchange, cross-border remittance, and wage payments via the WPS — Category A or B.
Operating a customer float in a wallet or prepaid instrument — device-based or account-based.
Payment accounts, cash-in/cash-out, merchant acquiring, aggregation and fund transfer — Category I, II, III or IV under the FTSR.
Issuing, custody and conversion of AED-referenced and foreign payment tokens (stablecoins).
MARKET
The CBUAE sits at the centre of the UAE's monetary system — banking, stored value, retail payments, payment tokens and Open Finance. This is the only regulator that lets you take deposits, hold customer float or move money onshore in the UAE, and the bar is set accordingly.
WHY CBUAE
The UAE has several financial regulators, but they don't overlap where it counts. The free zones (DIFC, ADGM) and VARA cannot license deposit-taking, e-money or onshore payment rails — only the Central Bank can. If your model touches customer money onshore, the CBUAE is the regulator; the only real question is which of its categories. Here's how the perimeters compare.
CAPITAL
The CBUAE sets minimum paid-up capital by licence category, then requires you to hold it — plus risk-based reserves and, for wallets, a capital overlay tied to customer float — on an ongoing basis, not just at filing. Deposit-taking and e-money carry the heaviest requirements; payment services the lightest. Figures are indicative and confirmed per category in scope. Select a licence to see the layers.
*Base capital figures reflect the CBUAE's published frameworks and should be reconfirmed against the current rules for your exact category.
PROCESS
CBUAE authorisation runs in two stages: you earn In-Principle Approval on your business case and controls before you build out, then satisfy the conditions to receive your final licence — so problems surface early, not after you've committed.
We confirm your activities fall within the CBUAE's remit and map them to the correct licence category before a dirham is spent.
Submit the business plan, financial projections, AML/CFT framework, and fit-and-proper disclosures for board and senior management.
The CBUAE reviews the file, holds meetings, and issues In-Principle Approval setting the conditions you must satisfy. No live operations yet.
Establish onshore, secure premises, put systems and controls in place, make key hires and deposit the required paid-up capital.
The CBUAE confirms your board, controls and capital are genuinely in place and every In-Principle condition has been met.
Your licence is issued for your category and permitted activities — and your live supervisory obligations begin.
You're licensed to operate — live supervisory obligations begin from day one.
The four things the CBUAE pushes back on most — and the four we harden before you file.
Boards and senior management without genuine financial-services track record.
Customer float not properly segregated, or the safeguarding model not tested under stress.
Off-the-shelf policies not tailored to your specific licence category and risk profile.
Infrastructure and controls below the CBUAE's technology and resilience expectations.
REQUIREMENTS
The category sets your capital. But authorisation turns on a wider set of requirements — the ones applicants most often underestimate. Here's the full checklist, in the CBUAE's own terms.
A UAE-incorporated company holding the correct commercial licence — for banks, typically a Public/Private Joint Stock Company. Regulated activity must be carried on onshore, outside the DIFC and ADGM free zones.
The paid-up capital for your category, plus risk-based reserves and — for SVF/e-money — segregated customer funds of at least 100% of customer float, often with a bank guarantee. Confirmed per category in scope.
Fit-and-proper controllers and senior management — a UAE-resident General Manager or CEO, plus a Compliance Officer and MLRO. A CISO and dedicated finance function are expected for money and payment firms.
Genuine local substance is expected: a real UAE office, secured as part of satisfying your In-Principle Approval conditions — not a flexi-desk afterthought.
Directors, controllers and key persons must pass the CBUAE's fit-and-proper assessment — competence, experience, financial soundness and integrity.
An adequate governance framework, clear division of responsibility, conflicts-of-interest management and internal controls proportionate to your scale and complexity — evidenced, not asserted.
THE KOLL GROUP DIFFERENCE
Getting the licence is one thing. Staying licensed — with compliance that holds up to supervision and security that holds up to attack — is another. We're the only Dubai advisor that carries all three in-house, so nothing gets handed off and dropped.
We don't coach from the sidelines. We run the whole file — perimeter analysis, entity, capital structuring, the full application and every round of CBUAE questions — through to authorisation.
AML/KYT screening, transaction monitoring and regulatory reporting on our own platform — so the controls you're approved on are the controls you actually run, not a slide deck.
The CBUAE holds technology and cyber resilience to a high bar. Our sister firm ITSEC delivers the penetration testing, cyber controls and audit evidence in-house — a capability no other licensing advisor has.
Three disciplines competitors outsource to three vendors. With KOLL Group it's one engagement, one accountable team — advisory, RegTech and cybersecurity under one roof.
HOW WE HELP
We map your activities to the correct CBUAE licence category and confirm what is — and isn't — in scope before you commit capital or time.
We prepare the business plan, financial projections, AML/CFT policy pack and key-person documentation, defend it through review — then keep you compliant after licensure: AML, KYC, prudential and audit.
The CBUAE expects technology risk and cyber resilience proportionate to your business. As part of ITSEC, we bring penetration testing, CISO and incident-response into the application from day one — where others outsource it later.
LIGHTER PATH
The CBUAE runs several adjacent frameworks alongside its six core categories — and choosing the right entry point can save months and capital. Two sit next to full authorisation, and mistaking one for the other is a common, costly error.
A foreign bank's Representative Office may market and liaise on behalf of its head office in the UAE — it cannot accept deposits or conduct banking business here.
Watch the line: a Representative Office cannot conclude transactions. Cross into deposit-taking or lending and a full banking licence is triggered instead.
Insurance brokers, agents and Open Finance participants sit under adjacent CBUAE-supervised frameworks with different capital and conduct requirements from a full licence category.
Watch the scope: these frameworks are activity-specific — broadening into payments, lending or deposit-taking still requires the matching core category.
OBLIGATION
The CBUAE supervises actively and enforces its rules. Its toolkit escalates with the breach, and includes:
Contested CBUAE decisions are referred to its independent Grievance and Appeal Committee, and onward to the UAE Federal Courts. Staying ahead of obligations is cheaper than answering for them.
Where KOLL takes it from here
Authorisation is one part of the engagement. We also handle regulatory and compliance advisory across the application, RegTech implementation for KYC, transaction monitoring and regulatory reporting, cybersecurity assurance for licensed firms, and ongoing compliance after your licence. Where models touch payments decisioning, see AI governance in UAE regulated activities.
FAQ
It depends on the activities you carry out — the CBUAE licenses by activity, not by label. The six categories run from Banks (deposit-taking) down to Payment Token Services, with dedicated tracks for Finance Companies, Exchange Houses, Stored Value Facilities and Retail Payment Services. We confirm the right category in a perimeter analysis before anything is filed.
The CBUAE is the sole regulator for deposit-taking, e-money, payments and lending onshore; the CMA regulates securities, commodities and capital markets. If your model touches customer money — deposits, wallets or payment rails — you need the CBUAE, not the CMA.
Minimum paid-up capital is set by category, held alongside risk-based reserves and — for wallets — a capital overlay tied to customer float. Licensed banks are AED 2,000,000,000, with specialised banks at AED 300,000 and branches of foreign banks at AED 100,000,000. Finance companies are AED 150,000,000. Payment Token Services and Stored Value Facilities are AED 15,000,000. Retail payment categories start at AED 100,000.
Yes — under the Payment Token Services Regulation (PTSR) 2024, the CBUAE licenses issuance, custody and conversion of AED-referenced and foreign payment tokens. Broader virtual-asset activity outside payment tokens sits with VARA or ADGM instead.
Yes. Genuine local substance is expected: a real UAE office secured as part of satisfying your In-Principle Approval conditions, plus a UAE-resident General Manager or CEO among your senior management.
It varies sharply by category — typically 3–6 months to In-Principle Approval, then a further build-out and review period. Simpler payment categories often complete in 6–9 months end-to-end; full banking licences can take 12–18 months or more.
Yes, but a properly registered UAE entity is a precondition to licensure — typically a Public or Private Joint Stock Company for banks, or a suitable commercial entity for other categories. We structure the UAE entity as part of the application.
COMPARE REGULATORS
Each pathway is advised end to end. Explore the others — or the services that run across them.
The world's first dedicated virtual-asset regulator, covering all of Dubai. Read the guide →
Financial services in the DIFC — common-law, institution-facing, firm-led crypto. Read the guide →
Abu Dhabi's common-law free zone with a pioneering virtual-asset framework. Read the guide →
The federal securities regulator for the onshore UAE capital markets. Read the guide →
The UAE's sole federal regulator for commercial gaming. Read the guide →
ECOSYSTEM
Building trust in payments
Tell us your goals. In one confidential call we'll confirm the framework you need, the right structure, a realistic timeline and the exact next steps.