Regulatory requirements

Regulatory business continuity requirements: Russia, UAE, KSA

Business continuity stopped being voluntary years ago: central banks and national regulators now audit continuity plans, tests and recovery times. A practical map of what is required in Russia, the United Arab Emirates and Saudi Arabia.

Published: July 18, 2026 · Author: Evgeny Telenkov · ≈ 7 min read
Regulatory business continuity requirements: Russia, UAE, Saudi Arabia

Why regulators care

A failed bank payment day or a halted critical service is no longer a private problem of one company — it is a systemic event. That is why financial and national regulators across jurisdictions have converged on the same idea: organizations must prove, with documents and test results, that they can survive disruption. The frameworks differ in names, but not in substance.

Russia: ONiVD and the Bank of Russia

The Bank of Russia requires supervised financial organizations to maintain a continuity and recovery framework known as ONiVD, with a core document — the continuity and recovery plan (PONiVD). Key expectations: named accountability at executive level, analysis of critical processes with recovery time objectives, a documented plan covering scenarios and communications, regular testing with recorded results, and incident reporting to the regulator.

UAE: NCEMA 7000, CBUAE, DIFC/ADGM

The UAE runs a national business continuity standard — AE/SCNS/NCEMA 7000 (2021 edition), aligned with ISO 22301 and mandatory for government entities and critical infrastructure, de facto expected from their suppliers. The Central Bank of the UAE requires banks to maintain board-approved disaster recovery and business continuity plans, review them annually, run independent reviews and promptly notify the regulator of disruptive events. Firms in the DIFC and ADGM financial free zones face additional operational resilience rules from DFSA and FSRA, including notification when a BCP is activated. A new consolidated central bank law issued in 2025 gives financial institutions a one-year window to align — a deadline worth checking against your continuity framework.

Saudi Arabia: SAMA framework

The Saudi Central Bank (SAMA) maintains a dedicated Business Continuity Management framework, mandatory for banks and financial institutions: governance, BIA, plans, exercises and reporting, with maturity assessed during supervisory reviews. For companies planning to serve the Saudi financial sector, SAMA-grade BCM documentation is effectively an entry ticket.

What all frameworks share

That last point is where we work: a resilience dashboard that turns continuity into numbers — a 0-100 index, cost of one day down, and traffic lights per critical area. It satisfies the regulator because the system behind it actually runs.

FAQ

We are ISO 22301 certified — are we compliant everywhere? ISO 22301 is the common backbone, and NCEMA 7000 is closely aligned with it. But each regulator adds specifics: reporting duties, test cadence, sector requirements. A gap assessment against the local framework is usually one to two weeks of work.

We are a supplier, not a bank — does this affect us? Increasingly yes: regulated organizations push continuity requirements down their supply chain through contracts and prequalification.

Where to start? With measurement: list critical processes, set recovery objectives, price one day of downtime. Every framework above starts from the same three steps.