Why regulators care
A failed bank payment day or a halted critical service is no longer a private problem of one company — it is a systemic event. That is why financial and national regulators across jurisdictions have converged on the same idea: organizations must prove, with documents and test results, that they can survive disruption. The frameworks differ in names, but not in substance.
Russia: ONiVD and the Bank of Russia
The Bank of Russia requires supervised financial organizations to maintain a continuity and recovery framework known as ONiVD, with a core document — the continuity and recovery plan (PONiVD). Key expectations: named accountability at executive level, analysis of critical processes with recovery time objectives, a documented plan covering scenarios and communications, regular testing with recorded results, and incident reporting to the regulator.
UAE: NCEMA 7000, CBUAE, DIFC/ADGM
The UAE runs a national business continuity standard — AE/SCNS/NCEMA 7000 (2021 edition), aligned with ISO 22301 and mandatory for government entities and critical infrastructure, de facto expected from their suppliers. The Central Bank of the UAE requires banks to maintain board-approved disaster recovery and business continuity plans, review them annually, run independent reviews and promptly notify the regulator of disruptive events. Firms in the DIFC and ADGM financial free zones face additional operational resilience rules from DFSA and FSRA, including notification when a BCP is activated. A new consolidated central bank law issued in 2025 gives financial institutions a one-year window to align — a deadline worth checking against your continuity framework.
Saudi Arabia: SAMA framework
The Saudi Central Bank (SAMA) maintains a dedicated Business Continuity Management framework, mandatory for banks and financial institutions: governance, BIA, plans, exercises and reporting, with maturity assessed during supervisory reviews. For companies planning to serve the Saudi financial sector, SAMA-grade BCM documentation is effectively an entry ticket.
What all frameworks share
- Accountability assigned to a named executive, not a department.
- Knowing your critical processes, their recovery time objectives and the cost of their downtime.
- A living, tested plan — regulators read test records first, because they expose paper plans instantly.
- Communication procedures: staff, clients, the regulator itself.
- Measurability as the direction of travel: boards and supervisors increasingly ask for metrics, not folders.
That last point is where we work: a resilience dashboard that turns continuity into numbers — a 0-100 index, cost of one day down, and traffic lights per critical area. It satisfies the regulator because the system behind it actually runs.
FAQ
We are ISO 22301 certified — are we compliant everywhere? ISO 22301 is the common backbone, and NCEMA 7000 is closely aligned with it. But each regulator adds specifics: reporting duties, test cadence, sector requirements. A gap assessment against the local framework is usually one to two weeks of work.
We are a supplier, not a bank — does this affect us? Increasingly yes: regulated organizations push continuity requirements down their supply chain through contracts and prequalification.
Where to start? With measurement: list critical processes, set recovery objectives, price one day of downtime. Every framework above starts from the same three steps.