The Central Bank of the UAE's Open Finance Framework, published under Circular No. 9/2024, does not simply extend Open Banking to a broader set of financial products — it recalibrates the operating model for every licensed financial institution in the country.
The framework establishes a tiered licensing regime: Licensed Financial Institutions ('LFIs') as data holders, Third Party Providers ('TPPs') as data users, and a category of Trust Framework Participants ('TFPs') that operate the shared infrastructure. LFIs' central obligation is to expose defined data sets — accounts, transactions, product features, and, in later phases, insurance and investment holdings — through standardised APIs.
The operational uplift is significant. LFIs must implement API infrastructure to specified performance and availability standards (target 99.5% uptime, sub-500ms response for account information calls), implement strong customer authentication under the framework's defined SCA standards, and maintain a customer-facing consent dashboard.
Governance is where most LFIs are behind. The framework requires a designated Open Finance Officer at senior management level, a documented consent lifecycle policy, and quarterly reporting on API performance, complaints, and consent revocations. These are not IT deliverables — they are compliance obligations.
The commercial opportunity is real. LFIs are permitted to become TPPs themselves, competing for data-driven propositions across the wider market. The institutions treating the framework purely as a compliance cost are already ceding ground to those treating it as a distribution channel.