ExSolution

Home / Insights / ISO 22301 in Dubai: what regulators require, and where programmes go wrong

ContinuityGuide

ISO 22301 in Dubai: what regulators require, and where programmes go wrong

Regulated firms in DIFC, ADGM and under the Central Bank must maintain and test continuity arrangements. None of those rules names ISO 22301, which changes why you would certify, and what the programme has to deliver.

In brief

DIFC, ADGM and Central Bank rules require a documented, tested continuity capability. They are outcome-based and name no standard. ISO 22301 is a way of meeting the obligation and evidencing it, not the obligation itself.

That distinction matters commercially. If you certify believing a regulator demanded the certificate, you will scope the programme to satisfy an auditor. If you certify to evidence a capability the regulator will test, you scope it to survive the test.

What the rules actually say

Three regimes carry explicit continuity obligations for the firms they regulate.

Continuity obligations on regulated firms in the UAE
RegimeRequirementNames a standard?
DFSA (DIFC)An Authorised Person must have adequate arrangements to continue to function and meet its obligations in the event of an unforeseen interruption, kept up to date and regularly tested.1No
ADGM FSRAA near-identical obligation on Authorised Persons, with guidance covering crisis management and disaster recovery planning.2No
Central Bank of the UAEFor banks: a documented business continuity management policy, ongoing business impact analysis, a documented plan, and review and testing at least annually with results reported to the Board.3No

What this means for your organisation

No UAE financial regulator we have found mandates ISO 22301 or any other continuity standard. The obligation is a capability, documented and tested. Anyone telling you the certificate is required by the regulator is describing a commercial preference as a rule, and that misunderstanding tends to produce a programme built for the certificate rather than for the disruption.

NCEMA 7000 is a UAE national standard. Its application depends on the organisation’s mandate, supervising authority and contractual obligations rather than the emirate in which an office is registered. It applies to UAE federal and government entities, and may extend through government or contractual requirements to suppliers, contractors and partners. Where both apply, the two frameworks are compared in detail here.

The three analyses the programme rests on

Whether a management system informs decisions or sits on a shelf is settled early, by three pieces of analysis.

Business impact analysis

The BIA is where the politics start. It requires every department to justify its recovery time objectives and its maximum tolerable period of disruption, and those answers carry budget consequences. Business units have an incentive to inflate their numbers to secure priority; shared services tend to be deprioritised by the same logic.

In practice the BIA is less a technical exercise than an internal negotiation. Without facilitation from someone with no stake in the outcome, the result reflects influence rather than risk.

Risk assessment

Technology, people, premises, suppliers and regulatory change. What the standard requires is that the decision to treat, transfer, accept or avoid each risk is documented, which is also what makes the assessment auditable later.

Supply chain mapping below the first tier

A programme that maps only direct suppliers has mapped only the dependencies it already knew about. Concentration risk usually sits deeper: several first-tier suppliers relying on the same logistics route, the same platform, or the same sub-contractor. Mapping below tier one is what exposes single points of failure that no individual supplier relationship reveals.

Where programmes go wrong, phase by phase

These are the friction points we see most often. They are practice observations, not requirements of the standard.

Certification phases and their common failure modes
PhaseWhere it goes wrong
Gap analysisExisting emergency and evacuation plans are assumed to constitute a continuity management system. They do not, and the gap is usually larger than the organisation expects.
System designScope drawn too broadly to be maintained, or too narrowly to cover what a customer is asking about.
Impact analysis and risk assessmentDepartmental politics distort the output, as above.
Plan developmentPlans written to be complete rather than usable. The test is whether someone can act on it under pressure, not whether it addresses every clause.
Training and awarenessCompletion recorded as competence. Generic modules do not survive first contact with an incident; role-specific, scenario-driven work does.
ExercisingScenarios designed to confirm the plan works rather than to break it. An exercise that produces no discomfort produces no findings.
Internal auditFindings written generically, so nothing is actionable and nothing changes.
Certification and surveillanceThe system stalls between audits. Continuity capability decays quietly, and the next audit examines the decay.

Integrating with standards you already hold

Organisations already certified to ISO 9001 or ISO 27001 share a common structure with ISO 22301, which allows one governance framework, one audit cycle and one management review rather than three parallel programmes.

The saving is real in consultancy and internal effort. On the certification-body side it is capped and not guaranteed; the cost guide sets out what the mandatory rules actually permit.

Why leadership involvement decides the outcome

Top management sets the policy, allocates the resources and decides whether the system has authority. A continuity programme without visible sponsorship becomes a documentation exercise, because the decisions it depends on are ones only leadership can make: which activities take priority, and who commits resources during a disruption.

ExSolution provides continuity consultancy and audit readiness support. We do not issue certificates and we do not guarantee the outcome of an independent audit.

Sources and references

All accessed 4 August 2026.

  1. Dubai Financial Services Authority, GEN 5.3.23, Business continuity and disaster recovery; prudential equivalent at PIB 6.9.
  2. ADGM Financial Services Regulatory Authority, General Rulebook GEN 3.3.33, with guidance under GEN 3.3; prudential equivalent at PRU 6.9.
  3. Central Bank of the UAE, Operational Risk Standards C 163/2018, Article 7, Disaster Recovery and Business Continuity Management. Article 10 requires notification to the Central Bank within 24 hours of an event triggering the plan. A parallel requirement applies to payment and stored-value facility licensees.
  4. NCEMA 7000 applicability as recorded in ExSolution’s verified regulatory register and stated on the business continuity service page.

Read next

If a regulator has tested your arrangements and found them wanting, the scope of the fix is the first conversation.

Discuss a continuity requirement