Open Finance in the UAE: an integrated fintech ecosystem for 2026
The United Arab Emirates is building one of the most ambitious open finance frameworks in the Middle East. Under the Central Bank of the UAE’s (CBUAE) Open Finance Regulation, requires banks, insurers and other licensees to share financial data under the customer’s explicit consent.
That regulation doesn’t operate in isolation. It rests on an instant payments infrastructure that is already live, and on a Digital Dirham the central bank itself is already using for government transactions.
This article explains how those three pieces (regulation, payments and CBDC) fit together, what figures back the project, and what it means in practice for banks and fintechs operating in the country.
What is the CBUAE’s Open Finance Regulation?
The CBUAE Open Finance Regulation (Circular 7/2023) was issued on 31 December 2023 and effective from 15 April 2024. A subsequent update in force, Circular 3/2025, was issued on 10 July 2025, and repeals and replaces Circular No. 7/2023.
The regulation requires every entity supervised by the CBUAE to take part in the framework within the scope of its products, though only in mainland UAE: the DIFC and the ADGM sit outside it and answer to their own regulators, the DFSA and the FSRA. Unlike classic open banking, which is limited to bank account data, open finance in the UAE also covers insurance, payments and other financial services under a single technical standard.
The framework rests on three pieces: a Trust Framework that vets participants (directory, digital certificates, an API portal and a certification sandbox), a common API Hub operated by Nebras Open Finance (the subsidiary the CBUAE created to run it and set its commercial model), and shared infrastructure services that route consent through a Consent and Authorisation Manager. The full technical detail is published in the Open Finance Regulation on the CBUAE Rulebook, the primary regulatory source.
On top of that Nebras infrastructure, the CBUAE built Al Tareq: the consent, authentication and user-experience layer that banks, fintechs and customers see when they connect. In practice it supports four functions: sharing financial data, generating comparable quotes across providers, initiating services or transactions, and onboarding a customer at a new licensed entity without repeating the full documentary process. None of those functions fires without the user’s explicit, informed consent.
Table 1. Timeline and infrastructure of the Open Finance Regulation
| Piece | Scope | Status |
| Phase 1 | Banks (including foreign bank branches) and insurance companies | First onboarding phase; Circular 3/2025 has been in force since 10 July 2025 |
| Phase 2 | Remaining licensees (fintechs, exchange houses, payment providers) | Pending official CBUAE announcement |
| Nebras Open Finance | CBUAE subsidiary operating the API Hub and the commercial model | Active |
| Al Tareq | Consent, authentication and user experience on top of the API Hub | Live in production: ADCB (Jul 2025), Commercial Bank of Dubai (full activation, Dec 2025), ADIB (Jan 2026, first Islamic bank) |
For institutions that need to build out their identity and consent layer ahead of Phase 2, Facephi details the UAE’s regulatory compliance requirements on its dedicated regional page.
The ecosystem in numbers: Aani, Al Tareq and the Digital Dirham
UAE open finance isn’t starting from zero. The country already runs Aani, the instant payments platform that Al Etihad Payments, the CBUAE’s own payments subsidiary, launched in October 2023.
As of Al Etihad Payments’ April 2026 update, Aani connects 74 licensed financial institutions and has surpassed 12.5 million users. Transfers settle in an average of three seconds, with an instant transfer cap of AED 50,000 per transaction.
Al Tareq now sits on top of that payments base. According to the CBUAE’s 2025 Annual Report, published on 9 April 2026, the platform is already active and the Digital Dirham has been completed as an official payment instrument, with the first government transactions already executed.
The Digital Dirham runs on its own timeline. The wholesale, government-facing pilot live since November 2025 rests on mBridge, the cross-border CBDC project originally driven by the BIS Innovation Hub alongside the central banks of China, Hong Kong, Thailand and the UAE; the BIS withdrew from the project in October 2024, describing its exit as a ‘graduation’ rather than an abandonment. The CBUAE’s roadmap plans to expand the Digital Dirham to peer-to-peer payments, merchants and additional cross-border corridors throughout 2026, with a full launch targeted for the end of that year.
Table 2. The UAE fintech ecosystem in numbers (data as of April 2026)
| Indicator | Figure | Source |
| Aani users | 12.5 million+ | Al Etihad Payments / CBUAE |
| Institutions connected to Aani | 74 | CBUAE |
| Average transfer time | 3 seconds | CBUAE |
| CBUAE-licensed fintechs | 36 | CBUAE 2025 Annual Report |
| Digital Dirham status | Official instrument; first government transactions executed | CBUAE 2025 Annual Report |
The number the headline misses: broad reach, still bank-heavy
The headline is striking: 74 institutions and 12.5 million users connected to instant payments. The fine print qualifies that figure.
Those 74 institutions don’t contribute equally by entity type. Al Etihad Payments itself specifies that Aani is integrated with 85% of the country’s banks, but only 10% of exchange houses and 5% of digital wallets and finance companies. It isn’t that most of the connected entities are banks: it’s that almost every bank is already in, and almost no exchange house, wallet or finance company is yet.
That figure belongs to Aani, the instant payments infrastructure, not to the Open Finance Regulation’s perimeter itself; the CBUAE doesn’t publish an equivalent segment-penetration figure for open finance as such. Even so, it works as a reasonable indirect indicator: if the payments base that Al Tareq is built on is already bank-centric, and Phase 1 of the regulation itself is limited to banks and insurers, it’s reasonable to expect open finance to follow the same pattern in its early years of rollout.
For a fintech planning to operate in the UAE, this translates into a real preparation window: it can build its identity and consent infrastructure before Phase 2 forces it to connect, rather than reacting once the CBUAE sets the date.
That window doesn’t apply to the whole country equally. The Open Finance Regulation covers mainland UAE; the DIFC and the ADGM sit outside it and answer to their own regulators, the DFSA and the FSRA. A fintech licensed only in one of those financial centres needs to check first whether its activity falls within the CBUAE’s perimeter before planning its connection.
This gap between formal coverage and real adoption isn’t unique to the UAE, but it is especially visible in a market that presents itself as a global open finance benchmark. The right reading isn’t that the project is failing, but that its most demanding phase (bringing non-bank players up to the same trust level as a licensed bank) is still ahead.
Table 3. Classic open banking versus the UAE’s open finance model
| Concept | Open banking (classic model) | Open finance (UAE model) |
| Data scope | Bank accounts | Banking, insurance, payments and other financial services |
| Core function | Sharing data | Sharing data, initiating transactions and initiating services |
| Participation | Mandatory but limited to payment accounts in the EU (PSD2) and UK (CMA Order); market-driven elsewhere | Mandatory for CBUAE licensees within scope (mainland UAE) |
| Governance | Proprietary APIs per entity | Trust Framework + centralised API Hub (Nebras) + consent and UX layer (Al Tareq) |
A pattern that repeats outside the UAE: open data tied to instant payments
The UAE isn’t the only market tying open financial data to an instant payments infrastructure. Canada follows a similar logic: its Consumer-Driven Banking framework is rolling out alongside the Real-Time Rail, the country’s new instant payments network.
The difference is in the starting point. The UAE already had Aani running before completing its open finance regulation; Canada is building both pieces almost in parallel, as explained in the equivalent open banking and real-time payments process in Canada. That sequencing (payments first, data regulation second) gives the UAE a deployment edge over markets that regulate and build infrastructure at the same time.
The identity challenges for banks and fintechs in the UAE
A shared-data framework between banks, insurers and fintechs only works if the identity of whoever authorises each operation can be verified reliably. The CBUAE has already moved on this: Notice 2025/3057 bans SMS OTP, email OTP and static passwords as standalone financial authentication methods, with 31 March 2026 as the compliance deadline. Banks’ liability for 3D Secure fraud via SMS OTP had already shifted onto the institutions themselves from July 2025, ahead of that deadline.
Table 4. Identity pains in an open finance ecosystem
| Pain | Why it matters | What it requires |
| Friction-free authentication without SMS OTP | Notice 2025/3057 sets 31 March 2026 as the deadline to stop using SMS OTP, email OTP and static passwords on their own | Biometrics with liveness detection, FIDO2 passkeys |
| Cross-sector remote onboarding | Open finance multiplies the data entry points between entities | Document and biometric verification aligned with the National KYC Platform |
| Auditable consent | The regulator requires traceability for every data authorisation | An explainable record of every risk and identity decision |
Facephi offers identity verification and biometric authentication aligned with these UAE regulatory requirements, including the SMS OTP replacement required by CBUAE Notice 2025/3057.
“The introduction of Open Finance Regulation establishes global standards for open finance and accelerates the adoption of digital financial services.”
– Khaled Mohamed Balama, Governor of the CBUAE
Frequently asked questions about Open Finance in the UAE
It’s the regulation (Circular 7/2023, updated by Circular 3/2025) that requires banks, insurers and other mainland UAE licensees to share financial data and allow transactions to be initiated, always with the customer’s explicit consent. It rests on an API Hub operated by Nebras Open Finance and on Al Tareq, the consent and authentication layer that banks, fintechs and customers see.
Traditional open banking is limited to sharing bank account data. UAE open finance extends that scope to insurance, payments and other financial services, and adds the ability to initiate transactions and services directly, not just view them.
It’s the UAE Central Bank subsidiary that operates the API Hub and the shared open finance services: the participant directory, technical certification, and the commercial and pricing model that banks, insurers and licensed fintechs must connect to.
It’s the consent, authentication and user-experience layer for open finance in the UAE, built on top of the API Hub that Nebras operates. ADCB was the first certified bank, in July 2025 in partnership with payments provider Pay10; Commercial Bank of Dubai, with full activation, and ADIB, the first Islamic bank to implement it, have since joined.
Through Aani, the instant payments platform operated by Al Etihad Payments since 2023. Aani already connects 74 financial institutions and serves as the settlement infrastructure that new open finance use cases are built on.
The CBUAE has completed it as an official payment instrument and already uses it for government transactions, according to its 2025 Annual Report. Its wholesale pilot rests on the mBridge project, and the roadmap plans to expand it to peer-to-peer payments and cross-border transfers throughout 2026, with a full launch targeted for the end of that year.
They need to check first whether their activity falls within the CBUAE’s perimeter, since the regulation doesn’t cover the DIFC or the ADGM, and then build an auditable identity verification and consent layer aligned with Notice 2025/3057, the National KYC Platform and the CBUAE’s traceability requirements, before Phase 2 of open finance forces them to connect.