CISI UAE FRR CBUAE & FSRA Regulations 5 — Questions and Answers
Question 1: The CBUAE's Guidance on Outsourcing requires banks to ensure that outsourced functions:
- Remain subject to the bank's oversight and regulatory access (Correct answer)
- Are fully transferred to the service provider's control
- Are disclosed only in annual reports
- Can be terminated without notice in any circumstance
Correct answer: Remain subject to the bank's oversight and regulatory access
Banks remain responsible for outsourced activities and must maintain oversight, ensure regulatory access to outsourced operations, and manage associated risks including operational, concentration, and data risks.
Question 2: The FSRA uses which approach to regulate FinTech firms in ADGM?
- RegLab (Regulatory Laboratory) for sandbox testing (Correct answer)
- Mandatory full licensing before any operations
- Exemption from all financial regulation for FinTech
- Application of conventional bank regulations without modification
Correct answer: RegLab (Regulatory Laboratory) for sandbox testing
ADGM's RegLab provides a regulatory sandbox allowing FinTech firms to test innovative products and services under a restricted licence, with tailored regulatory requirements appropriate to their developmental stage.
Question 3: Under CBUAE regulations, which risk does the Countercyclical Capital Buffer (CCyB) address?
- Systemic risk arising from excessive credit growth in the economy (Correct answer)
- Individual bank liquidity shortfalls
- Operational risk from technology failures
- Foreign exchange risk from USD peg
Correct answer: Systemic risk arising from excessive credit growth in the economy
The CCyB is activated during periods of excessive credit growth to build capital buffers that can be released during downturns, dampening the procyclicality of lending and protecting financial stability.
Question 4: The FSRA's recognition of overseas regulators through 'equivalence' arrangements means:
- Firms from equivalent jurisdictions may benefit from streamlined authorisation (Correct answer)
- All overseas firms are exempt from FSRA supervision
- Only FATF member firms can operate in ADGM
- Foreign regulators co-supervise ADGM firms directly
Correct answer: Firms from equivalent jurisdictions may benefit from streamlined authorisation
Equivalence arrangements recognise that overseas regulatory frameworks provide comparable protection, allowing firms from those jurisdictions to obtain ADGM authorisation through an expedited process.
Question 5: The CBUAE's Cyber Risk Guidance requires financial institutions to implement:
- A cyber resilience framework including incident response and recovery plans (Correct answer)
- Annual cyber awareness training only
- Third-party penetration testing exclusively
- Manual backup systems for all digital records
Correct answer: A cyber resilience framework including incident response and recovery plans
The CBUAE's Cyber Risk Guidance requires a comprehensive cyber resilience framework covering governance, risk identification, protection, detection, response, and recovery from cyber incidents.
Question 6: Under FSRA regulations, an 'Authorised Person' in ADGM must notify the FSRA:
- Of material changes to its business, significant events, and breaches of regulatory requirements (Correct answer)
- Only at annual licence renewal
- When it achieves profitability
- Exclusively through its external auditors
Correct answer: Of material changes to its business, significant events, and breaches of regulatory requirements
Authorised Persons have ongoing notification obligations to promptly inform the FSRA of material changes, significant events, and regulatory breaches, enabling the regulator to respond appropriately.
The CBUAE's Guidance on Outsourcing requires banks to ensure that outsourced functions: