- Blog
What Storage Solutions Help UAE Banks Meet Central Bank Uptime and Continuity Mandates?
When a UAE bank’s IT head asks about uptime mandates, they are rarely asking about uptime in isolation. What they are actually asking is: if something fails tonight, what does that mean for our regulatory position tomorrow morning?
The Central Bank of the UAE (CBUAE) does not publish a single document titled “uptime requirements.” What it does publish, through its Outsourcing Regulation for Banks (Circular No. 14/2021) and its broader operational risk framework (including Article 7 on Disaster Recovery and Business Continuity Management), is a clear set of expectations around business continuity, disaster recovery, and the resilience of systems that process and store confidential customer data.
Those expectations directly dictate storage architecture. Get the storage wrong, and the business continuity plan (BCP) fails. The continuity plan fails, and regulatory exposure begins.
What the CBUAE Framework Actually Requires
The CBUAE’s operational risk framework mandates that banks maintain documented BCPs and robust disaster recovery (DR) capabilities. These must be tested regularly, and the results fully documented for supervisory review.
Circular No. 14/2021 adds specific storage-related obligations:
Data Residency & Master System of Record (Article 6.1): The Master System of Record—the authoritative source of all confidential customer data—must be continuously maintained and stored within the UAE. The word continuously is doing real regulatory work here. If a primary storage system fails, the bank must demonstrate that the continuity of that record was maintained without a gap. A storage architecture allowing even a temporary loss of the authoritative record raises immediate compliance concerns.
Sub-contractor Compliance (Article 4.3): Any third-party storage or infrastructure provider—and any sub-contractors they engage—must satisfy applicable regulatory requirements. This applies whether running on-premises hardware, colocation storage, or a cloud platform.
Enforceable RTO and RPO Targets: The framework requires banks to define explicit Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for critical systems. These are regulatory commitments. A bank committing to a four-hour RTO whose storage architecture physically cannot support a four-hour recovery carries an undocumented compliance gap.
Key Storage Technologies Mapping to Regulatory Requirements
Not all storage solutions offer the same level of resilience. Understanding which technologies align with specific requirements matters far more than vendor branding.
1. Synchronous Replication
Synchronous replication writes data to both primary and secondary storage systems simultaneously before confirming a transaction as complete. This delivers zero data loss (RPO = 0). For core banking systems where even a few minutes of lost transaction data represents a regulatory and financial breach, synchronous replication between primary and DR sites within the UAE is essential. Platforms from Dell, NetApp, and EverPure support native synchronous replication, managing latency trade-offs based on distance and workload profiles.
2. Asynchronous Replication
Asynchronous replication writes to primary storage first and replicates to secondary storage with a short delay. Because an inherent RPO gap exists, data can be lost if the primary site fails between replication cycles. While generally unacceptable for tier-one banking systems, asynchronous replication is a practical, cost-effective choice for secondary workloads and archival systems.
3. Immutable Snapshots
Immutable snapshots are read-only, point-in-time copies of storage volumes that cannot be altered or deleted for a set duration. They address a failure mode replication cannot: logical corruption (such as ransomware or bad data replicating instantaneously to the DR site). Immutable snapshots provide a pristine recovery point that bypasses the corrupted state, making them a baseline requirement for modern bank resilience.
4. All-Flash Storage Arrays
Solid-state all-flash arrays deliver the high input/output performance required by transaction-heavy banking environments. Crucially, they accelerate recovery times. When a failover occurs, the speed at which the secondary system absorbs live traffic depends on storage performance. A secondary site using slower disk-based storage may technically meet failover criteria but underperform under live transaction loads.
5. Storage Virtualisation
Software-defined storage virtualisation abstracts physical hardware into a unified logical pool. It enables non-disruptive workload migration between systems, simplifies capacity management, and reduces single-vendor dependency across the estate.
Frequently Asked Questions
Does the CBUAE specify minimum uptime requirements for bank systems?
The CBUAE does not prescribe a single universal uptime percentage across all platforms. Instead, its operational framework mandates that banks define and document their own RTO and RPO targets for critical services, maintain viable BCPs, and prove via testing that these targets are achievable. Exposure arises when a bank commits to targets its storage cannot physically deliver.
Can a UAE bank use cloud storage to meet continuity requirements?
Yes, provided the primary cloud data centre and DR regions reside within the UAE, the arrangement has received prior CBUAE approval as a material outsourcing arrangement, and all contractual and technical controls comply with Circular No. 14/2021. Cloud adoption does not exempt an institution from Article 6.1 data residency or DR testing mandates.
What is the difference between replication and backup, and why do banks need both?
Replication maintains a continuously updated copy of live data on secondary storage to protect against hardware or site failure. However, it replicates data corruption instantaneously. Backup creates isolated, point-in-time snapshots (ideally immutable) that preserve uncorrupted historic states. Deploying both ensures recovery from both physical disasters and logical corruptions.
How often should a UAE bank test its storage DR capability?
At minimum, a full site failover test must be conducted annually, supplemented by more frequent partial and component-level testing. The CBUAE expects documented test results and remediation plans for supervisory evaluation.
How Brilyant Delivers CBUAE-Compliant Storage Architecture
Most storage continuity gaps discovered during infrastructure reviews stem from architectures designed strictly for normal operating conditions that were never stress-tested against severe failure scenarios.
Brilyant collaborates with financial institutions across the UAE to architect, deploy, and validate storage infrastructure aligned with CBUAE continuity requirements:
Certified Partnerships: Premier partner for NetApp, EverPure, and Dell enterprise storage, alongside AWS and Microsoft Azure for cloud-based DR.
End-to-End Execution: We design high-availability replication topologies, implement immutable backup policies, and conduct full failover validation under simulated production stress.
Audit-Ready Compliance: We deliver the comprehensive testing documentation and evidence required by compliance teams and supervisory reviews.
Contact Brilyant’s infrastructure team today to review your storage continuity architecture and validate your regulatory alignment.
Datacenter Services
Frequently Asked Questions
Can a Dubai bank use a data centre outside the UAE as its DR site?
No. Under CBUAE Circular 14/2021, Article 6.1, the Master System of Record including all confidential customer data must be stored within the UAE continuously. A DR site outside the UAE would breach this requirement unless specific prior CBUAE approval has been obtained.
What is the difference between RTO and RPO and why do they matter for DR architecture?
RTO (recovery time objective) is how quickly your systems need to be back online after a failure. RPO (recovery point objective) is the maximum amount of data you can afford to lose. These two figures directly determine which storage replication method and which DR architecture model is appropriate. Tight RTO and RPO requirements point toward active-active synchronous replication. More tolerance allows for active-passive with asynchronous replication.
Is cloud-based DR compliant for UAE banks?
It can be, provided the cloud infrastructure is located within the UAE, the data processing agreements meet CBUAE requirements, and the arrangement has received prior CBUAE approval as a material outsourcing decision. Both AWS and Microsoft Azure have operational regions within the UAE that can support DR workloads.
How often should banks test their DR setup?
The CBUAE’s operational risk framework expects documented DR testing. Industry practice for banks is at minimum one full failover test annually, with partial or component tests more frequently. Test results should be documented and remediation tracked.
Where Brilyant Can Help
The DR projects that go wrong aren’t usually the ones with bad intentions. They’re the ones where the storage architecture was designed for cost efficiency rather than regulatory compliance, or where the network redundancy between sites wasn’t validated before the first real failure occurred.
Brilyant works with banks across Dubai and Abu Dhabi to design and implement storage and DR architectures built for CBUAE compliance from day one. We’re a certified partner with NetApp, Pure Storage and Dell on the storage side, and with AWS and Microsoft Azure for cloud-based DR workloads. We design the replication topology, validate the network paths, and build the testing framework alongside the implementation.
Talk to Brilyant’s infrastructure team about DR architecture for UAE banks.
More Articles
We are here to help
Get in touch with our in-house experts to find the right solution for your IT Infrastructure