Open Banking Regulation and Compliance in the GCC
Open banking is reshaping financial services across the Gulf Cooperation Council (GCC), with each member state progressing at a different pace. Bahrain led the region by launching the first open banking framework in 2020, followed by Saudi Arabia and the UAE. For financial institutions, fintech providers, and third-party developers, understanding the regulatory landscape is critical to achieving compliance and capturing market opportunity.
Open Banking Frameworks by Country
The GCC does not have a unified open banking regulation. Instead, each country’s central bank or monetary authority has developed its own framework, creating a patchwork of requirements that multi-market participants must navigate carefully.
Bahrain: CBB Open Banking Framework
The Central Bank of Bahrain (CBB) launched the region’s first open banking framework in October 2020, making Bahrain a pioneer in GCC open banking. The CBB framework covers both account information services (AIS) and payment initiation services (PIS) and applies to all retail banking products including current accounts, savings accounts, and credit cards.
Key features of the CBB framework include:
- Mandatory API standards based on the Berlin Group (NextGenPSD2) specification
- Strict consent management requirements with granular permission controls
- A mandatory testing and certification programme for all API endpoints
- Licensing categories for account information service providers (AISPs) and payment initiation service providers (PISPs)
- Liability allocation rules that place responsibility on the party initiating the transaction
The CBB has taken a phased approach, with Phase 1 (account information) now operational and Phase 2 (payment initiation) in advanced stages of implementation. All licensed banks in Bahrain are required to maintain compliant API endpoints accessible to regulated third-party providers.
| Element | Bahrain CBB Framework |
|---|---|
| Launch date | October 2020 |
| API standard | Berlin Group (NextGenPSD2) |
| Licensing categories | AISP, PISP |
| Testing requirement | Mandatory certification |
| Phase 1 (AIS) | Operational |
| Phase 2 (PIS) | In implementation |
Saudi Arabia: SAMA Open Banking Policy
The Saudi Central Bank (SAMA) launched its Open Banking Policy in March 2022, followed by the Open Banking Framework in October 2022. Saudi Arabia’s approach is notable for its comprehensive scope and alignment with international standards, including the UK’s Open Banking Implementation Entity (OBIE) specifications.
SAMA’s framework mandates the following:
- Standardised APIs for account information and payment initiation
- Secure customer authentication (SCA) for all payment transactions
- Real-time consent management with revocation capabilities
- Third-party provider (TPP) licensing through SAMA’s regulatory sandbox and permanent licensing pathways
- Mandatory data sharing for all licensed banks and payment service providers
Saudi Arabia has adopted a progressive implementation timeline. Phase 1 (read access) launched in 2023, with Phase 2 (write access) rolling out through 2024 and 2025. SAMA has established a dedicated Open Banking Department to oversee compliance and market development.
Notably, SAMA requires banks to provide free-of-charge API access for regulated TPPs, with cost recovery permitted only through value-added services beyond the mandated data sets.
| Element | Saudi SAMA Framework |
|---|---|
| Policy launch | March 2022 |
| Framework effective | October 2022 |
| API standard | UK OBIE-aligned |
| SCA requirement | Mandatory for all payments |
| TPP licensing | Sandbox + permanent |
| Phase 1 (read) | Live (2023) |
| Phase 2 (write) | Rolling out (2024–2025) |
UAE: CBUAE Open Banking Regulation
The Central Bank of the UAE (CBUAE) published its Open Banking Regulation in 2023, following a consultation period that began in 2021. The CBUAE framework is the most recent and draws on lessons from Bahrain, Saudi Arabia, and international markets.
The UAE framework is distinguished by:
- A two-tier licensing structure distinguishing between account information services and payment initiation services
- Mandatory compliance with the UAE’s API Hub standards developed in partnership with the Dubai Financial Services Authority (DFSA)
- Strong emphasis on consent management with detailed customer experience requirements
- Data minimisation obligations requiring TPPs to access only the minimum data necessary for the service
- Strict security requirements including mandatory encryption, tokenisation, and fraud monitoring
The CBUAE has adopted a risk-based implementation timeline, with systemically important banks required to comply first, followed by smaller institutions. The framework applies to all retail and SME accounts and extends to certain Islamic banking products. Enforcement is supported by the CBUAE’s Fintech Office and the UAE’s broader digital finance regulatory framework.
| Element | UAE CBUAE Framework |
|---|---|
| Regulation published | 2023 |
| API standard | UAE API Hub (DFSA-aligned) |
| Licensing structure | Two-tier (AIS / PIS) |
| Data minimisation | Explicit requirement |
| Implementation approach | Risk-based phasing |
| Scope | Retail and SME accounts |
API Standards and Technical Requirements
While each GCC country has adopted a different base standard, common technical requirements are emerging. All jurisdictions mandate RESTful APIs with JSON payloads, OAuth 2.0 authorisation frameworks, and OpenID Connect for authentication. TLS 1.2 or higher is universally required, and all frameworks mandate rate limiting and throttling mechanisms to protect core banking systems.
Testing and certification requirements differ. Bahrain requires API certification through an approved testing laboratory, while Saudi Arabia operates a self-certification model with SAMA audit rights. The UAE is developing a centralised API testing facility under the UAE API Hub.
Consent Management and Data Sharing
Effective consent management is the cornerstone of GCC open banking compliance. All three active frameworks require:
- Granular consent – Customers must authorise specific data categories, purposes, and durations separately
- Real-time revocation – Consent must be revocable at any time through the same channel used to grant it
- Consent recording – All consent events must be logged and retained for audit purposes (typically six years)
- Re-authentication – Periodic re-authentication is required, ranging from 90 days (Bahrain) to 180 days (Saudi Arabia)
Third-Party Provider Regulation
TPPs face distinct licensing and operational requirements across GCC markets. All jurisdictions require TPPs to be licensed entities, not mere contractual partners. Common requirements include minimum capital thresholds, professional indemnity insurance, board-level fitness and propriety assessments, and independent security audits.
A notable difference is that Saudi Arabia requires TPPs to maintain a physical presence in the Kingdom, while Bahrain and the UAE permit cross-border TPP licensing under certain conditions. All three frameworks require TPPs to publish transparent pricing and terms of service.
Security Requirements
Security requirements across GCC open banking frameworks share common foundations but vary in specificity:
- Authentication – Strong customer authentication (SCA) is mandatory in all jurisdictions, with Saudi Arabia adopting the most prescriptive requirements including biometric verification for high-value transactions
- Encryption – All frameworks require end-to-end encryption, with minimum key lengths specified (AES-256 for data at rest, TLS 1.2+ for data in transit)
- Fraud monitoring – Real-time transaction monitoring and anomaly detection are mandatory, with specific reporting obligations for suspicious activity
- Incident reporting – Breach notification timelines range from 24 hours (Saudi Arabia) to 72 hours (Bahrain and UAE)
Implementation Timelines and Roadmaps
The implementation landscape is dynamic. Bahrain has achieved the most mature implementation, with all retail banks operational on open banking APIs. Saudi Arabia is in the late stages of Phase 2 rollout. The UAE is expected to reach full operational status by 2026. Qatar and Kuwait are in early consultation phases, with frameworks expected by 2026–2027. Oman has announced its intention to develop an open banking policy but has not yet published a timeline.
FAQ
Which GCC country has the most advanced open banking framework?
Bahrain currently has the most mature framework, having launched in 2020 and achieved full Phase 1 implementation. Saudi Arabia is close behind with its comprehensive Phase 2 rollout now underway.
Do I need separate licences for each GCC country to offer open banking services?
Generally, yes. Each jurisdiction has its own licensing regime. While some reciprocity provisions exist for Bahrain and UAE, Saudi Arabia requires independent licensing. A multi-jurisdictional strategy should account for separate application processes, capital requirements, and compliance obligations.
What are the penalties for non-compliance with open banking regulations in the GCC?
Penalties vary by jurisdiction. The CBB can impose fines of up to BHD 1 million and suspend licences. SAMA’s penalties range up to SAR 25 million under the Payment Services Provider Law. The CBUAE can impose fines of up to AED 10 million, with additional sanctions including licence revocation.
Are Islamic banks required to comply with open banking regulations?
Yes. All three active frameworks apply to conventional and Islamic banks equally. The UAE framework explicitly extends to Islamic banking products, and Saudi Arabia’s SAMA has confirmed that Sharia-compliant banks must provide open banking APIs consistent with their product structures.
What data must banks share under GCC open banking frameworks?
Mandatory data categories include account information (balances, transactions, standing orders), customer details (name, contact information), and product terms (interest rates, fees, charges). Saudi Arabia and the UAE also require sharing of credit card and loan product data. All frameworks exclude sensitive personal data and trade secrets.
Can TPPs charge customers for open banking services?
TPPs may charge for value-added services but cannot charge for access to mandated data sets. Pricing must be transparent and disclosed upfront. Saudi Arabia explicitly prohibits TPPs from charging customers for basic account information services.
Ready to Launch Your GCC Open Banking Strategy?
Our regulatory compliance team has deep expertise across all GCC open banking frameworks. We help banks, fintech companies, and TPPs navigate licensing, build compliant API infrastructure, and achieve market access efficiently.
Contact our open banking specialists for a compliance gap analysis and market entry roadmap.