DFSA Compliance Operational Resilience DIFC Regulations

DFSA Operational Resilience: CP170 Regulatory Requirements & Compliance Guide

Master the DFSA Operational Resilience Framework (CP170). A comprehensive guide for compliance officers and DFSA-licensed firms in the DIFC.

Updated
Table of Contents
4.9/5 Rating

CISI GFC

Join thousands of students who passed on their first attempt.

DFSA Operational Resilience: CP170 Regulatory Requirements & Compliance Guide

In an increasingly interconnected and digital financial services landscape, the traditional focus on financial resilience (capital and liquidity) is no longer sufficient. Regulators globally have recognized that operational failures can threaten both individual firm viability and systemic financial stability.

To address this, the Dubai Financial Services Authority (DFSA) released Consultation Paper 170 (CP170) on operational resilience on 27 March 2026, with comments due by 26 May 2026. CP170 set out proposals, not final binding rules. Compliance officers, senior managers, and candidates preparing for the CISI Global Financial Compliance (GFC) examination should use the concepts below as consultation context and check later DFSA rulebook amendments before treating them as requirements in the Dubai International Financial Centre (DIFC).


The Paradigm Shift: From Recovery to Resilience

Historically, firms approached operational disruptions through the lens of Business Continuity Management (BCM) and Disaster Recovery (DR). The core assumption of BCM was that disruptions could be completely avoided, and if they occurred, the objective was to restore the status quo.

The model proposed in CP170 reflects a shift from recovery alone to the assumption that disruptions will occur due to cyber-attacks, technological failures, third-party vendor collapses, or natural disasters. Rather than focusing solely on prevention, the proposal would expect relevant firms to maintain the delivery of critical business services during a disruption.


Core Pillars of the DFSA Framework

CP170 identified five essential elements for its proposed operational-resilience regime:

  1. Identify critical business services.
  2. Set an impact tolerance for each critical business service identified.
  3. Map the resources needed to deliver each service within its tolerance.
  4. Test the ability to remain within tolerances under severe but plausible scenarios.
  5. Notify the DFSA of a material disruption that breaches or comes reasonably close to breaching a tolerance.

1. Identification of Critical Business Services

Under the proposal, every DFSA Authorised Person would regularly assess which business services, if disrupted, could cause a material risk to users of its financial services or to the stability, reputation of, or confidence in the DIFC financial-services industry. Only a firm that identified at least one critical business service would proceed to the rest of the proposed regime.

2. Setting Impact Tolerances

For every identified critical business service, the proposal would require an Impact Tolerance. This is the maximum level of disruption beyond which the effect becomes intolerable. CP170 said a tolerance could use time, transaction count, transaction value or another relevant metric; it did not prescribe the example thresholds.

The proposed tolerance would be set at a point before intolerable harm is caused to clients or the financial system, not merely before it becomes financially inconvenient for the firm.

3. Resource Mapping and Scenario Testing

CP170 proposed that a firm map the minimum people, processes, technology, facilities and information needed to deliver each critical business service within its tolerance. The firm would then test its ability to remain within the tolerance under severe but plausible scenarios. Such tests could include:

  • Multi-day power grid and telecommunication outages.
  • Complete corruption of core database servers.
  • Concurrent failure of primary and secondary third-party cloud service providers.
  • Major ransomware attacks locking down all corporate workstations.

Interconnected Risk: Third-Party Dependency Management

A significant focus of the CP170 proposals is management of third-party risks. Modern DIFC firms rely heavily on outsourced solutions for cloud hosting, portfolio management systems, and custodial services.

Under CP170’s proposed approach, outsourcing a service would not outsource the firm’s responsibility. Relevant firms would maintain visibility over the operational resilience of material service providers through measures such as:

  • Conducting comprehensive due diligence on vendor backup capabilities.
  • Inscribing clear operational resilience and incident-reporting covenants in Service Level Agreements (SLAs).
  • Integrating key third-party providers directly into the firm’s severe but plausible scenario testing.

Interactive Knowledge Check

DFSA Operational Resilience Knowledge Check

Score

0 / 2

Question 1 of 2

Prompt


Governance and Accountability

CP170 assigned two specific approvals to the firm’s Governing Body:

  • Approve the outcome of the critical-business-services identification exercise.
  • Approve the impact tolerances.

CP170 separately proposed that findings from tolerance reviews, resource mapping and scenario testing be documented and retained for internal use and possible DFSA submission. It did not call this record a Self-Assessment Document or expressly assign approval of test results to Senior Management.


Compliance Career Path: Elevating Your Profile

Operational resilience is relevant to DIFC firms and to compliance professionals who help assess service dependencies, governance and disruption testing.

Knowledge of operational resilience, complemented by professional certifications such as the CISI Global Financial Compliance (GFC), supports work on governance and risk oversight. The GFC syllabus provides broader regulatory foundations; it does not turn CP170’s consultation proposals into examinable DFSA rules.

For professionals building a compliance career in the DIFC, the practical distinction is between preventing avoidable incidents and limiting harm when disruption occurs.

Free CISI GFC Mock Exam & Sample Paper

Try 15 CISI GFC practice questions from Money Laundering and Customer Due Diligence

Practice CISI GFC exam questions with answers and explanations. The full course includes 5 mock exams and complete syllabus coverage.

Money Laundering and Customer Due Diligence

Which organization conducts mutual evaluations of countries to assess their compliance with AML/CFT standards?

1 / 15

Frequently Asked Questions

1 What is the primary objective of the DFSA Operational Resilience Framework?

CP170 proposed a framework intended to improve how relevant firms prevent, adapt to, respond to, recover from and learn from operational disruptions. CP170 is a consultation paper, so its proposals should not be cited as final rules without checking subsequent DFSA rulebook amendments.

2 Which firms are subject to the DFSA CP170 guidelines?

CP170 consulted on the proposed scope and proportional application; it was not itself an in-force guideline applying automatically to every DFSA-authorised firm. Confirm the scope in any final rulemaking and the current DFSA rulebook before assigning obligations to a firm.

3 What are critical business services under DFSA CP170?

CP170 used 'critical business service' for a service whose disruption could cause a material risk to users of the firm's financial services or to the stability, reputation of, or confidence in the DIFC financial-services industry.

4 What is an 'impact tolerance' in operational resilience?

CP170 proposed an impact tolerance for each identified critical business service: the maximum disruption beyond which the effect becomes intolerable for users or the DIFC financial-services industry. The metric could be time, transaction count, transaction value or another relevant measure.

5 How does the CISI Global Financial Compliance qualification help with DFSA regulations?

The CISI Global Financial Compliance (GFC) syllabus covers international regulation, risk and governance concepts that provide useful background. It does not replace the DFSA Rulebook or make CP170's consultation proposals binding or examinable rules.

Keep learning

View all insights

Ready to Ace Your CISI Exam?

Join thousands of finance professionals who passed their exams on the first attempt with our AI-powered study platform.

Explore CISI Preparation

Exam Prep

4.9

CISI GFC