Book an appointment with us, or search the directory to find the right lawyer for you directly through the app.
Find out more
Deal by Design
Welcome to this edition of Law Update, focusing on the evolving M&A landscape across the MENA region. With deal activity and value continuing to grow, the region is seeing increased investor interest alongside a changing regulatory environment.
This edition explores key legal and market developments affecting M&A transactions, including regulatory reforms, foreign investment, governance, due diligence and deal structuring across the region.
The Central Bank of the UAE (the Central Bank) has issued a significant regulatory instrument that materially rebuilds the conduct architecture governing how licensed financial institutions (LFIs) engage with their customers. Circular No. 2/2026, dated 17 February 2026, introduces the SME Customer Protection Regulation (the SME Regulation), replacing the 2021 SME Market Conduct Regulation.
Together, these developments signal a decisive shift in the Central Bank’s supervisory priorities from rulebook compliance to outcomes-based customer protection, with governance accountability running from the boardroom to the front line.
The SME Regulation applies to all banks and finance companies licensed by the Central Bank for the provision of financial products and services to SMEs, including sole proprietors. It comes into effect six months from publication in the Official Gazette, giving institutions a structured but finite window to align their frameworks.
The most significant change introduced by the SME Regulation is not technical, but conceptual. The 2021 predecessor was framed as a market conduct regulation. The 2026 SME Regulation is expressly a customer protection regulation, and that distinction carries real regulatory weight.
The stated objective is reoriented towards promoting a culture of acting in the best interests of SMEs as customers. A new standalone article on institutional and governance oversight makes plain that the board and senior management are expected to set the tone from the top, establishing a strong governance framework that spans the design, development, promotion, sales, and distribution of financial products and services, as well as their ongoing review and amendment. This is not merely a procedural requirement; it is a signal that the Central Bank expects conduct risk to be owned at the highest levels of an institution, not delegated downward or siloed within compliance teams.
Importantly, the SME Regulation forms part of the Central Bank’s broader consumer protection framework and is expected to be complemented by forthcoming amendments to the Finance Companies Regulation, which are anticipated to introduce an additional licensing category targeting SME-focused lenders. The Central Bank’s support for alternative financing tools for SMEs, including government-backed credit guarantee schemes, reflects an ambition to deepen their access to the financial system.
The SME Regulation substantially raises the bar on disclosure. The Key Facts Statement requirement, which existed under the 2021 regime, is now supplemented by an express obligation that the customer acknowledge receipt of that statement before entering into the contract.
LFIs must present all reasonable options and comparisons and are prohibited from concealing suitable alternatives with lower costs, lower financing rates, lower fees, or different loan structures. The prohibition on steering customers away from better-value products is a direct response to mis-selling concerns and aligns the SME framework more closely with retail consumer protection standards.
Changes to terms and conditions (including fees) require a minimum of 60 calendar days’ written notice. Where contracts contain annual automatic renewal clauses, institutions must provide 30 calendar days’ notice before the renewal date.
Additionally, rejection of a financing application must now be communicated in writing, with reasons provided, subject only to financial-crime sensitivities or where disclosure is prohibited by applicable laws and regulations. These requirements impose meaningful discipline on the product lifecycle and on the manner in which institutions communicate adverse decisions.
Financial institutions are also required to provide clear, plain-language disclosures in both Arabic and English across the full customer lifecycle, ensuring that accessibility of information is not undermined by language barriers.
The responsible conduct article has grown from 24 paragraphs in 2021 to 52 in 2026, and the additions are substantive.
Complaints handling is recast around a two business-day acknowledgement with a unique reference number and a final written response within 30 business days. Critically, the customer’s right to escalate unresolved matters to the Ombudsman Unit Sanadak must be mandatorily disclosed, ensuring SMEs are aware of their recourse options. The complaints process must be free and independent.
A wholly new article on customer data protection introduces obligations that are particularly timely, given the increasing digitalisation of financial services. The Central Bank must be notified of significant data breaches. Affected customers must be directly notified of any customer data breach without undue delay. These requirements bring the SME regulatory framework into closer alignment with modern data governance standards and reflect growing Central Bank attention to the operational and reputational risks associated with data security failures.
The enforcement article is new in express form, and its scope is notably broad. Non-compliance may result in supervisory action, administrative action, and financial sanctions. At the more severe end, the Central Bank is empowered to withdraw, replace or restrict the powers of senior management or members of the board, impose interim management of the institution, and bar individuals from participating in the UAE financial sector.
The inclusion of individual accountability measures, particularly board-level sanctions, reinforces the message delivered by the governance article: responsibility for SME customer protection sits at the top of the institution, not only within operational or compliance functions.
The SME Regulation represents a material strengthening of the conduct and consumer protection framework applicable to SME banking in the UAE. It closes significant gaps in the 2021 regime, imports tools from the retail consumer protection framework, and introduces entirely new obligations across governance, disclosure, responsible lending, data protection, and enforcement.
Financial institutions would be well advised to undertake a comprehensive review of their SME onboarding processes, consumer protection frameworks, client agreements, disclosures, and complaints-handling mechanisms to ensure full alignment with the SME Regulation before it enters into force.
Given the breadth of the changes and the Central Bank’s expanded enforcement toolkit, the six-month implementation window should be treated as an active remediation period rather than a period of observation.