Compliance Monitoring in 2026: Know What Is Working
Your access policy says former employees lose production access promptly. The tickets are closed. But an account review...
The Central Bank of the UAE (CBUAE) Operational Risk Management Regulation C 1/2026, effective from 14 September 2026, introduces important ICT and cybersecurity requirements for Licensed Financial Institutions.
It requires institutions to identify and assess ICT risks, put appropriate mitigating measures in place, regularly monitor and test those measures, and proactively manage ICT and cybersecurity risks.
For CISOs, this creates an important shift from demonstrating that security controls exist to demonstrating that they are working and understanding the risk when they are not.
“Regular monitoring and testing of mitigating measures.” — CBUAE C 1/2026, Article 8.1.3
Most financial institutions already have substantial cybersecurity investments. IAM manages identities. PAM protects privileged access. EDR protects endpoints. Vulnerability platforms identify exposures. SIEM monitors security events. ITSM manages incidents and remediation.
The challenge is connecting what these systems know to answer a harder question:
Are our critical security controls actually working as expected?
Consider privileged access. A policy may require privileged accounts to be protected through PAM and appropriate authentication controls. Traditionally, proving this may involve requesting evidence from the control owner, collecting screenshots and reviewing a sample.
But much of the evidence already exists. Active Directory knows which accounts are privileged. PAM knows which accounts are vaulted. Identity platforms know which authentication controls are enabled.
That allows assurance to move from periodic evidence collection toward:
Control → System Evidence → Test → Exception → Remediation
The CBUAE requirement for regular monitoring and testing makes the ability to use current, authoritative system evidence increasingly important.
Control effectiveness is only useful when it can be connected back to risk. If a control fails, the CISO needs to understand what risk that failure creates.
For example, discovering that a privileged account is outside PAM is a control failure. But its significance depends on what that account can access, which assets could be affected, what other controls are in place, and the potential impact of compromise.
The same applies to vulnerabilities, endpoint protection, security configurations and other cyber controls.
This creates a natural progression:
Risk → Control → Evidence → Test → Effectiveness → Residual Risk → Remediation
For CISOs, the objective is therefore not to produce more security findings. It is to understand which controls are ineffective, what risk that creates, and what needs to be fixed first.
For CISOs preparing for C 1/2026, this can be translated into ten practical actions.
| # | What to do | What to check |
|---|---|---|
| 1 | Identify Critical Operations | Do you know the technology, assets, data and third parties supporting each Critical Operation? |
| 2 | Identify material cyber risks | Are ransomware, identity compromise, vulnerabilities, outages, data loss and other material risks mapped to the operations they could affect? |
| 3 | Map risks to controls | Do you know which preventive, detective, response and recovery controls mitigate each material risk? |
| 4 | Define control effectiveness | Have you defined what demonstrates that an important control is designed appropriately and operating as intended? |
| 5 | Use authoritative evidence | Can evidence come directly from IAM, PAM, EDR, VA, SIEM, ITSM, cloud and other source systems? |
| 6 | Prioritise exposure by risk | Are vulnerabilities considered alongside asset criticality, exploitability, existing controls and business impact? |
| 7 | Test cyber resilience | Can you demonstrate the ability to withstand, respond to and recover from cyber disruption affecting Critical Operations? |
| 8 | Understand third-party dependencies | Do you know which Critical Operations depend on external providers and the risks created by those dependencies? |
| 9 | Define meaningful KRIs | Can management see when cyber risk or control effectiveness moves outside established tolerance? |
| 10 | Close the remediation loop | Does every material control failure have an owner, remediation plan, timeline and associated risk? |
This isn’t about creating ten new compliance processes.
In most institutions, much of the required data already exists across security tools, IT platforms, asset inventories and GRC systems.
The challenge is connecting it.
SPOG.AI operationalizes the checklist by connecting the security, IT and risk systems an institution already uses.
Evidence from IAM, PAM, EDR, vulnerability management, SIEM, ITSM, cloud and other systems can be connected directly to the controls they support. That evidence can then be used to test whether controls are operating as intended and understand the resulting risk when they are not.
When a control fails, SPOG helps identify the exception, understand the resulting risk, assign remediation and track it through closure.
The result is a connected assurance model:
CBUAE Requirement → Risk → Control → Evidence → Test → Control Effectiveness → Residual Risk → Remediation
SPOG doesn’t replace the security technologies an institution already operates. It connects the evidence they generate with controls and risks, giving CISO, GRC and Operational Risk teams a common view of what is working, what is failing and what risk remains.
CBUAE C 1/2026 strengthens the connection between cyber risk, control effectiveness and Operational Resilience.
For CISOs, the opportunity is to use the security investments they already have to build a more current view of whether their controls are actually working.
Are the controls protecting us working as expected? Can we prove it? And what risk remains when they are not?
The checklist provides the framework. SPOG.AI operationalizes it by connecting risk, controls, evidence, effectiveness and remediation.
Your access policy says former employees lose production access promptly. The tickets are closed. But an account review...
A SaaS company can have strong security practices and still struggle to answer a customer’s questionnaire. The team...
The backup dashboard is green. A customer asks how quickly a critical service can be restored after an...