DuoKey
Compliance

CBUAE

Central Bank of the UAE IT risk and information security standards for licensed financial institutions. Cryptography, key management and outsourcing.

Requirements

What the regulation expects

CBUAE IT risk and information security standards address cryptography, key management and cryptographic modules alongside outsourcing obligations that apply to any externally operated key service. The platform ships a built-in rule pack for the central bank regime. Treat an externally operated KMS as an outsourced critical service and agree custody, audit access and exit in the contract.
What the regulation expects

Binding on licensed financial institutions

Banks, exchange houses, finance and insurance companies and payment service providers.

Cryptographic modules and key management

Approved algorithms, module assurance and lifecycle under one inventory the examiner can take.

Outsourcing of key services

If DuoKey runs as a managed service, the customer still owns T-side accountability. Document the split.

Evidence for examination

Key inventory, chain-verified audit trail, access review reports and CBUAE rule-pack gap output.

Solutions

How DuoKey supports the framework

OpenBAO + DuoKey SD-HSM

Enforced catalogue, HSM/MPC/software custody options, exportable inventory and activity trail.

Learn more

AWS XKS

External keys so the cloud operator is not the sole trust root.

Learn more

Microsoft 365 Customer Key & DKE

Customer-held keys for mail and files.

Learn more

SQL & database encryption

External key control for database encryption.

Learn more

Key themes

Where independent key control fits

Use the CBUAE Rulebook for operative wording. Product evidence below covers the cryptography and outsourcing angles that typically drive a KMS purchase.

Cryptography and key management

Approved solutions as an enforced catalogue, lifecycle as enforced key states, custody backend visible per key in inventory.

Relevant products

Cryptographic modules

HSM-backed or MPC custody where module assurance is required; software vault where the risk assessment allows it. Document the choice per vault.

Relevant products

Outsourcing of key services

Managed service vs on-premise split agreed in writing. Customer retains policy ownership and SIEM receipt of key events.

Access control and audit

MFA for privileged access, leaf-level permissions, JIT elevation, and hash-chained audit trail forwarded to the institution SIEM.

Relevant products

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.