This paper draws on an extended recorded discussion between Anand Singh, Legal Director and head of the insurance practice across the GCC at Al Tamimi & Company, and Frederik Bisbjerg, Managing Director of Axxion, on what the New CBUAE Law changes for insurers in the UAE. The content is provided for general information purposes only and does not constitute formal legal advice, and reading or accessing these publications does not create an attorney-client relationship. This information should not be acted upon as a substitute for specific legal counsel. Input on legal aspects is from Al Tamimi & Co and the operational reading is Axxion's.
1. Executive summary
Federal Decree-Law No. 6 of 2025 has been in force since September 2025. What closes in September 2026 is the Article 184 reconciliation period, the one year the law gives every regulated agency and person to bring their positions into conformity. The Board of Directors may extend it. Nothing published so far says it will.
That distinction sets what a firm is answerable for. The law did not arrive in September 2026; it has been in force since 2025. So in September the regulator will not ask whether a firm is ready for a new rule. It will ask what the firm did with the year it was given. That question cannot be answered after the fact, because the firm's own files show it: when the gap review was run, when the fixes started, all of it dated. A firm either has a trail across that year or it does not.
Anand Singh, Legal Director and head of the insurance practice across the GCC at Al Tamimi & Company, reframed the deadline in the recorded discussion:
"When they come for inspection tomorrow and you're able to demonstrate your intent and that you tried fixing it, i.e. after the law came, you took decisive steps, did the gap analysis, and you're now trying to fix the findings, I think you are in a better defendable position. Or you're at least somewhere in the process. So the payers need to start. If they haven't started, now is the time."
Anand Singh, Al Tamimi & Company3
The standard is not finished compliance by September. It is a documented view of where an operation stands, with remediation under way against it. That carries more weight with a regulator than an undocumented assumption that the operation is broadly compliant, and it is achievable in the weeks that remain even where the underlying fixes are not.
The rest of this paper is built for that decision. It sets out first where the framework lands inside a single claim and what to do about it before September, then how Axxion runs its own operation against the same requirements. The regulatory basis for those points, what the law changed and why four instruments now bear on one claim, follows in the second half for readers who want the detail.
2. Where the framework lands: the seven operational areas
The framework resolves into seven operational areas where motor claims compliance is most likely to be tested, set out in Axxion's March 2026 white paper.2 Those areas are the practical unit of work, because they map to what a claims operation does rather than to how the law is drafted. Each is set out below with what the law requires, drawn from Axxion's published mapping and Al Tamimi's published deck, and where a typical motor operation falls short.2,4
1. Audit trail integrity
The law requires timestamped, retrievable records of the basis for every claims decision, generated as the decision is made rather than reconstructed afterward (Article 130 governance; Article 122 reporting).1,2 Al Tamimi's Agents of Insight deck frames the shift in a single line: the old standard was an outcome noted on file and justified after the fact; the new standard is reasoning that has to be recorded at the time the decision is made.4 This is where most operations will find their largest gap, and the diagnostic is familiar. In the discussion, Singh's answer to the weekend-spreadsheet method of responding to a regulator was that it will not survive the regulator's own move to technology:
"That's not going to work anymore. The government here is ahead of the sector. If what you have shared doesn't follow a certain standard, a minimum requirement, it's going to be caught out pretty quickly. They have an initiative called RegTech, where they're bringing in the technology on the regulatory side."
Anand Singh, Al Tamimi & Company3
The implication runs past the individual file. Supervisory capacity has been the practical limit on how often firms are examined. Technology on the regulator's side relaxes that limit, and the volume of examination rises with it. In the discussion, Singh observed that inspection frequency has already increased.3
2. Role segregation
The law requires documented separation between claims assessment, repair authorization and payment approval, so that no single individual controls a claim end to end without independent review (Article 130 governance structures).1,2 In motor operations built for speed, the same handler frequently assesses, authorizes and releases, and the segregation exists in an org chart rather than in the system that enforces it.
3. Decision provenance
Every repair estimate, total loss determination and settlement amount must be traceable to its source data: inspection reports, parts pricing, labour schedules, market valuations (Article 130; Articles 90–91 data and disclosure).1,2 Provenance is what turns an audit trail from a log of what happened into evidence of why. The gap in a typical operation is that the number is recorded but the basis for it is not, so a settlement can be shown but not defended.
4. Structured data reporting
Claims data must be held in structured, machine-readable form, with regulatory returns submitted on schedule and data quality sufficient for the Central Bank's analytical use (Article 122; Articles 90–91).1,2 This is the area where the compliance requirement and a commercial asset coincide, addressed in section 8. The typical shortfall is data spread across systems that were never designed to reconcile, which is a systems problem rather than a competence one.
5. Complaint resolution
The law requires a documented, operational internal complaints process, integration with the Central Bank's Sanadak platform, and retained, retrievable complaint records (Article 148; Sanadak requirements).1,4 Al Tamimi's deck adds the conduct dimension from the Consumer Protection Regulation: complaints must be analyzed for systemic issues rather than resolved case by case, and an inadequate complaints process is a separate breach, independent of the underlying claim decision.4 The related and under-built requirement is vulnerable-customer identification at first notification, which the same deck flags most UAE insurers lack entirely in claims.4
6. Outsourcing governance
Written outsourcing agreements, defined service standards, performance monitoring, and the principle that the insurer retains regulatory responsibility regardless of delegation (Article 130 governance of outsourced functions).1,2 The statutory clock does not stop because a third party is doing the work, and the accountability does not transfer with the task. This is the point most often misread:
"TPA delays are your delays. There is no regulatory safe harbor for blaming a third-party administrator or loss adjuster."
Al Tamimi & Company, Agents of Insight session, 7 May 20264
7. Fraud prevention
The framework carries a distinct fraud-prevention obligation (Article 149).1 Its dependency is the first six areas: fraud detection that cannot cite the provenance of the decision it flags produces allegations rather than evidence, and the same structured, traceable record that satisfies an examiner is what makes a fraud finding defensible.
3. What to do before September
Al Tamimi set out five priority actions in their May 2026 session, reproduced here in their own framing because they are the most direct answer to where to start.4
| # | Action | Al Tamimi's stated reason it cannot wait |
|---|---|---|
| 1 | Timeline gap review: map current average claims handling times against the statutory windows | Gives an objective baseline of the current compliance position |
| 2 | Repudiation letter audit: review all rejection templates against the reasoned rejection standard and redesign | Template changes can be implemented quickly, and the exposure from non-compliant letters is immediate |
| 3 | TPA and loss adjuster contract review: service levels, audit rights, data processing agreements, flow-down obligations | TPA delays are the insurer's regulatory liability, and the contracts must reflect this |
| 4 | Data architecture review: audit trail retrievability, retention schedule, deletion processes for claims data | Indefinite retention of claims data is a live PDPL breach today |
| 5 | Complaints process redesign: ensure the internal process meets Consumer Protection Regulation standards as a genuine regulatory gateway | An inadequate complaints process is a separate breach, independent of the underlying claims decision |
Two of the five can be completed inside the window. Rejection templates can be rewritten and deployed in weeks, and their exposure is immediate and per-letter. Contract review is bounded work against a known set of counterparties. The other three are longer, and treating them as if they finish by September is how a firm ends up with a plan it misses rather than a position it can defend. The reconciliation the regulator will look for is the gap review itself, not its completion, which is why the intent standard in the executive summary is the one to plan against. Al Tamimi's own account of how a supervisory conversation opens closes the logic:
"The way the regulator works is, when they ask you a question, they actually have done their diligence. They know the right answer, and they know what you've done. They are only checking whether you're going to accept it or you're going to attempt to defend it, and how."
Anand Singh, Al Tamimi & Company3
A firm that has done the work of knowing its own gaps has something to accept with. A firm that has not is left defending a position it never examined, to a regulator that has. On who runs the review, Singh's view in the discussion was that it is a mixed exercise: legal counsel covers the legal dimension, an operational audit needs operational skills, and internal compliance carries part of it.3
4. How Axxion runs against the framework
Axxion manages the full motor claims lifecycle for insurance partners in the UAE, which puts Axxion inside the same perimeter under Article 61(1)(j) and against the same seven areas.1 Axxion has run the seven-area review this paper recommends against its own operation. What that operation runs, area by area:
| Operational area | What Axxion runs |
|---|---|
| 1. Audit trail integrity | Every write to a claim record is captured to an immutable log as it happens, so the basis for a decision exists at the moment the decision is made. Decisions, escalations and awards post to a claim timeline as they occur. |
| 2. Role segregation | Assessment, repair authorization and payment run as distinct stages, each leaving its own record, with per-insurer isolation and access controls enforced in the platform and step-level gates on the workflow. |
| 3. Decision provenance | Estimate review, negotiation and award each leave their own record, and an external AI damage assessment is pulled by VIN and shown against the negotiated estimate, so the figures trace to their source data. |
| 4. Structured data reporting | Repair, workshop and portfolio data run through structured dashboards, with own-book and pooled benchmarks held for comparison. |
| 5. Complaint resolution | The master claims procedure runs as data with the workflow gated step by step, and decision-letter templates are built to the clause-plus-evidence-plus-rights standard. |
| 6. Outsourcing governance | Axxion is the party an insurer appoints, and operates as the documented, service-levelled, Central Bank-aware partner that keeps the insurer's own outsourcing position defensible. |
| 7. Fraud prevention | Fraud prevention rests on the traceable record above; rework detection and cost-recovery tracking run across the book today. |
The pattern matters more than any single row. The hardest of the seven areas is the audit trail that exists at the moment a decision is made rather than being assembled when a regulator asks, and that is the one Axxion runs as live infrastructure. An operating partner's value on this framework is that it builds the evidence the framework requires into how the claim runs, and can produce it on demand.
The regulatory basis
The sections above set out what the framework asks and what to do about it. The sections that follow set out the basis, what the law changed and why four instruments bear on one claim, for readers who want the detail behind the points already made.
5. What closes in September
Federal Decree-Law No. 6 of 2025 was issued on 8 September 2025 and, under Article 188, came into force the day following its publication in the Official Gazette.1 It consolidated the previous Central Bank law and the dedicated insurance activities law into a single 188-article framework, repealing both under Article 185.1 Insurance supervision now sits inside the same perimeter as banking, under the same supervisory powers and the same enforcement toolkit. Axxion's March 2026 white paper maps that shift in full; this paper does not restate it.2
Article 184 is the transitional provision. It requires all agencies and persons subject to the law to reconcile their positions within one year of entry into force, and gives the Board discretion to extend.1 Article 183 keeps the regulations and circulars issued under the repealed laws in force until the Central Bank replaces them, which is why the operational timing rules did not reset when the statute did.1 Singh's framing of the law's reach corrects the common reading that this is an insurance measure:
"The new law is the starting of the change. This is not the only change. The main law has come in, which is for the entire sector. It's not just for insurance companies, it is for banks, it is for financial institutions, finance companies, everybody else who operates as an LFI."
Anand Singh, Al Tamimi & Company3
The change in posture is most legible in the sanction regime. Article 168 gives the Central Bank twenty-one categories of administrative sanction, among them a fine of up to AED 1 billion on a licensed financial institution and up to AED 5 million on an authorized individual.1 In the discussion, Singh framed the ceilings as existing to force the requirements to be taken seriously rather than to raise revenue, and set the law against the global standard of the International Association of Insurance Supervisors.3 That framing matters more than the number: the regulator's interest is in firms meeting the standard, which is precisely why demonstrated intent carries the weight Singh describes.
6. Why one law is four
The environment is not one instrument but four operating on the same claim decision. Al Tamimi's Agents of Insight deck states that no instrument supersedes another, the Central Bank examines them in a single supervisory review, and a breach of one neither excuses nor mitigates a breach of another.4
The new Civil Code, Federal Decree-Law No. 25 of 2025, took effect on 1 June 2026, replacing the 1985 code that underpinned UAE civil and contractual relations for four decades. It restates the insurance contract provisions with tighter statutory controls on restrictive terms and greater precision on disclosure, indemnity and limitation periods.5 Its operational effect is that a rejection must connect to the peril that caused the loss. Singh illustrated the point: a not-at-fault driver without a licence cannot have the claim rejected on the licence point alone, because the licence did not cause the loss.3
The Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, gives a claimant rights of access over the personal data in a claim file.7 Al Tamimi's Agents of Insight deck sets out that a declined claimant can request the internal record behind the decision, including adjuster reports, assessor notes and fraud flags, and that every internal claims document is therefore potentially disclosable.4 In the discussion, Singh made the same point on the proprietary-information objection: where a file holds the claimant's own personal data, that defence does not survive.3
In February 2026 the Central Bank issued its Guidance Note on the responsible adoption of artificial intelligence and machine learning by licensed financial institutions, built on five principles including transparency and explainability and effective human oversight.6 It is drafted as guidance, and in the discussion Singh described it as close to mandatory in practice, recounting that a Central Bank subsidiary had characterized the note as the minimum standard, below which is not acceptable.3 For claims, the operative consequence is that an automated step in a decision must be explainable, and "proprietary algorithm" is not a regulatory defence.4
7. Outsourcing does not move the obligation
Outsourcing was not addressed in the wider law before. It is now, and the belief it displaces is specific:
"A lot of the time the view that insurers take is, once they have passed on a process to a third party, it's not my problem. The law is clear that it continues to be the insurer's problem. You are fully responsible for the outsourcing. And not just the outsourcing, you need to have made sure that you chose the right vendor, you did the diligence on them and proper audit trail is maintained. And that is where it goes back to the board, that the diligence needs to have a proper process, and the process needs to be signed off by the very top."
Anand Singh, Al Tamimi & Company3
Al Tamimi's deck states the same rule in its enforcement form: a delay by a third-party administrator is the insurer's delay, and there is no regulatory safe harbor for attributing a breach to a TPA or loss adjuster.4
Two consequences follow that most firms have not worked through. The regulatory treatment of a claims arrangement turns partly on the licensing status of the party doing the work. In the discussion, Singh drew the line directly:
"The appointment of a loss adjuster is not really an outsourcing. Anyone who is licensed by the Central Bank of UAE for a certain activity and you appoint them for that activity that would not fall within outsourcing. Outsourcing is only when you go to a third party which is not licensed."
Anand Singh, Al Tamimi & Company3
A firm cannot know which of its arrangements fall inside the outsourcing provisions without knowing which of its partners hold Central Bank licences. And longevity does not grandfather a relationship; in the discussion Singh confirmed that a long-standing loss-adjusting arrangement still has to be re-examined on documentation, service levels and data.3
8. The compliance record is the underwriting asset
The work the framework demands produces something a firm wants independently of the regulator, and this is where a claims operator, rather than a law firm, is the right voice. A structured, traceable record of claim decisions captured as they are made, built to satisfy area 1 and area 4 above, is the same dataset underwriting has been asking claims for, the same evidence fraud detection needs to function, and the same book reinsurers price against. It is one artifact, captured once, that pays into compliance, pricing and recovery at the same time. The firm that builds it only to pass an examination pays for it once and collects on it once; the firm that treats it as an operating asset collects three times.
The reinsurance dimension carries the clearest financial consequence. In the discussion, Singh observed that reinsurer appetite for UAE risk turns partly on data availability, and that clean, consolidated data helps the whole chain, from underwriting quality to fraud to the terms on which international reinsurers will write the book.3 That characterization of reinsurer sentiment is Singh's from the recorded discussion and is not independently verified. The structural point stands regardless of how the sentiment is measured: data quality at the point of the claim decision is the input to the risk price, and the framework is forcing the market to produce it.
Disclaimer. This paper is provided for general information and does not constitute legal advice. It reflects Axxion's reading of the framework as at August 2026 and, where stated, Al Tamimi & Company's published positions. Statements attributed to Anand Singh are drawn from a recorded conversation published by Axxion and reproduce his remarks. Timing figures, market estimates and characterizations of regulator or reinsurer behavior attributed to Al Tamimi are their positions and have not been independently verified by Axxion. No statement here should be relied on as confirmation that any specific requirement applies to any specific firm. Firms should take their own legal advice on how these instruments apply to their operations.
About Axxion
Axxion Claims Settlement Services L.L.C. is the UAE's first dedicated motor third-party administrator. From Dubai, Axxion manages the full motor claims lifecycle for insurance partners: first notification of loss, surveying, repair coordination, quality control, recovery, and settlement. The company serves UAE insurers across both large and small-to-medium carriers and is preparing to extend into Saudi Arabia and the wider GCC.
Compliance by design. Axxion was built to operate inside a tightening regulatory environment. The Central Bank of the UAE absorbed insurance regulation in 2020 and consolidated the framework under Federal Decree-Law No. 6 of 2025, which brings TPAs and loss adjusters explicitly inside the CBUAE perimeter. Every claim Axxion handles passes through formal compliance gates covering UAE PDPL data protection, policyholder-consent requirements, settlement-authority bands, sanctions screening, and audit-trail completeness. Compliance is not an overlay; it is the operating substrate.
The Axxion Intelligent Operating System (AIOS). The ClaimOS that Axxion presents to insurer partners runs on the AIOS, a unified operating layer orchestrating a seven-stage claims pipeline across surveying, estimation, repair coordination, quality control, recovery, settlement, and reporting. The AIOS integrates human operators with structured AI-assisted decision points at every stage. Insurers receive cleaner data, faster cycle times, lower per-claim cost, and a complete audit trail, without giving up control over their portfolio.
More information: Managing Director and Co-Founder Frederik Bisbjerg · f@axxion.co · http://www.axxion.co/
References
- Federal Decree-Law No. (6) of 2025 Regarding the Central Bank, Regulation of Financial Institutions and Activities, and Insurance Business, issued 8 September 2025. Articles 61(1)(j), 90, 91, 122, 130, 148, 149, 168, 183, 184, 185, 188. Primary text.
- Axxion Claims Settlement Services, Motor Claims Compliance Under UAE Federal Decree-Law No. 6 of 2025, 2026. Source of the seven operational areas.
- Anand Singh (Al Tamimi & Company) in conversation with Frederik Bisbjerg (Axxion), recorded July 2026.
- Al Tamimi & Company, The Real Impact of Federal Decree Law No. 6 of 2025 on Insurance Claims Operations, presented by Anand Singh, Axxion Agents of Insight Edition 1, 7 May 2026.
- Federal Decree-Law No. 25 of 2025 (the new Civil Code), in force 1 June 2026, replacing Federal Law No. 5 of 1985. Insurance contract provisions restated in Book Two, Section Three.
- Central Bank of the UAE, Guidance Note on the Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions in the U.A.E., issued 23 February 2026.
- Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL).