Open banking in the Gulf: UAE, Saudi and Bahrain compared
How the three Gulf frameworks differ on architecture, licensing, scope and operational burden, and what that means for teams building across them.
The Gulf does not have one open banking model. It has three neighbouring regimes that made materially different choices about architecture, supervision and operational burden.
That matters because “GCC strategy” can hide three separate implementation problems.
The UAE centralised the ecosystem around a single API Hub and a Trust Framework. Bahrain built its framework earlier and imposed dedicated-interface, testing-facility and availability rules directly on retail banks. Saudi Arabia moved from framework-building and sandbox supervision into a licensing phase in March 2026, but its public material still says less about market plumbing than the UAE’s.
For a team building across the region, those are not stylistic differences. They change the integration model, the onboarding queue, and the amount of institution-specific work you carry.
The short comparison
| Market | Regulator | Market model | What third parties are clearly allowed to do | What stands out |
|---|---|---|---|---|
| UAE | Central Bank of the UAE / Open Finance UAE | Centralised API Hub plus Trust Framework | Connect through the hub under defined roles and certifications | One connection path, but heavy onboarding and conformance burden |
| Saudi Arabia | Saudi Central Bank (SAMA) | Framework plus licensing | Officially licensed open-banking services under SAMA supervision | Licensing phase is now live, but public implementation detail is still relatively thin |
| Bahrain | Central Bank of Bahrain | Bank-facing dedicated interfaces under a common framework | AIS and PIS through licensed providers | The rules are explicit about testing facilities, uptime parity and non-discriminatory access |
UAE: the most centralised of the three
The UAE does not follow the model of connecting separately to each bank’s own flavour of open banking API. Its framework routes participants through a central API Hub, and the surrounding Trust Framework handles participant discovery, client onboarding and client authentication.
That centralisation has two consequences.
First, it simplifies the shape of the technical problem. A provider is not building and maintaining bank-specific connections one by one; it is integrating into a supervised shared infrastructure.
Second, it moves cost and complexity into the front door. The UAE’s Trust Framework requires participants to manage transport, signing and encryption certificates, rotate them at least once every 12 months, register roles and metadata, and clear external certification before production. No consumer data passes through the Trust Framework itself, but a large amount of onboarding state does.
That is why the UAE’s regime reads cleanly in architecture diagrams and heavily in launch plans. The build is only one track. The onboarding queue is the other.
Related:
- Getting into UAE open finance: the Trust Framework
- The UAE’s security profile: ten-minute tokens and no DPoP
- UAE open finance pricing: what the API Hub actually costs
Saudi Arabia: licensing has now started
Saudi Arabia’s open banking story changed materially on 26 March 2026, when SAMA announced the commencement of licensing fintech companies to provide open banking services following the regulatory sandbox phase.
On the same day, SAMA announced licences for two companies to conduct payment services by providing account information, describing that as one of the services associated with open banking.
The important shift is not the company count. It is the supervisory phase change.
Once a market moves from sandbox experimentation into live licensing, the questions a serious operator asks change. The problem is no longer merely whether the regulator has a framework. It is whether your product, governance and operating model fit the licensed route the framework now supports.
Saudi public material remains less explicit than the UAE’s about the day-to-day mechanics of the ecosystem. That matters. A market can be live in supervisory terms while still leaving more of the implementation texture to programme documents, participant guidance or bank-specific execution.
For teams comparing the Gulf, Saudi Arabia currently looks like the market where the licensing signal is clear, but the public implementation picture is still thinner than in the UAE.
Related: Saudi open banking is now a licensed activity
Bahrain: earlier, and more bank-facing in its rules
Bahrain launched the Bahrain Open Banking Framework in October 2020 and said at the time that it built on comprehensive open-banking rules issued in December 2018.
Two service categories are explicit in the launch material: account information service and payment initiation service. The rulebook then becomes unusually concrete about the operating expectations imposed on retail banks.
Banks must provide access to customer accounts to AISPs and PISPs on an objective, non-discriminatory basis, through a dedicated interface. They must also provide a testing facility not only to authorised AISPs and PISPs, but also to sandbox participants and firms granted in-principle confirmation to proceed with licensing. And the dedicated interface must offer the same level of availability and performance as the bank’s own direct online channel.
That is a very different flavour of openness from the UAE model.
The UAE concentrates ecosystem coordination in a central hub and trust layer. Bahrain’s public rules lean harder on the obligations of each bank-facing interface: testing, access parity, availability, contingency measures and reporting.
What changes for a multi-market team
Three practical consequences follow.
1. There is no single Gulf deployment pattern
If your team has a working open-banking stack in one Gulf market, do not assume it portably answers the next. A centralised hub model, a bank-interface model and a licensing-first market can all use similar vocabulary while creating different delivery risks.
2. Onboarding burden is distributed differently
In the UAE, a large share of the burden sits in the central ecosystem: trust framework registration, certificates, certification and hub integration.
In Bahrain, the rules emphasise what each retail bank owes the ecosystem: dedicated interfaces, testing facilities and availability parity.
In Saudi Arabia, the newly explicit licensing phase pushes attention onto the supervised route itself: who is licensed, for what, and how the programme matures from sandbox to normal market entry.
3. “Open banking in the Gulf” is too broad for planning
The phrase is still useful as a market category. It is not specific enough for delivery planning, budgeting or timeline estimation. Those need to be market-specific from day one.
The practical reading
If you want the simplest summary:
- UAE is the most architecturally centralised.
- Bahrain is the most explicit, in public rulebook form, about bank interface obligations.
- Saudi Arabia has now clearly crossed into licensing, but still requires closer reading of programme-specific material to understand the full implementation path.
That is enough to stop treating the Gulf as one regulatory surface, which is the mistake most comparative writing still makes.
Sources
- Trust Framework User Documentation, Open Finance UAE, updated 5 August 2025. Checked 30 July 2026.
- Commercial and Pricing Model, Open Finance UAE, version 1.0, published 4 October 2024. Checked 30 July 2026.
- SAMA Commences Licensing of Fintech Companies to Provide Open Banking Services, Saudi Central Bank, published 26 March 2026. Checked 30 July 2026.
- SAMA Licenses “Altknwlwjya aljadydh llhulul albrmjyh” and “lyn tknwlwjyz Company Saudi Arabia litqniyat nuzum almaelumat” to Provide Open Banking Services, Saudi Central Bank, published 26 March 2026. Checked 30 July 2026.
- CBB launches the Bahrain Open Banking Framework, Central Bank of Bahrain, published 28 October 2020. Checked 30 July 2026.
- Volume 2: General Requirements, GR-6 Open Banking, Central Bank of Bahrain Rulebook. Checked 30 July 2026.
This article is a market comparison, not a licensing memo. Where implementation depends on the precise wording of a current programme document, use the source itself rather than the summary.