Money sitting in a UAE payment app is not a bank deposit, and it is not protected the way one is. What protects it instead is a segregation rule: Article 14 of the Central Bank’s Retail Payment Services and Card Schemes Regulation requires providers to keep your funds insulated against the claims of their other creditors, in particular in the event of insolvency.
The regulation also states something most users would not guess: “At no time shall Payment Service Providers hold funds of Retail Payment Service Users unless these are funds in transit.” A licensed payment app is a conduit, not a place to keep a balance. This guide covers who must be licensed and in which of the four categories, exactly how your money must be ring-fenced, the disclosures you are owed before you sign up, your rights over unauthorized transactions, and the 30-day notice a provider must give before changing its terms.
Who Needs a Licence
The regulation covers nine categories of digital payment service: payment account issuance, payment instrument issuance, merchant acquiring, payment aggregation, domestic fund transfer, cross-border fund transfer, payment token services, payment initiation services, and payment account information services. Card schemes must also be licensed by the Central Bank.
Providers apply for one of four licence categories, and the category determines what they may do:
| Licence | What it permits |
|---|---|
| Category I | The broadest: payment account and instrument issuance, merchant acquiring, aggregation, domestic and cross-border fund transfers, and payment token services |
| Category II | The same list without payment tokens, so including cross-border transfers |
| Category III | Domestic only: account and instrument issuance, merchant acquiring, aggregation and domestic fund transfers |
| Category IV | Payment initiation services and payment account information services only, meaning open-banking style access rather than holding money |
The practical use of that table is diagnostic. An app offering international transfers must hold at least a Category II licence. An app that only reads your bank data or initiates payments from your existing bank account sits in Category IV and should never be holding a balance at all.
The Central Bank also has the right to receive information on card scheme fees and charges, and to regulate them if it considers it appropriate. And the regulation requires proper contractual arrangements between banks or other providers issuing payment accounts on one side, and providers offering payment initiation and account information services on the other, which is the legal plumbing behind open banking in the UAE.
How Your Money Must Be Ring-Fenced
Article 14 sets two different safeguarding regimes depending on how fast the provider settles, and the dividing line is 24 hours.
Providers that settle within 24 hours must segregate user funds so that they are not commingled at any time with the funds of any person other than the users on whose behalf they are held, and so that they are insulated in the users’ interest against the claims of the provider’s other creditors, in particular in insolvency.
Providers that settle after 24 hours face a heavier requirement. They must either open a separate escrow account with a bank, restricted so that no operation is possible except transferring the deposited funds to the end beneficiary, or cover the funds with an insurance policy or a bank guarantee from a regulated insurer or bank that does not belong to the same group as the provider.
That last condition is the one that gives the protection teeth. A guarantee from an affiliate inside the same corporate group would fail in the same insolvency that triggered the claim, and the regulation forecloses it.
Banks acting as payment service providers are treated differently: they are not required to establish a separate escrow account, insurance policy or bank guarantee, but a separate bank account under the name of the concerned users must be set up to protect the funds.
What this protection is, and what it is not
Segregation is not deposit protection. It means that if the provider fails, your money should be identifiable as yours rather than forming part of the pool available to its creditors. It does not make the provider a bank, and it does not import the treatment that applies to bank deposits, which is covered separately in our guide to whether money in a UAE bank is protected.
The “funds in transit only” rule in Article 14 is the other half of the picture. A licensed provider is not authorized to hold a standing balance for you indefinitely. Treating a payment app as a savings account works against the model the regulation is built on.
What You Must Be Told Before You Sign Up
Article 14 requires providers to give terms and conditions to each new user sufficiently in advance of entering the relationship to allow an informed decision, written in clear, plain and understandable language, in a manner that is not misleading, and provided in both Arabic and English if the user asks.
Existing users are entitled to the terms on written request, delivered by their preferred channel including email or the mobile app.
For transactions under a single payment service agreement, the regulation lists ten items that must be disclosed before the contractual relationship begins:
- The schedule of fees, charges and commissions, including conversion rates and withdrawal charges where applicable.
- The provider’s contact details, legal name and registered address, including the address of any agent or branch.
- The form and procedure for giving consent to a payment order, and for withdrawing that consent.
- The communication channel between the provider and the user.
- How the funds are safeguarded under the segregation rules, and how any reserve of assets is held.
- The manner and timeline for notifying the provider of an unauthorized or incorrectly initiated or executed transaction.
- Information on the provider’s and the user’s liability for unauthorized payment transactions.
- The service level for the payment service.
- Information on the provider’s complaint procedure.
- The provider’s procedure for reporting unauthorized transactions.
Two of those are worth checking before you install anything. The conversion rate disclosure is where the real cost of a cross-border transfer usually sits, not in the headline fee. And the liability allocation for unauthorized transactions is the single most important term in the contract, because the regulation requires it to be disclosed but leaves its content to the agreement.
Unauthorized Transactions
The regulation defines an unauthorized payment transaction as one “for the execution of which the Payer has not given consent.” Consent must be given in the form agreed between you and the provider, and may also be given via the payee or a payment initiation service provider.
Your practical protection comes from three places rather than one:
- The disclosure duties above, which force the provider to tell you the notification timeline and the liability split up front, and to have a documented reporting procedure.
- Professional indemnity insurance. Providers offering payment initiation services must carry cover for their liabilities for unauthorized payment transactions and for non-execution, defective or late execution. Providers offering account information services must carry cover for liability arising from non-authorized or fraudulent access to, or use of, payment account information.
- The Consumer Protection Standards, which apply alongside this regulation. Article 14 requires providers to observe and comply with the Central Bank’s consumer protection requirements and standards, though it adds that where the two conflict, this regulation prevails.
Speed matters more than argument. The regulation frames the notification timeline as a contractual term you were told about in advance, so reporting within it is what preserves your position. Where the transaction ran on a card rather than through the app’s own balance, the chargeback route may also be open, as set out in our guide to card fraud and chargebacks in the UAE.
Security obligations behind the scenes
The regulation requires providers to run a technology and cyber security risk management framework proportionate to the nature, size and complexity of the business, to safeguard the APIs they expose, and to operate a security administration function that monitors for unusual or unauthorized activity. “Sensitive Payment Data” is defined as data including personalized security credentials that could be used to carry out unauthorized activities, with a carve-out for account name and account number in the context of payment initiation and account information services.
Changes to Terms, and Your Right to Walk
Any change to the terms and conditions must be communicated to you sufficiently in advance and at least 30 calendar days before it takes effect. If you do not agree with the revised terms, you are entitled to terminate the relationship at no charge.
That pairing is the most immediately usable right in the regulation. A fee increase, a change to conversion pricing or a new limit arriving with less than 30 days’ notice is a breach of the notice period, and a provider that charges you an exit fee for leaving over a term change it imposed is acting against Article 14.
Payment Tokens and Stablecoins
Payment token services sit in Category I only, and the regulation treats them more like an issuance than a payment. A provider issuing a payment token must publish a White Paper, approved by the Central Bank and endorsed by its management, written in simple, easy to understand and non-misleading language, and dated.
The White Paper must describe the token, the rights and obligations attached to it, the procedures and conditions for exercising them, the underlying technology, the risks, the governance arrangements including who operates and holds the reserve, a detailed description of the Reserve of Assets and its custody and segregation, the investment policy if the reserve is invested, and information on the nature and enforceability of holders’ rights, including how those rights would be treated in insolvency proceedings.
On the reserve itself, the regulation requires it to be segregated from the provider’s own assets and requires the provider to have prompt access to it to meet redemption requests from token holders, with the purchase and redemption procedure and the list of persons entitled to redeem set out in the White Paper.
Payment tokens are distinct from virtual assets. The regulation defines a virtual asset as a digital representation of value that can be digitally traded or transferred and used for payment or investment, expressly excluding digital representations of fiat currencies and securities. Crypto trading and custody sit under a different regime, covered in our guide to VARA and crypto in Dubai.
How to Check a Provider and What to Do If It Fails You
- Check the licence, and the category. The Central Bank licenses these providers, so an app offering cross-border transfers should hold at least a Category II licence. Absence of a licence is the single biggest red flag.
- Read the safeguarding disclosure. The provider is required to tell you how it safeguards funds. Whether it settles inside or outside 24 hours determines whether you are relying on segregation alone or on an escrow account, insurance policy or third-party bank guarantee.
- Keep the terms you were given. They are the source of the notification timeline and the liability split, and the provider had to give them to you before you signed up.
- Report unauthorized transactions inside the stated window. The reporting procedure is a mandatory disclosure item, so it exists and you were told about it.
- Complain to the provider first, then escalate. The complaint procedure is another mandatory disclosure item. Escalation to the Central Bank’s consumer protection route generally requires the provider to have had its own opportunity to resolve the matter first, the same sequencing that applies to other complaints against licensed financial institutions.
- Do not park money you cannot lose access to. The regulation’s own position is that these providers hold funds only in transit.
For everyday choices between providers, our guides to money transfer apps in the UAE and what works with Wise and Revolut here cover the commercial side.
Frequently Asked Questions
Is money in a UAE payment app protected like a bank deposit?
No. It is protected by segregation rather than by deposit protection. Article 14 of the Retail Payment Services and Card Schemes Regulation requires providers to keep user funds from being commingled with anyone else’s and to insulate them against the claims of the provider’s other creditors, particularly in insolvency. The regulation also states that providers shall at no time hold user funds unless they are funds in transit, so a payment app is not designed to be a place to keep a balance.
Do payment apps need a licence in the UAE?
Yes. Anyone providing retail payment services must hold one of four Central Bank licence categories, and card schemes must be licensed too. Category I is the broadest and includes payment token services. Category II covers the same services without tokens, including cross-border transfers. Category III is domestic only. Category IV covers payment initiation and payment account information services, meaning open-banking style access rather than holding money.
How must a UAE payment provider safeguard my money?
It depends on settlement speed. Providers settling within 24 hours must keep user funds unmingled with anyone else’s and insulated against their other creditors’ claims, particularly in insolvency. Providers settling after 24 hours must either open a separate escrow account with a bank restricted to transferring funds to the end beneficiary, or cover the funds with an insurance policy or bank guarantee from a regulated insurer or bank outside their own group. Banks acting as providers must instead set up a separate bank account in the users’ names.
What must a payment app tell me before I sign up?
Ten items under Article 14, given before the contractual relationship begins: the schedule of fees, charges and commissions including conversion rates and withdrawal charges; the provider’s legal name, registered address and contact details; how to give and withdraw consent to a payment order; the communication channel; how funds are safeguarded; the manner and timeline for notifying unauthorized or incorrect transactions; the liability split for unauthorized transactions; the service level; the complaint procedure; and the procedure for reporting unauthorized transactions.
How much notice must a UAE payment provider give before changing its terms?
At least 30 calendar days before the change takes effect, communicated sufficiently in advance. If you do not agree with the revised terms and conditions, you are entitled to terminate the contractual relationship at no charge. A provider that shortens that notice, or charges an exit fee for leaving over a change it imposed, is acting against Article 14.
What counts as an unauthorized payment transaction in the UAE?
One for the execution of which the payer has not given consent. Consent must be given in the form agreed between the payer and the provider, and may also be given via the payee or a payment initiation service provider. Providers must disclose in advance the manner and timeline for notifying them, the liability split, and their reporting procedure, so acting within the stated window is what preserves your position.
Are payment apps insured against fraud in the UAE?
Certain categories carry mandatory professional indemnity insurance. Providers offering payment initiation services must hold cover for their liabilities for unauthorized payment transactions and for non-execution, defective or late execution of transactions. Providers offering payment account information services must hold cover for liability arising from non-authorized or fraudulent access to, or use of, payment account information. That is cover for the provider’s liability rather than a direct guarantee to you.
What is a payment token under UAE rules?
A payment token is a service that only a Category I licensee may provide, and issuing one requires a Central Bank-approved White Paper written in simple, non-misleading language. It must describe the token, holders’ rights and how to exercise them, the technology, the risks, the governance, the Reserve of Assets and its custody and segregation, any investment policy, and how holders’ rights would be treated in insolvency. The reserve must be segregated from the provider’s own assets, with prompt access to meet redemption requests.
Is a payment token the same as cryptocurrency in the UAE?
No. The regulation separately defines a virtual asset as a digital representation of value that can be digitally traded or transferred and used for payment or investment, expressly excluding digital representations of fiat currencies, securities and other financial assets covered elsewhere. Payment tokens sit inside the retail payment services licensing regime, while crypto trading and custody are regulated under a different framework.
How do I complain about a payment app in the UAE?
Start with the provider. Its complaint procedure is one of the items it must disclose to you before you enter the relationship, and Article 14 requires providers to observe the Central Bank’s consumer protection requirements and standards alongside this regulation. Escalation beyond the provider generally requires it to have had its own opportunity to resolve the matter first, so opening a complaint file with the provider is what unlocks the next stage.
Official Sources
- Central Bank of the UAE – Retail Payment Services and Card Schemes Regulation
- Central Bank of the UAE – Consumer Protection Standards
- Central Bank of the UAE – Licensing
Information is current as of August 2026. Every licence category, safeguarding rule, disclosure item and notice period above was read from the text of the Central Bank of the UAE’s Retail Payment Services and Card Schemes Regulation as published in the CBUAE Rulebook. Four limitations are stated rather than smoothed over. The regulation requires the liability split for unauthorized payment transactions to be disclosed to the user but leaves its content to the contract between the parties, so no statement of who bears a fraudulent transaction can be made here; read your own terms. No licensing fee, capital requirement or penalty figure is quoted, because those sit in provisions and schedules not reproduced in this guide. The Central Bank periodically amends and renumbers rulebook instruments, so verify the current text before relying on an article reference in a formal complaint. And firms operating from the DIFC or ADGM are supervised by those centres’ own regulators under separate payment services regimes, which are not covered here. This is general information, not legal or financial advice.