Before getting into the numbers, it helps to be clear about the terms this piece leans on, since they get used loosely in board meetings and less loosely by regulators. Disaster Recovery, also known as DR, entails the systems, locations, and processes that the bank will use to recover its vital IT services after an occurrence of any disaster, whether caused by a technical failure, a hacker attack, or any physical disturbance. Within any DR framework lie two factors: first, the recovery time objective, also known as the RTO, is the time it takes to restore the services after an occurrence of an outage, while second, the recovery point objective, or RPO, is the amount of data lost in case of an outage. Zoom out further, and DR is really just one piece of business continuity management, the broader discipline of keeping a bank’s critical operations running through and after a disruption.
The model this piece walks through is what we’d call a downtime cost model: a structured way of estimating the full financial impact of an outage by adding up three layers: lost transaction revenue, regulatory penalties, and the reputational or churn-related losses that follow a visible failure. These guidelines will all be underpinned by the central bank policies within the region, namely the Business Continuity Management Framework policy at SAMA and the Operational Risk and Recovery Planning regulation at the Central Bank of the UAE, both of which mandate that the board of directors approves and tests the DR and BCM plans regularly.
Now that the terminology is sorted out, everything else about the model becomes simple.
It is very uncommon for banks in either Riyadh or Abu Dhabi to give any thought to downtime before it occurs, and when it does, it is all anybody there can think about. The mobile app freezes mid-transfer, the card network stalls, and within minutes, social media has already noticed. What most institutions lack in that moment isn’t a recovery plan. It’s a number. A defensible figure that tells the board and the regulator exactly what an hour of silence costs, and why the DR budget on the table is smaller than the risk it’s meant to cover.
This piece lays out a simple model for building that number. It draws on three layers of cost that apply to nearly every retail and commercial bank operating in the Gulf: lost transaction volume, regulatory penalties, and reputational damage. None of these require exotic assumptions. They rely on figures a finance team already has on hand.
Layer one: lost transaction volume
Start with what the bank actually processes. Saudi Arabia alone recorded 10.8 billion electronic transactions in 2023, a 24 percent jump from the year before, and “Electronic payments account for the majority of retail payments and continue to grow. In the GCC, the percentage of mobile banking uptake is greater than 70% in countries such as UAE and Saudi Arabia. The value of digital payments in the region is expected to increase sharply until 2030. These aren’t abstract growth charts. They mean that a bank’s daily transaction volume, divided across its operating hours, gives a rough hourly baseline of activity that simply stops the moment core systems go down.
To build this layer, take the average daily transaction value, divide it by active hours (often 16 to 24 for a digital-first bank), and apply a conservative capture rate, since not every failed transaction represents fully lost revenue. Some customers retry later. Many don’t, particularly for time-sensitive payments like payroll runs or merchant settlements. Industry research estimates downtime costs for large financial firms in excess of US$5 million per hour. This is dependent on transaction volume, the extent of the problem, and the business model for institutions with high transaction-critical loads, and even mid-sized regional banks can see six- or seven-figure losses within a single hour of a core banking outage.
Layer two: regulatory penalties
GCC regulators treat operational resilience as a supervisory priority, not a suggestion. SAMA’s BCM Framework necessitates that member organizations adopt BCM programs that are compliant with the internationally accepted standards and mandates that any disruptive incident classified as medium or high severity be reported to SAMA’s Banking IT Risk Supervision immediately, followed by a formal post-incident report. The Central Bank of the UAE’s Operational Risk Regulation similarly requires, requiring board-level approval of DR and BCM plans, annual review, and prompt notification of any event likely to trigger a continuity plan or materially affect operations.
In accordance with the situation and supervisory assessments, the regulators may take financial measures, make remediation plans, or provide more supervision, require formal remediation plans, or apply increased supervisory scrutiny that can follow an institution for years. For the cost model, this layer should include the direct fines a bank might face for reporting failures or repeated resilience gaps, plus the softer cost of remediation work and heightened audit attention that regulators can place on institutions they view as high risk.
Layer three: reputational cost
This is the layer boards tend to underestimate, largely because it’s harder to put a number on. But the data is not encouraging for banks that fail publicly. Nearly a quarter of banking customers worldwide say they are likely to switch banks within twelve months, according to Caliber’s 2023 Financial Services Reputation Report, which surveyed more than 10,000 consumers globally, say they’re likely to switch banks within twelve months, and that number climbs above a third in some markets. Trust and prior satisfaction do not fully offset the damage from a visible operational failure. Other studies have indicated that over 50% of customers discontinued their association with a brand following a negative experience with it, while almost 30% of them ended their relationship completely.
In case of a GCC bank, this means calculating a churn-related cost: determine the customer lifetime value and multiply that by the churn increase based on the severity of outages (an easily explainable outage is very different from several hours of application outage). Add the cost of the PR and customer service response required to contain the damage, and this layer often rivals the direct transaction losses from layer one.
Putting the model together
A usable downtime cost figure adds these three layers for a single hour of full outage, then adjusts for the type of failure. A partial degradation affecting one channel costs less than a full core banking shutdown. A failure during peak salary disbursement days, common across the Gulf around the last week of the month, costs considerably more than the same failure on a quiet Friday afternoon.
Once a bank has this hourly figure, the DR investment conversation changes shape entirely. Instead of asking how much a secondary data center costs, the board asks how many hours of downtime this investment prevents over five years, and what that is worth. A DR site with a sub-fifteen-minute RTO, geographically separated from the primary facility and tested quarterly, is priced against a realistic loss figure rather than treated as a compliance line item.
Consider a simplified example. A mid-sized regional bank processing the equivalent of 200 million dollars in daily transaction value, spread across 20 operating hours, has a rough hourly transaction baseline of 10 million dollars. Apply an illustrative capture rate of 40 percent for genuinely lost activity (a working assumption for this example, not a benchmark figure), and layer one alone reaches 4 million dollars for a single hour of full outage. Add a modest regulatory exposure figure for a medium-severity reporting failure, plus a churn-adjusted reputational cost calculated against a slice of the affected customer base, and the combined hourly figure can comfortably clear 5 to 6 million dollars. Multiply that by even a handful of hours of unplanned downtime across a year, and the case for a properly resourced DR site tends to build itself. Cost can vary depending on bank sizes, and this example generally applies to financial institutions.
This is also why location and architecture matter as much as the recovery technology itself. A DR facility built to Tier III or Tier IV standards, located away from the main site’s power grid and seismic zone, and connected through diverse network paths, closes part of the gap between paper compliance and actual resilience. But the Tier rating alone does not determine how fast a bank recovers. That depends just as much on the DR architecture itself, how data is replicated between sites, how much of the failover process is automated versus manual, and how often the whole sequence is tested under realistic conditions. Institutions that combine a well-sited facility with tested replication and automated failover, rather than relying on infrastructure certification alone, tend to recover in minutes rather than hours when something does go wrong. Well-designed and regularly tested DR environments can significantly reduce recovery times.
Based on the chosen approach of the organization, disaster recovery can be provided via the use of a secondary data center, collocation, DRaaS, or hybrid clouds, subject to meeting resiliency goals and regulatory demands.
The number matters because budgets get approved against numbers, not against fear of a hypothetical event. A bank that can show its board a credible hourly downtime figure, built from its own transaction data, its own regulatory exposure, and its own customer base, is in a far stronger position to secure the DR investment that figure justifies.
FAQ
What is the average cost of one hour of downtime for a bank in the GCC?
It varies by institution size and the type of outage, but financial services generally sit among the highest-cost industries for downtime, often exceeding five million dollars per hour for large, transaction-heavy banks. Regional banks with smaller transaction volumes will see a lower figure, though still significant once regulatory and reputational costs are added in.
Why do GCC regulators care so much about disaster recovery specifically?
Because a bank outage doesn’t just affect one institution. It can disrupt payment networks, payroll cycles, and public confidence in the financial system as a whole. That’s why frameworks like SAMA’s BCM Framework and the Central Bank of the UAE’s Operational Risk Regulation require board-level sign-off, regular testing, and prompt incident reporting rather than leaving continuity planning as an internal IT matter.
How is RTO different from RPO?
RTO measures how long it takes to get systems back online after a failure. RPO measures how much data, in terms of time, a bank can afford to lose. Many banks target an RTO of around fifteen minutes and an RPO of near zero for core banking, meaning services come back quickly and almost no transaction data is lost in the process.
Do regulatory fines really factor into a downtime cost model, or is that overstated?
They’re a real and quantifiable part of the exposure. Beyond direct financial penalties, regulators can increase audit frequency, impose operational restrictions, or apply capital surcharges to institutions with repeated resilience gaps. Those costs compound over time and should be included alongside the immediate transaction losses from an outage.
What makes a disaster recovery site effective rather than just a compliance checkbox?
Distance from the primary site, independent power and network paths, and regular live testing. A DR site that only exists on paper, or one that has never been tested under real failover conditions, tends to underperform exactly when it is needed most. Institutions that treat the DR site as an operational twin, tested quarterly, recover faster and with far less disruption to customers.
How should a bank start building its own downtime cost figure?
Begin with three numbers already sitting in existing reports: average hourly transaction value, the bank’s specific regulatory reporting obligations under its home central bank’s framework, and customer lifetime value by segment. Combining these gives a working hourly downtime figure that can anchor the DR budget conversation with the board.