Frequently Asked Questions
Find answers to your questions about cybersecurity and the CISO Consulting platform
Compliance & Regulations 6
The SAMA Cybersecurity Framework is a comprehensive framework issued by the Saudi Arabian Monetary Authority to help financial institutions manage cyber risks. It covers governance, risk management, compliance, operations, and third-party security.
ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS). It is not mandatory in Saudi Arabia by law, but is strongly recommended and often required by enterprise customers and government tenders. Achieving ISO 27001 certification demonstrates a mature security posture and can accelerate compliance with SAMA CSF and NCA ECC.
ISO 27001:2022 is the internationally recognized standard for Information Security Management Systems (ISMS). For Saudi fintechs, achieving certification signals a mature, structured approach to cybersecurity — but understanding how it interacts with local regulatory frameworks is essential.
What ISO 27001:2022 Requires: The 2022 revision introduced 93 controls organized into four themes (Organizational, People, Physical, Technological), replacing the 2013 version's 114 controls. It added 11 new controls covering threat intelligence, cloud security, ICT readiness for business continuity, and data masking — areas directly relevant to fintech operations.
Complementary Value with SAMA CSF: ISO 27001 provides a strong governance backbone. Many SAMA CSF controls map directly to ISO 27001 Annex A controls, meaning a well-implemented ISMS can satisfy a significant portion of SAMA's requirements. However, SAMA CSF goes further with sector-specific controls around payment systems, SWIFT security, and regulatory reporting that ISO 27001 does not explicitly address. Think of ISO 27001 as the foundation and SAMA CSF as the sector-specific overlay.
Complementary Value with NCA ECC: NCA ECC (Essential Cybersecurity Controls) shares significant overlap with ISO 27001, particularly in access management, vulnerability management, and incident response. NCA has acknowledged ISO 27001 certification as a positive indicator during assessments, though it does not replace ECC compliance.
PDPL Alignment: ISO 27001:2022 Annex A Control 5.34 (Privacy and protection of PII) directly supports PDPL obligations, making the certification valuable for privacy compliance as well.
Practical Guidance: Use a GRC platform to perform a gap analysis mapping your existing ISO 27001 controls against SAMA CSF and NCA ECC requirements. This avoids duplicating effort and clearly shows regulators the control coverage you already have in place.
Third-party risk management is a critical compliance obligation for Saudi fintechs. SAMA CSF Control 3.3 (Third-Party Management) and NCA ECC Article 2-13 together create a comprehensive framework that requires fintechs to assess, monitor, and manage cybersecurity risks introduced by vendors, partners, and service providers.
Core Requirements:
- Pre-Onboarding Due Diligence: Conduct cybersecurity risk assessments before engaging any third party with access to systems or data. This includes reviewing the vendor's security certifications (ISO 27001, SOC 2), penetration testing history, and incident response capabilities.
- Contractual Security Clauses: Per SAMA CSF Control 3.3.2, contracts must include minimum cybersecurity requirements, audit rights, incident notification obligations (typically within 72 hours), and data handling standards aligned with PDPL.
- Ongoing Monitoring: Establish annual reassessments for high-risk vendors. NCA ECC emphasizes continuous monitoring for vendors with privileged access to critical national infrastructure-connected systems.
- Concentration Risk: SAMA guidance warns against over-reliance on a single vendor, particularly in cloud and core banking services. Fintechs must document mitigation strategies for concentration risk.
- Fourth-Party Risk: Assess subcontractors and downstream dependencies of your primary vendors — a growing area of regulatory scrutiny.
Practical Tip: Develop a tiered vendor classification framework (Critical, High, Medium, Low) and tailor your due diligence and monitoring intensity accordingly. Maintain a vendor risk register as evidence for SAMA assessments.
ISO 27001:2022 restructures Annex A from 14 domains and 114 controls to 4 themes (Organizational, People, Physical, Technological) and 93 controls. Key additions include controls for Threat Intelligence, Information Security for Cloud Services, ICT Readiness for Business Continuity, Physical Security Monitoring, Configuration Management, and Data Masking. Organizations certified to 2013 must transition by October 2025.
Security awareness training is a foundational control that both SAMA CSF and NCA ECC explicitly mandate, yet many fintechs treat it as a checkbox exercise rather than a behavioral change program.
Regulatory Baseline:
- SAMA CSF Control 3.1.4 requires all employees to receive cybersecurity awareness training upon joining and at regular intervals thereafter, with content tailored to job roles and risk exposure.
- NCA ECC-1:2018 Control 2-7 mandates that organizations implement a cybersecurity awareness and training program covering all staff, including contractors and third parties with system access.
Program Design Best Practices:
1. Role-Based Curriculum: Generic training is insufficient. Develop separate tracks for general staff (phishing, social engineering, password hygiene), developers (OWASP Top 10, secure coding), and executives (board-level cyber risk, regulatory obligations).
2. Phishing Simulations: Run monthly simulated phishing campaigns. Employees who fail should be automatically enrolled in targeted micro-training rather than disciplined — this creates a learning culture rather than a punitive one.
3. Frequency and Format: Annual training alone does not satisfy SAMA examiners. Adopt a continuous model: monthly awareness nudges, quarterly topic-focused modules, and annual comprehensive assessments.
4. Metrics and Reporting: Track click rates on phishing simulations, training completion rates by department, and knowledge retention scores. Report quarterly to the CISO and annually to the Board Risk Committee.
5. PDPL Awareness: Include dedicated modules on handling personal data, data subject rights under PDPL, and reporting obligations — critical for customer-facing fintech teams.
Document all training records for a minimum of 3 years to support SAMA and NCA audit evidence requests.
No matching questions found.
Didn't find what you're looking for?
✉️ Contact Us