Frequently Asked Questions
Find answers to your questions about cybersecurity and the CISO Consulting platform
SAMA & Banking 220
All financial institutions regulated by the Saudi Arabian Monetary Authority (SAMA) must comply, including commercial banks, insurance companies, finance companies, payment service providers, and fintech firms operating in the Kingdom.
The SAMA Cybersecurity Framework v2.0 contains 251 sub-controls organized across 12 domains covering Governance, Risk Management, Identity & Access, Operations Security, Network Security, System Acquisition, Third-Party Management, Business Continuity, and Threat Management.
Under SAMA CSF Control Domain 3.3 (Third-Party Cybersecurity), regulated entities must implement a structured vendor risk management lifecycle covering onboarding, ongoing monitoring, and offboarding. Here's how to structure it effectively:
1. Vendor Classification & Tiering: Categorize vendors by criticality — Tier 1 (critical/core banking vendors), Tier 2 (important), and Tier 3 (low-risk). This determines the depth of due diligence required.
2. Pre-Onboarding Due Diligence: Require vendors to complete a cybersecurity questionnaire aligned with SAMA CSF controls. Request evidence of certifications such as ISO 27001 or SOC 2. For Tier 1 vendors, consider independent security assessments.
3. Contractual Controls: Embed cybersecurity obligations in contracts, including right-to-audit clauses, incident notification timelines (typically 72 hours per SAMA expectations), data handling requirements aligned with PDPL, and minimum security standards.
4. Continuous Monitoring: Conduct annual reassessments for Tier 1 and Tier 2 vendors. Use threat intelligence feeds and surface web monitoring to identify vendor breaches proactively.
5. Offboarding Controls: Ensure data deletion confirmation, access revocation, and documentation of asset returns.
6. Board Reporting: Per SAMA CSF Control 3.1.4, the board and senior management must receive regular reports on third-party risk exposure.
A common gap observed in Saudi financial institutions is treating third-party risk as a one-time checkbox rather than an ongoing program. Embed vendor risk reviews into your annual SAMA self-assessment cycle to ensure continuous compliance posture.
A robust cybersecurity incident response plan (IRP) for Saudi financial institutions must satisfy the requirements of SAMA CSF Control 3.6 (Cybersecurity Incident Management) as well as NCA ECC Domain 2-7 (Cybersecurity Incident and Threat Management). At its core, the IRP must define six phases: Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Review. SAMA specifically requires that any cybersecurity incident impacting operations, customer data, or financial services be reported to SAMA within 72 hours of discovery — with a full Root Cause Analysis (RCA) submitted within 30 days. NCA mandates reporting of significant incidents to the National Cybersecurity Authority through established channels, and institutions should register with the Saudi Computer Emergency Response Team (saCERT) for threat intelligence sharing. Practically, the IRP should include: clearly assigned roles (Incident Commander, Technical Lead, Communications Officer, Legal Counsel), a predefined severity classification matrix (P1–P4), communication templates for internal escalation and regulatory notification, and integration with PDPL obligations — since a breach involving personal data triggers mandatory notification to the SDAIA (Saudi Data and AI Authority) and potentially affected individuals. Tabletop exercises simulating ransomware, insider threats, and third-party breaches should be conducted at least annually per SAMA CSF best practices. The IRP must be reviewed after every major incident and updated annually. Our platform provides IRP templates pre-mapped to SAMA and NCA requirements, with automated incident ticketing and regulatory notification tracking.
Third-party risk management is a critical obligation for Saudi financial institutions under both SAMA CSF (Control 3.3.6 – Supplier Relationships) and NCA ECC (Domain 4 – Third-Party Cybersecurity). Here is a structured approach:
1. Pre-Onboarding Due Diligence: Before engaging any vendor, conduct a cybersecurity risk assessment covering data access scope, cloud or on-premise deployment, and regulatory exposure. SAMA CSF requires formal risk classification of all third parties with access to critical systems.
2. Contractual Safeguards: Embed cybersecurity clauses in all vendor contracts — including the right to audit, incident notification SLAs (typically 72 hours per PDPL Article 19), data handling obligations, and minimum security baseline requirements aligned with ISO 27001 Annex A controls.
3. Ongoing Monitoring: Third-party relationships must be continuously monitored, not just assessed at onboarding. This includes annual reassessments for critical vendors, review of their security certifications (e.g., ISO 27001, SOC 2), and tracking any publicly reported breaches.
4. Concentration Risk: SAMA specifically highlights the risk of over-reliance on a single vendor for critical services. Institutions must maintain documented exit strategies and business continuity plans for key third parties.
5. Cloud Providers: For cloud-based third parties, NCA CCC controls apply. Ensure your vendor is either hosted within Saudi Arabia or has received explicit regulatory approval for cross-border data processing.
Practically, build a third-party risk register, assign risk tiers (Critical, High, Medium, Low), and define review cycles accordingly. A CISO Consulting vCISO can help design and operationalize this program from day one.
Security awareness training is far more than a compliance checkbox — it is a frontline defense against phishing, social engineering, and insider threats. Both SAMA CSF (Control 3.3.2 – Cybersecurity Awareness and Training) and NCA ECC (Control 2-4 – Human Cybersecurity) mandate structured awareness programs. Here is how to build one that truly satisfies both frameworks:
Regulatory Minimum Requirements:
- SAMA CSF: Requires role-based security training differentiated by job function (general staff, privileged users, IT/security teams, and senior management). Training must be documented, tracked, and renewed at least annually.
- NCA ECC: Requires a formal awareness program covering phishing recognition, password hygiene, clean desk policy, and incident reporting procedures.
Recommended Program Structure:
- Baseline Assessment: Start with a phishing simulation to measure current susceptibility rates. This creates a measurable benchmark aligned with SAMA's maturity measurement approach.
- Role-Based Curricula:
- All Staff: Phishing, social engineering, password management, PDPL data handling basics
- IT & Security Teams: Secure coding (if applicable), incident escalation procedures, privileged access hygiene
- Management & Board: Cyber risk governance, regulatory liability, business continuity obligations
- Delivery Formats: Blend short monthly microlearning modules (5–10 minutes), quarterly phishing simulations, and annual in-depth workshops. Gamification significantly improves completion rates.
- Measurement & Reporting: Track completion rates, phishing click-through rates before and after training, and quiz scores. SAMA expects documented evidence of training effectiveness during assessments.
- Language Localization: Deliver content in both Arabic and English to maximize comprehension and engagement across your workforce.
Key Tip: Maintain a training register with employee names, completion dates, scores, and training version — this is frequently requested during SAMA regulatory examinations and NCA assessments.
Under SAMA CSF Control Domain 3.3 (Third-Party Cybersecurity), Saudi financial institutions must implement a structured vendor risk management lifecycle that spans onboarding, ongoing monitoring, and offboarding. Here's how to build a compliant program:
1. Vendor Classification & Tiering: Categorize vendors by the sensitivity of data they access and the criticality of services they provide. Tier-1 vendors (e.g., core banking system providers, cloud hosting partners) require the most rigorous scrutiny.
2. Pre-Onboarding Due Diligence: Before engagement, require vendors to complete a cybersecurity questionnaire aligned with SAMA CSF domains. Request evidence of ISO 27001 certification, penetration test results, and SOC 2 Type II reports where applicable.
3. Contractual Security Requirements (per SAMA CSF 3.3.4): Embed mandatory cybersecurity clauses in all vendor contracts, including: right-to-audit provisions, incident notification obligations (within 72 hours of discovery), data handling and encryption standards, and compliance with NCA ECC and PDPL where data is involved.
4. Continuous Monitoring: Conduct annual reassessments for Tier-1 vendors and bi-annual reviews for Tier-2. Use threat intelligence feeds to monitor for vendor breaches or vulnerabilities in vendor-supplied software.
5. Offboarding Controls: Ensure secure data deletion, credential revocation, and access termination are documented and verified upon contract termination.
A common gap found during SAMA assessments is that institutions maintain vendor lists but lack documented risk ratings or evidence of ongoing monitoring. Establishing a formal Third-Party Risk Register with assigned ownership and review dates is essential for audit readiness.
Under SAMA CSF Control 3.3 (Third-Party Management), Saudi banks and financial institutions must implement a structured, risk-based vendor management lifecycle that covers onboarding, ongoing monitoring, and offboarding. Here is how to build a compliant program:
1. Vendor Classification & Risk Tiering: Categorize vendors by the sensitivity of data they access and their criticality to operations (e.g., Tier 1 for core banking system providers, Tier 3 for low-risk suppliers). This tiering drives the depth of due diligence required.
2. Pre-Engagement Due Diligence: Before contracting, require vendors to complete a cybersecurity questionnaire aligned to SAMA CSF domains. For high-risk vendors, consider requesting ISO 27001 certification evidence or independent audit reports (SOC 2 Type II).
3. Contractual Controls: Ensure contracts include mandatory security clauses: right-to-audit provisions, incident notification obligations (within 72 hours per PDPL Art. 24 and SAMA CSF expectations), data handling restrictions, and business continuity commitments.
4. Continuous Monitoring: Conduct annual reassessments for Tier 1 vendors and biennial reviews for Tier 2. Use threat intelligence feeds and cyber ratings platforms to monitor vendor security posture between formal assessments.
5. Offboarding Controls: Define secure data return and destruction protocols when terminating vendor relationships, ensuring no residual data exposure.
Your GRC platform should automate vendor questionnaire distribution, track remediation timelines, and generate SAMA-ready reporting dashboards that demonstrate third-party risk governance to regulators during examinations.
Business Continuity Management (BCM) is a mandatory domain under both SAMA CSF (Domain 4 – Operational Resilience) and NCA ECC (Control 2-10 – Business Continuity). Saudi financial institutions must establish, implement, test, and continuously improve their BCM programs to satisfy regulatory expectations.
SAMA CSF Requirements: SAMA CSF Control 3.4 requires institutions to maintain a documented Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) that are reviewed and tested at least annually. Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) must be formally defined for all critical systems, with special attention to core banking platforms, payment systems, and customer-facing digital channels.
NCA ECC Alignment: NCA ECC Control 2-10 mandates that organizations define cybersecurity-specific continuity scenarios, including ransomware attacks, critical system outages, and supply chain disruptions. Cybersecurity must be embedded in BCM exercises, not treated as a separate workstream.
Practical Implementation Steps:
- Conduct a formal Business Impact Analysis (BIA) identifying critical processes, dependencies, and acceptable downtime thresholds.
- Define RTO/RPO for all critical assets and validate these with technology and business stakeholders.
- Develop cybersecurity-integrated DRP covering backup integrity, failover procedures, and out-of-band communication protocols.
- Conduct tabletop exercises and full simulation tests at least annually, involving IT, security, operations, and executive leadership.
- Document all test results, gaps identified, and corrective actions in your GRC platform for regulatory audit trails.
Regulators increasingly scrutinize BCM during SAMA examinations — institutions with outdated or untested plans face significant compliance findings.
Business Continuity Management (BCM) is a mandatory requirement for Saudi financial institutions under both SAMA CSF Control Domain 3.7 and NCA ECC Control 2-13. Here is a practical implementation roadmap:
1. BIA (Business Impact Analysis): Begin with a formal BIA to identify critical business processes, maximum tolerable downtime (MTD), Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO). SAMA expects RTOs for core banking systems to typically not exceed 4 hours.
2. BCM Policy and Governance: Establish a board-approved BCM policy that assigns clear ownership. SAMA CSF requires the CISO and senior management to be directly accountable for BCM outcomes.
3. Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP): Develop, document, and maintain separate BCP and DRP documents covering technology failover, manual workarounds, alternate site activation, and communication protocols.
4. Testing and Exercises: SAMA CSF mandates that BCM plans be tested at least annually through tabletop exercises, simulation drills, or full failover tests. NCA ECC Article 2-13 similarly requires documented test results and corrective action tracking.
5. Third-Party and Supply Chain Continuity: Ensure critical vendors maintain their own BCM programs aligned with your institution's RTO/RPO requirements, per SAMA CSF Control 3.6.
6. Cyber Incident Integration: BCM plans must explicitly address cybersecurity scenarios — ransomware, DDoS, and data center outages — ensuring alignment with your Cyber Incident Response Plan (CIRP).
7. Regulatory Reporting: SAMA requires institutions to report major disruptions within defined timeframes. Maintain a disruption log and ensure your BCM framework is reviewed during SAMA's annual cybersecurity examination cycle.
Business continuity and cyber resilience are among the most scrutinized areas during SAMA regulatory examinations. SAMA CSF Subdomain 3.5 (Cyber Resilience) sets out explicit requirements that go beyond traditional IT disaster recovery into true organizational resilience.
Core SAMA CSF Requirements (Subdomain 3.5):
- Control 3.5.1 – BCP/DRP Development: Banks must maintain documented Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) that specifically account for cyberattack scenarios (ransomware, DDoS, data destruction), not just natural disasters or hardware failures.
- Control 3.5.2 – Testing Frequency: BCPs and DRPs must be tested at least annually, with tabletop exercises, simulation drills, and full failover tests each serving distinct purposes. SAMA expects evidence of testing, including lessons-learned documentation.
- Control 3.5.3 – Recovery Objectives: Defined RTO (Recovery Time Objective) and RPO (Recovery Point Objective) targets must be formally approved by senior management and aligned to the criticality of each system.
- Control 3.5.4 – Cyber Incident Integration: The cyber incident response plan must be formally integrated into the BCP so that a cybersecurity event automatically triggers the appropriate continuity protocols.
Integration with ISO 22301: ISO 22301 (Business Continuity Management Systems) provides the structural framework that operationalizes SAMA CSF 3.5 requirements. Specifically:
- ISO 22301 Clause 6.2 (BIA) directly supports SAMA's requirement to identify and prioritize critical systems.
- ISO 22301 Clause 8.5 (Exercising and Testing) maps to SAMA CSF Control 3.5.2.
- Achieving ISO 22301 certification significantly strengthens your SAMA CSF maturity evidence.
NCA ECC Alignment: NCA ECC Article 2-14 independently mandates cyber resilience planning for government-affiliated entities — financial institutions with government ownership must satisfy both regulators.
Business Continuity Management (BCM) sits at the intersection of operational resilience and cybersecurity in SAMA's regulatory framework. Under SAMA CSF Domain 3.5 (Cyber Resilience), financial institutions are required to develop, maintain, and regularly test a Cyber Resilience Program that ensures critical operations can withstand, recover from, and adapt to cyber incidents.
SAMA CSF Control 3.5.1 mandates that banks establish a formal BCM framework that explicitly addresses cyber threat scenarios — not just traditional IT failures or natural disasters. This means BCP documents must include ransomware outbreak scenarios, DDoS attack playbooks, data exfiltration incidents, and critical system compromise procedures.
Key SAMA BCM requirements for CISOs include:
1. Business Impact Analysis (BIA): Identify critical business functions, their dependencies on IT systems, and define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for each. SAMA expects RTOs for critical payment systems to be extremely aggressive — often under 4 hours.
2. Cyber Incident Scenarios in BCP Testing: Annual BCM tests (per Control 3.5.3) must include at least one cyber-specific scenario. Tabletop exercises simulating ransomware or supply chain attacks are increasingly expected by SAMA examiners.
3. Crisis Communication Protocols: BCP must define escalation paths to SAMA (within 72 hours for major incidents per SAMA Cyber Incident Reporting Framework), the board, customers, and media.
4. Backup and Recovery Controls: Per SAMA CSF 3.3.10, offline and immutable backups must be maintained for critical data, with restoration tested regularly to validate actual RTO/RPO achievement.
5. Alignment with NCA ECC: NCA ECC Article 2-12 mirrors BCM obligations for all national entities, requiring coordination between the CISO and the COO/CRO on joint continuity planning.
CISOs should treat BCM not as a compliance checkbox but as a continuous resilience-building exercise embedded in the bank's annual security strategy.
Business Continuity Management (BCM) is a critical domain under SAMA CSF (Domain 5 – Cyber Resilience, Controls 5.1–5.4), requiring Saudi banks to maintain robust, tested, and board-approved continuity plans.
Program Foundation: Your BCM program must be anchored to a formal Business Impact Analysis (BIA) that identifies critical business functions, maximum tolerable downtime (MTD), recovery time objectives (RTO), and recovery point objectives (RPO) for each function. SAMA expects RTOs for critical systems to be defined and contractually enforced.
Cybersecurity Integration: BCM must be tightly integrated with the Cybersecurity Incident Response Plan (CIRP). Ransomware scenarios, DDoS attacks, and critical data loss must be explicitly covered in continuity plans — a gap many Saudi banks overlook.
Plan Components: A compliant BCM program includes: Crisis Management Plan, IT Disaster Recovery Plan (DRP), Business Recovery Plans per department, and Communication Plans (internal, regulatory, and customer-facing). SAMA CSF Control 5.2 specifically requires that SAMA be notified within defined timeframes during a major disruption.
Testing & Validation: SAMA requires annual BCP/DR exercises, including tabletop simulations and full failover tests. Results must be documented, lessons learned captured, and plans updated accordingly. NCA ECC also mandates resilience testing for entities managing critical national infrastructure.
Governance: The BCM program must have executive sponsorship, with the CISO and CRO jointly accountable. Plans must be reviewed and approved annually by senior management.
Our platform provides BCM templates pre-mapped to SAMA CSF domains, enabling banks to build, test, and evidence their resilience programs efficiently.
Business Continuity Management (BCM) is a tier-one requirement under SAMA CSF Domain 4 – Operational Resilience. SAMA expects member banks to maintain a formally documented, regularly tested, and board-approved BCM program that ensures the continuity of critical financial services during and after disruptive events.
Core BCM Components Required by SAMA CSF:
1. Business Impact Analysis (BIA): Per SAMA CSF Control 4.1.1, institutions must conduct a BIA to identify critical business functions, their dependencies (people, technology, third parties), and define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). For systemically important banks, RTOs for core banking services are typically expected within 4 hours.
2. BCM Policy and Strategy: A board-approved BCM policy must define scope, roles, responsibilities, and escalation procedures. The strategy must address alternative site activation, manual workarounds, and communication protocols.
3. IT Disaster Recovery (DR): Aligned with SAMA CSF Control 4.2, DR plans must be technically documented and cover failover procedures for all tier-1 systems. Data replication and backup frequencies must align with RPO commitments.
4. Testing and Exercises: SAMA requires at minimum an annual full DR test and tabletop exercises for crisis management scenarios. Results must be documented, gaps identified, and corrective actions tracked.
5. Integration with PDPL: Under PDPL Article 19, data backup and recovery mechanisms must preserve data integrity and access rights, ensuring that personal data is not exposed during DR failover events.
Documentation Tip: Maintain a BCM program register linking each plan to its owner, last test date, RTO/RPO targets, and SAMA CSF control reference. This significantly simplifies regulatory examination responses.
Business Continuity Management (BCM) is a mandatory component of SAMA CSF under Control Domain 3.5. Saudi banks must implement a BCM program that ensures critical financial services remain operational during disruptions — whether cyber incidents, natural disasters, or systemic failures.
SAMA CSF BCM Requirements:
1. Business Impact Analysis (BIA): Identify and classify critical business processes, define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for each, and assess interdependencies with third-party services and IT systems. SAMA expects RTOs for critical systems to be under 4 hours.
2. BCM Policy and Governance: A formally approved BCM policy must exist, endorsed by senior management and reviewed annually. A designated BCM owner must be appointed at the executive level.
3. Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP): Separate but integrated plans must cover people, processes, technology, and facilities. Plans must include clear escalation paths, communication trees, and alternate site arrangements.
4. Testing and Exercising: SAMA requires BCM plans to be tested at least annually. Tests must include tabletop exercises, simulation drills, and full failover tests for critical systems. Results must be documented and gaps remediated.
5. Alignment with NCA ECC: NCA ECC Article 2-15 reinforces BCM requirements for organizations operating national infrastructure, adding requirements around cyber-resilience and continuity of digital services.
6. PDPL Consideration: BCM plans must account for data protection obligations — backup systems must maintain the same security and access controls as primary systems.
Practical Steps:
- Integrate BCM into your annual SAMA self-assessment submission.
- Use our platform's BCM module to map RTOs/RPOs, schedule tests, and generate regulator-ready reports automatically.
- Align BCM with ISO 22301 for internationally recognized best practice.
Business Continuity Management (BCM) is a critical regulatory obligation for Saudi financial institutions. Both SAMA CSF (Domain 4 — Operational Resilience) and NCA ECC (Article 2-14) mandate formal BCM programs. Here is a practical implementation roadmap:
1. Governance and Policy Foundation: Establish a BCM policy approved by the Board or senior executive committee. SAMA CSF requires explicit ownership at the executive level. Assign a dedicated BCM owner — often the CISO or COO — responsible for program maintenance.
2. Business Impact Analysis (BIA): Conduct a thorough BIA to identify critical business functions, their dependencies, and acceptable Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). SAMA expects RTOs and RPOs to be defined for all critical systems including core banking, payments, and customer-facing channels.
3. Risk Assessment Integration: BCM must be integrated with the organization's broader cybersecurity risk assessment process. NCA ECC Article 2-14 specifically requires scenarios covering cyberattacks, ransomware, and system failures.
4. Plan Development: Develop Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) covering people, processes, technology, and facilities. Ensure plans address both partial and full site failures.
5. Testing and Exercises: SAMA CSF requires BCM plans to be tested at least annually through tabletop exercises, functional drills, or full failover tests. Test results and lessons learned must be documented and acted upon.
6. Third-Party Dependencies: Map and test continuity arrangements for critical vendors and cloud service providers. SAMA expects contractual BCM obligations to be embedded in third-party agreements.
Regular review cycles — at least annually or after significant changes — ensure plans remain current and aligned with evolving regulatory expectations.
Business Continuity Management (BCM) is a critical compliance domain for Saudi financial institutions, governed primarily by SAMA CSF Domain 4 (Operational Resilience) and NCA ECC Controls 2-9 and 2-10, which address resilience and recovery capabilities.
Core SAMA CSF Requirements: SAMA CSF Control 4.1 requires institutions to establish a formal BCM program covering Business Impact Analysis (BIA), Recovery Time Objectives (RTO), Recovery Point Objectives (RPO), and tested Business Continuity Plans (BCPs). RTOs for critical banking services are typically expected to be 4 hours or less, with RPOs of 1–2 hours for tier-1 systems.
NCA ECC Alignment: NCA ECC Article 2-9 mandates that organizations establish and maintain Disaster Recovery Plans (DRPs) with documented failover procedures, while Article 2-10 requires periodic testing and simulation exercises at least annually.
Practical Implementation Steps:
- Conduct a thorough BIA to identify critical processes and acceptable downtime thresholds.
- Define RTO/RPO for each critical system — core banking, payment rails, and customer-facing channels.
- Develop tiered BCPs: site-level, system-level, and crisis communication plans.
- Establish an alternate/hot site that meets SAMA's geographic separation requirements.
- Test plans through tabletop exercises, functional drills, and full failover simulations annually.
- Integrate BCM with your Cybersecurity Incident Response Plan to cover ransomware and cyber-induced outage scenarios.
Documentation of test results, gaps identified, and remediation actions must be maintained and submitted during SAMA regulatory reviews. A common weakness is treating BCM as an annual checkbox — successful institutions embed it into change management and release processes year-round.
Business Continuity Management (BCM) is a mandatory domain under SAMA CSF, addressed comprehensively in Domain 3.5 — Resilience. Financial institutions must build and maintain a BCM program that ensures critical operations can withstand and recover from disruptive incidents, whether cyber-related or operational.
Core components required by SAMA CSF:
- Business Impact Analysis (BIA): Identify and prioritize critical business functions, define Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) for each, and map dependencies on technology and third-party services.
- Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP): Develop documented, tested plans that address various disruption scenarios including ransomware attacks, data center failures, and key personnel unavailability.
- Crisis Management Framework: Establish a crisis management team with defined roles and escalation paths. SAMA expects named executives and deputies to be designated for continuity decisions.
- Testing and Exercises: SAMA CSF Control 3.5.4 requires that BCM plans be tested at least annually through tabletop exercises, functional drills, or full simulation tests. Results must be documented and gaps remediated.
- Integration with Cyber Incident Response: BCM must be aligned with the Cyber Incident Response Plan (CIRP) to ensure coordinated response during cyber disruptions, including ransomware or DDoS attacks targeting financial services.
- Regulatory Reporting: Any incident triggering BCP activation must be reported to SAMA within defined timeframes per the SAMA Cyber Incident Reporting Framework.
Fintechs should pay special attention to cloud dependencies, SaaS provider continuity, and ensuring contractual SLAs with vendors include documented RTOs aligned with their own SAMA-approved thresholds.
Business Continuity Management (BCM) is a mandatory domain under SAMA CSF, and for fintechs — given their digital-first nature and reliance on third-party infrastructure — it carries elevated risk. SAMA CSF Domain 4 (Operational Resilience) sets the overarching expectations, requiring that all member organizations establish, test, and maintain comprehensive BCM programs.
Core Requirements:
Business Impact Analysis (BIA): SAMA CSF Control 4.1 requires fintechs to conduct a formal BIA identifying critical business processes, dependencies, maximum tolerable downtime (MTD), recovery time objectives (RTO), and recovery point objectives (RPO). For payment services, RTOs are typically expected to be under 4 hours.
Business Continuity Plan (BCP) & Disaster Recovery Plan (DRP): Both must be documented, approved by senior management, and reviewed at least annually. DRP must address IT system recovery sequencing and failover procedures.
Testing & Exercises: SAMA expects regular tabletop exercises (at minimum annually) and full DR drills. Test results must be documented, gaps identified, and improvement actions tracked.
Communication Plans: BCPs must include internal escalation paths and external stakeholder communication protocols, including notification to SAMA in cases of significant operational disruptions.
Third-Party Resilience: Fintechs must validate the BCM posture of critical technology vendors (e.g., cloud providers, payment processors) as part of their overall resilience strategy.
ISO 22301 Alignment: While not explicitly mandated, aligning your BCM program with ISO 22301 significantly eases SAMA audit readiness and demonstrates a mature, internationally recognized approach to operational resilience.
Fintechs should treat BCM not as a compliance checkbox, but as a core operational risk discipline that directly protects customer trust and regulatory standing.
Business Continuity Management (BCM) is a critical compliance obligation for Saudi financial institutions. Both SAMA CSF and NCA ECC set explicit expectations that institutions must meet.
SAMA CSF Requirements (Control Domain 3.4): SAMA requires a formal BCM program covering Business Impact Analysis (BIA), Business Continuity Plans (BCP), and Disaster Recovery Plans (DRP). Key mandates include:
- RTO (Recovery Time Objective) and RPO (Recovery Point Objective) must be defined per critical system
- BCP must be tested at minimum annually through tabletop exercises, and full DR failover tests at least every two years
- SAMA expects BCM to align with the institution's risk appetite and be approved by senior management
NCA ECC Requirements (Article 2-13): NCA ECC mandates resilience controls including redundant systems, failover capabilities, and documented recovery procedures. Institutions must ensure cybersecurity continuity is embedded within the broader BCM framework.
Practical Implementation Steps:
- Conduct a formal BIA to identify critical business processes and their dependencies
- Define RTOs and RPOs in alignment with SAMA's operational resilience thresholds
- Develop tiered BCP and DRP documents covering people, process, and technology
- Establish an alternate site (hot, warm, or cold standby) for critical banking operations
- Integrate cyber incident scenarios into BCP testing, including ransomware and DDoS simulation
- Maintain an annual test schedule and document results with lessons learned
PDPL Consideration: Under Saudi PDPL, personal data must remain protected even during disaster recovery operations. Ensure DR environments enforce the same data protection controls as production.
Business Continuity Management under SAMA CSF is governed primarily by Domain 4 (Cyber Resilience), which mandates that Member Organizations establish, maintain, and test a comprehensive BCM program. Here are the core requirements and implementation steps:
1. BCM Policy & Governance (SAMA CSF Control 4.1) Establish a board-approved BCM policy that defines RTO (Recovery Time Objective) and RPO (Recovery Point Objective) thresholds for critical banking systems. Assign a dedicated BCM owner at the senior management level.
2. Business Impact Analysis (BIA) Conduct a formal BIA annually to identify critical business functions, dependencies, and acceptable downtime limits. For core banking systems, SAMA expects RTO to typically not exceed 4 hours for Tier-1 institutions.
3. Disaster Recovery Planning (SAMA CSF Control 4.3) Maintain a documented and tested Disaster Recovery Plan (DRP) covering IT systems, data centers, and third-party dependencies. DR sites must be geographically separated and tested at least annually through full failover exercises.
4. Testing & Exercising SAMA CSF requires at minimum annual tabletop exercises and bi-annual technical DR drills. Results must be documented, gaps remediated, and evidence retained for regulatory review.
5. Alignment with NCA ECC NCA ECC Article 3-8 also addresses resilience requirements. Ensure your BCM program satisfies both frameworks to avoid duplicate audit findings.
Practical Tip: Integrate your BCM program with your Cyber Incident Response Plan (CIRP) so that a major cyber incident automatically triggers BCM protocols. This alignment is increasingly scrutinized during SAMA on-site examinations.
Business Continuity Management (BCM) is a mandatory component under SAMA CSF Domain 4 and NCA ECC Control 2-10, requiring Saudi financial institutions to maintain resilient operations against disruptions, cyber incidents, and disasters.
SAMA CSF BCM Requirements (Domain 4.1):
- Develop and maintain a formal Business Continuity Policy approved by senior management
- Conduct Business Impact Analysis (BIA) to identify critical business functions and their maximum tolerable downtime (MTD)
- Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for all critical systems — for core banking, SAMA typically expects RTO within 4 hours
- Establish and test Disaster Recovery Plans (DRP) for IT systems at least annually through simulated exercises
NCA ECC Control 2-10 Alignment:
- Requires cybersecurity considerations to be embedded within BCM, including cyber-specific recovery scenarios
- Mandates that BCM plans account for ransomware, DDoS, and supply chain disruption scenarios
Testing & Exercises:
- Tabletop exercises, functional drills, and full failover tests must be documented
- Results, gaps, and corrective actions must be formally recorded and tracked
- SAMA examiners will request evidence of test outcomes during assessments
Integration with Incident Response:
- BCM and Incident Response Plans must be aligned to avoid conflicting procedures during crisis activation
- Assign clear crisis communication roles including regulatory notification to SAMA within required timeframes
Practical Tip: Establish a BCM Steering Committee with cross-functional representation (IT, Operations, Risk, Legal) to ensure enterprise-wide ownership and alignment with SAMA's governance expectations.
Business Continuity Management (BCM) is a critical regulatory obligation for Saudi financial institutions under SAMA CSF Domain 4, specifically Controls 4.3.1 through 4.3.6. A compliant BCM program must address the following areas:
1. Business Impact Analysis (BIA):
- Identify and classify critical business processes, their dependencies, and maximum tolerable downtime (MTD).
- Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for each critical system.
- BIA results must be reviewed and updated at least annually or after major changes.
2. Business Continuity Plan (BCP) Development:
- Document detailed recovery procedures for all critical functions.
- Assign clear roles, responsibilities, and escalation paths.
- Plans must address both cyber-incident-triggered disruptions and physical/environmental events.
3. Disaster Recovery (DR) Planning:
- Maintain a tested, operational DR site — SAMA expects financial institutions to have geographically separated primary and secondary data centers.
- DR failover capabilities must meet defined RTO/RPO commitments.
4. Testing and Exercising:
- SAMA CSF Control 4.3.5 requires regular BCM testing, including tabletop exercises and full failover drills.
- Testing must be conducted at least annually, with results documented and lessons learned incorporated.
5. Integration with Cyber Incident Response:
- BCM must be tightly integrated with the Cyber Incident Response Plan (CIRP) to ensure seamless activation during cybersecurity incidents.
6. Governance and Reporting:
- BCM program ownership should sit at the executive level (COO or CRO), with the CISO responsible for the cyber resilience component.
- Annual BCM reports must be presented to the Board Risk Committee.
Key practical advice: Regulators increasingly scrutinize the gap between documented plans and actual tested capabilities — invest in realistic simulation exercises.
Under SAMA CSF Domain 4 (Operational Resilience), Saudi financial institutions must establish a comprehensive Business Continuity Management program that addresses both technology and operational risks. Key requirements include:
1. BCP Documentation & Governance: Per SAMA CSF Control 4.1, institutions must maintain formally approved BCM policies, define clear ownership at the board level, and embed BCM into strategic planning cycles.
2. Business Impact Analysis (BIA): Control 4.2 requires a structured BIA that identifies critical business functions, maximum tolerable downtime (MTD), recovery time objectives (RTO), and recovery point objectives (RPO) for all core banking systems.
3. Testing & Exercising: SAMA mandates at least annual BCM tests, including tabletop exercises and full simulation drills. Results must be documented and remediation actions tracked.
4. IT Disaster Recovery Alignment: BCM must be integrated with IT Disaster Recovery Plans (DRP), ensuring that DR environments — whether on-premises or cloud-hosted — are tested independently and meet SAMA's data residency expectations.
5. Third-Party Coverage: BCM scope must extend to critical service providers. Vendors supporting core banking, payment processing, or data hosting must demonstrate their own BCM capabilities contractually.
6. PDPL Alignment: When activating recovery procedures, institutions must ensure personal data processed during failover scenarios remains protected per PDPL Article 19 obligations.
Practically, institutions should maintain a BCM register, schedule quarterly reviews, and report BCM status to the board risk committee at least semi-annually. SAMA may request BCM documentation during regulatory inspections, so audit-readiness is essential.
Business Continuity Management (BCM) is a critical regulatory obligation for Saudi banks under SAMA CSF Domain 3.4 (Resilience) and is further reinforced by SAMA's dedicated Business Continuity Management Guidelines. Here is a structured approach to achieving full compliance:
1. Establish a Formal BCM Program: SAMA requires a board-approved BCM policy that defines Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for all critical systems. For core banking platforms, RTOs are typically expected to be four hours or less.
2. Conduct Business Impact Analysis (BIA): Identify critical business functions, their dependencies on IT systems, and the financial/reputational impact of disruption. The BIA must be reviewed annually and after significant organizational changes.
3. Develop and Maintain Plans: You need three interconnected plans:
- Business Continuity Plan (BCP): Covers operational continuity
- IT Disaster Recovery Plan (DRP): Covers technical recovery of systems
- Crisis Communication Plan: Covers internal and SAMA notification procedures
4. Testing Requirements: SAMA CSF mandates regular testing — tabletop exercises at minimum annually, and full failover DR tests at least once per year. Results must be documented and gaps remediated.
5. Third-Party Dependencies: BCM must account for critical vendor dependencies. If a core system provider experiences outage, your plan must address continuity.
6. SAMA Notification: In the event of a significant disruption impacting customer services, SAMA expects notification within defined timeframes per the incident reporting framework.
Integrating your BCM documentation into a centralized GRC platform ensures version control, audit trails, and real-time test tracking.
Business continuity management under SAMA CSF (Domain 4, Controls 4.3.1–4.3.6) requires Saudi financial institutions to maintain a comprehensive, tested, and regularly updated BCM program. Key requirements include: (1) Business Impact Analysis (BIA): Identify critical business functions, acceptable recovery time objectives (RTO), and recovery point objectives (RPO) for all core banking systems. (2) Business Continuity Plan (BCP): Document recovery procedures for people, processes, technology, and facilities. Plans must cover scenarios including cyberattacks, not just natural disasters. (3) Disaster Recovery (DR): Maintain a geographically separated DR site within the Kingdom, with data replication aligned to RPO targets. SAMA requires DR sites to be activated and tested at least annually. (4) Testing and Exercises: Conduct tabletop exercises and full DR failover tests at least once per year. Results must be documented, gaps remediated, and evidence retained for SAMA examination. (5) Third-Party Dependencies: Map and address continuity risks from critical service providers, including cloud vendors and payment networks. Practically, banks should assign a dedicated BCM owner, integrate BCM into the overall risk management framework, and ensure board-level sign-off on the BCP annually. SAMA examiners will review test evidence, BIA documentation, and board minutes during assessments. Fintechs operating under SAMA oversight are equally subject to these requirements and must demonstrate proportional BCM maturity relative to their operational scale.
Business Continuity Management (BCM) for Saudi financial institutions sits at the intersection of operational resilience and regulatory compliance. SAMA CSF Domain 3.6 mandates a fully documented BCM framework that includes Business Impact Analysis (BIA), Recovery Time Objectives (RTO), Recovery Point Objectives (RPO), and tested Disaster Recovery Plans (DRP).
Key implementation steps include: (1) Conduct a BIA identifying critical business processes, dependencies, and acceptable downtime thresholds — SAMA expects RTOs for critical systems to be no more than 4 hours; (2) Develop and maintain a Business Continuity Plan (BCP) covering crisis communication, staff roles, and alternate processing sites; (3) Test your BCP at least annually through tabletop exercises, simulations, or full failover drills, with results documented and presented to the Board; (4) Integrate cyber incident scenarios — ransomware, DDoS, and data breach — into your continuity planning, aligning with SAMA CSF Control 3.6.5.
The PDPL dimension adds a critical data protection layer: if a business disruption involves personal data unavailability or breach, Article 24 of PDPL requires notification to the Saudi Data & AI Authority (SDAIA) within a defined timeframe. Your BCP must therefore include a data breach response workflow that triggers PDPL notification obligations simultaneously with operational recovery.
Best practice is to align your BCM documentation with ISO 22301, which SAMA accepts as a recognized standard, and to cross-reference NCA ECC controls 2-15 for cybersecurity resilience requirements. Our platform provides BCM templates pre-mapped to all relevant frameworks.
SAMA CSF Domain 4 — Business Continuity Management — sets comprehensive expectations for Saudi financial institutions to maintain operational resilience. A compliant BCM program must cover the following pillars: (1) Business Impact Analysis (BIA): Per SAMA CSF Control 4.1.2, conduct a formal BIA at least annually to identify critical business functions, Maximum Tolerable Downtime (MTD), Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO) for all critical systems including core banking, payment infrastructure, and digital channels. (2) BCM Policy and Governance: Establish a board-approved BCM policy with clearly defined roles, responsibilities, and escalation paths. The CISO and BCM owner must coordinate closely, as cybersecurity incidents are a primary BCM trigger. (3) Business Continuity Plans (BCPs) and Disaster Recovery Plans (DRPs): Develop and maintain tested BCPs for all critical business units and technical DRPs for IT systems. Plans must be reviewed after every significant incident or change, and at minimum annually. (4) Testing and Exercises: SAMA CSF Control 4.3 requires regular BCM tests — including tabletop exercises, functional drills, and full failover tests for critical systems. Results must be documented and findings tracked to closure. (5) Crisis Communication: Define internal and external communication protocols covering regulators (SAMA, NCA), customers, and media. (6) Third-Party Dependencies: Map BCM obligations to critical vendors and ensure contractual alignment. Integrate your BCM program into your GRC platform to maintain living documentation, automate test scheduling, and generate audit-ready reports for SAMA examinations.
Under SAMA CSF Domain 3 (Cybersecurity Operations), specifically Controls 3.3.1 through 3.3.5, Saudi banks must implement a comprehensive Identity and Access Management program addressing several critical areas:
Privileged Access Management (PAM): All privileged accounts (system administrators, database admins, network engineers) must be inventoried, subject to multi-factor authentication (MFA), and monitored via privileged access workstations. Standing privileged access should be minimized in favor of just-in-time (JIT) access models.
Least Privilege Principle: Role-based access control (RBAC) must be enforced across all systems, with access rights reviewed at minimum semi-annually. Segregation of duties (SoD) controls must prevent any single user from having end-to-end control over critical financial transactions.
User Lifecycle Management: Onboarding, transfer, and offboarding procedures must be formally documented. Departing employees' access must be revoked within 24 hours of termination, with immediate revocation for involuntary departures.
Directory Services: Active Directory or equivalent identity providers must enforce password complexity, account lockout thresholds, and session timeout policies aligned with SAMA CSF Appendix requirements.
Third-Party and Vendor Access: Remote vendor access must be time-limited, logged, and conducted through secure jump servers or PAM solutions — never via shared credentials.
From an ISO 27001 alignment perspective (Annex A Control 5.15–5.18), these requirements map directly to information access controls and privileged access procedures.
Practical Recommendation: Conduct a quarterly IAM audit using your GRC platform to flag orphaned accounts, excessive privileges, and SoD violations before your SAMA assessment cycle. Document all exceptions with formal risk acceptance sign-off from your CISO.
Cybersecurity governance is the foundational pillar that regulators evaluate first during SAMA examinations. Building a robust governance structure requires deliberate mapping between SAMA CSF and ISO 27001.
SAMA CSF Governance Requirements: SAMA CSF Domain 1 (Cybersecurity Leadership and Governance) requires financial institutions to establish a Board-approved Cybersecurity Strategy, a dedicated Cybersecurity Function reporting to senior management, and a formal Cybersecurity Policy Framework. Control 1.1 mandates that the Board receive cybersecurity risk reports at least quarterly, and the CISO role must have clear independence from IT operations.
ISO 27001 Alignment: ISO 27001:2022 Clause 5 (Leadership) and Clause 6 (Planning) directly complement SAMA CSF Domain 1. Institutions can leverage an ISO 27001-certified ISMS as documented evidence during SAMA assessments, demonstrating control implementation across Annex A domains. Gap analysis should map each SAMA CSF control to its ISO 27001 counterpart to eliminate duplication of effort.
Practical Governance Structure:
- Establish a Cybersecurity Steering Committee chaired by the CEO or COO with CISO, CRO, and Business Unit representation.
- Define a three-lines-of-defence model: Security Operations (1st), Risk & Compliance (2nd), Internal Audit (3rd).
- Develop a Policy Framework with a Master Cybersecurity Policy, supported by topic-specific standards (e.g., Access Control, Encryption, Incident Response).
- Implement a cybersecurity KRI/KPI dashboard reported to the Board Risk Committee quarterly per SAMA CSF Control 1.2.
- Schedule annual governance framework reviews aligned with ISO 27001 management review cycles.
Institutions that integrate both frameworks reduce audit fatigue significantly while achieving a stronger overall security posture.
Security awareness training is a foundational control under both SAMA CSF (Domain 2.3 – Human Resource Security) and NCA ECC (Control 1-3 – Cybersecurity Awareness and Training). Saudi financial institutions must implement structured, role-based training programs that address the following requirements:
SAMA CSF Requirements:
- All staff must complete cybersecurity awareness training at least annually, with records maintained for audit purposes.
- Privileged users and IT/security personnel require specialized, role-based training covering topics such as secure development, incident handling, and access management.
- New joiners must complete onboarding security training before or immediately upon gaining access to systems.
NCA ECC Requirements:
- Control 1-3 mandates a formal Cybersecurity Awareness Program with defined objectives, target audiences, delivery methods, and measurable KPIs.
- Training must cover phishing, social engineering, password hygiene, acceptable use policies, and incident reporting procedures.
Practical Implementation Guidance:
- Conduct an annual training needs assessment segmented by job role.
- Use a Learning Management System (LMS) to deliver, track, and report training completion.
- Run simulated phishing campaigns quarterly to measure behavioral change.
- Document all training completion records and present them during SAMA regulatory examinations.
- Include third-party contractors and vendors with access to sensitive systems in the training scope.
Non-compliance with these controls is a common finding during SAMA onsite inspections and can result in a lower maturity rating, impacting your institution's overall CSF assessment score.
Under SAMA CSF Control 3.3.1 (Human Resources Security), Saudi financial institutions are required to implement a formal, risk-based cybersecurity awareness and training program covering all employees, contractors, and privileged users. The program must be conducted at least annually, with role-specific training for personnel handling sensitive data or critical systems. Key requirements include: (1) Onboarding security orientation for all new hires before system access is granted; (2) Annual refresher training covering phishing, social engineering, password hygiene, and data handling; (3) Specialized technical training for IT, security, and developer teams aligned with their specific risk exposure; (4) Phishing simulation exercises to measure and improve employee vigilance; (5) Board and senior management briefings on cyber risk governance. Training effectiveness must be measured through KPIs such as phishing click-through rates, quiz scores, and completion rates, and documented for regulatory review. SAMA expects evidence of training records during examinations. Institutions should also align their programs with NCA ECC Article 2-8, which reinforces human security controls. Practical tip: Integrate awareness training into your GRC platform to automate scheduling, track completion, generate audit-ready reports, and trigger remediation workflows for employees who fail simulated phishing tests.
Cyber incident response for Saudi banks is governed primarily by SAMA CSF Control 3.5 (Cybersecurity Incident Management), which requires institutions to maintain a formally documented Incident Response Plan (IRP) that is tested at least annually through tabletop exercises or simulations. The IRP must define clear roles, escalation paths, containment procedures, and recovery objectives.
From a regulatory reporting perspective, SAMA requires that significant cybersecurity incidents — particularly those affecting customer data, core banking systems, payment infrastructure, or public-facing services — be reported to SAMA within 72 hours of detection. This timeline aligns with PDPL Article 27 requirements for personal data breach notification to the Saudi Data and Artificial Intelligence Authority (SDAIA). For critical infrastructure incidents, NCA ECC Article 4-3 may trigger parallel reporting obligations to the National Cybersecurity Authority.
The definition of a 'reportable' incident under SAMA typically includes: unauthorized access to customer accounts, ransomware or destructive malware affecting operations, DDoS attacks causing service unavailability exceeding defined thresholds, data exfiltration, and fraudulent transactions linked to a systemic compromise.
Post-incident, SAMA expects a formal Root Cause Analysis (RCA) report within 30 days, along with a remediation roadmap. Institutions must also maintain an incident log and demonstrate lessons-learned integration into their security controls.
Practically, your GRC platform should automate incident intake, classification by severity, and stakeholder notification workflows — ensuring that your team can trigger the right regulatory reporting chain within the 72-hour window without relying on manual processes under pressure.
Under SAMA CSF Control Domain 3.3 (People), Saudi financial institutions are required to implement a structured, role-based cybersecurity awareness and training program covering all staff, contractors, and third parties with access to critical systems. At minimum, programs must include: (1) Annual mandatory awareness training for all employees, with documented completion records; (2) Specialized technical training for IT and security personnel, aligned with their specific responsibilities; (3) Executive and board-level briefings on cyber risk governance; and (4) Phishing simulation exercises conducted at least quarterly. Programs should be mapped to real threats facing the Saudi financial sector, including social engineering, credential theft, and BEC (Business Email Compromise) attacks. Per SAMA CSF Control 3.3.2, institutions must maintain training completion metrics and report gaps to senior management. Practical structuring guidance: segment your curriculum into tiers — general staff, privileged users, developers, and executives — with differentiated content for each. Integrate PDPL obligations into training so employees understand data handling responsibilities. Leverage e-learning platforms with Arabic-language content to ensure accessibility across all workforce segments. Training effectiveness must be measured through post-training assessments, phishing click-rate tracking, and annual program reviews. Non-compliance in this domain is frequently cited in SAMA examination findings, making it a high-priority area for CISOs in Saudi banking.
Under SAMA CSF Control 3.3.1 (Security Awareness and Training), Saudi banks and financial institutions are required to establish a formal, risk-based Security Awareness and Training program that covers all employees, contractors, and privileged users. Here's a practical implementation roadmap:
Program Structure:
- Conduct an annual training needs assessment aligned to your organization's risk profile
- Develop role-based curricula: general staff, IT teams, and senior management each have distinct learning paths
- Include mandatory onboarding training for new hires and third-party staff with system access
Content Requirements:
- Social engineering, phishing simulation, and business email compromise (BEC) scenarios relevant to Saudi financial sector threats
- PDPL data handling obligations and confidentiality responsibilities
- Incident reporting procedures and escalation channels
- Acceptable use policies for critical systems
Delivery & Frequency:
- Minimum annual refresher training for all staff, with quarterly phishing simulations recommended
- Blended learning: e-learning modules, in-person workshops, and simulated attack exercises
- NCA ECC-3.3 also reinforces the need for continuous awareness campaigns, not just point-in-time training
Measurement & Reporting:
- Track completion rates, phishing click rates, and knowledge assessment scores
- Report program effectiveness to senior management and the board at least annually
- Use metrics to justify budget and demonstrate compliance during SAMA regulatory examinations
A mature SAT program is a leading indicator of your overall cybersecurity culture. Platforms like CISO Consulting can help automate tracking, generate compliance evidence, and align training content to your current threat landscape.
Third-party risk management (TPRM) is a critical obligation under SAMA CSF Domain 4 (Third-Party Management) and NCA ECC-1:2018 Control 3-8. Financial institutions must implement a structured lifecycle approach covering four key stages:
1. Vendor Due Diligence & Onboarding: Before engagement, conduct cybersecurity risk assessments for all vendors with access to sensitive systems or data. SAMA CSF requires classification of vendors by criticality tier, which directly determines the depth of assessment required.
2. Contractual Security Requirements: Embed mandatory security clauses into all vendor contracts, including right-to-audit provisions, incident notification SLAs (typically 24–72 hours per SAMA expectations), data handling obligations aligned with PDPL Article 29, and minimum acceptable security standards such as ISO 27001 certification.
3. Continuous Monitoring: Implement ongoing monitoring through annual reassessments for critical vendors, automated supply chain threat intelligence feeds, and periodic review of vendor security posture reports. NCA ECC Control 3-8-4 specifically mandates monitoring third-party access to organizational systems.
4. Offboarding & Access Revocation: Establish formal procedures for secure vendor offboarding, ensuring immediate revocation of access credentials and secure data return or destruction per PDPL requirements.
Practical recommendation: Maintain a centralized vendor risk register integrated into your GRC platform, enabling real-time risk scoring and automated compliance reporting. SAMA examiners routinely inspect TPRM documentation during regulatory reviews, so audit-ready records are essential. For fintechs leveraging multiple SaaS providers, prioritize vendors processing payment data or holding customer PII as your highest-risk tier.
Third-party risk management (TPRM) is a critical obligation under SAMA CSF Domain 4 (Third Party Management), which requires financial institutions to establish a structured, risk-based process for managing vendor and supplier cybersecurity risks throughout the relationship lifecycle.
Key Requirements:
- Pre-onboarding Assessment: Before engaging any third party with access to systems or sensitive data, conduct a cybersecurity due diligence assessment. Evaluate the vendor's security posture, certifications (e.g., ISO 27001), and compliance with NCA ECC controls.
- Contractual Controls (per SAMA CSF Control 4.2): Embed mandatory cybersecurity clauses in all vendor contracts, including the right to audit, incident notification obligations (within 72 hours), data handling requirements aligned with PDPL, and termination rights upon material breach.
- Ongoing Monitoring: Implement continuous monitoring for critical vendors — this includes periodic reassessments (at least annually), reviewing security incident reports, and conducting on-site or remote audits.
- Tiered Risk Classification: Categorize vendors by risk level (Critical, High, Medium, Low) based on data access, system integration depth, and regulatory sensitivity. Apply proportionate controls accordingly.
- Exit Strategy: Maintain documented exit and transition plans to ensure business continuity if a third party fails or is terminated.
Practical Tip: Use a standardized vendor questionnaire mapped to SAMA CSF and NCA ECC controls. For cloud service providers, additionally apply the NCA Cloud Cybersecurity Controls (CCC) framework. Document all assessments in your GRC platform for audit readiness and regulatory inspection by SAMA examiners.
Under SAMA CSF Control Domain 3.3 (Third-Party Management), Saudi financial institutions must implement a structured TPRM program covering the full vendor lifecycle. Here is a practical framework:
1. Vendor Classification & Risk Tiering Categorize vendors by criticality — Tier 1 (critical/high-risk, e.g., core banking providers, cloud hosts), Tier 2 (moderate), and Tier 3 (low-risk). Per SAMA CSF Control 3.3.2, due diligence depth must match the vendor's risk tier.
2. Pre-Onboarding Due Diligence Before contracting, assess vendors against: cybersecurity posture (ISO 27001 certification or equivalent), data handling practices aligned with PDPL obligations, sub-contractor exposure, and financial stability. Obtain evidence of relevant certifications and conduct questionnaire-based assessments.
3. Contractual Safeguards Contracts must include: right-to-audit clauses, cybersecurity incident notification obligations (within 72 hours per PDPL Article 19 if personal data is involved), data residency requirements (Saudi Arabia for sensitive financial data), and SLA-linked security KPIs.
4. Continuous Monitoring Conduct annual reassessments for Tier 1 vendors and biennial reviews for Tier 2. Use automated threat intelligence feeds to monitor vendor breach news and security ratings.
5. Offboarding Controls Ensure secure data deletion, certificate revocation, and access termination upon vendor exit — documenting closure per SAMA CSF Control 3.3.5.
NCA ECC Alignment: NCA ECC Article 2-8 reinforces third-party controls for government-adjacent financial entities.
Our GRC platform automates vendor questionnaires, tracks remediation timelines, and generates SAMA-ready TPRM reports — reducing manual effort by up to 60%.
Third-party risk management is a critical compliance obligation for Saudi financial institutions. Under SAMA CSF Control 3.3, member organizations must establish a formal TPRM framework that covers the entire vendor lifecycle — from onboarding due diligence through contract management to offboarding. NCA ECC Article 2-14 further mandates that critical suppliers undergo cybersecurity assessments before being granted access to organizational systems or data.
A robust TPRM program should include the following components:
1. Vendor Classification & Tiering: Categorize vendors by criticality (Tier 1–3) based on data access, system integration depth, and business dependency. Critical fintech partners and cloud providers typically fall into Tier 1 and require the most rigorous oversight.
2. Pre-Onboarding Assessment: Conduct cybersecurity due diligence using standardized questionnaires aligned with SAMA CSF domains. Verify ISO 27001 certification where applicable and review SOC 2 Type II reports for cloud vendors.
3. Contractual Obligations: Ensure all vendor contracts include cybersecurity clauses covering incident notification timelines (within 24 hours per SAMA guidelines), right-to-audit provisions, and data handling obligations consistent with PDPL Article 19.
4. Continuous Monitoring: Implement ongoing risk scoring using threat intelligence feeds and periodic reassessments — at least annually for Tier 1 vendors.
5. Concentration Risk: SAMA expects boards to be aware of concentration risk when multiple critical services depend on a single third party.
CISOs should maintain a centralized vendor risk register and present quarterly TPRM status reports to the board's risk committee. Regulators increasingly scrutinize TPRM maturity during SAMA examinations, making documentation and evidence collection as important as the controls themselves.
Under SAMA CSF Control Domain 3.3 (Third-Party Management), Saudi banks must implement a structured, risk-based approach to managing vendor and supplier relationships. Here's a practical framework:
Pre-Onboarding Due Diligence: Before engaging any third party with access to systems or data, conduct a formal cybersecurity risk assessment. Evaluate the vendor's security posture against SAMA CSF and ISO 27001 standards. Require evidence of certifications, audit reports (SOC 2, ISO 27001), and completed security questionnaires.
Contractual Obligations: All third-party contracts must include cybersecurity clauses covering data protection, incident notification timelines (typically 72 hours per PDPL obligations), right-to-audit provisions, and compliance with NCA ECC requirements where applicable.
Tiered Risk Classification: Classify vendors into Critical, High, Medium, and Low risk tiers based on their access level, data sensitivity, and operational dependency. Critical vendors (e.g., core banking system providers, cloud infrastructure) require annual reassessments and on-site audits.
Continuous Monitoring: Implement ongoing monitoring through periodic questionnaires, security ratings platforms, and review of vendor security bulletins. SAMA expects banks to maintain an updated third-party inventory with associated risk scores.
Exit Strategy: Document formal off-boarding procedures including data return/destruction certificates and access revocation timelines.
Practically, assign a dedicated Third-Party Risk Owner within your GRC team and integrate vendor assessments into your enterprise risk register. Regulators increasingly scrutinize supply chain risk, particularly for cloud and fintech partnerships, so documented evidence of this program is essential during SAMA examinations.
Third-party risk management is a critical obligation under SAMA CSF Domain 4 (Third Party Management), which requires Saudi banks to establish a formal, risk-based vendor management program. Here's how to implement it effectively:
1. Vendor Classification & Risk Tiering: Classify all third parties (cloud providers, fintech partners, IT vendors) based on data sensitivity, criticality of services, and access levels. SAMA CSF requires higher scrutiny for vendors with access to critical systems or customer data.
2. Pre-Onboarding Due Diligence: Before engagement, conduct cybersecurity assessments including review of ISO 27001 certifications, SOC 2 reports, and NCA ECC alignment. Require vendors to complete a security questionnaire aligned with SAMA CSF controls.
3. Contractual Security Requirements: Embed cybersecurity clauses in all vendor contracts covering: incident notification timelines (per SAMA CSF Control 4.3), data handling obligations under PDPL, right-to-audit provisions, and minimum security standards.
4. Continuous Monitoring: Don't treat vendor risk as a one-time assessment. Implement continuous monitoring through annual reassessments, periodic penetration testing of vendor-connected interfaces, and real-time threat intelligence on critical suppliers.
5. Offboarding Controls: Ensure data return/deletion processes are documented and verified upon contract termination, aligning with PDPL Article 19 on data retention.
Practical Tip: Maintain a centralized vendor risk register reviewed quarterly by your risk committee. SAMA examiners frequently assess the maturity of your third-party risk program during regulatory reviews, so documentation quality matters as much as the controls themselves.
Under SAMA CSF Domain 3.3 (Third-Party Management), Saudi banks must implement a structured TPRM program that spans the entire vendor lifecycle — from onboarding through offboarding.
Key Requirements:
- Risk Classification: Categorize vendors by criticality (Tier 1: critical/outsourced core banking; Tier 2: significant access; Tier 3: limited exposure). SAMA CSF Control 3.3.2 mandates risk-based due diligence prior to engagement.
- Contractual Controls: Ensure all vendor contracts include cybersecurity obligations, audit rights, incident notification clauses (within 72 hours per SAMA CSF 3.3.5), and data handling requirements aligned with PDPL Article 5.
- Ongoing Monitoring: Conduct annual cybersecurity assessments for Tier 1 vendors, including review of their ISO 27001 certification, SOC 2 reports, or completion of a standardized questionnaire aligned with NCA ECC controls.
- Cloud and Outsourcing: For cloud-based third parties, apply SAMA's Outsourcing Requirements and NCA Cloud Cybersecurity Controls (CCC-1 through CCC-4), ensuring data sovereignty requirements are met — particularly that sensitive customer data processed by third parties remains within approved jurisdictions.
- Offboarding: Define secure data disposal and access revocation procedures documented per SAMA CSF 3.3.8.
Practical Tip: Maintain a centralized Third-Party Register with risk scores, assessment dates, and contractual compliance status. This register is frequently reviewed during SAMA regulatory examinations. Automating this within your GRC platform significantly reduces audit preparation time and ensures continuous compliance visibility.
Third-party risk management (TPRM) is a critical obligation for Saudi financial institutions under SAMA CSF Domain 4 (Third-Party Management) and NCA ECC-1:2018 Article 3-5. Here is how to build a compliant program:
1. Vendor Classification & Risk Tiering Classify vendors based on data access, criticality, and integration depth. SAMA CSF Control 4.3 requires a formal classification methodology distinguishing critical from non-critical suppliers.
2. Pre-Onboarding Due Diligence Before engagement, conduct cybersecurity assessments including review of ISO 27001 certification, SOC 2 reports, and security questionnaires. Verify that cloud or SaaS vendors hosting financial data hold NCA approval where applicable.
3. Contractual Security Requirements Embed security clauses covering data handling, breach notification timelines (PDPL requires notifying SDAIA within 72 hours), right-to-audit provisions, and minimum security controls aligned with SAMA CSF.
4. Continuous Monitoring SAMA CSF Control 4.5 mandates ongoing oversight — not just point-in-time assessments. Use threat intelligence feeds, vendor security scorecards, and periodic reassessments (at least annually for critical vendors).
5. Exit & Termination Procedures Document data return and secure deletion processes upon contract termination, ensuring no residual data exposure.
6. Concentration Risk Awareness SAMA also expects boards to understand concentration risk — where multiple critical functions depend on a single third party.
A mature TPRM program protects your institution from supply-chain attacks and regulatory findings during SAMA examinations. Platforms like CISO Consulting can automate vendor risk scoring and map findings directly to SAMA CSF controls.
Third-party risk management (TPRM) is a critical obligation under SAMA CSF Domain 3.3 (Third-Party Management), requiring Saudi banks to establish a structured program covering the full vendor lifecycle. Here's a practical approach:
Pre-Engagement Assessment: Before onboarding any vendor with access to systems or data, conduct a cybersecurity due diligence review. Per SAMA CSF Control 3.3.1, vendors must be classified based on risk level — critical, high, medium, or low — depending on data sensitivity, system access, and regulatory impact.
Contractual Controls: All vendor contracts must include cybersecurity clauses addressing data handling, incident notification timelines (typically 72 hours), audit rights, and compliance with PDPL obligations if personal data is involved.
Ongoing Monitoring: SAMA CSF Control 3.3.3 mandates periodic reassessment of vendor risk posture. For critical vendors, this should occur at least annually, including review of their ISO 27001 certifications, penetration test results, and SOC 2 reports where available.
Exit Strategy: Define clear data return and destruction procedures for vendor offboarding, aligned with NCA ECC Article 2-14 on data lifecycle management.
Practical Tip: Use a vendor risk register maintained within your GRC platform to automate assessment workflows, track remediation deadlines, and generate audit-ready evidence for SAMA examination teams. Fintech companies should pay particular attention to cloud service providers and payment processors, as these often carry the highest concentration of risk.
Security awareness training is often underestimated, yet it is explicitly mandated and audited under both SAMA CSF and NCA ECC. A well-structured program goes far beyond annual click-through videos.
Regulatory Baseline:
- SAMA CSF Control 3.2.1 requires a formal cybersecurity awareness and training program tailored to staff roles.
- NCA ECC Article 2-7 mandates periodic awareness campaigns covering phishing, social engineering, and acceptable use policies.
Program Structure — What Auditors Look For:
- Role-Based Training: Generic training is insufficient. Segment your audience — executives require board-level briefings on cyber risk and governance; IT staff need technical deep-dives; general staff need phishing simulation and social engineering awareness.
- Frequency: SAMA expects at least annual mandatory training with documented completion records. For high-risk roles (e.g., privileged users, finance teams), quarterly refreshers are strongly recommended.
- Phishing Simulations: Run monthly or quarterly simulated phishing campaigns. Track click rates, report rates, and repeat offenders. Use results to trigger targeted remediation training — and maintain these records for SAMA examination.
- New Hire Onboarding: Security awareness must be embedded in onboarding programs within the first 30 days of employment.
- Metrics and Reporting: Report training completion rates, simulation results, and awareness KPIs to the CISO and board on a quarterly basis. This demonstrates a mature, measurable program.
- PDPL Awareness: Since Saudi PDPL imposes personal liability on staff handling personal data, include dedicated modules on data handling, consent, and breach reporting obligations.
Document everything rigorously — training logs, attendance records, and phishing simulation reports are standard evidence requests during SAMA regulatory inspections.
Third-party risk management (TPRM) is a critical compliance obligation under SAMA CSF Domain 3 (Cybersecurity Risk Management), specifically controls 3.3.1 through 3.3.5, which require financial institutions to assess, monitor, and govern all third-party relationships that touch sensitive systems or data.
To build a compliant TPRM program, Saudi banks should:
- Vendor Classification: Categorize all vendors by criticality — Tier 1 (critical/direct system access), Tier 2 (moderate risk), Tier 3 (low risk). SAMA CSF Control 3.3.2 mandates risk-based classification.
- Pre-Onboarding Due Diligence: Conduct cybersecurity assessments before contract signing. This includes reviewing ISO 27001 certifications, SOC 2 reports, or equivalent evidence of security posture.
- Contractual Controls: Ensure contracts include cybersecurity clauses covering incident notification timelines (typically 72 hours), right-to-audit provisions, and data handling obligations aligned with PDPL Article 19.
- Continuous Monitoring: SAMA CSF requires ongoing oversight — not just point-in-time assessments. Use automated tools or periodic questionnaires to monitor Tier 1 vendors at least annually, and Tier 2 vendors biannually.
- Fourth-Party Risk: Identify and assess sub-processors used by your critical vendors, particularly cloud providers or payment processors.
- Exit Strategy: Maintain documented offboarding procedures to revoke access and retrieve or destroy data when vendor relationships end.
NCA ECC Article 2-14 further reinforces these obligations for entities within the national cybersecurity scope. Non-compliance with TPRM controls is a frequent finding in SAMA regulatory examinations and can result in formal corrective action plans.
Security awareness training is not optional for Saudi financial institutions — it is a formal regulatory requirement embedded in SAMA CSF Domain 3.2 (Human Resources Security), and a contributing control under NCA ECC Article 4.
SAMA CSF Requirements:
- Control 3.2.1 requires institutions to implement a cybersecurity awareness program covering all employees, contractors, and privileged users.
- Training must be role-based: general staff receive phishing and social engineering awareness, while IT and security teams receive technically advanced content.
- New joiners must complete foundational cybersecurity training before or immediately after system access is granted.
- Annual refresher training is mandatory, with records maintained for audit purposes.
What Makes a Program Effective:
- Phishing Simulations: Run monthly or quarterly simulated phishing campaigns and track click rates over time. SAMA examiners look for measurable improvement metrics.
- Role-Based Modules: Tailor content for executives (social engineering, deepfake fraud), customer-facing staff (account takeover, vishing), and developers (secure coding, OWASP Top 10).
- Arabic-First Content: Ensure training materials are delivered in Arabic to maximize comprehension and engagement across all staff levels.
- Metrics and Reporting: Track completion rates, phishing simulation results, and knowledge assessment scores. Report quarterly to the CISO and annually to the board.
- Regulatory Scenario Training: Include Saudi-specific scenarios — PDPL data handling, SAMA incident reporting obligations, and NCA notification duties.
Exam Tip: During SAMA examinations, auditors commonly request training completion records, phishing simulation reports, and evidence of board-level cybersecurity briefings. Maintain these artifacts meticulously to demonstrate a mature security culture.
Third-party risk management (TPRM) is a critical compliance obligation for Saudi financial institutions. Under SAMA CSF Domain 4 (Third Party Management), banks must establish a formal vendor risk management program that includes due diligence, contractual security requirements, and continuous monitoring.
Key implementation steps include:
1. Vendor Classification & Due Diligence: Categorize vendors by criticality and data access. Critical vendors handling sensitive financial or personal data must undergo comprehensive security assessments before onboarding, including reviewing their ISO 27001 certification status and security posture.
2. Contractual Obligations: All vendor contracts must include security clauses covering data protection (aligned with PDPL Article 29), right-to-audit provisions, incident notification timelines (typically 72 hours), and compliance with NCA ECC controls where applicable.
3. Ongoing Monitoring: SAMA CSF requires periodic reassessment — at minimum annually for critical vendors. This includes reviewing SOC 2 Type II reports, conducting questionnaire-based assessments, and tracking regulatory changes affecting your vendors.
4. Cloud & SaaS Vendors: For cloud service providers, NCA CCC (Cloud Computing Controls) compliance must be validated. SAMA also requires that data residency within Saudi Arabia is confirmed for sensitive financial data.
5. Offboarding Procedures: Ensure data return or destruction obligations are enforced contractually and operationally upon vendor termination.
Our GRC platform provides a structured TPRM module with pre-built vendor questionnaires mapped to SAMA CSF, NCA ECC, and PDPL, enabling compliance officers to track vendor risk scores, automate reassessment schedules, and generate audit-ready reports — saving significant manual effort.
Third-party risk management (TPRM) is a critical obligation for Saudi financial institutions. Under SAMA CSF Control 3.3, banks must establish a formal vendor risk management program that classifies suppliers based on the sensitivity of data accessed and criticality of services provided.
Key implementation steps include:
1. Vendor Classification & Due Diligence: Categorize vendors as critical, important, or standard. Conduct pre-onboarding security assessments including reviewing SOC 2 Type II reports, ISO 27001 certifications, and financial stability indicators.
2. Contractual Obligations: All vendor contracts must include cybersecurity clauses covering data protection (aligned with PDPL Article 21), incident notification timelines (within 72 hours per SAMA CSF), audit rights, and right-to-terminate provisions.
3. Continuous Monitoring: Implement ongoing monitoring using automated tools to track vendor security posture. NCA ECC Article 3-4 requires organizations to assess the cybersecurity controls of cloud and technology service providers periodically.
4. Concentration Risk: SAMA guidelines warn against over-reliance on a single vendor, particularly for critical infrastructure. Maintain fallback arrangements and exit strategies.
5. Subcontractor Oversight: Ensure primary vendors disclose and control their own subcontractors who may access your data or systems.
Practically, institutions should maintain a vendor risk register, conduct annual reassessments for critical vendors, and include TPRM findings in quarterly board-level cybersecurity reports as required by SAMA CSF's governance domain. A GRC platform can automate vendor questionnaires, track remediation, and generate audit-ready evidence for SAMA examinations.
Third-party risk management is a critical obligation under SAMA CSF Domain 4 (Third Party Cybersecurity), which requires Saudi financial institutions to establish a structured vendor risk program across the entire supplier lifecycle.
Key Requirements:
- Pre-onboarding Due Diligence (SAMA CSF 4.1): Conduct cybersecurity risk assessments before contracting any third party with access to sensitive systems or data. This includes reviewing ISO 27001 certifications, SOC 2 reports, and NCA ECC alignment.
- Contractual Obligations (SAMA CSF 4.2): All vendor contracts must include cybersecurity clauses covering data handling, incident notification timelines (typically within 72 hours), right-to-audit provisions, and compliance with PDPL data processing requirements.
- Continuous Monitoring (SAMA CSF 4.3): Implement ongoing monitoring of critical vendors using tools such as security ratings platforms and periodic reassessments (at least annually for Tier-1 vendors).
- Concentration Risk: SAMA guidance also highlights the risk of over-reliance on single vendors, particularly for cloud or core banking services.
Practical Steps:
- Classify vendors by criticality (Tier 1–3) based on data access and operational impact.
- Develop a standardized vendor security questionnaire aligned to SAMA CSF and NCA ECC controls.
- Include third-party incidents in your incident response runbooks.
- Maintain a live vendor risk register reviewed quarterly by the CISO.
Non-compliance with third-party risk requirements can result in regulatory findings during SAMA examinations and reputational exposure.
Third-party risk management (TPRM) is a critical compliance obligation for Saudi financial institutions. Under SAMA CSF Control 3.3, banks must establish a formal vendor risk management program that includes pre-onboarding due diligence, contractual security requirements, and ongoing monitoring.
Key implementation steps include:
1. Vendor Classification: Categorize vendors by criticality — Tier 1 (critical/core systems), Tier 2 (significant), and Tier 3 (low-risk). Apply proportionate controls accordingly.
2. Pre-Onboarding Assessment: Require vendors to complete security questionnaires aligned with ISO 27001 Annex A controls and NCA ECC Article 2-14, which mandates that outsourced services meet equivalent cybersecurity standards.
3. Contractual Obligations: Contracts must include cybersecurity clauses covering incident notification timelines (typically within 24 hours per SAMA expectations), audit rights, data handling, and exit strategies.
4. Continuous Monitoring: Conduct annual reassessments for Tier 1 vendors and use automated tools (threat intelligence feeds, security ratings platforms) for real-time monitoring.
5. Cloud Providers: For cloud-based vendors, apply SAMA's Cloud Computing Framework requirements, including data residency confirmations for sensitive financial data within Saudi Arabia.
Practically, institutions should maintain a centralized vendor risk register, assign ownership per vendor, and integrate TPRM findings into the broader risk register reported to the board. Failure to manage third-party risk adequately is one of the most cited findings in SAMA regulatory examinations, making this a top-priority compliance area for CISOs and compliance officers alike.
Security Awareness Training (SAT) is a mandatory compliance requirement — not optional — for Saudi fintechs and financial institutions. Both SAMA CSF and NCA ECC explicitly require formal, ongoing awareness programs targeting all employees.
Regulatory Requirements:
- SAMA CSF Control 3.2: Mandates cybersecurity awareness programs covering phishing, social engineering, acceptable use policies, and incident reporting procedures. Programs must be role-based and conducted at least annually, with new hire onboarding training.
- NCA ECC Article 2-5: Requires organizations to implement cybersecurity awareness and training programs, maintain training records, and ensure personnel understand their cybersecurity responsibilities.
Building an Effective SAT Program:
1. Role-Based Training Tracks: Develop separate modules for general staff, IT/security teams, privileged users, executives, and developers. Each role faces distinct threats — developers need secure coding awareness, executives need spear-phishing and BEC (Business Email Compromise) training.
2. Simulated Phishing Campaigns: Run monthly or quarterly simulated phishing exercises. Track click rates and tailor follow-up training for vulnerable users. SAMA examiners frequently request phishing simulation data during reviews.
3. Training Content Areas: Cover password hygiene, data handling per PDPL, social engineering recognition, mobile device security, and insider threat awareness.
4. Metrics and Reporting: Track completion rates (target: 95%+), phishing simulation failure rates (target: below 5%), and post-training assessment scores. Present results quarterly to the CISO and annually to the board.
5. Documentation: Maintain training records for at least 3 years to support SAMA and NCA audit evidence requirements.
Integrating SAT into a broader human risk management strategy — rather than treating it as a checkbox exercise — significantly reduces the likelihood of successful social engineering attacks against your institution.
A robust Third-Party Risk Management (TPRM) program for Saudi financial institutions must address requirements across SAMA CSF Control Domain 3.3 and NCA ECC Article 2-7. Here is how to structure it effectively:
1. Vendor Classification & Due Diligence: Categorize all third parties by risk tier (critical, high, medium, low) based on data access, system integration depth, and service criticality. Per SAMA CSF Control 3.3.1, formal due diligence must be conducted before onboarding any vendor with access to financial or customer data.
2. Contractual Obligations: Ensure all vendor contracts include cybersecurity clauses covering data handling, incident notification timelines (within 72 hours per PDPL Article 27), audit rights, and compliance with NCA ECC standards. Offshore vendors must adhere to PDPL cross-border data transfer restrictions.
3. Continuous Monitoring: Implement ongoing monitoring through annual security assessments, quarterly performance reviews, and real-time threat intelligence feeds for critical vendors. SAMA CSF requires periodic reassessment aligned with vendor risk tier.
4. Fourth-Party Risk: Map your vendors' subcontractors to identify hidden concentration risks, particularly in cloud and payment processing chains.
5. Incident Response Coordination: Establish joint incident response procedures with critical vendors, ensuring alignment with your institution's overall IR plan per SAMA CSF Control 3.6.
Practical Tip: Maintain a centralized vendor registry with automated risk scoring updated at least annually. Regulators increasingly scrutinize TPRM documentation during SAMA examinations, so audit-ready records are essential.
Third-party risk management (TPRM) is a critical compliance obligation for Saudi financial institutions. Under SAMA CSF Control 3.3 (Third Party Management), member organizations must establish a formal vendor risk program that covers the entire supplier lifecycle — from onboarding through offboarding.
Key requirements include:
1. Pre-Engagement Due Diligence: Before contracting any vendor, conduct a cybersecurity risk assessment aligned with SAMA CSF Annex requirements. Classify vendors by criticality (e.g., Tier 1 for core banking system providers).
2. Contractual Security Clauses: Ensure all vendor contracts include mandatory cybersecurity clauses covering data protection, incident notification timelines (typically within 24-72 hours), audit rights, and compliance with PDPL obligations when personal data is shared.
3. Continuous Monitoring: NCA ECC Article 2-12 requires periodic reassessment of third-party risks. Implement quarterly or annual security reviews depending on the vendor's risk tier. Use standardized questionnaires (e.g., SIG Lite or a SAMA-aligned template).
4. Cloud and SaaS Vendors: For cloud service providers, ensure compliance with NCA CCC (Cloud Computing Controls) and verify that data residency requirements are met — critical for banks storing customer financial data.
5. Incident Escalation Paths: Define clear escalation procedures if a vendor experiences a breach that could impact your institution. This should align with your internal SAMA-required incident response plan.
Best practice is to maintain a centralized Vendor Risk Register reviewed by your CISO or vCISO quarterly. Failure to manage third-party risks has been a leading cause of regulatory findings during SAMA examinations.
Third-party risk management (TPRM) is a critical compliance obligation for Saudi financial institutions. Under SAMA CSF Control 3.3 (Third-Party Management), banks must establish a formal vendor risk program that covers the entire vendor lifecycle — from onboarding and due diligence through contract management to offboarding.
Key requirements include:
1. Risk-Based Vendor Classification: Categorize vendors by criticality (Tier 1–3) based on data access, system integration depth, and service criticality. Critical vendors providing core banking or cloud infrastructure services demand enhanced scrutiny.
2. Pre-Engagement Due Diligence: Before onboarding, assess vendors' security posture using standardized questionnaires aligned with NCA ECC controls. Obtain evidence of certifications such as ISO 27001, SOC 2, or equivalent.
3. Contractual Security Obligations: Per SAMA CSF Control 3.3.2, contracts must include mandatory cybersecurity clauses covering data protection, incident notification timelines (typically within 72 hours), audit rights, and compliance with Saudi regulations including PDPL.
4. Ongoing Monitoring: Conduct annual security assessments for Tier 1 vendors and periodic reviews for lower-tier suppliers. NCA ECC Article 2-6 emphasizes continuous monitoring of supply chain risks.
5. Cloud and SaaS Vendors: For cloud service providers, validate CSP compliance with NCA Cloud Cybersecurity Controls (CCC) and ensure data residency requirements within the Kingdom are met where applicable.
6. Exit and Offboarding: Ensure data destruction or return protocols are contractually mandated and verified upon vendor termination.
Practically, implement a centralized TPRM register within your GRC platform to track assessments, risk ratings, and remediation actions. This provides audit-ready documentation for SAMA regulatory examinations and NCA inspections.
Third-party risk management (TPRM) is a critical obligation under SAMA CSF Domain 3.3 and NCA ECC-1: 2-7, requiring financial institutions to establish a structured vendor risk lifecycle.
Key Steps for Compliance:
- Vendor Classification: Categorize all third parties based on data sensitivity, service criticality, and access level. Distinguish between Tier 1 (critical/direct system access) and lower tiers accordingly.
- Pre-Onboarding Due Diligence: Before contracting, assess vendors using security questionnaires aligned with SAMA CSF controls. Require evidence of ISO 27001 certification or equivalent for critical vendors.
- Contractual Controls (per SAMA CSF 3.3.5): Ensure contracts include cybersecurity clauses covering: data protection obligations, right-to-audit provisions, incident notification timelines (typically within 72 hours), and compliance with PDPL if personal data is shared.
- Ongoing Monitoring: Conduct annual cybersecurity assessments for Tier 1 vendors. Use automated tools to monitor for supply chain vulnerabilities and threat intelligence related to your vendors.
- NCA ECC Alignment: NCA ECC Article 2-7 specifically requires that outsourced services maintain security controls equivalent to the institution's own standards. Document this equivalency formally.
- Offboarding Procedures: Ensure data deletion, access revocation, and documentation of secure vendor exit.
A practical starting point is building a Vendor Risk Register that tracks vendor criticality, last assessment date, identified gaps, and remediation status. This register should be reviewed quarterly by the CISO and presented to the board risk committee annually.
Third-party risk management is a critical obligation under SAMA CSF Domain 3 (Cyber Security Risk Management), specifically Controls 3.3.1 through 3.3.5, which require financial institutions to formally assess, govern, and monitor all third-party relationships that could impact cybersecurity posture.
A compliant TPRM program for Saudi banks should include the following components:
1. Vendor Classification & Risk Tiering: Categorize all vendors based on data access, system connectivity, and service criticality. Tier 1 vendors (e.g., core banking providers, cloud platforms) require full due diligence.
2. Pre-Onboarding Due Diligence: Conduct security assessments before engaging any vendor. This includes reviewing ISO 27001 certifications, SOC 2 reports, and questionnaire-based assessments aligned with NCA ECC controls.
3. Contractual Safeguards: Per SAMA CSF Control 3.3.3, contracts must include cybersecurity clauses covering data handling, breach notification timelines (aligned with PDPL Article 19's 72-hour notification obligation), right-to-audit provisions, and exit strategies.
4. Continuous Monitoring: Implement ongoing monitoring of critical vendors using threat intelligence feeds, security ratings platforms, and periodic reassessments — at minimum annually for Tier 1 vendors.
5. Concentration Risk Management: SAMA specifically flags concentration risk when multiple critical services rely on a single vendor or technology provider.
6. Incident Coordination: Establish clear escalation procedures for vendor-related security incidents, ensuring alignment with your own incident response plan.
Practically, banks should maintain a centralized vendor register within their GRC platform, automated assessment workflows, and audit-ready documentation. Non-compliance in this area has been a recurring finding in SAMA examinations across the Saudi financial sector.
Third-party risk management (TPRM) is a critical obligation under both SAMA CSF Domain 4.3 and NCA ECC-2: 1-5. Saudi financial institutions must implement a structured, risk-based TPRM lifecycle covering the following stages:
1. Vendor Onboarding & Classification: Classify vendors by criticality — Tier 1 (critical/core banking systems), Tier 2 (significant), and Tier 3 (low-risk). Per SAMA CSF Control 4.3.2, all critical vendors must undergo security due diligence before contract execution.
2. Contractual Security Requirements: Contracts must include cybersecurity clauses covering data protection (aligned with PDPL Article 21), incident notification timelines (typically 72 hours), audit rights, and compliance with applicable Saudi regulations.
3. Ongoing Monitoring: Conduct annual security assessments or questionnaires for Tier 1 vendors. NCA ECC recommends periodic reviews of vendor access privileges and security posture. Use standardized frameworks like shared assessments or CAIQ (CSA Cloud) for cloud vendors.
4. Concentration Risk: SAMA specifically highlights the risk of over-reliance on single vendors for critical services. Maintain documented contingency plans and alternative sourcing strategies.
5. Offboarding: Ensure secure data deletion, access revocation, and documentation per PDPL data retention requirements.
Practical Tip: Build a centralized vendor register with risk ratings, assessment dates, and contract expiry. Automate reassessment triggers using your GRC platform. Assign a dedicated TPRM owner within the information security function to maintain accountability and audit-readiness during SAMA examinations.
SAMA CSF Domain 3 (Cybersecurity Operations & Technology) and specifically Controls 3.3.1–3.3.5 mandate that financial institutions maintain and regularly test an Incident Response Plan (IRP). A tabletop or simulation exercise must be conducted at least annually, with critical institutions advised to run them semi-annually.
Step 1 – Define Scope and Scenario Select a realistic scenario relevant to your institution (e.g., ransomware attack on core banking, BEC fraud targeting SWIFT transactions, or insider data exfiltration). Align the scenario with your institution's crown jewels and recent threat intelligence.
Step 2 – Assemble the Right Stakeholders Involve IT security, legal, compliance, communications, operations, and senior management. SAMA CSF requires board-level awareness of cyber incidents, so including C-suite members in tabletop exercises is strongly recommended.
Step 3 – Define Injects and Timelines Structure the exercise with pre-planned injects that simulate real decision points: initial alert triage, escalation thresholds, regulatory notification to SAMA (within 72 hours per SAMA CSF Control 3.3.4), and customer communication decisions.
Step 4 – Regulatory Notification Simulation Practice drafting the mandatory incident notification to SAMA, ensuring it covers: incident type and classification, affected systems and data, containment actions taken, and recovery timeline estimates.
Step 5 – Post-Exercise Lessons Learned Document all gaps, decision delays, and communication breakdowns. Create a remediation action plan with owners and deadlines. SAMA assessors will specifically look for evidence that lessons learned are tracked and closed.
Pro tip: Integrate NCA ECC Article 2-7 crisis management requirements into your exercise design if your institution is also subject to NCA oversight, ensuring dual-framework compliance in a single exercise.
Under SAMA CSF Domain 4 (Cyber Resilience), Saudi banks must establish a comprehensive Business Continuity Management (BCM) program that addresses both IT and cybersecurity dimensions. Key requirements include:
1. BCP and DRP Development: Per SAMA CSF Control 4.3, institutions must develop, document, and maintain a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) that explicitly cover cyber disruption scenarios — not just traditional outages.
2. Recovery Time and Point Objectives: Banks must define and validate RTO and RPO targets for critical systems, ensuring alignment with SAMA's operational resilience expectations. Core banking systems typically require RTOs under 4 hours.
3. Regular Testing: SAMA CSF requires BCM tests at least annually, including tabletop exercises and full failover drills. Test results must be documented and gaps remediated within defined timelines.
4. Cyber Incident Integration: BCP must be integrated with the Cyber Incident Response Plan (CIRP) to ensure seamless escalation from incident containment to business recovery.
5. Third-Party Dependencies: Critical third-party and outsourced service providers must be included in BCP scope, with contractual SLAs supporting recovery objectives.
6. Board and Senior Management Oversight: BCM governance must include board-level approval of BCP policies and annual reporting on resilience posture.
Practically, institutions should conduct a Business Impact Analysis (BIA) annually to reprioritize critical processes and map dependencies. Aligning your BCM framework with ISO 22301 alongside SAMA CSF provides a robust, internationally recognized structure that also satisfies NCA ECC resilience controls.
Third-party risk management is one of the most scrutinized areas in SAMA examinations and NCA assessments. SAMA CSF Control 3.3.14 (Third-Party Management) and NCA ECC Article 2-9 establish clear expectations. For Saudi fintechs — which typically rely heavily on external technology providers, cloud platforms, and payment processors — a structured TPRM program is non-negotiable.
Vendor Inventory & Tiering: Begin by building a comprehensive inventory of all third parties with access to your systems, data, or critical processes. Classify vendors into tiers based on criticality and data sensitivity. Tier-1 vendors (e.g., core banking system providers, cloud infrastructure, payment gateways) require the most rigorous controls.
Pre-Engagement Due Diligence: Before onboarding any Tier-1 or Tier-2 vendor, conduct formal security due diligence — review ISO 27001 certifications, SOC 2 Type II reports, NCA compliance attestations, and conduct questionnaire-based assessments mapped to SAMA CSF and NCA ECC controls. SAMA expects documented evidence of pre-contract security reviews.
Contractual Security Requirements: All vendor contracts must include cybersecurity clauses covering: right-to-audit, incident notification obligations (within 72 hours per SAMA guidance), data handling and sub-processor restrictions, and compliance with Saudi data residency requirements under PDPL.
Ongoing Monitoring: TPRM is not a one-time exercise. Implement continuous monitoring through annual reassessments for Tier-1 vendors, ongoing threat intelligence feeds tracking vendor-specific vulnerabilities, and real-time monitoring of vendor access logs where applicable.
Concentration Risk: SAMA specifically flags concentration risk — where a single third party supports multiple critical functions. Map your dependencies and maintain documented contingency plans and exit strategies for critical vendors.
Board-Level Reporting: Aggregate TPRM findings into quarterly risk reports presented to the Risk Committee, demonstrating active governance — a key SAMA CSF requirement under Control 3.1.
Business Continuity Management (BCM) under SAMA CSF (Domain 3.3) is a mandatory requirement for all Saudi financial institutions. Here is how to structure a compliant BCM program:
1. Business Impact Analysis (BIA): Conduct a formal BIA per SAMA CSF Control 3.3.2 to identify critical business functions, dependencies, and acceptable downtime thresholds (RTO/RPO). Financial institutions must document Maximum Tolerable Downtime (MTD) for each critical process.
2. BCM Policy and Governance: Establish a board-approved BCM policy. SAMA CSF requires senior management accountability for BCM, with clear roles assigned to a Business Continuity Manager and departmental owners.
3. Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP): Develop and maintain documented BCPs per SAMA CSF Control 3.3.4, covering manual workarounds, alternate processing sites, staff escalation trees, and communication protocols. DRPs must address IT system recovery with defined RTO objectives — typically 4 hours or less for critical banking systems.
4. Testing and Exercising: SAMA CSF mandates periodic testing (at minimum annually) including tabletop exercises, functional tests, and full failover simulations. Test results must be documented and gaps remediated within defined timelines.
5. Integration with Cyber Incident Response: Align BCM with your Cyber Incident Response Plan (CIRP) to ensure continuity during cyberattacks — particularly ransomware and DDoS scenarios common in the Saudi financial sector.
6. Third-Party BCM: Per SAMA CSF Control 3.3.6, assess and verify the BCM capabilities of critical third-party vendors annually.
Annual SAMA audits will review BCM documentation, test evidence, and board-level oversight. A well-structured BCM program also satisfies overlapping requirements under NCA ECC Section 2-7 and ISO 22301.
Business Continuity Management (BCM) for Saudi financial institutions is governed primarily by SAMA CSF Domain 4 (Resilience) and NCA ECC Article 3-5, which together require documented, tested, and board-approved continuity plans capable of sustaining critical operations during cyber incidents, natural disasters, and system failures.
Core BCM Requirements Under SAMA CSF:
- Business Impact Analysis (BIA): Identify critical business functions, dependencies, Recovery Time Objectives (RTOs), and Recovery Point Objectives (RPOs). SAMA expects RTOs for Tier-1 systems to be defined and technically achievable — typically under 4 hours for core banking.
- Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP): Separate but aligned documents. The BCP addresses operational continuity; the DRP addresses IT systems restoration.
- Crisis Communication Plan: Define internal escalation paths and external communication protocols with SAMA, NFIS, and the public where applicable.
NCA ECC Additional Requirements (Art. 3-5): NCA requires cybersecurity-specific resilience controls integrated into the BCP, including secure backup architectures, offline/immutable backup storage, and cyberattack-specific recovery scenarios — not just traditional IT disaster scenarios.
Testing and Validation: SAMA CSF mandates at minimum an annual full-scale BCP/DRP test, including tabletop exercises and live failover drills. Test results must be formally documented, gaps remediated, and executive sign-off obtained.
Practical Recommendation: Align your BCM program with ISO 22301 as the international standard underpinning SAMA's expectations. Map ISO 22301 controls to SAMA CSF and NCA ECC requirements to produce a unified compliance artifact that satisfies all three frameworks simultaneously.
Business Continuity Management (BCM) is a critical pillar under the SAMA Cyber Security Framework (CSF), specifically addressed in Domain 4 (Cyber Resilience) and Control area 3.3 (Business Continuity & Disaster Recovery). Here is a structured approach for Saudi banks:
1. Business Impact Analysis (BIA): Identify and classify critical banking functions — core banking systems, payment gateways, SWIFT connectivity, and customer-facing digital channels. Per SAMA CSF Control 3.3.1, each critical process must have defined Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
2. BCM Policy & Governance: Establish a board-approved BCM policy assigning clear ownership to senior management. SAMA expects BCM to be treated as an enterprise-wide risk, not solely an IT function.
3. Business Continuity Plan (BCP) Development: Document response procedures for various disruption scenarios — cyberattacks, natural disasters, system failures, and pandemic events. Plans must include communication trees, escalation paths, and alternate site operations.
4. Disaster Recovery (DR) for IT Systems: Implement redundant infrastructure with geographically separated data centers within Saudi Arabia. SAMA CSF Control 3.3.4 requires documented DR plans tested at least annually, with evidence of test results maintained.
5. BCM Testing & Exercising: Conduct tabletop exercises, simulation drills, and full failover tests regularly. SAMA examiners will request test results and remediation logs during assessments.
6. Integration with ISO 22301: Aligning your BCM program with ISO 22301 (Business Continuity Management Systems) provides a globally recognized framework that also satisfies SAMA's structured documentation and audit requirements.
Maintain updated BCM documentation, review plans after every significant incident, and ensure third-party critical service providers also have verified continuity arrangements.
Under SAMA CSF Domain 4 (Cybersecurity Operations and Technology), Member Organizations must establish a formal, documented Incident Response Program that covers the full lifecycle: preparation, detection, containment, eradication, recovery, and post-incident review.
Key Requirements:
- SAMA CSF Control 4.3.1 mandates a written Incident Response Policy and Procedure reviewed at least annually.
- Control 4.3.2 requires classification of incidents by severity (Critical, High, Medium, Low) with defined SLAs for each tier.
- Control 4.3.3 obligates notification to SAMA within specific timeframes for critical incidents — typically within 72 hours of confirmed breach, aligned with NCA ECC Article 4-3 reporting obligations.
Practical Guidance:
- Establish an Incident Response Team (IRT): Assign clear roles — IR Lead, Legal/Compliance, Communications, IT/SOC — with documented escalation paths.
- Integrate a SIEM/SOAR Platform: Automate detection and initial triage to reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
- Conduct Tabletop Exercises: Simulate ransomware, data breach, and DDoS scenarios at least twice per year, per SAMA CSF best practice.
- Coordinate with NCA: For critical infrastructure sectors, ensure your IR plan aligns with NCA's National Cybersecurity Incident Management Framework.
- Document Everything: Maintain evidence logs and post-incident reports to demonstrate compliance during SAMA audits.
A mature IR program not only satisfies regulatory requirements but significantly reduces financial and reputational damage during an actual incident.
Business Continuity Management is a critical pillar under SAMA CSF Domain 4 (Resilience), requiring Saudi financial institutions to establish, maintain, and periodically test a comprehensive BCM program. Per SAMA CSF Control 4.3, banks must develop a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP) that cover all critical business functions, IT systems, and third-party dependencies.
Key requirements include:
1. Business Impact Analysis (BIA): Identify critical processes and define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for each. Core banking systems typically require RTO of ≤4 hours and RPO of ≤1 hour.
2. Plan Documentation: BCPs must be formally documented, version-controlled, and approved by senior management and the board.
3. Testing Frequency: SAMA CSF mandates that BCM tests be conducted at least annually. Tests should include tabletop exercises, simulation drills, and full failover testing for critical systems.
4. Post-Test Reporting: Results must be documented and gaps remediated within defined timelines. Evidence of testing is a key artifact during SAMA regulatory examinations.
5. Alignment with NCA ECC: NCA ECC Article 3-5 also requires resilience controls for critical national infrastructure, which applies to licensed financial entities.
Best practice recommendations:
- Integrate BCM testing into your annual cybersecurity calendar.
- Include third-party providers in DR exercises where they host critical systems.
- Ensure your BCM documentation is reviewed after every significant infrastructure change or major incident.
A mature BCM program not only satisfies regulatory requirements but directly reduces operational risk exposure during ransomware attacks, outages, or natural disasters.
Under SAMA CSF Domain 4 (Cybersecurity Operations and Technology), specifically controls 4.3.1 through 4.3.5, Saudi financial institutions must establish a formal, documented Incident Response (IR) plan that covers the full lifecycle: detection, containment, eradication, recovery, and post-incident review.
Key mandatory elements include:
1. Incident Classification Framework: Define severity tiers (Critical, High, Medium, Low) aligned with business impact. Critical incidents — such as ransomware attacks or core banking system breaches — must be escalated to SAMA within 72 hours of detection, per SAMA's Cyber Incident Reporting guidelines.
2. Dedicated IR Team (CIRT): Assign clear roles including Incident Commander, Technical Lead, Legal/Compliance Liaison, and Communications Officer. Many Saudi banks fulfill this via a hybrid internal/vCISO model.
3. Playbooks by Scenario: Develop specific runbooks for high-risk scenarios relevant to banking: phishing-to-BEC attacks, ATM logical attacks, SWIFT fraud, DDoS on digital banking, and insider threats.
4. Integration with NCA ECC: NCA ECC Article 3-6-1 requires coordination with the National Cybersecurity Authority during major incidents. Ensure your IR plan includes the NCA escalation path alongside SAMA reporting.
5. Testing Requirements: SAMA CSF mandates that IR plans be tested at least annually via tabletop exercises or simulated attack scenarios. Results must be documented and used to update the plan.
6. Evidence Preservation: Establish forensic-ready logging (per SAMA CSF 4.2.x) to support post-incident analysis and potential regulatory investigations.
A practical starting point is to map your existing IR procedures against the SAMA CSF maturity model, targeting at least Level 3 (Defined) across all IR sub-domains before your next SAMA assessment.
Business Continuity Management (BCM) and cyber resilience are treated as critical pillars under SAMA CSF Domain 3.5, requiring Saudi financial institutions to maintain robust capabilities to withstand, respond to, and recover from disruptive cyber events.
Core SAMA CSF Requirements (Domain 3.5):
Business Continuity Planning: Institutions must develop, document, and maintain a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) that explicitly account for cyber incident scenarios — not just natural disasters or physical failures. Plans must identify Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) for critical systems, including core banking, payment processing, and customer-facing digital channels.
Testing and Exercises: Per SAMA CSF Control 3.5.3, BCPs and DRPs must be tested at least annually through tabletop exercises, simulations, or full failover drills. Test results must be formally documented, gaps identified, and remediation tracked to closure.
Cyber Incident Integration: BCM programs must be tightly integrated with the Cyber Incident Response Plan (CIRP). This means incident escalation paths, communication protocols, and recovery playbooks must be aligned and tested together — not maintained as separate silos.
Third-Party Dependencies: SAMA expects institutions to map critical third-party dependencies (e.g., cloud providers, payment networks, core banking vendors) within their BIA (Business Impact Analysis) and ensure contractual recovery commitments are captured in SLAs.
Board Oversight: Senior management and the Board must be briefed annually on BCM program status, test outcomes, and residual risks. Evidence of board engagement is a frequent SAMA examination checkpoint.
Building a resilient BCM program requires cross-functional collaboration between IT, cybersecurity, operations, legal, and communications teams — supported by a GRC platform that centralizes BIA data, test scheduling, and regulatory evidence.
Privileged Access Management (PAM) is a critical control for Saudi banks, directly addressed in SAMA CSF Domain 4 (Access Control) and NCA ECC Control 2-4 (Identity and Access Management). A non-compliant PAM posture is one of the most common findings in regulatory assessments.
SAMA CSF Requirements: Controls under Domain 4 require that privileged accounts are identified, strictly controlled, and their usage logged and monitored. Shared administrative accounts are explicitly discouraged.
NCA ECC Alignment: ECC Control 2-4-3 mandates that privileged access rights be reviewed periodically and revoked immediately upon role change or termination.
Practical PAM Implementation Framework:
- Discovery & Inventory: Enumerate all privileged accounts across on-premises systems, cloud environments, databases, and network devices. Many banks underestimate shadow admin accounts.
- Just-In-Time (JIT) Access: Eliminate standing privileges. Grant elevated access only when needed, for a defined duration, with full audit logging.
- Credential Vaulting: Store all privileged credentials in a PAM vault (e.g., CyberArk, Delinea, BeyondTrust). Rotate passwords automatically after each session.
- Session Recording: Record all privileged sessions for forensic and compliance purposes. This is essential for SAMA CSF audit evidence.
- Multi-Factor Authentication (MFA): Enforce MFA for all privileged access without exception.
- Quarterly Access Reviews: Conduct formal recertification of all privileged accounts every quarter, with documented approval from system owners.
CISOs should integrate PAM reporting into their board-level cybersecurity dashboards and ensure PAM controls are included in annual penetration testing scope to validate effectiveness.
Identity and Access Management (IAM) is a foundational control domain under both SAMA CSF and NCA ECC, and weak IAM is consistently cited in Saudi financial sector breach investigations. Here is a structured maturity roadmap:
SAMA CSF Requirements (Control Domain 3.3 & 3.4):
- Implement Role-Based Access Control (RBAC) aligned to job functions per SAMA CSF 3.3.5
- Enforce least-privilege principles and periodic access reviews (minimum quarterly for privileged accounts)
- Maintain a Privileged Access Management (PAM) solution for all administrative and system accounts per SAMA CSF 3.4.2
- Implement Multi-Factor Authentication (MFA) for all remote access, privileged sessions, and internet-facing applications per SAMA CSF 3.3.6
NCA ECC Requirements (Domain 2 - Access Management):
- NCA ECC Art. 2-1 mandates formal user lifecycle management including joiners, movers, and leavers processes
- NCA ECC Art. 2-3 requires annual recertification of all user access rights
- Shared and generic accounts must be eliminated or tightly controlled per NCA ECC Art. 2-2
Maturity Progression:
- Level 1 (Basic): Active Directory hardening, MFA deployment, documented access request process
- Level 2 (Intermediate): PAM solution deployment, automated provisioning/deprovisioning, SIEM integration for IAM events
- Level 3 (Advanced): Zero Trust Architecture adoption, Identity Governance & Administration (IGA) platform, behavioral analytics for anomalous access
Quick Wins for CISOs: Start with a privileged account discovery exercise — most Saudi banks discover 30-40% more privileged accounts than documented. Integrate IAM logs into your SOC for real-time detection of credential-based attacks, which account for over 60% of financial sector incidents globally.
Under SAMA CSF Domain 4 (Cybersecurity Resilience), Saudi banks must establish a robust Business Continuity Management (BCM) program that ensures critical financial services remain operational during and after a cyber incident.
Key Requirements:
- SAMA CSF Control 4.1: Develop and maintain a documented Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) covering all critical systems and data.
- SAMA CSF Control 4.2: Conduct BCP/DRP testing at least annually, including full simulation exercises, not just tabletop reviews.
- SAMA CSF Control 4.3: Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) aligned with SAMA's availability expectations for core banking systems.
Practical Implementation Steps:
- Business Impact Analysis (BIA): Identify critical banking processes (payments, core banking, customer portals) and classify them by criticality tier.
- Recovery Strategy Design: Establish geographically separated hot/warm standby sites within Saudi Arabia to comply with data residency requirements under PDPL and SAMA guidance.
- Integration with Cyber IR: Ensure your BCP directly references your Cyber Incident Response Plan (CIRP), so activation triggers are clearly defined.
- Staff Training: Assign BCM roles to specific personnel and conduct awareness sessions at least twice yearly.
- Vendor Alignment: Ensure critical third-party providers have compatible BCM plans reviewed during annual vendor assessments per SAMA CSF Control 3.3.
SAMA examiners will assess BCM maturity during regulatory inspections, so maintain evidence of tests, gap remediation, and board-level sign-off on BCP documents.
Security Awareness Training (SAT) is a mandatory control for Saudi fintechs operating under SAMA CSF and NCA ECC. Far too many organizations treat this as a checkbox exercise — a single annual e-learning module — rather than a continuous risk-reduction program.
SAMA CSF Requirements: Under Domain 2 (Cybersecurity Leadership & Governance), Control 2.4 mandates that organizations establish a formal security awareness program covering all employees, contractors, and privileged users. The program must be role-based, documented, and reviewed annually.
NCA ECC Requirements: Article 3-4 (Human Security) requires organizations to conduct awareness campaigns, enforce security policies through training, and maintain records of training completion for audit purposes.
Building an Effective Program:
- Role-Based Curriculum: Develop separate training tracks for general staff, IT/security teams, executives, and developers. Developers, for example, should receive secure coding and OWASP Top 10 training.
- Phishing Simulations: Run monthly simulated phishing campaigns. Track click rates and use failures as teachable moments, not punitive events. Target a sub-5% click rate as a KPI.
- Onboarding Integration: All new hires must complete baseline security training within their first 30 days, with signed acknowledgment of acceptable use and data handling policies.
- Executive Briefings: Conduct quarterly cybersecurity briefings for C-suite and board members aligned with SAMA's expectations for board-level oversight.
- Metrics and Reporting: Report SAT completion rates, phishing simulation results, and policy acknowledgment rates to the CISO and board annually, and maintain evidence for SAMA regulatory examinations.
- Cultural Localization: Deliver content in Arabic and contextualize scenarios to Saudi financial sector environments for maximum relevance and engagement.
Under SAMA CSF Control 3.3.1, member organizations must establish a formal cybersecurity awareness and training program covering all employees, contractors, and relevant third parties. The program must be risk-based, role-specific, and reviewed at least annually.
Key requirements include:
Program Design: Training content must be tailored by role — executives require governance-focused modules, IT staff need technical deep-dives, and general employees need phishing and social engineering awareness. Per SAMA CSF Control 3.3.2, specialized training is mandatory for staff with privileged access or critical system responsibilities.
Delivery & Frequency: Annual training is the minimum baseline, but SAMA expects banks to supplement with quarterly micro-modules, simulated phishing campaigns, and real-time threat briefings following major incidents or emerging threat intelligence.
Measurement & Metrics: Track completion rates, phishing simulation click rates, knowledge assessment scores, and repeat offenders. SAMA expects documented evidence of training effectiveness, not just attendance records.
Board & Senior Management: SAMA CSF explicitly requires cybersecurity awareness at the board level. CISOs should deliver annual briefings to the board covering threat landscape, regulatory updates, and organizational risk posture.
Practical Steps: Use a Learning Management System (LMS) with SCORM-compliant modules to automate delivery and track compliance. Integrate awareness campaigns with internal communications during events like National Cybersecurity Month. Localize content in Arabic and align scenarios to Saudi-specific threats such as CEO fraud targeting Saudi financial institutions.
Failure to maintain a documented, tested awareness program is a common finding in SAMA CSF maturity assessments and can negatively impact your maturity score across multiple domains.
Under SAMA CSF Control 3.3.1 and 3.3.2, Saudi financial institutions are required to establish a formal cybersecurity awareness and training program that covers all employees, contractors, and privileged users. The program must be risk-based, role-specific, and conducted at least annually — with more frequent training for high-risk roles such as IT administrators, finance staff, and executive leadership.
A CISO should structure the program across four pillars:
- Baseline Awareness: Mandatory onboarding training covering phishing, social engineering, password hygiene, and acceptable use policies. This applies to every employee from day one.
- Role-Based Training: Specialized modules for IT, development, and compliance teams — aligned with NCA ECC Article 2-14 which emphasizes competency-based cybersecurity education for technical staff.
- Phishing Simulations: Conduct quarterly simulated phishing campaigns. Track click rates, report rates, and remediation completion. SAMA examiners increasingly look for simulation evidence during assessments.
- Executive & Board Briefings: Senior management must understand cyber risk at a governance level. Align these sessions with ISO 27001 Clause 7.3 (Awareness) and document board-level acknowledgment.
Measure effectiveness through KPIs such as phishing simulation failure rates (target below 5%), training completion rates (target 100% within 30 days of assignment), and post-training knowledge assessment scores.
Document everything — SAMA examiners will request training records, completion reports, and evidence of program updates following incidents or threat landscape changes. Platforms like CISO Consulting can automate training assignments, track compliance status, and generate audit-ready reports mapped directly to SAMA CSF controls.
SAMA CSF Control 3.3.1 mandates that all financial institutions implement a formal cybersecurity awareness and training program covering all staff, contractors, and privileged users. The program must be role-based, regularly updated, and aligned with the institution's risk profile.
To build a compliant and effective program, Saudi banks should:
1. Define Training Tiers: Segment your audience into general staff, IT personnel, and executives. Each tier requires tailored content — for example, phishing simulation for general staff, secure coding for developers, and cyber risk governance for the C-suite.
2. Mandatory Frequency: SAMA CSF requires awareness training at least annually, but leading practice suggests quarterly micro-learning modules supplemented by monthly phishing simulations. New joiners must complete training within 30 days of onboarding.
3. Role-Specific Content: Per SAMA CSF Control 3.3.2, privileged users (system administrators, DBA, network engineers) must receive additional training covering access control risks, insider threats, and secure configuration management.
4. Metrics and Reporting: Track completion rates, phishing click-through rates, and assessment scores. SAMA examiners expect documented evidence of training completion and program effectiveness reviews.
5. Integration with ISO 27001: Annex A Control 6.3 (Information Security Awareness, Education and Training) aligns closely with SAMA requirements, making it efficient to design a unified program.
6. PDPL Awareness: Include data privacy obligations under the Saudi PDPL as a mandatory training module — particularly for customer-facing staff handling personal and financial data.
Document all training records for at least three years and present them during SAMA examinations as evidence of a sustainable, risk-driven awareness culture.
Under SAMA CSF Control 3.3.1 and related subcontrols, Saudi banks and financial institutions are required to establish a formal, risk-based cybersecurity awareness and training program covering all employees, contractors, and privileged users. The program must be documented, regularly updated, and aligned with the institution's overall cybersecurity risk profile.
Key mandatory elements include:
Frequency & Coverage: Annual awareness training is the minimum baseline, but SAMA expects role-specific training for IT, security, and privileged users to occur more frequently — typically every six months. New joiners must complete onboarding security training before accessing critical systems.
Content Requirements: Training must cover phishing awareness, social engineering, acceptable use policies, data classification, and incident reporting procedures. For technical staff, content should extend to secure development practices and system hardening principles.
Phishing Simulations: SAMA CSF implicitly supports simulated phishing exercises as part of a mature awareness program. CISOs should run quarterly simulations and track click rates, reporting rates, and repeat offenders.
Metrics & Reporting: Completion rates, assessment scores, and phishing simulation results must be tracked and reported to the board or senior management periodically.
Building the Program: Start with a skills gap assessment, segment your audience by role and risk level, select a Learning Management System (LMS) that supports Arabic content, and integrate awareness campaigns with real-world threat intelligence (e.g., SAMA cybersecurity alerts or NCA advisories).
Cross-referencing with NCA ECC Article 2-6 further reinforces mandatory awareness requirements for government-related financial entities. ISO 27001 Annex A.7.2.2 also aligns with these obligations, making a unified program viable across multiple compliance frameworks.
Under SAMA CSF Control 3.3.1 and related sub-controls, Saudi financial institutions must establish a formal, risk-based cybersecurity awareness and training program covering all employees, contractors, and privileged users. Key requirements include:
Mandatory Elements:
- Annual cybersecurity awareness training for all staff, with documented completion records
- Role-specific training for IT, security, and privileged access users (at least semi-annually)
- Board and senior management briefings on cyber risk (aligned with SAMA CSF Governance Domain)
- Phishing simulation exercises to measure and reduce human risk
Building an Effective Program:
- Baseline Assessment: Conduct a staff awareness survey to identify knowledge gaps across departments
- Tiered Curriculum: Design separate tracks for general staff, IT/security teams, and executives — content must be relevant to job function
- Localization: Deliver content in Arabic and ensure cultural relevance for Saudi workforce segments
- Metrics & KPIs: Track phishing click rates, training completion rates, and incident reports attributed to human error
- Continuous Reinforcement: Supplement annual training with monthly micro-learning modules, security newsletters, and tabletop exercises
NCA ECC Alignment: NCA ECC Article 3-5 also requires organizations to maintain a documented security awareness program, making this a dual-compliance requirement for banks operating under both frameworks.
Practical Tip: Link awareness program outcomes to your SAMA CSF maturity assessment. Regulators expect evidence of a continuously improving program — not just a checkbox exercise. Maintain a training register and make it audit-ready at all times.
Privileged Access Management (PAM) is one of the highest-risk control domains for Saudi financial institutions and is explicitly addressed in both NCA ECC (Article 2-4: Access Management) and SAMA CSF (Control 3.3.6: Access Control). Misconfigured or unmonitored privileged accounts are among the leading causes of major breaches in the banking sector.
Key Regulatory Requirements:
- NCA ECC Art. 2-4: Mandates strict controls on privileged accounts including separation of duties, just-in-time access, and full session logging.
- SAMA CSF Control 3.3.6: Requires a formal access control policy with documented procedures for granting, reviewing, and revoking privileged access.
Practical Implementation Guidance:
- Privileged Account Discovery: Inventory all privileged accounts across on-premise, cloud, and third-party systems. Many institutions are surprised by the number of orphaned or shared admin accounts discovered.
- Implement a PAM Solution: Deploy a PAM platform (e.g., CyberArk, BeyondTrust, Delinea) to vault credentials, enforce just-in-time (JIT) access, and record all privileged sessions.
- Enforce Least Privilege: No user or service account should hold more privileges than required for their specific function. Review and right-size privileges at minimum semi-annually.
- Separate Privileged and Standard Accounts: Admins should use dedicated privileged accounts only for administrative tasks — never for email or browsing.
- Session Recording and Monitoring: All privileged sessions must be recorded and subject to real-time monitoring and anomaly detection, feeding into your SIEM.
- Periodic Access Reviews: Conduct quarterly access recertification reviews, with results documented for SAMA and NCA audit purposes.
Both SAMA and NCA examiners pay close attention to PAM maturity. A well-implemented PAM program is one of the most impactful investments a Saudi financial institution can make in its security posture.
Under SAMA CSF Control 3.3, Saudi banks must establish a comprehensive Identity and Access Management framework covering the full lifecycle of user identities. Key requirements include: Least Privilege Principle — access rights must be limited to what is strictly necessary per role (SAMA CSF 3.3.2). Privileged Access Management (PAM) — all privileged accounts (domain admins, DBAs, root accounts) must be inventoried, approved by management, and reviewed quarterly at minimum (SAMA CSF 3.3.5). Multi-Factor Authentication (MFA) — mandatory for all remote access, privileged accounts, and critical system access, aligning with NCA ECC-1:2-6.2.4. Access Reviews — formal recertification of user access rights must occur at least every six months, with immediate revocation upon role changes or termination. Separation of Duties — conflicting roles such as transaction initiator and approver must be segregated, especially critical in banking operations. Practically, banks should deploy a PAM solution (e.g., CyberArk, BeyondTrust) to vault privileged credentials, enforce session recording, and generate audit trails. All IAM activities must feed into the SIEM for anomaly detection. ISO 27001 Annex A.9 provides a complementary control framework that maps well to SAMA CSF 3.3 requirements. Non-compliance with IAM controls is consistently cited in SAMA examination findings, making this a high-priority area for CISOs.
SAMA CSF Control 3.7 mandates that Saudi banks maintain a formally documented, tested, and board-approved Cyber Incident Response Plan (CIRP). This is one of the most operationally critical compliance requirements, with direct regulatory reporting obligations.
Incident Response Plan Requirements (SAMA CSF 3.7.1–3.7.4):
- Define clear incident classification tiers (Critical, High, Medium, Low) based on business impact and data sensitivity
- Establish a dedicated Computer Security Incident Response Team (CSIRT) with defined roles, escalation paths, and 24/7 on-call coverage
- Integrate with SOC operations for real-time detection, triage, and containment
- Test the CIRP at least annually through tabletop exercises and simulate real attack scenarios (e.g., ransomware, data breach)
Regulatory Reporting Obligations:
- SAMA: Cybersecurity incidents that materially impact operations, customer data, or financial systems must be reported to SAMA within 72 hours of discovery. Post-incident reports are required within 30 days
- NCA (ECC-1: 6-2): Critical cybersecurity incidents must also be reported to the National Cybersecurity Authority (NCA) via the National Cyber Crisis Management Framework
- PDPL (Article 18): Personal data breaches must be reported to the Saudi Data & Artificial Intelligence Authority (SDAIA) within 72 hours, and affected individuals must be notified without undue delay if high-risk harm is likely
Practical Guidance:
- Develop incident classification playbooks for the top 5 threat scenarios relevant to your institution
- Pre-establish legal and communications protocols to manage breach disclosure to regulators, customers, and media
- Retain forensic evidence per chain-of-custody procedures to support regulatory investigations
- Conduct post-incident reviews (PIR) and feed lessons learned back into your risk register and control framework
- Align your CIRP with NIST CSF Respond and Recover functions for a globally recognized structure
Failure to report within mandated timelines can result in supervisory actions by SAMA, including formal citations and reputational consequences.
SAMA CSF Control Domain 3.3 (Third-Party Management) requires Saudi financial institutions to establish a comprehensive vendor risk management program covering the full supplier lifecycle — from onboarding to offboarding. Key requirements include:
Pre-Engagement: Conduct a risk classification of every vendor based on data access, system criticality, and service dependency. High-risk vendors (e.g., cloud providers, core banking system vendors) require full due diligence including ISO 27001 certification review, SOC 2 Type II reports, and on-site assessments where feasible.
Contractual Controls: Per SAMA CSF Control 3.3.3, contracts must include mandatory cybersecurity clauses covering data handling, incident notification timelines (typically within 72 hours), audit rights, and compliance with NCA ECC and PDPL obligations.
Ongoing Monitoring: Annual reassessment is the minimum for critical vendors. Monitoring should include continuous review of the vendor's threat landscape, patch management posture, and any regulatory sanctions.
Subcontractor Oversight: SAMA expects banks to apply equivalent scrutiny to fourth parties — vendors your vendors rely on — especially for cloud and managed service chains.
Practical Guidance: Build a vendor risk register categorized by tier (critical, high, medium, low). Use standardized questionnaires aligned to SAMA CSF and NCA ECC-2 controls. For fintech partnerships, ensure PDPL data processing agreements (DPAs) are executed before any data sharing begins. Document all assessments and maintain evidence for SAMA examination cycles.
SAMA CSF dedicates an entire control domain (Domain 4.5 – Third-Party Management) to vendor risk, requiring Saudi financial institutions to govern all outsourced services and technology providers through a structured lifecycle.
Key SAMA CSF Requirements:
- Control 4.5.1: Maintain a complete register of all third-party relationships, categorized by criticality and the data/systems they access.
- Control 4.5.2: Conduct formal due diligence and cybersecurity risk assessments before onboarding any vendor.
- Control 4.5.3: Ensure contracts include mandatory cybersecurity clauses covering data protection, incident notification (typically within 72 hours), audit rights, and compliance with applicable Saudi regulations including PDPL.
- Control 4.5.4: Perform periodic reassessments — annually at minimum for critical vendors, and upon any material change to the relationship.
Practical Implementation Steps:
- Tiering: Classify vendors into Critical, High, Medium, and Low tiers based on data sensitivity, system access, and operational dependency.
- Questionnaires: Use standardized cybersecurity questionnaires aligned to ISO 27001 Annex A or NIST CSF to evaluate vendor security posture.
- Contract Controls: Embed right-to-audit clauses, minimum security baseline requirements, and PDPL data processing agreements (DPAs).
- Continuous Monitoring: Leverage threat intelligence feeds and external attack surface monitoring tools to assess vendor risk between formal reviews.
- Exit Planning: Define offboarding procedures to ensure secure data return or deletion per PDPL obligations.
NCA ECC Article 2-14 further reinforces these obligations for organizations within the national cybersecurity scope. Non-compliance with SAMA's third-party requirements can result in regulatory findings during the annual SAMA CSF assessment cycle.
Under SAMA CSF Domain 3 (Cybersecurity Risk Management) and specifically Control 3.3, Saudi banks must establish a formal Third-Party Risk Management (TPRM) program that governs all vendor relationships with access to critical systems or sensitive data.
Key requirements include:
- Pre-onboarding due diligence: Conduct cybersecurity risk assessments before engaging any vendor. Evaluate their ISO 27001 certification status, data handling practices, and incident history.
- Contractual obligations: Embed cybersecurity clauses in all vendor contracts covering data protection (aligned with PDPL Article 29 on data processor obligations), right-to-audit, breach notification timelines (within 72 hours), and compliance with NCA ECC controls.
- Risk tiering: Classify vendors as Critical, High, Medium, or Low risk based on data sensitivity and system access. Critical vendors — such as core banking providers or cloud platforms — require annual on-site or remote audits.
- Continuous monitoring: Use automated vendor risk platforms or periodic questionnaires (at least annually for high-risk vendors) to track changes in their security posture. Review SOC 2 Type II or equivalent reports.
- Offboarding procedures: Ensure data deletion, access revocation, and credential decommissioning upon contract termination.
SAMA examiners specifically look for evidence of a documented TPRM policy, a vendor inventory register, completed risk assessments, and contractual cybersecurity annexes. Financial institutions that rely on cloud services must additionally comply with NCA Cloud Cybersecurity Controls (CCC) to ensure vendor environments meet residency and security benchmarks.
Security awareness training is a foundational requirement under SAMA CSF Domain 2 (Cybersecurity Leadership & Governance), specifically Control 2.4, which mandates that all financial institutions establish and maintain a cybersecurity awareness and training program tailored to employee roles.
Mandatory requirements:
- Frequency: All employees must complete cybersecurity awareness training at least annually. Employees with privileged access or critical roles (IT, finance, executive) require additional role-based training.
- Onboarding: New hires must complete foundational security training within their first 30 days.
- Phishing simulations: SAMA examiners expect evidence of phishing simulation campaigns conducted at least twice a year, with click-rate tracking and remedial training for employees who fail.
- Awareness metrics: Maintain records of training completion rates, test scores, and phishing simulation results. SAMA may request these during examinations.
Recommended program structure:
- Tier 1 – All Staff: Annual e-learning covering phishing, social engineering, password hygiene, data classification, and incident reporting procedures.
- Tier 2 – Technical & IT Staff: Advanced training on secure coding (if applicable), network security, vulnerability management, and access control best practices.
- Tier 3 – Executives & Board: Cybersecurity risk briefings focused on governance, regulatory liability, and crisis decision-making.
NCA alignment: NCA ECC Article 2-5 also requires organizations to ensure all users understand their cybersecurity responsibilities, reinforcing SAMA's training obligations.
Practical tips: Use Arabic-language training modules relevant to Saudi regulatory context, gamify assessments to improve engagement, and integrate training with your GRC platform to automate tracking and reporting.
Third-party risk management (TPRM) is a critical compliance obligation under SAMA CSF Domain 4 (Third Party Cybersecurity). Banks and fintechs must implement a structured lifecycle for managing vendor cyber risk across onboarding, ongoing monitoring, and offboarding.
Key requirements include:
- Risk Classification (SAMA CSF 4.1): Categorize all vendors by criticality — critical, high, medium, or low — based on data access, system integration depth, and service criticality to core banking operations.
- Due Diligence Before Onboarding: Require vendors to submit cybersecurity assessments, ISO 27001 certificates, or equivalent evidence before contract execution. For critical vendors, conduct independent security reviews.
- Contractual Controls (SAMA CSF 4.2): Embed mandatory cybersecurity clauses covering incident notification timelines (typically within 24–72 hours), right-to-audit provisions, data handling obligations aligned with PDPL, and minimum security baseline standards.
- Continuous Monitoring: Perform annual reassessments for critical vendors and biennial reviews for others. Use questionnaires, audit reports (e.g., SOC 2 Type II), or on-site assessments.
- Concentration Risk: Identify and document scenarios where multiple critical services depend on a single vendor to assess systemic exposure.
- Offboarding Controls: Ensure data deletion, credential revocation, and access termination are formally documented upon contract end.
NCA ECC Article 2-7 also requires organizations to assess cybersecurity controls of entities with access to national infrastructure. Institutions using cloud services must additionally apply SAMA's Cloud Computing Framework and NCA's Cloud Cybersecurity Controls (CCC-1).
Building a vendor risk register with automated review triggers is the most practical starting point for institutions scaling their TPRM programs.
Under SAMA CSF Domain 3.3 (Third-Party Management), Saudi banks and financial institutions are required to establish a formal, risk-based vendor management program. Here is what compliance looks like in practice:
Pre-Onboarding Assessment: Before engaging any third party, conduct a cybersecurity due diligence review. This includes reviewing vendor SOC 2 Type II reports, ISO 27001 certifications, and completing a standardized security questionnaire aligned with SAMA CSF controls. Classify vendors by criticality — Tier 1 (critical/core banking systems), Tier 2 (significant), and Tier 3 (low risk).
Contractual Requirements (SAMA CSF 3.3.2): All contracts must include mandatory cybersecurity clauses: right-to-audit provisions, incident notification obligations (typically within 72 hours), data handling and retention requirements aligned with PDPL, and minimum security standards the vendor must maintain.
Ongoing Monitoring: SAMA expects continuous oversight, not just point-in-time assessments. Implement annual reassessments for Tier 1 vendors, biannual for Tier 2. Monitor vendor security posture using threat intelligence feeds or external attack surface tools.
Concentration Risk: SAMA CSF also requires institutions to identify and manage concentration risk — if multiple critical functions depend on a single vendor, document this risk and establish contingency plans.
NCA ECC Alignment: NCA ECC Article 2-12 reinforces supply chain security controls, particularly for cloud and outsourced services. Ensure vendor agreements reference NCA ECC compliance obligations where applicable.
Practical Tip: Maintain a centralized vendor risk register updated quarterly, and report critical third-party risks to the board-level risk committee at least annually as required under SAMA governance expectations.
Third-party risk management is a critical compliance obligation for Saudi financial institutions. Under SAMA CSF Control 3.3, banks must establish a formal TPRM program covering vendor onboarding, continuous monitoring, and offboarding. NCA ECC Article 2-7 further mandates that outsourced services do not compromise organizational cybersecurity posture.
Key implementation steps include:
- Vendor Classification: Categorize vendors by risk tier (critical, high, medium, low) based on data access, system integration depth, and service criticality.
- Due Diligence: Conduct pre-contract cybersecurity assessments including questionnaires, evidence review, and on-site audits for Tier-1 vendors. Verify ISO 27001 certifications or equivalent controls.
- Contractual Controls: Embed cybersecurity clauses covering data handling, breach notification timelines (aligned with PDPL's 72-hour reporting requirement), audit rights, and right-to-terminate provisions.
- Continuous Monitoring: Implement ongoing assessments at least annually for critical vendors, with real-time monitoring for vendors with direct system access.
- Concentration Risk: SAMA expects banks to identify and mitigate over-reliance on single vendors, particularly in cloud and core banking services.
- Incident Coordination: Define escalation paths for vendor-originated security incidents and ensure vendors participate in your incident response exercises.
A mature TPRM program should integrate with your GRC platform to automate vendor scoring, track assessment cycles, and generate audit-ready reports for SAMA examinations. Financial institutions that outsource to cloud providers must additionally comply with SAMA's Cloud Computing Framework, ensuring data residency within the Kingdom where required.
Saudi banks must establish a robust Third-Party Risk Management (TPRM) program aligned with SAMA CSF Domain 3.3 (Third-Party Management) and NCA ECC-1:2-6.3. Here's a practical implementation roadmap:
1. Vendor Classification & Risk Tiering Categorize all vendors based on data access, criticality, and service type. Critical vendors (e.g., core banking providers, cloud platforms) must undergo full due diligence including on-site assessments.
2. Pre-Onboarding Security Assessment Before contracting, evaluate vendors against a standardized questionnaire covering ISO 27001 controls, data handling practices, and incident response capabilities. Per SAMA CSF Control 3.3.2, contractual obligations must include cybersecurity requirements, audit rights, and breach notification clauses (within 72 hours aligned with PDPL Article 19).
3. Continuous Monitoring Implement ongoing monitoring mechanisms including periodic security reassessments (annually for high-risk vendors), review of SOC 2 Type II or ISO 27001 certification validity, and threat intelligence feeds for vendor-related breaches.
4. Concentration Risk Management NCA ECC requires identifying and managing concentration risks where multiple critical services depend on a single vendor. Maintain documented fallback or exit strategies.
5. Fourth-Party Risk Awareness Extend risk visibility to sub-processors and key subcontractors your critical vendors rely upon.
6. SAMA Reporting Material third-party incidents or changes must be reported to SAMA through the established supervisory channels. Maintain a live vendor register accessible during regulatory examinations.
A well-structured TPRM program not only satisfies regulatory obligations but significantly reduces supply-chain attack exposure — a growing threat vector in the Saudi financial sector.
Identity and Access Management (IAM) sits at the core of cybersecurity compliance for Saudi financial institutions. Both SAMA CSF and NCA ECC establish detailed, mandatory controls governing how organizations manage user identities, privileges, and authentication.
Regulatory Requirements:
- SAMA CSF Control 3.3.3 requires formal access control policies, least-privilege enforcement, privileged access management (PAM), and periodic access reviews.
- NCA ECC Control 2-5 mandates strong authentication, role-based access control (RBAC), and monitoring of privileged accounts.
- SAMA CSF Control 3.3.7 specifically addresses privileged access, requiring multi-factor authentication (MFA) for all privileged users and administrators.
Practical Implementation Roadmap:
- Access Governance Foundation: Establish a formal Joiner-Mover-Leaver (JML) process ensuring accounts are provisioned, modified, and deprovisioned in a timely and auditable manner. Orphaned accounts represent one of the most common SAMA audit findings.
- Least Privilege & RBAC: Map all job roles to defined access rights. Eliminate shared accounts and generic admin credentials — common in legacy banking environments.
- Privileged Access Management (PAM): Deploy a PAM solution for all privileged accounts (domain admins, database admins, system owners). Session recording, just-in-time access, and password vaulting are considered baseline requirements.
- Multi-Factor Authentication: Enforce MFA across all remote access, privileged sessions, and internet-facing applications. SAMA and NCA both treat MFA as non-negotiable for financial institutions.
- Access Reviews: Conduct quarterly access certification campaigns for privileged users and semi-annual reviews for general users. Document all review outcomes as audit evidence.
- ISO 27001 Alignment: IAM controls map to ISO 27001:2022 Annex A Controls 5.15–5.18, making a unified implementation efficient across multiple frameworks.
A GRC platform can automate access review workflows, track exceptions and remediation, and generate cross-framework compliance evidence linking SAMA, NCA, and ISO 27001 controls in a single audit-ready report.
Under SAMA CSF Control Domain 3.3 (Human Resources Security), Saudi banks are required to implement a formal, role-based cybersecurity awareness and training program covering all staff — from executives to frontline employees. The program must be documented, periodically reviewed, and aligned with identified risks.
A compliant program should include:
1. Mandatory Onboarding Training: Every new hire must complete cybersecurity awareness training before or shortly after gaining system access, covering topics such as phishing, social engineering, password hygiene, and acceptable use policies.
2. Role-Based Modules: Privileged users, IT administrators, developers, and senior management must receive tailored content beyond general awareness — including secure coding (for developers), insider threat recognition (for managers), and access control responsibilities (for system admins).
3. Annual Refresher Cycles: SAMA CSF requires at minimum annual re-training, but best practice — especially given NCA ECC alignment — recommends quarterly micro-learning sessions supplemented by simulated phishing campaigns.
4. Phishing Simulation & Metrics: Run controlled phishing simulations at least twice a year and track click rates, reporting rates, and repeat offenders. Use these metrics to demonstrate program effectiveness to auditors.
5. Executive & Board Awareness: Senior leadership must receive briefings on cyber risk governance, their responsibilities under SAMA CSF, and emerging threat landscapes — ideally quarterly.
6. Documented Evidence: Maintain training completion records, assessment scores, and simulation results. These are reviewed during SAMA regulatory examinations and third-party audits.
Our platform automates training assignments, tracks completions, generates audit-ready reports, and integrates phishing simulation results — ensuring your institution remains continuously compliant with SAMA CSF human resource security requirements.
SAMA CSF Control Domain 3.5 (Third-Party Management) establishes clear obligations for Saudi financial institutions when engaging vendors, outsourced service providers, fintech partners, and cloud providers. Failure to manage third-party cyber risks adequately is one of the most cited findings in SAMA regulatory examinations.
Core SAMA CSF Third-Party Requirements:
1. Pre-Engagement Security Assessment: Before onboarding any vendor with access to systems, networks, or data, conduct a formal cybersecurity risk assessment. This should evaluate the vendor's ISO 27001 certification status, penetration testing history, SOC 2 reports, and adherence to NCA ECC controls if they are a Saudi entity.
2. Security Clauses in Contracts: All vendor contracts must include mandatory cybersecurity provisions covering: data handling obligations (aligned with PDPL Article 21 for cross-border transfers), breach notification timelines, right-to-audit clauses, and compliance with applicable Saudi regulations.
3. Ongoing Monitoring & Periodic Re-Assessment: Third-party risk management is not a one-time exercise. SAMA CSF requires periodic reassessment — annually at minimum for critical vendors — reviewing changes in their security posture, certifications, and incident history.
4. Concentration Risk Management: Evaluate dependencies on single vendors providing critical services (e.g., core banking platforms, cloud infrastructure). SAMA examiners assess whether institutions have contingency plans if a critical vendor suffers a major cyber incident.
5. Outsourcing-Specific Controls: For outsourced processes involving customer data or critical functions, SAMA CSF 3.5 requires additional controls including dedicated SLAs for security incidents, segregation of duties, and monitoring of vendor privileged access.
6. Vendor Register Maintenance: Maintain a continuously updated inventory of all third parties, categorized by risk tier (Critical, High, Medium, Low), with documented assessment outcomes and remediation tracking.
Practical Tip: Integrate your vendor risk program with your broader GRC platform so that third-party assessments, contract status, and risk ratings are centrally visible and audit-ready.
Our platform provides a structured vendor risk management module aligned to SAMA CSF 3.5, with automated questionnaires, risk scoring, and escalation workflows.
Saudi banks must establish a formal Third-Party Risk Management (TPRM) program aligned with SAMA CSF Domain 3.3 (Third-Party Management) and NCA ECC-2: 1-5. A mature TPRM program should include the following pillars:
1. Vendor Classification & Risk Tiering: Categorize all third parties based on data sensitivity, system access levels, and business criticality. SAMA CSF requires risk-based due diligence proportional to the vendor's exposure.
2. Pre-Onboarding Assessment: Before contracting, conduct cybersecurity assessments covering ISO 27001 controls, data handling practices, and regulatory compliance posture. Verify whether the vendor holds certifications recognized under NCA guidelines.
3. Contractual Security Obligations: All vendor contracts must embed security clauses covering incident notification timelines (within 72 hours per SAMA expectations), right-to-audit clauses, and data residency requirements aligned with PDPL Article 29 on cross-border data transfers.
4. Continuous Monitoring: Implement ongoing monitoring using automated tools (e.g., SecurityScorecard, BitSight) to track vendor security posture. Periodic reassessments — at least annually for critical vendors — are required under SAMA CSF Control 3.3.5.
5. Offboarding Controls: Ensure data deletion, access revocation, and formal offboarding procedures are enforced when vendor relationships end.
6. Concentration Risk Awareness: SAMA has increasingly scrutinized over-reliance on single vendors, particularly in cloud and payment processing. Document and report concentration risks to the board.
Our platform provides a structured TPRM workflow with pre-built assessment templates mapped to SAMA CSF, NCA ECC, and ISO 27001, enabling compliance officers to track vendor risk posture from onboarding through contract termination in a single dashboard.
Third-party risk management (TPRM) is a critical compliance obligation for Saudi banks under SAMA CSF Domain 4 (Third Party Management) and NCA ECC-1:2018 Article 3.3. A robust TPRM program must include the following layers:
1. Vendor Classification & Due Diligence: Categorize vendors by criticality (critical, high, medium, low) based on data access, system integration, and service dependency. Per SAMA CSF Control 4.2, due diligence must occur before contract signing and include cybersecurity posture assessments.
2. Contractual Obligations: Ensure all vendor contracts include cybersecurity clauses covering: data handling standards aligned with PDPL, the right to audit, incident notification SLAs (typically 72 hours or less), and minimum security baselines per NCA ECC.
3. Continuous Monitoring: SAMA CSF requires ongoing monitoring of critical vendors, not just point-in-time assessments. Use automated risk rating platforms and schedule annual reviews for critical vendors and biennial reviews for others.
4. Subcontractor Oversight: Extend your TPRM scope to include fourth-party risk — vendors your suppliers rely on — especially for cloud and IT service providers.
5. Exit Strategy: Maintain documented exit plans for critical vendor relationships, including data recovery procedures and transition timelines, to ensure operational resilience per SAMA BCM guidelines.
Practically, banks should establish a dedicated Third-Party Risk Committee, maintain a live vendor inventory, and integrate TPRM findings into the overall risk register presented to the board annually. Non-compliance with SAMA TPRM requirements can trigger regulatory findings during SAMA's cybersecurity examinations.
SAMA CSF uses five maturity levels: Level 1 (Initial/Ad-hoc) — informal controls; Level 2 (Developing) — repeatable but not documented; Level 3 (Defined) — documented and standardized; Level 4 (Managed) — measured and controlled; Level 5 (Optimizing) — continuous improvement. Financial institutions are expected to achieve at least Level 3 for most controls.
SAMA requires regulated entities to conduct an annual self-assessment against the Cybersecurity Framework. Results must be submitted to SAMA and used to drive remediation plans. SAMA may also conduct on-site inspections or request third-party audit reports.
SAMA can impose regulatory penalties including fines, supervisory warnings, mandatory remediation timelines, restrictions on business activities, or in severe cases, suspension of licenses. Exact penalties depend on the nature and severity of the non-compliance and SAMA's assessment discretion.
Under SAMA CSF Domain 3 (Cybersecurity Risk Management), specifically controls 3.3.1 through 3.3.5, Saudi banks and financial institutions must implement a structured Third-Party Risk Management (TPRM) program. This involves four critical phases:
1. Pre-Onboarding Due Diligence: Before engaging any vendor, conduct a cybersecurity risk assessment covering the vendor's security posture, data handling practices, and compliance certifications (e.g., ISO 27001, SOC 2). Classify vendors by risk tier — critical, high, medium, or low — based on data access and system integration levels.
2. Contractual Security Requirements: Embed security obligations into vendor contracts, including the right to audit, mandatory breach notification timelines (aligned with PDPL's 72-hour reporting requirement), data residency clauses for Saudi-hosted data, and compliance with NCA ECC controls where applicable.
3. Ongoing Monitoring: Conduct annual security assessments for critical vendors and biannual reviews for high-risk suppliers. Use continuous monitoring tools to track vendor security ratings and any publicly disclosed breaches.
4. Offboarding Controls: Ensure secure data deletion, access revocation, and documentation upon contract termination.
SAMA expects board-level oversight of TPRM programs, with the CISO responsible for maintaining a vendor risk register. Non-compliance may trigger regulatory findings during SAMA's annual supervisory review cycle. Platforms like CISO Consulting can help automate vendor assessments, map findings to SAMA CSF controls, and generate audit-ready reports for regulators.
Third-party risk management is a critical obligation under SAMA CSF Domain 3.3, which requires regulated entities to establish a formal vendor risk management program before onboarding any third party with access to sensitive systems or data. Practically, this means conducting a cybersecurity due diligence assessment for every vendor — covering their security controls, certifications (e.g., ISO 27001), incident response capabilities, and data handling practices. Per SAMA CSF Control 3.3.2, contracts with critical vendors must include mandatory cybersecurity clauses covering data protection, audit rights, breach notification timelines (typically within 72 hours), and the right to conduct or commission security assessments. Financial institutions should classify vendors by criticality — Tier 1 vendors (those with direct access to core banking systems) require the most rigorous scrutiny, including on-site assessments and continuous monitoring. Tier 2 and Tier 3 vendors may be managed through standardized questionnaires and periodic reviews. Additionally, PDPL intersects here: if vendors process personal data of Saudi residents, a Data Processing Agreement (DPA) must be in place, and the institution remains accountable as the data controller. Recommended actions include maintaining a live vendor inventory, performing annual reassessments for critical vendors, and establishing exit strategies to manage vendor offboarding securely. Our platform automates vendor risk scoring, tracks assessment cycles, and generates SAMA-ready reports to streamline this process.
Under SAMA CSF Control Domain 3.3 (Third-Party Cybersecurity), Saudi banks and financial institutions must establish a structured, risk-based vendor management program that goes well beyond standard procurement due diligence. At a minimum, your program should include: 1) Pre-onboarding assessment: Evaluate all third parties handling sensitive data or critical systems using standardized security questionnaires aligned to SAMA CSF controls. Classify vendors by inherent risk (critical, high, medium, low). 2) Contractual obligations: Ensure all vendor contracts include cybersecurity clauses covering data protection per PDPL requirements, incident notification timelines (72-hour breach reporting is a benchmark), right-to-audit clauses, and minimum security baseline expectations. 3) Continuous monitoring: Critical vendors (e.g., core banking providers, cloud platforms) should undergo annual on-site or remote security assessments. Use automated tools to monitor for vendor data breaches, dark web exposure, and certificate issues. 4) Concentration risk: SAMA expects boards to understand and manage concentration risk — if multiple critical functions rely on a single third party, a formal risk acceptance or mitigation plan is required. 5) Offboarding controls: Define procedures for data return, destruction, and access revocation when a vendor relationship ends. Practically, most Saudi banks find the greatest gaps in ongoing monitoring and contractual coverage. Start by inventorying all third parties, classifying them by risk, and ensuring your highest-risk vendors are assessed at least annually. Document everything — SAMA assessors look closely at evidence of active program management, not just policy documents.
Third-party risk management (TPRM) is a critical obligation for Saudi financial institutions. Under SAMA CSF Control 3.3, regulated entities must establish a formal vendor risk management program that includes pre-onboarding security assessments, contractual security obligations, and ongoing monitoring throughout the vendor lifecycle.
Practically, your TPRM program should include:
1. Vendor Tiering: Classify vendors by criticality — Tier 1 (critical/core banking), Tier 2 (significant), Tier 3 (low impact) — and apply proportionate controls.
2. Pre-Onboarding Due Diligence: Require vendors to demonstrate compliance with ISO 27001 or equivalent. For Tier 1 vendors, conduct on-site security assessments or review independent audit reports (SOC 2 Type II).
3. Contractual Requirements: Embed security clauses covering data handling, breach notification (within 72 hours per PDPL Article 19), right-to-audit, and minimum security standards aligned with NCA ECC controls.
4. Continuous Monitoring: Use automated attack surface monitoring tools to track vendor exposure. NCA ECC Domain 2 (Asset Management) implicitly requires visibility into third-party connected systems.
5. Offboarding Procedures: Ensure secure data deletion and access revocation upon contract termination.
Financial institutions that outsource critical operations to cloud or fintech providers must also comply with SAMA's Outsourcing Rules, which require SAMA notification for material outsourcing arrangements. Failure to manage third-party risk adequately is a common finding in SAMA supervisory reviews and can directly impact your CSF maturity score.
Saudi financial institutions face overlapping incident response obligations from multiple regulators. Understanding each layer is essential to avoid both operational and legal exposure.
SAMA CSF Requirements (Control 3.3.5 – Cybersecurity Incident Management):
- Institutions must maintain a documented Cybersecurity Incident Response Plan (CIRP) reviewed at least annually.
- Security incidents must be classified using a defined severity matrix (Critical, High, Medium, Low).
- Critical incidents must be reported to SAMA within timeframes specified in the SAMA Cyber Incident Reporting Framework — typically within 4 hours of detection for major incidents.
- Post-incident reviews (PIRs) are mandatory and must be documented with root cause analysis and corrective actions.
NCA ECC Requirements (Control 2-7 – Cybersecurity Incident Management):
- NCA requires entities to maintain a 24/7 security operations capability or a contracted SOC.
- Incidents must be reported to the National Cybersecurity Authority through official channels when they involve national infrastructure or sensitive data.
PDPL Requirements (Article 19):
- If a breach involves personal data, organizations must notify the Saudi Data & AI Authority (SDAIA) within 72 hours of becoming aware of the incident.
- Affected data subjects must also be notified if the breach poses a high risk to their rights or interests.
Practical Readiness Checklist: ✅ Documented CIRP with defined roles and escalation paths ✅ Incident classification and prioritization matrix ✅ Regulatory notification templates pre-drafted for SAMA, NCA, and SDAIA ✅ Tabletop exercises conducted at least twice per year ✅ Forensic investigation capability (internal or retained)
Building this capability in-house is resource-intensive. Many Saudi fintechs and mid-sized banks engage a vCISO service to design and maintain the CIRP while providing on-call incident support.
SAMA CSF Control 3.3 mandates that regulated entities establish a formal Third-Party Risk Management (TPRM) framework covering the full vendor lifecycle — from onboarding to offboarding. Practically, your program should include four pillars:
- Pre-Engagement Due Diligence: Before contracting any vendor, conduct a cybersecurity risk classification (critical, high, medium, low) based on data access, system integration depth, and service criticality. Per SAMA CSF Control 3.3.1, vendors with access to sensitive financial or customer data must undergo rigorous security assessments.
- Contractual Security Requirements: All vendor contracts must include enforceable cybersecurity clauses — right-to-audit provisions, incident notification timelines (typically 72 hours per PDPL Article 24 alignment), data handling standards, and compliance attestation obligations.
- Continuous Monitoring: SAMA expects ongoing monitoring, not just point-in-time assessments. Implement quarterly security questionnaires for critical vendors, annual on-site audits, and automated monitoring of vendors' public threat intelligence posture.
- Exit and Transition Planning: Document data return/destruction procedures and access revocation protocols for vendor offboarding, aligned with ISO 27001 Annex A.15.2.
Many Saudi banks fail SAMA assessments specifically on TPRM because they treat it as a procurement checkbox rather than a continuous risk process. Your GRC platform should map each vendor to relevant SAMA controls, assign risk owners, and track remediation timelines. A minimum viable TPRM program for a mid-sized bank typically covers 50–200 active vendors segmented by risk tier.
Business Continuity Management (BCM) is one of the most rigorously assessed domains in SAMA CSF audits. Under SAMA CSF Domain 4 (Operational Resilience) and specifically Control 4.2 (Business Continuity & Disaster Recovery), Saudi financial institutions must establish, implement, and regularly test a comprehensive BCM program.
Core BCM Components Required by SAMA CSF:
1. Business Impact Analysis (BIA): Conduct a formal BIA to identify critical business functions, their Maximum Tolerable Downtime (MTD), Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO). For banking systems, RTOs are often set at 4 hours or less for tier-1 systems.
2. BCP & DRP Documentation: Maintain documented Business Continuity Plans and Disaster Recovery Plans that are reviewed and updated at least annually, or after significant organizational changes.
3. Testing Frequency: SAMA requires a minimum of one full DR test annually, complemented by tabletop exercises for key scenarios (ransomware, data center failure, cyber incidents). Results must be formally documented.
4. Backup & Recovery Controls: Per SAMA CSF Control 3.3.8, backups must be encrypted, stored offsite or in a secondary data center, and tested regularly to confirm restorability. Backup integrity checks should occur at minimum quarterly.
5. Communication Plans: Define escalation matrices, stakeholder notification procedures, and regulatory reporting timelines — including SAMA notification requirements for major disruptions.
6. Alignment with NCA ECC: NCA ECC Article 2-12 (Resilience) adds complementary requirements around cyber resilience that should be integrated into your BCM framework to avoid duplication of effort.
Organizations should nominate a BCM Owner at the senior management level and ensure BCM is integrated into the enterprise risk management framework rather than treated as a standalone exercise.
Business continuity and cyber resilience are among the most scrutinized domains during SAMA examinations. SAMA CSF dedicates a full control domain (Domain 3.6 – Cyber Resilience) to ensuring financial institutions can withstand, recover from, and adapt to cyber incidents.
SAMA CSF Core Requirements:
- Business Impact Analysis (BIA): Institutions must conduct a formal BIA identifying critical business processes, their dependencies, and acceptable recovery timeframes (RTO/RPO).
- Cyber Resilience Plans: A documented Cyber Resilience Plan must exist, covering incident containment, recovery procedures, and communication protocols — integrated with the overall Business Continuity Plan (BCP).
- Testing & Exercising: SAMA requires annual testing of BCP/DRP, including tabletop exercises and simulated cyber incident scenarios. Results must be reviewed by senior management.
- Recovery Time Objectives: Critical banking services (e.g., core banking, payment systems) must have RTOs defined per SAMA's operational resilience expectations — typically under 4 hours for tier-1 services.
- Supply Chain Resilience: Continuity planning must account for critical third-party dependencies.
Alignment with ISO 22301: ISO 22301 (Business Continuity Management Systems) complements SAMA CSF well. Key overlaps include BIA methodology, documented BCMS policies, competency requirements, and continual improvement cycles. Achieving ISO 22301 certification demonstrates maturity and can streamline SAMA examinations.
Practical Guidance:
- Map SAMA CSF 3.6 controls directly to ISO 22301 clauses to identify gaps.
- Integrate cyber incident scenarios (ransomware, DDoS, data breach) into your annual BCP testing.
- Ensure your crisis communication plan covers SAMA notification obligations (within 72 hours for major incidents).
- Review and update plans after every major incident or significant infrastructure change.
Business Continuity Management (BCM) is a critical compliance domain under the SAMA Cyber Security Framework. SAMA CSF Control Domain 3.5 (Resilience) requires member organizations to establish, implement, test, and continuously improve BCM programs that address both cybersecurity incidents and broader operational disruptions.
A SAMA-compliant BCM program should be structured around the following pillars:
1. Business Impact Analysis (BIA) Identify critical business functions, their dependencies, and determine Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). SAMA expects that RTO/RPO targets for critical banking services align with the institution's risk appetite and customer commitments.
2. Business Continuity Plan (BCP) & Disaster Recovery Plan (DRP) Document step-by-step response procedures for various disruption scenarios — cyberattacks, system failures, facility unavailability. Ensure your DRP specifically covers IT system failover, data backup restoration, and alternate processing sites.
3. Crisis Communication Define internal escalation paths and external communication protocols, including notification to SAMA within required timeframes during significant incidents (per SAMA's Cyber Incident Reporting guidelines).
4. Testing & Exercising SAMA requires documented evidence of BCM tests — tabletop exercises, simulation drills, and full failover tests — at least annually. Gaps identified must feed into a formal improvement plan.
5. Third-Party Dependencies Ensure critical vendors and cloud service providers have their own BCM capabilities validated as part of your vendor risk management process.
Integrating your BCM program with ISO 22301 best practices will strengthen your SAMA maturity score and demonstrate a structured, internationally aligned approach during regulatory examinations.
Business Continuity Management (BCM) is a mandatory regulatory obligation for Saudi financial institutions, governed primarily by SAMA CSF Domain 5 (Resilience) and NCA ECC Control 3-7. Institutions must establish a comprehensive BCM program that integrates cybersecurity resilience with broader operational continuity.
Regulatory Baseline: SAMA CSF Control 5.1 requires institutions to develop, maintain, and regularly test Business Continuity Plans (BCPs) and Disaster Recovery Plans (DRPs). Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) must be formally defined and aligned with the criticality of each system.
Key Implementation Steps:
- Business Impact Analysis (BIA): Identify critical business processes, supporting IT assets, and maximum tolerable downtime. For core banking systems, RTOs are typically set at 4 hours or less.
- Cyber-Specific Scenarios: BCM plans must explicitly address ransomware attacks, DDoS incidents, and data center outages—not just natural disasters or hardware failures.
- Testing Cadence: SAMA CSF requires BCM tests at least annually. Tests should include tabletop exercises, simulation drills, and full failover tests for critical systems. NCA ECC reinforces this under its resilience controls.
- Third-Party Dependencies: BCP documentation must address the continuity posture of critical suppliers and cloud providers, including contractual SLA obligations.
- Board Reporting: BCM program status, test results, and identified gaps must be reported to senior management and the Board Risk Committee at least annually.
Documentation, test evidence, and gap remediation records should be maintained within your GRC platform to demonstrate regulatory compliance during SAMA examinations.
Business Continuity Management (BCM) is a regulatory imperative for Saudi financial institutions. SAMA CSF Domain 4 (Resilience) dedicates an entire section to BCM requirements, mandating that all member organizations maintain a documented, tested, and Board-approved BCM program. Alignment with ISO 22301 is strongly recommended and increasingly treated by SAMA examiners as the gold standard for BCM governance.
Here is a structured implementation roadmap:
1. Business Impact Analysis (BIA) Identify critical business functions, acceptable Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO). SAMA CSF Control 4.2.1 requires that RTOs and RPOs be formally documented and approved by senior management.
2. Risk Assessment Integration BCM must be tightly linked to your organization's cybersecurity and enterprise risk framework. Cyber incidents, ransomware, and DDoS attacks must be explicitly modeled as threat scenarios in your Business Continuity Plan (BCP).
3. Develop Response Plans Create and maintain a BCP, Disaster Recovery Plan (DRP), and Crisis Communication Plan. Ensure these plans cover core banking systems, payment processing (SARIE/AFAQ connectivity), and customer-facing digital channels.
4. Testing and Exercises SAMA CSF Control 4.2.5 requires at least annual BCP tests, including tabletop exercises and full simulation drills. Test results and gaps must be documented and reported to the Board Risk Committee.
5. Third-Party Continuity Ensure that critical service providers also maintain BCM programs aligned with your own RTOs. This is a common gap flagged during SAMA examinations.
6. Continuous Improvement Post-incident reviews and annual BCM audits (preferably by an independent party) are required to maintain ISO 22301 certification and SAMA compliance.
Business continuity and cyber resilience are among the most scrutinized areas during SAMA supervisory examinations. SAMA CSF Control Domain 3.4 (Cyber Resilience) requires financial institutions to develop, maintain, and regularly test Business Continuity Plans (BCPs) and Cyber Incident Recovery Plans that specifically address cybersecurity scenarios — not just traditional IT disaster recovery.
Key Requirements:
1. Recovery Objectives: SAMA expects documented Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for all critical systems, typically ranging from 4–24 hours for core banking depending on system criticality. These must be validated — not just estimated.
2. Scenario-Based Testing: Annual BCP tests must include cyber-specific scenarios such as ransomware attacks, DDoS against core banking infrastructure, and third-party service provider outages. Tabletop exercises involving the CISO, CRO, and Executive Management are mandatory per SAMA guidance.
3. Crisis Communication: SAMA CSF requires pre-approved communication templates and escalation matrices for cybersecurity incidents, including timely notification to SAMA within defined windows (typically within 72 hours of a significant incident).
4. Integration with NCA ECC: NCA ECC Control 2-14 mandates that organizations maintain operational resilience capabilities. SAMA-regulated entities should ensure their BCPs are cross-referenced and consistent with NCA requirements to avoid duplication of gaps.
5. Documentation & Evidence: Maintain test records, lessons-learned reports, and remediation logs in your GRC platform. SAMA examiners will request these during regulatory visits.
Weak BCP posture is a leading cause of downgraded SAMA CSF maturity scores. Treat resilience testing as a continuous program, not an annual checkbox.
Business Continuity Management (BCM) is a critical compliance area governed by multiple Saudi regulatory frameworks. Here is how financial institutions should structure their BCM program: SAMA CSF Requirements (Control 3.3.9): SAMA mandates a formalized BCM program that includes Business Impact Analysis (BIA), Recovery Time Objectives (RTO), Recovery Point Objectives (RPO), and tested Disaster Recovery Plans (DRP). RTOs for critical banking services such as core banking, payment systems, and internet banking are typically expected to be under 4 hours, with RPOs of no more than 1 hour. NCA ECC Alignment (Article 2-18): NCA ECC reinforces BCM requirements by mandating resilience controls for critical national infrastructure entities, including financial institutions. This includes documented continuity plans reviewed and tested at least annually. Key Implementation Steps: (1) Conduct a comprehensive BIA to identify critical processes and dependencies; (2) Define RTOs and RPOs per system criticality tier; (3) Establish alternate processing sites or cloud-based failover environments; (4) Develop and maintain a Crisis Communication Plan; (5) Conduct tabletop exercises and full DR drills at least annually; (6) Ensure BCM scope covers cybersecurity incidents, not just natural disasters or outages. Testing & Documentation: SAMA assessors will expect to review test results, lessons-learned reports, and evidence of executive sign-off on BCM plans. Gaps identified during drills must be tracked and remediated with clear ownership. Integrating BCM with your incident response plan ensures a seamless response to cyber-induced disruptions.
Business Continuity Management (BCM) is a mandatory domain under SAMA CSF (Domain 4: Resilience), and SAMA expects Saudi banks to maintain a comprehensive, tested, and board-approved BCM program. Here is what maturity looks like in practice:
Foundation — Policy and Governance:
- A Board-approved BCM Policy aligned with SAMA CSF Control 4.1 and ISO 22301.
- Clear ownership: a BCM Manager or function reporting to the CISO or COO.
- BCM scope covering critical business processes, technology systems, and third-party dependencies.
Business Impact Analysis (BIA):
- Identify and prioritize critical business functions with defined Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
- SAMA expects RTOs for critical banking services (e.g., payment processing, core banking) to be aggressive — typically under 4 hours for Tier-1 banks.
Plans and Playbooks:
- A documented Business Continuity Plan (BCP) covering people, process, and technology continuity.
- A separate Disaster Recovery Plan (DRP) for IT systems, with tested failover to a secondary data center.
- Crisis Communication Plans for internal staff, regulators (SAMA notification obligations), and customers.
Testing and Exercises:
- Full BCM tests must be conducted at least annually. SAMA CSF Control 4.3 requires documented test results and evidence of lessons learned.
- Tests should progress from tabletop exercises to full simulation drills.
Integration with Cybersecurity:
- Ransomware and cyber-incident scenarios must be embedded into BCP/DRP testing, reflecting SAMA's focus on cyber resilience.
- BCM findings should feed into your risk register and annual SAMA self-assessment.
A truly mature BCM program is not a document — it is a living capability that is continuously tested, updated, and embedded in your operational culture.
Business Continuity Management (BCM) is a critical compliance area for Saudi fintechs, governed by SAMA CSF Domain 4 (Operational Resilience) and NCA ECC Control 2-14. Non-compliance can result in regulatory sanctions and reputational damage, particularly given the Central Bank's focus on payment system resilience.
SAMA CSF Requirements (Domain 4):
- Conduct a formal Business Impact Analysis (BIA) identifying critical processes, dependencies, and maximum tolerable downtime (MTD) for each function.
- Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) aligned with the BIA findings.
- Develop and document a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) reviewed and approved by senior management annually.
- Test BCM plans at least annually through tabletop exercises, and full failover drills for technology-dependent processes.
NCA ECC Control 2-14 Requirements:
- Establish a dedicated BCM policy and assign ownership at the executive level.
- Ensure cyber incident scenarios are embedded within BCP exercises, not treated separately.
- Document lessons learned from tests and update plans accordingly.
Practical Implementation Steps:
- Map all fintech services (payments, lending, onboarding) to underlying IT systems and third-party dependencies.
- Define tiered recovery priorities — payment processing should typically target RTO < 4 hours.
- Use cloud-based geo-redundant infrastructure within Saudi Arabia or approved data residency regions per SAMA guidelines.
- Integrate BCM with your Incident Response Plan to ensure seamless escalation.
- Report BCM test results to the Risk Committee quarterly.
Aligning BCM with ISO 22301 principles provides an internationally recognized structure that satisfies both SAMA and NCA auditors simultaneously.
Business Continuity Management (BCM) is a mandatory domain under SAMA CSF, addressed comprehensively in Domain 4 — Resilience. Financial institutions must establish, maintain, and periodically test a BCM program that ensures the continued delivery of critical financial services during and after disruptive events.
Core SAMA CSF Requirements:
Business Impact Analysis (BIA): Per SAMA CSF Control 4.1, institutions must conduct a formal BIA to identify critical business functions, dependencies, Recovery Time Objectives (RTOs), and Recovery Point Objectives (RPOs). RTOs for critical banking systems are generally expected to be under 4 hours.
Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP): Documented plans must exist for all critical processes and IT systems, covering scenarios such as cyberattacks, data center failures, and pandemic events.
Testing and Exercises: SAMA CSF Control 4.3 requires BCM plans to be tested at least annually. Tests should include tabletop exercises, functional drills, and full failover simulations for critical systems. Results must be documented with lessons learned and improvement actions.
Crisis Communication: Plans must include defined communication trees for internal stakeholders, SAMA regulators, and customers during incidents.
Third-Party Dependencies: BCM must account for critical vendor and outsourcing continuity, ensuring suppliers maintain compatible BCM standards.
Board Oversight: The board and senior management are expected to review and approve BCM policies annually and receive test results.
Integration with ISO 22301: Many Saudi institutions align their BCM programs with ISO 22301 (Business Continuity Management Systems), which provides a globally recognized certification pathway that also satisfies SAMA's intent. Maintaining evidence of BCM testing, BIA updates, and board approvals is essential for SAMA regulatory examinations.
Under SAMA CSF Domain 3.7 (Resilience Management), Saudi financial institutions must establish a comprehensive Business Continuity Management (BCM) program that addresses both operational disruptions and cybersecurity incidents. Key requirements include: (1) BIA and RTO/RPO Definition — Conduct a formal Business Impact Analysis identifying critical processes, with Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) defined per system criticality. SAMA CSF Control 3.7.2 mandates these be formally documented and approved by senior management. (2) Tested DR Plans — Disaster Recovery Plans must be tested at least annually, with results documented and remediation actions tracked. Tabletop exercises alone are insufficient; full failover tests are expected for Tier-1 systems. (3) Cyber Resilience Integration — BCM plans must explicitly address ransomware scenarios, DDoS attacks, and core banking system outages. This aligns with NCA ECC Article 2-14 requirements for continuity under cyber incidents. (4) Third-Party Dependencies — Continuity plans must account for critical vendor failures, including cloud providers and payment processors. (5) Board Oversight — SAMA expects the Board Risk Committee to receive annual BCM status reports. Practical implementation tip: map your BCM documentation directly to SAMA CSF control references to simplify regulatory examinations. Integrate your BCM framework with ISO 22301 standards for a defensible, internationally recognized posture that satisfies both SAMA examiners and international auditors.
The SAMA Cyber Security Framework (CSF) uses a structured maturity model to evaluate the cybersecurity posture of member organizations. Understanding this model and preparing systematically is critical for Saudi banks and financial institutions seeking to demonstrate regulatory compliance and build genuine cyber resilience.
The SAMA CSF Maturity Model: SAMA CSF defines five maturity levels — from Level 1 (Initial/Ad-hoc) to Level 5 (Optimized). Most financial institutions are expected to achieve at minimum Level 2 (Developing) for foundational controls, with Tier 1 banks expected to target Level 3 (Defined) or higher across critical domains including Cybersecurity Leadership, Cybersecurity Risk Management, and Cybersecurity Operations.
Key Assessment Domains: The framework covers five primary domains: (1) Cybersecurity Leadership & Governance, (2) Cybersecurity Risk Management & Compliance, (3) Cybersecurity Operations & Technology, (4) Third-Party Cybersecurity, and (5) Cybersecurity Resilience. Each domain contains subdomains with specific controls and maturity indicators.
Preparation Best Practices:
- Conduct a gap assessment first: Map your current controls against each SAMA CSF subdomain using a structured gap analysis tool before the formal evaluation.
- Document everything: Maturity assessors look for evidence — policies, procedures, meeting minutes, training records, and technical configurations all matter.
- Align your CISO reporting structure: SAMA CSF Control 3.1.1 requires cybersecurity to report at the Board or senior executive level; ensure this is formalized.
- Prioritize high-risk domains: Focus remediation efforts on Identity & Access Management, Incident Response, and Vulnerability Management, which are frequently cited in findings.
- Engage an independent assessor: Use a qualified third party for pre-assessment to identify gaps before the regulatory review.
- Build a continuous monitoring program: Demonstrate ongoing control effectiveness, not just point-in-time compliance.
Banks that treat the SAMA CSF assessment as an annual event rather than a continuous program consistently score lower. Embed maturity improvement into your cybersecurity roadmap for sustained results.
Business Continuity Management (BCM) is a critical regulatory obligation for Saudi fintechs. SAMA CSF dedicates an entire control domain (Domain 3.6 – Cyber Resilience) to BCM, while NCA ECC addresses it under Article 2-10 (Business Continuity and Disaster Recovery).
Key Program Components:
1. Business Impact Analysis (BIA): Identify all critical business processes and their supporting IT systems. Define Maximum Tolerable Downtime (MTD), Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO) for each. SAMA expects RTOs for critical payment services to be within 4 hours.
2. Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP): Develop documented, tested plans covering people, processes, technology, and facilities. Plans must address cyber-induced outages specifically — not just physical disasters.
3. Testing Requirements: SAMA CSF requires BCM tests at minimum annually. Tests must include tabletop exercises, functional drills, and full failover tests for critical systems. Results and lessons learned must be documented.
4. Backup and Recovery Controls: NCA ECC Article 2-10 mandates encrypted, geographically separated backups. Restoration tests must confirm data integrity. Backups of critical systems should follow a 3-2-1 strategy.
5. Governance and Ownership: A named BCM owner at senior management level is required. The CISO and Board must receive annual BCM status reports.
6. Regulatory Notification: Under SAMA guidelines, significant disruptions to financial services must be reported to SAMA within defined timeframes, aligned also with PDPL breach notification obligations.
Integrating BCM into your GRC platform ensures continuous monitoring, automated testing reminders, and audit-ready evidence management.
Business Continuity Management (BCM) for Saudi fintechs must address overlapping requirements from both SAMA CSF (Domain 4 – Operational Resilience) and NCA ECC (Control 2-18). Here is a practical implementation roadmap: 1. Business Impact Analysis (BIA): Identify critical business functions, define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). SAMA CSF requires RTOs to be formally approved by senior management. 2. BCM Policy and Governance: Establish a formal BCM policy endorsed by the Board. SAMA CSF Control 4.1 mandates board-level oversight of operational resilience. 3. Disaster Recovery Planning: Maintain a tested Disaster Recovery Plan (DRP) for all critical IT systems. NCA ECC Control 2-18 requires DR site separation and regular failover testing. 4. Crisis Management: Define escalation procedures, communication trees, and regulatory notification timelines — SAMA requires notification within specific windows during major disruptions. 5. Testing and Exercises: Conduct at least one full BCM simulation annually and tabletop exercises semi-annually. Maintain documented test results. 6. Third-Party Dependencies: Map and test BCM arrangements with critical service providers. 7. Continuous Improvement: Feed post-exercise lessons into annual BCM review cycles. Our platform provides BCM module templates pre-mapped to SAMA CSF and NCA ECC controls, enabling gap assessments and automated compliance scoring.
Business Continuity Management (BCM) is a mandatory governance obligation for Saudi financial institutions, deeply embedded in both SAMA CSF Domain 3.5 and NCA ECC Article 3.7. A compliant and mature BCM program must address the full lifecycle from risk assessment through to testing and continuous improvement.
SAMA CSF BCM Requirements (Domain 3.5):
- Establish a formal BCM policy approved by senior management.
- Conduct Business Impact Analysis (BIA) to identify critical processes and define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
- Develop and maintain Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP).
- Test BCM plans at least annually through tabletop exercises, functional drills, or full failover tests.
- Integrate cybersecurity scenarios (ransomware, DDoS, data center outage) into BCM exercises.
NCA ECC Alignment: NCA ECC Article 3.7 requires organizations to ensure critical national infrastructure remains operational during disruptions. Financial institutions classified as Critical National Infrastructure (CNI) must align BCM with national resilience objectives and report major outages to NCA.
Practical Implementation Steps:
- Appoint a BCM Owner at the VP or C-suite level with clear accountability.
- Map dependencies between IT systems, third-party providers, and critical business processes.
- Establish alternate processing sites (hot, warm, or cold) for critical systems.
- Define escalation matrices and communication trees for crisis scenarios.
- Document lessons learned after every test or real incident and update plans accordingly.
- Ensure BCM documentation is reviewed and approved by the board at least annually.
Regulatory examinations routinely assess BCM maturity, and gaps in testing evidence are frequently cited as high-risk findings.
Business Continuity Management (BCM) is a critical compliance domain for Saudi financial institutions, governed primarily by SAMA CSF Domain 4 (Resilience) and NCA ECC Controls 2-9 and 2-10. A compliant BCM program must address both cybersecurity-specific disruptions and broader operational resilience.
SAMA CSF Requirements (Domain 4):
- Maintain a formally approved Business Continuity Policy reviewed at least annually.
- Conduct Business Impact Analyses (BIA) to identify critical processes, Maximum Tolerable Downtime (MTD), Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO).
- Develop and test Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) at least once per year, including tabletop and live failover exercises.
- Ensure cyber incident scenarios are embedded in BCP testing, not treated separately.
NCA ECC Alignment: NCA ECC Article 2-9 requires organizations to establish a resilience framework covering system redundancy, failover capabilities, and backup integrity verification. Article 2-10 mandates periodic DR drills with documented results reported to senior management.
Practical Implementation Steps:
- Assign a BCM Owner accountable to the Board or Risk Committee.
- Classify systems using a tiered criticality model (Tier 1: Mission Critical, Tier 2: Business Critical, Tier 3: Supporting).
- Ensure backup systems are geographically separated and tested for restoration integrity quarterly.
- Integrate BCM with the Cyber Incident Response Plan to create a unified crisis management framework.
- Document lessons learned from every exercise and update plans accordingly.
Regulators frequently assess BCM maturity during on-site examinations, so maintaining an evidence portfolio of test results, BIA reports, and plan updates is essential.
Business Continuity Management (BCM) under SAMA CSF (Domain 4.3) requires Saudi banks to establish a comprehensive, tested, and regularly updated BCM program. Here are the key implementation requirements:
1. BIA and Risk Assessment: Conduct a formal Business Impact Analysis (BIA) to identify critical business functions, acceptable downtime thresholds (RTO/RPO), and dependencies on IT systems and third parties — per SAMA CSF Control 4.3.1.
2. BCP and DRP Documentation: Develop and maintain written Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) that cover cybersecurity scenarios, not just physical disasters. Plans must be approved by senior management.
3. Testing and Exercises: SAMA CSF Control 4.3.4 mandates periodic testing — at minimum annually — including tabletop exercises, simulations, and full failover tests. Results must be documented and gaps remediated.
4. Cyber Incident Integration: BCM plans must explicitly address cyber incidents such as ransomware, DDoS attacks, and critical system compromise. Recovery procedures should align with your Cyber Incident Response Plan (CIRP).
5. Communication Plans: Define clear internal and external communication protocols, including SAMA notification timelines and customer communication procedures during disruptions.
6. Third-Party Dependencies: Map all critical vendor dependencies and ensure vendors have their own tested BCM/DRP plans, reviewed as part of your third-party risk management process.
Practical Tip: Align your BCM program with ISO 22301 standards for additional assurance — this strengthens your SAMA CSF posture and is increasingly expected by examiners during regulatory reviews.
Business Continuity Management (BCM) is a critical compliance domain under SAMA CSF Domain 4, specifically Controls 4.2 through 4.5. Saudi financial institutions must build a structured BCM program that goes beyond documentation to demonstrate operational resilience.
Governance Structure: Appoint a dedicated BCM owner at the senior management level, with clear accountability reported to the board. BCM policy must be reviewed and approved annually per SAMA CSF Control 4.2.1.
Business Impact Analysis (BIA): Conduct a formal BIA to identify critical business processes, dependencies, Maximum Tolerable Downtime (MTD), Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO). SAMA expects RTOs for critical banking systems (core banking, payment rails, internet banking) to be aggressive — typically under four hours.
Plan Development: Maintain separate but integrated plans: Business Continuity Plan (BCP), Disaster Recovery Plan (DRP), and Crisis Communication Plan. Each plan must include activation triggers, escalation paths, and designated recovery teams.
Testing Requirements: SAMA CSF mandates regular testing — at minimum an annual full-scale simulation exercise and quarterly tabletop exercises. Test results, including gaps identified, must be documented and remediated.
Third-Party & Technology Dependencies: BCM must account for critical third-party providers (cloud vendors, payment processors, core banking vendors). SAMA CSF Control 4.3.5 requires continuity clauses in vendor contracts.
Integration with Cyber Incident Response: BCM and cyber incident response plans must be integrated, especially for ransomware or DDoS scenarios that could trigger a continuity event.
Practical Tip: Use your GRC platform to automate BIA reviews, track exercise outcomes, and link BCM controls directly to SAMA CSF control mappings for audit-ready reporting.
Business Continuity Management (BCM) for Saudi financial institutions sits at the intersection of SAMA CSF's Cyber Resilience domain and NCA ECC Article 3-7 (Resilience and Continuity Controls), making a unified, framework-aligned BCM program essential.
SAMA CSF Requirements (Control 3.5.x): SAMA requires institutions to maintain a Cyber Resilience program encompassing Business Continuity Plans (BCP), Disaster Recovery Plans (DRP), and Crisis Management procedures. Key obligations include:
- Formal BIA (Business Impact Analysis) identifying critical business processes and Maximum Tolerable Downtime (MTD)
- Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) defined per system criticality
- Annual BCP/DR testing, with results reviewed by senior management
- Integration of cyber incident scenarios into BCM exercises
NCA ECC Alignment (Art. 3-7): NCA ECC reinforces continuity requirements by mandating that organizations maintain documented recovery procedures for all critical national infrastructure-adjacent systems, with particular emphasis on data backup integrity and alternate site readiness.
Practical Implementation Steps:
- Conduct a unified BIA mapping both operational and cyber-specific risks
- Define and document RTOs/RPOs aligned with SAMA's criticality tiers
- Establish hot/warm/cold site strategies for critical payment and core banking systems
- Run tabletop exercises quarterly and full failover tests annually, documenting outcomes
- Ensure BCM documentation is reviewed by the CISO, CRO, and Board Risk Committee annually
- Maintain offline, immutable backups tested for restoration integrity per SAMA's ransomware resilience guidance
Our platform maps your BCM controls directly to both SAMA CSF and NCA ECC control families, providing real-time compliance gap visibility.
Identity and Access Management (IAM) is a foundational pillar under the SAMA Cyber Security Framework (CSF), specifically addressed in Domain 4 (Cybersecurity Operations) and Domain 3 (Cybersecurity Risk Management). Saudi banks must implement the following key IAM controls:
1. Privileged Access Management (PAM): Per SAMA CSF Control 4.2, privileged accounts must be strictly governed, with just-in-time access provisioning, session recording, and regular privilege reviews. No shared admin accounts should exist.
2. Multi-Factor Authentication (MFA): MFA is mandatory for all remote access, privileged user sessions, and access to critical banking systems. This aligns with SAMA CSF Control 4.3 and NCA ECC-1-4-3, which mandates strong authentication mechanisms.
3. Role-Based Access Control (RBAC): Access rights must follow the principle of least privilege. Roles should be formally defined, approved, and reviewed at least semi-annually, with user access recertification campaigns documented.
4. Joiner-Mover-Leaver (JML) Process: Automated workflows must ensure timely provisioning and, critically, de-provisioning of access. SAMA CSF requires that terminated employee access is revoked within defined SLAs — typically within 24 hours for critical systems.
5. Identity Governance: Banks should maintain a centralized identity directory with audit logs for all access changes, reviewed by internal audit periodically.
Practical Recommendation: Conduct a quarterly Access Rights Review (ARR) exercise using your IAM platform and document findings for SAMA CSF assessment evidence. Integrate your IAM solution with SIEM to correlate access anomalies in real time. Non-compliance in this domain is a recurring finding in SAMA CSF maturity assessments.
Under SAMA CSF Domain 3 (Cybersecurity Operations), Saudi banks are required to implement a robust Identity and Access Management program covering several critical controls. Per SAMA CSF Control 3.3.1, organizations must enforce the principle of least privilege, ensuring users are granted only the minimum access necessary for their roles. Control 3.3.2 mandates multi-factor authentication (MFA) for all privileged accounts, remote access sessions, and critical system interfaces. Banks must also maintain a formal joiner-mover-leaver process, ensuring access rights are reviewed during role changes and immediately revoked upon employee termination per Control 3.3.4. Privileged Access Management (PAM) solutions should be deployed to monitor, record, and audit all privileged sessions. Quarterly access reviews are required for critical systems, while annual reviews apply to standard user accounts. Additionally, shared or generic accounts must be eliminated or strictly controlled with individual accountability maintained. From an NCA ECC perspective, Article 2-6 reinforces these obligations for entities within scope, requiring documented IAM policies, automated provisioning workflows, and integration with a centralized directory service. Practical steps include deploying a PAM solution such as CyberArk or BeyondTrust, integrating Single Sign-On (SSO) with MFA via solutions like Azure AD or Okta, and conducting automated quarterly access certification campaigns. Non-compliance with these controls can result in regulatory findings during SAMA examination cycles and increased risk of insider threats or unauthorized access incidents.
Under SAMA CSF Domain 3 (Cybersecurity Operations), specifically Controls 3.3.1 through 3.3.6, Saudi banks must implement a comprehensive Identity and Access Management program that governs how users — especially privileged users — access critical systems and data.
Key requirements include:
1. Least Privilege Principle: Every user, system, and application should have only the minimum access needed to perform their function. Per SAMA CSF Control 3.3.2, access rights must be formally approved, documented, and periodically reviewed (at least annually or upon role changes).
2. Privileged Access Management (PAM): Privileged accounts (admins, DBAs, network engineers) must be tightly controlled. Implement a dedicated PAM solution (e.g., CyberArk, BeyondTrust) to vault credentials, enforce session recording, and require multi-factor authentication (MFA) for all privileged sessions.
3. Multi-Factor Authentication: SAMA CSF mandates MFA for remote access, privileged accounts, and critical system access. This aligns with NCA ECC Control ECC-2-2-6, reinforcing its importance across both frameworks.
4. Access Reviews: Conduct quarterly access recertification for privileged accounts and annual reviews for standard users. Automated joiner-mover-leaver (JML) processes should revoke access within 24 hours of employee departure.
5. Separation of Duties (SoD): No single individual should have end-to-end control over critical processes. Conflicting roles must be identified and mitigated via compensating controls.
Practical Tip: Integrate your IAM solution with your SIEM to alert on anomalous privileged activity. Document your IAM policy, access request workflow, and exception process — SAMA assessors will review these during maturity evaluations.
Identity and Access Management (IAM) is a foundational control domain that sits at the intersection of SAMA CSF and ISO 27001. Here is how Saudi fintechs can design a unified, compliant IAM program:
SAMA CSF Alignment (Control Domain 3.4 – Identity & Access Management):
- Implement a formal access control policy covering role-based access control (RBAC), need-to-know principles, and separation of duties.
- Enforce privileged access management (PAM): all privileged accounts must be individually assigned, logged, and reviewed quarterly.
- Multi-factor authentication (MFA) is mandatory for remote access, privileged accounts, and customer-facing portals.
- Conduct access recertification reviews at least every 90 days for privileged users and every 6 months for standard users.
ISO 27001 Alignment (Annex A Controls A.9.x – Access Control):
- Maintain a formal User Access Management procedure covering joiner, mover, and leaver (JML) processes.
- Document a Business Need justification for each access grant.
- Ensure privileged utility programs are restricted and monitored per A.9.4.4.
Practical Implementation Steps:
- Deploy an Identity Governance & Administration (IGA) platform to automate provisioning and de-provisioning workflows.
- Integrate Single Sign-On (SSO) with your IGA tool to reduce credential sprawl.
- Log all access events to your SIEM and retain logs per SAMA's 12-month minimum retention requirement.
- Map your IAM controls to both SAMA CSF and ISO 27001 in a unified controls register to avoid duplicating audit evidence.
Common Gap: Many fintechs overlook service accounts and API tokens — these must be included in your PAM scope and rotated regularly.
This is one of the most common strategic questions from CISOs at Saudi banks, and the short answer is: yes, pursuing both is highly recommended — they are complementary, not duplicative.
How They Relate: ISO 27001 provides a globally recognized Information Security Management System (ISMS) framework with rigorous process and governance requirements. SAMA CSF, on the other hand, is a sector-specific regulatory framework tailored to the risks and operational realities of Saudi financial institutions. The two share significant overlap — particularly in risk management, access control, incident management, and supplier security — which means ISO 27001 implementation work directly accelerates SAMA CSF compliance.
Key Areas of Overlap:
- Risk Assessment & Treatment (ISO 27001 Clause 6.2 ↔ SAMA CSF Control 3.2)
- Asset Management (ISO 27001 Annex A.8 ↔ SAMA CSF Control 3.3)
- Supplier Relationships (ISO 27001 Annex A.15 ↔ SAMA CSF Third-Party Risk Controls)
- Incident Management (ISO 27001 Annex A.16 ↔ SAMA CSF Control 3.6)
What ISO 27001 Adds: ISO 27001 certification signals to international partners, regulators, and customers that your institution meets a globally audited security standard. It also introduces structured continual improvement cycles (PDCA) that institutionalize security maturity over time.
Practical Recommendation: Conduct an integrated gap assessment mapping your current controls against both frameworks simultaneously. Use a unified control library to avoid redundant documentation. Sequence your effort: establish your ISMS foundation first, then layer SAMA-specific controls. Most mid-sized Saudi banks achieve both within 12–18 months with proper program management.
Our platform's GRC module supports cross-framework mapping to eliminate duplication and track compliance posture across SAMA CSF, ISO 27001, NCA ECC, and NIST CSF in a single dashboard.
Identity and Access Management (IAM) is one of the most scrutinized control domains during SAMA examinations. Under SAMA CSF Control 3.3.3 (Access Control), banks must enforce a formal access management lifecycle covering provisioning, periodic review, and de-provisioning. Key mandatory controls include: (1) Role-Based Access Control (RBAC) — all system access must be granted based on documented job roles with least-privilege principles; standing privileged access must be eliminated in favor of just-in-time (JIT) access; (2) Multi-Factor Authentication (MFA) — SAMA CSF requires MFA for all remote access, privileged accounts, and critical system interfaces; NCA ECC Article 2-5 further mandates MFA for administrative access to national infrastructure-connected systems; (3) Privileged Access Management (PAM) — privileged sessions must be recorded and stored for a minimum of 12 months; shared administrative accounts are prohibited; (4) Access Reviews — quarterly access certification reviews are expected for privileged users; annual reviews for standard users, with evidence retained for regulatory inspection; (5) Segregation of Duties (SoD) — SAMA CSF Control 3.3.3 explicitly requires SoD matrices to prevent conflicts such as a single user having both transaction initiation and approval rights; (6) Directory Hardening — Active Directory or equivalent IAM systems must be hardened per CIS Benchmarks, with service accounts inventoried and managed. Integration with a SIEM for failed login monitoring, account lockout alerting, and anomalous access detection is also required per SAMA CSF Control 3.3.6. Banks should target maturity Level 3 (defined and implemented) across all IAM sub-domains in their SAMA CSF self-assessment.
Under SAMA CSF Control 3.3.1 (Cybersecurity Awareness and Training), Saudi financial institutions are required to establish a formal, role-based security awareness program that covers all employees, contractors, and third parties with access to critical systems. The program must be conducted at least annually, with targeted sessions for privileged users and IT staff delivered more frequently — ideally quarterly.
A well-structured program should include: (1) onboarding training for new joiners before system access is granted; (2) annual refresher training for all staff covering phishing, social engineering, password hygiene, and data handling; (3) role-specific modules for developers (secure coding), finance teams (fraud awareness), and executives (cyber risk governance); and (4) simulated phishing exercises with measurable outcomes tracked over time.
SAMA expects institutions to document training completion rates, maintain evidence of attendance, and report gaps to senior management and the board. Completion rates below 90% across departments should trigger escalation. Additionally, per NCA ECC Article 2-6, awareness programs must align with the national cybersecurity culture framework.
Practically, platforms like the CISO Consulting GRC portal allow you to track training completion by department, generate audit-ready reports, and schedule automated reminders — helping you maintain continuous compliance posture rather than treating awareness as a one-time annual checkbox.
SAMA CSF Control 3.3.1 mandates that Member Organizations establish a formal cybersecurity awareness and training program tailored to roles and responsibilities. Here is a practical implementation roadmap:
1. Program Structure: Design a tiered training model — general staff receive foundational security awareness, IT teams get technical training, and executives and board members receive governance-focused briefings. All new hires must complete onboarding security training before accessing systems.
2. Mandatory Content Areas (per SAMA CSF):
- Phishing and social engineering recognition
- Acceptable use of information assets
- Password hygiene and multi-factor authentication
- Incident reporting procedures
- Data classification and handling
3. Delivery Frequency: SAMA expects at minimum annual training for all staff, with quarterly phishing simulations recommended. High-privilege users (system admins, privileged access holders) should receive role-specific training every six months.
4. Measurement and Metrics: Track completion rates (target: 100% within 30 days of assignment), phishing simulation click rates (benchmark: below 5% after 12 months), and post-training assessment scores. Report metrics to the CISO and board risk committee.
5. Documentation for Audit: Maintain training records including completion timestamps, assessment scores, and training material version history. SAMA examiners will request these during regulatory reviews.
6. Alignment with NCA ECC: NCA ECC Article 2-6 also requires cybersecurity culture promotion across the organization. A unified program satisfies both frameworks simultaneously.
Platforms like our GRC solution can automate training assignment, track compliance status per employee, and generate audit-ready reports aligned with SAMA CSF control evidence requirements.
A robust Cyber Incident Response Plan (CIRP) is not optional for Saudi financial institutions — it is a regulatory necessity under both SAMA CSF and NCA ECC, with specific reporting timelines that carry compliance consequences if missed.
SAMA CSF Requirements (Control 3.5 – Cybersecurity Incident Management): SAMA requires Member Organizations to maintain a documented CIRP that covers: preparation, detection and analysis, containment, eradication, recovery, and post-incident review. Critically, SAMA must be notified of significant cybersecurity incidents within 72 hours of detection. Material breaches may require escalation to the Financial Sector Cyber Threat Intelligence (FinCERT) platform.
NCA ECC Reporting Obligations (Article 2-9): NCA requires reporting of high-impact incidents to the National Cybersecurity Authority within 24 hours of identification. This creates a dual-reporting obligation — organizations must maintain separate notification workflows for SAMA and NCA.
Key CIRP Structural Elements:
- Incident Classification Matrix — define severity levels (P1–P4) with escalation thresholds tied to regulatory reporting triggers.
- Response Team (CSIRT) — assign roles: Incident Commander, Technical Lead, Legal/Compliance Liaison, Communications Officer, and Executive Sponsor.
- Playbooks — develop scenario-specific playbooks for ransomware, DDoS, insider threat, data exfiltration, and payment fraud.
- Communication Templates — pre-draft regulatory notification letters for SAMA, NCA, and PDPL authority (SDAIA) to minimize delay during crisis.
- Evidence Preservation — define chain-of-custody procedures for forensic artifacts; critical for post-incident regulatory inquiries.
- Post-Incident Review (PIR) — conduct within 14 days; document root cause, timeline, and corrective actions. SAMA examiners will review PIR reports.
Testing Frequency: Conduct tabletop exercises at least annually and full simulation drills every 18–24 months. Document results and remediation actions for regulatory evidence.
Our platform provides pre-built CIRP templates mapped to SAMA CSF controls, dual-reporting workflow automation for SAMA and NCA, and incident timeline tracking for regulatory evidence.
Third-party risk management is a critical compliance obligation for Saudi financial institutions. Under SAMA CSF Domain 4.3 (Third Party Management), regulated entities must establish a formal vendor risk assessment program before onboarding any third party with access to critical systems or data.
Key requirements include:
Pre-Onboarding: Conduct cybersecurity due diligence assessments covering the vendor's security posture, certifications (e.g., ISO 27001), and incident response capabilities. SAMA CSF Control 4.3.1 requires risk classification of all third parties based on data sensitivity and system access levels.
Contractual Controls: Embed cybersecurity clauses in all vendor contracts, including data handling obligations, breach notification timelines (aligned with PDPL's 72-hour notification requirement), audit rights, and right-to-terminate clauses.
Ongoing Monitoring: Per SAMA CSF Control 4.3.3, annual reassessments are mandatory for high-risk vendors. NCA ECC Article 2-5 further requires that critical infrastructure dependencies on third parties are documented and tested during business continuity exercises.
Cloud & SaaS Vendors: For cloud service providers, additional controls apply under the NCA Cloud Cybersecurity Controls (CCC-1), requiring data residency confirmation within the Kingdom or explicit SAMA approval for offshore processing.
Practical Steps: Maintain a live vendor inventory, tier suppliers by risk level (Critical/High/Medium/Low), and conduct annual or triggered reassessments. Use standardized questionnaires aligned with SAMA CSF and ISO 27001 Annex A.15. Ensure your TPRM policy is reviewed and approved by the board or relevant risk committee annually.
SAMA CSF Domain 3 (Cybersecurity Operations) and specifically Control 3.3 mandate that all regulated financial institutions maintain a formally documented and tested Cyber Incident Response Plan (CIRP). Non-compliance is a common finding during SAMA examinations and can result in significant regulatory consequences.
Core CIRP Requirements under SAMA CSF:
- Detection & Triage: Implement 24/7 security monitoring capabilities (SOC or managed SIEM) capable of detecting incidents within defined timeframes. SAMA CSF requires clear severity classification criteria aligned with impact to operations and customer data.
- Escalation & Notification: Critical incidents must be escalated to senior management and the Board within defined SLAs. Importantly, SAMA requires member institutions to report significant cybersecurity incidents to SAMA's Cyber Threat Intelligence Unit within 72 hours of discovery — failure to report is treated as a separate regulatory violation.
- Containment, Eradication & Recovery: Document specific technical playbooks for common attack scenarios (ransomware, data breach, DDoS, insider threat). NCA ECC Control 3-5 also requires maintaining forensic evidence integrity throughout the response process.
- Post-Incident Review: Conduct formal lessons-learned reviews within 30 days of incident closure, with findings feeding back into risk registers and control improvements.
Structural Recommendation: Your CIRP should reference and integrate with your Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) to ensure seamless activation. Test the plan via tabletop exercises at least annually, with results documented for SAMA examiner review. For smaller fintechs, engaging a vCISO or managed security provider to maintain CIRP readiness is a cost-effective approach.
Third-party risk management (TPRM) is a critical compliance requirement for Saudi financial institutions. Under SAMA CSF Control 3.3 (Third-Party Management), organizations must establish a formal vendor risk program covering the entire vendor lifecycle — from onboarding and due diligence to ongoing monitoring and offboarding.
Key implementation steps include:
1. Vendor Classification & Risk Tiering: Classify vendors based on data access, criticality, and service nature. High-risk vendors (e.g., cloud providers, core banking system vendors) require deeper scrutiny per SAMA CSF Control 3.3.2.
2. Pre-Onboarding Due Diligence: Require vendors to complete cybersecurity questionnaires, provide ISO 27001 certificates or SOC 2 Type II reports, and sign Data Processing Agreements (DPAs) aligned with PDPL Article 29 obligations.
3. Contractual Security Requirements: Embed mandatory clauses covering incident notification timelines (per SAMA CSF Control 3.3.4), right-to-audit provisions, and minimum security baselines aligned with NCA ECC Article 2-7.
4. Continuous Monitoring: Conduct annual security assessments for critical vendors and quarterly reviews for high-risk ones. Use threat intelligence feeds to monitor vendor breach disclosures.
5. Concentration Risk Management: SAMA specifically flags risks from over-reliance on a single vendor for critical services — document contingency plans accordingly.
6. Offboarding Controls: Ensure secure data deletion, access revocation, and certificate/key rotation upon vendor termination.
Our platform provides automated vendor risk scorecards, pre-built questionnaire templates mapped to SAMA CSF and NCA ECC controls, and audit-ready reporting — helping your compliance team reduce manual effort while maintaining full regulatory traceability.
Incident reporting obligations in Saudi Arabia's financial sector are among the most stringent in the region, governed by multiple overlapping frameworks that CISOs must navigate carefully.
SAMA CSF Reporting Requirements (Control 3.4.3):
- Immediate notification (within 2 hours): Critical incidents involving core banking disruption, large-scale data breach, or ransomware affecting production systems must be reported to SAMA via the official incident reporting portal.
- Full incident report (within 72 hours): A comprehensive report detailing the nature, scope, affected systems, customer impact, and initial containment actions must be submitted.
- Post-incident report (within 30 days): A root cause analysis (RCA) with remediation plan and lessons-learned documentation is mandatory.
NCA Reporting Obligations: Under the National Cybersecurity Authority's Cybersecurity Event Management (CEM) framework, organizations operating Critical National Infrastructure (CNI) must report significant incidents to the National Cybersecurity Operations Center (NCOC) — with initial notification expected within 4 hours of detection.
PDPL Breach Notification (Article 19): If the incident involves personal data exposure, PDPL mandates notification to the Saudi Data & AI Authority (SDAIA) within 72 hours, and affected data subjects must be informed without undue delay if there is a high risk to their rights.
Practical Preparation Checklist:
- Maintain a pre-approved incident response retainer with 24/7 escalation contacts for SAMA and NCA.
- Document your Incident Classification Matrix aligned to SAMA CSF severity tiers.
- Conduct tabletop exercises simulating breach scenarios at least twice annually.
- Ensure your SIEM/SOAR platform timestamps and logs all detection-to-notification steps for audit evidence.
Failure to meet these timelines can result in regulatory sanctions, reputational damage, and heightened supervisory scrutiny.
Under SAMA CSF Control Domain 3.3 (Third-Party Management), Saudi banks must establish a comprehensive TPRM program that covers the full vendor lifecycle — from onboarding to offboarding. Key requirements include:
1. Risk-Based Vendor Classification: Categorize vendors by criticality (Critical, High, Medium, Low) based on data access, system connectivity, and service dependency. Vendors with access to core banking systems or customer PII require the highest scrutiny.
2. Pre-Engagement Due Diligence: Before contracting, conduct security assessments covering ISO 27001 certification status, data handling practices, incident response capabilities, and sub-contractor dependencies. Per SAMA CSF 3.3.2, banks must obtain documented security assurances before granting access.
3. Contractual Security Obligations: All vendor contracts must include cybersecurity clauses: right-to-audit, incident notification timelines (typically 72 hours under SAMA guidance), data return/destruction upon termination, and compliance with NCA ECC where applicable.
4. Ongoing Monitoring: Conduct annual reassessments for Critical/High-risk vendors and biennial reviews for others. Use questionnaires aligned with SAMA CSF and cross-reference with NCA ECC Article 2-6 controls for technology service providers.
5. Cloud and SaaS Vendors: For cloud providers, apply SAMA's Cloud Framework requirements alongside NCA's Cloud Cybersecurity Controls (CCC-1), ensuring data residency within KSA for sensitive financial data.
Practically, banks should maintain a central vendor registry within their GRC platform, automate assessment workflows, and produce board-level reports on third-party risk exposure. CISO Consulting's platform supports automated TPRM workflows mapped directly to SAMA CSF control requirements.
Security awareness is not optional — it is a formal regulatory requirement under SAMA CSF Domain 2 (Cybersecurity Leadership & Governance) and NCA ECC Article 3-3. A well-structured program goes far beyond annual e-learning modules.
Regulatory Baseline Requirements SAMA CSF Control 2.3 requires institutions to establish a cybersecurity awareness program covering all staff, contractors, and third parties with system access. Programs must be documented, tracked, and evidence must be available for SAMA examiners.
Program Structure Best Practices
Role-Based Training: Generic training is insufficient. Tailor content by role — developers need secure coding training, finance staff need phishing and social engineering awareness, executives need cyber risk governance modules.
Frequency: Conduct mandatory awareness training at onboarding and at minimum annually. Supplement with monthly micro-learning content, newsletters, and simulated phishing campaigns.
Phishing Simulations: SAMA expects evidence of phishing simulation exercises. Track click rates, report rates, and remedial training completion. Benchmark quarterly to demonstrate improvement.
Privileged User Training: Staff with elevated access (system admins, IT ops) require additional specialized training per SAMA CSF Control 3.3.7, covering insider threat, access abuse, and incident reporting obligations.
Metrics & Reporting: Report awareness program effectiveness to senior management and the board annually. Key metrics include training completion rates, phishing simulation improvement trends, and security incident attribution to human error.
Arabic Language Content: Ensure training materials are available in Arabic to maximize staff comprehension and regulatory credibility with SAMA auditors.
A mature awareness program demonstrably reduces your human-layer risk and provides auditable evidence of SAMA CSF compliance.
Third-party risk management (TPRM) is a critical obligation for Saudi financial institutions under SAMA CSF Domain 3.3 and NCA ECC-1:2-6.3. A compliant and mature TPRM program should be built around the following pillars:
1. Vendor Classification & Tiering: Categorize all third parties based on criticality, data access level, and service dependency. Vendors with access to customer data or core banking systems should be classified as Tier 1 and subjected to the most rigorous due diligence.
2. Pre-Onboarding Due Diligence: Before contracting, conduct a formal cybersecurity assessment covering the vendor's security posture, certifications (e.g., ISO 27001), incident history, and subcontractor dependencies. SAMA CSF Control 3.3.3 explicitly requires documented assessments prior to engagement.
3. Contractual Security Requirements: Ensure all vendor contracts include clauses on data protection obligations aligned with PDPL, incident notification timelines (typically within 72 hours), audit rights, and the right to terminate upon non-compliance.
4. Continuous Monitoring: TPRM is not a one-time exercise. Implement ongoing monitoring using threat intelligence feeds, periodic reassessments (at least annually for Tier 1), and automated alerts for changes in vendor risk profiles.
5. Offboarding Controls: Establish secure data return or destruction procedures when a vendor relationship ends, consistent with PDPL Article 19 on data retention and disposal.
A practical starting point is maintaining a centralized vendor risk register reviewed quarterly by the CISO and risk committee. Institutions that treat TPRM as a living program — not just a checkbox — are far better positioned during SAMA regulatory examinations.
Security awareness training is not optional for Saudi fintechs — it is explicitly mandated under SAMA CSF Control 3.2.2 and NCA ECC Article 2-10-1, which require institutions to establish a formal, recurring human security program. Here is how to build one that is both compliant and impactful:
1. Define a Training Policy: Start with a documented Cybersecurity Awareness Policy that sets scope, frequency, roles, and accountabilities. SAMA CSF requires this to be reviewed at least annually.
2. Role-Based Curriculum Design: Generic training fails. Design separate modules for: General staff (phishing, social engineering, password hygiene), IT/security teams (technical threat awareness, secure coding), and Senior management/Board (cyber risk governance, regulatory obligations). NCA ECC Control 2-10-2 specifically calls for tailored content by role.
3. Phishing Simulation Exercises: Run quarterly simulated phishing campaigns to test employee vigilance. Track click rates, credential submission rates, and reporting rates as measurable KPIs. SAMA examiners frequently request evidence of these exercises.
4. Onboarding & Refresher Training: All new employees must complete security awareness training before being granted system access. Existing staff should receive refresher training at least annually, with additional targeted sessions following any security incident.
5. Awareness Metrics & Reporting: Track completion rates, assessment scores, and phishing simulation outcomes. Report these metrics to senior management quarterly and include them in your annual SAMA self-assessment submission.
6. Regulatory & Cultural Localization: Ensure training content references Saudi-specific regulations (SAMA, NCA, PDPL) and uses Arabic-language materials where applicable to maximize comprehension and engagement among your workforce.
A mature awareness program transforms your employees from your greatest vulnerability into your most effective first line of defense.
Third-party risk management (TPRM) is a critical obligation under SAMA CSF Domain 3 (Cybersecurity Risk Management) and specifically referenced in Control 3.3, which mandates that member organizations establish a formal supplier and third-party risk management program.
Practical implementation steps include:
- Vendor Classification: Categorize all third parties by risk level — critical, high, medium, and low — based on the data they access, services they provide, and systemic impact if compromised.
- Pre-Onboarding Assessment: Before engagement, conduct cybersecurity due diligence using standardized questionnaires aligned with SAMA CSF controls, ISO 27001 Annex A, and NCA ECC requirements.
- Contractual Controls: Ensure all vendor contracts include cybersecurity clauses covering data protection (per PDPL obligations), incident notification timelines (typically within 72 hours), right-to-audit provisions, and acceptable use policies.
- Ongoing Monitoring: Perform annual reassessments for critical vendors and bi-annual reviews for high-risk suppliers. Use threat intelligence feeds and continuous monitoring tools to detect supply chain threats.
- Concentration Risk: SAMA specifically flags technology concentration risk — if a single vendor supports multiple critical functions, a dedicated contingency plan must exist.
- Cloud and SaaS Vendors: For cloud-hosted services, verify CSP compliance with NCA Cloud Cybersecurity Controls (CCC) and confirm data residency within the Kingdom where required.
Failure to maintain a documented TPRM program can result in SAMA examination findings, remediation obligations, and reputational damage. Institutions should maintain a live vendor register reviewed at least annually by the CISO and risk committee.
Security Awareness Training (SAT) is not optional for Saudi financial institutions — SAMA CSF Domain 2 (Leadership and Governance) and Control 3.2.1 explicitly mandate a formalized, role-based security awareness program reviewed at least annually.
Program Design Essentials:
- Audience Segmentation: Design differentiated training tracks for: general staff, IT and security personnel, privileged users, and the Board/C-suite. SAMA CSF distinguishes awareness needs across organizational levels.
- Mandatory Topics: At a minimum, cover phishing and social engineering, password hygiene, acceptable use of IT assets, data handling per PDPL obligations, and incident reporting procedures.
- Phishing Simulations: Conduct simulated phishing campaigns at least quarterly. Track click rates, credential submission rates, and remediation completion to demonstrate measurable risk reduction — a key expectation in SAMA examinations.
- Role-Specific Modules for High-Risk Roles: Treasury, payments, and customer-facing staff require specialized training on fraud, BEC (Business Email Compromise), and social engineering tactics given their exposure profile.
- Metrics and Reporting: Maintain training completion records (minimum 90% completion rate recommended), phishing simulation results, and trend analysis. Present these metrics to the Board Risk Committee at least annually per SAMA CSF governance requirements.
- Regulatory Alignment: NCA ECC Article 2-5 also mandates cybersecurity awareness as a foundational control. Align your SAT calendar with the broader cybersecurity governance cycle.
- Continuous Reinforcement: Move beyond annual training — use micro-learning, security newsletters, and real-incident case studies to embed security culture year-round.
A well-documented SAT program with evidence of effectiveness is increasingly scrutinized during SAMA regulatory examinations and demonstrates genuine cybersecurity maturity.
Under SAMA CSF Control Domain 3.3 (Third-Party Management), Saudi banks must establish a formal, risk-based vendor management program that covers the entire lifecycle of third-party relationships — from onboarding through offboarding.
Key requirements include:
- Risk Classification: Categorize all vendors by criticality (e.g., Tier 1 for core banking processors, cloud providers) based on data access, system integration depth, and regulatory exposure.
- Pre-Onboarding Due Diligence: Conduct cybersecurity assessments before contracting, including reviewing the vendor's ISO 27001 certification status, SOC 2 reports, and vulnerability management practices.
- Contractual Controls: Ensure all contracts include clauses mandating incident notification within defined timeframes (aligned with SAMA's 72-hour reporting window), the right to audit, and data return/deletion obligations consistent with PDPL Article 19.
- Continuous Monitoring: Perform annual reassessments for Tier 1 vendors and biennial reviews for lower-risk suppliers. Use threat intelligence feeds to monitor vendors for breaches disclosed externally.
- Concentration Risk: SAMA specifically flags risks arising from over-reliance on a single technology vendor — ensure contingency plans exist if a critical supplier fails.
- Offboarding Controls: Mandate secure data deletion and revoke all access credentials within 24 hours of contract termination.
Financial institutions should also cross-reference NCA ECC Article 2-14 (Supply Chain Security) when procuring technology services. Maintaining a centralised vendor register with real-time risk scores is a recommended best practice that simplifies SAMA examination responses.
Third-party risk management (TPRM) is a critical obligation for Saudi financial institutions under SAMA CSF Domain 3.3 (Third-Party Management) and NCA ECC-1:2018 Control 2-7. Institutions must implement a structured TPRM lifecycle covering vendor onboarding, ongoing monitoring, and offboarding.
Key requirements include:
- Risk-Based Classification: Classify all third parties by their access level to critical systems and sensitive data. Vendors with direct access to core banking infrastructure or customer PII should be categorized as high-risk and subject to enhanced due diligence.
- Contractual Security Obligations: Per SAMA CSF Control 3.3.3, all vendor contracts must include enforceable cybersecurity clauses covering incident notification timelines (typically within 24–72 hours), data handling standards, and the right to audit.
- Cybersecurity Assessments: Conduct annual cybersecurity assessments for critical vendors using standardized questionnaires aligned to ISO 27001 Annex A or NIST CSF. On-site audits should be reserved for Tier-1 suppliers.
- Concentration Risk Monitoring: SAMA expects institutions to identify and mitigate concentration risk where multiple critical functions rely on a single third party.
- Cloud and SaaS Vendors: NCA ECC Control 2-7-3 specifically addresses cloud service provider (CSP) oversight, requiring institutions to ensure CSPs meet local data residency and security standards before onboarding.
Practically, institutions should maintain a centralized Third-Party Risk Register, integrate TPRM into the annual risk assessment cycle, and assign clear ownership to a dedicated vendor risk team or the CISO's office. Automated GRC platforms can streamline evidence collection and continuous monitoring across your supplier ecosystem.
Third-party risk management (TPRM) is a critical obligation under SAMA CSF Domain 3.3, which requires financial institutions to establish a structured lifecycle for managing vendor relationships from onboarding through offboarding.
Key Requirements:
- Pre-onboarding Due Diligence: Per SAMA CSF Control 3.3.1, institutions must assess the cybersecurity posture of all third parties before engagement. This includes reviewing SOC 2 Type II reports, ISO 27001 certifications, and conducting vendor security questionnaires.
- Contractual Controls: SAMA CSF Control 3.3.2 mandates that contracts with third parties include explicit cybersecurity obligations, right-to-audit clauses, data breach notification timelines (aligned with PDPL Article 29), and incident response coordination procedures.
- Continuous Monitoring: Vendors must be re-assessed periodically — at minimum annually for critical vendors — using risk tiering to prioritize effort.
- Cloud and SaaS Providers: When outsourcing to cloud providers, NCA ECC Article 7 cloud security controls also apply, requiring data residency validation and access control reviews.
Practical Steps:
- Build a vendor inventory classified by criticality (critical, high, medium, low).
- Use standardized security questionnaires mapped to SAMA CSF and NCA ECC controls.
- Establish a vendor risk register and escalation thresholds.
- Include TPRM reporting in your board-level cybersecurity dashboards.
Failure to manage third-party risk exposes institutions to regulatory penalties and supply-chain breaches. SAMA has increasingly scrutinized vendor management during examination cycles, making this a top compliance priority for CISOs in 2024 and beyond.
Third-party risk management (TPRM) is a critical compliance obligation for Saudi financial institutions. Under SAMA CSF Control 3.3.1, institutions must establish a formal vendor risk management program that covers the entire vendor lifecycle — from onboarding and due diligence through to contract termination.
Key requirements include:
1. Pre-onboarding Due Diligence: Conduct cybersecurity assessments of all critical vendors, reviewing their ISO 27001 certifications, audit reports (SOC 2 Type II), and security policies before contract signing.
2. Contractual Obligations: Embed security clauses into vendor contracts mandating breach notification timelines (aligned with PDPL's 72-hour reporting obligation), right-to-audit provisions, and data handling requirements per PDPL Articles 19–21.
3. Continuous Monitoring: Per SAMA CSF Control 3.3.3, perform annual reassessments for critical vendors and quarterly reviews for those with access to sensitive financial or personal data. NCA ECC Article 2-14 also requires that outsourced services maintain equivalent security controls to those applied internally.
4. Concentration Risk: Assess single-vendor dependencies, especially for cloud providers, to avoid systemic exposure.
5. Fourth-Party Risk: Identify and assess subcontractors used by your primary vendors, particularly in cloud and SaaS environments.
Our GRC platform provides a structured vendor risk register, automated assessment workflows, and real-time compliance dashboards that map vendor risks directly to SAMA CSF and NCA ECC control requirements — enabling your compliance team to demonstrate regulatory adherence efficiently during SAMA examinations.
Third-party risk management is a critical compliance area under SAMA CSF Domain 3.4 and NCA ECC Article 2-7. Saudi financial institutions must establish a formal Third-Party Risk Management (TPRM) program that covers the entire vendor lifecycle — from onboarding to offboarding.
Key requirements include:
1. Pre-Engagement Due Diligence: Before contracting any vendor, conduct a cybersecurity risk assessment that evaluates the vendor's security posture, certifications (e.g., ISO 27001), and data handling practices. Per SAMA CSF Control 3.4.1, vendors with access to critical systems or sensitive data must undergo enhanced scrutiny.
2. Contractual Security Obligations: All vendor contracts must include cybersecurity clauses mandating compliance with SAMA CSF and PDPL data protection standards, incident notification timelines (typically within 72 hours per PDPL Article 20), right-to-audit provisions, and data return/destruction obligations upon contract termination.
3. Continuous Monitoring: SAMA CSF requires ongoing monitoring of critical vendors, not just point-in-time assessments. Implement automated vendor risk scoring using tools integrated with your GRC platform, and schedule periodic reassessments — at least annually for Tier-1 vendors.
4. Vendor Tiering and Criticality Classification: Classify vendors by criticality (Tier 1–3) based on data sensitivity and operational dependency. NCA ECC Article 2-7-3 specifically requires documented risk treatment plans for high-criticality third parties.
5. Cloud and SaaS Vendors: For cloud service providers, ensure compliance with NCA Cloud Cybersecurity Controls (CCC-1) in addition to standard TPRM controls.
A GRC platform like CISO Consulting automates vendor questionnaires, risk scoring, and compliance gap tracking, significantly reducing the manual burden on your security and procurement teams.
Third-party risk management (TPRM) is a critical obligation under both SAMA CSF (Domain 3.3 – Third Party Management) and NCA ECC (Control 2-14). Saudi financial institutions must establish a formal, risk-based vendor management program that covers the entire vendor lifecycle — from onboarding to offboarding.
Key implementation steps include:
- Vendor Classification: Categorize vendors by criticality and data access level. Vendors handling personal financial data or core banking infrastructure require the highest scrutiny.
- Pre-Onboarding Due Diligence: Conduct cybersecurity assessments before contracting. Request evidence of ISO 27001 certification, penetration test results, and SOC 2 reports where applicable.
- Contractual Obligations: Ensure all vendor contracts include cybersecurity clauses covering data protection (aligned with PDPL Article 21), incident notification timelines (typically 72 hours), audit rights, and right-to-terminate for security failures.
- Continuous Monitoring: Per SAMA CSF Control 3.3.4, institutions must conduct periodic reassessments — at minimum annually for critical vendors. Use automated vendor risk platforms or structured questionnaires (e.g., CAIQ, SIG).
- Concentration Risk: SAMA expects banks to identify and manage concentration risk where multiple critical functions rely on a single vendor or cloud provider.
- Offboarding Controls: Ensure secure data deletion, access revocation, and credential rotation when a vendor relationship ends.
Our GRC platform provides pre-built TPRM workflows mapped directly to SAMA CSF and NCA ECC controls, enabling compliance teams to automate assessments, track vendor risk scores, and generate audit-ready reports with minimal manual effort.
Security awareness training is a mandatory control under both SAMA CSF Domain 2 (Cybersecurity Leadership & Governance) and NCA ECC Control 1-3 (Cybersecurity Awareness and Training). For Saudi fintechs, building a compliant and effective program requires more than generic annual training — it demands a structured, role-based, and continuously measured approach.
Program Design Essentials:
1. Role-Based Training Tracks: Not all employees face the same threats. Separate training modules should be developed for general staff, IT/security teams, privileged users, executives, and board members. SAMA CSF specifically requires board-level cybersecurity awareness per Control 2.1.2.
2. Training Frequency: Annual training alone is insufficient. SAMA recommends at minimum annual formal training supplemented by monthly micro-learning, phishing simulations (quarterly), and just-in-time training triggered by security incidents or policy changes.
3. Content Requirements: Programs must cover phishing and social engineering, password hygiene, data handling aligned with PDPL obligations, acceptable use policies, incident reporting procedures, and secure remote work practices.
4. Phishing Simulation: Regular simulated phishing campaigns are considered a baseline control. Track click rates, report rates, and repeat offenders. Results should feed back into targeted remedial training.
5. Measurement & Reporting: SAMA CSF requires documented training completion rates and effectiveness metrics. These must be reported to senior management and can be requested during regulatory examinations.
6. New Employee Onboarding: Security training must be completed before new hires are granted system access, as required under SAMA CSF Control 3.3.2.
Our platform provides a pre-built awareness training framework with content mapped to SAMA, NCA, and PDPL requirements, automated scheduling, completion tracking, and executive dashboards for audit readiness.
Security awareness training is a foundational control under SAMA CSF Domain 2 (Cybersecurity Leadership & Governance), specifically Control 2.3, which mandates that all employees — regardless of role — receive structured, role-appropriate cybersecurity training.
Baseline Requirements:
- Frequency: General security awareness training must occur at least annually for all staff. Privileged users (system admins, developers, finance personnel) require more frequent, role-specific training — typically semi-annually.
- New Hire Onboarding: All new employees must complete security awareness training before or immediately upon gaining system access, per SAMA CSF 2.3.1.
- Phishing Simulations: SAMA CSF strongly recommends periodic simulated phishing campaigns to measure and improve employee resilience. Results should feed back into training content.
Content Requirements:
- Social engineering and phishing awareness
- Password hygiene and MFA usage
- Data classification and handling (aligned with PDPL obligations for personal data)
- Incident reporting procedures
- Acceptable use of IT systems and BYOD policies
- Remote work security practices
Governance & Documentation:
- Maintain training completion records for all employees — SAMA examiners frequently request these during assessments.
- Track completion rates via an LMS (Learning Management System) and report results to senior management and the Board Risk Committee at least annually.
- Tailor training for the Board and C-suite on cyber risk governance topics.
Maturity Consideration: Institutions targeting SAMA CSF Maturity Level 3+ should demonstrate measurable improvements in training effectiveness through metrics such as phishing click-rate reduction over time.
A well-executed awareness program significantly reduces the human-factor risk that remains the top attack vector for Saudi financial institutions.
Identity and Access Management (IAM) is a foundational requirement under SAMA CSF Domain 4 (Access Control), specifically controls 4.2 and 4.3, which mandate that financial institutions enforce least-privilege access, role-based access control (RBAC), and periodic access reviews. Here's a practical implementation roadmap:
1. Privileged Access Management (PAM): Deploy a PAM solution (e.g., CyberArk, BeyondTrust) to manage, monitor, and audit all privileged accounts. SAMA CSF Control 4.3.2 explicitly requires privileged access to be logged and reviewed.
2. Multi-Factor Authentication (MFA): Enforce MFA for all remote access, administrative consoles, and critical banking systems. This also aligns with NCA ECC-1:2018 Article 3-5-3.
3. Access Reviews: Conduct quarterly access recertification campaigns, ensuring managers formally approve or revoke user entitlements. Document all outcomes for audit evidence.
4. Segregation of Duties (SoD): Implement SoD controls, especially in core banking, treasury, and payment systems, to prevent fraud and unauthorized transactions.
5. Identity Lifecycle Management: Automate provisioning and de-provisioning workflows tied to your HR system. Terminated employees' accounts must be disabled within 24 hours per SAMA CSF guidelines.
6. Directory Services Hardening: Secure Active Directory or LDAP with tiered administration models and monitor for Kerberoasting, pass-the-hash, and lateral movement indicators.
Regular IAM audits, mapped against SAMA CSF maturity levels (1–5), will help identify gaps. Aim for at least Maturity Level 3 (Defined) for core IAM controls, with Level 4 (Managed) for privileged access in larger institutions.
Under SAMA CSF Control 3.3.1 and NCA ECC Article 2-7, Saudi financial institutions are required to establish a formal, risk-based Security Awareness Training (SAT) program that covers all employees, contractors, and privileged users. Here's how to structure it effectively:
Program Design:
- Conduct an annual training needs analysis aligned to your threat landscape and role-based risk profiles.
- Develop at least three training tiers: general staff, IT/security staff, and senior management/board.
- Include topics such as phishing recognition, social engineering, password hygiene, data classification under PDPL, and incident reporting procedures.
Delivery & Frequency:
- Mandatory onboarding training for all new joiners within 30 days.
- Annual refresher training for all staff, with quarterly phishing simulations.
- Role-specific deep-dives for privileged users at least twice annually.
Measurement & Reporting:
- Track completion rates, phishing simulation click-through rates, and post-training assessment scores.
- Report SAT effectiveness metrics to the CISO and Board Risk Committee at least semi-annually.
- Maintain training records for a minimum of 3 years to support SAMA examination requests.
Practical Tip: Integrate SAT outcomes into your SAMA CSF maturity assessment under Domain 3 (Human Resources Security). Low awareness scores can negatively impact your maturity level, so remediation plans should be documented and tracked. Linking the program to PDPL awareness—particularly around data handling and breach reporting obligations—adds dual compliance value.
Security Awareness Training is a mandatory control under SAMA CSF (Control 3.3.1) and NCA ECC (Article 2-7), requiring Saudi financial institutions to maintain a structured, ongoing awareness program for all staff. Here's how to implement one effectively:
Program Structure:
- Conduct a role-based training curriculum — differentiate between general staff, IT teams, executives, and privileged users. SAMA CSF requires tailored content for different user groups.
- Deliver training at least annually, with mandatory onboarding sessions for new hires. NCA ECC recommends quarterly refreshers for high-risk roles.
Required Content Areas:
- Phishing and social engineering recognition
- Password hygiene and multi-factor authentication (MFA) use
- Incident reporting procedures
- Acceptable use of organizational assets
- Data classification and handling (aligned with PDPL obligations)
Measurement and Evidence:
- Run simulated phishing campaigns at least quarterly to measure click rates and improve training effectiveness
- Track completion rates and maintain documented records — SAMA examiners will request training logs and completion evidence during assessments
- Conduct pre- and post-training assessments to measure knowledge improvement
Governance:
- Assign program ownership to the Information Security function with executive sponsorship
- Include SAT metrics in your quarterly security reporting to the Board Risk Committee, as required under SAMA CSF Control 3.1.2
Practical Tip: Integrate real-world Saudi-specific threat scenarios (e.g., SADAD phishing, WhatsApp-based fraud) to increase relevance and engagement. Localized Arabic content significantly improves training retention among staff.
Security awareness training is a mandatory control under SAMA CSF Domain 2 (Cybersecurity Leadership & Governance), specifically Control 2.4, which requires all staff — including board members and senior management — to receive role-appropriate cybersecurity education.
Structuring a compliant program involves:
- Audience Segmentation: Design separate training tracks for general staff, IT personnel, privileged users, and executive leadership. SAMA CSF distinguishes between general awareness and technical role-based training requirements.
- Training Frequency: Conduct mandatory awareness sessions at least annually, with additional targeted modules triggered by significant threat events, new regulatory guidance, or after a security incident. Phishing simulation exercises should run quarterly.
- Content Requirements: Programs must cover phishing recognition, social engineering, password hygiene, data handling per PDPL obligations, acceptable use policies, and incident reporting procedures. For fintech staff, include topics specific to open banking and API security risks.
- Measurement & Reporting: Track completion rates, phishing simulation click rates, and pre/post assessment scores. SAMA CSF Control 2.4.3 expects measurable outcomes — present these metrics in the quarterly Cybersecurity Risk Report to the board.
- New Hire Onboarding: Integrate security awareness into the onboarding process so new employees complete baseline training before accessing production systems.
- Documentation & Evidence: Maintain training records, attendance logs, and assessment results for at least three years to support SAMA examinations and ISO 27001 Annex A.7.2.2 audit evidence.
Institutions that gamify training content and integrate real-world threat scenarios relevant to Saudi banking (e.g., CEO fraud targeting remittance operations) typically achieve significantly higher engagement and retention rates.
A well-structured Cyber Incident Response Plan (CIRP) is a regulatory necessity, not just a best practice. Both SAMA CSF and NCA ECC impose specific, enforceable obligations around incident response.
SAMA CSF Requirements: Under SAMA CSF Domain 3 (Cyber Security Operations), Control 3.4 mandates that financial institutions maintain a documented CIRP that is tested at least annually through tabletop exercises or simulations. The plan must define clear escalation paths, incident classification tiers (low, medium, high, critical), and mandatory reporting to SAMA within specific timeframes — critical incidents must be reported within 3 hours of detection.
NCA ECC Requirements: Per NCA ECC Control 2-8 (Cybersecurity Incident and Threat Management), organizations must establish a Cyber Defense Center (CDC) or equivalent function capable of 24/7 monitoring, triage, and response. The ECC also requires post-incident reviews and lessons-learned documentation to be retained for a minimum of 5 years.
Key CIRP Components:
- Preparation: Defined roles (Incident Commander, Technical Lead, Legal/Compliance, Communications), contact lists, and pre-authorized response playbooks.
- Detection & Analysis: Integration with SIEM/SOAR tools; incident triage criteria aligned with SAMA's severity classification.
- Containment, Eradication & Recovery: Step-by-step procedures per incident type (ransomware, DDoS, insider threat, data breach).
- Notification: Regulatory reporting to SAMA and NCA; PDPL breach notification to SDAIA within 72 hours if personal data is involved.
- Post-Incident Review: Root cause analysis, control gap identification, and plan updates.
Regularly testing and refining your CIRP ensures both regulatory compliance and operational resilience.
Third-party risk management (TPRM) is a critical compliance obligation for Saudi financial institutions under SAMA CSF Domain 3.3 (Third-Party Management) and NCA ECC-1:2018 Article 3-3. Here is a structured approach:
1. Vendor Classification & Due Diligence Begin by classifying all vendors based on data sensitivity and criticality. SAMA CSF Control 3.3.1 requires institutions to assess cybersecurity posture before onboarding. Conduct pre-contract security assessments including SOC 2 Type II reviews, ISO 27001 certification checks, and questionnaire-based evaluations.
2. Contractual Obligations Embed cybersecurity clauses in all vendor contracts — covering incident notification timelines (typically within 24–72 hours), right-to-audit provisions, data handling obligations under PDPL Article 21, and minimum security baseline requirements aligned with NCA ECC controls.
3. Continuous Monitoring SAMA CSF Control 3.3.3 mandates ongoing monitoring of third-party performance. Use threat intelligence feeds, security ratings platforms (e.g., BitSight or SecurityScorecard), and conduct periodic reassessments — at least annually for critical vendors.
4. Offboarding Controls Establish secure data deletion and access revocation procedures when vendor relationships end, consistent with PDPL data retention principles.
5. CISO-Level Oversight Maintain a third-party risk register reviewed quarterly by the CISO or risk committee. Escalate critical findings to the board where required under SAMA governance expectations.
Organizations that treat TPRM as a checkbox exercise often discover supply-chain vulnerabilities during incidents. A mature TPRM program should be risk-based, continuously updated, and integrated into your overall cybersecurity governance framework.
Incident response (IR) is a foundational requirement under SAMA CSF Domain 3.6 and NCA ECC Domain 2-10. Saudi banks must maintain a documented, tested, and board-approved IR capability.
Mandatory IR Program Components (SAMA CSF 3.6):
- IR Policy and Plan: A formal Incident Response Plan (IRP) covering preparation, detection, containment, eradication, recovery, and lessons learned — aligned with the NIST CSF Respond function.
- IR Team Structure: Designate a Computer Security Incident Response Team (CSIRT) with clearly defined roles, escalation paths, and 24/7 contact availability for critical incidents.
- Incident Classification: Classify incidents by severity (Critical, High, Medium, Low) with corresponding response SLAs. SAMA expects Critical incidents to trigger immediate executive notification.
- Regulatory Reporting Obligations:
- SAMA: Report significant cyber incidents within 3 hours of detection for critical incidents, followed by a detailed report within 72 hours. SAMA's Cyber Incident Reporting portal (via REGTECH) must be used.
- NCA (via CERT-SA): Report incidents affecting national infrastructure or government-connected systems to CERT-SA promptly.
- PDPL: If the incident involves personal data breach, the National Data Management Office (NDMO) must be notified within 72 hours of discovery.
- Tabletop Exercises: SAMA CSF 3.6.5 requires IR exercises at least annually, with evidence of lessons learned integrated into plan updates.
- Forensic Readiness: Maintain forensic logging capabilities with at least 12 months of log retention to support post-incident investigation.
Failing to report a significant incident to SAMA within the required window is a serious compliance violation — ensure your SOC team has the reporting playbook ready and tested before an incident occurs.
Third-party risk management (TPRM) is a critical obligation under SAMA CSF Domain 3 (Cybersecurity Risk Management) and NCA ECC controls related to supply chain security. Here is a practical implementation approach:
1. Vendor Classification & Due Diligence Classify vendors by criticality — Tier 1 (critical systems access), Tier 2 (sensitive data access), Tier 3 (general services). Per SAMA CSF Control 3.3.1, conduct formal cybersecurity due diligence before onboarding any third party with access to your infrastructure or data.
2. Contractual Security Requirements Embed cybersecurity clauses in all vendor contracts covering: data protection obligations aligned with PDPL, minimum security baseline (ISO 27001 certification preferred), right-to-audit provisions, and breach notification timelines (within 72 hours per SAMA incident reporting guidelines).
3. Continuous Monitoring Do not treat TPRM as a one-time checkbox. Implement ongoing monitoring through annual security questionnaires, periodic penetration test evidence requests from critical vendors, and automated threat intelligence feeds tracking vendor exposure.
4. NCA ECC Alignment NCA ECC Article 2-14 requires organizations to enforce cybersecurity requirements on third parties and service providers operating within their environment. This includes cloud providers, managed security service providers (MSSPs), and software vendors.
5. Practical Tip Maintain a centralized vendor risk register within your GRC platform, updated at least quarterly. Assign ownership to each vendor relationship and escalate critical findings to the CISO and board risk committee.
Non-compliance in this area is one of the most frequently cited gaps in SAMA regulatory examinations.
Under SAMA CSF Domain 3 (Cybersecurity Risk Management), Saudi banks must establish a formal Third-Party Risk Management program that governs the entire vendor lifecycle — from onboarding to offboarding. Specifically, SAMA CSF Control 3.3 mandates that institutions assess the cybersecurity posture of all third parties who access, process, or store bank data.
Key program components include:
1. Vendor Classification: Tier vendors by criticality — critical (core banking, payment processors), high, medium, and low — with risk assessments scaled accordingly.
2. Pre-Onboarding Due Diligence: Require vendors to submit cybersecurity questionnaires, evidence of certifications (ISO 27001, SOC 2), and penetration test results before contract execution.
3. Contractual Obligations: Embed cybersecurity clauses covering data handling, incident notification (within 72 hours per PDPL Article 19), right-to-audit provisions, and compliance with NCA ECC Art. 2-3 where applicable.
4. Ongoing Monitoring: Conduct annual reassessments for critical vendors and trigger event-based reviews following any vendor security incident or significant operational change.
5. Offboarding Controls: Ensure secure data deletion, revocation of all access credentials, and documented confirmation of data return or destruction.
From a practical standpoint, banks should integrate their TPRM platform with the institution's GRC system to maintain a live vendor risk register. SAMA examiners increasingly scrutinize whether banks have real-time visibility into critical vendor posture rather than point-in-time assessments. Aligning TPRM with ISO 27001:2022 Annex A Control 5.19 (Information Security in Supplier Relationships) further strengthens audit readiness across multiple frameworks simultaneously.
Incident response in Saudi banking is governed by multiple overlapping frameworks, creating layered reporting obligations that CISOs must navigate carefully.
SAMA CSF Requirements (Domain 4 — Cybersecurity Resilience): SAMA CSF Control 4.1 requires banks to maintain a formally documented Incident Response Plan (IRP) covering preparation, detection, containment, eradication, recovery, and post-incident review. The IRP must be tested at least annually through tabletop exercises or simulations.
Regulatory Notification Timelines:
- SAMA: Banks must notify SAMA of significant cybersecurity incidents within 3 hours of detection via the SAMA Cybersecurity Notification Portal. A follow-up detailed report is required within 72 hours covering root cause, affected systems, data exposure, and remediation steps.
- PDPL (Article 19): If personal data of Saudi residents is compromised, the National Data Management Office (NDMO) must be notified within 72 hours, and affected individuals notified without undue delay where there is high risk to their rights.
- NCA ECC: Critical infrastructure entities must additionally report to the National Cybersecurity Authority through the CERT-SA reporting channel.
Practical Guidance: Banks should maintain pre-approved communication templates for each regulator to avoid delays under pressure. Designate a dedicated Incident Response Coordinator who owns regulatory notifications. Conduct quarterly reviews of the incident classification matrix to ensure all staff distinguish between a security event, incident, and crisis — each triggering different escalation paths. Align playbooks with NIST CSF's Respond function (RS.CO-2, RS.CO-3) to maintain internationally recognized standards alongside local compliance.
Under SAMA CSF Control Domain 3.5 (Third-Party Management), Saudi banks must establish a comprehensive TPRM program that covers the full vendor lifecycle — from onboarding to offboarding. Here is a practical framework to follow:
1. Vendor Classification & Risk Tiering: Categorize all vendors by criticality (Tier 1: critical, Tier 2: significant, Tier 3: low-risk). Critical vendors handling customer data or core banking functions require the most rigorous due diligence.
2. Pre-Onboarding Due Diligence: Before contracting, assess vendors against SAMA CSF controls, NCA ECC requirements, and ISO 27001 alignment. Request evidence of certifications, penetration test results, and data handling practices especially under PDPL obligations.
3. Contractual Safeguards: Contracts must include cybersecurity obligations, right-to-audit clauses, SLA definitions for incident notification (per SAMA CSF 3.5.3), data residency requirements, and exit/termination procedures.
4. Continuous Monitoring: Conduct annual reassessments for Tier 1 vendors and biennial reviews for Tier 2. Use automated tools to monitor vendor security posture, track vulnerability disclosures, and assess compliance drift.
5. Incident Notification Requirements: Vendors must notify the bank within defined timeframes (typically 24–72 hours) of any security incident that may impact bank systems or customer data.
6. Cloud & SaaS Vendors: For cloud service providers, additional controls per SAMA Cloud Computing Guidelines apply, including data classification, shared responsibility matrix documentation, and exit strategy planning.
A mature TPRM program not only satisfies SAMA CSF expectations but also reduces supply chain risk — a growing threat vector for Saudi financial institutions.
SAMA CSF dedicates a specific domain to third-party and outsourcing risk, requiring financial institutions to maintain a formal Vendor Risk Management (VRM) program that spans the entire vendor lifecycle — from onboarding through offboarding. Per SAMA CSF Control 3.3.1, institutions must conduct risk-based due diligence on all third parties before engagement, assessing their cybersecurity posture, data handling practices, and regulatory compliance status.
Key program components include:
1. Vendor Classification & Tiering: Categorize vendors by criticality (e.g., Tier 1 for core banking system providers, Tier 3 for low-risk suppliers). Apply proportionate controls based on the data and system access each vendor holds.
2. Contractual Security Requirements: All contracts must embed cybersecurity clauses covering incident notification timelines (typically ≤72 hours), right-to-audit provisions, data handling obligations aligned with PDPL, and compliance with NCA ECC where applicable.
3. Continuous Monitoring: Annual reassessments are insufficient for high-risk vendors. Implement continuous monitoring via security ratings platforms, periodic questionnaires, and mandatory penetration test evidence submission.
4. Concentration Risk: SAMA explicitly expects institutions to assess and mitigate concentration risk — where multiple critical functions depend on a single third party (e.g., a dominant cloud provider).
5. Fourth-Party Risk: Extend due diligence to subcontractors used by your vendors, particularly for outsourced IT and managed security services.
Practically, institutions should maintain a centralized vendor risk register, assign ownership to each vendor relationship, and report aggregated third-party risk exposure to the Board Risk Committee quarterly. Alignment with ISO 27001 Annex A.15 further strengthens your VRM framework and supports audit readiness.
SAMA CSF dedicates Domain 4 (Third-Party Management) to vendor risk, requiring financial institutions to establish a formal Third-Party Risk Management (TPRM) framework that covers the full vendor lifecycle — from initial due diligence to contract termination.
Key requirements include:
Pre-engagement: Conduct cybersecurity risk assessments before onboarding any vendor with access to systems or data. Classify vendors by criticality (critical, significant, standard) per SAMA CSF Control 4.1.2.
Contractual controls: Ensure contracts mandate security standards, right-to-audit clauses, incident notification obligations (typically within 72 hours), and data protection terms aligned with PDPL.
Ongoing monitoring: Perform periodic reassessments — at minimum annually for critical vendors. This includes reviewing SOC 2 Type II reports, ISO 27001 certificates, or conducting direct security assessments.
Concentration risk: SAMA specifically requires banks to assess and manage over-reliance on single vendors, particularly cloud and technology providers.
Exit strategy: Maintain documented exit plans for critical vendors to ensure business continuity under SAMA CSF Control 4.3.1.
Practically, build a vendor register categorizing all third parties, automate reassessment workflows through your GRC platform, and align your questionnaires with SAMA CSF, NCA ECC, and ISO 27001 Annex A.15 controls. Ensure your information security team signs off on all critical vendor engagements before the procurement team finalizes contracts. Many Saudi banks also require critical vendors to demonstrate NCA ECC compliance, especially when those vendors operate within the Kingdom.
Third-party risk management (TPRM) is a critical obligation under SAMA CSF Domain 4 (Third Party Management), which requires Saudi financial institutions to establish a formal, risk-based vendor governance framework. Here's how to structure it effectively:
1. Vendor Classification (SAMA CSF Control 4.1): Categorize all vendors by criticality — critical, high, medium, and low — based on data access, system integration depth, and business impact. Critical vendors supporting core banking or payment infrastructure require the most rigorous oversight.
2. Pre-Onboarding Due Diligence: Before contracting, conduct cybersecurity assessments covering ISO 27001 certification status, penetration testing history, data handling practices, and incident response capabilities. Require vendors to complete a standardized security questionnaire aligned with NCA ECC Art. 3-4 controls.
3. Contractual Security Obligations (SAMA CSF Control 4.3): Embed mandatory cybersecurity clauses covering right-to-audit, breach notification timelines (ideally within 24–72 hours), data residency requirements under PDPL, and compliance with SAMA's outsourcing regulations.
4. Continuous Monitoring: Implement ongoing risk monitoring using automated vendor risk scoring tools, periodic reassessments (annually for critical vendors, biennially for others), and real-time threat intelligence feeds related to your vendor ecosystem.
5. Incident and Exit Management: Define clear escalation paths if a vendor suffers a breach, and maintain documented exit strategies to ensure business continuity without vendor lock-in.
SAMA also requires that outsourced critical functions remain under the institution's effective control — meaning your internal team must retain oversight authority at all times. Document all TPRM activities in a centralized register reviewable by SAMA examiners during assessments.
SAMA CSF Domain 3.3 (Cybersecurity Incident Management) mandates that all Saudi banks and financial institutions maintain a formally documented and regularly tested incident response (IR) program. Here's what compliance requires and how CISOs should build it:
Mandatory IR Program Components (SAMA CSF Control 3.3.1–3.3.5):
- A formally approved Incident Response Plan (IRP) covering detection, containment, eradication, recovery, and lessons learned phases
- Defined severity classification levels aligned to business impact
- Clear escalation procedures, including board and executive notification thresholds
- Dedicated IR roles and responsibilities documented in a RACI matrix
Regulatory Notification Obligations: SAMA requires institutions to report significant cybersecurity incidents to SAMA within defined timelines. Incidents affecting critical financial infrastructure or customer data must be reported promptly — typically within 24 hours of discovery for high-severity events. Coordinate simultaneously with NCA's Cybersecurity Operations Center (CSOC) for incidents that may have national significance.
Practical Build-Out Steps for CISOs:
- Develop playbooks for your top 10 incident scenarios: ransomware, insider threat, DDoS on banking platforms, SWIFT fraud, mobile banking compromise, etc.
- Integrate your SIEM/SOAR with the IRP workflow to enable automated alerting and ticket creation
- Conduct tabletop exercises at minimum quarterly; full simulation exercises annually
- Align forensic evidence preservation procedures with Saudi legal requirements to maintain admissibility
- Cross-reference NIST CSF's Respond and Recover functions for international best-practice alignment
Document all exercises, incidents, and post-incident reviews in a centralized log available to SAMA examiners. Continuous improvement cycles are a key evaluation criterion during SAMA assessments.
SAMA CSF Domain 4.5 mandates that all Member Organizations establish a formal Cybersecurity Incident Management capability. For CISOs at Saudi banks and fintechs, this translates into a structured program with the following key requirements:
Regulatory Reporting Obligations: Per SAMA CSF Control 4.5.3 and SAMA's Cyber Incident Reporting Framework, significant incidents must be reported to SAMA within 72 hours of detection. Incidents affecting payment systems or customer data may also trigger parallel reporting to NCA (per ECC-2: 2-3) and SDAIA under PDPL Article 24.
IR Program Components (SAMA CSF 4.5):
- Documented Incident Response Plan (IRP) reviewed at least annually
- Defined incident classification matrix (P1–P4 severity levels)
- Designated Incident Response Team (IRT) with clear roles and escalation paths
- 24/7 monitoring capability or SOC coverage (in-house or managed)
- Evidence preservation and forensic investigation procedures
- Post-incident review and lessons-learned process
NIST CSF Alignment: Structure your IR capability around NIST's five functions — Identify, Protect, Detect, Respond, Recover — which maps well to SAMA CSF's control domains.
Tabletop Exercises: SAMA CSF requires periodic IR drills. Conduct at least one tabletop exercise annually, simulating scenarios such as ransomware, BEC fraud, or data exfiltration. Document results and remediation actions.
Practical Tip: Integrate your IR workflows directly into your GRC platform to auto-generate incident tickets, track SLA compliance with SAMA reporting timelines, and produce audit-ready evidence for SAMA examinations.
Under SAMA CSF Domain 4 (Third-Party Management), Saudi financial institutions must implement a structured, lifecycle-based approach to vendor risk. Here's a practical framework:
1. Pre-Onboarding Due Diligence Before contracting any third party, conduct a cybersecurity risk assessment covering the vendor's security posture, certifications (e.g., ISO 27001), and compliance with NCA ECC controls. Classify vendors by criticality — Tier 1 (critical systems access), Tier 2 (sensitive data access), Tier 3 (general services).
2. Contractual Security Requirements (per SAMA CSF 4.3) Ensure all vendor contracts include mandatory clauses for: data protection aligned with PDPL, incident notification within 72 hours, right-to-audit provisions, and minimum security baselines mirroring your internal standards.
3. Continuous Monitoring Establish quarterly security reviews for Tier 1 vendors and annual reviews for Tier 2/3. Use automated vendor risk platforms where possible. Review vendor access logs, patch compliance, and any reported breaches.
4. Concentration Risk SAMA also expects institutions to assess concentration risk — if multiple critical services rely on a single vendor (e.g., a cloud provider), your BCP must account for vendor failure scenarios.
5. Offboarding Controls Upon contract termination, revoke all access immediately, retrieve or securely destroy data per PDPL Article 19, and document the offboarding in your risk register.
A mature TPRM program integrates with your ISO 27001 Annex A.15 controls and feeds directly into your board-level risk reporting cycle. SAMA inspectors increasingly focus on vendor risk during regulatory examinations — treat this as a first-class risk domain.
SAMA CSF Domain 3 (Cybersecurity Operations & Resilience) mandates a formal, tested incident response capability. Here is what a CISO must build:
1. Documented IR Policy and Playbooks (SAMA CSF 3.3) Maintain a board-approved IR policy with specific playbooks for high-probability scenarios: ransomware, data breach, DDoS against banking systems, and insider threat. Each playbook must define roles, escalation paths, and communication templates.
2. Classification and Severity Thresholds Adopt a clear severity matrix (P1–P4). Critical incidents affecting customer funds, core banking availability, or involving confirmed data exfiltration must escalate to the CISO and CEO within 1 hour.
3. Regulatory Notification Obligations SAMA requires financial institutions to notify SAMA's cybersecurity team within 72 hours of detecting a significant cyber incident. Coordinate this with PDPL Article 26 obligations — if personal data is involved, the National Data Management Office (NDMO) must also be notified. Maintain a dual-notification checklist.
4. Digital Forensics and Evidence Preservation Ensure your SOC or retained IR firm follows a proper chain-of-custody process for digital evidence — this is critical if legal proceedings or regulatory investigation follow.
5. Post-Incident Review and Lessons Learned Within 2 weeks of incident closure, conduct a structured post-mortem. Findings must feed back into your risk register, control improvements, and training program per ISO 27001 Clause 10.1.
6. Annual IR Drills Conduct at least one tabletop exercise and one technical simulation annually. SAMA inspectors will ask for evidence of testing — document everything including attendance, scenarios, and action items.
SAMA CSF Domain 4 (Operational Resilience) mandates that financial institutions establish, document, and regularly test Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP). Per SAMA CSF Control 4.3, institutions must define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for all critical systems, with annual testing at minimum.
Practical implementation steps include:
- Business Impact Analysis (BIA): Identify critical business processes and their dependencies, classifying systems by criticality tier. Core banking and payment systems typically require RTOs of less than 4 hours.
- Scenario-Based Testing: Conduct tabletop exercises, parallel run tests, and full failover drills. SAMA expects evidence of testing results, gaps identified, and remediation actions.
- Third-Party Dependencies: Map and test continuity plans for critical vendors and cloud providers, especially given SAMA's outsourcing guidelines.
- ISO 22301 Alignment: Aligning your BCP framework with ISO 22301 strengthens SAMA CSF compliance and provides an internationally recognized structure for documentation and audits.
- Board Reporting: SAMA CSF requires that BCP/DRP status and test results be reported to senior management and the Board Risk Committee annually.
Failure to demonstrate tested and effective continuity plans is one of the most common findings in SAMA cybersecurity assessments. Ensure your DRP includes cyber incident scenarios such as ransomware attacks, which are increasingly relevant for Saudi financial institutions.
Under SAMA CSF Domain 4 (Third-Party Management), Saudi banks must implement a structured, risk-based vendor oversight program covering the entire supplier lifecycle. Here's a practical implementation roadmap:
1. Vendor Classification & Risk Tiering Classify all third parties based on data access, system criticality, and service type. SAMA CSF Control 4.1.2 requires you to distinguish between critical, significant, and standard suppliers, applying proportionate controls accordingly.
2. Pre-Onboarding Due Diligence Before contracting, conduct security assessments that include: review of the vendor's ISO 27001 or equivalent certification, network architecture diagrams, incident response procedures, and PDPL compliance posture if they process personal data.
3. Contractual Security Requirements All vendor contracts must embed cybersecurity obligations per SAMA CSF Control 4.2.1, including: right-to-audit clauses, breach notification timelines (typically within 72 hours aligned with PDPL Article 28), data handling standards, and subcontractor disclosure requirements.
4. Continuous Monitoring Conduct annual security assessments for critical vendors and bi-annual assessments for significant ones. Use automated tools to monitor vendor risk scores, and track any changes in their security posture or regulatory standing.
5. Offboarding Controls Establish formal offboarding procedures ensuring secure data deletion, revocation of all access credentials, and documented confirmation of data return or destruction.
A common gap we see is treating third-party risk as a one-time procurement checklist rather than an ongoing governance function. Appoint a dedicated vendor risk owner and integrate third-party findings into your board-level cybersecurity reporting to demonstrate SAMA CSF maturity at Tier 3 and above.
Third-party risk management (TPRM) is a critical obligation under SAMA CSF Domain 3.3 and NCA ECC-1:2-6, requiring Saudi financial institutions to maintain a structured vendor risk program. Here's a practical implementation roadmap:
1. Vendor Classification & Tiering Categorize vendors by criticality — Tier 1 (critical system access), Tier 2 (significant data access), Tier 3 (limited exposure). SAMA CSF Control 3.3.1 mandates formal risk classification before onboarding.
2. Due Diligence & Contractual Controls Conduct pre-onboarding cybersecurity assessments including security questionnaires, ISO 27001 certification verification, and penetration testing results review. Contracts must include right-to-audit clauses, incident notification SLAs (typically 24–72 hours), and data handling obligations aligned with PDPL Articles 18–21.
3. Continuous Monitoring Implement ongoing monitoring using threat intelligence feeds and periodic reassessments (at minimum annually for Tier 1 vendors). NCA ECC requires evidence of vendor compliance documentation being maintained.
4. Concentration Risk SAMA specifically flags concentration risk where multiple critical services rely on a single vendor — this must be flagged in your risk register and escalated to the Board Risk Committee.
5. Exit Strategy Document vendor exit plans ensuring business continuity per SAMA CSF Control 3.3.6, including data recovery, transition timelines, and service continuity assurance.
Practically, your GRC platform should automate vendor risk scoring, track assessment lifecycles, and generate Board-ready TPRM dashboards to demonstrate regulatory compliance during SAMA examinations.
Third-party risk management (TPRM) is a critical obligation under SAMA CSF Domain 4 (Third-Party Management), requiring Saudi financial institutions to implement a structured, lifecycle-based approach to vendor oversight.
Key Requirements:
- Vendor Classification & Due Diligence (SAMA CSF 4.1): Classify vendors by criticality — Tier 1 (critical/core banking), Tier 2 (important), Tier 3 (standard). Conduct cybersecurity due diligence before onboarding, including reviewing SOC 2 Type II reports, ISO 27001 certifications, and penetration testing results.
- Contractual Controls (SAMA CSF 4.2): Embed mandatory cybersecurity clauses covering data protection, incident notification (within 24–48 hours), right-to-audit, and compliance with SAMA CSF and PDPL obligations.
- Continuous Monitoring: Perform annual security assessments for Tier 1 vendors and biennial reviews for Tier 2. Use automated threat intelligence feeds and vendor risk platforms to monitor ongoing risk posture.
- Concentration Risk: SAMA also expects institutions to assess concentration risk — over-reliance on a single vendor (e.g., a sole cloud provider) must be documented with contingency plans.
- Offboarding Controls: Ensure data deletion, access revocation, and exit procedures are formally managed upon vendor termination.
Practical Tip: Establish a Vendor Risk Committee with representation from IT, Legal, Procurement, and the CISO's office. Maintain a centralized vendor risk register updated quarterly. For fintechs relying heavily on SaaS providers, map each vendor's data access to PDPL Article 29 obligations to ensure cross-border data transfer compliance is addressed simultaneously.
Business Continuity Management (BCM) is a foundational requirement under SAMA CSF Domain 6 (Cyber Resilience) and strongly aligns with ISO 22301 (Business Continuity Management Systems). Saudi banks must treat BCM not as a checkbox exercise but as a living, tested program integrated with cybersecurity incident response.
SAMA CSF BCM Requirements (Domain 6):
- Business Impact Analysis (BIA): Identify critical business processes, systems (especially core banking, payment infrastructure, and SWIFT), and establish Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). SAMA expects RTOs for Tier 1 systems to be less than 4 hours.
- BCM Policy & Governance: The BCM program must be approved at Board level, with a designated BCM Owner (often the COO or CISO) and reviewed annually.
- Disaster Recovery Plans (DRP): Technical recovery runbooks must exist for all critical systems, with documented failover procedures to geographically separated data centers (SAMA mandates primary and DR sites within the Kingdom).
- Crisis Communication Plans: Define communication trees for internal staff, SAMA notifications, customer communications, and media handling during a major disruption.
ISO 22301 Alignment:
- Conduct a formal gap assessment against ISO 22301 clauses 6–10 to identify BCM maturity gaps.
- ISO 22301 Clause 8.5 specifically addresses testing requirements — tabletop exercises, functional drills, and full failover tests.
Testing Cadence:
- Tabletop exercises: Twice annually.
- Technical DR failover tests: Annually.
- Full-scale business continuity exercises: Every two years.
Practical Tip: Integrate BCM testing scenarios with cybersecurity incident response drills. A ransomware simulation that triggers the DR plan is far more valuable than isolated testing. Document all lessons learned and update plans within 30 days post-exercise. Ensure SAMA is notified per CSF reporting timelines if a real incident triggers BCM activation.
Business continuity and cyber resilience represent one of the most rigorously assessed domains for Saudi financial institutions, with obligations spanning both SAMA CSF and NCA ECC frameworks.
SAMA CSF Requirements (Domain 3 — Cybersecurity Resilience): SAMA CSF Control 3.3 mandates that member organizations develop, maintain, and regularly test a Cyber Resilience Plan (CRP) that specifically addresses cyber-triggered disruptions — distinct from general IT disaster recovery. Key requirements include:
- Recovery Time Objectives (RTO): Core banking systems must have RTOs defined and tested, typically ≤4 hours for Tier-1 institutions.
- Recovery Point Objectives (RPO): Data recovery capabilities must be validated against defined RPOs with evidence of backup integrity testing.
- Tabletop and Simulation Exercises: At minimum annual cyber resilience exercises simulating ransomware, DDoS, or data breach scenarios involving senior leadership and the CISO.
- Third-Party Dependencies: BCP must document and test recovery procedures that account for critical vendor or cloud provider outages.
NCA ECC Alignment (Article 2-13 — Business Continuity): NCA ECC extends these requirements to government-affiliated financial entities and critical national infrastructure, mandating:
- Formal BCM policy approved at executive level.
- Annual BIA (Business Impact Analysis) reviews with cybersecurity scenarios explicitly included.
- Integration of cybersecurity incident response timelines within BCP documentation.
Practical Integration Steps:
- Map SAMA CSF CRP controls against ISO 22301 (Business Continuity Management) for international alignment.
- Include cloud failover and data sovereignty provisions in BCP for institutions using hyperscaler environments.
- Conduct joint exercises between cybersecurity and BCM teams — SAMA examiners look for this integration evidence.
Our vCISO consulting service helps institutions build, test, and document BCPs that satisfy both SAMA and NCA examiners.
Under SAMA CSF Domain 4 (Cybersecurity Resilience), Saudi banks must establish a robust Business Continuity Management program that addresses cyber-induced disruptions specifically — not just traditional operational risks.
Core Requirements:
- Business Impact Analysis (BIA): Identify critical systems, acceptable Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO) per SAMA CSF Control 4.1. For core banking systems, SAMA typically expects RTOs under 4 hours.
- BCM Policy & Plans: Maintain documented Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) aligned with SAMA CSF Control 4.2, covering cyber incident scenarios such as ransomware, DDoS, and data destruction attacks.
- Crisis Communication: Define escalation paths, internal notification trees, and SAMA regulatory notification timelines (within 72 hours for major incidents per SAMA incident reporting guidelines).
Testing Requirements: SAMA CSF mandates annual testing at minimum, but best practice for Tier-1 banks includes:
- Tabletop exercises (quarterly) simulating cyber breach scenarios
- Functional drills testing failover to DR sites
- Full simulation tests annually involving IT, operations, legal, and senior management
Test results must be documented, gaps tracked as findings, and remediation plans presented to the Board Risk Committee.
NCA ECC Alignment: NCA ECC Article 2-14 also requires BCM integration with cybersecurity controls, so dual-framework mapping is recommended.
Our platform provides pre-built BCM control templates mapped to both SAMA CSF and NCA ECC, with automated testing schedule reminders and gap tracking dashboards.
SAMA CSF Control 3.3.1 mandates that all financial institutions implement a formal cybersecurity awareness and training program covering all employees, contractors, and third parties with system access. The program must be risk-based, role-specific, and conducted at least annually — with additional targeted training for privileged users and IT/security staff.
To build a compliant and effective program, Saudi banks and fintechs should:
1. Establish a Training Policy: Document objectives, target audiences, frequency, and measurement criteria aligned with SAMA CSF and NCA ECC Section 2-7.
2. Segment by Role: General staff should receive phishing awareness, password hygiene, and data handling training. IT teams need technical modules covering secure development, access control, and incident reporting. Executives require risk governance and regulatory obligation briefings.
3. Use Simulated Attacks: Run quarterly phishing simulations to measure human risk. Track click rates and report-to-IT rates as KPIs.
4. Integrate Regulatory Context: Include PDPL obligations (e.g., data subject rights, breach notification duties) to ensure employees understand their personal liability under Saudi law.
5. Maintain Records: SAMA examiners expect evidence of completion rates, assessment scores, and remediation actions for failed participants. Maintain audit-ready logs for at least three years.
6. Measure Effectiveness: Conduct pre/post assessments and annual program reviews. Link training metrics to your cybersecurity risk register.
A mature awareness program not only satisfies SAMA CSF compliance but also directly reduces the likelihood of social engineering attacks — the leading initial access vector in Saudi financial sector breaches.
Security awareness training is a foundational requirement under SAMA CSF and is critical for reducing human-factor risks in Saudi financial institutions.
SAMA CSF Requirements: Under SAMA CSF Domain 3 (Cybersecurity Governance), Control 3.2.2 mandates that all employees, contractors, and third-party users with access to organizational systems must complete role-based cybersecurity awareness training. The training program must be:
- Conducted at least annually for all staff
- Delivered upon onboarding for new employees
- Tailored to specific roles (e.g., privileged users, executives, IT staff)
- Documented with completion records maintained for audit purposes
Designing an Effective Program:
- Role-Based Curriculum: Develop separate training tracks for general staff (phishing awareness, password hygiene, social engineering), IT and security teams (secure coding, incident handling), and executives (cyber risk governance, regulatory obligations under SAMA and NCA)
- Phishing Simulations: Run quarterly simulated phishing campaigns and use click-rate data to measure human risk exposure. Link simulation results to targeted micro-training
- Regulatory Content Integration: Include modules specifically covering PDPL obligations, SAMA CSF responsibilities, and reporting duties under NCA ECC Art. 3-3 to build compliance literacy
- Metrics and Reporting: Track completion rates, simulation performance, and knowledge assessment scores. Report quarterly to the CISO and Board Risk Committee as part of your GRC dashboard
- Continuous Reinforcement: Supplement annual training with monthly security newsletters, awareness posters in Arabic, and real-time alerts following emerging threats relevant to the Saudi financial sector
An underdeveloped awareness program is consistently flagged during SAMA CSF assessments. Institutions scoring Maturity Level 1 or 2 in this domain face increased scrutiny and remediation requirements.
Security Awareness Training (SAT) is a mandatory control under both SAMA CSF (Domain 3.6 — Cybersecurity Awareness and Training) and NCA ECC (Control 2-6), and regulators increasingly scrutinize program maturity during assessments. A compliant and effective program should include the following elements:
Role-Based Training Curricula: Generic training is insufficient. Develop tailored content for executive leadership, IT and security staff, privileged users, and general employees. SAMA CSF 3.6.2 specifically requires role-specific awareness programs.
Mandatory Induction and Annual Refresh: All staff — including contractors and third parties with system access — must complete onboarding security training and annual refreshers. Track completion rates as a KPI for regulatory evidence.
Phishing Simulation Exercises: Conduct regular simulated phishing campaigns (at minimum quarterly) to measure real-world susceptibility. Results must be documented and used to refine training content. NCA ECC Control 2-6-3 references awareness exercises as a required activity.
Specialized Training for Security Teams: Your SOC analysts, incident responders, and CISO staff require advanced training covering threat intelligence, forensics, and framework-specific knowledge (SAMA CSF, NCA ECC). Align certifications like CISSP, CISM, or CEH to role requirements.
Metrics and Reporting: Report SAT metrics — completion rates, phishing click-through rates, and training effectiveness scores — to senior management and the board at least annually, as required under SAMA CSF 3.6.1.
Localization: Deliver content in Arabic to ensure comprehension and cultural relevance across your Saudi workforce. An Arabic-first approach significantly improves engagement and retention.
Business Continuity Management (BCM) is a mandatory compliance domain under SAMA CSF Control Domain 6, requiring Saudi banks to maintain resilient operations even during major cyber incidents or operational disruptions. Achieving maturity in this domain requires both a well-structured program and a rigorous testing cadence.
Program Design Requirements (per SAMA CSF 6.1–6.4):
- Conduct a formal Business Impact Analysis (BIA) to identify critical business functions and their Maximum Tolerable Downtime (MTD).
- Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for each critical system — SAMA typically expects RTOs of 4 hours or less for core banking functions.
- Establish a documented Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) that cover cyber incident scenarios, not just natural disasters.
- Ensure BCM governance is owned at the board and senior management level, with a designated BCM Officer.
Testing Requirements:
- SAMA CSF requires BCM tests at least annually, with results documented and reviewed by senior management.
- Testing types should progress from tabletop exercises to full simulation drills that include IT failover, data recovery validation, and communication tree activation.
- Penetration testing findings should feed directly into BCM scenario updates.
- Align BCM testing schedules with NCA ECC Article 3-7 resilience controls for government-regulated entities.
Practical Guidance:
- Maintain an always-current contact directory and escalation matrix.
- Test backup restoration — not just backup creation — at least quarterly.
- Ensure cloud-based recovery environments are validated against the same RTO/RPO commitments as on-premise systems.
- Document lessons learned after every test and track remediation actions to closure.
Business Continuity Management (BCM) is a critical obligation for Saudi financial institutions under SAMA CSF Domain 4 (Cyber Resilience) and specifically Control 4.3, which mandates that banks establish, test, and maintain robust BCM and Disaster Recovery (DR) programs aligned with cybersecurity risks.
Key requirements include:
1. Business Impact Analysis (BIA): Identify critical business processes, systems, and assets. Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for each. Per SAMA CSF Control 4.3.2, RTOs must reflect the criticality of financial services.
2. BCM Policy and Plan: Develop a formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) approved by senior management and the Board. Plans must cover cybersecurity incident scenarios, including ransomware and data breaches.
3. Testing and Exercises: SAMA CSF Control 4.3.5 requires regular BCM testing — at minimum annually — including tabletop exercises, simulation drills, and full failover tests. Results must be documented and gaps remediated.
4. Third-Party and Cloud Dependencies: BCM plans must address continuity risks from critical third-party providers and cloud platforms, ensuring contractual SLA alignment.
5. Regulatory Reporting: Any activation of the BCP due to a cyber incident must be communicated to SAMA within defined timelines per the Cyber Incident Reporting Framework.
Practical Tip: Integrate your BCM program with your ISO 22301 certification roadmap to demonstrate dual compliance. Use tabletop scenarios specific to Saudi banking threats — such as payment system outages and core banking disruptions — to make exercises realistic and regulatorily defensible.
SAMA CSF dedicates Domain 4 (Cyber Resilience) to Business Continuity Management, making it a mandatory capability for all regulated banks and financial institutions. A compliant BCM program must cover the following pillars: (1) Business Impact Analysis (BIA) — identify critical business functions, recovery time objectives (RTO), and recovery point objectives (RPO) per SAMA CSF Control 4.1. Critical banking systems (core banking, payment rails, internet banking) typically require RTOs under 4 hours. (2) BCM Policy and Plan Development — document Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) addressing cybersecurity-specific scenarios including ransomware, DDoS, and data center failure. Plans must integrate with the institution's Incident Response Plan per SAMA CSF Control 3.5. (3) Testing and Validation — SAMA CSF Control 4.3 mandates that BCM plans be tested at least annually. Testing types should progress from tabletop exercises and walkthrough drills to full simulation exercises involving IT, operations, and executive leadership. Results must be documented, gaps remediated, and plans updated accordingly. (4) Third-Party and Outsourcing Continuity — BCM must extend to critical service providers, ensuring their RTOs align with the bank's requirements. (5) Regulatory Reporting — significant disruptions must be reported to SAMA in accordance with the Cyber Incident Reporting Framework. Aligning BCM with ISO 22301 (Business Continuity Management Systems) provides an internationally recognized structure that satisfies SAMA's expectations and prepares institutions for regulatory examination. Annual SAMA inspections frequently assess BCM maturity using a 1–4 capability scale.
SAMA CSF Domain 4 — Resilience — mandates that member organizations establish, implement, and continuously improve a Business Continuity Management (BCM) program that directly integrates cybersecurity resilience. Here is how Saudi banks should approach this: (1) BIA and Risk Assessment — conduct a Business Impact Analysis (BIA) per SAMA CSF Control 4.1 to identify critical business processes, acceptable downtime (RTO), and data loss tolerances (RPO). Cybersecurity-driven scenarios — ransomware, DDoS, and insider sabotage — must be explicitly included. (2) BCP and DRP Documentation — develop Business Continuity Plans and Disaster Recovery Plans that are reviewed and updated at least annually or after significant changes, per SAMA CSF Control 4.3. (3) Cyber Incident Integration — BCM plans must be tightly linked to your Cyber Incident Response Plan (CIRP). SAMA expects that a cyber event triggering BCM activation follows defined escalation and communication protocols reaching executive and board level. (4) Testing Regime — SAMA CSF requires regular testing: tabletop exercises at minimum annually, and full simulation or failover tests at least every two years. Test results must be documented and remediation actions tracked to closure. (5) Third-Party Dependencies — BCM must account for critical vendor and infrastructure dependencies, particularly for payment processing, core banking, and cloud services. (6) Regulatory Reporting — SAMA expects BCM test summaries and any major incidents affecting continuity to be reportable. Practically, CISOs should ensure BCM ownership sits with a cross-functional team including IT, operations, legal, and communications, with CISO oversight on the cyber resilience components. Align BCM documentation with ISO 22301 to satisfy both SAMA expectations and international best practice simultaneously.
Business Continuity Management (BCM) for Saudi financial institutions is governed by multiple overlapping frameworks. SAMA CSF Subdomain 3.3 mandates a comprehensive BCM program, while NCA ECC Article 2-13 sets specific resilience requirements for critical national infrastructure entities — which includes major banks and payment processors.
Step 1 — Business Impact Analysis (BIA): Identify and prioritize critical business functions, systems, and interdependencies. Per SAMA CSF Control 3.3.1, institutions must define Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) for each critical process. Typical SAMA expectations for core banking systems are RTOs under 4 hours and RPOs under 1 hour.
Step 2 — Risk Assessment: Conduct a threat-based risk assessment covering cyber incidents, natural disasters, third-party failures, and pandemic scenarios. Link this to your existing SAMA CSF Risk Management framework (Subdomain 2.1).
Step 3 — Plan Development: Develop four interconnected plans: Business Continuity Plan (BCP), Disaster Recovery Plan (DRP), Crisis Communication Plan, and IT Incident Response Plan. NCA ECC requires these plans to address cyberattack scenarios specifically, not just physical disruptions.
Step 4 — Testing & Exercises: SAMA CSF Control 3.3.5 requires at minimum an annual full simulation exercise and quarterly tabletop exercises for critical systems. Results must be documented and remediation tracked.
Step 5 — Continuous Improvement: BCM plans must be reviewed after any significant incident, major system change, or annually. Appoint a dedicated BCM Owner and establish a Steering Committee with executive representation.
Also ensure alignment with SAMA's dedicated BCM circular (issued 2022) which introduced stricter testing documentation requirements for Tier-1 banks.
Under SAMA CSF Domain 4 (Resilience), Saudi banks must establish a comprehensive Business Continuity Management (BCM) program that addresses both operational resilience and cyber-specific recovery scenarios. Key requirements include:
Per SAMA CSF Control 4.1 – Business Continuity Planning:
- Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for all critical systems, with SAMA typically expecting RTOs of 4 hours or less for core banking functions.
- Conduct Business Impact Analyses (BIA) annually or whenever significant changes occur to identify critical processes, dependencies, and acceptable downtime thresholds.
Per SAMA CSF Control 4.2 – Disaster Recovery:
- Maintain a tested, documented Disaster Recovery Plan (DRP) that is separate from but aligned with the BCP.
- DR environments must be geographically separated — SAMA recommends a minimum of 50km between primary and secondary data centers for systemically important banks.
- Full DR tests must be conducted at least annually, with results documented and gaps remediated within defined timelines.
Cyber-Specific BCM Additions:
- BCM plans must now explicitly address ransomware scenarios, including offline backups tested for integrity quarterly.
- Incident Response Plans (IRP) must be integrated into BCM workflows so cyber events trigger appropriate BCP activation.
Practical Guidance: Most Saudi banks fall short by treating BCM as an IT exercise rather than an enterprise-wide program. Involve business unit owners in BIA workshops, ensure executive sign-off on RPO/RTO commitments, and coordinate BCP drills with SAMA's supervisory expectations. Align your BCM documentation with ISO 22301 standards to demonstrate maturity during SAMA examinations.
Building a cyber incident response plan (IRP) for a Saudi financial institution requires aligning with SAMA CSF Control Domain 3.4 (Cyber Incident Management) and NCA's Cybersecurity Event Management guidelines. Both frameworks demand a formally documented, tested, and board-approved IRP that covers the full incident lifecycle.
Your IRP must define six core phases: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. Critically, it must include escalation thresholds and regulatory notification timelines. Under SAMA CSF Control 3.4.4, significant cybersecurity incidents must be reported to SAMA within 72 hours of detection, with an initial notification followed by detailed incident reports and a final root cause analysis.
NCA's CSCC (National Cybersecurity Operations Center) additionally requires reporting of incidents affecting critical information infrastructure (CII), with immediate notification for Severity 1 events. Your plan must define what constitutes a reportable event per NCA classification criteria, including unauthorized access, ransomware, data breaches, DDoS attacks, and system compromise.
Practically, the IRP should include: a designated Incident Response Team (IRT) with clearly assigned roles; pre-approved communication templates for regulators, customers, and media; integration with your SIEM/SOAR tools for automated alert triage; evidence preservation procedures aligned with forensic best practices; and a mandatory post-incident review process.
Regulatory examiners from both SAMA and NCA will assess whether your IRP is not just documented but operationally exercised — tabletop exercises and full simulation drills must occur at least annually. Our platform provides IRP templates pre-mapped to SAMA CSF and NCA requirements, automated notification workflows, and drill scheduling tools to keep your team audit-ready.
Business Continuity Management (BCM) is a critical compliance domain for Saudi financial institutions. SAMA CSF Control Domain 3.5 (Cybersecurity Resilience) and NCA ECC Control 2-18 jointly define the minimum expectations for BCM programs.
SAMA CSF Key Requirements (Domain 3.5):
- Develop and maintain a formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) covering cyber-incident scenarios
- Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for all critical systems, with SAMA expecting RTOs of 4 hours or less for Tier-1 banking services
- Conduct BCP/DRP testing at least annually, including tabletop exercises and full failover simulations
- Integrate cybersecurity incident response into BCM frameworks
NCA ECC Control 2-18 Requirements:
- Classify systems by criticality and ensure BCM plans align with national critical infrastructure protection goals
- Maintain geographically separated disaster recovery sites within the Kingdom
- Document and test backup and restoration procedures, ensuring data integrity post-recovery
Practical Implementation Steps:
- Conduct a Business Impact Analysis (BIA) to identify critical processes and maximum tolerable downtime
- Map IT dependencies for each critical business process
- Establish a Crisis Management Team with defined roles and escalation paths
- Integrate BCM testing results into SAMA's annual cybersecurity maturity assessment
- Ensure BCM documentation is reviewed and approved by the Board at least annually
Institutions that treat BCM as a standalone IT exercise — rather than an enterprise-wide governance function — consistently underperform in SAMA maturity evaluations.
Under SAMA CSF Domain 4 (Operational Resilience), Saudi banks and financial institutions are required to establish a comprehensive Business Continuity Management (BCM) program that ensures the availability and resilience of critical financial services. Key requirements include:
1. Business Impact Analysis (BIA): Per SAMA CSF Control 4.2, institutions must conduct a formal BIA to identify critical business functions, define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO), and assess the financial and reputational impact of disruptions.
2. BCP and DRP Documentation: Documented Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) must cover IT systems, data centers, and operational processes. Plans must be reviewed and updated at least annually.
3. Testing and Exercises: SAMA requires regular BCP/DRP testing, including tabletop exercises and full failover simulations. Test results must be documented and gaps remediated within defined timelines.
4. Alternate Site Requirements: Banks must maintain geographically separated DR sites within the Kingdom to ensure data sovereignty and rapid failover capability, aligned with NCA ECC requirements on data residency.
5. Communication Plans: Clear escalation and communication protocols must be established for internal stakeholders, SAMA regulators, and customers during a disruption event.
Practical Tip: Integrate your BCM program with your Incident Response Plan to avoid response gaps. Map your RTO/RPO targets to specific SAMA CSF controls and conduct at least one full DR simulation annually, documenting outcomes for regulatory review. SAMA examiners will specifically request evidence of testing cycles and remediation plans during assessments.
Business Continuity Management (BCM) is a critical compliance domain under SAMA CSF Domain 4 (Resilience), which requires Saudi financial institutions to maintain robust continuity and recovery capabilities. Here are the key requirements and implementation steps:
SAMA CSF Requirements:
- Control 4.3.1–4.3.5: Institutions must establish a formal BCM framework covering Business Impact Analysis (BIA), Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO).
- Control 4.4: Disaster Recovery Plans (DRPs) must be documented, tested at least annually, and aligned with the institution's risk appetite.
- Crisis communication plans must be defined, including escalation paths to SAMA and relevant stakeholders.
Implementation Guidance:
- Conduct a BIA: Identify mission-critical systems (core banking, payment switches, SWIFT connectivity) and define acceptable RTOs — typically 4 hours for tier-1 banking services.
- Develop BCP and DRP: Ensure these are not siloed documents but integrated into operational workflows and tested via tabletop exercises and full failover drills.
- Define Cyber Recovery Scenarios: Incorporate ransomware and DDoS scenarios into your BCP, as required by SAMA's cybersecurity resilience expectations.
- Third-Party BCP Alignment: Verify that critical vendors maintain BCPs aligned with your RTOs, as per SAMA CSF third-party risk controls.
- Annual Testing and Reporting: Document test results and remediation actions. SAMA may request evidence during regulatory examinations.
A mature BCM program not only satisfies SAMA CSF compliance but also strengthens your institution's overall cyber resilience posture.
Under SAMA CSF Domain 4 (Cybersecurity Operations), Saudi banks and financial institutions are required to maintain a formally documented Incident Response Plan (IRP) that covers detection, containment, eradication, recovery, and post-incident review phases. Per SAMA CSF Control 4.3, organizations must establish a 24/7 Security Operations Center (SOC) capability or an equivalent managed service to ensure continuous monitoring and rapid response.
Regarding reporting timelines, SAMA requires member organizations to notify SAMA of any significant cybersecurity incident within 72 hours of detection — a requirement that aligns with global best practices and mirrors PDPL Article 24 obligations for personal data breaches. Critical incidents affecting core banking systems or customer data must be escalated immediately to senior management and the Board Risk Committee.
Practically, your IRP should define clear severity classification levels (P1–P4), assign incident response roles (IR Lead, Legal, PR, IT), and include pre-approved communication templates for regulatory notifications. Tabletop exercises should be conducted at least annually per SAMA CSF Control 4.3.5 to validate response readiness.
Additionally, NCA ECC Article 3-6 requires government-affiliated financial entities to coordinate incident reporting with CERT-SA (cert.gov.sa) in parallel with SAMA notifications. Failure to meet these timelines can result in regulatory sanctions, reputational damage, and potential fines under PDPL if personal data is involved.
Our platform provides a built-in Incident Response workflow module that automates notification timelines, tracks SLA adherence, and generates SAMA-ready incident reports — reducing manual effort and ensuring you never miss a regulatory deadline.
Business Continuity Management (BCM) is one of the most scrutinized domains during SAMA regulatory examinations. SAMA CSF Subdomain 3.5 dedicates an entire control set to ensuring member organizations can maintain critical operations during and after a disruptive event — whether a cyberattack, ransomware incident, natural disaster, or major system failure.
Key SAMA CSF Requirements (Subdomain 3.5):
Business Impact Analysis (BIA): Banks must conduct a formal BIA to identify critical business functions, their dependencies, maximum tolerable downtime (MTD), Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO). The BIA must be reviewed at least annually and after significant operational changes.
Business Continuity Plan (BCP) Development: The BCP must cover crisis communication protocols, roles and responsibilities, escalation procedures, and continuity strategies for critical processes. SAMA expects the plan to address both cyber-triggered disruptions and non-cyber scenarios.
Disaster Recovery Plan (DRP): The technical counterpart to the BCP, the DRP must document recovery procedures for critical IT systems, databases, and infrastructure. It should define failover mechanisms, backup restoration procedures, and alternative processing site activation. SAMA CSF Control 3.5.4 requires that recovery capabilities are tested regularly to validate that RTOs and RPOs can actually be achieved.
Testing Requirements:
- Tabletop exercises: At minimum annually, involving senior management and IT teams
- Functional drills: Testing specific components such as backup restoration or failover switching
- Full-scale simulations: At least every two years, simulating a complete site failure or major cyber incident
- Post-test reviews: Lessons learned must be documented and fed back into plan improvements
SAMA Examination Evidence: During SAMA assessments, examiners typically request BIA reports, BCP/DRP documents, test results, remediation logs, and board-level sign-off. Gaps in testing evidence are a common finding.
Our GRC platform provides BCM lifecycle management, test scheduling, evidence collection, and automated gap analysis against SAMA CSF Subdomain 3.5 controls.
Identity and Access Management is a foundational pillar under both SAMA CSF (Domain 3.3 – Access Control) and NCA ECC (ECC-1-3-4). Saudi banks must implement the following controls:
1. Privileged Access Management (PAM): All privileged accounts — including system administrators, DBAs, and network engineers — must be governed under a formal PAM program. SAMA CSF Control 3.3.4 explicitly requires time-limited, monitored, and logged privileged sessions.
2. Multi-Factor Authentication (MFA): MFA is mandatory for all remote access, administrative portals, and critical system interfaces. NCA ECC Article 3.4 reinforces this for all government-connected and critical infrastructure systems, which applies to licensed financial entities.
3. Least Privilege & Role-Based Access Control (RBAC): Access rights must be granted based on job function with quarterly access reviews. SAMA CSF 3.3.2 mandates formal access provisioning and de-provisioning workflows tied to HR processes.
4. Segregation of Duties (SoD): Conflicting roles — such as a developer having production access — must be identified and resolved. This aligns with SAMA CSF 3.3.5 and ISO 27001 Annex A.9.2.
5. Identity Lifecycle Management: Joiner-Mover-Leaver (JML) processes must be automated where possible, with orphaned accounts reviewed monthly. Dormant accounts inactive for 90+ days must be disabled per SAMA CSF guidance.
Practical Tip: Conduct a semi-annual IAM audit mapped against your SAMA CSF maturity assessment. Document all exceptions with risk acceptance sign-off from your CISO or designated authority to demonstrate regulatory readiness during SAMA inspections.
Under SAMA CSF Domain 4 (Operational Resilience), Saudi banks must establish a formally documented Business Continuity Management program that covers cyber-resilience scenarios. Key requirements include:
SAMA CSF Requirements:
- Control 4.3.1: Conduct annual Business Impact Analysis (BIA) identifying critical systems, maximum tolerable downtime (MTD), and recovery time objectives (RTO/RPO).
- Control 4.3.3: Develop, test, and update Business Continuity Plans (BCPs) and Disaster Recovery Plans (DRPs) at least annually, including cyber-incident scenarios.
- Control 4.3.5: Maintain offline/air-gapped backups of critical data with verified restoration testing every six months.
NCA ECC Alignment (Article 3-5): NCA ECC requires organizations to define BCM policies that integrate cybersecurity events, including ransomware and DDoS, as trigger scenarios. Banks must cross-reference their BCM with the NCA's cybersecurity incident classification levels to ensure response thresholds are consistent.
Practical Implementation Steps:
- Establish a BCM governance committee with CISO and COO representation.
- Map critical banking services (core banking, payment systems, mobile apps) to RTO targets — typically under 4 hours for Tier-1 systems.
- Conduct tabletop exercises simulating a ransomware attack or core-banking outage at least twice per year.
- Integrate BCM testing results into the annual SAMA CSF self-assessment submission.
- Ensure third-party vendors supporting critical systems have equivalent BCM capabilities documented in contracts.
Non-compliance with BCM requirements can result in SAMA supervisory action, including mandatory remediation timelines and increased regulatory scrutiny during annual assessments.
Saudi banks must establish a robust Business Continuity Management (BCM) program that satisfies both SAMA CSF Domain 4 (Operational Resilience) and NCA ECC controls on resilience planning.
SAMA CSF Requirements:
- Per SAMA CSF Control 4.1, banks must maintain a formally documented Business Continuity Plan (BCP) reviewed and approved by senior management at least annually.
- Control 4.2 mandates a Recovery Time Objective (RTO) and Recovery Point Objective (RPO) defined for all critical systems, typically aligned to SAMA's expectation of ≤4 hours RTO for core banking platforms.
- Control 4.3 requires regular BCP testing — at minimum an annual full-scale simulation and semi-annual tabletop exercises.
NCA ECC Alignment:
- NCA ECC Article 3.3.6 requires that cybersecurity continuity is embedded within the BCM program, ensuring cyber incident scenarios are explicitly included in BCP tests.
- Disaster Recovery (DR) sites must be geographically separated within the Kingdom unless SAMA grants specific exemptions.
Practical Guidance:
- Conduct a Business Impact Analysis (BIA) covering all critical business functions and their technology dependencies.
- Integrate your Cyber Incident Response Plan (CIRP) with the BCP to avoid response gaps during simultaneous cyber and operational disruptions.
- Ensure DR drills include ransomware recovery scenarios, as SAMA increasingly scrutinizes this area.
- Document lessons learned from each exercise and track remediation actions with defined owners and deadlines.
- Present BCP test results to the Board Risk Committee to satisfy SAMA's governance expectations.
Failure to maintain an operational BCM program can result in SAMA supervisory findings and mandatory corrective action plans.
Under SAMA CSF Domain 4 (Cyber Resilience), Saudi banks must establish a comprehensive Business Continuity Management program that ensures operational resilience against cyber disruptions. Key requirements include:
1. BIA and Risk Assessment (SAMA CSF Control 4.1): Conduct a Business Impact Analysis identifying critical systems, maximum tolerable downtime (MTD), and recovery time objectives (RTO/RPO). Financial institutions must document dependencies between business processes and underlying IT assets.
2. BCP and DRP Development (Control 4.2): Develop, document, and maintain Business Continuity Plans and Disaster Recovery Plans. Plans must cover ransomware scenarios, data center failures, and third-party outages. Per SAMA CSF, plans must be reviewed at least annually or after significant changes.
3. Testing and Exercises (Control 4.3): SAMA requires at least annual testing of BCM plans through tabletop exercises, functional drills, or full-scale simulations. Results must be documented, gaps remediated, and evidence retained for regulatory review.
4. Cloud and Outsourcing Considerations: If critical workloads run on cloud or third-party infrastructure, BCM must extend to service provider SLAs, failover capabilities, and contractual recovery commitments.
5. Regulatory Reporting: Any cyber incident impacting business continuity must be reported to SAMA within defined timeframes per the SAMA Cyber Incident Reporting Guidelines.
Practical Tip: Align your BCM program simultaneously with NCA ECC Article 3-6 controls on resilience and ISO 22301 for a unified, audit-ready framework. Maintain a living BCM document repository accessible to your crisis management team at all times.
SAMA CSF Control 3.3 mandates that Saudi financial institutions establish a formal, risk-based cybersecurity awareness and training program covering all staff, including senior management and the board. Key requirements include: (1) Annual baseline security awareness training for all employees, with role-specific training for IT, security, and privileged-access users; (2) Documented training records maintained for audit purposes; (3) Phishing simulation exercises conducted periodically to measure human risk; (4) Awareness content tailored to emerging threats such as social engineering, ransomware, and insider threats. CISOs should establish a training governance framework that links awareness outcomes to the institution's overall cyber risk posture. Training effectiveness must be measured using KPIs such as phishing click rates, quiz pass rates, and incident reduction trends. Board and C-suite training should specifically address cyber risk oversight responsibilities per SAMA CSF Control 3.2. Institutions are also encouraged to align their programs with NIST CSF's 'Protect' function (PR.AT) for a globally consistent approach. Practical tip: Integrate awareness campaigns with real-world threat intelligence relevant to the Saudi banking sector, including Business Email Compromise (BEC) and ATM fraud schemes, to increase relevance and engagement among staff.
Under SAMA CSF Control Domain 3.3 (Human Resources Security), Saudi financial institutions must establish a formal, risk-based cybersecurity awareness and training program covering all staff, contractors, and third parties with system access.
Key Requirements:
- Mandatory onboarding training: All new employees must complete cybersecurity awareness training before accessing institutional systems, per SAMA CSF Control 3.3.2.
- Annual refresher cycles: Recurring training must be conducted at least annually, with role-specific modules for IT, security, finance, and executive staff.
- Specialized training for privileged users: System administrators, developers, and security personnel require advanced training covering secure coding, access management, and threat response, aligned with SAMA CSF Control 3.3.4.
- Phishing simulation exercises: Institutions should conduct periodic simulated phishing campaigns to measure human risk and reinforce training outcomes.
- Metrics and reporting: Training completion rates, phishing simulation results, and awareness KPIs must be reported to senior management and the board.
Practical Guidance:
- Map training content to current threat landscapes relevant to Saudi banking, including social engineering, account takeover, and insider threats.
- Leverage e-learning platforms that support Arabic content to maximize staff engagement.
- Maintain documented training records for audit purposes — SAMA examiners will request evidence of completion rates and curriculum content.
- Align your program with NCA ECC Article 2-7 (Cybersecurity Awareness) for organizations also subject to NCA oversight.
A well-documented, measurable training program not only satisfies regulatory expectations but demonstrably reduces human-factor risk, which remains the leading cause of security incidents in the Saudi financial sector.
Under SAMA CSF Control 3.3.1 (Cybersecurity Awareness and Training), Saudi banks are required to establish a formal, risk-based security awareness program covering all staff, including senior management and the board. Here is how a CISO should approach building a compliant and effective program:
Mandatory Components:
- Annual baseline security awareness training for all employees
- Role-based training for IT, security, privileged users, and executives
- Documented training records and completion tracking
- Phishing simulation exercises conducted at least quarterly
Practical Implementation Steps:
- Conduct a Training Needs Analysis (TNA): Map roles to risk exposure and tailor content accordingly — a teller has different risks than a developer or an IT admin.
- Establish a Training Calendar: Schedule mandatory annual training with quarterly refreshers aligned to emerging threats (e.g., Business Email Compromise, deepfake fraud).
- Integrate Phishing Simulations: Run at minimum quarterly phishing campaigns with immediate coaching for employees who fail. Track click rates as a KPI.
- Measure Effectiveness: Use pre/post assessments, phishing simulation metrics, and incident reports to demonstrate program maturity to auditors.
- Board and Senior Management Engagement: SAMA expects governance-level awareness — conduct tailored briefings covering cyber risk appetite and regulatory obligations.
- Align with ISO 27001: Control A.7.2.2 of ISO 27001 reinforces the need for regular, documented awareness activities.
Document everything — SAMA examiners will request training plans, completion records, and simulation results during assessments. A mature awareness program also directly reduces your attack surface against social engineering, which remains the top threat vector for Saudi financial institutions.
Under SAMA CSF Control 3.3 (Identity and Access Management), Saudi banks must establish a robust IAM program that governs the entire lifecycle of user identities—from provisioning to deprovisioning. Key requirements include: enforcing multi-factor authentication (MFA) for all privileged and remote access, implementing the principle of least privilege, and conducting quarterly access reviews for all critical systems.
For Privileged Access Management (PAM) specifically, SAMA CSF Control 3.3.5 requires that privileged accounts be strictly controlled through dedicated PAM solutions such as CyberArk, BeyondTrust, or similar platforms. Banks must ensure that shared administrative credentials are eliminated, all privileged sessions are recorded and monitored, and just-in-time (JIT) access is granted where feasible.
From an NCA ECC perspective, ECC-1:2018 Article 2-7 reinforces these requirements by mandating separation of duties and periodic recertification of access rights. Practically, Saudi banks should:
- Maintain a centralized identity repository integrated with HR systems to automate provisioning and deprovisioning.
- Deploy a PAM solution with session recording for all Tier-1 infrastructure.
- Enforce MFA across all administrative consoles, VPN, and cloud management portals.
- Conduct semi-annual privilege access reviews and document findings for SAMA audit purposes.
- Align IAM policies with ISO 27001 Annex A Control 9 (Access Control).
Non-compliance can result in SAMA supervisory findings during annual cybersecurity assessments, making IAM one of the highest-scrutiny areas during regulatory reviews.
Under SAMA CSF Control 3.3, Saudi banks must establish a comprehensive Identity and Access Management program covering user provisioning, authentication, and privileged access governance. Key requirements include:
Privileged Access Controls (SAMA CSF 3.3.3):
- Implement Privileged Access Management (PAM) solutions to vault, rotate, and audit privileged credentials
- Enforce just-in-time (JIT) access for administrative accounts — no standing privileges
- Require multi-factor authentication (MFA) for all privileged and remote access, aligning with NCA ECC-1: 2-3.2
Practical Implementation Steps:
- Conduct a full access rights review at least quarterly and immediately upon role changes
- Segregate privileged accounts from standard user accounts — administrators should not use admin credentials for daily tasks
- Deploy session recording and real-time monitoring for all privileged sessions
- Establish a formal onboarding/offboarding process with HR integration to revoke access within 24 hours of termination
- Apply the principle of least privilege across all systems, enforced through role-based access control (RBAC)
NCA ECC Alignment: ECC-1: 2-3 further mandates that access to critical national infrastructure systems must be logged, reviewed, and protected against unauthorized elevation.
ISO 27001 Mapping: Annex A Control 8.2 (Privileged Access Rights) and 8.18 (Use of Privileged Utility Programs) directly support these obligations.
Banks should conduct annual PAM maturity assessments and report IAM control effectiveness to the Board-level cybersecurity committee as part of SAMA's governance reporting requirements under Control 2.1.
Under SAMA CSF Domain 3 (Cybersecurity Operations), specifically Controls 3.3.1 through 3.3.6, Saudi banks must establish a comprehensive Identity and Access Management program that enforces least-privilege principles, role-based access control (RBAC), and multi-factor authentication (MFA) for all critical systems.
Key Implementation Requirements:
Privileged Access Management (PAM): SAMA CSF Control 3.3.4 mandates that privileged accounts (domain admins, database admins, system administrators) be managed through a dedicated PAM solution with session recording, just-in-time access provisioning, and regular access reviews — conducted at least quarterly.
Multi-Factor Authentication: MFA must be enforced for all remote access, administrative consoles, internet-facing systems, and core banking platforms. This aligns with NCA ECC Article 2-14, which similarly mandates MFA for sensitive systems.
Access Reviews: Conduct formal access certification campaigns every 90 days for privileged users and every 6 months for standard users. Terminated or transferred employee access must be revoked within 24 hours per SAMA CSF Control 3.3.2.
Segregation of Duties (SoD): Conflicting roles — such as system administration and audit log management — must be separated to prevent insider threats.
Practical Steps:
- Deploy a PAM solution (e.g., CyberArk, BeyondTrust) integrated with your SIEM.
- Implement an Identity Governance and Administration (IGA) platform for automated provisioning/deprovisioning.
- Document an Access Control Policy mapped to SAMA CSF and ISO 27001 Annex A.9 controls.
- Conduct annual IAM audits and include findings in your SAMA CSF self-assessment reporting.
Non-compliance with SAMA CSF IAM controls can result in regulatory findings during SAMA examinations and reputational risk for the institution.
Under SAMA CSF Control Domain 3.4 (Third-Party Management), Saudi banks must establish a formal vendor risk management program that covers the entire vendor lifecycle — from onboarding through offboarding. Key mandatory requirements include:
Risk Tiering: Classify vendors into critical, high, medium, and low risk based on data access, system integration depth, and regulatory exposure. Critical vendors (e.g., core banking system providers, cloud hosting) require the most rigorous due diligence.
Pre-Onboarding Assessments: Before engaging any third party with access to sensitive systems or customer data, conduct a cybersecurity assessment aligned with SAMA CSF domains. This should include reviewing the vendor's ISO 27001 certification, SOC 2 Type II reports, and their own subcontractor (fourth-party) risk posture.
Contractual Controls (per SAMA CSF 3.4.3): All contracts must include clauses for data protection obligations (aligned with PDPL), right-to-audit provisions, incident notification timelines (typically within 72 hours), and exit/transition security requirements.
Ongoing Monitoring: Critical vendors must be reassessed annually at minimum. Implement continuous monitoring through questionnaires, threat intelligence feeds, and external attack surface monitoring tools.
NCA ECC Alignment: NCA ECC Article 2-6 reinforces these requirements for entities operating national infrastructure, mandating that vendor agreements explicitly address cybersecurity responsibilities and incident escalation paths.
Practical Tip: Build a vendor risk register within your GRC platform that maps each vendor to the SAMA CSF controls they impact. This simplifies annual regulatory examinations and demonstrates mature governance to SAMA inspectors.
Third-party risk management (TPRM) is a critical obligation under SAMA CSF Control Domain 3.3 and NCA ECC Article 2-9. Saudi banks must establish a formal vendor risk program that begins before onboarding any third party. Here is a practical framework:
1. Vendor Classification & Due Diligence: Classify vendors by criticality (critical, high, medium, low) based on data access and system integration. Per SAMA CSF Control 3.3.1, conduct cybersecurity due diligence before signing contracts, including reviewing the vendor's ISO 27001 certification, SOC 2 reports, or equivalent assurance.
2. Contractual Controls: Embed cybersecurity clauses covering right-to-audit, incident notification SLAs (within 72 hours per SAMA CSF 3.3.4), data handling obligations aligned with PDPL, and minimum security standards.
3. Continuous Monitoring: Conduct annual cybersecurity assessments for critical vendors and biannual reviews for high-risk vendors. Use standardized questionnaires aligned with SAMA CSF control domains.
4. Fourth-Party Risk: Identify your vendors' critical subcontractors. NCA ECC requires visibility into the supply chain, especially for cloud and managed security service providers.
5. Offboarding Controls: Ensure secure data deletion, access revocation, and certificate of destruction upon contract termination.
A common gap auditors identify is the lack of documented evidence for ongoing monitoring — banks often perform initial due diligence but fail to track vendor risk posture changes. Maintain a central vendor risk register with last assessment date, risk rating, and remediation status. This register should be reviewed quarterly by the CISO and reported to the Board Risk Committee annually.
An effective Cyber Incident Response Plan (CIRP) for Saudi banks must align with SAMA CSF Control Domain 3.6 and NCA ECC Articles 2-11 and 2-12. Here is how to build one that satisfies both frameworks:
1. Define Incident Severity Tiers: Establish at least four severity levels (P1–P4) with clear criteria. P1 events (e.g., ransomware, core banking system breach) trigger mandatory regulatory reporting. Map your severity matrix to SAMA's incident classification taxonomy.
2. Mandatory Reporting Timelines: Per SAMA CSF Control 3.6.5, critical incidents must be reported to SAMA within 72 hours of detection. NCA ECC Article 2-11 requires simultaneous notification to the National Cybersecurity Authority (NCA) via the Musaned/CERT-SA portal. Document your reporting workflow with named owners and escalation paths.
3. CIRP Core Phases: Structure your plan around six phases: Preparation → Identification → Containment → Eradication → Recovery → Post-Incident Review. Each phase must have documented runbooks, responsible parties (RACI matrix), and time-bound SLAs.
4. Evidence Preservation: Establish digital forensics procedures to preserve chain of custody — critical if the incident involves fraud or regulatory investigation. Use write-blockers and maintain forensic logs for a minimum of 12 months per SAMA CSF.
5. Communication Templates: Pre-draft notifications for SAMA, NCA, affected customers (per PDPL Article 24 — 72-hour breach notification), and media holding statements.
6. Tabletop Exercises: SAMA CSF Control 3.6.7 requires annual incident response testing. Conduct at least one full tabletop exercise and one technical simulation (e.g., red team scenario) annually. Document results, gaps, and improvement actions.
7. Lessons Learned Integration: Post-incident reports must feed back into your risk register and control framework within 30 days of incident closure.
SAMA CSF Control Domain 3.3 (Third-Party Management) mandates that Saudi banks establish a formal third-party risk management (TPRM) program covering the entire vendor lifecycle — from initial onboarding through contract termination. Per SAMA CSF Control 3.3.2, banks must conduct cybersecurity risk assessments before engaging any third party that accesses sensitive systems or customer data.
Key implementation steps include:
1. Vendor Classification: Categorize vendors by risk tier (Critical, High, Medium, Low) based on data access, system integration depth, and business criticality.
2. Pre-Onboarding Due Diligence: Require vendors to complete security questionnaires aligned to ISO 27001 Annex A controls and NCA ECC requirements. Critical vendors should provide SOC 2 Type II reports, ISO 27001 certificates, or equivalent third-party audit results.
3. Contractual Controls: Embed cybersecurity clauses covering incident notification timelines (within 24 hours per SAMA CSF 3.3.5), data handling obligations under PDPL Articles 21–22, right-to-audit provisions, and compliance with NCA ECC.
4. Ongoing Monitoring: Conduct annual reassessments for critical vendors and biennial reviews for others. Use automated vendor risk platforms to track security posture changes continuously.
5. Offboarding Procedures: Ensure secure data return or destruction and revocation of all access credentials upon contract termination.
SAMA examiners increasingly scrutinize TPRM programs during regulatory reviews, so maintaining a centralized vendor registry with documented risk ratings and assessment histories is essential for audit readiness. Financial institutions relying heavily on cloud or fintech partners should also align vendor oversight with NCA Cloud Cybersecurity Controls (CCC) requirements.
Third-party risk management is a critical compliance area under SAMA CSF Control Domain 3.3, which mandates that financial institutions establish a structured Vendor Risk Management (VRM) program. Here is how to implement it effectively:
1. Vendor Classification & Tiering Classify vendors based on data sensitivity, system access, and criticality. Tier-1 vendors (e.g., core banking providers, cloud platforms) require the most rigorous controls, including annual security assessments and contractual cybersecurity clauses.
2. Pre-Onboarding Due Diligence Before contracting, require vendors to complete a security questionnaire aligned with SAMA CSF and ISO 27001. Validate certifications such as ISO 27001 or SOC 2 Type II. Per SAMA CSF Control 3.3.2, you must assess a vendor's ability to protect your data before granting access.
3. Contractual Obligations Ensure contracts include clauses covering data protection (aligned with PDPL Articles 21–22), incident notification timelines (typically within 72 hours), right-to-audit provisions, and business continuity requirements.
4. Ongoing Monitoring Conduct periodic reassessments — at least annually for Tier-1 vendors. Use threat intelligence feeds to monitor for vendor breaches. Establish a vendor risk register tracked by your GRC platform.
5. Offboarding Controls When terminating vendor relationships, ensure data deletion certifications are obtained and access credentials are revoked immediately.
NCA ECC Article 2-14 further reinforces these obligations by requiring documented supplier security policies. Failure to maintain a robust VRM program is a common finding in SAMA examinations and can result in remediation requirements. Your GRC platform should automate vendor assessments, track remediation actions, and generate audit-ready reports.
Third-party risk management is a critical compliance area under both SAMA CSF (Domain 3.3 – Third Party Management) and NCA ECC (Control 2-7). Saudi banks and fintechs must implement a structured Vendor Risk Management (VRM) program covering the full supplier lifecycle.
Key Steps:
- Pre-onboarding Assessment: Before contracting, require vendors to complete a cybersecurity questionnaire aligned to SAMA CSF maturity levels. Evaluate their ISO 27001 certification status, data handling practices, and incident response capabilities.
- Contractual Obligations: Per SAMA CSF Control 3.3.3, contracts must include cybersecurity clauses covering data protection, audit rights, breach notification timelines (within 72 hours per PDPL Art. 25), and right-to-terminate provisions.
- Ongoing Monitoring: Classify vendors by risk tier (critical, high, medium, low). Critical vendors — those with access to core banking systems or personal data — must undergo annual security assessments, and you should review their SOC 2 Type II or equivalent reports.
- Fourth-Party Risk: SAMA CSF also requires visibility into sub-contractors. Ensure your vendor contracts mandate disclosure of any fourth parties with access to your data or systems.
- Offboarding Controls: Revoke access, retrieve or destroy data, and document the offboarding per NCA ECC Control 2-7-4.
Practically, maintain a centralized vendor registry with risk ratings updated at least annually. Your GRC platform should automate assessment workflows, track remediation, and generate audit-ready reports for SAMA examiners. Non-compliance in this domain has been a recurring finding in SAMA regulatory reviews.
Third-party risk management is a critical pillar of SAMA CSF compliance, addressed specifically under Domain 3 (Cybersecurity Risk Management) and Domain 6 (Third-Party Cybersecurity). Saudi banks must establish a formal Third-Party Risk Management (TPRM) program that covers the entire vendor lifecycle — from onboarding due diligence to offboarding controls.
Key requirements include:
Pre-Engagement: Conduct cybersecurity risk assessments before contracting any vendor with access to systems or data. Per SAMA CSF Control 3.3.1, risk classification must determine the level of scrutiny applied.
Contractual Obligations: All third-party contracts must include cybersecurity clauses covering data protection, incident notification timelines (typically within 72 hours), right-to-audit provisions, and minimum security standards aligned with NCA ECC controls.
Ongoing Monitoring: High-risk vendors (e.g., cloud providers, payment processors, core banking vendors) must undergo annual cybersecurity assessments, including questionnaires, evidence reviews, and where applicable, independent audits or penetration test results review.
Concentration Risk: SAMA also requires banks to assess dependency and concentration risk — particularly for critical outsourced services — to ensure business continuity is not compromised.
PDPL Alignment: If the third party processes personal data on your behalf, a Data Processing Agreement (DPA) must be in place per PDPL Article 29, designating them as a data processor with defined obligations.
Practical tip: Tier your vendors (Critical, High, Medium, Low) and apply proportionate controls. Use automated TPRM platforms integrated into your GRC system to track assessment cycles, remediation actions, and contract renewal dates efficiently.
Security Awareness Training is not optional for Saudi financial institutions — it is a mandatory control under both SAMA CSF (Domain 2: Cybersecurity Leadership and Governance, Control 2.4) and NCA ECC (Domain 2, Control 2-10). However, many organizations treat awareness training as a checkbox exercise rather than a behavioral change program. Here's how to do it right:
Program Foundations: Establish a formal SAT policy endorsed by the CISO and Board. Define target audiences — all staff, privileged users, third-party contractors, and board members each require tailored content. Per SAMA CSF Control 2.4.1, role-based training must address job-specific threats.
Core Content Modules Should Include:
- Phishing and social engineering recognition
- Secure handling of customer and financial data (PDPL-aligned)
- Password hygiene and MFA usage
- Incident reporting procedures
- Acceptable use of corporate systems
- Insider threat awareness
Phishing Simulation: Conduct monthly or quarterly simulated phishing campaigns. Track click rates, credential submission rates, and reporting rates as KPIs. Employees who fail should receive immediate remedial training — not punitive action.
Frequency and Format: Annual training alone is insufficient. Implement microlearning modules, monthly security tips, and event-driven training (e.g., after a major industry breach). NCA ECC recommends awareness activities be conducted at least annually, but leading practices suggest quarterly touchpoints.
Measuring Effectiveness: Report SAT metrics to senior management and the board annually, including training completion rates (target: 95%+), phishing simulation trends, and incident reports attributed to human error.
Regulatory Reporting: SAMA may request evidence of your SAT program during regulatory examinations. Maintain records of training completion, content versions, and assessment scores for at least three years.
Third-party risk management (TPRM) is a critical compliance obligation for Saudi financial institutions under SAMA CSF Domain 3.3 and NCA ECC Control 2-7. A robust TPRM program should follow these key steps:
1. Vendor Classification & Tiering: Categorize all third parties by criticality — Tier 1 (critical suppliers with access to core systems or sensitive data), Tier 2 (significant vendors), and Tier 3 (low-risk suppliers). SAMA CSF requires formal risk classification before onboarding.
2. Pre-Onboarding Due Diligence: Conduct security assessments including questionnaire-based reviews, evidence collection (ISO 27001 certificates, SOC 2 reports), and for Tier 1 vendors, independent security assessments or on-site audits per SAMA CSF Control 3.3.2.
3. Contractual Controls: Embed cybersecurity clauses covering data protection obligations, right-to-audit provisions, incident notification timelines (typically within 72 hours per PDPL Article 28), and compliance with SAMA and NCA requirements.
4. Ongoing Monitoring: Perform annual reassessments for Tier 1 vendors and biennial reviews for Tier 2. Monitor for adverse events such as breaches, regulatory sanctions, or financial instability.
5. Offboarding Procedures: Ensure secure data deletion, access revocation, and formal closure documentation when vendor relationships end.
6. Cloud & SaaS Providers: For cloud vendors, additionally verify alignment with NCA Cloud Cybersecurity Controls (CCC) and SAMA's cloud outsourcing guidelines, including data residency requirements within the Kingdom.
Maintain a centralized vendor register with risk ratings, assessment dates, and contractual status. SAMA expects this register to be available during regulatory examinations.
Identity and Access Management (IAM) is one of the most scrutinized control domains during SAMA and NCA regulatory examinations. Requirements are detailed under SAMA CSF Controls 3.3.5–3.3.7 and NCA ECC Controls 2-5 and 2-6.
Core IAM Requirements:
1. Least Privilege & Need-to-Know: All user access rights must be provisioned based on job function and strictly limited to what is necessary. Access requests must follow a formal approval workflow with documented justification.
2. Privileged Access Management (PAM): Privileged accounts (domain admins, database admins, root accounts) must be managed through a dedicated PAM solution. All privileged sessions must be recorded and monitored. Generic or shared admin accounts are prohibited per SAMA CSF.
3. Multi-Factor Authentication (MFA): MFA is mandatory for all remote access, privileged accounts, and access to critical systems. SAMA CSF specifically requires MFA for internet-facing portals and core banking system access.
4. Access Reviews: Formal quarterly access recertification is required for privileged accounts and semi-annual reviews for all other accounts. Results must be documented and actioned within defined remediation windows.
5. Joiners, Movers, Leavers (JML) Process: Access provisioning and deprovisioning must be tied to HR workflows. Leavers' access must be revoked within 24 hours of termination, with immediate revocation for involuntary departures.
6. Directory & Identity Governance: Maintain a central identity directory (e.g., Active Directory, Azure AD) integrated with HR systems. Orphaned accounts — accounts with no active owner — must be detected and disabled regularly.
Document all IAM policies, procedures, and evidence of control operation for regulatory examination readiness. SAMA expects IAM evidence to be produced within 48 hours of an examination request.
Third-party risk management (TPRM) is a critical compliance obligation under SAMA CSF Domain 4 (Third Party Cybersecurity), which requires Saudi banks and financial institutions to maintain a structured, lifecycle-based approach to vendor risk.
Key implementation steps include:
- Vendor Inventory & Classification: Maintain a complete register of all third parties with access to systems or data. Classify vendors by risk tier — critical, high, medium, low — based on access level, data sensitivity, and operational dependency.
- Pre-Onboarding Due Diligence: Per SAMA CSF Control 4.1, conduct cybersecurity assessments before onboarding. Require vendors to demonstrate compliance with recognized frameworks (ISO 27001, NCA ECC) and review their security policies, audit reports (SOC 2, ISAE 3402), and incident history.
- Contractual Safeguards: Embed cybersecurity clauses covering data handling, breach notification timelines (aligned with PDPL's 72-hour reporting), right-to-audit provisions, and minimum security standards.
- Continuous Monitoring: SAMA CSF requires ongoing oversight — not just point-in-time assessments. Use automated threat intelligence feeds, periodic reassessments (at least annually for critical vendors), and monitor for adverse news or certifications lapsing.
- Incident & Exit Management: Define clear procedures for vendor-side incidents, including escalation paths and contractual remediation obligations. Maintain exit strategies to ensure data return/destruction and service continuity.
NCA ECC Article 3-4 also mandates controls on third-party access to national infrastructure components, which overlaps for banks with cross-sector connectivity.
Platforms like CISO Consulting can help automate vendor questionnaires, risk scoring, and evidence collection to keep your TPRM program audit-ready year-round.
Human error remains the leading cause of cybersecurity incidents in financial institutions globally, and SAMA CSF Domain 2 (Human Resources Cybersecurity) mandates that Saudi banks establish a formal, measurable security awareness and training program for all staff.
Building a SAMA-compliant Security Awareness Program:
- Role-Based Training Design: Per SAMA CSF Control 2.3, training must be tailored to roles. General staff need phishing awareness and data handling basics; IT and security teams require technical deep-dives; executives and board members need governance-focused content on cyber risk and regulatory liability.
- Mandatory Onboarding & Annual Refreshers: All new employees must complete security awareness training before being granted system access. Annual refresher training is the minimum — quarterly micro-learning modules (5–10 minutes) significantly improve retention.
- Phishing Simulation Campaigns: Run regular simulated phishing exercises (at least quarterly) to baseline and track employee click rates. SAMA CSF expects documented evidence of these exercises, including remedial training triggers for employees who fail simulations.
- Metrics & Reporting: Track KPIs such as training completion rates (target: 100% for mandatory modules), phishing simulation failure rates (benchmark: below 5% after 6 months), and incident reports attributable to human error. Report these to the CISO and board-level risk committee.
- Regulatory & Policy Acknowledgements: Require staff to formally acknowledge key policies (Acceptable Use, Data Classification, Incident Reporting) annually — these acknowledgements serve as audit evidence under SAMA CSF and NCA ECC assessments.
- Specialized Training for Privileged Users: Admins and developers with elevated access must receive additional training on topics such as social engineering, secure coding (OWASP Top 10), and insider threat indicators.
A well-executed awareness program not only satisfies SAMA examiners but measurably reduces your organization's attack surface — making it one of the highest-ROI investments in your cybersecurity portfolio.
Security awareness and training is explicitly mandated under SAMA CSF Domain 3.1 (Cybersecurity Leadership and Governance), and it extends beyond a simple annual e-learning course. Here is how to build a program that satisfies regulators and actually reduces risk:
Mandatory Training Scope (SAMA CSF 3.1.4): All employees — including contractors and third-party staff with system access — must receive cybersecurity awareness training. New joiners must complete training within 30 days of onboarding. Board members and senior management require specialized training covering cyber risk governance, not just general awareness.
Frequency and Format: General staff: minimum annual training with quarterly micro-learning campaigns (phishing simulations, policy reminders). IT and security staff: role-specific technical training at least twice per year. Executives: annual cyber risk briefing aligned with the institution's risk appetite and threat landscape.
Phishing Simulation Requirements: SAMA CSF expects institutions to test employee resilience through simulated phishing campaigns. Run simulations quarterly, track click rates, and provide immediate remedial training to employees who fail. Document results for regulatory evidence.
Topics to Cover: Social engineering and phishing recognition, password hygiene and MFA usage, secure handling of customer data (PDPL obligations), incident reporting procedures, acceptable use of IT systems, and remote working security.
NCA ECC Alignment: NCA ECC Article 2-2 reinforces the need for cybersecurity awareness programs with documented evidence of completion. Training records must be maintained and available for NCA assessments.
Measurement and Reporting: Track training completion rates (target: 95%+ within compliance windows), phishing simulation click rates over time, and security incident reports attributed to human error. Present these metrics to the CISO and risk committee quarterly.
Documentation: Maintain training completion records, curriculum content, and assessment results for a minimum of three years to support SAMA and NCA audit requirements.
Identity and Access Management (IAM) is one of the most scrutinized control areas during SAMA and NCA regulatory examinations. Here are the mandatory requirements and best practices:
SAMA CSF Requirements (Domain 3.2 – Access Management)
- Implement role-based access control (RBAC) with least-privilege principles across all systems (SAMA CSF Control 3.2.1)
- Enforce Multi-Factor Authentication (MFA) for all privileged accounts and remote access without exception
- Conduct quarterly access reviews for privileged users and semi-annual reviews for standard users
- Disable or remove access within 24 hours of employee termination (SAMA CSF Control 3.2.4)
NCA ECC Controls (ECC-1:2-7.1 to 7.4) NCA mandates strict Privileged Access Management (PAM) controls including session recording, just-in-time access provisioning, and vault-based credential management for all administrative accounts.
Practical Implementation Steps:
- Deploy a PAM solution (CyberArk, BeyondTrust, or equivalent) for privileged account governance
- Integrate Identity Governance & Administration (IGA) tools to automate access certification campaigns
- Implement Single Sign-On (SSO) with federation protocols (SAML 2.0/OIDC) to centralize authentication
- Enforce conditional access policies based on device posture, location, and risk score
- Log all privileged sessions and integrate with SIEM for real-time anomaly detection
PDPL Consideration: Under PDPL Article 10, access to personal data must be restricted to authorized personnel only, making IAM controls a legal obligation beyond just cybersecurity best practice.
Regulatory examiners frequently test IAM controls through user access listing reviews — ensure your access matrix is current and audit-ready at all times.
Third-party risk management (TPRM) is a critical compliance area under SAMA CSF Domain 3 (Cybersecurity Risk Management) and specifically Control 3.3.6, which mandates that financial institutions maintain a structured program for assessing and monitoring vendors with access to systems or data.
Key requirements and practical steps:
- Vendor Classification: Categorize all vendors by risk tier — critical, high, medium, and low — based on data access, system connectivity, and service criticality. Cloud providers, core banking vendors, and payment processors typically fall in the critical tier.
- Pre-Onboarding Assessment: Before contracting, conduct a cybersecurity due diligence review covering ISO 27001 certification status, penetration test results, SOC 2 reports, and security policy documentation.
- Contractual Controls: Per SAMA CSF, contracts must include cybersecurity clauses covering data protection, incident notification timelines (typically 72 hours), audit rights, and compliance with Saudi regulations including PDPL.
- Continuous Monitoring: Implement ongoing monitoring through annual or semi-annual reassessments for critical vendors, automated threat intelligence feeds, and tracking of vendor security incidents.
- PDPL Alignment: When vendors process personal data, ensure Data Processing Agreements (DPAs) are in place per PDPL Article 29, defining the purpose, retention limits, and cross-border transfer restrictions.
- Exit Strategy: Maintain documented exit plans to ensure data recovery and service continuity if a vendor relationship is terminated.
A GRC platform centralizes vendor risk scoring, automates assessment workflows, tracks remediation, and generates SAMA-ready audit evidence — reducing manual effort significantly for compliance teams.
Under SAMA CSF Control 3.3.1 and supporting sub-controls, Saudi banks are required to establish a formal, documented cybersecurity awareness and training program that covers all employees, contractors, and privileged users. The program must be risk-based, role-specific, and conducted at least annually — with additional training triggered by significant threat changes or after security incidents.
An effective program should include the following components:
1. Role-Based Training Tracks: General staff receive phishing awareness, password hygiene, and social engineering modules. IT and security teams receive advanced technical training aligned with their functions. Executives and board members require governance-level sessions covering cyber risk appetite and regulatory obligations.
2. Phishing Simulation Campaigns: Conduct quarterly simulated phishing exercises and track click rates over time. SAMA CSF expects measurable improvement, so document baseline metrics and remediation steps for repeat offenders.
3. Onboarding Integration: New employees must complete cybersecurity awareness training before being granted access to systems, per SAMA CSF's access control requirements under Control 3.3.3.
4. Awareness Metrics and Reporting: Track completion rates, assessment scores, and simulation results. Report these metrics to senior management and the board as part of cybersecurity KPIs.
5. Arabic-Language Content: Given Saudi Arabia's workforce demographics, awareness materials must be available in Arabic to ensure comprehension and regulatory defensibility.
From an NCA ECC perspective, Article 2-6 also mandates cybersecurity awareness as a foundational control. Aligning your program to satisfy both frameworks simultaneously reduces duplication and strengthens audit readiness. Our platform provides pre-built, SAMA-aligned training modules, phishing simulation tooling, and automated completion tracking dashboards.
SAMA CSF Control 3.3.1 mandates that all employees, contractors, and third parties with access to organizational systems receive regular cybersecurity awareness training tailored to their roles. Banks must establish a formal, documented training program that is reviewed and updated at least annually.
An effective program should include the following components:
1. Role-Based Training: General staff receive foundational awareness covering phishing, social engineering, and password hygiene. IT and security teams require advanced technical training. Executives and board members need governance-focused modules aligned with their oversight responsibilities.
2. Phishing Simulation: Conduct quarterly simulated phishing campaigns to measure staff susceptibility. Track click-through rates and remediate with targeted coaching for repeat offenders.
3. Onboarding Integration: New hires must complete cybersecurity orientation before accessing production systems, per SAMA CSF Control 3.3.2.
4. Regulatory Alignment: Training content should reference PDPL obligations (e.g., data handling, breach reporting duties) and NCA ECC awareness requirements to ensure holistic compliance.
5. Metrics and Reporting: Track completion rates, assessment scores, and phishing simulation results. Report outcomes to the CISO and board risk committee at least semi-annually.
6. Culture Building: Beyond compliance, embed security into daily workflows through awareness campaigns, internal newsletters, and gamified learning modules in Arabic and English.
Failure to maintain an active training program is a common finding in SAMA regulatory examinations. Institutions should retain training records for a minimum of three years to demonstrate compliance during audits.
Third-party risk management is a critical compliance obligation for Saudi financial institutions under SAMA CSF Domain 3 (Cybersecurity Risk Management) and NCA ECC-1:2018 Article 3-4. A well-structured TPRM program should cover the following pillars:
1. Vendor Classification & Due Diligence Classify all third parties by risk tier — critical, high, medium, and low — based on data access, system integration, and operational dependency. SAMA CSF requires documented due diligence before onboarding any vendor with access to sensitive financial or personal data.
2. Contractual Security Requirements All vendor contracts must include cybersecurity clauses aligned with SAMA CSF Control 3.3, covering data handling, incident notification obligations (typically within 72 hours), right-to-audit provisions, and compliance with PDPL Article 29 for any data processing arrangements.
3. Continuous Monitoring Don't treat TPRM as a one-time assessment. NCA ECC recommends periodic reassessment cycles — annually for critical vendors and every two years for lower-risk suppliers. Use automated tools to track vendor security posture changes, certificate expirations, and breach notifications.
4. Exit Strategy & Data Return Include contractual provisions for secure data deletion or return upon contract termination, in line with PDPL data minimization principles.
5. Governance & Reporting TPRM findings should be escalated to the CISO and reported to the Board Risk Committee at least annually, as required under SAMA CSF governance controls.
Our platform provides a structured TPRM workflow with pre-built assessment templates mapped to SAMA CSF and NCA ECC controls, enabling your team to onboard, monitor, and offboard vendors with full audit traceability.
Third-party risk management is a critical compliance obligation for Saudi financial institutions. Under SAMA CSF Control 3.3 (Third-Party Management), banks must establish a formal TPRM program that covers the entire vendor lifecycle — from onboarding due diligence through contract termination and offboarding.
Key implementation steps include:
- Vendor Inventory & Classification: Maintain a comprehensive register of all third parties and classify them by criticality — critical, high, medium, and low — based on their access to systems, data sensitivity, and operational dependency.
- Pre-Engagement Due Diligence: Before contracting, assess vendors against cybersecurity posture, financial stability, regulatory compliance history, and geographic risk. SAMA CSF requires documented due diligence for critical vendors.
- Contractual Controls: Embed mandatory security clauses covering data protection (aligned with PDPL), incident notification timelines (typically 72 hours per SAMA guidance), audit rights, and right-to-terminate triggers.
- Ongoing Monitoring: Per NCA ECC Article 2-14, organizations must conduct periodic reassessments. Critical vendors should be reviewed at least annually, with continuous monitoring for high-risk suppliers.
- Concentration Risk: SAMA expects banks to identify and manage vendor concentration risk — where over-reliance on a single supplier could impact operational resilience.
- Fourth-Party Risk: Extend your program to cover subcontractors and sub-processors used by your vendors, especially in cloud and fintech supply chains.
A mature TPRM program should integrate with your broader GRC platform, enabling automated risk scoring, evidence collection, and audit-ready reporting for SAMA examinations.
Third-party risk management (TPRM) is a critical compliance obligation under SAMA CSF Domain 3 (Third-Party Management) and NCA ECC-1:2018 Control 3-3. Saudi banks must implement a structured, lifecycle-based approach covering vendor onboarding, ongoing monitoring, and offboarding.
Key requirements include:
- Risk-based vendor classification: Categorize suppliers based on data sensitivity, system criticality, and service dependency. Vendors with access to core banking or customer data require enhanced due diligence.
- Contractual security obligations (SAMA CSF Control 3.3.2): All third-party contracts must include mandatory cybersecurity clauses covering incident notification timelines (typically 72 hours), right-to-audit provisions, data handling obligations aligned with PDPL, and minimum security standards.
- Continuous monitoring: Implement annual security assessments for critical vendors and conduct surprise audits where contractually permitted. Use automated attack surface monitoring tools for real-time risk visibility.
- Concentration risk: SAMA expects banks to identify and mitigate vendor concentration risk, particularly for cloud and IT outsourcing providers. Document alternative arrangements and exit strategies.
- Board reporting: Senior management and board risk committees must receive regular TPRM dashboards reflecting vendor risk ratings, open findings, and remediation status.
Practical guidance: Establish a dedicated vendor risk register integrated with your GRC platform, ensure security questionnaires map explicitly to SAMA CSF and NCA ECC controls, and conduct tabletop exercises simulating a critical vendor failure. Non-compliance with TPRM requirements has been a recurring theme in SAMA regulatory findings, making this a top audit priority for 2024–2025.
Third-party risk management (TPRM) is a critical obligation under both SAMA CSF (Domain 4 – Third Party Risk Management) and NCA ECC (Control 2-14). Saudi financial institutions must establish a formal TPRM program covering the full vendor lifecycle: onboarding, ongoing monitoring, and offboarding.
Key requirements include:
- Risk-based classification: Categorize vendors by criticality and data sensitivity before engagement. SAMA CSF Control 4.1 mandates risk tiering to determine due diligence depth.
- Contractual obligations: All contracts with third parties must include cybersecurity clauses covering data protection, incident notification windows (typically 72 hours), right-to-audit provisions, and compliance with PDPL where personal data is processed.
- Security assessments: Conduct pre-onboarding security assessments and annual reviews for critical vendors. NCA ECC requires documented evidence of vendor compliance with applicable controls.
- Concentration risk: SAMA specifically flags cloud and outsourcing concentration risk — institutions must avoid over-dependence on a single vendor for critical services.
- Exit strategy: Maintain documented exit and transition plans to ensure business continuity if a vendor relationship is terminated.
Practical tip: Build a vendor risk register integrated into your GRC platform that tracks assessment status, residual risk ratings, contract renewal dates, and remediation actions. Automate vendor questionnaire distribution and scoring to reduce manual overhead and maintain audit-ready documentation for SAMA and NCA examinations.
Under SAMA CSF Domain 4 (Cybersecurity Resilience), Saudi banks and financial institutions must maintain robust Business Continuity Management (BCM) and Disaster Recovery (DR) capabilities. Key requirements include:
SAMA CSF Control 4.3 – Business Continuity Planning:
- Develop and maintain a Cyber Resilience Plan that aligns with the institution's overall BCM framework.
- Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for all critical systems, ensuring RTO for Tier-1 banking systems typically does not exceed 4 hours.
- Conduct Business Impact Analyses (BIA) annually to identify critical assets and acceptable downtime thresholds.
SAMA CSF Control 4.4 – Testing & Exercising:
- Perform full DR drills at least once per year, with tabletop exercises conducted semi-annually.
- Document test results, identify gaps, and remediate findings within agreed timelines.
- Simulate ransomware or cyber-attack scenarios during DR exercises to assess real-world resilience.
Practical Guidance:
- Maintain offline, immutable backups tested regularly for integrity and restoration speed.
- Ensure DR sites (whether on-premises or cloud-based) comply with NCA ECC geographic data residency requirements — primary and backup data must remain within Saudi Arabia.
- Integrate your Incident Response Plan with BCM so that a declared cyber incident automatically triggers continuity procedures.
- Assign clear ownership: a Cyber Resilience Owner accountable to the CISO should oversee BCM testing and reporting.
Non-compliance with SAMA CSF resilience controls may trigger supervisory action, including mandatory remediation plans and increased inspection frequency.
No matching questions found.
Didn't find what you're looking for?
✉️ Contact Us