Understanding SAMA CSF Governance and Scope

The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework establishes a risk-based, control-oriented standard for all licensed financial institutions operating in the Kingdom. Unlike prescriptive checklists, the SAMA CSF organizes cybersecurity into functional domains—Governance, Asset Management, Access Control, Data Protection, Incident Management, and Business Continuity—each with defined maturity levels and evidence requirements.

Financial institutions must demonstrate that controls are not merely documented but actively operated, monitored, and improved. SAMA expects evidence of design, implementation, testing, and continuous review across all domains. This shift from checkbox compliance to outcome-focused assurance requires a structured evidence-gathering and reporting discipline.

Core Control Domains and Evidence Requirements

Governance and Risk Management

SAMA requires a documented cyber risk management strategy aligned with business objectives. Evidence includes a board-approved cyber security policy, defined roles and responsibilities, risk appetite statements, and regular board reporting on cyber metrics. Organizations must maintain a risk register that tracks identified threats, mitigation actions, and residual risk acceptance. Evidence of governance maturity includes meeting minutes, policy version control, and audit trails of policy reviews.

Asset Management and Inventory

Institutions must maintain an authoritative inventory of all IT and operational technology assets, including hardware, software, data repositories, and cloud services. Evidence includes automated discovery tools, asset classification matrices, and documented ownership chains. Regular reconciliation between the inventory and actual deployed assets—supported by audit logs—demonstrates control effectiveness. SAMA expects evidence that shadow IT is identified and managed, not ignored.

Access Control and Identity Management

Multi-factor authentication, role-based access control (RBAC), and privileged access management (PAM) are foundational. Evidence includes access control matrices, approval workflows, periodic access reviews with sign-off, and logs of access provisioning and revocation. Organizations must demonstrate that access is granted on a least-privilege basis and that dormant accounts are regularly deprovisioned. Testing evidence—such as penetration test results showing unauthorized access attempts blocked—strengthens this domain.

Data Protection and Privacy

SAMA CSF aligns with the Saudi Personal Data Protection Law (PDPL). Evidence includes data classification schemes, encryption inventories (both in transit and at rest), data retention policies, and breach response procedures. Organizations must document data handling agreements with third parties and evidence of staff training on data protection obligations. Incident response logs demonstrating timely breach notification and remediation are critical.

Incident Detection and Response

A mature Security Operations Center (SOC) or equivalent detection capability is expected. Evidence includes Security Information and Event Management (SIEM) configurations, alert tuning records, incident response playbooks, and logs of incident investigations. Organizations must demonstrate that incidents are logged, escalated according to severity, and resolved with root-cause analysis. Tabletop exercises and incident simulation drills provide evidence of readiness.

Business Continuity and Resilience

Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) must be defined for critical systems. Evidence includes backup testing logs, disaster recovery plan reviews, failover tests, and documented lessons learned. SAMA expects evidence that backup integrity is regularly verified and that restoration procedures are tested at least annually.

Building an Evidence Framework

Effective compliance requires a centralized evidence repository—often a governance, risk, and compliance (GRC) platform—where control documentation, test results, audit findings, and remediation actions are tracked and timestamped. This repository should link each control to relevant policies, procedures, test evidence, and responsible parties.

Regular internal audits and third-party assessments provide independent verification. SAMA expects institutions to conduct annual cyber risk assessments and to document how findings are remediated. Evidence of management review and sign-off on control effectiveness is essential for demonstrating accountability.

Alignment with Broader Standards

The SAMA CSF aligns with ISO/IEC 27001:2022 and NIST Cybersecurity Framework 2.0. Many organizations use these international standards as operational foundations while mapping their controls to SAMA domains for regulatory reporting. This dual approach strengthens both compliance and resilience.

Security leaders in Saudi Arabia and the GCC should treat evidence gathering not as a compliance burden but as a mechanism for continuous improvement. Documented controls, regular testing, and transparent reporting to senior management create accountability, reduce risk, and demonstrate to regulators that cybersecurity is embedded in the organization's operational culture.