Understanding SAMA CSF Governance Requirements
The SAMA Cyber Security Framework (CSF) mandates that financial institutions establish a formal cybersecurity governance structure with clearly defined roles, responsibilities, and accountability. This is not optional delegation—the Board and senior management must demonstrate active oversight of cyber risk as a business risk, not a technology issue.
Evidence of compliance includes:
- Board-approved cybersecurity policy and strategy aligned to the institution's risk appetite
- Documented cyber risk governance charter specifying the Chief Information Security Officer (CISO) or equivalent authority and their reporting line
- Meeting minutes showing Board review of cyber incidents, risk assessments, and control effectiveness at least quarterly
- Audit committee sign-off on cybersecurity audit findings and remediation plans
Many institutions still rely on informal governance or bury cyber oversight in IT committees. SAMA expects a dedicated governance body—whether a cyber risk committee or equivalent—with cross-functional membership (finance, compliance, operations, technology) and documented terms of reference.
Risk Assessment and Management Evidence
SAMA requires institutions to conduct comprehensive cybersecurity risk assessments at least annually, or more frequently if material changes occur. The framework aligns with ISO/IEC 27001:2022 and NIST CSF 2.0 principles, but adds specific financial-sector context.
Demonstrable evidence includes:
- Formal risk assessment reports identifying assets, threats, vulnerabilities, and residual risk ratings
- Risk heat maps or matrices showing business impact and likelihood for each identified risk
- Risk treatment plans with assigned owners, timelines, and budget allocation
- Documented risk appetite statement approved by the Board
- Evidence of reassessment following significant incidents, system changes, or regulatory updates
Self-assessment alone is insufficient. SAMA expects third-party validation—either through external audit, penetration testing, or vulnerability assessments conducted by qualified independent firms. Documentation must show how findings were tracked, prioritized, and resolved.
Technical and Operational Controls
SAMA CSF specifies controls across seven domains: governance, asset management, access control, data protection, incident management, business continuity, and third-party risk. Evidence of implementation is critical.
For access control, institutions must demonstrate:
- Multi-factor authentication (MFA) for all privileged accounts and remote access
- Privileged Access Management (PAM) system logs showing who accessed what, when, and why
- Quarterly access reviews with documented approval and deprovisioning of unused accounts
- Role-based access control (RBAC) policies aligned to job functions
For incident management, evidence includes:
- Incident response plan with defined escalation procedures and contact lists
- Incident log showing detection, investigation, containment, and recovery timelines
- Root cause analysis reports for material incidents
- Evidence of notification to SAMA and affected customers within required timeframes
SAMA expects institutions to maintain a Security Operations Centre (SOC) or equivalent monitoring capability. Evidence includes 24/7 log aggregation, alerting rules, and response procedures documented and tested.
Compliance Verification and Audit Readiness
SAMA conducts on-site examinations and requests evidence during supervisory reviews. Institutions should maintain a compliance evidence repository organized by CSF domain, with version control and audit trails.
Recommended structure:
- Policy library with approval dates and review cycles
- Control testing reports from internal audit or external assessors
- Remediation tracking system showing status of identified gaps
- Training and awareness records demonstrating staff competency
- Third-party risk assessments and vendor security certifications (ISO 27001, SOC 2)
Institutions should conduct annual self-assessments against SAMA CSF using the same criteria SAMA applies. This identifies gaps before supervisory review and demonstrates mature risk management culture.
Alignment with Broader Regulatory Landscape
SAMA CSF aligns with the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) and the Saudi Personal Data Protection Law (PDPL). Institutions must evidence compliance across all three frameworks—they are complementary, not redundant.
Financial institutions should map their controls to SAMA CSF, NCA ECC, and PDPL requirements in a single framework to avoid duplication and ensure comprehensive coverage. This integrated approach simplifies audit and demonstrates governance maturity to regulators and stakeholders.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment