SAMA Framework Overview and Scope
The Saudi Central Bank's Cyber Security Framework (SAMA CSF) establishes binding requirements for all banks, insurance companies, and financial services entities operating under SAMA's supervision. The framework aligns with the National Cybersecurity Authority's Essential Cybersecurity Controls (NCA ECC) and international standards including NIST CSF 2.0, ISO/IEC 27001:2022, and ISO/IEC 42001 for AI governance.
The framework covers five primary domains: governance and risk management, asset management and data protection, access control and identity management, security operations and incident response, and business continuity and resilience. Compliance is not optional—SAMA expects all supervised entities to meet baseline controls within defined timelines and provide evidence of implementation.
Governance and Risk Management Evidence
SAMA requires financial institutions to establish a formal cybersecurity governance structure with board-level oversight and a dedicated Chief Information Security Officer (CISO) or equivalent. To evidence this requirement, organisations must document:
- Board-approved cybersecurity strategy and annual risk assessment reports
- CISO appointment letters and defined roles, responsibilities, and reporting lines
- Documented cybersecurity policies covering all domains (access, data handling, incident response, third-party management)
- Quarterly risk review minutes and board reporting on key metrics
- Regulatory gap assessments against SAMA CSF and NCA ECC controls
Institutions should maintain a control register mapping each SAMA requirement to implemented controls, responsible teams, and testing frequency. This register becomes the primary artefact during regulatory examinations.
Technical Controls and Testing Evidence
SAMA mandates specific technical controls: network segmentation, encryption of sensitive data at rest and in transit, multi-factor authentication for privileged access, endpoint detection and response (EDR) capabilities, and security information and event management (SIEM) systems. Evidence includes:
- Network architecture diagrams showing segmentation and DMZs
- Encryption inventory and key management procedures
- MFA deployment logs and user access reviews
- EDR and SIEM configuration documentation and alert tuning records
- Vulnerability scanning and penetration testing reports, with remediation tracking
- Annual security control testing results (both internal and third-party assessments)
SAMA expects annual independent assessments of critical controls. Many institutions engage external auditors to verify compliance against the framework and produce attestation reports suitable for regulatory submission.
Incident Response and Business Continuity
Institutions must evidence an active incident response capability and tested business continuity plans. Required documentation includes:
- Incident response procedures and contact trees
- Annual tabletop exercises and full-scale incident simulations with documented outcomes
- Business continuity and disaster recovery plans with recovery time objectives (RTOs) and recovery point objectives (RPOs)
- Annual testing of backup and recovery procedures with signed test reports
- Incident log showing detection, investigation, remediation, and lessons learned
Third-Party and Supply Chain Risk
SAMA requires oversight of vendors and outsourced service providers. Evidence should include:
- Vendor risk assessment framework and scoring methodology
- Contracts with cybersecurity clauses (audit rights, incident notification, data handling)
- Annual vendor security assessments or third-party audit reports (SOC 2 Type II, ISO 27001 certificates)
- Documented vendor incident response and escalation procedures
Data Protection and Privacy Alignment
SAMA CSF aligns with the Saudi Personal Data Protection Law (PDPL) and its implementing regulations. Institutions must demonstrate data inventory, classification, and protection controls. Evidence includes data processing impact assessments, consent records, and procedures for handling data subject requests.
Practical Compliance Roadmap
Financial institutions should begin by conducting a baseline assessment against SAMA CSF and NCA ECC. Prioritise high-risk gaps and develop a phased remediation plan with clear ownership and timelines. Invest in a governance platform or control management tool to centralise policy, testing, and evidence. Engage SAMA early through supervisory dialogue to clarify expectations and confirm alignment.
Compliance is a continuous cycle—SAMA expects institutions to review and update controls annually, respond to emerging threats, and maintain current evidence. Documentation discipline and board visibility are essential to demonstrate a mature, sustainable cybersecurity posture.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment