Understanding SAMA's Current Cyber Security Framework

The Saudi Arabian Monetary Authority (SAMA) has established a comprehensive Cyber Security Framework that applies to all financial institutions operating under its supervision. Unlike prescriptive checklists, the framework is principles-based and risk-driven, requiring institutions to identify their threat landscape, assess the impact of potential breaches, and implement proportionate controls.

The framework aligns with international standards including ISO/IEC 27001:2022 and NIST Cybersecurity Framework 2.0, but tailors expectations to the Saudi financial sector's specific vulnerabilities and strategic importance. SAMA expects institutions to move beyond point-in-time compliance audits toward continuous, demonstrable risk management.

Core SAMA Expectations for 2024 and Beyond

SAMA's framework rests on five foundational pillars:

  • Governance and Risk Management: Board-level oversight, a Chief Information Security Officer with executive authority, and documented risk appetite aligned to business strategy.
  • Asset and Data Protection: Inventory, classification, and encryption of sensitive data; secure disposal; and controls over third-party access.
  • Access Control and Identity Management: Multi-factor authentication, privileged access management, and role-based access control enforced across all systems.
  • Incident Response and Business Continuity: Tested response plans, forensic capability, and recovery time objectives (RTOs) that meet regulatory thresholds.
  • Third-Party and Supply Chain Risk: Vendor risk assessments, contractual security clauses, and ongoing monitoring of critical service providers.

Evidencing Compliance: What SAMA Auditors Expect

Regulatory examiners now demand contemporaneous, auditable evidence rather than retrospective documentation. Security leaders must establish:

Documented Policies and Procedures: Written information security policies approved by the Board, covering all framework domains. These must be reviewed annually and updated when the threat environment or business changes. Maintain version control and sign-off records.

Risk Assessment Records: Annual enterprise risk assessments that identify financial, operational, and cyber threats; quantify likelihood and impact; and map mitigating controls. Use a consistent methodology (e.g., NIST Risk Management Framework or ISO 31000) and retain assessment workpapers.

Control Testing and Monitoring Logs: Evidence that critical controls are tested at least annually by internal audit or a qualified external party. For continuous controls (e.g., access reviews, patch deployment), maintain automated logs showing execution, exceptions, and remediation.

Incident and Breach Records: A centralized log of all security incidents, including date, type, systems affected, root cause, and remedial actions. SAMA expects institutions to report material breaches within defined timeframes; maintain records of all reports submitted.

Training and Awareness Records: Documentation that all staff, particularly those handling sensitive data or systems, complete mandatory security training annually. Track completion rates and maintain certificates or attestations.

Third-Party Assessments: Engage an independent auditor or penetration testing firm annually to validate the design and operating effectiveness of key controls. SAMA recognizes assessments conducted under ISO/IEC 27001:2022 or equivalent frameworks.

Integration with Broader Regulatory Obligations

SAMA's Cyber Security Framework does not exist in isolation. Financial institutions must also align with:

  • The Saudi Personal Data Protection Law (PDPL) and its implementing regulations, which mandate data minimization, consent management, and breach notification.
  • The National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC), which set baseline expectations for all critical infrastructure operators.
  • PCI DSS 4.0 for payment card data, requiring encryption, tokenization, and secure development practices.

A unified compliance program that maps controls across all three frameworks reduces duplication and strengthens the overall security posture.

Practical Steps for Security Leaders

To evidence SAMA compliance effectively:

  • Conduct a gap analysis against the current SAMA framework and remediate high-risk gaps within 90 days.
  • Establish a compliance calendar with quarterly control testing, annual risk assessment, and board reporting cycles.
  • Implement a centralized control tracking system that links policies, risks, controls, and test results.
  • Engage a Big Four or regional audit firm to conduct an independent assessment and provide a remediation roadmap.
  • Brief the Board quarterly on cyber risk, compliance status, and emerging threats.

SAMA's shift toward continuous, evidence-based oversight reflects the sophistication of modern cyber threats. Institutions that embed compliance into operational workflows—rather than treating it as an annual exercise—will demonstrate resilience and reduce regulatory friction.