The SAMA Framework: Scope and Expectations

The Saudi Central Bank's Cyber Security Framework establishes mandatory security and resilience standards for all financial institutions under SAMA's supervision. Unlike advisory guidance, the Framework is a regulatory requirement. Financial institutions must demonstrate compliance across three pillars: governance and risk management, operational resilience, and technical controls. Auditors and compliance teams are expected to evidence each pillar through documented artefacts, not assertions alone.

Governance and Board Accountability

SAMA expects the board of directors or equivalent governing body to own cybersecurity as a strategic risk. Evidence of compliance includes:

  • Board-approved cybersecurity policy and strategy — aligned with the institution's business objectives and risk appetite, reviewed and updated at least annually.
  • Documented board oversight records — minutes showing regular (typically quarterly or more frequent) review of cyber incidents, risk metrics, and remediation progress.
  • Chief Information Security Officer (CISO) or equivalent role — with clear mandate, budget, and direct reporting line to the board or audit committee, not buried in IT operations.
  • Risk appetite statement — explicit tolerance for cyber risk, approved by the board and cascaded to business units.

Auditors should verify that board discussions are substantive, not ceremonial. Meeting minutes should reference specific threats, control gaps, and decisions, not generic summaries.

Risk Management and Third-Party Oversight

SAMA requires institutions to identify, assess, and monitor cybersecurity risks continuously. Key evidence includes:

  • Annual cyber risk assessment — covering assets, threats, vulnerabilities, and business impact. Must be documented and traceable to business process owners.
  • Third-party and vendor risk management programme — with due diligence questionnaires, security assessments, and contractual security clauses for all critical service providers (cloud, payment processors, data centres).
  • Business continuity and disaster recovery (BCDR) plans — tested at least annually, with documented results and remediation of gaps.
  • Incident response and crisis communication plan — tested through tabletop exercises or simulations, with evidence of cross-functional participation.

Align third-party assessments with NCA ECC (National Cybersecurity Authority Essential Cyber Controls) and the Saudi Personal Data Protection Law (PDPL) requirements for data processors and handlers.

Technical Controls and Operational Resilience

SAMA expects technical controls proportionate to risk. Auditors should verify:

  • Access control and authentication — multi-factor authentication for privileged accounts, role-based access control (RBAC) policies, and periodic access reviews.
  • Data protection — encryption of data in transit and at rest, data classification, and compliance with PDPL data minimization and retention rules.
  • Monitoring and logging — centralized Security Operations Centre (SOC) or equivalent, with 24/7 monitoring, alerting, and log retention aligned to regulatory timelines.
  • Vulnerability and patch management — documented processes, timelines for critical patches (typically 30 days or less), and evidence of testing before deployment.
  • Security awareness training — mandatory for all staff, with documented attendance and phishing simulation results.

Alignment with ISO/IEC 27001:2022 and NIST CSF 2.0

Many institutions reference ISO/IEC 27001:2022 certification or NIST Cybersecurity Framework 2.0 as supplementary evidence of control maturity. SAMA does not mandate either, but auditors increasingly expect alignment. Map SAMA requirements to the relevant ISO/IEC 27001:2022 controls (e.g., A.5 Organizational Controls, A.8 Asset Management) and NIST CSF 2.0 functions (Govern, Protect, Detect, Respond, Recover) to streamline audit and certification efforts.

Documentation and Audit Trail

SAMA auditors and external auditors will request evidence. Prepare:

  • Board minutes and cybersecurity committee papers.
  • Risk assessment reports with sign-off.
  • Vendor risk assessments and contracts.
  • BCDR test reports and remediation logs.
  • Incident register and post-incident reviews.
  • Training records and phishing campaign results.
  • Vulnerability scans and patch deployment logs.

Store these centrally and ensure version control. Auditors expect a clear audit trail from policy to execution to evidence of effectiveness.

Practical Next Steps

If your institution has not yet formally mapped SAMA requirements to your control environment, begin with a gap assessment. Engage the board, CISO, and compliance teams to prioritize gaps and define remediation timelines. Pilot testing of incident response and BCDR plans early; results often reveal process and communication gaps that are easier to fix before a real incident. Finally, document everything — SAMA compliance is as much about demonstrable governance as it is about technical capability.