The SAMA Cyber Security Framework: Current Expectations

The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework establishes mandatory controls for all financial institutions operating in the Kingdom. Unlike earlier guidance that emphasised principle-based compliance, the current framework—aligned with the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) and NIST CSF 2.0—requires financial institutions to produce concrete evidence of implementation, monitoring, and continuous improvement.

Security leaders must understand that SAMA auditors and examiners now expect to see documented artefacts at every control level: governance policies, risk registers, technical configurations, audit logs, incident records, and training completion certificates. Assertions without evidence carry minimal weight.

Five Core Evidence Categories SAMA Auditors Examine

1. Governance and Risk Management Artefacts

SAMA expects a board-approved cybersecurity strategy and a documented Information Security Management System (ISMS) aligned with ISO/IEC 27001:2022. Auditors will request:

  • Board resolutions and risk committee minutes demonstrating cybersecurity oversight
  • A current risk register showing cyber threats, likelihood, impact, and mitigation owners
  • Security policies covering access control, data classification, and incident response
  • Evidence of annual risk assessments with sign-off from senior management

The SAMA framework now explicitly aligns with the Saudi Data Protection Law (PDPL) and its implementing regulations. Auditors will verify that data handling policies address personal data protection obligations and that privacy impact assessments are completed for new systems.

2. Technical and Operational Controls

Auditors expect to see configuration baselines, change logs, and vulnerability management records. Specific evidence includes:

  • Network diagrams and system inventory records
  • Patch management schedules and compliance reports
  • Multi-factor authentication (MFA) implementation logs
  • Encryption certificates and key management audit trails
  • Firewall and intrusion detection system (IDS) configurations and alert logs

For financial institutions, SAMA also mandates segregation of duties (SoD) matrices and privileged access management (PAM) logs. Auditors will sample access requests and approvals to verify no single individual can initiate, authorise, and execute critical transactions.

3. Monitoring, Detection, and Response Evidence

A Security Operations Centre (SOC)—whether in-house or outsourced—must produce daily, weekly, and monthly security monitoring reports. SAMA expects:

  • Centralised logging and SIEM dashboards showing real-time threat detection
  • Incident logs with timestamps, severity classifications, and resolution records
  • Playbooks for common attack scenarios (phishing, ransomware, DDoS)
  • Evidence of tabletop exercises or simulated incident drills at least annually
  • Third-party penetration test and vulnerability assessment reports

Auditors will trace specific incidents through the full lifecycle: detection, investigation, containment, eradication, recovery, and post-incident review. Gaps in documentation or delayed responses are red flags.

4. Third-Party and Supply Chain Risk Management

SAMA now emphasises vendor risk assessments. Auditors will examine:

  • Vendor security questionnaires and certifications (ISO 27001, SOC 2, etc.)
  • Service level agreements (SLAs) with explicit security and availability clauses
  • Audit rights and periodic security assessments of critical vendors
  • Incident notification protocols and contractual remediation timelines

For cloud and outsourced services, SAMA expects data residency confirmations and evidence that customer data is not co-mingled with other institutions' data without explicit consent.

5. Training, Awareness, and Capability Evidence

SAMA auditors will request:

  • Annual security awareness training completion records for all staff
  • Specialist certifications for security personnel (CISSP, CISM, CCSK, etc.)
  • Phishing simulation campaign results and remedial training for repeat offenders
  • Board and executive cybersecurity briefing agendas and attendance records

Practical Steps to Build Audit-Ready Evidence

Document everything. Implement a centralised control repository (e.g., a GRC platform) that links policies, risk assessments, technical configurations, and audit logs. Assign clear ownership and review cycles.

Automate compliance reporting. Use SIEM, vulnerability scanners, and identity governance tools to generate continuous evidence of control operation. Manual, point-in-time reports are less persuasive than ongoing logs.

Align with international standards. Map your controls to ISO/IEC 27001:2022, NIST CSF 2.0, and the NCA ECC. SAMA examiners are familiar with these frameworks and expect cross-referencing.

Conduct internal audits. Before SAMA arrives, perform your own control testing and remediate gaps. Document the audit scope, findings, and corrective actions.

Engage external assessors. Commission independent penetration tests and vulnerability assessments annually. These third-party reports carry significant weight with regulators.

Conclusion

SAMA's current Cyber Security Framework is not a checklist; it is a mandate for demonstrable, measurable security maturity. Financial institutions that invest in robust governance, technical controls, monitoring, and continuous improvement—and that meticulously document every step—will satisfy auditor expectations and build genuine resilience against evolving threats.