Understanding SAMA's Current Expectations

The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework establishes a tiered control environment for all regulated financial institutions operating in the Kingdom. Unlike prescriptive checklists, the framework demands evidence of risk-based governance, proportionate technical controls, and measurable incident response capability. SAMA examiners now assess not just whether controls exist, but whether they are documented, tested, and aligned to the institution's risk appetite and business model.

The framework aligns with international standards—particularly ISO/IEC 27001:2022 and NIST CSF 2.0—while reflecting Saudi Arabia's regulatory priorities under the National Cybersecurity Authority (NCA) and the Personal Data Protection Law (PDPL). This convergence means compliance evidence must address three overlapping domains: financial stability, data protection, and critical infrastructure resilience.

Key Domains SAMA Examiners Review

1. Governance and Risk Management

SAMA expects documented proof of:

  • Board-level cyber oversight: Board minutes, cyber risk reporting cadence, and evidence that cyber risk is treated as a business risk, not just an IT issue.
  • Chief Information Security Officer (CISO) accountability: Clear reporting line, defined authority, and documented cyber strategy approved by senior management.
  • Risk assessment and treatment: Annual risk assessments covering financial, operational, and reputational impacts; documented risk register; and evidence of risk treatment decisions with business sign-off.
  • Third-party and supply-chain risk: Vendor assessment frameworks, contractual security clauses, and periodic audits of critical service providers.

2. Technical and Operational Controls

Examiners verify implementation and testing of:

  • Access control: Privileged access management (PAM), multi-factor authentication (MFA) for sensitive systems, and periodic access reviews with documented approval.
  • Data protection: Encryption of data at rest and in transit, data classification, and evidence of PDPL compliance (consent, retention, and subject rights).
  • Network segmentation and monitoring: Documented network architecture, intrusion detection/prevention systems (IDS/IPS), and Security Operations Centre (SOC) logs showing active threat hunting and anomaly investigation.
  • Patch and vulnerability management: Vulnerability scanning results, patch deployment schedules, and evidence of remediation timelines for critical findings.
  • Incident detection and response: SOC playbooks, alert tuning metrics, mean time to detect (MTTD) and mean time to respond (MTTR) KPIs, and tabletop exercise records.

3. Incident Response and Business Continuity

SAMA mandates:

  • Incident response plan: Written procedures, defined roles, escalation paths, and notification protocols (including SAMA and NCA notification timelines).
  • Testing and drills: Annual tabletop exercises, simulated breach scenarios, and documented lessons learned with remediation tracking.
  • Business continuity and disaster recovery: Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) aligned to financial criticality; regular testing with evidence of successful failover.
  • Forensic capability: Log retention policies, evidence preservation procedures, and access to forensic tools or third-party retainers.

How to Evidence Compliance

Documentation is your proof. SAMA examiners expect:

  • A cyber security policy framework signed by the board or audit committee.
  • Quarterly or annual cyber risk reports to senior management with metrics and trend analysis.
  • Risk assessment reports with risk ratings, treatment plans, and owner accountability.
  • SOC dashboards or reports showing detection rates, false positive ratios, and incident trends.
  • Vulnerability scan reports with remediation status tracked to closure.
  • Incident logs (sanitised for confidentiality) showing detection, investigation, containment, and recovery actions.
  • Training records demonstrating security awareness across the organisation.
  • Audit reports (internal and external) validating control effectiveness.

Practical Next Steps

If your institution has not yet mapped its controls to SAMA's framework, begin with a gap assessment. Prioritise governance documentation first—board awareness and risk ownership are foundational. Then systematically evidence technical controls through SOC metrics, patch reports, and access reviews. Finally, schedule and document incident response drills to demonstrate readiness.

Alignment with ISO/IEC 27001:2022 certification or NIST CSF maturity assessments strengthens your evidence posture and simplifies SAMA examination responses. The framework is not a one-time compliance exercise; it is a continuous cycle of assessment, remediation, testing, and reporting.