SAMA Cyber Security Framework: The Regulatory Baseline

The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework represents the authoritative standard for financial institutions operating in the Kingdom. Unlike advisory guidelines, SAMA's framework is binding on all banks, insurance companies, and payment service providers. Compliance is not optional; it is a condition of regulatory license and operational continuity.

The framework aligns with international standards—including ISO/IEC 27001:2022 and NIST Cybersecurity Framework 2.0—while reflecting Saudi Arabia's regulatory philosophy and the threat landscape specific to the GCC region. Financial institutions must treat SAMA expectations as a floor, not a ceiling.

Five Core Pillars: What You Must Evidence

1. Governance and Risk Ownership

SAMA requires documented board-level accountability for cybersecurity. Evidence must include:

  • Board-approved cybersecurity strategy aligned with business objectives
  • Defined roles: Chief Information Security Officer (CISO) with direct reporting to executive leadership
  • Documented risk appetite and tolerance thresholds for cyber threats
  • Board meeting minutes demonstrating quarterly or semi-annual cyber risk reviews

Boards often delegate cyber oversight to audit or risk committees. SAMA expects to see formal charters, attendance records, and evidence that cyber risk is treated as a strategic business risk, not a technical IT issue.

2. Risk Assessment and Management

Annual, documented risk assessments are mandatory. Your evidence should demonstrate:

  • Comprehensive asset inventory (hardware, software, data, third-party dependencies)
  • Threat modeling specific to your institution's business model and customer base
  • Vulnerability scanning and penetration testing results, with remediation tracking
  • Third-party and supply-chain risk evaluations, especially for critical service providers
  • Risk registers that map threats to controls and show residual risk acceptance

SAMA auditors expect to see that risk assessments are not one-time exercises. Maintain evidence of updates triggered by significant business changes, new threats, or regulatory changes.

3. Access Control and Identity Management

SAMA mandates strong authentication and least-privilege access. Demonstrate:

  • Multi-factor authentication (MFA) for all administrative and remote access
  • Role-based access control (RBAC) matrices, reviewed and approved annually
  • Privileged access management (PAM) solutions with session recording for high-risk accounts
  • User access reviews with sign-off from business owners
  • Timely deprovisioning of leavers and role-changers

Maintain audit logs showing who accessed what, when, and why. SAMA expects these logs to be retained for at least one year and protected against tampering.

4. Incident Response and Business Continuity

SAMA requires a documented incident response plan and evidence of its effectiveness:

  • Incident response plan approved by senior management, with clear escalation paths
  • Defined roles and contact information for the incident response team
  • Tabletop exercises or simulations conducted at least annually, with documented outcomes
  • Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets for critical systems
  • Business continuity and disaster recovery testing results
  • Incident logs showing detection, containment, eradication, and recovery timelines

SAMA also expects institutions to report significant cyber incidents to the regulator within defined timeframes. Maintain evidence of notifications and remediation actions taken.

5. Awareness, Training, and Third-Party Management

Human and organizational factors are central to SAMA expectations:

  • Annual mandatory cybersecurity training for all staff, with completion records
  • Role-specific training for developers, system administrators, and security teams
  • Phishing simulation campaigns with metrics on click rates and reporting behavior
  • Third-party vendor assessments, including security questionnaires and audit rights
  • Contracts that impose cybersecurity obligations aligned with SAMA requirements

Practical Compliance Steps

Document everything. SAMA audits rely on evidence. Maintain organized repositories of policies, risk assessments, training records, audit logs, and incident reports. Use a governance, risk, and compliance (GRC) platform to centralize and version-control documentation.

Align with the National Cybersecurity Authority (NCA) standards. The NCA's Essential Cyber Controls (ECC) and the broader Saudi cybersecurity ecosystem (including the Saudi Personal Data Protection Law, PDPL) reinforce SAMA's expectations. Treat them as complementary, not separate.

Engage internal audit and external assessors. Regular third-party assessments (ISO/IEC 27001:2022 certification, penetration testing) provide independent evidence of control effectiveness and identify gaps before SAMA does.

Plan for maturity growth. SAMA does not expect perfection overnight, but it expects documented progress. Demonstrate a roadmap for improving controls, with timelines and accountability.

The Bottom Line

SAMA's Cyber Security Framework is not abstract. It translates into concrete control requirements and evidence obligations. Financial institutions that treat compliance as a checkbox exercise, rather than as an integral part of risk management, expose themselves to regulatory action, reputational damage, and operational disruption. Security leaders who can articulate what they are protecting, how they are protecting it, and how they know it is working will satisfy SAMA's expectations and build resilience in an increasingly hostile threat environment.