Understanding SAMA's Current Cyber Security Framework

The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework remains the authoritative standard for financial institutions operating in the Kingdom. Unlike prescriptive checklists, the framework establishes outcome-focused requirements across five core pillars: governance and risk management, security operations, incident response and business continuity, third-party risk management, and regulatory reporting. Financial leaders must recognize that SAMA expects demonstrable, auditable evidence of compliance—not merely policy documents filed away.

The framework aligns with international standards including ISO/IEC 27001:2022 and NIST CSF 2.0, but tailors expectations to Saudi Arabia's financial ecosystem and regulatory context. SAMA supervisors now conduct regular examinations to verify that institutions have implemented controls proportionate to their risk profile and asset criticality.

Key Compliance Pillars and Evidence Requirements

Governance and Cyber Risk Oversight

SAMA requires a documented cyber governance structure with clear accountability. Evidence includes:

  • Board-level cyber risk committee charter with defined responsibilities and meeting minutes
  • Annual cyber risk assessments signed off by the Chief Information Security Officer (CISO) and board
  • Cyber security budget allocation and resource plans approved at executive level
  • Written cyber security strategy aligned to business objectives, reviewed and updated annually

Many institutions fail this pillar not because they lack controls, but because they cannot produce a coherent audit trail showing board engagement. SAMA examiners expect to see evidence that senior management actively monitors and approves cyber investments.

Technical Controls and Asset Management

SAMA expects institutions to maintain an authoritative inventory of critical assets, systems, and data flows. Required evidence includes:

  • Documented asset register with classification by criticality and sensitivity
  • Network diagrams and data flow maps reviewed and certified by the CISO
  • Access control matrices showing role-based permissions, reviewed quarterly
  • Patch management and vulnerability remediation logs with defined SLAs
  • Encryption standards for data at rest and in transit, with key management procedures

Institutions must also evidence multi-factor authentication for privileged accounts, logging and monitoring of critical systems, and regular security testing (vulnerability scans, penetration tests). SAMA now expects at least annual third-party penetration testing with findings remediated and documented.

Incident Response and Business Continuity

SAMA mandates formal incident response and disaster recovery plans with documented testing. Evidence includes:

  • Incident response plan with defined roles, escalation procedures, and communication protocols
  • Tabletop exercises or simulations conducted at least annually, with attendance records and findings
  • Business continuity and disaster recovery plans tested quarterly, with recovery time objective (RTO) and recovery point objective (RPO) targets documented
  • Incident log showing detection, investigation, remediation, and lessons learned for all security events

Critical is the ability to demonstrate that incidents are reported to SAMA within required timeframes and that root-cause analysis findings drive control improvements.

Third-Party Risk Management

With increasing reliance on vendors and cloud services, SAMA expects rigorous third-party oversight. Evidence includes:

  • Vendor risk assessment questionnaires completed and scored before engagement
  • Service-level agreements (SLAs) with explicit cyber security and data protection clauses
  • Annual vendor audits or SOC 2 Type II reports reviewed and documented
  • Contractual right to conduct security assessments and audit vendor controls

Practical Steps to Evidence Compliance

Establish a compliance register. Map each SAMA requirement to specific policies, procedures, and control evidence. Update quarterly and present to the board.

Conduct a third-party assessment. Engage an independent auditor to validate compliance against SAMA CSF. Use findings to prioritize remediation and demonstrate good-faith effort to regulators.

Integrate with the Saudi PDPL. Ensure cyber controls also satisfy data protection obligations under the Personal Data Protection Law and its implementing regulations. SAMA and the National Cybersecurity Authority (NCA) increasingly expect coordinated compliance.

Document everything. Create a secure repository of policies, audit reports, testing results, and board minutes. SAMA examiners will request evidence; institutions must produce it promptly and in organized form.

Looking Ahead

SAMA's expectations continue to evolve in response to emerging threats, regulatory alignment with international standards, and lessons from financial sector incidents across the GCC. Institutions that treat the framework as a checklist rather than a strategic imperative will struggle during examinations. Those that embed cyber governance into business operations and maintain transparent, auditable compliance evidence will demonstrate resilience and earn regulator confidence.