Understanding SAMA's Current Expectations
The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework establishes a mandatory baseline for all financial institutions and critical infrastructure operators under its supervision. Unlike prescriptive checklists, SAMA's framework uses a maturity-based approach aligned with international standards including NIST CSF 2.0 and ISO/IEC 27001:2022, requiring organisations to evidence progressively sophisticated controls across governance, risk management, technical security and incident response.
Security leaders must recognise that SAMA compliance is not a one-time audit exercise. The framework demands continuous evidence of risk-based decision-making, board-level oversight, and integration of cybersecurity into business strategy. This shift from checkbox compliance to outcome-focused governance reflects global regulatory trends and the evolving threat landscape facing Saudi financial services.
Core Pillars and Evidence Requirements
Governance and Risk Management
SAMA expects documented evidence of:
- Board and senior management accountability for cybersecurity strategy, with meeting minutes and decisions recorded
- A formal Cyber Risk Committee with defined charter, membership and escalation protocols
- Annual risk assessments aligned to the institution's risk appetite, with documented assumptions and sign-off
- Integration of cyber risk into enterprise risk management frameworks and business continuity plans
Evidence should include board papers, risk registers, policy approval records and governance meeting documentation. SAMA reviewers expect to trace cyber decisions from the board level through operational teams.
Technical and Operational Controls
The framework requires evidence of:
- Access control: Role-based access matrices, privileged access management (PAM) logs, and periodic access reviews with documented approval
- Data protection: Encryption inventories, key management procedures, and data classification policies applied across systems
- Network segmentation: Network diagrams, firewall rules documentation, and evidence of testing and monitoring
- Vulnerability management: Scanning schedules, remediation timelines, patch deployment records and exception approvals
- Incident response: Tabletop exercise reports, incident logs with root cause analysis, and evidence of lessons learned implementation
Security teams should maintain centralised repositories of control evidence—audit logs, configuration baselines, and test results—accessible for SAMA examinations.
Third-Party and Supply Chain Risk
SAMA expects documented vendor risk assessments, service level agreements with security clauses, and evidence of ongoing monitoring. This aligns with NCA ECC requirements and reflects the reality that cyber risk extends beyond organisational boundaries.
Aligning with Saudi PDPL and Data Governance
The Saudi Personal Data Protection Law (PDPL) and its implementing regulations reinforce SAMA's expectations on data handling. Security leaders must evidence:
- Data mapping and inventory aligned to PDPL definitions of personal data
- Consent management systems with audit trails
- Data subject rights procedures (access, correction, deletion) with response timelines
- Data breach notification protocols tested and documented
SAMA views PDPL compliance as integral to cybersecurity governance, not a separate legal function. Evidence should show cross-functional accountability between security, legal and data governance teams.
Practical Evidence Collection Strategy
Security leaders should establish a structured evidence management approach:
- Baseline documentation: Policies, procedures, architecture diagrams and control matrices, all version-controlled and dated
- Operational logs: Automated collection of security tool outputs—SIEM events, vulnerability scans, access logs—with retention aligned to SAMA's audit periods
- Testing and validation: Penetration test reports, control effectiveness assessments, and evidence of remediation
- Training and awareness: Attendance records, phishing simulation results and security culture metrics
- Continuous monitoring dashboards: Real-time visibility into control status, exceptions and remediation progress
Key Takeaway
SAMA compliance requires security leaders to shift from reactive incident management to proactive, evidence-based governance. The framework rewards organisations that embed cybersecurity into business decision-making, maintain transparent risk reporting and demonstrate measurable progress against defined maturity targets. Success depends on treating evidence collection as a continuous operational discipline, not a compliance sprint before an examination.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment