SAMA Framework: From Principle to Proof
The SAMA Cyber Security Framework (CSF) is not a voluntary guidance document—it is a binding regulatory requirement for all financial institutions operating in Saudi Arabia. As of 2026, the framework expects security leaders to move beyond policy statements and demonstrate active, measurable control implementation through evidence.
The core shift in SAMA's expectations is the transition from assertion-based compliance to evidence-based assurance. Regulators now require financial institutions to produce tangible proof that controls are in place, functioning, and monitored continuously.
Key Control Domains and Evidence Requirements
Governance and Risk Management
SAMA requires documented governance frameworks that align with the National Cybersecurity Authority (NCA) Essential Cyber Controls (ECC). Evidence must include:
- Board-approved cybersecurity policies and risk appetite statements
- Documented role definitions for Chief Information Security Officers (CISOs) and security committees
- Risk assessment reports updated at least annually, with evidence of board review
- Incident response plans tested and validated with dated records
Institutions must also align with the Saudi Personal Data Protection Law (PDPL) and its implementing regulations. This means maintaining evidence of data classification, consent mechanisms, and breach notification procedures.
Technical Controls and Detection
SAMA expects organizations to implement controls aligned with the NCA ECC and ISO/IEC 27001:2022 standards. Evidence includes:
- Configuration baselines for critical systems, with version control and change logs
- Security Information and Event Management (SIEM) logs showing continuous monitoring
- Vulnerability assessment reports with remediation timelines and closure evidence
- Access control matrices documenting who has access to what, and why
- Encryption implementation records for data in transit and at rest
A functioning Security Operations Center (SOC), whether in-house or outsourced, must produce daily or real-time alert logs, escalation procedures, and investigation records. SAMA auditors will request samples of incident detection and response timelines.
Third-Party and Supply Chain Risk
Financial institutions handle sensitive data and critical infrastructure. SAMA requires evidence of vendor risk management:
- Vendor security assessment questionnaires and audit reports
- Service Level Agreements (SLAs) with explicit cybersecurity clauses
- Periodic penetration testing results for critical third-party integrations
- Incident notification agreements with documented response procedures
How to Structure Your Evidence Program
Documentation Repository: Maintain a centralized, version-controlled repository of all security policies, procedures, and control evidence. This should be indexed by SAMA control domain and NCA ECC reference.
Control Testing Schedule: Establish a rolling schedule of control testing—both automated (via SIEM, vulnerability scanners) and manual (penetration tests, policy audits). Document the frequency, scope, and results of each test.
Audit Trail Preservation: Ensure all system logs, change management records, and access logs are retained for the period specified by SAMA (typically 12–24 months) and are tamper-evident.
Metrics and Dashboards: Create dashboards that show control status, remediation rates, and incident trends. These should be reviewable by the board and SAMA examiners.
Regular Self-Assessment: Conduct internal assessments using the SAMA CSF checklist at least annually. Document findings, remediation actions, and closure evidence.
Common Gaps in Evidence Submission
Many institutions fail SAMA compliance reviews not because controls are absent, but because evidence is poorly organized or incomplete. Typical gaps include:
- No documented link between policy and technical implementation
- Logs and alerts not retained or searchable
- Incident response drills conducted but not documented with findings
- Vendor assessments outdated or missing
- No evidence of board oversight or management review
Preparing for SAMA Examination
When SAMA examiners arrive, they will request a sample of evidence across all control domains. Prepare by:
- Creating an evidence index mapped to the SAMA CSF
- Designating a compliance coordinator to manage document requests
- Running a mock examination using the SAMA CSF assessment tool
- Aligning with NCA ECC and ISO/IEC 27001:2022 to ensure no gaps
Compliance is not a one-time event. SAMA expects continuous improvement, and your evidence program must reflect that maturity over time.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment