SAMA Cyber Security Framework: Current Scope and Principles
The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework, updated to align with international best practice, now mandates a comprehensive, risk-driven approach to cybersecurity governance across all financial institutions operating in the Kingdom. Unlike prescriptive checklists, the framework emphasizes outcome-based compliance—institutions must demonstrate that their controls effectively mitigate identified risks and protect critical assets.
The framework is structured around five core pillars: governance and risk management, asset and data protection, operational resilience, incident response and recovery, and third-party and supply-chain security. Each pillar aligns with NIST Cybersecurity Framework 2.0 functions (Govern, Protect, Detect, Respond, Recover) and incorporates principles from ISO/IEC 27001:2022, ensuring compatibility with global standards and facilitating cross-border financial operations.
Key Expectations for 2026 Compliance
1. Board-Level Governance and Accountability
SAMA now requires explicit board oversight of cybersecurity strategy, risk appetite, and resource allocation. Boards must receive quarterly cybersecurity performance reports, including metrics on control effectiveness, emerging threats, and regulatory changes. Institutions must evidence this through board minutes, governance charters, and documented risk committees with defined cybersecurity mandates.
2. Risk-Based Control Implementation
Rather than implementing generic controls, institutions must conduct formal risk assessments aligned with the Saudi Data Protection Law (PDPL) and its implementing regulations. Controls must be proportionate to risk: high-risk systems (payment processing, customer data repositories) require stronger authentication, encryption, and monitoring than lower-risk administrative systems. Evidence includes risk registers, control matrices, and documented risk acceptance decisions.
3. Continuous Monitoring and Metrics
Static annual assessments no longer suffice. SAMA expects continuous monitoring through Security Information and Event Management (SIEM) systems, vulnerability scanning, and threat intelligence integration. Institutions must maintain dashboards tracking key risk indicators (KRIs): mean time to detect (MTTD), mean time to respond (MTTR), patch compliance rates, and access review completion rates. Monthly reporting to senior management is standard practice.
4. Third-Party and Supply-Chain Security
Given the financial sector's reliance on vendors, SAMA mandates formal vendor risk assessments, contractual security requirements, and periodic audits. Institutions must evidence vendor due diligence through questionnaires, security certifications (ISO 27001, SOC 2 Type II), and contractual clauses requiring incident notification within 24–72 hours. A maintained vendor registry with risk ratings is essential.
5. Incident Response and Business Continuity
SAMA requires documented incident response plans with defined roles, escalation procedures, and communication protocols. Institutions must conduct annual tabletop exercises and maintain detailed incident logs—even for minor events—to demonstrate a mature incident management culture. Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) must be defined for critical systems and tested regularly.
6. AI and Emerging Technology Controls
As financial institutions adopt AI for fraud detection and customer service, SAMA expects controls aligned with NIST AI Risk Management Framework and ISO/IEC 42001. Institutions must document AI model validation, bias testing, and explainability measures, especially for systems affecting customer decisions or regulatory compliance.
How to Evidence Compliance
Documentation: Maintain a compliance evidence repository including policies, procedures, risk assessments, control test results, and audit reports. Use a control framework (e.g., COBIT 2019) to map SAMA expectations to specific controls and evidence artifacts.
Audit Trails: Implement logging and monitoring to create immutable records of security activities. Export and retain logs for at least one year; use log aggregation to correlate events across systems.
Assessments: Conduct annual internal audits and biennial external penetration tests. Document findings, remediation plans, and closure evidence. Share results with the board and SAMA as required.
Training Records: Maintain attendance records for mandatory cybersecurity training, phishing simulations, and incident response drills. Track completion rates by role and remediation of non-compliance.
Regulatory Reporting: Respond promptly to SAMA information requests and submit required cybersecurity metrics and incident notifications on schedule. Use standardized templates to ensure consistency and reduce interpretation disputes.
Conclusion
SAMA's Cyber Security Framework in 2026 reflects a mature, risk-driven regulatory environment. Compliance is not a one-time project but an ongoing discipline requiring board commitment, skilled personnel, and integrated technology. Institutions that embed cybersecurity into business strategy, maintain transparent governance, and invest in continuous monitoring will not only meet regulatory expectations but also build resilience against evolving threats.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment