SAMA Cyber Security Framework: Core Pillars and Current Expectations

The Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework establishes mandatory governance and technical standards for all financial institutions operating in the Kingdom. Unlike prescriptive checklists, the framework operates on a risk-based approach aligned with international standards such as ISO/IEC 27001:2022 and NIST Cybersecurity Framework 2.0, requiring institutions to demonstrate why their controls are appropriate for their risk profile, not merely that they exist.

Governance and Accountability

SAMA expects a documented governance structure with clear accountability. This includes:

  • A Board-level Cyber Security Committee or equivalent oversight mechanism with defined charter and meeting cadence
  • A Chief Information Security Officer (CISO) or equivalent role with direct reporting line to the Chief Risk Officer or Board
  • Documented cybersecurity strategy aligned to business objectives and reviewed annually
  • Evidence of Board awareness and sign-off on cyber risk appetite and tolerance thresholds

To evidence governance, maintain Board minutes reflecting cyber discussion, CISO appointment letters, and signed strategy documents. SAMA examiners expect to see that governance is active—not ceremonial—through meeting records and documented decisions on resource allocation and risk acceptance.

Risk Assessment and Management

SAMA requires a formal, documented risk assessment process conducted at least annually, or more frequently if material changes occur. This must include:

  • Identification of critical assets, systems, and data flows
  • Threat and vulnerability analysis specific to the financial services sector
  • Impact and likelihood scoring using a defined methodology
  • Risk treatment decisions (mitigate, accept, transfer, avoid) with documented rationale
  • Residual risk reporting to governance

Evidence should include risk registers, assessment reports signed by appropriate stakeholders, and records of risk acceptance decisions. SAMA also expects alignment with sector-specific guidance from the National Cybersecurity Authority (NCA) and the Financial Sector Cyber Security Program (FSCSP).

Technical and Operational Controls

SAMA's framework requires implementation of controls across key domains:

  • Access Control: Multi-factor authentication for privileged accounts, role-based access control, and periodic access reviews
  • Data Protection: Encryption of sensitive data in transit and at rest, consistent with the Saudi Personal Data Protection Law (PDPL) and its implementing regulations
  • Network Security: Segmentation, intrusion detection/prevention, and monitoring of external connections
  • Incident Response: Documented plan with defined roles, communication protocols, and testing through tabletop exercises or simulations
  • Third-Party Risk: Due diligence on vendors, contractual security requirements, and periodic reassessment

Evidence includes configuration documentation, access control matrices, encryption certificates, network diagrams, and records of control testing. SAMA expects institutions to maintain a control inventory mapped to risks and to demonstrate that controls are tested and monitored continuously, not just annually.

Continuous Monitoring and Incident Response

SAMA mandates continuous security monitoring through Security Operations Center (SOC) capabilities, whether in-house or outsourced. This includes:

  • 24/7 log aggregation and analysis
  • Alert tuning and investigation procedures
  • Metrics and KPIs reported to governance monthly or quarterly
  • Incident reporting to SAMA within defined timelines (typically 24–72 hours for material incidents)

Evidence includes SOC metrics dashboards, incident logs with timestamps and investigation notes, and records of notifications sent to SAMA. Institutions must also maintain cyber insurance and ensure incident response plans are tested at least annually with documented results.

Compliance with PDPL and NCA Guidance

The Saudi Personal Data Protection Law (PDPL) and its current implementing regulations impose additional requirements for data handling and breach notification. SAMA expects institutions to integrate PDPL compliance into their cybersecurity program, with evidence of data inventory, processing impact assessments, and breach notification procedures.

Documentation and Audit Trail

SAMA examiners review evidence during on-site examinations and through regulatory returns. Maintain:

  • Policies and procedures (current, dated, and approved)
  • Training records for all staff with access to sensitive systems
  • Vulnerability assessment and penetration testing reports
  • Change management logs for critical systems
  • Audit reports from internal and external auditors

The key principle: if it is not documented, SAMA will assume it does not exist. Evidence must be contemporaneous, not retroactively created.

Conclusion

SAMA's framework is outcome-focused and risk-based. Compliance is demonstrated through governance structures, documented risk decisions, tested controls, continuous monitoring, and clear evidence of accountability. Financial institutions should view the framework not as a checkbox exercise but as a foundation for a mature, resilient cybersecurity program that protects both the institution and the broader financial system.