SAMA CSF: From Principles to Proof

The Saudi Central Bank (SAMA) Cyber Security Framework establishes mandatory governance, technical, and operational controls for all financial institutions operating in the Kingdom. Unlike prescriptive checklists, the framework is principles-based—but that does not mean evidence is optional. SAMA supervisors expect institutions to demonstrate how their security programme translates framework requirements into measurable, auditable outcomes.

The gap between "having controls" and "proving controls work" is where many institutions stumble. SAMA's examination teams assess compliance through documentation, testing, and interviews. Security leaders must therefore build an evidence architecture that shows not just what controls exist, but that they function, are monitored, and are continuously improved.

Core Evidence Pillars

1. Risk Assessment and Governance

SAMA requires a documented, board-approved cybersecurity strategy aligned with business objectives. Evidence includes:

  • Annual enterprise risk assessments covering digital assets, third-party dependencies, and emerging threats
  • Board minutes confirming cybersecurity oversight and budget allocation
  • A documented risk register with risk owners, mitigation plans, and residual risk acceptance sign-offs
  • Policies aligned with ISO/IEC 27001:2022 and the Saudi Personal Data Protection Law (PDPL) implementing regulations

Institutions must show that risk assessment is not a one-time exercise but a continuous cycle. Quarterly or semi-annual updates, with documented changes in threat landscape or control effectiveness, demonstrate active governance.

2. Technical Controls and Testing

SAMA expects evidence of effective preventive and detective controls. Acceptable evidence includes:

  • Vulnerability management reports showing discovery, remediation timelines, and closure verification
  • Penetration testing and red-team exercise results, with remediation tracking
  • Network segmentation diagrams and firewall rule documentation
  • Encryption inventories (data at rest and in transit) with key management procedures
  • Access control matrices showing role-based provisioning, periodic recertification, and privileged account monitoring logs

Testing must be independent or third-party validated. SAMA reviewers expect to see both the test results and evidence of remediation—not just a clean report, but proof that findings were addressed within acceptable timeframes.

3. Incident Response and Resilience

The framework mandates a tested incident response plan. Evidence requirements include:

  • A current, documented IR plan with defined roles, escalation paths, and communication protocols
  • Tabletop exercise results demonstrating team readiness at least annually
  • Business continuity and disaster recovery test results with recovery time objective (RTO) and recovery point objective (RPO) validation
  • A log of security incidents (even minor ones), investigation summaries, and corrective actions taken

Institutions must also demonstrate coordination with the National Cybersecurity Authority (NCA) and compliance with the NCA's Cyber Security Event Classification (ECC) for incident reporting obligations.

4. Third-Party and Supplier Management

SAMA recognizes that risk extends beyond the institution's perimeter. Evidence includes:

  • A documented third-party risk assessment process covering vendors, cloud providers, and outsourced service providers
  • Contractual clauses mandating security standards, audit rights, and breach notification
  • Periodic vendor security assessments (questionnaires, certifications, or audits)
  • A register of critical dependencies and contingency plans for vendor failure

5. Compliance with PDPL and Data Protection

The Saudi Personal Data Protection Law and its implementing regulations require institutions to evidence:

  • Data inventory and classification (personal, sensitive, regulated)
  • Data protection impact assessments for high-risk processing
  • Documented data subject rights procedures (access, deletion, portability)
  • Breach notification procedures and incident logs

Practical Evidence Management

Security leaders should establish a compliance evidence repository—a centralized system (policy management platform, audit repository, or ISMS software) that organizes controls, test results, and supporting documentation. This enables rapid response to SAMA inquiries and demonstrates mature governance.

Documentation should be current, version-controlled, and signed by appropriate owners. Undated or unsigned policies, or evidence older than 12–18 months, will raise questions about control effectiveness.

Conclusion

SAMA's Cyber Security Framework is not a box-ticking exercise—it is a mandate to build, operate, and prove a resilient security programme. Institutions that translate framework principles into documented, tested, and continuously monitored controls will satisfy supervisory expectations and reduce the risk of enforcement action. Start with a gap assessment against the latest framework version, prioritize evidence collection, and establish a governance rhythm that keeps controls current and demonstrable.