Governance, Risk & Compliance

SAMA CSF Compliance

Assessment and preparation for compliance with the Cybersecurity Framework (CSF) issued by the Saudi Central Bank (SAMA)

We assess your SAMA CSF compliance level for the financial sector and prepare a comprehensive remediation plan covering the five domains: Governance, Risk, Controls, Operations, and Recovery.

What's included

  • Define the assessment scope for the SAMA-regulated financial entity and its systems and financial services
  • Measure current maturity for each control on the six-level maturity model against the required level 3
  • Strengthen the Leadership and Governance domain (board oversight, CISO independence, policies)
  • Cover the Risk Management and Compliance domain and the Operations and Technology domain across the financial systems lifecycle
  • Implement the Third Party Cyber Security domain including outsourcing and financial service providers
  • Prepare the annual self-assessment submittable to the central bank and link results to a maturity uplift plan

Methodology & standards

01

Scoping: define the financial services and systems in scope and the applicable central bank requirements

02

Maturity measurement: assess each control across the six levels and quantify the gap to level 3

03

Gap analysis: prioritize gaps by their impact on maturity and on financial and regulatory risk

04

Maturity uplift plan: define projects, controls and policies to raise each domain to the required level

05

Readiness and submission: prepare the annual self-assessment and an evidence pack submittable to the central bank

Deliverables

  • A detailed maturity report with each control's level across the four domains compared to level 3
  • A gap register and a maturity uplift plan prioritized with timelines
  • A policy, standard and procedure set aligned with the central bank framework
  • A compliance evidence matrix mapped to each control and subdomain
  • An annual self-assessment ready for submission to the central bank
  • A board report on overall maturity level and residual risk

Regulatory controls it satisfies

SAMA CSF
Reach at least maturity level 3 across the four domains: Leadership and Governance, Risk Management and Compliance, Operations and Technology, and Third Party Cyber Security
SAMA periodic self-assessment
Prepare and submit the annual maturity measurement with auditable supporting evidence
SAMA Business Continuity Management framework
Align resilience and continuity of financial services with the related central bank framework
PDPL
Protect financial customer data within the operations and third-party security controls

Typical timeline

Maturity measurement and gap analysis are usually completed in four to eight weeks, after which the uplift plan to level 3 spans six to twelve months depending on the starting posture.

Common questions

Who does the SAMA CSF apply to?

It applies to entities regulated by the Saudi Central Bank: banks, insurance companies, finance companies, payment service providers, fintech firms and credit bureaus.

What maturity level is required?

The central bank expects at least level 3, Structured and Formalized, for all applicable controls, and reaching it first requires meeting the criteria of the lower levels.