What the SAMA Cybersecurity Framework Actually Is
The SAMA Cybersecurity Framework is the Saudi Arabian Monetary Authority's mandatory cybersecurity standard for all financial institutions operating in the Kingdom. Banks, insurance companies, financing companies, currency exchange businesses, and increasingly fintech businesses operating under SAMA licensing are all subject to it.
The framework is organised around four maturity levels and spans domains including leadership and governance, risk management, compliance and audit, the human element, information asset management, operations and technology, and third-party cybersecurity. There is an important distinction between having documented policies and having controls that operate effectively in practice, and SAMA auditors look specifically for the latter. A policy document your team has never read is not a functioning control.
What SAMA Auditors Are Actually Looking For
Evidence of genuine leadership engagement. Auditors want to see that senior leadership is meaningfully involved in cybersecurity risk, not just that a policy exists with an executive signature on it. Board-level risk reporting and documented management reviews matter here.
A complete and current risk register. Your risk register needs to capture the actual cybersecurity risks your business faces, with documented owners, ratings, and evidence of regular review. A register populated once and never updated attracts scrutiny every time.
Meaningful third-party oversight. Auditors will assess whether you have conducted security assessments of key vendors, have appropriate contractual security requirements, and monitor vendor performance on an ongoing basis.
A tested incident response capability. Having a written plan is not the same as having a capability. Auditors will look for evidence that it has actually been exercised.
Effective access management controls. Who has access to what, how it is granted, reviewed, and removed, are assessed carefully. Access gaps are among the most common findings and also among the most straightforward to close with focused attention.
A Realistic Preparation Timeline
If you have six to nine months before your audit, you have time to run a thorough gap assessment, build and execute remediation, and conduct a mock audit. If you have three to six months, focus on the domains that carry the most audit risk: governance, risk management, and incident response typically come first. If you have six to twelve weeks, the work becomes a triage exercise focused on the gaps most likely to generate critical findings.
The Most Common Critical Findings
No documented information asset register. Auditors cannot assess whether you are protecting your assets if you cannot demonstrate what they are, where they live, and how they are classified.
Untested business continuity plans. Plans that exist only on paper, or were last updated more than twelve months ago, are a reliable source of critical findings. The test matters as much as the plan.
Inadequate vendor management. Using third-party services without formal security assessment or contractual security requirements is one of the most consistently cited gaps in first-time audits.
Our vCISO service runs SAMA audit preparation as a structured, evidence-first programme rather than a documentation scramble in the final weeks.
