Internal Audit in Saudi Arabia: The Complete Guide
The complete guide to internal audit in Saudi Arabia — IIA and IPPF standards, the audit universe, risk-based planning, and the audit obligations SAMA and the NCA impose.
Internal audit in Saudi Arabia is governed by two things at once: a global professional standard, and a set of Saudi regulator obligations that are more specific than anything the standard says.
The Institute of Internal Auditors' International Professional Practices Framework (IPPF) defines how the function should operate — charter, independence, risk-based planning, quality assurance. SAMA and the NCA then impose concrete review obligations with named frequencies, defined independence requirements, and evidence an inspector will ask to see.
Most Saudi audit functions are strong on the first and improvising on the second. This guide covers both, and how they connect.
Where internal audit sits in the Saudi regulatory picture
Internal audit is unusual among GRC disciplines: it is both a governance function and a control that other frameworks require you to operate. That dual role is the source of most confusion.
| Source | What it requires of audit | Frequency |
|---|---|---|
| IIA / IPPF | Audit charter, independence, risk-based planning, engagement standards, QAIP | External quality assessment at least every 5 years |
| NCA ECC 2:2024 | Subdomain 1-8 — periodical cybersecurity review and audit | Periodic, per the entity's defined cadence |
| NCA CSCC | 1-4-1 review by the cybersecurity function · 1-4-2 review by independent parties outside that function | Annually · Every 3 years |
| SAMA CSF | Internal audit of the cyber security function, findings tracked to closure and reported to the audit committee | Defined cadence, evidenced |
| SAMA BCM | Assurance over the continuity programme; testing and lessons-learned closure | Aligned to the test cycle |
The audit universe
Everything downstream depends on this artefact. A Saudi audit universe has to cover more than processes and business units — the regulated obligations are auditable entities in their own right.
A complete universe includes:
- Business processes — by function, product line and geography
- Systems and applications — including those classified critical under the CSCC
- Legal entities and subsidiaries, including those outside the Kingdom where ECC scope reaches them
- Third parties and outsourcing arrangements — a distinct auditable population under both SAMA and NCA third-party controls
- Regulatory obligations themselves — SAMA CSF domains, NCA ECC subdomains, PDPL duties, each as an auditable unit
Each unit carries a risk rating built from inherent risk, control environment strength and regulatory exposure — the third factor being the one generic audit methodologies omit and Saudi practice requires.
Our internal audit universe template sets out the column structure and the risk-rating approach, with a downloadable working copy.
Risk-based planning
The annual plan is derived from the universe, not from rotation. In practice a Saudi plan balances three demands that pull against each other:
- Regulatory coverage — the review obligations above have fixed frequencies and cannot slip.
- Risk coverage — the highest-rated auditable units, wherever they sit.
- Committee expectations — what the audit committee has asked to see this year.
The failure mode is a plan that satisfies (3), partially covers (2), and quietly misses a fixed-frequency item in (1) until an inspection finds it. Build the regulated items into the plan first as immovable commitments, then allocate remaining capacity by risk.
Our guide to risk-based internal audit in Saudi Arabia works through the full eight-step cycle from universe to QAIP.
Compliance audit versus internal audit
These are frequently conflated and the distinction matters for scoping.
Internal audit is a function with a charter, independence requirements and a professional standard, providing assurance across the whole organisation.
Compliance audit is an engagement type — auditing against a specific framework's control set. Most Saudi audit plans are heavy with compliance audits because the regulatory load is heavy, but a plan made entirely of compliance audits is not a risk-based plan and will be challenged at an external quality assessment.
The practical structure is compliance audits as a subset of a risk-based plan, using the framework's own control library as the audit programme. Our compliance audit playbook covers scoping, evidence and reporting against SAMA CSF, NCA ECC, PDPL and ISO 27001.
Evidence: the recurring failure
Saudi audit functions rarely fail on methodology. They fail on producing evidence, at speed, when an inspector or a quality assessor asks.
The pattern that works is a single connected control library where every framework's controls point at the same underlying evidence, so an audit against SAMA CSF and an audit against NCA ECC draw from one store rather than two. The pattern that fails is a folder structure per engagement, which makes each audit self-contained and every cross-framework question a manual reconciliation.
Three evidence habits separate the two:
- Evidence is captured against a control reference, not against an engagement folder.
- Recommendations carry an owner, a due date and an ageing clock, and overdue items escalate automatically. Overdue recommendations are the most common audit committee question.
- Committee reporting is generated from live data. A pack assembled by hand each quarter is a pack that is out of date on the day it is read.
Quality assurance and improvement
The IPPF requires a QAIP with internal monitoring, periodic internal assessment and an external quality assessment at least every five years. In a Saudi context the external assessment increasingly examines whether the function's regulatory coverage is complete — that is, whether the fixed-frequency obligations above were actually met, on time, with evidence.
Treat the QAIP as the mechanism that catches a missed CSCC 1-4-2 review before an inspector does.
Choosing tooling
Once the function is running risk-based planning across a regulated universe, the constraint becomes tooling. Our guide to internal audit management software in Saudi Arabia sets out the six criteria that decide selections, including the ones specific to the Kingdom — Saudi regulator control libraries pre-loaded, in-Kingdom data residency, and Arabic committee reporting.
Where to go next
The cluster
- Risk-based internal audit in Saudi Arabia — the eight-step cycle
- Internal audit universe template — structure and downloadable copy
- Compliance audit in Saudi Arabia — SAMA, NCA and PDPL engagements
- Internal audit management software — selection criteria
The frameworks that create the obligations
- NCA ECC 2:2024 — subdomain 1-8, periodical review and audit
- NCA CSCC — the annual and three-yearly review obligations
- SAMA CSF — internal audit of the cyber security function
- SAMA BCM — assurance over continuity
To see an audit universe, an annual plan and audit committee reporting running on connected data rather than spreadsheets, see GRC Vantage's audit module or book a session with our teams in Riyadh and Dammam.
Frequently asked questions
- Is internal audit mandatory in Saudi Arabia?
- For regulated entities, effectively yes. SAMA-supervised institutions are expected to maintain an internal audit function with cybersecurity in its scope, and NCA-obligated entities carry explicit review and audit obligations under the Essential Cybersecurity Controls and the Critical Systems Cybersecurity Controls. For unregulated private companies internal audit is a governance choice rather than a legal requirement.
- How often must NCA-regulated entities audit their cybersecurity controls?
- Under the Critical Systems Cybersecurity Controls, the cybersecurity function must review CSCC implementation at least annually (control 1-4-1), and independent parties from outside the cybersecurity function must review it at least every three years (control 1-4-2). The Essential Cybersecurity Controls carry their own periodical review and audit subdomain (1-8).
- What standards should a Saudi internal audit function follow?
- The Institute of Internal Auditors' International Professional Practices Framework (IPPF) is the global reference and the basis on which a Quality Assurance and Improvement Programme is externally assessed. Saudi regulator expectations from SAMA and the NCA sit on top of it rather than replacing it.
- What is an audit universe?
- A structured inventory of everything the internal audit function could audit — business processes, systems, entities, third parties and regulatory obligations — each risk-rated so the annual plan can be built on risk rather than on rotation or habit. It is the artefact an audit committee and an external quality assessor will ask for first.
- Who can perform the independent review NCA requires?
- Control 1-4-2 requires parties independent of the cybersecurity function. Internal audit is the natural home for it where the function has the technical capability and reports independently of IT and cybersecurity; otherwise an external assessor is used. The key test is independence from the function whose controls are being reviewed.