SAMA BCM Compliance Checklist (Free Template)
A free SAMA BCM Framework compliance checklist — every lifecycle stage, evidence requirement and testing cadence Saudi banks need before an inspection.
Business continuity is the SAMA domain where the gap between having a programme and being able to evidence one is widest. Most Saudi banks have plans. Fewer can produce, on request, a current BIA, a test report with closed-out lessons, board minutes showing engagement, and a third-party continuity assessment for every material outsourcing arrangement — which is what an inspection actually asks for.
This is the structured SAMA BCM Framework compliance checklist, organised by the framework's lifecycle. A downloadable working copy is available at the end.
How to use this checklist
For each line item:
- Mark the current state — not started, partial, complete, or tested.
- Identify the owner by name, not by function.
- Note the evidence reference and where it lives.
- Record the date the assessment was made.
- Identify the gap and the action required to close it.
1 — Governance and policy
1.1 Board-approved BCM policy. Documented policy approved at board level, with a defined review cadence and evidence of the most recent approval.
1.2 Named programme owner. A BCM programme owner with sufficient seniority to direct the business, not only IT. Named individual, documented mandate.
1.3 Defined scope. Explicit statement of what is in and out of the programme, with the rationale for exclusions.
1.4 Roles and responsibilities. Documented across the BCM function, business process owners, IT recovery, crisis management and communications.
1.5 Independent reporting line. The BCM function reports independently of IT, so the resilience view is not filtered through a single technology lens.
1.6 Board reporting cadence. BCM reporting reaches the board at a defined frequency. Minutes evidence engagement — questions, decisions, budget, actions tracked — not just noting.
2 — Business Impact Analysis
The BIA is the spine. Every other artefact derives from it, and inspectors ask for it first.
2.1 Every critical business process documented. With, for each one: RTO, RPO, maximum tolerable downtime, resources required to recover, the person responsible, and dependencies across technology, people, third parties, data and premises.
2.2 Refreshed at least annually and after any material change to the business.
2.3 Change history retained. Inspectors ask for the current BIA and the change history, to confirm it is live rather than reconstructed.
2.4 Traceability. Demonstrable link from the BIA to the recovery strategies, plans and test scope — evidence the BIA is genuinely the basis for the programme.
3 — Risk assessment
3.1 BCM-specific risk assessment covering the threats most likely to disrupt the processes identified in the BIA — cyber incidents, third-party failure, physical events, regional disruption, pandemic scenarios, infrastructure failure (power, telecoms, payment rails) and insider events.
3.2 National shared-service dependencies mapped. Saudi banks operate inside interconnected national payments and clearing infrastructure. Scenarios where the local payment switch or another shared service is degraded must be assessed explicitly.
3.3 Assessment refreshed on the same cadence as the BIA and after material change.
4 — Strategy and planning
4.1 Recovery strategy per critical process — alternate sites, backup providers, manual workarounds, technology recovery, communication trees, customer notification scripts.
4.2 Business Continuity Plan — approved, version-controlled, dated.
4.3 IT Disaster Recovery Plan — with recovery sequences and dependencies aligned to the BIA's RTOs.
4.4 Crisis Management Plan — with escalation criteria and decision authorities.
4.5 Plans accessible when the network is not. Offline or out-of-band copies available to the people who need them, tested as reachable.
5 — Cyber resilience
SAMA's BCM Framework explicitly treats cyber resilience as a continuity domain. This is where most programmes are furthest behind.
5.1 Destructive cyber scenarios in scope — ransomware, wiper malware, supply-chain compromise treated as continuity events, not only as security incidents.
5.2 Data integrity addressed. Recovery plans consider whether restored data is trustworthy, not just whether it restores.
5.3 Immutable backups in place for critical data, with restoration tested.
5.4 Clean-room recovery capability defined, with the time needed to validate restored systems built into the RTO.
5.5 BCM and CSIRT rehearse together. Evidence of cross-team exercising, not two separate plans that have never met.
6 — Crisis management
6.1 Documented crisis management structure with named members and deputies.
6.2 Escalation criteria and decision authorities defined in advance.
6.3 Senior business leaders on the crisis team — not operations staff alone.
6.4 Communication protocols covering internal, customer, media and regulator channels.
6.5 Crisis team tested in realistic scenarios, with board participation at least periodically.
7 — Regulator notification
7.1 Incident classification defined with thresholds that trigger SAMA notification.
7.2 Notification timeframes and channels documented, with a named owner and deputy.
7.3 Notification rehearsed as part of exercising — the decision "is this reportable?" made before the clock starts, not during.
8 — Third parties and outsourcing
8.1 Material outsourcing arrangements identified and mapped to the critical processes they support.
8.2 Continuity assessment per material provider — not a generic vendor questionnaire.
8.3 Contractual recovery commitments — RTOs and RPOs written into the contract, with a right to evidence.
8.4 Ongoing monitoring of provider continuity capability, on a defined cadence.
8.5 Cloud and managed service providers demonstrably hold credible continuity capabilities, evidenced rather than assumed.
This section intersects with the SAMA Outsourcing Regulations; run it as one programme rather than two. See our guide to third-party risk assessment in Saudi Arabia.
9 — Awareness and training
9.1 Role-based training, not a generic e-learning module.
9.2 Every staff member knows their role in a continuity event relevant to their job.
9.3 Participation measured and reported, with completion rates evidenced.
10 — Testing and exercising
10.1 A test programme covering tabletop exercises, walkthroughs, technical recovery tests and full simulations.
10.2 Frequency matched to criticality — the most critical processes tested at least annually.
10.3 Test reports retained with scope, participants, results and issues raised.
10.4 Lessons learned closed out — and demonstrably fed back into the BIA, the risk assessment and the plans.
10.5 Year-on-year improvement visible to the board. The framework treats BCM as a continuous improvement discipline; the board should see how the programme has improved, not just that an exercise happened.
The five places SAMA goes beyond ISO 22301
If you hold ISO 22301 certification you have most of this. These are the gaps to check first:
| Area | What SAMA adds |
|---|---|
| Regulator notification | Defined timeframes and channels for notifying SAMA of significant continuity events. Absent from ISO 22301 entirely. |
| National shared services | Explicit requirement to map and scenario-test dependency on shared national payments and clearing infrastructure. |
| Cyber resilience | Specific cyber recovery scenarios, immutable backups and BCM–CSIRT cross-rehearsal, rather than cyber as one risk among many. |
| Board engagement | Prescribed reporting cadence and periodic board participation in crisis exercises. |
| Outsourcing | Intersection with the SAMA Outsourcing Regulations — continuity assessment, contractual recovery commitments and monitoring per material provider. |
Get the downloadable checklist
The full checklist — formatted as a working spreadsheet with state, owner, evidence reference and target date columns — is available on request. Contact us to receive a copy.
For the framework itself, read SAMA BCM Framework explained. For the wider regulatory picture, see the SAMA frameworks complete guide, our guide to BCM in Saudi Arabia and the business impact analysis guide for Saudi banks.
To run this checklist as a live, audit-trailed programme — with the BIA, plans, test schedule and third-party assessments connected rather than sitting in separate documents — see GRC Vantage's BCM module, supported from Riyadh and Dammam.
Book a demo with the GRC Vantage team in Riyadh or Dammam.
See BCM →
The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.
Related articles
A free business continuity plan template for Saudi organisations — sections, contents and structure aligned to SAMA BCM Framework and ISO 22301, downloadable.
A practical guide to business impact analysis for Saudi banks — MTPD, RTO, RPO, dependency mapping, SAMA BCM Framework and ISO 22301 alignment in 2026.
What the SAMA Business Continuity Management Framework actually requires — governance, BIA, recovery, testing — and how to evidence it for an inspection.