SAMA Rulebook · Circular 44021528 · October 2022

Counter-Fraud Framework

SAMA's framework for identifying and addressing fraud risk across the Saudi financial sector. Four domains — Governance, Prevent, Detect and Respond — spanning 23 sub-domains, with a six-level maturity model on which SAMA expects Member Organisations to operate at level 3 or higher.

4
Domains
23
Sub-domains
200+
Control requirements
Level 3
Minimum maturity
Overview

What is the SAMA Counter-Fraud Framework?

The SAMA Counter-Fraud Framework was issued by the Saudi Central Bank under circular number 44021528, dated 5/3/1444H — 11 October 2022. It defines the Principles and Control Requirements for initiating, implementing, maintaining, monitoring and improving Counter-Fraud controls within Member Organisations regulated by SAMA.

SAMA states three objectives for the Framework: to create a common approach for addressing fraud risk across Member Organisations, to achieve an appropriate maturity level of fraud controls, and to ensure fraud risks are properly managed throughout the organisation. The Framework is then used to periodically assess maturity and evaluate the effectiveness of those controls.

Fraud is defined broadly — any intentional act aiming to obtain an unlawful benefit or cause loss to another party, whether through technical or documentary means, relationships or social means, functional powers, or the deliberate neglect or exploitation of weaknesses in systems or standards. The Framework should be implemented in conjunction with other SAMA frameworks, in particular the SAMA Cyber Security Framework, which remains the reference for cyber security requirements.

It is a principle-based framework. Each sub-domain states a Principle summarising the main set of controls, followed by mandated Control Requirements that allow a risk-based approach within applicable KSA law. Where a Control Requirement cannot be implemented, an exception process applies — compensating controls, internal risk acceptance, and finally a formal waiver request to SAMA.

At a glance
Issuer
Saudi Central Bank (SAMA)
Circular
44021528 · 11 Oct 2022
Hijri date
15/3/1444H
Status
In force
Scope
Banking sector
Applies to
Member Organisations notified by SAMA
Structure
4 domains · 23 sub-domains
Maturity
6 levels (0–5) · level 3 minimum
Assessment
Periodic self-assessment · SAMA review and audit
Official SAMA Rulebook ↗
Scope

Who the Counter-Fraud Framework applies to

Applicability is set by SAMA, not assumed. The Framework states it applies to all Member Organisations operating in Saudi Arabia based on SAMA discretion, and that those required to implement it will be notified by SAMA.

Published scope: banking sector

The SAMA Rulebook records the scope of application for this framework as the banking sector — the population from which SAMA notifies organisations required to implement it.

Notified Member Organisations

Applicability is at SAMA's discretion. Member Organisations required to implement and comply with the Framework are notified directly by SAMA, so confirm your position with your supervisor.

Three lines of defence

The target audience is Senior and Executive Management, business owners, the Counter-Fraud Department, and everyone responsible for planning, defining, implementing and reviewing Counter-Fraud controls across all three lines.

International branches

For Member Organisations headquartered in the KSA, the Counter-Fraud Policy should apply across all international branches and subsidiaries — with a documented, approved exemption where another jurisdiction's law prohibits compliance.

Majority-owned subsidiaries

The Counter-Fraud Policy must be readily accessible to all employees, contractors and relevant third parties, including all branches and majority-owned subsidiaries.

Read alongside SAMA CSF

The Framework is explicitly to be implemented in conjunction with other SAMA frameworks — cyber security requirements are governed by the SAMA Cyber Security Framework, not restated here.

Maturity model

The six-level Counter-Fraud Maturity Model

Maturity is measured on six levels. Levels are cumulative — to reach 3, 4 or 5 an organisation must first meet every criterion of the preceding levels. SAMA expects Member Organisations to operate at level 3 or higher.

LevelDefinitionCriteria
0Non-existentNo documentation. No awareness of, or attention to, Counter-Fraud controls.
1Ad-hocControls are not, or only partially, defined and are performed inconsistently. Design and execution vary by department or owner.
2Repeatable but informalExecution is based on informal, unwritten but standardised practice. Control objectives and design are not formally defined or approved.
3Structured and formalisedSAMA minimumControls defined, approved and implemented formally. Fraud detection system capability embedded. KPIs defined and reported. Compliance with Counter-Fraud documentation monitored — preferably using a GRC tool.
4Managed and measurableControl effectiveness periodically assessed and improved. KRIs and trend reporting monitor position against risk appetite and give early warning of emerging issues.
5AdaptiveContinuous improvement plan in place. Counter-Fraud controls integrated with enterprise risk management and supported by automated real-time monitoring.

Level 3 is where documentation stops being aspirational: policies, standards and procedures are established and approved, fraud detection system capability is in place across all products and channels, and compliance with Counter-Fraud documentation is monitored — in SAMA's own words, preferably using a governance, risk and compliance (GRC) tool, with Key Performance Indicators defined and reported.

Framework structure

All four domains and 23 sub-domains

Each sub-domain states a Principle and a set of lettered Control Requirements. References and counts below follow the official SAMA Rulebook text.

Domain 3

Governance

The Board and Executive Leadership are ultimately responsible for creating the Counter-Fraud Programme — strategy, policy, governance structure and the reporting that lets Senior Management oversee fraud risk.

9 sub-domains · 60 control requirements
3.1Governance Structure9 CRs

Establish and maintain a Counter-Fraud Governance Structure owned by Senior Management with responsibility for oversight and control of all aspects of the Counter-Fraud Programme — including a dedicated Counter-Fraud Governance Committee (CFGC) headed by an Executive Committee member.

3.2Counter-Fraud Strategy5 CRs

Define, approve, implement and maintain a Counter-Fraud Strategy aligned to overall strategic objectives, identifying short and long-term initiatives and a roadmap to achieve them.

3.3Counter-Fraud Policy and Procedures7 CRs

Define, approve, communicate and implement a Counter-Fraud Policy setting commitment and objectives, supported by procedures covering the step-by-step tasks employees perform.

3.4Roles and Responsibilities10 CRs

Define, approve and implement Counter-Fraud roles and responsibilities across the three lines of defence, with stakeholders holding an adequate understanding of what their role expects of them.

3.5Counter-Fraud Department9 CRs

Establish and maintain a Counter-Fraud Department responsible for day-to-day operation of the Counter-Fraud Programme, adequately resourced and appropriately skilled.

3.6Management Information4 CRs

Define, approve and implement a process for reporting Management Information so Senior Management can monitor Counter-Fraud risks and performance.

3.7Supervisory Notifications4 CRs

Immediately notify SAMA of new fraud typologies and significant fraud incidents, to mitigate the risk of fraud impacting additional customers, other organisations or the wider Saudi financial sector.

3.8Counter-Fraud Technology4 CRs

Define, approve and implement a strategy for sourcing or developing and implementing counter-fraud systems and technology proportionate to the fraud risks faced.

3.9Counter-Fraud Internal Audits8 CRs

Conduct audits in accordance with generally accepted auditing standards and relevant SAMA frameworks to verify that fraud control design is adequately implemented and operating as intended.

Domain 4

Prevent

The largest domain. Proactive processes and controls that identify threats and stop fraud before harm occurs — risk management, due diligence, awareness, authentication and prevention standards.

18 sub-domains · 109 control requirements
4.1Risk Management5 CRs

A Fraud Risk Management Framework should be defined, approved and implemented, aligned with the organisation's enterprise risk management process.

4.1.1Intelligence Monitoring8 CRs

Draw on a variety of internal and external data sources to identify and monitor emerging fraud threats.

4.1.2Fraud Risk Assessment10 CRs

Conduct a Fraud Risk Assessment to identify the fraud risks to which the organisation or its customers are subject, and assess the effectiveness of the controls mitigating them.

4.1.3Risk Appetite6 CRs

Define, approve and apply a Fraud Risk Appetite when designing and implementing Counter-Fraud systems and controls.

4.1.4Key Risk Indicators4 CRs

Define, approve and monitor KRIs that measure position against agreed Fraud Risk Appetite and give early indication of increasing fraud risk exposure.

4.2Due Diligence7 CRs

Define, approve and implement standards for assessing the fraud risk associated with employees, customers and third parties — preventing relationships outside risk appetite and managing risk through the life of the relationship.

4.2.1Employee Due Diligence6 CRs

Ensure background checks are conducted on employees, including contractors, to reduce exposure to internal fraud and reputational damage.

4.2.2Customer Due Diligence5 CRs

Establish controls to capture and validate the identity of customers to reduce exposure to external fraud losses.

4.2.3Third Party Due Diligence6 CRs

Ensure proportionate due diligence is conducted on third parties to understand the fraud risk in business relationships and manage it appropriately.

4.3Training and Awareness8 CRs

A fraud awareness programme should be defined, approved and conducted for employees, customers and third parties.

4.3.1Employee Fraud Training and Awareness8 CRs

Define and deliver an employee fraud training and awareness programme enabling employees to identify fraud and report it promptly.

4.3.2Customer Fraud Awareness6 CRs

Define and conduct a customer fraud awareness programme that increases understanding of fraud risks, helps customers recognise and resist fraud attempts, and tells them how to report fraud.

4.3.3Third Party Fraud Awareness3 CRs

Define and deliver a proportionate fraud awareness programme to third parties outlining Counter-Fraud expectations and prompt reporting of suspicious activity.

4.4Authentication12 CRs

Define, approve, implement and maintain a standard for authenticating customer, employee and third-party credentials and instructions — risk-based, and using multi-factor authentication.

4.5Fraud, Financial Crime and Cyber Alignment1 CRs

Ensure Cyber Security, Counter-Fraud and Financial Crime team operational capabilities are aligned to deter fraud.

4.6Fraud Prevention Standards7 CRs

Define, approve, implement and maintain fraud prevention standards aligned to the fraud risks impacting the organisation and its customers.

4.6.1Internal Fraud4 CRs

Fraud prevention standards should include controls designed specifically to prevent internal fraud.

4.6.2External Fraud3 CRs

Fraud prevention standards should include controls designed specifically to prevent external fraud.

Domain 5

Detect

Systems, monitoring and reporting channels that surface fraud and suspicious activity — including the fraud detection system capability SAMA requires before an organisation can reach maturity level 3.

4 sub-domains · 25 control requirements
5.1Fraud Detection Standards10 CRs

Define, approve, implement and maintain fraud detection standards aligned to the fraud risks impacting the organisation and its customers.

5.2Fraud Detection Systems10 CRs

Implement and maintain fraud detection systems that identify anomalies in transactional and non-transactional data and in customer or employee behaviour that may indicate fraud.

5.3Monitoring to Detect Fraud2 CRs

Design and implement controls that monitor activity and behaviour in order to detect potential indicators of external fraud and internal fraud.

5.4Whistle Blowing3 CRs

Define, approve, implement and maintain a process enabling concerned employees and third parties to report potential fraud violations without fear of negative consequences or repercussions.

Domain 6

Respond

What happens after an alert: the response plan, case management, investigation standard and the remediation loop that feeds root causes and lessons learnt back into prevention.

4 sub-domains · 18 control requirements
6.1Fraud Response Plan5 CRs

Define, approve, implement and maintain a Fraud Response Plan outlining the organisational response to an actual or suspected fraud incident.

6.2Alert and Case Management4 CRs

Implement and maintain a Case Management System that records, monitors and stores data on the assessment, investigation and resolution of suspected and identified fraud.

6.3Fraud Investigation5 CRs

Define, approve, implement and maintain a fraud investigation standard directing a consistent approach to fraud investigation.

6.4Fraud Remediation4 CRs

Define, approve, implement and maintain a process to identify the root cause of a fraud incident, determine lessons learnt and take corrective action to prevent recurrence.

Framework comparison

Counter-Fraud vs SAMA CSF

The two frameworks are complementary, not alternatives. SAMA expects Counter-Fraud to be implemented in conjunction with the Cyber Security Framework.

DimensionCounter-Fraud FrameworkSAMA CSF
Risk addressedFraud risk to the organisation and its customersCyber security risk to information assets
IssuedCircular 44021528 — October 2022Version 1.0 — 2017
Structure4 domains · 23 sub-domains · 12 sub-sections4 domains · 30+ sub-domains
Maturity model6 levels (0–5), minimum level 36 levels (0–5), minimum level 3
AssessmentPeriodic self-assessment, reviewed and audited by SAMASelf-assessment and SAMA inspection
Governance bodyCounter-Fraud Governance Committee (CFGC), quarterly minimumCyber security committee and CISO function
Incident dutyImmediate notification of new typologies and significant fraud incidentsCyber incident reporting to SAMA
RelationshipImplemented in conjunction with CSF; sub-domain 4.5 requires alignment of fraud, financial crime and cyber teamsReferenced by Counter-Fraud for all cyber security requirements
Platform

How GRC Vantage supports Counter-Fraud compliance

SAMA names a GRC tool as the preferred way to monitor compliance with Counter-Fraud documentation at maturity level 3. GRC Vantage is built to be that tool.

01

Counter-Fraud control library

All four domains and 23 sub-domains pre-loaded with principle text, evidence prompts and ownership templates. Assign sub-domains to the Counter-Fraud Department, Operational Risk or business owners and track completion against your own self-assessment.

02

Maturity scoring and KPI reporting

Score your own position on the 0–5 Counter-Fraud Maturity Model, evidence the criteria behind each level, and generate the KPI and Management Information reporting the CFGC needs for its quarterly cycle.

03

Fraud risk register and KRIs

Maintain your Fraud Risk Assessment output, Fraud Risk Appetite thresholds and fraud KRIs in the same register as your enterprise risks — so level 5 integration with enterprise risk management is a configuration, not a migration.

Fraud detection systems, alert generation and transaction monitoring sit in your banking and payments stack — GRC Vantage governs the programme around them: the documentation, control ownership, maturity evidence and reporting SAMA reviews.

FAQ

Frequently asked questions

What is the SAMA Counter-Fraud Framework?

It is the framework issued by the Saudi Central Bank (SAMA) under Circular 44021528, dated 15/3/1444H (11 October 2022), that defines the Principles and Control Requirements for initiating, implementing, maintaining, monitoring and improving Counter-Fraud controls at Member Organisations. It spans four domains — Governance, Prevent, Detect and Respond — covering 23 sub-domains and more than 200 lettered Control Requirements.

Who does the Counter-Fraud Framework apply to?

The published scope of application is the Banking Sector. The Framework states that it is applicable to all Member Organisations operating in Saudi Arabia based on SAMA discretion, and that Member Organisations required to implement and comply with it will be notified by SAMA. In other words, applicability is determined and communicated by SAMA rather than assumed — confirm your own position with your SAMA supervisor.

What maturity level does SAMA expect?

The Framework uses a six-level Counter-Fraud Maturity Model (0 to 5). To achieve an appropriate maturity level, Member Organisations should operate at maturity level 3 or higher. Levels are cumulative — to reach level 3, 4 or 5 an organisation must first meet all criteria of the preceding levels. Level 3 specifically requires that fraud detection system capability is implemented and embedded, and that compliance with Counter-Fraud documentation is monitored.

How does it relate to the SAMA Cyber Security Framework?

The Counter-Fraud Framework states it should be implemented in conjunction with other SAMA frameworks, in particular the Cyber Security Framework (CSF), which should be referred to for specific cyber security requirements. The two are complementary rather than overlapping: CSF governs cyber security controls, while Counter-Fraud governs fraud risk across governance, prevention, detection and response. Sub-domain 4.5 explicitly requires that Cyber Security, Counter-Fraud and Financial Crime team capabilities are aligned.

What is the Counter-Fraud Governance Committee (CFGC)?

Sub-domain 3.1 requires a dedicated Counter-Fraud Governance Committee headed by a member of the Executive Committee (for example the CEO or CRO). Minimum representation includes the Head of Counter-Fraud, Chief Risk Officer, Chief Operating Officer, Head of Digital, heads of relevant business departments and senior managers from departments involved in fraud risk management, with Internal Audit attending as an observer. The committee needs an approved charter covering objectives, authority, quorum, meeting frequency of at least quarterly, Board escalation and minute retention.

Do we have to notify SAMA when fraud occurs?

Yes. Sub-domain 3.7 Supervisory Notifications requires Member Organisations to immediately notify SAMA of new fraud typologies and significant fraud incidents, so that the risk of the fraud impacting additional customers, other organisations or the wider Saudi financial sector is mitigated. Significance is judged on factors including the number of customers impacted, reputational damage, whether regulation has been breached, whether the incident reflects control weaknesses, and whether it could affect other Member Organisations.

Is there a self-assessment, and does SAMA review it?

Yes. Implementation of the Framework is subject to a periodic self-assessment performed by the Member Organisation based on a questionnaire. Those self-assessments are then reviewed and audited by SAMA to determine the level of compliance with the Framework and the organisation's Counter-Fraud maturity level.

Can a control requirement be waived?

The Framework is principle-based and allows a risk-based approach. Where a Control Requirement cannot be implemented, the Member Organisation should follow an exception process: consider compensating controls proportionate to business operations, pursue an internal risk acceptance, and finally request a formal waiver from SAMA. Approval of waiver requests is at SAMA's discretion, and the process is set out in Appendix E of the Framework.

Further reading

SAMA Counter-Fraud Framework: a guide for Saudi banks

Our practitioner walkthrough of scope, the four domains, the maturity model, third-party due diligence and fraud reporting obligations.

Read the guide
Get started

Run your Counter-Fraud programme in one place.

Bring Counter-Fraud governance, your fraud risk register, maturity evidence and CFGC reporting into a single Saudi-resident platform — alongside SAMA CSF, BCM and IT Governance. Arabic and English support, Riyadh and Dammam teams.