Counter-Fraud
Framework
SAMA's framework for identifying and addressing fraud risk across the Saudi financial sector. Four domains — Governance, Prevent, Detect and Respond — spanning 23 sub-domains, with a six-level maturity model on which SAMA expects Member Organisations to operate at level 3 or higher.
- 4
- Domains
- 23
- Sub-domains
- 200+
- Control requirements
- Level 3
- Minimum maturity
What is the SAMA Counter-Fraud Framework?
The SAMA Counter-Fraud Framework was issued by the Saudi Central Bank under circular number 44021528, dated 5/3/1444H — 11 October 2022. It defines the Principles and Control Requirements for initiating, implementing, maintaining, monitoring and improving Counter-Fraud controls within Member Organisations regulated by SAMA.
SAMA states three objectives for the Framework: to create a common approach for addressing fraud risk across Member Organisations, to achieve an appropriate maturity level of fraud controls, and to ensure fraud risks are properly managed throughout the organisation. The Framework is then used to periodically assess maturity and evaluate the effectiveness of those controls.
Fraud is defined broadly — any intentional act aiming to obtain an unlawful benefit or cause loss to another party, whether through technical or documentary means, relationships or social means, functional powers, or the deliberate neglect or exploitation of weaknesses in systems or standards. The Framework should be implemented in conjunction with other SAMA frameworks, in particular the SAMA Cyber Security Framework, which remains the reference for cyber security requirements.
It is a principle-based framework. Each sub-domain states a Principle summarising the main set of controls, followed by mandated Control Requirements that allow a risk-based approach within applicable KSA law. Where a Control Requirement cannot be implemented, an exception process applies — compensating controls, internal risk acceptance, and finally a formal waiver request to SAMA.
- Issuer
- Saudi Central Bank (SAMA)
- Circular
- 44021528 · 11 Oct 2022
- Hijri date
- 15/3/1444H
- Status
- In force
- Scope
- Banking sector
- Applies to
- Member Organisations notified by SAMA
- Structure
- 4 domains · 23 sub-domains
- Maturity
- 6 levels (0–5) · level 3 minimum
- Assessment
- Periodic self-assessment · SAMA review and audit
Who the Counter-Fraud Framework applies to
Applicability is set by SAMA, not assumed. The Framework states it applies to all Member Organisations operating in Saudi Arabia based on SAMA discretion, and that those required to implement it will be notified by SAMA.
Published scope: banking sector
The SAMA Rulebook records the scope of application for this framework as the banking sector — the population from which SAMA notifies organisations required to implement it.
Notified Member Organisations
Applicability is at SAMA's discretion. Member Organisations required to implement and comply with the Framework are notified directly by SAMA, so confirm your position with your supervisor.
Three lines of defence
The target audience is Senior and Executive Management, business owners, the Counter-Fraud Department, and everyone responsible for planning, defining, implementing and reviewing Counter-Fraud controls across all three lines.
International branches
For Member Organisations headquartered in the KSA, the Counter-Fraud Policy should apply across all international branches and subsidiaries — with a documented, approved exemption where another jurisdiction's law prohibits compliance.
Majority-owned subsidiaries
The Counter-Fraud Policy must be readily accessible to all employees, contractors and relevant third parties, including all branches and majority-owned subsidiaries.
Read alongside SAMA CSF
The Framework is explicitly to be implemented in conjunction with other SAMA frameworks — cyber security requirements are governed by the SAMA Cyber Security Framework, not restated here.
The six-level Counter-Fraud Maturity Model
Maturity is measured on six levels. Levels are cumulative — to reach 3, 4 or 5 an organisation must first meet every criterion of the preceding levels. SAMA expects Member Organisations to operate at level 3 or higher.
| Level | Definition | Criteria |
|---|---|---|
| 0 | Non-existent | No documentation. No awareness of, or attention to, Counter-Fraud controls. |
| 1 | Ad-hoc | Controls are not, or only partially, defined and are performed inconsistently. Design and execution vary by department or owner. |
| 2 | Repeatable but informal | Execution is based on informal, unwritten but standardised practice. Control objectives and design are not formally defined or approved. |
| 3 | Structured and formalisedSAMA minimum | Controls defined, approved and implemented formally. Fraud detection system capability embedded. KPIs defined and reported. Compliance with Counter-Fraud documentation monitored — preferably using a GRC tool. |
| 4 | Managed and measurable | Control effectiveness periodically assessed and improved. KRIs and trend reporting monitor position against risk appetite and give early warning of emerging issues. |
| 5 | Adaptive | Continuous improvement plan in place. Counter-Fraud controls integrated with enterprise risk management and supported by automated real-time monitoring. |
Level 3 is where documentation stops being aspirational: policies, standards and procedures are established and approved, fraud detection system capability is in place across all products and channels, and compliance with Counter-Fraud documentation is monitored — in SAMA's own words, preferably using a governance, risk and compliance (GRC) tool, with Key Performance Indicators defined and reported.
All four domains and 23 sub-domains
Each sub-domain states a Principle and a set of lettered Control Requirements. References and counts below follow the official SAMA Rulebook text.
Governance
The Board and Executive Leadership are ultimately responsible for creating the Counter-Fraud Programme — strategy, policy, governance structure and the reporting that lets Senior Management oversee fraud risk.
Establish and maintain a Counter-Fraud Governance Structure owned by Senior Management with responsibility for oversight and control of all aspects of the Counter-Fraud Programme — including a dedicated Counter-Fraud Governance Committee (CFGC) headed by an Executive Committee member.
Define, approve, implement and maintain a Counter-Fraud Strategy aligned to overall strategic objectives, identifying short and long-term initiatives and a roadmap to achieve them.
Define, approve, communicate and implement a Counter-Fraud Policy setting commitment and objectives, supported by procedures covering the step-by-step tasks employees perform.
Define, approve and implement Counter-Fraud roles and responsibilities across the three lines of defence, with stakeholders holding an adequate understanding of what their role expects of them.
Establish and maintain a Counter-Fraud Department responsible for day-to-day operation of the Counter-Fraud Programme, adequately resourced and appropriately skilled.
Define, approve and implement a process for reporting Management Information so Senior Management can monitor Counter-Fraud risks and performance.
Immediately notify SAMA of new fraud typologies and significant fraud incidents, to mitigate the risk of fraud impacting additional customers, other organisations or the wider Saudi financial sector.
Define, approve and implement a strategy for sourcing or developing and implementing counter-fraud systems and technology proportionate to the fraud risks faced.
Conduct audits in accordance with generally accepted auditing standards and relevant SAMA frameworks to verify that fraud control design is adequately implemented and operating as intended.
Prevent
The largest domain. Proactive processes and controls that identify threats and stop fraud before harm occurs — risk management, due diligence, awareness, authentication and prevention standards.
A Fraud Risk Management Framework should be defined, approved and implemented, aligned with the organisation's enterprise risk management process.
Draw on a variety of internal and external data sources to identify and monitor emerging fraud threats.
Conduct a Fraud Risk Assessment to identify the fraud risks to which the organisation or its customers are subject, and assess the effectiveness of the controls mitigating them.
Define, approve and apply a Fraud Risk Appetite when designing and implementing Counter-Fraud systems and controls.
Define, approve and monitor KRIs that measure position against agreed Fraud Risk Appetite and give early indication of increasing fraud risk exposure.
Define, approve and implement standards for assessing the fraud risk associated with employees, customers and third parties — preventing relationships outside risk appetite and managing risk through the life of the relationship.
Ensure background checks are conducted on employees, including contractors, to reduce exposure to internal fraud and reputational damage.
Establish controls to capture and validate the identity of customers to reduce exposure to external fraud losses.
Ensure proportionate due diligence is conducted on third parties to understand the fraud risk in business relationships and manage it appropriately.
A fraud awareness programme should be defined, approved and conducted for employees, customers and third parties.
Define and deliver an employee fraud training and awareness programme enabling employees to identify fraud and report it promptly.
Define and conduct a customer fraud awareness programme that increases understanding of fraud risks, helps customers recognise and resist fraud attempts, and tells them how to report fraud.
Define and deliver a proportionate fraud awareness programme to third parties outlining Counter-Fraud expectations and prompt reporting of suspicious activity.
Define, approve, implement and maintain a standard for authenticating customer, employee and third-party credentials and instructions — risk-based, and using multi-factor authentication.
Ensure Cyber Security, Counter-Fraud and Financial Crime team operational capabilities are aligned to deter fraud.
Define, approve, implement and maintain fraud prevention standards aligned to the fraud risks impacting the organisation and its customers.
Fraud prevention standards should include controls designed specifically to prevent internal fraud.
Fraud prevention standards should include controls designed specifically to prevent external fraud.
Detect
Systems, monitoring and reporting channels that surface fraud and suspicious activity — including the fraud detection system capability SAMA requires before an organisation can reach maturity level 3.
Define, approve, implement and maintain fraud detection standards aligned to the fraud risks impacting the organisation and its customers.
Implement and maintain fraud detection systems that identify anomalies in transactional and non-transactional data and in customer or employee behaviour that may indicate fraud.
Design and implement controls that monitor activity and behaviour in order to detect potential indicators of external fraud and internal fraud.
Define, approve, implement and maintain a process enabling concerned employees and third parties to report potential fraud violations without fear of negative consequences or repercussions.
Respond
What happens after an alert: the response plan, case management, investigation standard and the remediation loop that feeds root causes and lessons learnt back into prevention.
Define, approve, implement and maintain a Fraud Response Plan outlining the organisational response to an actual or suspected fraud incident.
Implement and maintain a Case Management System that records, monitors and stores data on the assessment, investigation and resolution of suspected and identified fraud.
Define, approve, implement and maintain a fraud investigation standard directing a consistent approach to fraud investigation.
Define, approve, implement and maintain a process to identify the root cause of a fraud incident, determine lessons learnt and take corrective action to prevent recurrence.
Counter-Fraud vs SAMA CSF
The two frameworks are complementary, not alternatives. SAMA expects Counter-Fraud to be implemented in conjunction with the Cyber Security Framework.
| Dimension | Counter-Fraud Framework | SAMA CSF |
|---|---|---|
| Risk addressed | Fraud risk to the organisation and its customers | Cyber security risk to information assets |
| Issued | Circular 44021528 — October 2022 | Version 1.0 — 2017 |
| Structure | 4 domains · 23 sub-domains · 12 sub-sections | 4 domains · 30+ sub-domains |
| Maturity model | 6 levels (0–5), minimum level 3 | 6 levels (0–5), minimum level 3 |
| Assessment | Periodic self-assessment, reviewed and audited by SAMA | Self-assessment and SAMA inspection |
| Governance body | Counter-Fraud Governance Committee (CFGC), quarterly minimum | Cyber security committee and CISO function |
| Incident duty | Immediate notification of new typologies and significant fraud incidents | Cyber incident reporting to SAMA |
| Relationship | Implemented in conjunction with CSF; sub-domain 4.5 requires alignment of fraud, financial crime and cyber teams | Referenced by Counter-Fraud for all cyber security requirements |
How GRC Vantage supports Counter-Fraud compliance
SAMA names a GRC tool as the preferred way to monitor compliance with Counter-Fraud documentation at maturity level 3. GRC Vantage is built to be that tool.
Counter-Fraud control library
All four domains and 23 sub-domains pre-loaded with principle text, evidence prompts and ownership templates. Assign sub-domains to the Counter-Fraud Department, Operational Risk or business owners and track completion against your own self-assessment.
Maturity scoring and KPI reporting
Score your own position on the 0–5 Counter-Fraud Maturity Model, evidence the criteria behind each level, and generate the KPI and Management Information reporting the CFGC needs for its quarterly cycle.
Fraud risk register and KRIs
Maintain your Fraud Risk Assessment output, Fraud Risk Appetite thresholds and fraud KRIs in the same register as your enterprise risks — so level 5 integration with enterprise risk management is a configuration, not a migration.
Fraud detection systems, alert generation and transaction monitoring sit in your banking and payments stack — GRC Vantage governs the programme around them: the documentation, control ownership, maturity evidence and reporting SAMA reviews.
Frequently asked questions
What is the SAMA Counter-Fraud Framework?
It is the framework issued by the Saudi Central Bank (SAMA) under Circular 44021528, dated 15/3/1444H (11 October 2022), that defines the Principles and Control Requirements for initiating, implementing, maintaining, monitoring and improving Counter-Fraud controls at Member Organisations. It spans four domains — Governance, Prevent, Detect and Respond — covering 23 sub-domains and more than 200 lettered Control Requirements.
Who does the Counter-Fraud Framework apply to?
The published scope of application is the Banking Sector. The Framework states that it is applicable to all Member Organisations operating in Saudi Arabia based on SAMA discretion, and that Member Organisations required to implement and comply with it will be notified by SAMA. In other words, applicability is determined and communicated by SAMA rather than assumed — confirm your own position with your SAMA supervisor.
What maturity level does SAMA expect?
The Framework uses a six-level Counter-Fraud Maturity Model (0 to 5). To achieve an appropriate maturity level, Member Organisations should operate at maturity level 3 or higher. Levels are cumulative — to reach level 3, 4 or 5 an organisation must first meet all criteria of the preceding levels. Level 3 specifically requires that fraud detection system capability is implemented and embedded, and that compliance with Counter-Fraud documentation is monitored.
How does it relate to the SAMA Cyber Security Framework?
The Counter-Fraud Framework states it should be implemented in conjunction with other SAMA frameworks, in particular the Cyber Security Framework (CSF), which should be referred to for specific cyber security requirements. The two are complementary rather than overlapping: CSF governs cyber security controls, while Counter-Fraud governs fraud risk across governance, prevention, detection and response. Sub-domain 4.5 explicitly requires that Cyber Security, Counter-Fraud and Financial Crime team capabilities are aligned.
What is the Counter-Fraud Governance Committee (CFGC)?
Sub-domain 3.1 requires a dedicated Counter-Fraud Governance Committee headed by a member of the Executive Committee (for example the CEO or CRO). Minimum representation includes the Head of Counter-Fraud, Chief Risk Officer, Chief Operating Officer, Head of Digital, heads of relevant business departments and senior managers from departments involved in fraud risk management, with Internal Audit attending as an observer. The committee needs an approved charter covering objectives, authority, quorum, meeting frequency of at least quarterly, Board escalation and minute retention.
Do we have to notify SAMA when fraud occurs?
Yes. Sub-domain 3.7 Supervisory Notifications requires Member Organisations to immediately notify SAMA of new fraud typologies and significant fraud incidents, so that the risk of the fraud impacting additional customers, other organisations or the wider Saudi financial sector is mitigated. Significance is judged on factors including the number of customers impacted, reputational damage, whether regulation has been breached, whether the incident reflects control weaknesses, and whether it could affect other Member Organisations.
Is there a self-assessment, and does SAMA review it?
Yes. Implementation of the Framework is subject to a periodic self-assessment performed by the Member Organisation based on a questionnaire. Those self-assessments are then reviewed and audited by SAMA to determine the level of compliance with the Framework and the organisation's Counter-Fraud maturity level.
Can a control requirement be waived?
The Framework is principle-based and allows a risk-based approach. Where a Control Requirement cannot be implemented, the Member Organisation should follow an exception process: consider compensating controls proportionate to business operations, pursue an internal risk acceptance, and finally request a formal waiver from SAMA. Approval of waiver requests is at SAMA's discretion, and the process is set out in Appendix E of the Framework.
SAMA Counter-Fraud Framework: a guide for Saudi banks
Our practitioner walkthrough of scope, the four domains, the maturity model, third-party due diligence and fraud reporting obligations.
Run your Counter-Fraud programme in one place.
Bring Counter-Fraud governance, your fraud risk register, maturity evidence and CFGC reporting into a single Saudi-resident platform — alongside SAMA CSF, BCM and IT Governance. Arabic and English support, Riyadh and Dammam teams.