Score your third-party risk
programme readiness.
Answer 15 questions across all 5 outsourcing-risk domains aligned to the SAMA Outsourcing Regulations. Get an instant maturity score, scored domain breakdown, and prioritised list of gaps — built for Saudi banks managing material vendor estates.
How robust is your third-party risk programme under SAMA?
15 questions across 5 control domains. One at a time. Keyboard-driven. You'll get an instant maturity score and a prioritised remediation roadmap in under five minutes.
What happens when you finish
Your full results are instant — score, domain breakdown and priority gaps, no email required. Optionally enter your email on the results screen to receive the report in your inbox.
Overall outsourcing readiness percentage and your maturity level — Initial, Developing, Defined, or Managed.
See which outsourcing domain — Governance, Materiality, Due Diligence, Contracts, or Monitoring — is your biggest exposure.
Top 3 gaps ranked by severity, with specific first steps you can act on before your next SAMA examination cycle.
Ready to put your vendor estate on auditable rails?
GRC Vantage has the SAMA Outsourcing Regulations, NCA CCC, and PDPL controls pre-mapped. Run vendor due diligence once, prove third-party oversight everywhere.
Pre-built questionnaires
SAMA-aligned security and outsourcing questionnaires that adapt by supplier criticality with reviewer routing and risk scoring.
Risk-rated supplier register
One register of all material vendors with concentration risk views, geographies, and SAMA notification status.
Right-to-audit & exit tracking
Track right-to-audit clauses, exit plans, sub-outsourcing chains, and contractual security obligations across all critical suppliers.
Frequently asked questions
- Is the SAMA Third-Party Risk assessment really free?
- Yes. No credit card, no sign-up to start, no commitment. Your full results — score, domain breakdown and priority gaps — appear immediately after the 15 questions. Optionally enter your email to receive the report in your inbox.
- Who is this assessment for?
- CROs, Heads of Procurement, Vendor Risk Managers, IT Audit Managers, and Compliance Officers at any SAMA-licensed entity managing material outsourcing arrangements.
- Does it cover sub-outsourcing (4th-party) risk?
- Yes. The Pre-Contract Due Diligence and Ongoing Monitoring domains both ask about sub-processor visibility — a fast-rising SAMA examination concern, especially for cloud and offshore IT.
- How does it differ from PDPL or NCA CCC assessments?
- PDPL focuses on personal data handling. NCA CCC covers cloud security controls. This assessment scores the SAMA outsourcing-governance lifecycle: policy, materiality classification, due diligence, contracts, and ongoing oversight.
Run another readiness assessment
Score your maturity against the other Saudi frameworks — same conversational format, same instant results.
NCA ECC Readiness
Score your cybersecurity maturity across the four NCA ECC-2:2024 domains.
Start AssessmentNCA CSCC Readiness
Score your critical-systems protection against the NCA CSCC overlay.
Start AssessmentSAMA CSF Readiness
Score your cybersecurity maturity against the Saudi Central Bank Cyber Security Framework.
Start AssessmentSAMA IT Governance
Score your IT governance maturity against the SAMA IT Governance Framework.
Start AssessmentBCM Readiness
Score your business continuity maturity against ISO 22301 and the SAMA BCM Framework.
Start AssessmentPDPL Readiness
Score your privacy programme against the Saudi Personal Data Protection Law.
StartStart your SAMA Third-Party Risk assessment now — under 5 minutes.
Free. Instant results. No commitment. Built for vendor risk and procurement teams across Saudi banking and finance.
Take the assessment