SAMA · CSF · ITGF · BCM · TPRM · Counter-fraud

SAMA compliance services, across every framework SAMA supervises.

The Saudi Central Bank supervises its licensed institutions against a set of interlocking frameworks — cybersecurity, IT governance, business continuity, third-party risk and counter-fraud. We help banks, insurers, financing companies and payment providers build one evidence-backed posture across all of them.

How we help

Platform and advisory, working as one

01 · Platform

Run compliance on GRC Vantage

SAMA's frameworks are pre-loaded in GRC Vantage as structured control libraries: maturity self-assessment per control, evidence templates, ownership workflows and reporting built for supervisory review. One unified control library connects overlapping CSF, ITGF and BCM requirements so each control is evidenced once.

02 · Advisory

Bring in our practitioners

Our practitioners run maturity reviews against applicable SAMA requirements, build remediation roadmaps, author the policy and governance documentation the frameworks require, and prepare institutions for SAMA assessments and inspections — in Arabic and English.

What engagements deliver
  • Maturity reviews against applicable SAMA framework requirements
  • Unified control library across CSF, ITGF, BCM and TPRM
  • Prioritised remediation roadmaps with owners and target dates
  • Inspection-ready evidence files maintained year-round
  • Policy and governance documentation aligned with SAMA requirements
  • Bilingual Arabic and English delivery from Riyadh and Dammam
FAQ

Frequently asked questions

What maturity level does SAMA expect?

SAMA measures CSF compliance on a maturity scale of 0–5 and generally expects supervised institutions to demonstrate at least level 3 — controls that are documented, approved and implemented — with evidence supporting the rating on every control. Where an institution rates itself higher, the evidence bar rises accordingly.

We answer to CSF, ITGF and BCM at once — do we need three programmes?

No — and running three parallel programmes is where most duplicated effort comes from. The frameworks overlap substantially. We rationalise the requirements into one unified control library where each control maps to every framework that references it, is owned once, and is evidenced once.

How do you help us prepare for a SAMA inspection?

By making the inspection an export rather than a project: the platform maintains per-control maturity ratings and evidence continuously, and our advisors review evidence quality and close priority gaps ahead of the cycle — so the file you hand the supervisor reflects how you actually operate.

Can our compliance data stay inside Saudi Arabia?

Yes. GRC Vantage can be hosted inside the Kingdom, or deployed fully on-premise inside your own infrastructure — a common choice for SAMA-supervised institutions.

Talk to us

Build one posture across every SAMA framework

Book a working session with our advisors. We'll review which SAMA frameworks apply to your institution, where your maturity stands, and outline a practical route to an inspection-ready position.