REGULATOR · SAUDI ARABIA · BANKING, PAYMENTS, FINANCE
SAMA compliance software for Saudi institutions.
Saudi Central Bank obligations mapped to one control set, evidenced from your systems and filed with named approval — for banks, finance companies, payment providers and insurers in Saudi Arabia.
What SAMA requires
The Saudi Central Bank supervises banks, finance companies, payment providers and insurers in Saudi Arabia, and publishes what it expects as a set of frameworks — cyber security, business continuity and the rest — each binding on the entities it licenses.
Much of what those frameworks ask for is what ISO 27001 and PCI DSS already ask for, which is why running SAMA as a separate programme means evidencing the same control two and three times over.
Thiqa maps SAMA obligations onto the same control set as your other regulators, identifies the overlaps instead of duplicating them, and keeps Saudi entities scoped separately from Egyptian and UAE ones inside one group.
Runs alongside CBE
SAMA FAQ
- Does SAMA need a control set of its own?
- No. SAMA obligations map onto the same control set as your other regulators, and the overlaps with ISO 27001 and PCI DSS are identified rather than duplicated.
- How are Saudi entities kept apart from Egyptian and UAE ones?
- Each licensed entity carries its own scope, so Saudi obligations route only to SAMA-licensed entities — while a control genuinely shared across the group is still evidenced once.