Thiqa

REGULATOR · SAUDI ARABIA · BANKING, PAYMENTS, FINANCE

SAMA compliance software for Saudi institutions.

Saudi Central Bank obligations mapped to one control set, evidenced from your systems and filed with named approval — for banks, finance companies, payment providers and insurers in Saudi Arabia.

Request a call →Early access · work email only

What SAMA requires

The Saudi Central Bank supervises banks, finance companies, payment providers and insurers in Saudi Arabia, and publishes what it expects as a set of frameworks — cyber security, business continuity and the rest — each binding on the entities it licenses.

Much of what those frameworks ask for is what ISO 27001 and PCI DSS already ask for, which is why running SAMA as a separate programme means evidencing the same control two and three times over.

Thiqa maps SAMA obligations onto the same control set as your other regulators, identifies the overlaps instead of duplicating them, and keeps Saudi entities scoped separately from Egyptian and UAE ones inside one group.

Runs alongside CBE

SAMA FAQ

Does SAMA need a control set of its own?
No. SAMA obligations map onto the same control set as your other regulators, and the overlaps with ISO 27001 and PCI DSS are identified rather than duplicated.
How are Saudi entities kept apart from Egyptian and UAE ones?
Each licensed entity carries its own scope, so Saudi obligations route only to SAMA-licensed entities — while a control genuinely shared across the group is still evidenced once.

Run SAMA and the rest from one control set.