Zeeshan Naeem, Senior Director, Assurance at BDO Saudi Arabia, shares insights on SAMA compliance in practice, exploring key regulatory expectations, common challenges and practical steps financial institutions can take to strengthen their compliance programmes.
What is SAMA compliance in Saudi Arabia?
Saudi Central Bank (SAMA) compliance in Saudi Arabia is no longer just about meeting regulatory requirements. The best organisations use compliance to improve governance, manage risks, make better decisions and build trust with customers and regulators. For financial institutions, demonstrating effective governance and operational resilience has become just as important as meeting regulatory requirements themselves.
As Saudi Arabia continues its Vision 2030 journey through digital banking, fintech, cloud services and open banking, SAMA expects higher standards from financial institutions. Compliance, cybersecurity, business continuity and data management are now key topics for senior management and Boards. In the past, compliance was mainly focused on audits, inspections and maintaining policies. Today, leading organisations see compliance as a business tool that helps improve business continuity, protect customers, manage risks, strengthen reputation and support long-term growth. The real focus is that controls in place work effectively. Explore what SAMA compliance means in practice, the challenges financial institutions commonly face and practical steps to strengthen compliance programmes in Saudi Arabia.
Understanding SAMA requirements
SAMA supervises banks, finance companies, payment providers, money exchange businesses, credit bureaus and fintech companies. Recent supervisory expectations place particular emphasis on governance and risk management, cybersecurity, business continuity and operational resilience, third-party risk management and fraud prevention and threat management. Regulators expect institutions to show strong risk management, clear accountability and the ability to continue operating during disruptions. Depending on the nature of the institution, these expectations are reflected across several SAMA focus areas. This means compliance is a shared responsibility that involves business teams, risk and compliance functions, technology teams and the Board.
“In simple terms, regulators are demanding clear evidence that their internal controls are actively working. True compliance has evolved past a mere documentation exercise into a demonstrable operational reality where businesses must continuously validate their risk management and resilience frameworks.” — mentions Zeeshan Naeem.
Key Takeaways
- Compliance is now a Board responsibility.
- Evidence matters more than documentation.
- Operational resilience is becoming a regulatory expectation.
- Governance must evolve alongside AI and digital transformation.
- Institutions that embed compliance into daily operations strengthen trust and long-term resilience.
Common SAMA compliance challenges
Across audits, reviews and compliance checks, many organisations face the same challenges, regardless of their size or level of development.
- Unclear responsibility. Compliance duties are often spread across different teams, making it difficult to know who is accountable and creating gaps in coordination.
- Limited evidence. Many organisations have controls in place but cannot clearly show that those controls are working consistently.
- Third-party risk. As organisations increase their use of cloud services and outsourcing, oversight of vendors and service providers often does not keep up.
- Compliance fatigue. As regulatory requirements continue to evolve, organisations sometimes focus on responding to individual regulations rather than maintaining an integrated compliance framework.
Organisations also face growing pressure from new regulations, cyber threats, rapid digital transformation initiatives and a shortage of skilled compliance and risk professionals.
In most cases, the root issue is the same: controls are in place, but they are not always applied consistently, updated timely or supported by enough evidence.
What effective SAMA compliance looks like
Organisations with strong compliance programmes usually have clear responsibilities, effective oversight from management and the Board, a risk-based approach, regular monitoring, meaningful compliance reporting, automated evidence collection and prompt action to address identified issues. Most importantly, compliance is built into daily business activities rather than treated as an occasional task.
SAMA Three Lines Model
Strong governance requires clear roles and responsibilities:
- First Line: Business and operational teams manage risks.
- Second Line: Risk and Compliance teams provide oversight and challenge risks.
- Third Line: Internal Audit independently checks whether controls and governance processes are working properly.
In simple terms, the first line manages risk, the second line oversees risk, and the third line provides independent assurance. The model works best when responsibilities are clearly documented, communicated and periodically reviewed.
What are the most common SAMA compliance gaps found in reviews?
Many regulatory findings are not caused by technology failures. Common issues include having controls without enough supporting evidence, adopting new technology without proper oversight and having security tools without testing response plans. Regulators want organisations to prove that controls work in practice, not just show that they exist.
For example, an institution may have documented controls over outsourced service providers, but unless ongoing monitoring and periodic reviews can be demonstrated, those controls may not fully satisfy regulatory expectations.
Regulators are increasingly focused on how organisations respond to disruptions. Institutions should identify critical services, set recovery targets, test recovery plans, monitor important third parties and ensure management remains accountable. Operational resilience is now an important part of compliance and customer confidence. Regular scenario testing and lessons learned from simulation exercises are becoming increasingly important in demonstrating operational resilience.
How are AI and Cloud Technologies changing SAMA compliance expectations?
SAMA is expanding its focus beyond traditional cybersecurity to include governance over artificial intelligence, cloud services and digital platforms. Institutions are expected to apply the same standards of oversight, data protection and accountability to AI and cloud tools as they do to core banking systems.
Organisations need clear governance around AI, strong data protection measures and effective use of technology to automate monitoring, evidence gathering and reporting. Technology can support compliance through automated monitoring, evidence gathering and reporting, but it cannot replace good governance, management oversight and accountability.
Organisations generally move through three compliance stages:
- Reactive – dealing with issues as they arise. Compliance activities are driven by audits and regulatory requests.
- Managed – having structured processes and controls. Policies, controls, ownership and monitoring are established.
- Optimised – embedding compliance into business decisions and daily operations.
Practical steps to become SAMA compliant
While every institution has different regulatory priorities, several practical actions consistently contribute to stronger compliance outcomes:
- Clearly define ownership and accountability for compliance activities.
- Embed compliance into day-to-day business processes rather than treating it as a periodic exercise.
- Maintain sufficient evidence to demonstrate that controls operate consistently and effectively.
- Regularly test operational resilience and incident response arrangements.
- Periodically assess compliance maturity and address identified gaps.
- Periodically review governance arrangements to ensure they remain aligned with changing regulatory expectations.
How BDO Saudi Arabia can help with SAMA compliance?
Strong compliance is built on effective governance, clear accountability, proactive risk management, operational resilience and evidence that controls are working as intended. The most successful organisations are not necessarily those that invest the most in compliance, but those that clearly define responsibilities, identify and address risks early and embed compliance into their day-to-day operations. Ultimately, SAMA compliance is a business strength that enhances trust, supports sustainable growth and creates a competitive advantage. Institutions that treat compliance as an ongoing business capability are generally better positioned to respond to supervisory expectations, strengthen stakeholder confidence and support sustainable growth.
BDO Saudi Arabia supports financial institutions throughout the compliance lifecycle—from assessing regulatory readiness and identifying control gaps to strengthening governance, enhancing operational resilience and preparing for supervisory reviews.
Our multidisciplinary teams can assist with:
- Regulatory compliance assessments
- Governance and internal control reviews
- Internal audit and independent assurance
- Operational resilience and business continuity
- Cybersecurity and third-party risk
- AI governance and technology-enabled compliance
- Remediation programmes and regulatory readiness
Ultimately, organisations that embed compliance into decision-making, not just regulatory reporting, are better positioned to strengthen stakeholder confidence, respond to evolving supervisory expectations and achieve sustainable growth.

