NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new →
SAMA CSF Audit: What to Expect
Learn

SAMA CSF Audit: What to Expect

·Alexander Sverdlov

A SAMA CSF audit starts from your own self-assessment. Section 2.3 of the SAMA Cyber Security Framework makes implementation subject to a periodic self-assessment, performed by the Member Organization on a questionnaire, and says those self-assessments will be reviewed and audited by SAMA to determine two things: the level of compliance with the Framework and the cyber security maturity level reached. Every Member Organization should operate at maturity level 3 or higher. So what SAMA tests is whether your answers are true: that each control you rate at level 3 is defined, approved, implemented and monitored, and that you can show it.

The Framework also requires audits you commission yourself. Subdomain 3.2.5 requires thorough, independent and regular cyber security audits, performed to generally accepted auditing standards and the Framework, following your audit manual and audit plan. Subdomain 3.2.4 requires periodic cyber security reviews. Four activities are involved, and preparing for one does not prepare you for the others.

ActivityWho performs itWhere the Framework sets it
Self-assessment on SAMA's questionnaireThe Member OrganizationSection 2.3
Review and audit of the self-assessmentSAMASection 2.3
Cyber security auditsThe internal audit function, independently, to generally accepted auditing standardsSubdomains 3.1.4 and 3.2.5
Cyber security reviewsThe CISO's cyber security functionSubdomains 3.1.4 and 3.2.4
How SAMA tests the Cyber Security Framework under section 2.3: periodic self-assessment on a questionnaire, review and audit by SAMA, then compliance and maturity level determined

What does SAMA actually test?

The Framework is organised as four domains with subdomains, and each subdomain states a principle, an objective and control considerations. An audit works at that level. A domain average hides the gaps, so expect evidence to be requested subdomain by subdomain, against the control considerations that apply to you.

Applicability is the first thing to get right. All domains apply to banks. For insurers, reinsurers, financing companies, credit bureaus and the financial market infrastructure, section 1.4 excludes subdomains 3.2.3, 3.3.12 and 3.3.13, with conditions: if you store, process or transmit cardholder data or use SWIFT services, PCI DSS or the SWIFT Customer Security Controls Framework must be implemented, and if you provide online services to customers, multi factor authentication must be. Our guide to SAMA CSF requirements walks through each domain.

What evidence proves maturity level 3?

The maturity model has six levels, 0 to 5, and a Member Organization must meet all criteria of the preceding levels to reach level 3, 4 or 5. The level 3 criteria in Table 1 are the audit checklist:

Level 3 criterionEvidence that shows it
Controls are defined, approved and implemented in a structured and formalised wayApproved policy, standards and procedures with dates and approvers
The implementation of controls can be demonstratedConfigurations, logs, tickets, test results: artefacts, not statements
Policies, standards and procedures are establishedThe documentation set, current and version controlled
Compliance with the documentation is monitored, preferably using a GRC toolCompliance monitoring records per control
Key performance indicators are defined, monitored and reportedKPI definitions and the reports that went to management

Section 2.4.1 describes the documentation as a pyramid. The board endorses the cyber security policy, which says why. Standards say what must be implemented and act as baselines. Procedures say how. Level 2 is the trap: repeatable controls that work, but whose objectives and design are not formally defined or approved. A working control with no approved document behind it is level 2, however good it is.

The Framework also notes additional level 4 requirements for banks under a later SAMA circular. Level 4 adds periodic measurement of control effectiveness, with key risk indicators, thresholds and trend reporting.

SAMA CSF by the numbers: maturity level 3 as the minimum, six maturity levels, annual review and penetration tests for internet facing services, and quarterly committee meetings

What do the Framework's own reviews and audits require?

Subdomain 3.2.4 on cyber security review has five control considerations. Reviews must be performed periodically for critical information assets. Customer and internet facing services must be subject to annual review and penetration tests. Details of each review must be recorded, including results, issues identified and recommended actions. Results must be reported to the business owner. Follow-up reviews must check that identified issues were addressed, critical risks were treated effectively and agreed actions are being managed.

Subdomain 3.2.5 on cyber security audits aims to establish with reasonable assurance whether controls are securely designed and implemented and whether their effectiveness is monitored. Audits must be performed independently, to generally accepted auditing standards and the Framework, and according to your audit manual and audit plan. Subdomain 3.1.4 gives internal audit the responsibility for performing them, while cyber security reviews sit with the CISO. On the cyber security committee in 3.1.1, internal audit may attend only as an observer, which protects its independence.

The records these produce are the material an examiner reads. A missing follow-up review is a finding on its own, because the control consideration asks for it explicitly.

The SAMA CSF sections a cyber security audit relies on: 2.3 self-assessment, 2.4 maturity model, 3.1.4 roles, 3.2.4 review, 3.2.5 audits and the Appendix D waiver process

What if a control consideration does not fit?

Section 2.2 describes the Framework as principle based. When a control consideration cannot be tailored or implemented, the Member Organization should consider compensating controls, an internal risk acceptance and a formal waiver request to SAMA. Appendix D sets the route: approval by the CISO, then by the cyber security committee; signature by the CISO and the relevant business owner; and a written request to SAMA from the CEO or managing director to the Deputy Governor of Supervision. SAMA IT Risk Supervision evaluates it. Until a waiver is granted, the Framework applies in full. An unimplemented control with no waiver on file is a gap, not a risk decision.

Illustrative SAMA CSF audit readiness view: subdomains at maturity level 3, internet facing services tested, review findings without follow-up and waivers on file

What the other results get wrong

The first error is certification. At least one guide on page one says external auditors report to SAMA, which then issues a certificate of compliance. The Framework describes a self-assessment, a review and an audit that determine compliance and maturity. It describes no certificate, and treating an audit as a certificate you renew misreads what is being measured.

The second is scope. One guide lists consumer protection among the areas SAMA examiners check under the CSF. Consumer protection is not a CSF domain. The four domains are leadership and governance, risk management and compliance, operations and technology, and third party cyber security.

The third is inventing a calendar. Guides that suggest a quarterly review cycle are describing common practice, not the Framework. The Framework says periodic, and fixes only a few frequencies: annual review and penetration testing for customer and internet facing services, and cyber security committee meetings at least quarterly.

Venvera SAMA CSF assessment showing current and target maturity for each subdomain

How do you prepare?

Fill this in. A blank row is the first thing to fix.

QuestionYour answerFramework reference
Which subdomains apply to you, and which are excluded as a non-bank?1.4
For each applicable subdomain, what maturity level do you claim, and where is the evidence?2.3 and 2.4
Is the cyber security policy endorsed by the board, with standards and procedures under it?2.4.1
When were customer and internet facing services last reviewed and penetration tested?3.2.4
Did every review finding get a follow-up review?3.2.4
Does internal audit have an audit manual and a plan that covers cyber security?3.2.5
Is every unimplemented control consideration covered by a waiver request?2.2 and Appendix D

Our guide to SAMA CSF compliance cost prices the recurring work behind these rows. Venvera's SAMA CSF module scores each subdomain on the maturity model and holds the evidence behind each answer, and a free compliance check gives you a starting position.

Venvera evidence repository showing stored compliance artefacts with owners and freshness status
The bottom line on a SAMA CSF audit: maturity level 3 is a claim proved with records, not a score declared

Frequently asked questions

Does SAMA certify compliance with the CSF?

The Framework describes no certificate. It describes a periodic self-assessment that SAMA reviews and audits to determine the level of compliance and the maturity level.

Who does the CSF apply to?

All banks, insurance and reinsurance companies, financing companies and credit bureaus operating in Saudi Arabia, and the financial market infrastructure, with three subdomains excluded for non-banks.

What maturity level does SAMA expect?

Level 3 or higher, under section 2.4. The Framework notes additional level 4 requirements for banks.

How often must we be audited?

The Framework says regular and periodic without fixing an interval for audits. Your audit plan sets it. Customer and internet facing services need a review and penetration test every year.

Can internal audit sit on the cyber security committee?

Only as an observer, under subdomain 3.1.1.

Can we get an exemption from a control?

You can request a formal waiver from SAMA through the Appendix D process. The control applies until a waiver is granted.

Primary sources

Everything above is taken from the SAMA Cyber Security Framework as published in the SAMA Rulebook, issued under Circular No. 381000091275 dated 24 May 2017: sections 1.4, 2.2, 2.3 and 2.4, subdomains 3.1.1, 3.1.4, 3.2.4 and 3.2.5, and Appendix D. SAMA owns the Framework's interpretation and may update it. Confirm the current text before relying on a specific provision.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander →

CONTINUE READING