A SAMA CSF audit starts from your own self-assessment. Section 2.3 of the SAMA Cyber Security Framework makes implementation subject to a periodic self-assessment, performed by the Member Organization on a questionnaire, and says those self-assessments will be reviewed and audited by SAMA to determine two things: the level of compliance with the Framework and the cyber security maturity level reached. Every Member Organization should operate at maturity level 3 or higher. So what SAMA tests is whether your answers are true: that each control you rate at level 3 is defined, approved, implemented and monitored, and that you can show it.
The Framework also requires audits you commission yourself. Subdomain 3.2.5 requires thorough, independent and regular cyber security audits, performed to generally accepted auditing standards and the Framework, following your audit manual and audit plan. Subdomain 3.2.4 requires periodic cyber security reviews. Four activities are involved, and preparing for one does not prepare you for the others.
| Activity | Who performs it | Where the Framework sets it |
|---|---|---|
| Self-assessment on SAMA's questionnaire | The Member Organization | Section 2.3 |
| Review and audit of the self-assessment | SAMA | Section 2.3 |
| Cyber security audits | The internal audit function, independently, to generally accepted auditing standards | Subdomains 3.1.4 and 3.2.5 |
| Cyber security reviews | The CISO's cyber security function | Subdomains 3.1.4 and 3.2.4 |
What does SAMA actually test?
The Framework is organised as four domains with subdomains, and each subdomain states a principle, an objective and control considerations. An audit works at that level. A domain average hides the gaps, so expect evidence to be requested subdomain by subdomain, against the control considerations that apply to you.
Applicability is the first thing to get right. All domains apply to banks. For insurers, reinsurers, financing companies, credit bureaus and the financial market infrastructure, section 1.4 excludes subdomains 3.2.3, 3.3.12 and 3.3.13, with conditions: if you store, process or transmit cardholder data or use SWIFT services, PCI DSS or the SWIFT Customer Security Controls Framework must be implemented, and if you provide online services to customers, multi factor authentication must be. Our guide to SAMA CSF requirements walks through each domain.
What evidence proves maturity level 3?
The maturity model has six levels, 0 to 5, and a Member Organization must meet all criteria of the preceding levels to reach level 3, 4 or 5. The level 3 criteria in Table 1 are the audit checklist:
| Level 3 criterion | Evidence that shows it |
|---|---|
| Controls are defined, approved and implemented in a structured and formalised way | Approved policy, standards and procedures with dates and approvers |
| The implementation of controls can be demonstrated | Configurations, logs, tickets, test results: artefacts, not statements |
| Policies, standards and procedures are established | The documentation set, current and version controlled |
| Compliance with the documentation is monitored, preferably using a GRC tool | Compliance monitoring records per control |
| Key performance indicators are defined, monitored and reported | KPI definitions and the reports that went to management |
Section 2.4.1 describes the documentation as a pyramid. The board endorses the cyber security policy, which says why. Standards say what must be implemented and act as baselines. Procedures say how. Level 2 is the trap: repeatable controls that work, but whose objectives and design are not formally defined or approved. A working control with no approved document behind it is level 2, however good it is.
The Framework also notes additional level 4 requirements for banks under a later SAMA circular. Level 4 adds periodic measurement of control effectiveness, with key risk indicators, thresholds and trend reporting.
What do the Framework's own reviews and audits require?
Subdomain 3.2.4 on cyber security review has five control considerations. Reviews must be performed periodically for critical information assets. Customer and internet facing services must be subject to annual review and penetration tests. Details of each review must be recorded, including results, issues identified and recommended actions. Results must be reported to the business owner. Follow-up reviews must check that identified issues were addressed, critical risks were treated effectively and agreed actions are being managed.
Subdomain 3.2.5 on cyber security audits aims to establish with reasonable assurance whether controls are securely designed and implemented and whether their effectiveness is monitored. Audits must be performed independently, to generally accepted auditing standards and the Framework, and according to your audit manual and audit plan. Subdomain 3.1.4 gives internal audit the responsibility for performing them, while cyber security reviews sit with the CISO. On the cyber security committee in 3.1.1, internal audit may attend only as an observer, which protects its independence.
The records these produce are the material an examiner reads. A missing follow-up review is a finding on its own, because the control consideration asks for it explicitly.
What if a control consideration does not fit?
Section 2.2 describes the Framework as principle based. When a control consideration cannot be tailored or implemented, the Member Organization should consider compensating controls, an internal risk acceptance and a formal waiver request to SAMA. Appendix D sets the route: approval by the CISO, then by the cyber security committee; signature by the CISO and the relevant business owner; and a written request to SAMA from the CEO or managing director to the Deputy Governor of Supervision. SAMA IT Risk Supervision evaluates it. Until a waiver is granted, the Framework applies in full. An unimplemented control with no waiver on file is a gap, not a risk decision.
What the other results get wrong
The first error is certification. At least one guide on page one says external auditors report to SAMA, which then issues a certificate of compliance. The Framework describes a self-assessment, a review and an audit that determine compliance and maturity. It describes no certificate, and treating an audit as a certificate you renew misreads what is being measured.
The second is scope. One guide lists consumer protection among the areas SAMA examiners check under the CSF. Consumer protection is not a CSF domain. The four domains are leadership and governance, risk management and compliance, operations and technology, and third party cyber security.
The third is inventing a calendar. Guides that suggest a quarterly review cycle are describing common practice, not the Framework. The Framework says periodic, and fixes only a few frequencies: annual review and penetration testing for customer and internet facing services, and cyber security committee meetings at least quarterly.

How do you prepare?
Fill this in. A blank row is the first thing to fix.
| Question | Your answer | Framework reference |
|---|---|---|
| Which subdomains apply to you, and which are excluded as a non-bank? | 1.4 | |
| For each applicable subdomain, what maturity level do you claim, and where is the evidence? | 2.3 and 2.4 | |
| Is the cyber security policy endorsed by the board, with standards and procedures under it? | 2.4.1 | |
| When were customer and internet facing services last reviewed and penetration tested? | 3.2.4 | |
| Did every review finding get a follow-up review? | 3.2.4 | |
| Does internal audit have an audit manual and a plan that covers cyber security? | 3.2.5 | |
| Is every unimplemented control consideration covered by a waiver request? | 2.2 and Appendix D |
Our guide to SAMA CSF compliance cost prices the recurring work behind these rows. Venvera's SAMA CSF module scores each subdomain on the maturity model and holds the evidence behind each answer, and a free compliance check gives you a starting position.

Frequently asked questions
Does SAMA certify compliance with the CSF?
The Framework describes no certificate. It describes a periodic self-assessment that SAMA reviews and audits to determine the level of compliance and the maturity level.
Who does the CSF apply to?
All banks, insurance and reinsurance companies, financing companies and credit bureaus operating in Saudi Arabia, and the financial market infrastructure, with three subdomains excluded for non-banks.
What maturity level does SAMA expect?
Level 3 or higher, under section 2.4. The Framework notes additional level 4 requirements for banks.
How often must we be audited?
The Framework says regular and periodic without fixing an interval for audits. Your audit plan sets it. Customer and internet facing services need a review and penetration test every year.
Can internal audit sit on the cyber security committee?
Only as an observer, under subdomain 3.1.1.
Can we get an exemption from a control?
You can request a formal waiver from SAMA through the Appendix D process. The control applies until a waiver is granted.
Primary sources
Everything above is taken from the SAMA Cyber Security Framework as published in the SAMA Rulebook, issued under Circular No. 381000091275 dated 24 May 2017: sections 1.4, 2.2, 2.3 and 2.4, subdomains 3.1.1, 3.1.4, 3.2.4 and 3.2.5, and Appendix D. SAMA owns the Framework's interpretation and may update it. Confirm the current text before relying on a specific provision.




