Saudi Central Bank (SAMA)

    SAMA IT Governance Framework

    IT governance, operations and change requirements for SAMA-regulated institutions.

    Who it applies to

    Institutions supervised by the Saudi Central Bank and the IT functions and providers that run their core systems.

    What internal audit has to show

    Audit covers IT strategy and governance, project and change management, operations, and the general controls that financial reporting and regulatory returns depend on.

    What Oversight does with SAMA ITGC

    • Places the framework domains against your application and infrastructure inventory so coverage gaps in the plan are visible.
    • Drafts IT general control programs per system with walkthrough, design and operating-effectiveness steps.
    • Tracks samples, evidence and exceptions per control so the workpaper shows what was tested and what failed.
    • Reports control deficiencies with the affected systems and the supporting evidence referenced in every finding.

    Typical engagements

    • IT general controls review
    • Change and release management review
    • IT project governance review
    • Outsourcing and cloud governance review

    See a SAMA ITGC engagement drafted from your scope

    Bring the regulation and your org structure. The walkthrough builds the universe, drafts a program and traces a finding to its source on your documents.

    Request a demo