Security & compliance · Saudi Arabia

Edrak and the Saudi Central Bank

SAMA sets the rules that licensed financial institutions must follow for cybersecurity, resilience and outsourcing. Adding AI to a bank's workflows raises exactly those questions, so Edrak is built to answer them: your permissions, your data location, a full record, and contracts written for regulated outsourcing.

SAMA
Financial regulator. Sets cybersecurity, business continuity and outsourcing requirements for licensed institutions.
Applies to
Banks, insurers, finance companies and payment providers licensed by SAMA. Sector-specific requirements.
Where Edrak stands
Edrak supports institutions in meeting their SAMA obligations as a technology provider. We map our controls to the SAMA frameworks and structure contracts to fit its outsourcing rules. SAMA does not certify vendors.

The SAMA frameworks

Four frameworks shape what a licensed institution needs from a technology provider. They apply to the licensed institution.

  • CSF

    Cyber Security Framework

    Governance, risk management, operations and third-party cybersecurity for member organisations.

  • BCM

    Business Continuity Management Framework

    Continuity planning, recovery objectives and testing.

  • Outsourcing

    Rules on Outsourcing

    Materiality, due diligence, contract terms, data location and regulator notification for outsourced services.

  • IT Gov

    IT Governance Framework

    IT strategy, architecture, change and operations governance.

How Edrak supports your SAMA obligations

The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.

  • Outsourcing and materiality

    Edrak: Contract terms, exit and data-return provisions, and audit rights are written to fit financial-sector outsourcing rules.

    You: Materiality assessment and any regulator notification or approval.

  • Identity and access

    Edrak: Signs in through your identity provider and inherits the permissions people already hold. It cannot see data a user could not see.

    You: Identities, roles, and joiner, mover and leaver processes.

  • Data location

    Edrak: Runs in Edrak Cloud in your chosen region, in your own cloud account, or on-premises. Your data is used for your business only.

    You: Choosing the deployment that meets SAMA's data-location expectations.

  • Records

    Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.

    You: Retention aligned to SAMA requirements and audit access.

  • Resilience

    Edrak: Defined availability targets, tested recovery, and workflows that pause safely when something goes wrong.

    You: Business-continuity plans and recovery objectives.

  • Incidents

    Edrak: A named security contact, notification commitments and support for your investigation, agreed in contract.

    You: Incident handling and SAMA notification.

For your security and compliance teams

We share a requirement-by-requirement mapping to the SAMA frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.

Talk to our team

SAMA issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Requirements apply to institutions licensed by the regulator. Edrak supports your obligations as a technology provider to a regulated institution. Confirm applicability with your compliance team.