4.1 Counter-Fraud Solutions and Controls for Elevated Risk
Para. 4.1.13Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Where a customer relationship is initiated on a remote basis (e.g., online), Member Organizations should assess the risk of impersonation and the set-up of mule accounts, implementing appropriate controls to mitigate the risk, including but not limited to: a. Ensuring a phone number and National ID/Iqama is linked to one customer application only. In the event an exception is identified (e.g., dependent family member), additional due diligence checks should be conducted to validate the authenticity of the application and monitoring use cases should be developed. b. Verification that the ownership of the phone number is registered to the same user through a trusted party (i.e., the name of the account applicant and national ID match). c. Authentication of the account registration request via the National Single Sign-On portal using Biometric based authentication (e.g., facial identification from national trusted party), including a one-time-password mechanism (OTP) explaining that a new account is being registered as a form of verification. The OTP must be sent to the verified phone number as per step (4.1.13-b). d. Requiring the use of a registered National Address. e. Notification of the completion of account registration should be sent to verified phone number that is registered for the account as well as to the phone number that is registered in the national single sign-on portal. f. Following initial set up, account fraud risk scoring should be established with restrictions placed on the account where applicable (e.g., reduced transaction value limit) until such time as the Member Organization validates that the customer is genuine through a combination of activities (e.g., use of biometric authentication mechanism through facial identification from national trusted party periodically, physical presence in a branch, regular pattern of account activity over a period of time). g. Member Organization should have process implemented to assure the recipient IBAN belongs to the loan requester. h. Implementing a process to ensure the ability to identify the source of inbound customer transactions. i. Implementing a process to allow accepting/rejecting inbound customer transactions that are not originating from the same customer for e-wallet card top-up and crowdfunding participation.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded