Business Continuity Management Framework
Para. 2.12Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Periodic Documents Review Principle The business continuity and disaster recovery program, policies, plans and procedures should be reviewed and updated periodically, and in case of (major) change in the Member Organization's critical products, services, business functions and/or processes. Objective To ensure that all the business continuity documents are up to date and can be used during a disruptive incident to recover the business operations. Control considerations Member Organizations should establish a process for document review/update to ensure the BC documents are up-to-date, reviewed and approved. All documents should clearly identify the last date in which the document was reviewed and approved. 2.13 Assurance Principle The BCM of the Member Organizations should be subjected to periodically reviews and audits by a qualified independent internal or external party to ensure its effectiveness, and to obtain assurance regarding the compliance with the SAMA BCM. Objective To ensure that an independent party is reviewing the BCM framework activities and reporting the identified issues to the senior management independently. Control considerations Member organization should conduct review / audit of BCM by qualified independent internal/ external party. the Member Organization should identify the gaps and provide a road map to enhance the BCM within the organization. The identified gaps along with road map should be reported to senior management and BCM committee.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded