Counter-Fraud Framework
Para. 4.1.3Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Risk Appetite Principle Member Organisations should define, approve, and apply their Fraud Risk Appetite when designing and implementing Counter-Fraud systems and controls. Control Requirements a. The Fraud Risk Appetite of the Member Organisation should be defined to state the level of fraud risk the Member Organisation is willing to tolerate. b. The Member Organisation Fraud Risk Appetite should be based on the outcome of the Fraud Risk Assessment and aligned to the overall risk appetite of the organisation. c. When defining Fraud Risk Appetite , Member Organisations should put in place measures with associated thresholds and limits that address the impact on both: 1. The Member Organisation (e.g., fraud losses, reputational damage); and 2. Its customers (e.g., customer losses, number of fraud victims, inconvenience). d. In the event that a Fraud Risk Appetite limit is breached with an impact on customers, a Member Organisation should escalate to Senior Management and initiate a crisis management process that should: 1. Involve the CEO and other Senior Managers in the Member Organisation. 2. Require meetings on at least a weekly basis until the issue is resolved and the measure returns to a level within appetite. e. Fraud Risk Appetite should be reviewed on at least an annual basis and be formally endorsed by the Board. f. Fraud Risk Appetite should be monitored and updated for material changes to the Member Organisation’s business model. 4.1.4 Key Risk Indicators Principle Member Organisations should define, approve, and monitor KRIs to measure and evaluate position against agreed Fraud Risk Appetite and provide an early indication of increasing fraud risk exposure. Control Requirements a. The KRIs defined by the Member Organisation should be based on a documented methodology which should require: 1. KRIs to monitor exposure against the risks identified in the Fraud Risk Assessment . 2. KRIs to consider risks to the organisation (e.g., fraud losses, reputational impact, operational management of fraud alerts) and its customers (e.g., customer losses). 3. KRIs to be approved by the CFGC or wider Risk Committee which governs the Counter-Fraud Programme in line with the requirements included in sub-domain 3.1 . 4. All KRIs to have a documented owner who is responsible for monitoring the KRI and taking early action if risk exposure exceeds Fraud Risk Appetite . 5. KRIs to be periodically reported to Senior Management and relevant stakeholders (minimum on a quarterly basis). 6. KRIs to be reviewed and updated at a minimum on an annual basis and more frequently in response to material changes to the fraud landscape or the Member Organisation Fraud Risk Assessment . b. KRIs should be forward looking and provide an early indication of increasing fraud risk exposure rather than simply measuring fraud volumes or losses (e.g., controls rated as ineffective in control testing; failure of employees to complete mandatory fraud training; or fraud alerts not reviewed within defined service level agreements). c. When developing KRIs , Member Organisations should define thresholds that allow them to determine whether the actual result of measurement is below, on, or above the targeted risk appetite position. d. Member Organisations should ensure that metrics associated with KRIs are complete, accurate and generated on a timely basis.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded