Alqanoni

Counter-Fraud Framework

Para. 4.2
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

Due Diligence Principle Member Organisations should define, approve and implement standards for assessing the fraud risk associated with employees, customers and third parties to prevent the establishment of relationships outside risk appetite and manage fraud risks throughout the duration of the relationship. Control Requirements a. Due Diligence standards should be defined, communicated, and implemented. b. Due Diligence standards should be approved by individuals of appropriate responsibility (e.g., Employee Due Diligence in HR). c. Due Diligence standards should consider employees, customers and third parties . d. Due Diligence standards should be aligned to the risks identified in the Fraud Risk Assessment . e. Member Organisations should review and update Due Diligence standards on a periodic basis and in response to material changes to the fraud landscape , the Member Organisation Fraud Risk Assessment , customer groups serviced by the Member Organisation or changes to the products or services it offers. f. The effectiveness of the fraud Due Diligence standards should be measured and periodically evaluated. g. Due Diligence standards should include: 1. The Due Diligence checks and requirements that should be conducted to provide an informed understanding of fraud risk. 2. When Due Diligence should be conducted. 3. The role(s) responsible for conducting and approving Due Diligence . 4. Red flags or warning signs which may indicate increased fraud risk and result in the requirement for escalation or further checks to be completed. 5. Red flags or warning signs which indicate an employee, customer or third party is outside risk appetite and the relationship should be declined or exited. 6. Steps to be taken to exit relationships outside risk appetite. 4.2.1 Employee Due Diligence Principle Member Organisations should ensure background checks are conducted on employees, including contractors , to reduce the exposure to internal fraud risks and reputational damage resulting from the actions of staff of the Member Organisation. Control Requirements a. Employee Due Diligence measures should reflect the risks of internal fraud impacting the Member Organisation. b. Employee Due Diligence should have the objective of establishing the identity, integrity, and verifying the credentials of the employee, enabling the Member Organisation to determine whether they are suitable for the position. c. Employee Due Diligence should consist of screening and background checks on the employee, including but not limited to: 1. Confirmation of identity. 2. Criminal background checks. 3. Conflict of interest checks. 4. Verification of qualifications claimed. 5. Previous employment checks. d. Employee Due Diligence should be: 1. Conducted as part of the hiring process. 2. Reassessed when an existing employee moves to a new role. 3. Reperformed periodically on a risk-based approach (e.g., re-performance of screening for criminal or fraudulent behaviour to validate that employees remain suitable for the position). e. Member Organisations should assess roles which represent a high risk of fraud and document any enhanced checks required. f. The outcome of Employee Due Diligence checks should be retained in line with the Member Organisation’s record management policies for personal information.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.