Alqanoni

Counter-Fraud Framework

Para. 4.2.3
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

Third Party Due Diligence Principle Member Organisations should ensure proportionate Due Diligence is conducted on third parties to develop an understanding of fraud risk associated with business relationships and ensure third parties are appropriately managed to mitigate the risk. Control Requirements a. Third Party Due Diligence should consist of checks and vetting procedures on a risk-based approach to allow an assessment of the fraud risks presented by the relationship. b. Third Party Due Diligence should be conducted prior to entering into a commitment for a new relationship c. Third Party Due Diligence should be reviewed periodically or following a trigger which indicates increased fraud risk (e.g., concerns on the conduct of a third party or its employees; or negative media articles). d. Third Party Due Diligence should be enhanced for: 1. Higher risk third parties or their representatives 2. Third parties providing critical services to the Member Organisation. e. Enhanced Third Party Due Diligence checks should include additional steps to assess the fraud risks presented by the relationship (e.g., additional vetting or assessing the third party approach to managing the risk of fraud). f. Where a Member Organisation outsources services to a third party organisation, that third party should comply with the Member Organisation’s Counter-Fraud Policy or apply an equivalent approach. 4.3 Training and Awareness Principle A fraud awareness programme should be defined, approved, and conducted for employees, customers and third parties of the Member Organisation. Control Requirements a. The fraud awareness programme should be defined, approved, and conducted to promote awareness of fraud risks, provide education on preventing, detecting, and responding to potential fraud and create a positive Counter-Fraud culture . b. The fraud awareness programme should include coverage of: 1. Employees of the Member Organisation. 2. Customers of the Member Organisation. 3. Third parties who hold relationships with the Member Organisation. c. The fraud awareness programme should consist of training, education and awareness materials directly linked to risks and threats identified in the Fraud Risk Assessment . d. The fraud awareness programme should: 1. Outline the nature, scale and scope of training and education to be delivered. 2. Be tailored to the different target groups. 3. Be delivered via multiple channels. e. The activities of the fraud awareness programme should be conducted periodically and throughout the year. f. Member Organisations should ensure that the programme is updated at least annually to account for changes in the fraud threat landscape or in response to new fraud threats identified in Intelligence Monitoring . g. Where a new or emerging fraud typology may impact the Member Organisation and its customers, Member Organisations should take immediate action to make employees, customers and relevant third parties aware of the threat and preventive measures to be taken (where applicable). h. Member Organisations should monitor and evaluate the effectiveness of the fraud awareness programme and implement improvements where required.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.