Counter-Fraud Framework
Para. 4.3.1Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Employee Fraud Training and Awareness Principle Member Organisations should define and deliver an employee fraud training and awareness programme to enable employees to identify fraud and report it promptly. Control Requirements a. Counter-Fraud training should enable employees to develop a clear understanding of the Member Organisation's Counter-Fraud policies and procedures and their personal responsibilities in relation to fraud prevention and detection. b. Training should be provided to all employees at, or shortly after, onboarding and be refreshed at regular intervals. c. The Member Organisation's fraud training and awareness programme should be risk based, including the requirement for certain employees to be provided with specialised training depending upon the fraud risk associated with their role (e.g., managers with positions of authority, customer facing staff in branches, employees operating CounterFraud controls and fraud investigators). d. Counter-Fraud training should include a knowledge check to assess whether the employee has understood the content. Employees who do not pass the knowledge check should be required to repeat the training and pass rates should be monitored, with action taken if there are repeated failures (e.g., re-training via another delivery method or removal of authority to operate a Counter-Fraud control until successful). e. The Board of Directors and Senior Management at Member Organisations should be provided with fraud training tailored to the seniority of the role (e.g., fraud awareness, setting an appropriate culture and governance). f. Formally delivered training should be augmented by ongoing employee education activity to maintain the general fraud awareness of employees (e.g., issuing reminders and circulars on potential indicators of fraud and common fraud typologies ). g. Member Organisations should maintain records of fraud training delivered to employees and awareness activity conducted. h. Member Organisations should have a documented process to manage employees who are non-compliant with the training requirements for their role. 4.3.2 Customer Fraud Awareness Principle Member Organisations should define and conduct a customer fraud awareness programme of activity to increase customer understanding of fraud risks; help customers to recognise and resist fraud attempts; and inform them how to report fraud. Control Requirements a. Customer fraud awareness activity should deliver relevant and timely education to customers and promote fraud awareness. b. The activity delivered through the customer fraud awareness programme should include, at a minimum: 1. Information on the fraud threats and scams customers may be exposed to. 2. Customer responsibilities about countering fraud. 3. How customers can prevent themselves from becoming victims. 4. How to report to the Member Organisation if the customer believes they have been a victim of fraud. c. Customer fraud awareness activity should be tailored to the current fraud trends impacting the Member Organisation and its sector, including but not limited to the fraud typologies observed and the point of compromise which led to the fraud (e.g., SMS, email, social media). d. Customer fraud awareness activity should cover the duration of the customer lifecycle (e.g., onboarding, changes to product holdings, transactions and settlements). e. Member Organisations should deliver customer awareness materials through all communication channels offered to the customer (e.g., website, mobile app, email, post, and SMS). f. Member Organisations should provide additional education on fraud protection to customers who may be vulnerable to or have been the victim of a scam (e.g., support on the phone or additional materials via email or post).
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded