Counter-Fraud Framework
Para. 4.3.3Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Third Party Fraud Awareness Principle Member Organisations should define and deliver a proportionate fraud awareness programme to third parties outlining expectations in respect of Counter-Fraud activity and prompt reporting of suspicious activity. Control Requirements a. Third party fraud awareness requirements should be documented and agreed in contractual arrangements where applicable. b. Member Organisations should provide risk-based fraud awareness materials to third parties at the outset of a relationship and refresh periodically as required. c. Third party fraud awareness requirements should as a minimum include: 1. The creation of a positive Counter-Fraud culture . 2. Third party roles and responsibilities regarding fraud. 3. Tailored messaging aligned to the fraud risks of the services provided by the third party . 4. Reporting mechanisms available to the third party . 4.4. Authentication Principle Member Organisations should define, approve, implement and maintain a standard for the authentication of customer, employee and third party credentials and instructions to ensure information is protected and unauthorised access or actions are prevented. This should be risk-based and utilise multi-factor authentication. Control Requirements a. A Member Organisation should define, approve, implement and maintain an authentication standard with input from both the Counter-Fraud Department and Cyber Security Team. b. A Member Organisation's authentication standard should consider the risks identified in its Fraud Risk Assessment and Cyber Security Risk Assessment. c. The authentication standard should consider both customer access to products and services, and employee and third party access to Member Organisation systems. d. When defining the authentication standard, Member Organisations should take note of the following Control Requirements outlined in The Cyber Security Framework : 1. 3.3.5 Identity and access management 2.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded