Counter-Fraud Fundamental Requirements
Para. 1.3Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Applicability The Fundamental Requirements are applicable to Member Organizations based on SAMA discretion. Member Organisations required to implement and comply with the Fundamental Requirements will be notified by SAMA. Due to the elevated fraud risk of products and services offered, Member Organizations (including FinTechs) operating in the payments sector, offering credit cards, electronic money or providing products which can be used to send or receive funds must adopt additional controls to protect their customers against the risk of fraud and to ensure that the organization is not being used to receive the proceeds of fraud. An additional domain mandatory for Electronic Money Institutions (EMIs); Account Information Service Providers (AISPs) and Member Organizations offering digital payment services that offer the means to send and receive funds; Credit Cards; Microfinance; Buy Now Pay Later (BNPL) Services; or safeguarding funds on behalf of customers is included in Chapter 4 . Member Organizations not included in the mandatory list above should take a risk-based approach to the implementation of the additional requirements. Through a risk assessment, Member Organizations should identify, assess, and understand the fraud risk to which they and their customers are exposed, and implement appropriate requirements. The application of a risk based approach will help to encourage growth in the sector by not putting barriers to market entry and allow Member Organizations to implement enhanced measures where the fraud risks are higher and focus resources accordingly. 1.4 Responsibilities and Interpretation The Fundamental Requirements are mandated by SAMA and will be circulated to Member Organizations for implementation. SAMA, as the owner of the Fundamental Requirements, is solely responsible for providing interpretations of the control requirements, if required. In scope Member Organizations are responsible for implementing and complying with the Fundamental Requirements. 1.5 Target Audience The Fundamental Requirements are intended for Senior and Executive Management, business owners, members of the Member Organization’s Counter-Fraud Department (where applicable) and those who are responsible for, and involved in planning, defining, implementing, and reviewing Counter-Fraud controls across the three lines of defence. 1.6 Review, Updates and Maintenance SAMA will review the Fundamental Requirements periodically to evaluate its applicability to the context of the KSA financial sector and its intended Member Organizations. If deemed necessary, SAMA will update the fundamental Requirements based on the outcome of the review. SAMA will implement version control for maintaining the Fundamental Requirements. Whenever making any changes, SAMA will retire the preceding version, as well as release and communicate the new version to all Member Organizations. For the convenience of the Member Organizations, SAMA will clearly indicate any changes to the revised Fundamental Requirements. 1.7 Reading Guide The Fundamental Requirements is structured as follows: Chapter 2 elaborates on the structure of the Fundamental Requirements and provides guidance on how to apply the Fundamental Requirements; Chapter 3 presents the Counter-Fraud domains including control requirements; Chapter 4 presents control requirements mandatory for EMIs; AISPs; and Member Organizations offering digital payment services that offer the means to send and receive funds; Credit Cards; Microfinance; Buy Now Pay Later (BNPL) Services; or safeguarding funds on behalf of customers and applicable to other Member Organizations on a risk based approach as outlined in section 1.3 . 2 Fundamental Requirements Structure and Features
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded