Alqanoni

Counter-Fraud Fundamental Requirements

Para. 2.1
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

Structure The Fundamental Requirements span the prevention, detection, and response to fraud, as well as the governance of a Member Organization’s Counter-Fraud Programme. Chapter 3 of the Fundamental Requirements is structured around five domains, including: Counter-Fraud Governance and Risk Management Fraud Prevention Fraud Detection Fraud Response Counter-Fraud Technology Control requirements have been uniquely numbered throughout the Fundamental Requirements. The control requirements are numbered according to the following numbering system: Figure 1. Control requirement numbering system The figure below illustrates the overall structure of the Fundamental Requirements and indicates the Counter-Fraud domains: Figure 2. Fundamental Requirements domains 2.2 Risk Based Approach The domains and control requirements included in the Fundamental Requirements are risk-based and intended to provide Member Organizations with essential direction on how to develop a control structure to mitigate the most common risks they face, without placing undue burden on them that could stifle innovation and business growth. From this perspective, the Fundamental Requirements set the essential Counter-Fraud minimum standards for Member Organizations that are within the scope of applicability. In addition, SAMA expects Member Organizations to conduct their own internal risk assessments: to monitor the development of the fraud threat landscape; to identify new and evolving risks particularly as new products and models such as open finance are launched; to evaluate the potential impact of these risks; and where deemed necessary to implement additional or enhanced control requirements beyond the fundamental requirements to mitigate these risks in line with the entities risk appetite. 2.3 Member Organization Self-Assessment and SAMA Audit The implementation of the fundamental requirements at the Member Organizations will be subject to periodic self-assessment. The self-assessment will be performed by the Member Organizations based on a questionnaire. The Member Organizations will send a copy of its self-assessment to SAMA, and SAMA reserves the right to review the self-assessment to evaluate compliance with the fundamental requirements at its discretion. SAMA also reserves the right to audit the compliance with the fundamental requirements of Member Organizations at any time. 3 Control Requirements 3.1 Counter-Fraud Governance and Risk Management Control ID Control requirement description 3.1.1 Member Organizations should develop a risk-based Counter-Fraud Programme proportional to the size and nature of its business to address people, process, and technology, including adequate systems and controls to prevent, detect and respond to fraud. The progress of the implementation, performance and compliance of the Counter-Fraud systems and controls should be periodically monitored using Key Performance Indicators (KPIs) with updates made to the programme to address new and emerging threats and changes in the severity of existing risks. 3.1.2 Member Organization’s Board of Directors should be ultimately responsible for the establishment of a robust governance structure that is supported by adequate resources of appropriate role and seniority to set the tone from top; and provide leadership, direction and oversight of the overall approach to fraud risk management. 3.1.3 Member Organizations should establish and maintain a Counter-Fraud Governance Committee (CFGC) that is required to meet at least on a quarterly basis. The CFGC should at a minimum be responsible for approving, supporting, communicating, and monitoring the Counter-Fraud Program; Counter-Fraud Policy; and Management Information.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.