Counter-Fraud Fundamental Requirements
Para. 3.1.14Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Where third party services or resources (e.g., contractors or Managed Services) are used to fulfil Counter-Fraud responsibilities, Member Organizations should ensure the resource is appropriately vetted and monitored. 3.1.15 Member Organizations should ensure periodic independent audits are conducted in accordance with generally accepted auditing standards and relevant SAMA regulations to verify that the fraud control design is adequately implemented and operating as intended. 3.2 Fraud Prevention Control ID Control requirement description 3.2.1 Member Organizations should define, communicate and implement Due Diligence standards aligned to the risks identified in the fraud risk assessment for employees, customers and third parties. 3.2.2 Employee Due Diligence measures should reflect the risks of internal fraud impacting the Member Organization and have the objective of establishing the identity, integrity, and verifying the credentials of the employee, enabling the Member Organization to determine whether they are suitable for the position (e.g., Confirmation of identity, Criminal background, and Previous employment checks). 3.2.3 When establishing a new customer relationship, Member Organizations should check and verify the identity of the customer to reasonably ensure that it is not exposed to external fraud risk. 3.2.4 Third Party Due Diligence should consist of checks and vetting procedures on a risk-based approach to allow an assessment of the fraud risks presented by the relationship and ensure third parties are appropriately managed to mitigate the risk. 3.2.5 Member Organizations should periodically conduct Counter-Fraud training to ensure all employees are aware of their responsibilities under applicable Counter-Fraud Policies, Standards and Procedures; promote awareness of fraud risks; create a positive Counter-Fraud culture; and communicate the requirement to report any suspicions of fraud in a timely manner. 3.2.6 Customer fraud awareness activity should deliver relevant and timely education to customers and promote awareness of fraud risks, e.g., information on recent fraud cases, current or emerging threats, how customers can protect themselves and how to report fraud. 3.2.7 Member Organizations should define, approve, implement and maintain an authentication standard that is aligned to Cyber Security control requirements. The standard should consider both customer access to products and services; and employee and third party access to Member Organization systems. 3.2.8 Member Organizations should adopt a risk-based approach to authentication with higher risk access, instructions or activity (e.g., registration process for online or mobile product access; payments; reset of security credentials; or instructions for disbursement of a loan) subject to multi-factor authentication before they are acted upon. 3.2.9 Member Organizations should define, approve, implement and maintain controls to mitigate the risk of internal fraud occurring, e.g., Requiring employees to adhere to a Code of Conduct; segregation of duties; secondary checking of control operation; restricting access to sensitive and customer information; controls over access to cash or cheques; and physical security of assets. 3.2.10 Member Organizations should put in place appropriate processes and controls to deter and avoid conflicts of interest and related party transactions for their directors, managers, employees, external businesses, and contractors, e.g., information barriers to limit the flow of information; training on what constitutes a conflict of interest and how to avoid; and clear guidance on prohibited activity.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded