Counter-Fraud Fundamental Requirements
Para. 3.1.4Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Member Organizations should consider areas of operational collaboration between Counter-Fraud, Cyber Security and Financial Crime Teams. Examples of capabilities to consider include establishment of multi-disciplinary contacts; cross training; development of joint task forces; sharing threat intelligence; aligning incident response; and coordinating corrective actions. 3.1.5 Member Organizations should define, approve, communicate and implement Counter-Fraud Policies, Standards and Procedures aligned to the risks identified in the Fraud Risk Assessment and the legal, regulatory and payment operator requirements of the Member Organization. Counter-Fraud Policy should include at a minimum, overall Counter-Fraud objectives and scope; policy requirements; consequences of non-compliance; and roles and responsibilities, including overall responsibility for Counter-Fraud. 3.1.6 Member Organizations should periodically review and update Counter-Fraud Policy and Procedures to ensure they take into consideration fraud and attempted fraud impacting the Member Organization and the sector; the evolving fraud landscape; the fraud risks and scale of the Member Organization’s business model and operations; and manage identified risks effectively. 3.1.7 Member Organizations should identify and implement reporting of appropriate Management Information to adequately inform Senior Management of Counter-Fraud risks and performance. At a minimum, this should include volume and trends of fraud cases handled; near misses or potential frauds that were detected and prevented; typologies; and the value of both customer and operational fraud losses. 3.1.8 Member Organizations should notify the SAMA Executive Department of Operational Resilience Control (ORC) immediately of: - A new fraud typology (e.g., type of fraud not previously observed or new scam attempt detected). - Any significant internal or external fraud incidents. When assessing whether a fraud is considered significant, Member Organizations should consider the value of the loss to the organization or its customers; the number of customers impacted; reputational damage to the organization or wider sector; regulatory breaches; and the potential to impact other Member Organizations. Member Organizations should use the standard reporting template in Appendix C to notify SAMA. 3.1.9 Member Organizations should define Fraud Risk Appetite to state the level of fraud risk the Member Organization is willing to tolerate when designing and implementing Counter-Fraud systems and controls. 3.1.10 Member Organizations should define, approve, and monitor Key Risk Indicators (KRIs) to measure and evaluate their position against agreed Fraud Risk Appetite and the control requirements in this document. 3.1.11 Member Organizations should conduct Intelligence Monitoring utilising internal and external information sources to develop and maintain an awareness of new and emerging fraud threats which may impact the organization and its customers. 3.1.12 Member Organizations should conduct an enterprise-wide Fraud Risk Assessment to identify fraud risks to which they or their customers are subject; inform the controls required based on the level of inherent fraud risk identified for products and services offered; assess the effectiveness of controls in place to mitigate the risks; and determine residual risk. The risk assessment should be refreshed periodically and updated following changes in the internal or external fraud risk environment, e.g., new products or services; new digital platforms; new business acquisitions; new fraud threats identified. 3.1.13 Prior to the introduction of a new product or service, Member Organizations should engage Counter-Fraud to assess the potential fraud vulnerabilities and recommend controls required to mitigate the risks.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded