Alqanoni

Counter-Fraud Fundamental Requirements

Para. 3.2.11
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

Member Organizations should define, approve, implement and maintain controls to mitigate the risk of external fraud occurring, e.g., Communication channels to report fraud; customer identity and access management controls; issue of OTPs to verify payments or activity; blocking or freezing accounts if fraud is suspected; and additional verification checks to verify unusual behaviours or requests. 3.2.12 To encourage fraud conscious behaviours in customers, Member Organizations should educate customers on the channels they will use to communicate with them and not include clickable links in emails and SMS sent to customers. 3.3 Fraud Detection Control ID Control requirement description 3.3.1 Member Organizations should design and implement controls to monitor customer products and services for behaviours and activity that may be indicative of external fraud. At a minimum these should address the risk presented by: a. First party fraud – Where a customer of the Member Organization misrepresents their identity, gives false information to commit fraud using their own account, loan application or submits false or inflated insurance claims. b. Second party fraud – Where a customer or individual knowingly provides their personal information or allows their identity to be used to commit fraud. c. Third party fraud – Where an unauthorised individual or entity obtains details of a customer of a Member Organization without his/her consent or knowledge, then uses the information to commit fraud. 3.3.2 Member Organizations should design and implement controls to monitor employees in roles which have been identified in the Fraud Risk Assessment as presenting a risk of internal fraud, e.g., Audit trail of system access and activity; monitoring for unusual behaviours or activity; reconciliation and settlement of financial transactions; monitoring and approval of corporate card use and expense claims. 3.3.3 Member Organizations should define, approve, implement and maintain a whistle blowing process across multiple channels for employees, customers and third parties to report potential fraud violations, the process should comply with SAMA relevant regulations for Financial Institutions. 3.4 Fraud Response Control ID Control requirement description 3.4.1 Member Organizations should define, approve, implement and maintain a Fraud Response Plan which outlines the organizational response to an actual or suspected fraud incident. Where appropriate this should be aligned with the enterprise incident management process. The response plan should include: a. Roles and responsibilities for individuals and teams required to respond to a potential fraud. b. Procedures to quickly respond to potential fraud cases identified by the Member Organization, informed by the customer or notified by other organizations. c. The actions the Member Organization will take when fraud is suspected or has been identified. d. The process to be followed in the event a potential fraud incident is detected outside of the normal working hours of the Member Organization. e. Determining external notifications required (e.g., liaising with law enforcement, notifying credit information companies, reporting to SAMA, reporting to the General Directorate of Financial Intelligence (FIU) if the Member Organization has any suspicion that rises to the level stated in article 15 of AML Law and article 17 of CTF law ). 3.4.2 Member Organizations should conduct a prompt and competent assessment, investigation, and resolution of all suspected or identified fraud. If the required capabilities to conduct the investigation are not available internally, the Member Organization should seek external support to investigate and resolve the fraud as required, and ensure that the external support resource is appropriately vetted and monitored.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.