Alqanoni

Counter-Fraud Fundamental Requirements

Para. 3.4.3
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

Member Organizations should implement and maintain a system or database to manage the responses to fraud and be used as a repository for fraud case data retention in-line with legal and regulatory requirements. This should be used to record and monitor suspected fraud alerts, internal and external reports, case investigations from initial assessment to resolution, and actions taken. 3.4.4 Member Organizations should define, approve, implement and maintain a process to identify the root cause of a fraud incident at the conclusion of an investigation, e.g., Understand point of compromise; Determine involvement of other parties; Review control failures. 3.4.5 Following determination of the root cause, Member Organizations should define, approve and implement a process to determine lessons learnt and inform corrective actions to prevent a recurrence, e.g., Collating and storing data which may support the analysis of patterns in fraud cases; assessing whether there is a gap in the current control framework; evaluating whether the issue could impact other Member Organizations; and sharing relevant information where permitted. 3.4.6 Member Organizations should take corrective actions to remediate the root cause and/or the impact of a fraud incident, e.g., Implementing a new control; providing employee training; putting a fraud victim back into the position they were in prior to the incident or remediating a credit report; providing support to a victim of fraud; exiting a customer or third party relationship if they are found to be the perpetrator of a fraud; internal disciplinary action where internal fraud is identified; and liaising with law enforcement agencies. 3.5 Counter-Fraud Technology Control ID Control requirement description 3.5.1 Based on the output of the fraud risk assessment, the scale of the organization and the nature of the products offered, Member Organizations should implement detection solutions to monitor customer products and services, and internal systems and accounts for transactions or behaviours that may be indicative of fraud. 3.5.2 Where fraud detection solutions are in use, Member Organizations should develop a holistic 360 degrees view of current sources of data to be used to inform detection and prevention of suspicious activity and fraud, e.g., Customer products and services held; Contact channels; External information; Transactional data; Non-transactional data. 3.5.3 Where fraud detection solutions are in use, Member Organizations should implement controls (e.g., data governance, de-duplication, data quality alerts, regular audit, integration testing, regression testing for change management) to ensure that the underlying data is timely, complete and accurate. 3.5.4 To optimise fraud detection solutions, Member Organizations should monitor performance and periodically test effectiveness through tuning and calibration. 3.5.5 Member Organizations should periodically review scenarios and parameters in fraud detection solutions to ensure they remain appropriate in view of the insights gathered in Intelligence Monitoring and/or the outcome of the Fraud Risk Assessment. 4 Control Requirements – Products and Services of Elevated Risk The following additional requirements are mandatory for licensed EMIs; AISPs; and Member Organizations offering digital payment services that offer the means to send and receive funds; Credit Cards; Microfinance; Buy Now Pay Later (BNPL) Services; or safeguarding funds on behalf of customers. In addition, as outlined in section 1.3 , Member Organizations not included in the mandatory list above should take a risk-based approach to the implementation of the additional requirements and determine and document the most effective way to mitigate the fraud risks they have identified. 4.1 Counter-Fraud Solutions and Controls for Elevated Risk Control ID Control requirement description

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.