Alqanoni

Counter-Fraud Fundamental Requirements

Para. 4.1.1
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

Member Organizations should implement real-time fraud detection and prevention solutions to identify anomalies in transactional and non-transactional data, and monitor systems and internal accounts for transactions or behaviours that may be indicative of fraud. 4.1.2 Fraud detection systems should operate 24/7 with appropriate resources in place to manage outputs on a timely basis. 4.1.3 Member Organizations should ensure that the solutions and rules are designed or can be customised to align to the products, services, and fraud risks of the organization. 4.1.4 Member Organizations should implement controls that allow real-time actions such as freezing of accounts and blocking of transactions in a timely manner if a customer or Member Organization suspects an account has been compromised. 4.1.5 Member Organizations should use data and intelligence to screen and block transactions or access from identified high risk accounts; GPS locations; IP addresses; email addresses; devices that are subject to jailbreaking or rooting; use of VPN services when accessing online or mobile services; and compromised devices or those that have previously been used for fraud. 4.1.6 Member Organizations should implement device registration controls which allow users to register trusted devices for access management. 4.1.7 Member Organizations should implement controls to protect customers from payments and product application fraud, including but not limited to: a. Notification to the customer of new payees added (e.g., SMS, Mobile App notification). b. Notification to the customer when: a. User submitted the product application request. b. When the product request is approved or denied. c. Setting a default limit subject to periodic review for single and daily transactions. 4.1.8 Member Organizations should conduct multi-factor authentication checks to verify: a. Payments to newly added payees or beneficiaries b. Unusual transactions (e.g., transactions after a period of account dormancy, changes to customer behaviours, payments to a high-risk foreign jurisdiction). c. Unusual patterns of transactions (e.g., multiple payments to one or more beneficiaries in a short period, rapid inflow and outflow of funds). d. Transactions exceeding a defined value threshold. e. Requests to increase the single or daily transaction limit. f. Initial transactions after registration for online or mobile services, or registration of a new device. 4.1.9 Multi-factor authentication conducted by Member Organizations for identification and transaction verification should not solely consist of One Time Passwords (OTPs) sent via SMS. Member Organizations should implement additional factors, e.g., a. Approval of transactions through Mobile App by a push notification on a trusted device; b. Device characteristics; Precise Geolocation; Behavioural profile; or Biometric behaviours; c. Call-backs. 4.1.10 Where a Member Organization sends an OTP via SMS, the purpose, amount and merchant name should be clearly defined and in line with SAMA approved notification templates. OTPs sent via SMS should be in the language selected by the customer on the account (e.g., Arabic, English). 4.1.11 Member Organizations should implement controls to detect mule accounts (e.g., accounts set-up to receive fraudulently obtained funds and launder the proceeds of crime) and take action to prevent the outward flow and recovery of funds. 4.1.12 Member Organizations should update controls, rules and decision-making models in solutions to mitigate fraud risks resulting from new and emerging fraud typologies identified through intelligence monitoring or root cause analysis and take proactive action to prevent fraud.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.