Counter-Fraud Fundamental Requirements
Para. 4.1.13Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Where a customer relationship is initiated on a remote basis (e.g., online), Member Organizations should assess the risk of impersonation and the set-up of mule accounts, implementing appropriate controls to mitigate the risk, including but not limited to: a. Ensuring a phone number and National ID/Iqama is linked to one customer application only. In the event an exception is identified (e.g., dependent family member), additional due diligence checks should be conducted to validate the authenticity of the application and monitoring use cases should be developed. b. Verification that the ownership of the phone number is registered to the same user through a trusted party (i.e., the name of the account applicant and national ID match). c. Authentication of the account registration request via the National Single Sign-On portal using Biometric based authentication (e.g., facial identification from national trusted party), including a one-time-password mechanism (OTP) explaining that a new account is being registered as a form of verification. The OTP must be sent to the verified phone number as per step (4.1.13-b). d. Requiring the use of a registered National Address. e. Notification of the completion of account registration should be sent to verified phone number that is registered for the account as well as to the phone number that is registered in the national single sign-on portal. f. Following initial set up, account fraud risk scoring should be established with restrictions placed on the account where applicable (e.g., reduced transaction value limit) until such time as the Member Organization validates that the customer is genuine through a combination of activities (e.g., use of biometric authentication mechanism through facial identification from national trusted party periodically, physical presence in a branch, regular pattern of account activity over a period of time). g. Member Organization should have process implemented to assure the recipient IBAN belongs to the loan requester. h. Implementing a process to ensure the ability to identify the source of inbound customer transactions. i. Implementing a process to allow accepting/rejecting inbound customer transactions that are not originating from the same customer for e-wallet card top-up and crowdfunding participation. Appendices Appendix A – Glossary Term Definition Access Management The process of granting authorised users the right to use a service, while preventing access to non-authorised users. Code of Conduct A defined set of expectations which outline principles, values, and behaviours that an organization considers important to its operations and success. Contractor An individual or organization under contract for the provision of services to an organization. Counter-Fraud Culture The shared values, beliefs, knowledge, attitudes and understanding about fraud risk within an organization. In a strong Counter-Fraud culture people proactively identify, discuss, and take responsibility for fraud risks. Counter-Fraud Governance A set of responsibilities and practices exercised by the Board, Executive and Senior Management with the goal of providing strategic direction for countering fraud, ensuring that Counter-Fraud objectives are achieved, ascertaining that fraud risks are managed appropriately and verifying that the enterprise's resources are used responsibly. Counter-Fraud Governance Committee (CFGC) A governance Structure owned by Senior Management with responsibility for oversight and control of all aspects of the organisational Counter-Fraud Programme. Counter-Fraud Policy A set of criteria for the provision of Counter-Fraud activities. It sets the commitment and objectives for Counter-Fraud and documents responsibilities. Counter-Fraud Programme A collection of strategy, policies, processes, guidelines, risk management approaches, actions, training, best practices, assurance, and technologies that are used to protect the Member Organization and its custo
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded