Alqanoni

New Banking Products and Services Regulation

Para. 6.2.6
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

Compliance with all applicable rules and regulations issued by SAMA and all other relevant regulators when developing a new product and service as well as any subsequent updates to the rules and regulations. Examples of such rules and regulations (but not limited to): a. Responsible Lending Principle for Individual Customers (issued in 2018) . b. Financial Consumer Protection Principles and Rules (issued in 2022) . c. Rules for Advertising Products and Services Provided by Financial Institutions (issued in 2023) . d. Debt Collection Regulations and Procedures for Individual Customers (issued in 2018) .* e. SAMA Cyber security Framework (issued in 2017) . f. SAMA Counter-Fraud Framework (issued in 2022) . g. SAMA Business Continuity Management Framework (issued in 2017) . h. Information Technology Governance Framework (issued in 2021) . i. Rules related to touch\face ID, Tahaqaq requirements, digital signature, national and global payment requirements for MADA, Visa, MasterCard, Face recognition. *These regulations have been replaced by the updated Debt Collection Regulations and Procedures in accordance with circular No. (106889333), dated 06/09/1446H, corresponding to 05/03/2025G. 6.3 Products and Services Risk Assessments 6.3.1 Banks must establish lines of responsibility for managing risks related to new products and services. 6.3.2 Banks must conduct a full risk assessment of new products and services which form the basis on whether or not to introduce them to the market taking into account reviewing all the associated risk throughout the life cycle of the products and services. 6.3.3 Banks must have risk management standards for developing and launching any new products and services to the market. These include, inter alia, adequate due diligence and approvals, procedures to identify, measure, monitor, report, and mitigate risks, effective change management processes and technologies, ongoing performance monitoring and review mechanisms. 6.3.4 Banks must have risk classification process for each product and service that the bank intend to launch. The classification process must result with an overall risk classification for the product or service (for example: high, medium or low risk). 6.3.5 Banks must have a risk management, controls and monitoring processes in respect of third party risks management, where the bank’s products and services are offered in partnership with Fintech companies, agents or similar entities. 6.3.6 The risk management function must have internal organizational and operational capacity i.e. effective controls, monitoring and reporting systems and procedures in place, to monitor and manage potential risks of the proposed new products and services poses to the bank's own financial health, as well as to the financial well-being of the customers and overall market stability. 6.3.7 The risk management function must document, review and approve risk profile (associated risks) of new products and services before its launch. Risk profile of the new products and services must include at least detailed description of all associated risks i.e. identification, quantification (if possible), assessment, classification and its mitigation plan.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.