Alqanoni

Regulatory Rules for Prepaid Payment Services in the Kingdom of Saudi Arabia

Para. 2.5.4
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

Funds transfers If the prepaid payment service allows the primary cardholder to transfer money to a bank account in the Kingdom of Saudi Arabia or abroad, the issuer must conduct the following precautionary measures: Obtain adequate levels of information about the beneficiary bank; and Assess whether the beneficiary bank’s anti-money laundering controls and risk management procedures are adequate; and Screen the beneficiary's bank account against available AML/CFT negative files. Consider all the relevant rules relating to remittances and follow Customer Due Diligence (CDD) processes with individual customers and with receiving banks (correspondent banks). 2.5.5 Face to face verification Further to the customer due diligence measures carried out at the onset of the contract (see 2.3 ), a further full verification must be carried out face-to- face whenever: a. There is a suspicion of money laundering or terrorist financing; b. There are doubts about the veracity or adequacy of the previously obtained primary cardholder identification data; c. Higher compliance risks are posed. The prepaid account must be blocked until full verification occurs if any of the above suspicions are raised. 2.5.6 SAMA Examination SAMA may conduct the following activities: a. Request the issuer to provide, detailed information about the transaction (e.g. primary cardholder’s identity, transactions history) upon request; b. Interview staff at the Issuer to investigate potential compliance issues; c. Conduct an inspection of the books and accounts of a bank, or affiliated third parties; d. Impose penalties to any issuer who fails to observe the primary cardholder due diligence and the transaction archiving requirements. 2.6 Data Protection Banks must ensure that card and account holder's confidentiality is maintained at all times and comply with the requirements of: a) " Rules Governing Anti-Money Laundering & Combating Terrorist Financing ", Section 4.10: "Record Keeping & Retention" and b) " Rules Governing the Opening of Bank Accounts & General Operational Guidelines in Saudi Arabia ", Part 2 "Supervisory Rules & Controls" Section 4: "Updating Account Data". In addition to the requirements described as follows: 2.6.1 Contracting entity (an individual or a juristic person or government entity) data collection The issuer is responsible for ensuring that the primary cardholder’s data is collected and processed, irrespective of other parties being involved in providing the service (refer to 1.2.1 ). 2.6.2 Contracting entity (an individual or a juristic person or government entity) data storage The issuer shall ensure that contracting entity (an individual or an organisation) personal data, either in electronic format or paper-based, collected during the contracting entity’s recruitment, as well as from the transactional activity of the payment device is stored in secured facilities within the Kingdom of Saudi Arabia (see " Rules on Outsourcing " issued by SAMA). The data storage facilities and the data transmission processes are considered secured if the issuer has taken the necessary technical and organisational measures to comply with the Payment Card Industry (PCI) standards as defined, to protect the data against: a) Accidental loss; b) Alteration, unauthorised disclosure or access; c) All other forms of unlawful processing.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.