Why the central bank cares about your suppliers
The Saudi Central Bank Cyber Security Framework (SAMA CSF) was issued in 2017 to set a common minimum for cybersecurity across the organisations SAMA supervises: banks, insurance and reinsurance companies, finance companies, credit bureaus and financial market infrastructure. The framework measures maturity on a scale of levels and expects each regulated organisation to reach a defined level and hold it.
The framework rests on a simple idea: risk does not stop at your network boundary. Your cloud provider, your support contractor, your application developer and your payment-card supplier all touch your data or your systems to some degree. A breach at any of them is your breach in the eyes of your customers and your regulator. That is why the framework dedicates an entire main domain to third-party cybersecurity, alongside leadership and governance, risk management and compliance, and operations and technology.
What the third-party domain asks for
The domain covers three areas: contract and vendor management, outsourcing, and cloud computing. The common message is that the regulated organisation remains accountable for information security even when the service runs elsewhere. For control numbers and detailed requirements, refer to the current version of the framework and to SAMA's separate instructions on outsourcing, since both are updated.
In practice this means you hold:
- A complete register of third parties, classified by the sensitivity of what they can reach.
- A cyber risk assessment before contracting and a periodic reassessment after it.
- Security requirements written into the contract, not into an email.
- A right to audit and review, and a channel for incident reporting.
- An exit plan that provides for the return and destruction of your data when the relationship ends.
What to ask a vendor
A good questionnaire is short and asks for evidence, not yes-or-no answers. The questions that separate a mature vendor from the rest:
- Which certifications or independent reports do you hold, such as ISO 27001 or independent assurance reports, what is their scope, who issued them and when do they expire?
- Where is our data actually stored and processed, and does it leave the Kingdom at any stage, including backups and technical support?
- How do you manage access to our systems: who has it, with what authentication, and how is it reviewed and revoked?
- What is your vulnerability management process, and how long do critical vulnerabilities take to fix?
- How will you notify us of an incident affecting our data, within what period, and through whom?
- Which subcontractors reach our data, and will you tell us before changing them?
- What is your business continuity plan and when was it last tested?
Ask for evidence with every answer: a copy of the certificate, a report summary, a configuration screenshot. A vendor that refuses to provide evidence is telling you something important.
Contract clauses you cannot skip
- Binding security requirements, referencing the SAMA framework as the standard.
- Incident notification within an agreed period, short enough for you to meet your own obligations to the regulator.
- A right to audit, yourselves or through an independent party, and a right to see the results of the vendor's own audits.
- Data location and transfer restrictions, with your consent required for any change.
- Subcontracting: prior approval or notification, and flow-down of the same obligations to the subcontractor.
- Exit: data returned in a usable format, documented destruction, and a transition period.
- Personal data handled in line with the Personal Data Protection Law (PDPL), because your obligations there are independent of the SAMA framework.
Continuous monitoring after signature
A pre-contract assessment describes a single moment. Vendors change their architecture, their staff and their own suppliers, and new vulnerabilities appear every week. Continuous monitoring means:
- Reassessing periodically according to risk tier, and on any material change.
- Tracking certificate expiry and renewal.
- Reviewing the access the vendor holds on your systems at regular intervals.
- Treating incidents and service-level failures as indicators of declining maturity.
- Recording all of the above in one place you can show an auditor or the regulator on request.
How DataSec helps
Our third-party risk service starts by listing and classifying your suppliers, then assesses them against the SAMA framework and the NCA Essential Cybersecurity Controls (ECC), with a remediation plan for each. The governance, risk and compliance (GRC) platform we work on keeps questionnaires, evidence, contracts and expiry dates in one register, alerts you when a reassessment is due, and produces review-ready reports.
Beyond that, our GRC advisory service drafts the policies and model contract clauses, and our compliance assessment measures your position against the whole framework, not only the third-party domain.
Illustrative example: an insurer with thirty technology suppliers found that three reached customer data directly. After classification, the deep assessment effort concentrated on those three and the rest received a short annual questionnaire. The result was better coverage with less effort, and one register that answers an auditor's question without a search through email.
This article is general awareness content, not legal advice. Refer to the current version of the regulations and frameworks mentioned.
All articles
