Skip to content
Limaz

Compliance service

Assess and implement SAMA CSF controls.

Limaz assesses readiness, maps applicable controls, designs remediation, supports implementation, builds the evidence model, and validates progress for SAMA-supervised organizations.

What Limaz delivers

  • SAMA CSF readiness and gap assessment
  • Control applicability, ownership, and target-state mapping
  • Risk-prioritized implementation and remediation roadmap
  • Hands-on process and technical control implementation
  • Evidence model, validation, and progress reporting

What the SAMA Cyber Security Framework is

The SAMA Cyber Security Framework sets cybersecurity expectations for institutions supervised by the Saudi Central Bank. Implementation requires a target control set, named owners, technical and process changes, and current evidence for review.

How Limaz implements SAMA CSF

  1. 01

    Scope the requirement

    Establish which controls apply to your licence and activities, and which systems and owners they land on.

  2. 02

    Map the current state

    Review the policies, systems, owners, evidence, and gaps that exist today.

  3. 03

    Design the target

    Control architecture, decision rights, and what must change in process and technology.

  4. 04

    Sequence the work

    Create an implementation backlog with owners, dependencies, priorities, and acceptance criteria.

  5. 05

    Connect evidence

    Logs, approvals, tests, and artefacts tied to owners so reviews do not start from zero.

  6. 06

    Validate and remediate

    Prove operation, then close residual risk as measurable work.

Common implementation gaps

  • Policies exist without implemented technical or process controls.
  • Owners are named in documents but not in operating routines.
  • Evidence is assembled for a review week, then decays.
  • Remediation lists are not sequenced as engineering work.
  • Third-party access sits outside the control model.
  • Fraud and AML tooling is disconnected from the cybersecurity control set.

Where Naiza and Limaz solutions fit

SAMA CSF is broader than financial crime. Limaz implements the control program through cybersecurity and regulatory engineering. Where fraud, AML, screening, and decisioning need a product layer, Naiza by Limaz is used only in that slice.

Do not treat a fraud platform as a substitute for SAMA CSF implementation, and do not treat a policy pack as a substitute for either.

Related Limaz pages

Naiza by Limaz

Fraud and AML decisioning where it belongs in the operating model.

Naiza by Limaz

Questions

  • The Saudi Central Bank publishes the SAMA Cyber Security Framework for supervised financial institutions.

Last reviewed: Sep 12, 2026

Discuss your requirements with Limaz

Tell us which system, control, or requirement you are working on. We’ll review the scope and suggest the next step.