SAMA CSF implementation
Cybersecurity control implementation for supervised institutions.
SAMA CSF implementationCompliance service
Limaz turns IT governance expectations into decision rights, owners, and working routines, then builds the evidence that shows they operate — for SAMA-supervised institutions.
IT governance concerns who decides, on what basis, and with what oversight: technology strategy and its link to business objectives, portfolio and investment decisions, technology and third-party risk, resourcing and capability, performance measurement, and reporting to executive and board level.
The failure mode is familiar. Structures exist on paper, meetings happen, and nothing about how decisions get made actually changes. Evidence then has to be reconstructed under review.
01
Establish which governance expectations apply to your institution and where accountability sits today.
02
Identify how technology decisions are made today, by whom, and where accountability actually sits.
03
Structures, decision rights, escalation, and the reporting line to executive and board level.
04
Portfolio review, risk acceptance, exception handling, and performance reporting as routines people run.
05
Minutes, approvals, risk decisions, and reports tied to owners and produced as a by-product of operating.
06
Test whether the model holds under real decisions, then close the gaps as measurable work.
CSF asks whether controls are implemented and operating. ITGF asks whether the institution is governing technology well enough to keep them that way. Institutions that implement them separately usually build the evidence model twice.
Limaz implements both through the same delivery program so ownership, routines, and evidence are defined once.
Cybersecurity control implementation for supervised institutions.
SAMA CSF implementationControl and resilience expectations for payment operations.
SAMA payment systemsRisk routines that governance depends on.
Cybersecurity risk managementThe delivery program behind SAMA control implementation.
Cybersecurity and regulatory engineeringThe Saudi Central Bank sets expectations for how supervised institutions govern technology: structures, decision rights, oversight, and accountability.
ITGF is the common abbreviation for the IT Governance Framework issued by the Saudi Central Bank for the institutions it supervises.
CSF concerns cybersecurity controls. ITGF concerns how technology decisions are made, owned, and overseen — strategy, portfolio, risk, resourcing, and performance. They overlap in evidence and ownership, which is why the two are best implemented together.
It should not be. Governance that exists only in a committee charter does not survive review. The test is whether decisions are actually made, recorded, and traceable to named owners in normal operation.
Last reviewed: Sep 12, 2026
Tell us which system, control, or requirement you are working on. We’ll review the scope and suggest the next step.