Skip to content
Limaz

Compliance service

Make SAMA IT governance operational.

Limaz turns IT governance expectations into decision rights, owners, and working routines, then builds the evidence that shows they operate — for SAMA-supervised institutions.

What Limaz delivers

  • ITGF readiness and gap assessment
  • Governance structures, decision rights, and accountable owners
  • Technology risk, portfolio, and performance routines that actually run
  • Policy and process changes implemented, not just drafted
  • Evidence model, validation, and reporting for supervisory review

What IT governance expectations cover

IT governance concerns who decides, on what basis, and with what oversight: technology strategy and its link to business objectives, portfolio and investment decisions, technology and third-party risk, resourcing and capability, performance measurement, and reporting to executive and board level.

The failure mode is familiar. Structures exist on paper, meetings happen, and nothing about how decisions get made actually changes. Evidence then has to be reconstructed under review.

How Limaz implements ITGF

  1. 01

    Scope the requirement

    Establish which governance expectations apply to your institution and where accountability sits today.

  2. 02

    Map decisions, not documents

    Identify how technology decisions are made today, by whom, and where accountability actually sits.

  3. 03

    Design the governance model

    Structures, decision rights, escalation, and the reporting line to executive and board level.

  4. 04

    Rebuild the routines

    Portfolio review, risk acceptance, exception handling, and performance reporting as routines people run.

  5. 05

    Connect evidence

    Minutes, approvals, risk decisions, and reports tied to owners and produced as a by-product of operating.

  6. 06

    Validate and remediate

    Test whether the model holds under real decisions, then close the gaps as measurable work.

Common implementation gaps

  • Committees exist but decisions are made elsewhere.
  • Risk acceptance has no owner, expiry, or review.
  • Technology strategy is not traceable to portfolio decisions.
  • Third-party dependencies are governed by contract only.
  • Board reporting describes activity rather than risk and outcomes.
  • Evidence is reconstructed for review instead of produced by operating.

Where this sits alongside SAMA CSF

CSF asks whether controls are implemented and operating. ITGF asks whether the institution is governing technology well enough to keep them that way. Institutions that implement them separately usually build the evidence model twice.

Limaz implements both through the same delivery program so ownership, routines, and evidence are defined once.

Related Limaz pages

Questions

  • The Saudi Central Bank sets expectations for how supervised institutions govern technology: structures, decision rights, oversight, and accountability.

Last reviewed: Sep 12, 2026

Discuss your requirements with Limaz

Tell us which system, control, or requirement you are working on. We’ll review the scope and suggest the next step.