SAMA CSF implementation
Cybersecurity expectations across SAMA-supervised institutions.
SAMA CSF implementationCompliance service
Limaz maps applicable payment-system expectations to real systems and owners, implements the control and process changes, and builds the evidence model for SAMA-supervised payment operations.
The Saudi Central Bank oversees payment systems and their operators under the Oversight Framework of the Payment Systems and Their Operators, issued in March 2026 to replace the 2021 Oversight Framework for Payments and Financial Settlement Systems. Organisations that were scoped against the old text should re-check their position against the new one.
Payment-system expectations concern how a payment service is operated and controlled: authorization and settlement flows, availability and resilience, change and incident handling, third-party and outsourcing arrangements, customer protection, and the records that evidence all of it.
Implementation is engineering work, not a document exercise. It needs a target control set, named owners, changes in systems and processes, and current evidence a reviewer can follow.
01
Establish which expectations apply to your licence and payment activities, and which systems carry them.
02
Trace authorization, clearing, settlement, reconciliation, and exception paths across the systems that actually carry them.
03
Control architecture, decision rights, resilience objectives, and what must change in process and technology.
04
An implementation backlog with owners, dependencies, priorities, and acceptance criteria.
05
Logs, approvals, test results, and reconciliation artefacts tied to owners so reviews do not start from zero.
06
Prove operation under real conditions, then close residual risk as measurable work.
Payment operations generate exactly the decisions Naiza is built for: screening, transaction monitoring, and review workflow at the point money moves. Naiza covers that slice.
The surrounding governance, resilience, and evidence work is implementation, and Limaz delivers it through cybersecurity and regulatory engineering. Do not treat either as a substitute for the other.
Cybersecurity expectations across SAMA-supervised institutions.
SAMA CSF implementationDecision rights and oversight for technology in supervised institutions.
SAMA IT governance frameworkFraud and AML decisioning where money actually moves.
Naiza by LimazThe implementation program around screening, monitoring, and decisioning.
Financial crime technologyThe Saudi Central Bank oversees payment systems and their operators through its Oversight Framework of the Payment Systems and Their Operators, issued in March 2026 to replace the earlier Oversight Framework for Payments and Financial Settlement Systems.
Applicability depends on SAMA supervision, licence category, and the payment activities actually performed. A fintech is not automatically in or out of scope.
SAMA CSF sets cybersecurity expectations across supervised institutions. Payment-system expectations concern the operation, resilience, and control of payment services themselves. Many providers must address both, and the evidence model should be built once rather than twice.
No. Fraud and AML decisioning is one control area inside a broader operating model. A detection platform does not satisfy governance, resilience, or oversight expectations on its own.
Last reviewed: Sep 12, 2026
Tell us which system, control, or requirement you are working on. We’ll review the scope and suggest the next step.