Key Takeaways
- 68% of first SAMA self-assessments fail, mostly on evidence and governance, not on technical understanding of the framework
- Board-endorsed governance is the first thing SAMA checks, and its absence can sink a submission before controls are reviewed
- Identity and Access Management is the most cited finding in audits and requires continuous, not one-time, proof
- Third-party risk is a shared accountability problem; SAMA holds the licensed institution responsible regardless of where a breach originates
- Legacy infrastructure caps how much evidence collection can realistically be automated, which caps maturity scores
- Understaffed compliance teams turn correct controls into incomplete self-assessments simply due to lack of hands
- Governed AI Teammates, starting with a single function like GRC, can absorb the evidence and execution burden while humans keep final authority
More than two out of three Saudi financial institutions fail their first SAMA self-assessment submission. That is not a story about one missing control. It is a pattern that repeats across banks, fintechs, and insurers, and it shows up in the same handful of places every single time.
Saudi Arabia’s financial sector is scaling fast under Vision 2030, and the Saudi Central Bank’s Cyber Security Framework (SAMA CSF) is scaling its expectations right alongside it. The framework spans four domains: governance and oversight, cybersecurity operations, risk management, and third-party security, with maturity scored on a five-point scale and Level 3 required for most banks. Institutions submit annual self-assessments, and SAMA auditors validate them through evidence review, technical interviews, and sometimes on-site inspection.
The 68% Problem
More than two out of three Saudi financial institutions fail their first SAMA self-assessment — not on understanding the framework, but on proving it, in writing, continuously.
The failure rate is not about institutions ignoring the rules. It is about security teams that are stretched too thin to prove, continuously and in writing, that the rules are being followed. Below is the pattern behind that 68%, and what actually closes the gap.
The Real Pattern Behind SAMA Audit Failures
SAMA auditors are not looking for perfect security. They are looking for governed, evidenced, repeatable control. Institutions tend to fail in the same five places:
One Problem. Five Costumes.
Institutions tend to fail in the same five places, every time. Each looks separate. They’re actually one problem wearing five costumes: the work of proving control is growing faster than the people available to do it.
Execution capacity hasn’t kept pace with what SAMA expects teams to prove
On paper only
Board-endorsed governance exists in the document, not in practice — accountability still sits inside IT.
No continuous evidence
Identity and Access Management is implemented, but can’t produce ongoing, audit-ready proof.
Risk assumed
Vendor security is assumed rather than verified — SAMA holds the institution accountable regardless.
Legacy systems
Pre-modern identity tooling forces manual evidence collection, which caps maturity scores.
Understaffed
Two or three people trying to run 47 controls at once — correct controls, incomplete submissions.
- Governance exists on paper but is not board-owned in practice
- Identity and Access Management cannot produce continuous evidence
- Third-party risk is assumed rather than verified
- Legacy systems make evidence collection manual and slow
- Compliance teams are too small to run 47 controls at once
Each of these looks like a separate problem. They are actually one problem wearing five costumes: the work of proving control is growing faster than the people available to do it.
Governance Gaps That Auditors Catch First
SAMA’s framework starts with board-endorsed cybersecurity governance, and it is where most self-assessments unravel before the technical controls are even reviewed. Only a minority of Saudi banks currently have the board-level governance structure SAMA expects, which means cybersecurity budget, reporting cadence, and accountability often still sit inside IT rather than at the executive table. Without that governance foundation documented and evidenced, SAMA can reject a self-assessment outright, regardless of how strong the technical controls underneath it are.
The Identity and Access Management Trap
Proof, Not Just Policy
Access control is consistently the single most cited finding in SAMA audits. Most institutions can implement it. Very few can prove it continuously — and continuous proof is what the audit actually checks for.
Every privileged account inventoried
Not just the ones IT remembers
Entitlement reviews on a fixed 90-day cycle
Not run whenever someone has time
Failed login patterns analyzed
Not just logged
Evidence packaged, audit-ready year-round
Not assembled the week before submission
Third-Party Risk Nobody Owns
A large share of breaches at Saudi financial institutions trace back to a vendor, not an internal system. Yet many banks run vendor rosters in the hundreds without standardized security clauses in the contracts, without pre-engagement risk assessments, and without audit rights that would let them verify a vendor’s claims. SAMA holds the licensed institution accountable for that exposure regardless of whose infrastructure the breach happened on, which makes third-party risk one of the least visible and most expensive gaps to leave open.
Legacy Systems and the Evidence Problem
A majority of banks are still running infrastructure that predates modern identity tooling, which blocks the kind of automated access control SAMA now expects. The workaround is usually manual: spreadsheets for asset inventories, access reviews that eat weeks of analyst time every quarter, and logging that is too fragmented to demonstrate real event management. Manual evidence collection does not just slow teams down. It caps the maturity level an institution can realistically claim, because SAMA is assessing whether monitoring is continuous, not whether a control was configured once.
A Skills Shortage Compounding Everything
Saudi Arabia’s cybersecurity talent gap means most compliance functions run on two or three people trying to manage roughly 47 controls at once, while competing for hires against Aramco and NEOM. That staffing reality is a big part of why a large share of self-assessments come back incomplete rather than simply wrong. The controls are understood. There are not enough hands to execute and document them all before the deadline.
Why Point Tools and Manual Process Cannot Close This Gap
Most institutions responding to this pattern buy another dashboard, another scanner, or another compliance tracker. These tools are useful for visibility, but they mostly hand triage, evidence, and follow-through back to the same stretched team. A tool that flags a stale access review still needs a person to run the review. A tool that surfaces an unassessed vendor still needs a person to assess it. Point tools create another queue. Copilots stop at advice. Neither one closes an audit gap; they just relocate it.
Governed Defense, Powered by Offense.
No More Grunt Work. No More Burnout.
The gap in Saudi financial institutions is not a knowledge gap. It is an execution gap, and execution is exactly what Secure.com’s AI Teammates are built to close, inside the scope, permissions, and approvals the institution sets.
For SAMA readiness specifically, the GRC AI Teammate is the one to know. It owns:
Controls mapping and compliance posture tracking across all four SAMA domains
Continuous evidence collection instead of a scramble before submission
Audit readiness documentation that stays current, not a one-time snapshot
Trust reporting that gives the board and the CISO the same picture SAMA will see
That evidence discipline connects directly to the wider Attack, Harden, Prove, Repeat loop. A Red AI Teammate validates what is actually exploitable across identity, infrastructure, and payment systems — turning audit prep from guesswork into prioritized, evidence-backed remediation.
The teammate that attacks teaches the teammate that defends, and the GRC AI Teammate is what turns that evidence into an audit-ready record.
Your team still sets the rules. AI Teammates do the work.
Because a single teammate is built to be complete and valuable on its own, one function, done well, is enough to start.
FAQs
What is the SAMA Cyber Security Framework?
Why do so many institutions fail their first SAMA audit?
Why do so many institutions fail their first SAMA audit?
Which SAMA control causes the most audit findings?
How does third-party risk affect a SAMA audit outcome?
Conclusion
The 68% failure rate is not a sign that Saudi financial institutions do not understand SAMA. It is a sign that the work of proving compliance, quarter after quarter, control after control, has outgrown what a two or three person compliance team can execute manually. Governed AI Teammates change that equation by taking on the evidence, the reviews, and the reporting itself, inside the scope the institution sets, so the next self-assessment is built on a year of continuous proof instead of a scramble at the deadline.