Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SAMA Business Continuity Management Framework explained

SAMA Business Continuity Management Framework: 9 Principles (2026)

The SAMA Business Continuity Management Framework is the Saudi Central Bank’s set of mandatory requirements for how a financial institution keeps its critical services running through a disruption and recovers when it cannot — issued under Circular 381000058504 of 27 February 2017, recorded In-Force in the SAMA Rulebook, and applicable to all Member Organizations, all banks operating in Saudi Arabia, banking subsidiaries of Saudi banks and subsidiaries of foreign banks in the Kingdom.

It is built, by SAMA’s own account, on ISO 22301, ISO 27001, the BCI Good Practice Guidelines and the DRII Professional Practices, and it is structured as nine principles — governance, strategy, policy, business impact analysis and risk assessment, the business continuity plan, the IT disaster recovery plan, cyber resilience, the crisis management plan and testing — each with an objective and numbered control considerations.

Some of the considerations are specific enough to fail on their own: a BCM committee meeting at least quarterly, an alternative data centre whose location is approved by SAMA, BCP simulation tests and DR tests at least once a year. This guide sets out the nine principles of the SAMA Business Continuity Management Framework as SAMA writes them, the control considerations that decide most findings, how the Framework relates to the Cyber Security and IT Governance Frameworks and to ISO 22301, and how to build the programme in the order the Framework’s dependencies dictate.

The SAMA Business Continuity Management Framework: nine principles
2.1 BCM Governance · 2.2 BCM Strategy · 2.3 BC Policy · 2.4 BIA and Risk Assessment · 2.5 Business Continuity Plan · 2.6 IT Disaster Recovery Plan · 2.7 Cyber Resilience · 2.8 Crisis Management Plan · 2.9 Testing — BCP and DR tests at least once a year · Circular 381000058504, 27 Feb 2017.

What the SAMA Business Continuity Management Framework is, and who it binds

Section 1.1 states the purpose: 24 × 7 availability of business operations is expected of financial institutions in the Kingdom, and the Framework is to enhance organisational resilience so that operations and services stay continuous and available. Section 1.3 defines its scope as principles, objectives and control considerations for business continuity, and section 1.4 the applicability set out above. Section 1.5 mandates it: SAMA owns and updates the document, and Member Organizations adopt and implement it.

The target audience in 1.7 runs from the board and CEO through the CRO, CIO and CISO to business continuity managers and internal auditors — a signal that SAMA expects the programme to be governed, not delegated. Our guide to SAMA compliance covers the Cyber Security Framework issued three months later, which the BCM Framework’s cyber resilience principle points at.

The nine principles of the SAMA Business Continuity Management Framework

Principle What it requires Control considerations that decide findings
2.1 BCM Governance A business continuity governance framework defined, approved, implemented and maintained, monitored by senior management, with the structure communicated to employees and third parties The board or a delegated executive holds ultimate responsibility and allocates budget; a BCM committee mandated by the board with CRO, COO, CIO, CISO and the BCM manager represented and a charter with quarterly minimum meetings; a BCM function with an appointed, qualified BCM manager and adequate staff
2.2 BCM Strategy A business continuity strategy aligned with the organisation’s strategic business objectives Strategy approved and embedding BCM as part of management practice
2.3 Business Continuity Policy A policy defined, approved and communicated to relevant stakeholders Documents the commitment and objectives of the programme
2.4 Business Impact Analysis and Risk Assessment A BIA and risk assessment for all relevant activities to determine continuity and DR requirements A defined methodology; periodic risk assessment identifying internal and external threats including single points of failure across people, process, technology and premises; prioritisation of processes and dependencies
2.5 Business Continuity Plan A BCP for critical activities, defined, approved, implemented and maintained; compliance monitored and effectiveness measured Procedures covering key resources, roles and authorities, immediate-consequence management and escalation, continuity within RTO, RPO and MAO, resumption to business as usual, and communication with employees, third parties and stakeholders
2.6 IT Disaster Recovery Plan An IT DRP for critical activities and their technology infrastructure, aligned with the BIA An alternative data centre at a location chosen by risk assessment so it does not share the main site’s risks and approved by SAMA; configurations and capacity commensurate with the main data centre; the same logical, physical, environmental and cyber security controls; a backup and recovery process with offsite storage; formal third-party contracts
2.7 Cyber Resilience Critical services, functions and processes run on reliable, robust infrastructure and software In-depth risk assessment and strict development, testing and change management for changes to critical infrastructure; a periodic architectural review; further resilience controls referred to the Cyber Security Framework
2.8 Crisis Management Plan A crisis management plan for a well-managed response to major incidents, including rapid communication for the safety of internal and external stakeholders Criteria for declaring a crisis; a command centre and an emergency command centre; a crisis management team with communications represented; contact details including third parties; defined steps; compliance monitored and effectiveness measured
2.9 Testing Regular BCP and DRP tests, defined, approved, implemented, executed and monitored, to train employees and third parties and prove the plans BCP simulation tests at least once a year with well-planned scenarios including cyber security and crisis-team activation, and an integrated test across critical services; a DR test combined with the BCP at least once a year, evaluated for readiness; detailed documented results with objectives met, resource readiness, lessons learnt and, on failure, root causes

SAMA Business Continuity Management Framework: the control considerations that decide most findings

  1. The quarterly committee. A BCM committee whose charter does not set a quarterly minimum, or whose minutes do not show it, fails 2.1 on the face of the document.
  2. The SAMA-approved alternative data centre. 2.6 requires the location to be selected by risk assessment and approved by SAMA, and to be commensurate in configuration, capacity and controls — a secondary site that shares the primary’s geographical risk, or that runs a reduced configuration, is a finding whatever the DR test shows.
  3. RTO, RPO and MAO in the plan. 2.5 requires the process to continue critical activities within predetermined recovery objectives; a BCP without the three figures per activity, derived from the BIA, has no target to test against.
  4. Annual tests with cyber scenarios. 2.9 sets “at least once a year” for BCP simulations and DR tests, requires cyber security scenarios to be considered, and requires crisis-team activation in the scenarios. A DR test that restores systems without invoking the crisis management team tests half the Framework.
  5. Documented results with root causes. 2.9.3 requires detailed results: objectives met, readiness confirmed, lessons learnt, and on failure the root causes and corrective actions. The test report is the evidence SAMA reads.

How the SAMA BCM Framework relates to the other frameworks

Relationship How the Framework handles it
Cyber Security Framework (May 2017) Principle 2.7 covers resilience of critical infrastructure and refers further resilience controls — threat management, vulnerability management and others — to the Cyber Security Framework; the CSF in turn requires cyber security incident management aligned with enterprise incident management
IT Governance Framework (November 2021) To be implemented in conjunction with the BCM Framework; its data backup and recoverability (3.3.10), IT incident (3.3.8) and availability and capacity (3.3.4) subdomains are the operational side of the DRP
Cyber Resilience Fundamental Requirements (2022) The licensing-stage minimum for fintechs and sandbox entities includes a Resilience domain built from BCM principles 2.5, 2.6 and 2.7; full BCM Framework compliance applies after licensing
ISO 22301 Named in 1.1 as a source. The Framework’s principles map to ISO 22301’s clauses — policy (5.2), BIA and risk assessment (8.2), strategies (8.3), plans and procedures (8.4), exercise programme (8.5) — but SAMA’s control considerations are more specific (committee frequency, SAMA-approved DR site, annual tests) and are mandatory rather than certifiable
Rules on Outsourcing Third parties in critical activities appear in 2.5 communications, 2.6 formal contracts and 2.9 test participation

Our guides to the SAMA IT Governance Framework and SAMA outsourcing cover the two neighbours; the SAMA CSF domains covers where the cyber controls that 2.7 points at live.

Building the programme in dependency order

  1. Governance first (2.1–2.3). Board accountability, budget, the committee and its charter, the BCM function and manager, the strategy and the policy — because every later principle requires approval by a body that has to exist.
  2. BIA and risk assessment (2.4). The methodology, then the analysis: critical activities, dependencies across people, process, technology and premises, single points of failure, and the RTO, RPO and MAO per activity that the plans will inherit.
  3. The three plans (2.5, 2.6, 2.8). The BCP with its procedures, the IT DRP with the alternative data centre and backup process, and the crisis management plan with its declaration criteria, command centres and team — written to the BIA’s objectives and cross-referenced.
  4. Cyber resilience (2.7). Change control and architectural review for critical infrastructure, linked to the Cyber Security Framework’s threat and vulnerability management.
  5. Testing (2.9). The annual BCP simulation with cyber scenarios and crisis-team activation, the annual DR test combined with the BCP, the integrated test across critical services, and the documented results with root causes.
  6. Measure and report. 2.5 and 2.8 require compliance monitored and effectiveness measured; the committee’s quarterly agenda is where the measures are reported.

Frequently asked questions

What is the SAMA Business Continuity Management Framework?
The Saudi Central Bank’s mandatory business continuity requirements, issued under Circular 381000058504 on 27 February 2017: nine principles — governance, strategy, policy, BIA and risk assessment, BCP, IT DRP, cyber resilience, crisis management and testing — each with an objective and control considerations, built on ISO 22301, ISO 27001, BCI and DRII practice.

Who must comply?
All organisations affiliated with SAMA, all banks operating in Saudi Arabia, banking subsidiaries of Saudi banks and subsidiaries of foreign banks in the Kingdom; the Rulebook records the scope of application as the banking sector, finance sector, payment systems and PSPs, and credit bureaus.

How often must plans be tested?
Principle 2.9: BCP simulation tests at least once a year, with cyber security scenarios considered and crisis-team activation included, and a DR test combined with the BCP at least once a year; results are documented with lessons learnt and root causes of any failure.

Does SAMA have to approve the disaster recovery site?
Yes. Principle 2.6 requires the alternative data centre’s location to be chosen by a risk assessment showing it does not share the main site’s risks, and approved by SAMA, with configuration, capacity and security controls commensurate with the main data centre.

Is ISO 22301 certification enough?
No. SAMA names ISO 22301 as a source, but its control considerations — quarterly committee, SAMA-approved DR site, RTO/RPO/MAO in the plan, annual tests with cyber scenarios — are more specific than the standard and are assessed by SAMA, not by a certification body.

Where this leaves you

Build the SAMA Business Continuity Management Framework in the order its nine principles depend on each other — governance, strategy and policy; BIA and risk assessment with RTO, RPO and MAO; the BCP, the IT DRP with a SAMA-approved alternative data centre, and the crisis management plan; cyber resilience through change control; and annual tests with cyber scenarios and documented root causes — because SAMA’s control considerations are specific enough to be checked line by line, and the committee minutes, the DR-site approval and the test reports are what the review reads.

References

More on SAMA

The BCM committee charter, the BIA and risk assessment methodology, the business continuity, IT disaster recovery and crisis management plan templates and the annual test and exercise records are in the SAMA Compliance Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.