There is no single rulebook for finance. Financial services compliance is a patchwork determined by what you do and where you do it — a bank in Riyadh, a European crypto exchange and a lender calculating capital ratios are all regulated, but by regimes that share almost nothing. This guide sets out three that come up repeatedly, what each is actually asking for, and how to tell which applies to you.
If your concern is operational resilience specifically, start with our DORA requirements guide — that regime sits alongside all three below.
Three regimes at a glance
| Applies to | Question it asks | How it is enforced | |
|---|---|---|---|
| Basel III | Banks, internationally | Are you financially resilient? | Supervisory review of capital and liquidity |
| SAMA CSF | Saudi financial institutions | Are you cyber resilient? | Supervised maturity assessment |
| MiCA | Crypto-asset firms in the EU | Are you authorised to operate? | Authorisation and ongoing obligations |
Basel III: capital, leverage and liquidity
Basel III is prudential rather than operational. Published by the Basel Committee and implemented through national regulators, it governs how much capital a bank holds against its risk-weighted assets, how much leverage it may run, and whether it can survive a liquidity squeeze.
The documentation burden is heavier than people expect, because supervisors assess the governance around the numbers as well as the numbers themselves. Our Basel III Prudential Risk Toolkit covers that layer with 25 templates — capital management policy, RWA calculation standard, capital planning and forecasting, the ICAAP and ILAAP documents, interest rate risk in the banking book, large exposures and the governance charter that ties them together.
SAMA Cyber Security Framework: Saudi Arabia
The Saudi Central Bank requires its regulated institutions — banks, insurers, financing companies — to comply with its Cyber Security Framework. What makes SAMA distinctive is the assessment model: it is scored on maturity, and the regulator reviews the score, so the target is a maturity level rather than a pass mark.
That makes evidence of governance as important as the controls themselves. Our SAMA Compliance Toolkit provides 38 templates across the framework’s domains, including the cybersecurity framework compliance policy, information security and access control policies, the business continuity and IT governance frameworks, outsourcing and cloud computing policies, and the counter-fraud framework.
Firms operating across the Gulf often face the Saudi framework alongside the UAE and regional equivalents — our guide to the NCA Essential Cybersecurity Controls covers the neighbouring regime.
MiCA: crypto-assets in the European Union
MiCA — Regulation (EU) 2023/1114 — brought crypto-asset service providers inside the regulatory perimeter for the first time. It is an authorisation regime: you apply, you are approved, and then you carry ongoing obligations around disclosure, custody, conflicts of interest and complaints.
It also distinguishes sharply between token types. Asset-referenced tokens and e-money tokens carry issuer obligations, including a published white paper, that ordinary crypto-assets do not. Our MiCA Toolkit is the largest of the three at 100+ templates, covering CASP authorisation, ART and EMT issuer procedures and white paper templates, custody and safekeeping, the AML interface including the crypto travel rule, and the advice and portfolio management procedures for firms offering those services.
Working out which applies
Start with three questions. Are you a bank taking deposits and lending? Basel III, through your national regulator. Are you a financial institution supervised in Saudi Arabia? The SAMA framework, regardless of what else you hold. Do you issue crypto-assets or provide crypto services to EU customers? MiCA, whether or not you are established in the EU.
These stack rather than substitute. A European bank offering crypto custody faces Basel III for capital, MiCA for the crypto business and DORA for operational resilience simultaneously — which is why documentation that maps controls once and reuses the evidence is worth more than three separate programmes.
Frequently asked questions
Does Basel III apply to non-banks?
Not directly. It is written for banks and implemented through banking regulators, though investment firms often face closely related capital requirements under separate national or regional rules.
Is the SAMA Cyber Security Framework a certification?
No. It is assessed on a maturity scale and reviewed by the regulator, so the outcome is a supervised maturity rating rather than a certificate you can show a customer.
Does MiCA apply to firms outside the EU?
It applies where crypto-asset services are provided to customers in the EU, so non-EU firms serving EU clients generally fall in scope and need authorisation through a member state.