Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SAMA IT Governance Framework explained

SAMA IT Governance Framework: All 35 Subdomains Explained (2026)

The SAMA IT Governance Framework is the third of the Saudi Central Bank’s control frameworks, issued under Circular 43028139 of 4 November 2021 and recorded In-Force in the SAMA Rulebook with a scope of application covering the banking sector and credit bureaus. It exists because the Cyber Security Framework of 2017 governs the protection of information assets and the Business Continuity Management Framework of 2017 governs their recovery, and neither governs how IT itself is run — strategy, architecture, risk, operations and change.

The Framework fills that gap with four domains — Information Technology Governance and Leadership, IT Risk Management, IT Operations Management and System Change Management — 35 subdomains, each with a principle and numbered control requirements, and the same 0-to-5 maturity model, self-assessment questionnaire and SAMA review that the Cyber Security Framework uses. This guide sets out every subdomain in the SAMA IT Governance Framework as SAMA names it, explains how it interlocks with the other two frameworks, describes the maturity model and the assessment, and lays out how to implement it in a bank that already runs the Cyber Security Framework.

The SAMA IT Governance Framework: four domains, 35 subdomains
3.1 IT Governance and Leadership (9) · 3.2 IT Risk Management (4) · 3.3 IT Operations Management (11) · 3.4 System Change Management (11) · principle + control requirements per subdomain · maturity 0–5 · self-assessment reviewed and audited by SAMA · to be implemented with the Cyber Security and BCM Frameworks.

What the SAMA IT Governance Framework is for

Section 1.1 states the objectives: a common approach to addressing IT risks across Member Organizations, an appropriate IT governance maturity level, and IT that supports the business securely and reliably. Section 1.3 sets the scope — principles and objectives for initiating, implementing, maintaining, monitoring and improving IT governance controls over the Member Organization’s information assets, extending to subsidiaries, staff, third parties and customers — and says the Framework should be implemented in conjunction with the Cyber Security Framework and the Business Continuity Management Framework, with a figure showing the three as interlocking.

Section 1.4 applies it to Member Organizations regulated by SAMA; the Rulebook records the sector scope as banking and credit bureaus. Our guide to SAMA compliance covers the Cyber Security Framework the IT Governance Framework is designed to sit beside.

Domain 3.1: Information Technology Governance and Leadership

Subdomain Title What the principle and control requirements ask for
3.1.1 Information Technology Governance An IT Steering Committee mandated by the board, headed by the senior manager responsible for operations, with the CIO, CRO, CISO, compliance and business heads represented and internal audit as observer; a charter with objectives, roles, quorum and meeting frequency
3.1.2 Information Technology Strategy An IT strategy aligned with strategic objectives and legal and regulatory requirements, translated into a roadmap
3.1.3 Manage Enterprise Architecture Enterprise architecture defining the business process, data and technology layers
3.1.4 Information Technology Policy and Procedures IT policy, standards and procedures defined, approved, communicated and reviewed
3.1.5 Roles and Responsibilities IT roles and responsibilities defined, with the board accountable for establishing IT governance
3.1.6 Regulatory Compliance Relevant regulations including data privacy identified, communicated and complied with through a compliance process
3.1.7 Internal IT Audit IT audits to generally accepted auditing standards and SAMA frameworks, on an audit cycle, with a plan approved by the audit committee and a follow-up process
3.1.8 Staff Competence and Training Staff equipped with the skills and training to operate information assets and apply IT controls
3.1.9 Performance Management Efficiency and effectiveness of IT measured with KPIs and reported

Domain 3.2: IT Risk Management

Subdomain Title What the principle and control requirements ask for
3.2.1 Managing IT Risks An IT risk management process defined, approved, implemented, communicated and aligned to enterprise risk management, covering identification, analysis and classification, treatment, reporting, and monitoring and profiling; effectiveness measured
3.2.2 Risk Identification and Analysis Information assets identified and recorded; threats, existing controls and risks analysed by likelihood and impact
3.2.3 Risk Treatment Risks treated by the applicable criteria — accepted, avoided, transferred or mitigated — under an approved treatment plan
3.2.4 Risk Reporting, Monitoring and Profiling Assessment results documented and reported to business owners and senior management; treatment plans reviewed and monitored

Domain 3.3: IT Operations Management

Subdomain Title What the principle and control requirements ask for
3.3.1 Manage Assets An asset management process maintaining an accurate and up-to-date inventory of information assets
3.3.2 Interdependencies Interdependencies of critical information assets identified and managed through a governance model with stakeholders such as service providers
3.3.3 Manage Service Level Agreements Contractual terms with internal stakeholders and third parties formally agreed and controlled, including internal IT service level agreements
3.3.4 IT Availability and Capacity Management Availability maintained by monitoring system thresholds and predicting performance and capacity requirements
3.3.5 Manage Data Center Physical and environmental controls protecting IT facilities and equipment from damage and unauthorised access, monitored
3.3.6 Network Architecture and Monitoring A network architecture policy and IT event management controls that continuously monitor operations against unauthorised access
3.3.7 Batch Processing A batch management process for bulk automated tasks, with effectiveness measured
3.3.8 IT Incident Management An IT incident management process to identify, respond to and handle incidents and report relevant incidents to SAMA under a defined communication protocol
3.3.9 Problem Management Criteria and procedures for reporting problems to limit recurring incidents
3.3.10 Data Backup and Recoverability A backup management strategy with backup and restoration procedures for reliability, availability and recoverability
3.3.11 Virtualization A formal process for creation, distribution, storage, use and retirement of virtual images, snapshots and containers, with the same security as non-virtual environments and minimum baseline security standards

Domain 3.4: System Change Management

Subdomain Title What the principle and control requirements ask for
3.4.1 System Change Governance A change management process ensuring changes are classified, tested and approved before production
3.4.2 Change Requirement Definition and Approval Change requirements formally initiated, specifying functional and non-functional needs, and approved by the asset owner
3.4.3 System Acquisition A system acquisition process assessing and mitigating acquisition and vendor service-level risks before acquiring
3.4.4 System Development A documented, approved system development methodology
3.4.5 Testing All changes comprehensively tested in a test environment against approved test cases to find defects and vulnerabilities before release
3.4.6 Change Security Requirements Cyber security requirements defined and tested for every change in a test environment before production
3.4.7 Change Release Management A release management process so changes are planned and released to production in a strictly controlled manner
3.4.8 System Configuration Management A configuration management process maintaining reliable, accurate information about configuration items
3.4.9 Patch Management A patch management process: impact assessment including cyber security before production, periodic scanning for outdated patches, formal deployment, effectiveness measured
3.4.10 IT Project Management A formal process to manage IT projects and their risks through the project life cycle
3.4.11 Quality Assurance A quality assurance process independently ascertaining the quality of changes and developments before production

SAMA IT Governance Framework maturity and assessment

Section 2.3 subjects implementation to periodic self-assessment on a questionnaire, reviewed and audited by SAMA to determine compliance and the IT governance maturity level. Section 2.4’s model has the same six levels as the Cyber Security Framework — 0 non-existent, 1 ad-hoc, 2 repeatable but informal, 3 structured and formalized, 4 managed and measurable, 5 adaptive — and is cumulative: levels 3, 4 and 5 require every criterion of the preceding levels. The recurring control requirement across the subdomains — defined, approved, implemented and communicated, with effectiveness measured and periodically evaluated — is the level 3 and level 4 test written into each principle.

How the three SAMA frameworks interlock

Topic IT Governance Framework (2021) Cyber Security Framework (2017) BCM Framework (2017)
Governance body IT Steering Committee (3.1.1) Cyber security committee (3.1.1) BCM governance (2.1)
Risk IT risk management (3.2) Cyber security risk management (3.2.1) BIA and risk assessment (2.4)
Incidents IT incident management (3.3.8) Cyber security incident management (3.3.15) Crisis management plan (2.8)
Backup and recovery Data backup and recoverability (3.3.10) IT disaster recovery plan (2.6); DR testing (2.9.2)
Change System change management (3.4) Change management (3.3.7); application security (3.3.6) Cyber resilience — changes to critical infrastructure (2.7)
Patching and vulnerabilities Patch management (3.4.9) Vulnerability management (3.3.17)
Third parties SLAs (3.3.3); system acquisition (3.4.3) Third party cyber security (3.4) Third-party involvement in BCP tests (2.9)

Our guides to the SAMA CSF domains and the SAMA Business Continuity Management Framework cover the two neighbours.

Implementing the SAMA IT Governance Framework alongside the CSF

  1. Map the overlaps before writing anything. A bank at CSF maturity 3 already has a committee, a risk process, incident management and change security; the IT Governance Framework asks for the IT-side counterparts, which can share procedures where the table above shows a pair.
  2. Establish the IT Steering Committee separately from the cyber security committee. 3.1.1 specifies its chair (operations), its membership and its charter; one committee wearing two hats fails the independence the Cyber Security Framework requires of the cyber function.
  3. Run one self-assessment calendar. Both frameworks use questionnaires reviewed by SAMA; assess them in the same cycle with the same evidence library.
  4. Build Domain 3.4 on the existing change process. Change security requirements (3.4.6) and patch management (3.4.9) already exist under the CSF; the IT Governance Framework adds acquisition, development, testing, release, configuration, project and quality controls around them.
  5. Treat Domain 3.3 as the operations evidence. SLAs, capacity, batch, backup and virtualisation are where auditors find the gaps, because they were never in the cyber programme.
  6. Measure from year one. Every principle ends with effectiveness measured and evaluated; the KPIs of 3.1.9 are what carry the organisation from level 3 to level 4.

Frequently asked questions

What is the SAMA IT Governance Framework?
The Saudi Central Bank’s Information Technology Governance Framework, issued under Circular 43028139 on 4 November 2021: four domains — IT Governance and Leadership, IT Risk Management, IT Operations Management and System Change Management — with 35 subdomains, each stating a principle and control requirements, assessed on a 0–5 maturity model.

Who does it apply to?
Section 1.4 applies it to Member Organizations regulated by SAMA; the Rulebook records its scope of application as the banking sector and credit bureaus, and section 1.3 extends its direction to subsidiaries, staff, third parties and customers.

How does it relate to the Cyber Security Framework?
It is to be implemented in conjunction with the Cyber Security Framework and the Business Continuity Management Framework; cyber security and business continuity requirements are left to those documents, and the IT Governance Framework covers how IT is governed, risk-managed, operated and changed.

How is maturity assessed?
By periodic self-assessment on a questionnaire, reviewed and audited by SAMA, against a six-level model identical in form to the Cyber Security Framework’s — cumulative, with level 3 (structured and formalized) as the practical target and level 4 requiring measured effectiveness.

What does the IT Steering Committee require?
Subdomain 3.1.1: an ITSC mandated by the board, headed by the senior manager responsible for operations, with the CIO, CRO, CISO, compliance officer and business heads represented, internal audit as observer, and a charter covering objectives, roles, quorum and meeting frequency.

Where this leaves you

Implement the SAMA IT Governance Framework as the third leg of one programme: map its 35 subdomains against the Cyber Security and BCM Frameworks you already run, establish the IT Steering Committee with its own charter, build the operations and change domains on the processes that exist, assess all three frameworks in one calendar, and measure from the start — because the maturity model is the same, and level 4 is reached by evidence of effectiveness, not by documents.

References

More on SAMA

The IT Steering Committee charter, the IT governance self-assessment workbook by subdomain, the IT risk management procedure and the change, patch and configuration management procedures are in the SAMA Compliance Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.