SAMA compliance starts with a simple question: who has access to what, and why? For a bank with thousands of users and applications, answering it requires more than an access list.
This is where SAMA compliance identity governance becomes important. Banks need clear access records, regular reviews, timely removal, and evidence that shows how each access decision took place.
The Saudi Central Bank (SAMA) Cyber Security Framework (CSF) sets expectations for access control and accountability. Identity Governance and Administration (IGA) helps banks put these expectations into everyday identity processes.
What Is Identity Governance for SAMA Compliance?
Identity governance in Saudi Arabia gives security and IT teams one clear view of access across the organization. It shows who has access, why they need it, who approved it, and when it was last reviewed. This helps teams manage access with greater clarity across users, roles, and applications.
For SAMA-regulated organizations, these checks are an important part of SAMA compliance and IAM requirements. Identity governance helps identify outdated permissions and unapproved access early, reducing risk and keeping the organization better prepared for audits.
IGA vs. IAM vs. PAM
IAM, PAM, and IGA each handle a different part of identity and access security. The table below shows the key differences between them.
| Parameter | IAM | PAM | IGA |
|---|---|---|---|
| Primary Focus | Manages user identities and access | Secures privileged accounts and access | Governs and reviews access across the organization |
| Main Users | Employees, customers, partners | Administrators, IT teams, privileged users | IT, security, compliance, and business teams |
| Access Type | Standard user access | Privileged and elevated access | User access across applications, systems, and data |
| Key Function | Authentication and access management | Controls and monitors privileged sessions | Reviews, approves, and removes access |
| Role Management | Creates and manages user roles | Controls privileged roles | Reviews roles and identifies excessive permissions |
| Compliance | Supports identity and access controls | Helps secure privileged accounts for audits | Supports access certification and compliance requirements |
Who Must Comply
Banks, insurance and reinsurance companies, financing companies, credit bureaus, payment providers, and licensed fintechs operating as SAMA Member Organizations.
What SAMA CSF Control 3.3.5 Requires for Identity and Access Management
Control 3.3.5 focuses on access based on business needs. Banks need to make sure users receive only the access required for their responsibilities and that teams review those permissions over time.
The SAMA cybersecurity framework uses the principles of need-to-have and need-to-know access. These principles limit permissions according to job duties and information requirements.
| SAMA CSF Expectation | How Identity Governance Supports It |
|---|---|
| Need-to-Have Access | Grants permissions based on defined business requirements |
| Need-to-Know Access | Limits access to information users need for their responsibilities |
| Access Approval | Records requests, reviewers, decisions, and timestamps |
| Access Review | Sends permissions to managers or application owners for certification |
| Access Removal | Removes unnecessary access after role or employment changes |
| Segregation of Duties | Identifies conflicting permissions before assignment |
| Accountability | Links access decisions to users, reviewers, and applications |
| Evidence | Maintains records for audits and maturity assessments |
For SAMA CSF compliance, the focus goes beyond granting access. Banks need to show that permissions match business needs and that teams review and remove access when those permissions no longer make sense.
Where Access Control Breaks Down Before the Assessment
Access gaps often appear between systems, teams, and processes. A bank might have individual controls in place while lacking one clear view of how those controls work together.
No Unified View of Access
Teams often manage employee identities, application permissions, privileged accounts, and third-party access through separate systems. This makes it harder to spot excessive permissions or understand access across the environment.
An IGA platform brings these records together and gives security teams one view of identity and access relationships.
Manual Joiner, Mover, Leaver Processes
When HR changes do not trigger access updates, employees can keep permissions after moving teams or leaving the organization. Manual tickets also create delays and inconsistent removal practices.
Automated JML workflows link employment changes with provisioning and deprovisioning actions. This helps teams remove outdated access faster and keep a clear record of each change.
Inconsistent Access Reviews
Managers often review access without enough context about the permissions assigned to their teams. Application owners also face long review lists with limited information about each account.
Access certification allows reviewers the information they need to approve, modify, or revoke permissions. It also records each decision for later verification.
Unclear Third-Party Access
Vendors, contractors, and partners often need access to banking systems for limited periods. Without clear ownership and expiry rules, those accounts can stay active after the business need ends.
Third-party governance assigns ownership, tracks access duration, and supports periodic review. These controls also support SAMA expectations for third-party cyber security.
SAMA Maturity Levels: What Level 3 Actually Requires
SAMA maturity assessments look beyond the presence of policies. Institutions need evidence that security practices operate consistently and support measurable control outcomes.
At SAMA maturity level 3, organizations need defined processes, clear ownership, repeatable controls, and evidence of ongoing execution. Identity governance helps move access management from policy documents into daily practice.
| Maturity Level | Identity Governance View |
|---|---|
| Level 1: Ad Hoc | Access decisions depend heavily on individual teams and manual processes |
| Level 2: Developing | Policies and processes exist, but execution varies across systems |
| Level 3: Defined And Formalized | Access controls follow documented processes with clear ownership and recurring reviews |
| Level 4: Managed | Teams measure control performance and improve processes using defined metrics |
| Level 5: Optimized | Organizations improve controls using data, automation, and risk insights |
For banks working toward Level 3, the focus should remain on repeatable access decisions, clear ownership, regular certification, and evidence that shows control execution.
Eight Identity Governance Areas That Map To SAMA CSF
These eight areas connect everyday identity processes with SAMA access expectations. Each one addresses a common access issue while helping teams create evidence for review.
Need-to-Know Access Enforcement
Need-to-know access limits information access according to business responsibility. IGA helps teams define policies that check whether requested permissions match a user’s role, department, or business requirement.
This supports SAMA CSF 3.3.5 by creating consistent rules for access assignment instead of leaving each request to individual judgment.
Joiner-Mover-Leaver Automation
Employee changes often create access gaps when teams depend on manual communication. IGA links HR events with provisioning and deprovisioning workflows.
When an employee joins, changes roles, or leaves, teams receive the right access action. This reduces outdated permissions and creates an auditable record for each lifecycle event.
SAMA-Aligned Access Certification
Regular reviews help banks confirm whether users still need their current permissions. Access certification sends access records to the right manager, application owner, or designated reviewer.
Reviewers approve required permissions and revoke unnecessary ones. The system records decisions, dates, reviewers, and actions to support SAMA audit evidence.
Segregation of Duties for Financial Transactions
Conflicting permissions can create risks around financial transactions and sensitive processes. SoD enforcement policies identify combinations of access that should not exist together.
IGA checks conflicts before teams assign permissions and flags existing violations for remediation. This gives banks a consistent way to manage separation between incompatible responsibilities.
Third-Party and Vendor Access Governance
Third-party users often need access for specific applications, projects, or time periods. Banks need clear ownership and review controls for these accounts.
IGA tracks vendor identities, assigned permissions, sponsors, review dates, and expiry information. This supports SAMA expectations for third-party cybersecurity and helps teams remove access when contracts or business needs end.
Orphaned and Dormant Account Cleanup
Accounts without active owners create visibility gaps. Orphaned accounts can remain active after employees leave, ownership changes, or applications lose their original administrators.
IGA identifies dormant and ownerless accounts across connected systems. Security teams can investigate, assign ownership, disable, or remove them according to policy.
Non-Human Identity Governance
Applications, service accounts, bots, and robotic process automation (RPA) identities also receive permissions. These identities often lack a direct employee owner, which makes oversight harder.
Identity Governance for AI agents and NHIs gives teams visibility into ownership, permissions, usage, and review requirements. Banks gain a consistent process for managing service accounts alongside workforce identities.
Audit-Ready Evidence for Maturity Assessments
Compliance teams need evidence that shows how access controls operate over time. Screenshots and manually collected spreadsheets often provide limited context.
Audit-ready reporting captures access requests, approvals, certifications, policy violations, provisioning actions, and revocations. Teams gain evidence linked to specific identities, applications, and decisions.
How to Implement Identity Governance for SAMA Compliance in Five Steps
A practical rollout starts with visibility and then moves toward control. Banks do not need to govern every application at once. They should first establish ownership across systems with higher access risk.
1. Integrate
Connect HR systems, directories, applications, privileged systems, cloud services, and other relevant identity sources. Build an accurate inventory of users, accounts, permissions, and ownership.
2. Visualize
Create a clear view of who has access to which applications and resources. Identify privileged permissions, dormant accounts, third-party identities, and access without clear ownership.
3. Identify
Use policies to find excessive permissions, conflicting roles, inactive accounts, and access outside defined requirements. Prioritize issues based on business and security impact.
4. Validate
Run access certification campaigns with managers and application owners. Use SoD enforcement policies to prevent or identify conflicting access before assignment.
5. Demonstrate
Maintain evidence for access requests, approvals, certifications, revocations, policy checks, and remediation. Use reports to show how controls operate during a SAMA assessment.
SAMA compliance checklist for Identity and Access Management
A practical SAMA compliance checklist helps teams spot gaps before an assessment. Review these areas to see whether identity processes support access control, accountability, and evidence requirements.
- Documented IAM policy and access standards
- Defined roles and access ownership
- Need-to-have and need-to-know enforcement
- HR-triggered provisioning and revocation
- Preventive segregation of duties controls
- Scheduled access certification
- Privileged access governance
- Third-party and vendor access reviews
- Service account and RPA ownership
- Orphaned accounts and dormant account detection
- Evidence export for audits
- Management metrics for access reviews and remediation
One Control Set, Many Frameworks: NCA ECC, PDPL, SWIFT CSP
Saudi banks often work with several regulatory and security requirements at the same time. Identity governance helps teams apply common identity controls across frameworks instead of creating separate processes for every requirement.
| Framework | Relevant Identity Governance Focus |
|---|---|
| SAMA CSF | Access control, need-to-have, need-to-know, and accountability |
| SAMA ITGF | IT governance, control oversight, and accountability |
| National Cybersecurity Authority Essential Cybersecurity Controls (NCA ECC) | Identity, access control, privileged access, and security monitoring |
| Personal Data Protection Law (PDPL) | Access to personal data and protection of personal information |
| Society for Worldwide Interbank Financial Telecommunication Customer Security Programme (SWIFT CSP) | Access control and security around SWIFT environments |
| International Organization for Standardization 27001 (ISO 27001) | Identity management, access control, and review |
| System and Organization Controls 2 (SOC 2) | Access governance, control operation, and evidence |
| Payment Card Industry Data Security Standard (PCI DSS) | User access, least privilege, and account management |
| General Data Protection Regulation (GDPR) | Access control around personal data |
| Basel III | Governance and controls supporting financial risk management |
NCA ECC compliance also fits within the same identity process, which can support several requirements when teams maintain clear ownership, access policies, reviews, and evidence. This reduces duplicated work across compliance and security teams.
Why SAMA-Regulated Institutions Choose miniOrange IGA
Banks need SAMA compliance software that fits existing identity environments and gives compliance teams clear evidence. miniOrange IGA brings identity, access, policy, certification, and reporting workflows into one platform.
The platform supports mapping to SAMA CSF requirements, including Control 3.3.5 and third-party access expectations. Teams can govern workforce identities, privileged accounts, applications, cloud resources, and non-human identities from one place.
No-code policy configuration supports segregation of duties, access certification, lifecycle automation, and remediation workflows. Evidence-first reporting gives security and compliance teams records for assessments.
miniOrange IGA also supports cloud and on-premises deployment. This gives Saudi institutions flexibility when they need to align identity governance with existing infrastructure and security requirements.
Frequently Asked Questions
What is SAMA identity governance?
SAMA identity governance refers to the processes and controls organizations use to manage identities, permissions, approvals, reviews, and access removal in line with SAMA requirements.
Does SAMA CSF Control 3.3.5 require an IGA platform?
No, SAMA CSF does not prescribe a specific IGA product. Organizations need controls that support appropriate access, business need, accountability, and evidence. An IGA platform helps automate and document these processes.
How does IGA support SAMA maturity level 3?
IGA helps establish repeatable access reviews, lifecycle processes, policy checks, ownership, and evidence. These controls support the defined and formalized processes expected at SAMA maturity level 3.
How does IGA help with SAMA access certification?
IGA automates access certification campaigns and routes permissions to the appropriate reviewers. It records approval, rejection, revocation, reviewer identity, and timestamps for audit purposes.
Does SAMA require segregation of duties?
SAMA’s access control expectations support controls that limit inappropriate combinations of permissions. Segregation of duties helps institutions prevent or identify conflicting access across sensitive business functions.
Can SAMA identity governance cover non-human identities?
Yes, non-human identity governance extends oversight to service accounts, application identities, bots, and RPA accounts. Teams can assign ownership, review permissions, identify inactive accounts, and maintain evidence for these identities.




Leave a Comment