miniOrange Logo

Products

Services

Plugins

Pricing

Resources

Company

SAMA Compliance Identity Governance: Meeting CSF Control 3.3.5

28th September, 20268 Min Read

SAMA compliance starts with a simple question: who has access to what, and why? For a bank with thousands of users and applications, answering it requires more than an access list.

This is where SAMA compliance identity governance becomes important. Banks need clear access records, regular reviews, timely removal, and evidence that shows how each access decision took place.

The Saudi Central Bank (SAMA) Cyber Security Framework (CSF) sets expectations for access control and accountability. Identity Governance and Administration (IGA) helps banks put these expectations into everyday identity processes.

What Is Identity Governance for SAMA Compliance?

Identity governance in Saudi Arabia gives security and IT teams one clear view of access across the organization. It shows who has access, why they need it, who approved it, and when it was last reviewed. This helps teams manage access with greater clarity across users, roles, and applications.

For SAMA-regulated organizations, these checks are an important part of SAMA compliance and IAM requirements. Identity governance helps identify outdated permissions and unapproved access early, reducing risk and keeping the organization better prepared for audits.

IGA vs. IAM vs. PAM

IAM, PAM, and IGA each handle a different part of identity and access security. The table below shows the key differences between them.

Parameter IAM PAM IGA
Primary Focus Manages user identities and access Secures privileged accounts and access Governs and reviews access across the organization
Main Users Employees, customers, partners Administrators, IT teams, privileged users IT, security, compliance, and business teams
Access Type Standard user access Privileged and elevated access User access across applications, systems, and data
Key Function Authentication and access management Controls and monitors privileged sessions Reviews, approves, and removes access
Role Management Creates and manages user roles Controls privileged roles Reviews roles and identifies excessive permissions
Compliance Supports identity and access controls Helps secure privileged accounts for audits Supports access certification and compliance requirements

Who Must Comply

Banks, insurance and reinsurance companies, financing companies, credit bureaus, payment providers, and licensed fintechs operating as SAMA Member Organizations.

What SAMA CSF Control 3.3.5 Requires for Identity and Access Management

Control 3.3.5 focuses on access based on business needs. Banks need to make sure users receive only the access required for their responsibilities and that teams review those permissions over time.

The SAMA cybersecurity framework uses the principles of need-to-have and need-to-know access. These principles limit permissions according to job duties and information requirements.

SAMA CSF Expectation How Identity Governance Supports It
Need-to-Have Access Grants permissions based on defined business requirements
Need-to-Know Access Limits access to information users need for their responsibilities
Access Approval Records requests, reviewers, decisions, and timestamps
Access Review Sends permissions to managers or application owners for certification
Access Removal Removes unnecessary access after role or employment changes
Segregation of Duties Identifies conflicting permissions before assignment
Accountability Links access decisions to users, reviewers, and applications
Evidence Maintains records for audits and maturity assessments

For SAMA CSF compliance, the focus goes beyond granting access. Banks need to show that permissions match business needs and that teams review and remove access when those permissions no longer make sense.

Where Access Control Breaks Down Before the Assessment

Access gaps often appear between systems, teams, and processes. A bank might have individual controls in place while lacking one clear view of how those controls work together.

No Unified View of Access

Teams often manage employee identities, application permissions, privileged accounts, and third-party access through separate systems. This makes it harder to spot excessive permissions or understand access across the environment.

An IGA platform brings these records together and gives security teams one view of identity and access relationships.

Manual Joiner, Mover, Leaver Processes

When HR changes do not trigger access updates, employees can keep permissions after moving teams or leaving the organization. Manual tickets also create delays and inconsistent removal practices.

Automated JML workflows link employment changes with provisioning and deprovisioning actions. This helps teams remove outdated access faster and keep a clear record of each change.

Inconsistent Access Reviews

Managers often review access without enough context about the permissions assigned to their teams. Application owners also face long review lists with limited information about each account.

Access certification allows reviewers the information they need to approve, modify, or revoke permissions. It also records each decision for later verification.

Unclear Third-Party Access

Vendors, contractors, and partners often need access to banking systems for limited periods. Without clear ownership and expiry rules, those accounts can stay active after the business need ends.

Third-party governance assigns ownership, tracks access duration, and supports periodic review. These controls also support SAMA expectations for third-party cyber security.

SAMA Maturity Levels: What Level 3 Actually Requires

SAMA maturity assessments look beyond the presence of policies. Institutions need evidence that security practices operate consistently and support measurable control outcomes.

At SAMA maturity level 3, organizations need defined processes, clear ownership, repeatable controls, and evidence of ongoing execution. Identity governance helps move access management from policy documents into daily practice.

Maturity Level Identity Governance View
Level 1: Ad Hoc Access decisions depend heavily on individual teams and manual processes
Level 2: Developing Policies and processes exist, but execution varies across systems
Level 3: Defined And Formalized Access controls follow documented processes with clear ownership and recurring reviews
Level 4: Managed Teams measure control performance and improve processes using defined metrics
Level 5: Optimized Organizations improve controls using data, automation, and risk insights

For banks working toward Level 3, the focus should remain on repeatable access decisions, clear ownership, regular certification, and evidence that shows control execution.

Eight Identity Governance Areas That Map To SAMA CSF

These eight areas connect everyday identity processes with SAMA access expectations. Each one addresses a common access issue while helping teams create evidence for review.

Need-to-Know Access Enforcement

Need-to-know access limits information access according to business responsibility. IGA helps teams define policies that check whether requested permissions match a user’s role, department, or business requirement.

This supports SAMA CSF 3.3.5 by creating consistent rules for access assignment instead of leaving each request to individual judgment.

Joiner-Mover-Leaver Automation

Employee changes often create access gaps when teams depend on manual communication. IGA links HR events with provisioning and deprovisioning workflows.

When an employee joins, changes roles, or leaves, teams receive the right access action. This reduces outdated permissions and creates an auditable record for each lifecycle event.

SAMA-Aligned Access Certification

Regular reviews help banks confirm whether users still need their current permissions. Access certification sends access records to the right manager, application owner, or designated reviewer.

Reviewers approve required permissions and revoke unnecessary ones. The system records decisions, dates, reviewers, and actions to support SAMA audit evidence.

Segregation of Duties for Financial Transactions

Conflicting permissions can create risks around financial transactions and sensitive processes. SoD enforcement policies identify combinations of access that should not exist together.

IGA checks conflicts before teams assign permissions and flags existing violations for remediation. This gives banks a consistent way to manage separation between incompatible responsibilities.

Third-Party and Vendor Access Governance

Third-party users often need access for specific applications, projects, or time periods. Banks need clear ownership and review controls for these accounts.

IGA tracks vendor identities, assigned permissions, sponsors, review dates, and expiry information. This supports SAMA expectations for third-party cybersecurity and helps teams remove access when contracts or business needs end.

Orphaned and Dormant Account Cleanup

Accounts without active owners create visibility gaps. Orphaned accounts can remain active after employees leave, ownership changes, or applications lose their original administrators.

IGA identifies dormant and ownerless accounts across connected systems. Security teams can investigate, assign ownership, disable, or remove them according to policy.

Non-Human Identity Governance

Applications, service accounts, bots, and robotic process automation (RPA) identities also receive permissions. These identities often lack a direct employee owner, which makes oversight harder.

Identity Governance for AI agents and NHIs gives teams visibility into ownership, permissions, usage, and review requirements. Banks gain a consistent process for managing service accounts alongside workforce identities.

Audit-Ready Evidence for Maturity Assessments

Compliance teams need evidence that shows how access controls operate over time. Screenshots and manually collected spreadsheets often provide limited context.

Audit-ready reporting captures access requests, approvals, certifications, policy violations, provisioning actions, and revocations. Teams gain evidence linked to specific identities, applications, and decisions.

How to Implement Identity Governance for SAMA Compliance in Five Steps

A practical rollout starts with visibility and then moves toward control. Banks do not need to govern every application at once. They should first establish ownership across systems with higher access risk.

1. Integrate

Connect HR systems, directories, applications, privileged systems, cloud services, and other relevant identity sources. Build an accurate inventory of users, accounts, permissions, and ownership.

2. Visualize

Create a clear view of who has access to which applications and resources. Identify privileged permissions, dormant accounts, third-party identities, and access without clear ownership.

3. Identify

Use policies to find excessive permissions, conflicting roles, inactive accounts, and access outside defined requirements. Prioritize issues based on business and security impact.

4. Validate

Run access certification campaigns with managers and application owners. Use SoD enforcement policies to prevent or identify conflicting access before assignment.

5. Demonstrate

Maintain evidence for access requests, approvals, certifications, revocations, policy checks, and remediation. Use reports to show how controls operate during a SAMA assessment.

SAMA compliance checklist for Identity and Access Management

A practical SAMA compliance checklist helps teams spot gaps before an assessment. Review these areas to see whether identity processes support access control, accountability, and evidence requirements.

  • Documented IAM policy and access standards
  • Defined roles and access ownership
  • Need-to-have and need-to-know enforcement
  • HR-triggered provisioning and revocation
  • Preventive segregation of duties controls
  • Scheduled access certification
  • Privileged access governance
  • Third-party and vendor access reviews
  • Service account and RPA ownership
  • Orphaned accounts and dormant account detection
  • Evidence export for audits
  • Management metrics for access reviews and remediation

One Control Set, Many Frameworks: NCA ECC, PDPL, SWIFT CSP

Saudi banks often work with several regulatory and security requirements at the same time. Identity governance helps teams apply common identity controls across frameworks instead of creating separate processes for every requirement.

Framework Relevant Identity Governance Focus
SAMA CSF Access control, need-to-have, need-to-know, and accountability
SAMA ITGF IT governance, control oversight, and accountability
National Cybersecurity Authority Essential Cybersecurity Controls (NCA ECC) Identity, access control, privileged access, and security monitoring
Personal Data Protection Law (PDPL) Access to personal data and protection of personal information
Society for Worldwide Interbank Financial Telecommunication Customer Security Programme (SWIFT CSP) Access control and security around SWIFT environments
International Organization for Standardization 27001 (ISO 27001) Identity management, access control, and review
System and Organization Controls 2 (SOC 2) Access governance, control operation, and evidence
Payment Card Industry Data Security Standard (PCI DSS) User access, least privilege, and account management
General Data Protection Regulation (GDPR) Access control around personal data
Basel III Governance and controls supporting financial risk management

NCA ECC compliance also fits within the same identity process, which can support several requirements when teams maintain clear ownership, access policies, reviews, and evidence. This reduces duplicated work across compliance and security teams.

Why SAMA-Regulated Institutions Choose miniOrange IGA

Banks need SAMA compliance software that fits existing identity environments and gives compliance teams clear evidence. miniOrange IGA brings identity, access, policy, certification, and reporting workflows into one platform.

The platform supports mapping to SAMA CSF requirements, including Control 3.3.5 and third-party access expectations. Teams can govern workforce identities, privileged accounts, applications, cloud resources, and non-human identities from one place.

No-code policy configuration supports segregation of duties, access certification, lifecycle automation, and remediation workflows. Evidence-first reporting gives security and compliance teams records for assessments.

miniOrange IGA also supports cloud and on-premises deployment. This gives Saudi institutions flexibility when they need to align identity governance with existing infrastructure and security requirements.

Frequently Asked Questions

What is SAMA identity governance?

SAMA identity governance refers to the processes and controls organizations use to manage identities, permissions, approvals, reviews, and access removal in line with SAMA requirements.

Does SAMA CSF Control 3.3.5 require an IGA platform?

No, SAMA CSF does not prescribe a specific IGA product. Organizations need controls that support appropriate access, business need, accountability, and evidence. An IGA platform helps automate and document these processes.

How does IGA support SAMA maturity level 3?

IGA helps establish repeatable access reviews, lifecycle processes, policy checks, ownership, and evidence. These controls support the defined and formalized processes expected at SAMA maturity level 3.

How does IGA help with SAMA access certification?

IGA automates access certification campaigns and routes permissions to the appropriate reviewers. It records approval, rejection, revocation, reviewer identity, and timestamps for audit purposes.

Does SAMA require segregation of duties?

SAMA’s access control expectations support controls that limit inappropriate combinations of permissions. Segregation of duties helps institutions prevent or identify conflicting access across sensitive business functions.

Can SAMA identity governance cover non-human identities?

Yes, non-human identity governance extends oversight to service accounts, application identities, bots, and RPA accounts. Teams can assign ownership, review permissions, identify inactive accounts, and maintain evidence for these identities.

About the Author


Alankrita Shrivastava

Content Writer

Alankrita Shrivastava is a B2B technical content writer specializing in SaaS, cybersecurity, and WordPress security. She translates complex security concepts into clear, practical insights that support both technical decision-making and business outcomes. At miniOrange, she develops content on IAM, including SSO, MFA, and User Lifecycle Management, along with WordPress Plugin Security. She also covers broader security areas such as UEM, MDM, CASB, and DLP. Her work focuses on real-world use cases, security best practices, and solution-driven guidance that helps organizations assess risks, improve access control, and strengthen their overall IT security posture.

Leave a Comment