Risk & Compliance Advisory · Saudi Arabia
Risk and compliance frameworks that stand up to a SAMA review.
SRR helps regulated and institutional clients in Saudi Arabia design AML and compliance frameworks and risk governance that meet the Anti-Money Laundering Law, its Implementing Regulations, and the expectations of SAMA and the CMA, and that can be evidenced when tested.
The short answer
What does risk and compliance advisory in Saudi Arabia cover?
Risk and compliance advisory in Saudi Arabia covers the design and evidencing of an AML and CFT framework under the Anti-Money Laundering Law (Royal Decree No. M/20 of 1439H) and its Implementing Regulations; customer due diligence, sanctions screening, and suspicious transaction reporting to the Saudi Financial Intelligence Unit; and enterprise risk and governance frameworks, risk appetite, registers, and the three lines of defence, for SAMA-regulated and CMA-listed entities. SAMA supervises AML for banks, finance companies, exchange houses, and payment service providers.
The work is not writing a policy and stopping. It is building controls that operate, are tested and monitored, and can be evidenced to a supervisor. SRR advises on and helps build the framework and is not a licensed audit firm; independent testing of a framework is a separate role from designing it.
Source: Saudi Anti-Money Laundering Law and SAMA rulebook. Checked 8 September 2026.
- AML Law
- Royal Decree M/20
- The Anti-Money Laundering Law, issued by Royal Decree No. M/20 of 1439H (2017), with its Implementing Regulations, sets the CDD, record-keeping, and reporting obligations.
- Primary supervisor
- SAMA
- The Saudi Central Bank (SAMA) supervises AML and CFT for banks, finance companies, exchange houses, and payment service providers, and issues binding circulars.
- Reporting
- STRs to the FIU
- Suspicious transaction reports are filed, in Arabic, with the Saudi Financial Intelligence Unit, alongside screening against UN and domestic sanctions lists.
What We Handle
From framework design to controls that can be evidenced.
One senior team takes risk and compliance from a gap review through to a framework that operates and holds up when a supervisor asks for evidence.
- AML and CFT framework design under the Anti-Money Laundering Law and its Implementing Regulations
- Customer due diligence, enhanced due diligence, and beneficial ownership procedures
- Sanctions screening against UN and domestic lists, and suspicious transaction reporting workflows
- Enterprise risk frameworks: risk appetite, registers, and the three lines of defence
- Governance and internal control structuring for CMA-listed and SAMA-regulated entities
- Compliance function design, policies, and a testing and monitoring plan
- Gap reviews against SAMA circulars and regulator expectations
- Board and audit committee reporting so ownership and escalation are clear
Who It Is For
Where clients usually come to us on risk and compliance.
You are SAMA or CMA regulated
A bank, finance company, payment provider, or listed entity that has to evidence an AML framework, a compliance function, and risk governance to a supervisor, and the current setup will not stand up to a review.
A regulator or correspondent is asking questions
SAMA, a correspondent bank, or an auditor has raised a finding on due diligence, screening, or reporting, and there is a deadline to remediate it properly rather than patch it.
You are entering the Saudi market
A new licensee or a foreign group standing up operations in the Kingdom, needing the AML, compliance, and risk framework built correctly from the start rather than retrofitted.
Your framework is a document, not a practice
Policies exist on paper but are not tested, monitored, or evidenced, so there is nothing to show a supervisor that the controls actually operate.
How It Works
A clear path from gap review to a framework that operates.
-
Scope and gap review
We establish which obligations apply to your entity, from the AML Law and Implementing Regulations to the relevant SAMA circulars and CMA governance rules, and review the current framework against them.
-
Design the framework
We build the AML, compliance, and risk framework: CDD and screening procedures, risk appetite and registers, the three lines of defence, and the policies that sit behind them.
-
Make it operate
We put the testing, monitoring, and reporting in place so the controls actually run and can be evidenced, and so the board and audit committee can see ownership and escalation clearly.
-
Keep it current
Regulations and circulars change. We build a review rhythm so the framework stays aligned as SAMA and the CMA update their requirements, rather than drifting out of date.
What Goes Wrong
The compliance gaps a supervisor is built to find.
Most frameworks that fail a review fail on the same few gaps, and every one of them is avoidable with the right structure.
Buying a policy template and stopping there
A generic AML policy that is never mapped to the Implementing Regulations, tested, or evidenced is exactly what a SAMA review is designed to find. The document is the start of the work, not the end.
Treating screening and reporting as an afterthought
Sanctions screening against UN and domestic lists, and timely suspicious transaction reporting to the FIU, are where deficiencies attract penalties. They need a defined workflow, not ad hoc checks.
No clear ownership of risk
Without a risk appetite, a maintained register, and the three lines of defence set out, a board cannot show it owns and oversees the risks the regulator holds it accountable for.
Confusing internal audit with framework design
Designing the control framework and independently testing it are different roles. Collapsing them leaves the supervisor without the independence the model is built to provide.
Common Questions
Risk and compliance advisory, answered.
What is the legal basis for AML compliance in Saudi Arabia?
The core instrument is the Anti-Money Laundering Law, issued by Royal Decree No. M/20 of 1439H (2017), together with its Implementing Regulations, alongside the separate law on combating the financing of terrorism. These set the customer due diligence, record-keeping, screening, and reporting obligations. SAMA is the primary supervisor for banks, finance companies, exchange houses, and payment service providers, and issues binding circulars on top of the law.
Who supervises AML and CFT for our type of business?
For most financial institutions, banks, finance companies, exchange houses, and payment service providers, the supervisor is the Saudi Central Bank (SAMA). Designated non-financial businesses and professions are supervised by other authorities. Part of the scoping work is confirming which supervisor and which set of expectations apply to your entity before designing anything.
What does a suspicious transaction report involve?
Where a transaction raises a reasonable suspicion, a suspicious transaction report is filed, in Arabic, with the Saudi Financial Intelligence Unit. Alongside that, entities screen customers and transactions against UN and domestic sanctions lists. Both need a defined workflow with clear responsibilities, because gaps in screening and reporting are where supervisory findings and penalties tend to arise.
How is risk advisory different from internal audit?
Risk advisory designs the framework: the risk appetite, the registers, the three lines of defence, and the controls. Internal audit independently tests whether that framework actually works. They are deliberately separate roles so that the testing is independent of the design. We are clear about which role we are performing on any given engagement.
Can you help a company that is new to the Saudi market?
Yes. New licensees and foreign groups entering the Kingdom often need the AML, compliance, and risk framework built correctly from the start. Building it in from day one is far cheaper than retrofitting it after a supervisor or a correspondent bank raises a finding.
Who delivers the work, and what is SRR’s role?
SRR Consultants is a management and business advisory consultancy. Risk, compliance, and AML advisory is delivered by SRR’s own practitioners. SRR advises on and helps build the framework; it does not act as your licensed money laundering reporting officer or perform a regulated function on your behalf, and it is not a licensed audit firm.
Part of our advisory and assurance practice in Saudi Arabia. For the Bahrain equivalent under the CBB regime, see compliance advisory in Bahrain and risk advisory in Bahrain.
Build a framework that holds up when it is tested.
A short call with a senior practitioner is the quickest way to scope an AML framework, a compliance review, or a risk and governance structure for the Kingdom.