2012-12-16
Added · Updated
The Saudi Central Bank mandates banks operating in the Kingdom to implement electronic channels with robust security standards, including Two-Factor Authentication, to verify sender identity for transfer requests. Until full implementation, banks must require employees to exercise due care and independently verify that email-based transfer instructions originate from the actual client rather than an impersonator. This circular explicitly nullifies previous circular No. 10/4/10611 dated 25/07/2019 and requires banks to submit a timeline for implementing the new security measures.
In the Name of Allah, the Most Gracious, the Most Merciful
Number: 10/4/ Date: / /1440 AH Corresponding to: / /2019 AD
Circular to Banks Operating in the Kingdom
Greetings,
In light of recent reports received regarding breaches of email accounts belonging to several bank clients, and the subsequent sending of transfer requests from the compromised emails without the clients' knowledge, which led to the execution of transfers from client accounts to unrelated parties, we request confirmation of adherence to the following:
It is necessary to make your services available through the use of electronic channels that enable the application of appropriate security standards, including the ability to verify the sender's identity. Examples include, but are not limited to, Online Banking, Mobile Applications, Digitally Signed Emails, etc., with a preference for using Two-Factor Authentication (2FA) technology. There is also a necessity to urge your clients to use these technologies.
Until the above is implemented, please disseminate to all relevant employees the requirement to exercise due professional care and utmost caution regarding transfer requests received via email or any similar means. It must be verified, under the bank's responsibility, that the incoming transfer request was based on the request of the bank's client and not from any other party impersonating them, by employing all available means to avoid falling victim to such incidents.
The contents of our circular No. (10/4/10611) dated 25/07/2019 are hereby considered null and void. There is a necessity to provide us with the timeline for implementing what was stated in item (a) above.
Please accept our highest regards,
The Governor Dr. Ziad Farez
Circular - 4/8/2019 - Spoofing