2022-04-21 | 202200000245

Added

Minimum Verification Controls

SAMA mandates that member organizations providing E-wallet, lending, crowdfunding, or other fintech services implement specific registration, general, and lending application controls to address cyber risks. Member organizations must enforce single-device and single-application linkage per user, utilize trusted parties for identity verification, and implement session timeouts and SMS notifications for account changes. The document requires Multi-Factor Authentication for logins and One-Time Passwords for various transactions, with cross-channel OTPs mandated for transfers exceeding a defined value or involving IBANs. Lending companies must additionally verify recipient IBANs, use authorized digital signature providers, and confirm loan requests via phone calls.

Saudi Central Bank logo

Saudi Arabia

Saudi Central Bank

Scan of the document's first page
Share

Get SAMA alerts — same-day email on every new publication.

Read the rest free

Lineage: In force

Digital Certification of Produc…2020Digital Certification of Products for Finance Companies Customers (2020-10-14)Minimum Verification Controls2022-04-21 · this documentMinimum Verification Controls (2022-04-21)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Saudi Central Bank — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from SAMA

We email you every new SAMA publication the day it's published.