Law / Saudi Arabia

Counter-Fraud Framework: fraud detection systems, machine learning and artificial intelligence

SAMA Counter-Fraud Framework

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived . Publisher's page: https://www.sama.gov.sa/en-US/RulesInstructions/CyberSecurity/Counter_Fraud_Framework.pdf

In force.

An AI sector rules rule binding private bodies.

Enforcement body
Saudi Central Bank (SAMA)
Instrument type
a regulation made under an act
Obligation class
Governance
Audit expectation
periodic
Who audits it
Internal independent, Regulator, Self
Where the report goes
Kept

As of .

What it requires

  • It reaches you if you are a Member Organisation, meaning a financial institution or financial services provider regulated by SAMA, that SAMA has notified is required to implement and comply with the Counter-Fraud Framework (the Framework applies to Member Organisations operating in Saudi Arabia at SAMA's discretion, Sections 1.4 and 1.5 and Appendix A): implement and maintain fraud detection systems that monitor customer products and services, and internal systems, for transactions or behaviors that may be indicative of fraud, and have them operate 24/7 with appropriate resources in place to manage their outputs on a timely basis (Sections 5.2(a) and 5.2(b)). The Framework words its Control Requirements as "should", and each line below keeps that strength.
  • Build the fraud detection system capability to include, at a minimum, analysis of structured data, monitoring of customer and internal accounts, baselining of user behavior patterns into profiles so that deviations from normal activity can be identified, a library of rules based on known fraud typologies, segmentation of customer groups to tailor rules, a weighting of rules based on the assessed level of fraud risk together with risk scoring, aggregation of risk scores across multiple channels, and linking of outputs to a Case Management System (Section 5.2(e)).
  • Draw on holistic and current data sources for detection, including customer products and services held across all lines of business, all contact channels, external information, the insights gathered from Intelligence Monitoring, transactional or settlement data and non-transactional data, and put controls in place so that the data supplied to the detection system is timely, complete and accurate (Sections 5.2(c) and 5.2(d)).
  • Where the Fraud Risk Assessment identifies a higher risk of fraud or fraud incidents are higher, additionally implement system capability for big data mining, analytical tools that enhance rules-based monitoring such as predictive analytics and anomaly detection, an overlay of Artificial Intelligence and Machine Learning algorithms to enhance the system's decision making capability, predict the likelihood of fraud and learn from historical patterns of fraudulent and legitimate behavior, link analytics or entity resolution, and analysis of additional unstructured external data (Section 5.2(g)); where the inherent risk of fraud is assessed as higher, have the fraud detection standards require additional detection controls such as real time monitoring, additional data sources or Machine Learning models, or more stringent detection threshold criteria (Section 5.1(f)).
  • Where Machine Learning or Artificial Intelligence is used in a counter-fraud system, whether sourced from a vendor or developed in-house, make sure the system is not a "black box" and is capable of being audited, with the capability to test what the algorithms are designed to do and whether they are correctly implemented (Section 3.8(d)(8)).
  • Define, approve and implement a strategy for sourcing or developing counter-fraud systems and technology, implement them and verify that they are operating as intended, and for any such system document the rationale for the scenarios developed and thresholds applied, be able to implement new rules on a timely basis against new or emerging fraud typologies, and be able to explain the fraud threats the scenarios are designed to monitor and mitigate (Sections 3.8(a), 3.8(b), 3.8(d)(2), 3.8(d)(4) and 3.8(d)(7)).
  • When a deviation from the baselined user behavior patterns is identified, either require further authentication of the user or the user's instructions, or generate an alert for further investigation to determine whether fraud has occurred (Section 5.2(h)).
  • Calibrate and test detection scenarios to validate that they are working as designed, implement feedback loops that review false positives, false negatives and alerts which identified fraud, periodically review scenarios and parameters, periodically test the effectiveness of systems through tuning and calibration measures that include model validation, update user behavior patterns and rules for the latest threats, retain a documented record of changes made to configuration or rules and the rationale for the decision, and monitor for unauthorized changes to the system such as rule tampering or disabling of monitoring (Section 5.2(i)).
  • Give the fraud detection systems the capability to monitor and report metrics and Management Information on data integrity, rule and scenario effectiveness such as the false positive rate, and operational performance (Section 5.2(j)).
  • Operate at Counter-Fraud maturity level 3 or higher, which includes implementing fraud detection system capability to prevent and proactively detect fraud, and perform the periodic self-assessment, based on a questionnaire, that SAMA reviews and audits (Sections 2.3, 2.4 and 2.4.1).

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

The Counter-Fraud Framework of the Saudi Central Bank (SAMA), October 2022, Version 1.0, defines Principles and Control Requirements for initiating, implementing, maintaining, monitoring, and improving Counter-Fraud controls within Member Organisations regulated by SAMA. The Framework defines a Member Organisation as all financial institutions or financial services providers regulated by SAMA.

The Framework is applicable to all Member Organisations operating in Saudi Arabia based on SAMA discretion, and Member Organisations required to implement and comply with it are notified by SAMA. The Framework states that it is mandated by SAMA and will be circulated to Member Organisations for implementation, and that the Member Organisations are responsible for implementing and complying with it.

The Control Requirements reflect the mandated Counter-Fraud controls that Member Organisations should consider when designing and implementing a Counter-Fraud Programme. When a Control Requirement cannot be implemented, a Member Organisation should follow an exception process that ends in a request to SAMA for a formal waiver, and approval of waiver requests is at the discretion of SAMA.

Implementation of the Framework at Member Organisations is subject to a periodic self-assessment based on a questionnaire, and SAMA reviews and audits the self-assessments to determine the level of compliance with the Framework and the Counter-Fraud maturity level of the Member Organisation. Member Organisations should at least operate at Counter-Fraud maturity level 3 or higher, which includes implementing fraud detection system capability to prevent and proactively detect fraud.

The Framework asks that a counter-fraud system that uses Machine Learning or Artificial Intelligence not be a black box and be capable of being audited, with the organisation able to test what the algorithms are designed to do and whether they are correctly implemented. The Framework defines a Black Box System as a complex system where the internal rules and mechanisms are not visible to or understood by the system owner.

The Framework defines Artificial Intelligence as the use of computer systems to perform tasks typically requiring human knowledge and logical capabilities, often in problem solving scenarios. Where the inherent risk of fraud is assessed as higher, the fraud detection standards should require additional detection controls, for example real time monitoring, additional data sources or Machine Learning models, or more stringent detection threshold criteria.

Fraud detection systems should operate 24/7 with appropriate resources in place to manage outputs on a timely basis.

Where a higher risk of fraud is identified in the Fraud Risk Assessment or higher incidences of fraud occur, Member Organisations should additionally implement system capability that includes overlaying Artificial Intelligence and Machine Learning algorithms, for example decision trees, random forests and neural networks, to enhance system decision making capability, predict the likelihood of fraud and learn from historical patterns of fraudulent and legitimate behavior.

Where a deviation from the baselined user behavior patterns is identified, a Member Organisation should either require further authentication of the user or the user's instructions, or generate an alert for further investigation to determine whether fraud has occurred.

Member Organisations should calibrate and test detection scenarios to validate that they work as designed, for example through rule logic review, threshold testing and precision and recall testing, and should implement feedback loops that review false positives, false negatives and alerts which identified fraud. Article 4 of the Saudi Central Bank Law lists, among the tasks the Bank performs, issuing the regulations and instructions relating to financial institutions and their business.

The Banking Control Law defines a bank as any natural or legal person who primarily engages in any banking business in the Kingdom.

Article 22 of the Banking Control Law provides that SAMA may, if it is established that a bank has violated any of the Law's provisions or the rules and resolutions issued for its implementation, take measures that include suspending or dismissing any of the bank's board members or staff and prohibiting the bank from extending loans or receiving deposits, on the approval of the Minister of Finance and National Economy.

Article 23 of the Banking Control Law punishes a person who violates any of the other provisions of the Law or the rules and resolutions issued for its implementation by a fine not exceeding 5,000 riyals.

When LexLint raises it

When your app profile says your app provides financial services or makes high-risk automated decisions.

Back to the example  ·  Lint your app