SAMA Cyber Resilience Framework
The Saudi Central Bank's cyber-resilience framework — sets the technology and data-residency expectations for regulated financial institutions, with explicit AI provisions in the 2025 update.
What SAMA Cyber Resilience Framework means in practice
The Saudi Central Bank's Cyber Resilience Framework sets the technology controls expected of regulated financial institutions in Saudi Arabia. The 2025 update extended explicit guidance to AI-driven systems: model lifecycle artefacts and inference must remain under the regulated entity's exclusive control, cross-border AI inference on customer data is constrained, and the audit trail of AI-driven decisions must satisfy the same standards as any other regulated decision. The practical effect is that sovereign deployment is the default architectural choice for any GenAI workload touching customer data at a Saudi bank or insurer.
Related terms
Sovereign AI →
An architecture where customer data never leaves the network perimeter, model weights run on customer-controlled hardware, inference logs stay in the customer's SIEM, and the entire stack can operate air-gapped.
RBI Master Direction on IT Governance →
The Reserve Bank of India's master directive on IT governance for regulated entities — specifies that AI/ML model lifecycle artefacts must be hosted under the regulated entity's exclusive control.
EU AI Act →
The European Union's AI Act — risk-tiered regulation of AI systems, with high-risk-system requirements that effectively mandate auditability, human oversight and conformity assessment.
More in this category
All 62 terms, in plain language
Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.