Saudi Arabia: 224 fintechs, one AML standard

Under Vision 2030 the Saudi fintech sector went from 10 companies to 224. The regulatory response was not to build a lighter regime for them. It was to close the gap the other way: every fintech licence issued after 1 July 2026 must meet the same AML…

Illustration for “Saudi Arabia: 224 fintechs, one AML standard”

Under Vision 2030 the Saudi fintech sector went from 10 companies to 224. The regulatory response was not to build a lighter regime for them. It was to close the gap the other way: every fintech licence issued after 1 July 2026 must meet the same AML standards as a traditional bank.

That single sentence is the whole story. There is no longer a compliance-light on-ramp into the Saudi market.

What SAMA has been doing about it

The Saudi Central Bank has imposed penalties in the SAR 3 million to SAR 12 million range for AML compliance failures across 2024–2026. Those are not headline-grabbing numbers next to a US settlement, but they are not meant to be — SAMA’s enforcement model runs on binding circulars and on-site inspection, with the fine as the last step rather than the first.

The other change to plan for is SAFIU-Connect. SAMA’s 2026 roadmap mandates it for all electronic STR submissions, which turns suspicious-activity reporting from a document exercise into a systems integration. If your STR process today ends with someone attaching a file to an email, that process has a deadline on it.

Who supervises what

BodyScope
SAMABanks, exchange houses, fintechs, insurers — binding circulars, on-site inspection, penalties
SAFIUThe FIU, under the Presidency of State Security — receives, analyses and disseminates STRs; Egmont node
CMABroker-dealers, investment funds, digital-asset platforms
Ministry of CommerceDNFBPs — real estate, accountants, dealers in precious metals and stones
Ministry of JusticeAML/CFT manuals and guidelines; supports prosecution
ZATCACross-border cash and trade-based money laundering

Saudi Arabia is a founding member of MENAFATF and active in its technical assistance and typologies working groups — which in practice means Saudi supervisory expectations tend to arrive in the regional typologies before they arrive in your inbox.

The trap for cross-border firms

A firm licensed elsewhere in the Gulf and passporting activity into the Kingdom tends to assume its home-regulator programme travels with it. It does not. SAMA supervises against its own rulebook, ZATCA looks at the trade and cash leg, and the CMA takes the securities and digital-asset leg. Three supervisors, three evidence expectations, one customer file.

Three things worth doing this week

  1. Check your licence date against 1 July 2026. If you were licensed after it, run your programme against a bank-grade checklist, not a fintech one — and document the comparison.
  2. Start the SAFIU-Connect work now. Electronic STR submission is an integration project with a testing cycle, not a policy update.
  3. Name your supervisor for every product line. If two people in your firm would answer that question differently, you have found this week’s real finding.

The Saudi market grew twenty-two-fold in a decade. The supervisory framework caught up deliberately, and the direction of travel is one standard for everyone. Build to the bank standard and the licence question takes care of itself.



Sources

This article draws on the following sources. Follow the links for the original text.

Start with a compliance health check.

A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.

Or write to info@sonarpulse.mu