Saudi Arabia: two targeted-sanctions rulebooks, one screening calendar
Fifteen days apart at the end of 2025, two Saudi financial supervisors each put out a targeted financial sanctions rulebook. The Saudi Central Bank (SAMA) issued its Rules for the Implementation of Targeted Financial Sanctions by circular No. (472035766),…
Fifteen days apart at the end of 2025, two Saudi financial supervisors each put out a targeted financial sanctions rulebook. The Saudi Central Bank (SAMA) issued its Rules for the Implementation of Targeted Financial Sanctions by circular No. (472035766), dated 16/6/1447H, corresponding to 7 December 2025; SAMA’s rulebook shows their status as In-Force. The Capital Market Authority issued its Targeted Financial Sanctions Implementation Rules (TFS) by Board Resolution No. (4-163-2025), dated 2/7/1447H, corresponding to 22 December 2025.
Both run to nine chapters, in the same order: definitions and general provisions, governance, screening, list management, alerts, freezing and unfreezing, record keeping, training, and final provisions. In most places the two texts say the same thing in slightly different English.
For a group holding a SAMA licence and a CMA licence, that is the useful part. One screening calendar, one alert procedure and one retention rule will satisfy both rulebooks. What does not merge is the reporting: each supervisor wants the notification in its own inbox.
Who each rulebook binds
SAMA’s rules define a Financial Institution as any financial institution subject to SAMA’s regulation, monitoring and supervision that is tasked with combating money laundering, terrorist financing and proliferation financing, and Chapter One states that the rules apply to Financial Institutions. The CMA’s rules use the mirror-image definition: any financial institution regulated, overseen and supervised by the Authority with the same responsibilities.
That is worth reading literally. Neither instrument is Saudi law for every regulated firm. SAMA’s rules bind the institutions SAMA supervises; the CMA’s bind the institutions the CMA supervises. Insurers sit outside both texts: the Insurance Authority says that from 23 November 2023 it became the authorised regulator of the insurance industry in the Kingdom.
Both sets are a floor rather than a ceiling. SAMA’s general provisions describe the rules as establishing the minimum obligations for implementing targeted financial sanctions. The CMA’s scope article says the rules are mandatory and represent the minimum requirements financial institutions must meet, without prejudice to any other relevant laws, regulations or instructions.
“Without delay” is defined, and it is measured in hours
Both definitions sections define the phrase rather than leaving it to judgement. SAMA’s reads: within hours of the designation of a listed person on the sanctions lists, or of delisting from them. The CMA’s is a shade softer in wording:
> “The phrase without delay means, ideally, within a matter of hours of the > designation of a person in the sanctions lists or the announcement of the > delisting of a person from the sanctions lists.”
Both rulebooks position themselves against the same external framework: the implementation mechanisms for Security Council Resolutions 1267, 1989, 2253, 1988 and 1373 on terrorism and its financing, Resolutions 1718 and 1737 on proliferation financing, national instructions and circulars, and FATF Recommendations 6 and 7 with Immediate Outcomes 10 and 11.
The screening calendar
Paragraph 3.5 of each rulebook lists when you screen, and paragraph 3.6 turns that list into timeframes. The two are close enough to run as one schedule.
| Trigger | What the rules require |
|---|---|
| New relationship | Before establishing a business relationship, opening an account or opening an electronic wallet for a customer or related party. SAMA’s version adds opening a remittance membership. |
| Outgoing transactions | Screened before they are executed. |
| Incoming transactions | Screened as soon as they are received, without waiting for the end of the day or a specified period. |
| List update | Immediately on any update to the sanctions lists. All customer and transaction data, beneficial owners, directors or managers, authorised signatories and related parties are screened against the updated list, with a record of the update, the screening and any action taken. |
| Customer data update or review | Whenever the institution updates or reviews customer data. |
| Quarterly | Comprehensive screening of customer databases and information, transactions, beneficial owners, directors or managers, authorised signatories and related parties, at least once every three months. |
| Specific events | Additional screening on material changes: a change in ownership or control structure, a new high-risk country in a customer’s transactions or relationships, a change in transaction patterns suggesting higher risk, alerts from regulators about a sector, country or group of customers, a rise in a customer’s risk rating after a periodic assessment, a customer’s association with suspicious behaviour around a list update, or adverse media on a customer, country or sector. The institution defines and documents these events in its own policies. |
Paragraph 3.4 in both rulebooks adds a look-back that is easy to miss. As well as screening names against the latest Security Council decisions and the national sanctions lists, the institution must review the transactions it carried out in the previous twelve months to identify any prior dealings with persons newly added to the lists. The review must be documented and auditable, showing its scope, its results and the action taken, and it should run further back than twelve months where the institution’s risk level and available resources allow.
Chapter Four sets the list-management duty behind all of this: update internal lists immediately on an announcement or notification of a listing, monitor and update daily through official websites and channels, and keep a log of when each update was received, applied and confirmed in internal systems. Both rulebooks say in terms that reliance on automated or manual screening tools is not a guaranteed assurance of compliance. The official channels named are the sanctions committees; the committee on terrorism and its financing under the Presidency of State Security, which SAMA calls the Permanent Counter Terrorism Committee (PCTC) and the CMA calls the Standing Committee for Combating Terrorism and its Financing; the standing committee at the Ministry of Foreign Affairs for Security Council resolutions issued under Chapter VII; and the United Nations sanctions committees. Both rulebooks close by naming the two Saudi committee websites to monitor: pctc.pss.gov.sa and securitycouncil.mofa.gov.sa.
A confirmed match does not go to a committee
This is the paragraph to take to your next procedure review. Under paragraph 5.4 of both rulebooks, two specialists may close an alert as a false positive after following internal procedures, keeping a written justification for the closure. If they cannot close it, it goes straight to the senior officer with the experience and authority to assess the match. Then, in SAMA’s paragraph 5.5:
> “the funds shall be frozen without delay, and the Financial Institution shall > not delay the freezing measures pending approval by an internal committee, > legal review, approval by senior management, or for any other reason, if the > match is confirmed.”
The CMA’s 5.5 says the same in its own words: once a match is confirmed the funds must be frozen without delay, and the institution may not defer the freezing procedures pending an internal committee’s approval, a legal review, senior management approval, or for any other reason.
Chapter Six then describes the freeze itself. It happens without delay and without prior notice, and it reaches funds owned, controlled, managed, directed or held by a listed person, wholly or partially, directly or indirectly, plus funds of anyone acting for, at the direction of or on behalf of that person. The worked examples in 6.3 are the ones sanctions teams argue about: companies controlled without formal ownership, joint bank accounts, trust funds, holdings through minor children or spouses, shell and front companies, joint ventures, and structures built to obscure control. Jointly held funds are frozen in full, including the non-listed person’s share, and may only be dealt with after consulting the supervisor, case by case. Funds generated from frozen funds are caught too.
Unfreezing follows the same clock. Where the Security Council sanctions committees delist a person, the freeze is lifted without delay and without prior notice — unless prior notice says otherwise because of a designation under Resolution 1373. Funds frozen on the direction of the competent authorities stay frozen until the supervisor gives instructions.
Maker-checker, and eight fields on every alert
Paragraph 5.3 requires two people on every alert: SAMA calls it two specialists in a maker-and-checker arrangement to ensure dual screening, and the CMA calls it two qualified personnel working in a dual-control manner. Both require sufficient experience and knowledge of targeted financial sanctions, and both allow due diligence information, public records and open sources to support the decision.
Paragraph 5.6 sets the audit trail. Every alert record carries the time and date of receipt; the time and date of processing and of any escalation; the source of the alert, such as the UN Security Council lists or the national lists; its nature, such as a name match, an indirect match, or a match related to evasion or circumvention; the action taken with its justification; the names of the specialists who handled it; the outcome; and details of any freeze carried out.
Repeat false positives may go on an internal whitelist, with justification and periodic review and approval by the board or senior management — but whitelisted names remain subject to comprehensive screening, post-update screening and event-driven screening.
Confidentiality runs alongside: no disclosure to the customer or any internal or external party that there is a match, that a freeze is intended or that a review is under way. The two carve-outs are the notification to the supervisor and the report to the financial intelligence body.
Two notification routes
| Obligation | SAMA-supervised institution | CMA-supervised institution |
|---|---|---|
| After taking freezing measures | Notify SAMA by email at TFS-FIGD@SAMA.GOV.SA | Notify the Authority by email at CMA-AML@cma.org.sa |
| Indications of evasion, circumvention or suspicious financial behaviour | Suspicious activity report to the General Directorate of Financial Investigations | Suspicious activity report to the Financial Intelligence Unit |
| Funds of listed persons not under your management, possession or control | Notify SAMA in writing | Notify the Authority in writing |
| Lifting a freeze | Notify SAMA immediately, in writing | Notify the Authority immediately, in writing |
| Manual screening tools | Written non-objection from SAMA; the exception does not apply to institutions offering payment or transfer products or services | Written non-objection from the Authority |
| Who approves the policies | The board of directors or senior management, as the case may be | The board of directors in joint-stock companies, senior management in non-joint-stock companies |
The content of the freeze notification is the same on both sides: sufficient information about the customer and the transaction, details of the freezing measures, the nature and value of the frozen funds, the relevant listing information and whether it is a UN or a national list, any transactions carried out or attempted, and any other relevant information or measures. Anything further the supervisor asks for comes back within the time and through the mechanism it specifies.
Ten years, an annual independent test, and a named unit
Records — policies, list updates, alerts and their outcomes, event-driven reviews, freezes and unfreezes with their correspondence, reports to the supervisor, suspicious activity reports, internal and external audit reports, board reporting and training records — are kept for not less than ten years from the date the transaction or procedure was completed, indexed by date, type of procedure and customer or transaction, and retrievable on request.
Governance sits in Chapter Two. Each institution runs a specialised targeted financial sanctions unit, organisationally linked to its AML/CFT unit, resourced in proportion to its activities and risk, and headed by a competent officer. SAMA allows a non-bank financial institution, with written non-objection, to give the role to its AML/CTF officer; the CMA allows the same with its own non-objection. The internal policies, procedures and controls are tested annually by an independent auditor, internally or externally, and the results go to the board or senior management. Screening effectiveness gets its own regular testing under 3.12, including analysis of matches the system failed to detect and of indirect matches, not just name matches.
The final chapters put the consequences differently. The CMA’s paragraph 9.4 names who is accountable under the relevant laws: anyone who fails to impose or execute a freezing order against a listed person, anyone who makes funds or services available to or for the benefit of one, and anyone who fails to disclose information, discloses incorrect information intentionally or negligently, or delays providing it. SAMA’s paragraph 9.5 works from the supervisory end: SAMA monitors full compliance through its supervisory and regulatory procedures, and the penalties provided under the relevant regulations apply to negligence, failure or non-compliance.
On commencement, read the two carefully. SAMA’s paragraph 9.9 says the rules enter into force from the date of their publication on SAMA’s website, and the rulebook entry records their status as In-Force. The CMA’s paragraph 9.8 uses the same formula — entry into force as of the date of publication on the Authority’s website — but the rules do not state that date. Treat 22 December 2025 as the date of the Board resolution, not as a commencement date, and confirm the commencement with the CMA before you write it into a policy.
Three things worth doing
- Date the quarterly run and prove the base was whole. Comprehensive screening at least once every three months is a scheduled, evidenced event, not a byline on a monitoring report. Record the run date, the record counts for customers, beneficial owners, directors and managers, authorised signatories and related parties, and the list version screened against.
- Read your freeze procedure for approval gates. Any step that routes a confirmed match to a committee, to legal, or to an executive for sign-off before the funds are frozen is the step paragraph 5.5 is aimed at. Sign-off after the freeze is a different thing, and both rulebooks require it in the form of records and reports.
- Write both notification templates now, and name the owners. One to TFS-FIGD@SAMA.GOV.SA, one to CMA-AML@cma.org.sa, each carrying the content items paragraph 5.9 lists, plus a separate suspicious activity report where there are signs of evasion or circumvention. If your group holds both licences, agree in advance which entity’s team sends which.
Sources
This article draws on the following sources. Follow the links for the original text.
- Saudi Central Bank (SAMA) — Rules for the Implementation of Targeted Financial Sanctions (circular No. 472035766, 7 December 2025)
- Capital Market Authority — Targeted Financial Sanctions Implementation Rules (TFS), Board Resolution No. (4-163-2025)
- Insurance Authority (Saudi Arabia) — FAQs
AML compliance financial-crime intermediate jurisdiction-briefing saudi-arabia what-changed