SAMA’s 13 Principles for Internal Audit and Compliance: What Finance Companies Must Do Now
Finance companies operating in Saudi Arabia now sit inside one of the most active regulatory environments in the GCC. The SAMA internal audit compliance principles reshape how boards, audit committees, and executive teams govern risk across finance and real estate refinance companies. Every regulated entity seeking reliable internal audit consultancy services needs to understand this framework in detail, as the 13 principles set the minimum standard SAMA expects of every licensed finance company in the Kingdom.
Firms that rely on generic internal audit templates or outdated compliance manuals expose themselves to supervisory findings, licensing delays, and reputational damage. Engaging structured internal audit consultancy services helps finance companies translate the 13 principles into working policies, audit charters, and reporting lines that satisfy SAMA examiners. This article breaks down each cluster of requirements, presents verified figures on the Kingdom’s finance sector, and explains the practical steps finance companies must take before their next supervisory review.
The Regulatory Background Behind the 13 Principles
SAMA published the draft Compliance Principles and Internal Audit Principles for finance and real estate refinance companies for public consultation in May 2024, inviting feedback from industry stakeholders through the Istitlaa platform. After reviewing market input, SAMA issued the final Compliance Principles and Internal Audit Principles in October 2024, and the principles came into force on 2 April 2025. The SAMA internal audit compliance principles consist of 13 principles that cover the duties of the board of directors, audit committees, and executive management toward the internal audit function, along with documentation, reporting, and audit methodology requirements.
Regulatory experts describe the framework as SAMA’s attempt to bring finance company governance in line with international internal audit standards. The principles set the floor, not the ceiling – finance companies must scale their internal audit and compliance structures to match their size, complexity, and risk profile, but no company can fall below the baseline SAMA has defined.
Why the Timing Matters for Saudi Arabia’s Finance Sector
Saudi Arabia’s non-bank finance sector has expanded at a rapid pace, which is exactly why SAMA tightened internal audit and compliance expectations. The table below shows how quickly the regulated finance landscape has grown.
|
Metric |
Figure |
Period |
|
Licensed finance companies in Saudi Arabia |
77 |
July 2026 |
|
Licensed finance companies |
64 |
January 2025 |
|
Licensed consumer microfinance providers |
11 |
2025–2026 |
|
Licensed payment service providers |
32 |
May 2026 |
|
Fintech companies operating in the Kingdom |
301 |
End of 2025 |
|
Fintech companies operating in the Kingdom |
261 |
End of 2024 |
|
Vision 2030 fintech target |
525 companies |
By 2030 |
|
Electronic payments share of retail transactions |
85% |
2025 |
This growth trajectory explains why SAMA introduced a unified rulebook. With more than 13 new finance companies licensed in under 18 months, and fintech firms climbing toward the 525-company Vision 2030 target, SAMA needed a consistent governance baseline that scales across banks, finance companies, and real estate refinance firms alike. This baseline now functions as the reference point for every newly licensed entity building its internal audit department from day one.
Breaking Down the 13 Principles: Core Clusters Finance Companies Must Master
The 13 principles group naturally into distinct clusters of obligation. Finance companies preparing for supervisory review should organize their internal audit and compliance programs around these clusters rather than treating each principle as an isolated checklist item.
- Board and Audit Committee Oversight: The board carries ultimate accountability for the internal audit function under the SAMA internal audit compliance principles. Directors must approve the internal audit charter, review the annual audit plan, and monitor how management closes out audit findings. The audit committee reviews and approves the audit plan, tracks the implementation of recommendations, and confirms that internal audit activity supports the company’s strategic objectives rather than operating as a disconnected control function.
- Internal Audit Independence and Structure: SAMA requires finance companies to position the internal audit department outside the operational chain of command. The head of internal audit reports functionally to the audit committee, not to the CEO or business line heads, which removes conflicts of interest and protects the objectivity of audit findings. Staffing decisions, budget allocation, and access to records must all support this independence.
- Executive Management Responsibilities: Executive management owns day-to-day implementation of the compliance and audit framework. Management must provide the internal audit and compliance units with adequate resources, respond to audit findings within defined timelines, and escalate unresolved issues to the audit committee rather than allowing them to remain open indefinitely.
- Risk-Based Audit Planning and Methodology: Every finance company must build its annual audit plan on a documented risk assessment. The SAMA internal audit compliance principles require the audit function to define scope, objectives, and methodology for each engagement, ensuring that higher-risk business lines – consumer finance, buy-now-pay-later products, real estate refinancing – receive proportionately deeper audit coverage.
- Compliance Unit Governance: Separate from internal audit, the compliance unit monitors adherence to SAMA regulations and internal policy on an ongoing basis. Finance companies must resource this unit adequately, define escalation paths for regulatory breaches, and ensure compliance officers have direct access to senior management and the board when material issues arise.
- Documentation, Reporting, and Timeliness: Auditors must document testing procedures, evidence, and conclusions in a manner that supports independent review. Reports must reach the board and audit committee within defined timeframes, and findings must include clear remediation deadlines. Weak documentation remains one of the most common gaps SAMA examiners identify during on-site reviews.
- Alignment With Broader SAMA Supervisory Frameworks: The internal audit and compliance principles do not operate in isolation. Finance companies must also align their internal audit scope with SAMA’s Cyber Security Framework, AML/CTF Guide, and debt collection circulars, since examiners increasingly test whether internal audit coverage extends across cyber risk, financial crime controls, and third-party outsourcing arrangements.
Verified Figures Finance Companies Should Track
Regulatory enforcement in Saudi Arabia’s financial sector has become measurably more active. Reported penalty activity linked to SAMA’s Cyber Security Framework alone reached more than SAR 20 million across over 50 violations in a recent 12-month period, underscoring that gaps in governance, audit coverage, or documented controls carry direct financial consequences. SAMA also updates its regulatory frameworks on an annual cycle, which means finance companies cannot treat the 13 principles as a one-time implementation project – internal audit charters, risk assessments, and compliance monitoring plans require periodic refresh to remain aligned with the latest circulars.
Finance companies that already operate mature audit functions still face pressure to demonstrate continuous monitoring rather than point-in-time compliance. SAMA’s supervisory approach increasingly favors evidence of ongoing testing, quarterly access reviews, and board-level reporting over annual self-assessments submitted just before an examination window.
The pace of licensing activity adds further pressure. SAMA has approved new finance companies almost monthly through 2025 and 2026, spanning buy-now-pay-later providers, consumer microfinance firms, and finance aggregation platforms. Each newly licensed entity enters the market already bound by the full 13-principle framework, which means internal audit and compliance functions cannot be treated as a later-stage addition once a company scales. Boards that delay building an independent internal audit department risk falling behind their peers on governance maturity precisely when SAMA’s supervisory attention on the sector is at its highest.
Common Gaps Finance Companies Face When Applying the Principles
Finance companies frequently struggle with a handful of recurring issues when they attempt to implement the SAMA internal audit compliance principles internally. Audit committees sometimes lack members with sufficient financial services experience to challenge management effectively. Internal audit departments often remain understaffed relative to the complexity of consumer finance and buy-now-pay-later product lines. Compliance units in smaller finance companies frequently combine roles that SAMA expects to remain separate, blurring the line between first-line risk ownership and second-line compliance oversight. Documentation standards also vary widely, with many companies unable to produce a clear audit trail linking risk assessments to the annual audit plan and, ultimately, to specific audit findings.
Mapping the 13 Principles to Practical Governance Actions
|
Principle Cluster |
SAMA Expectation |
Practical Action for Finance Companies |
|
Board Oversight |
Approve audit charter and annual plan |
Schedule quarterly board reviews of audit status |
|
Audit Committee Duties |
Monitor recommendation closure |
Track open findings with defined remediation dates |
|
Internal Audit Independence |
Functional reporting to audit committee |
Remove audit head from operational reporting lines |
|
Risk-Based Planning |
Document methodology and scope |
Refresh risk assessment before each annual audit cycle |
|
Compliance Unit Resourcing |
Adequate staffing and authority |
Define escalation matrix for regulatory breaches |
|
Documentation Standards |
Evidence-based, timely reporting |
Standardize audit workpapers and reporting templates |
|
Cross-Framework Alignment |
Coverage of cyber, AML, and outsourcing risk |
Integrate CSF and AML/CTF testing into audit scope |
How Insights KSA Can Help You?
Meeting the SAMA internal audit compliance principles requires more than a policy update – it requires a working internal audit function that survives an on-site SAMA review. As a financial management consultancy company based in the Kingdom, the team works directly with finance companies, real estate refinance firms, and fintech lenders to build internal audit charters, risk-based audit plans, and compliance monitoring programs that map directly to SAMA’s 13 principles.
The engagement typically starts with a gap assessment against the current internal audit and compliance structure, benchmarked line-by-line against each of the 13 principles. From there, the team helps finance companies redesign audit committee terms of reference, restructure reporting lines to protect internal audit independence, and build documented risk assessments that support a defensible annual audit plan. For finance companies expanding into new products such as buy-now-pay-later or consumer microfinance, the team also builds audit coverage models that scale with product risk rather than headcount alone.
Beyond one-time implementation, the team supports finance companies with ongoing internal audit outsourcing and co-sourcing arrangements, quarterly compliance monitoring reviews, and board reporting packages that give directors the evidence SAMA examiners expect to see. Finance companies that have already faced supervisory findings receive targeted remediation support to close documentation gaps and rebuild audit trails before the next review cycle.
FAQs
What are the SAMA internal audit compliance principles?
They are a set of 13 principles SAMA issued for finance and real estate refinance companies operating in Saudi Arabia, covering board and audit committee duties, internal audit independence, risk-based planning, compliance unit governance, and documentation standards. The principles came into force on 2 April 2025.
Which companies must follow the 13 principles?
Finance companies, real estate refinance companies, and related SAMA-regulated lenders operating in the Kingdom must apply the principles, scaled to their size and the complexity of their business activities.
Do the principles apply to banks as well?
SAMA maintains a separate but closely aligned set of internal auditing and compliance principles for commercial banks. Finance companies and banks each follow frameworks tailored to their sector, though the underlying governance concepts overlap significantly.
How often does SAMA update its compliance requirements?
SAMA reviews and updates its regulatory frameworks, including cyber security and internal audit expectations, on an ongoing basis, and finance companies should treat compliance as a continuous process rather than a one-time project.
What happens if a finance company fails to meet the principles?
Non-compliance can trigger supervisory findings, remediation timelines, financial penalties, and in serious cases, restrictions on licensed activities. SAMA has issued significant financial penalties linked to governance and control gaps across the regulated sector.
Can external advisors help implement the principles?
Yes. Many finance companies engage specialized internal audit consultancy services to design audit charters, build risk-based audit plans, and prepare documentation that satisfies SAMA’s expectations ahead of supervisory reviews.
How does internal audit differ from the compliance unit under SAMA’s framework?
Internal audit provides independent, periodic assurance over governance, risk management, and controls, while the compliance unit performs ongoing, real-time monitoring of regulatory adherence. SAMA expects both functions to operate independently of each other and of the business lines they oversee.