There is a persistent confusion in how the Saudi market talks about audit technology. Ask what an internal audit function in the Kingdom must comply with, and the answer that comes back is usually a list of cybersecurity and data frameworks: the NCA's Essential Cybersecurity Controls, SAMA's Cyber Security Framework, ISO 27001, the PDPL.

Those are real obligations. But for a Chief Audit Executive they are audit subjects, not audit rulebooks. They describe controls the function will examine. None of them says anything about how the function itself is governed, who it reports to, how often it must cover its universe, or how its quality is assessed.

Three other documents do. This is what each asks for, and where the detail lives.

Layer 1 — The IIA 2024 Global Internal Audit Standards

Effective 9 January 2025, the 2024 Standards replaced the 2017 IPPF with a single restructured rulebook: five domains, fifteen principles, fifty-two standards. Saudi functions adopt them directly; there is no local grace period beyond the global effective date.

Two changes matter most in day-to-day practice. Governance moved to the centre — Domain III sets out conditions the board must establish, and CAEs are explicitly responsible for keeping the board well-informed. And Standard 9.4 requires the risk assessment behind the plan to be documented and reviewed at least annually.

What internal auditors in Saudi need to know about the new IIA StandardsWhy your audit universe can't be a once-a-year fileWriting a charter that satisfies both the Standards and SAMA

Layer 2 — The CMA's Corporate Governance Regulations

For any company listed on Tadawul, the Capital Market Authority sets the governance frame. The audit committee is mandatory, comprises three to five non-executive members with at least one independent director, and internal audit is supervised by it.

That supervisory line is the architecture of independence for a listed Saudi company: the plan is approved by a body management does not sit on, and findings reach it without an executive filter.

The CMA's audit committee rules and internal audit

Layer 3 — SAMA's Principles of Internal Auditing (banks)

For local banks, SAMA adds the most prescriptive layer in the stack. Effective 1 December 2021, nine principles govern the function — and the specifics go well beyond what most governance codes attempt.

SAMA's Principles of Internal Auditing: what Saudi banks must get rightThe three-to-four-year audit cycle and universe coveragePreparing for the five-year external quality assessment

Where the layers stack

A listed Saudi bank sits under all three simultaneously, and they are not alternatives — the strictest requirement in each area governs.

Requirement IIA 2024 CMA (listed) SAMA (banks)
Audit committee Board conditions (Domain III) Mandatory, 3–5 non-executive Mandatory
Reporting line Functional to the board Supervised by the committee Functional to committee, administrative to CEO
Head of function CAE role defined SAMA prior non-objection
Risk assessment Documented, annual (9.4) Formal framework, annual review
Coverage cycle Risk-based 3–4 years by risk class
External assessment At least every 5 years At least every 5 years

The thread running through all of it

Read together, the three layers ask for the same thing in different registers: evidence rather than assertion.

Documented, not intended. Traceable, not remembered. Refreshed, not filed. A function can satisfy every one of these obligations on paper and still be unable to produce the trail when a quality assessor, a committee chair or a supervisor asks for it — and the gap between the two is almost always a tooling problem rather than a methodology one.

That is the argument for running the lifecycle inside audit management software built around the standard: the universe stays live and versioned, the plan carries its committee approval as a state, sign-off is captured as the work happens, and findings are tracked to a verified close with escalation that operates by default.

For Saudi functions weighing that decision, the deployment, residency and Arabic detail sits on our audit management software for Saudi Arabia page, and an honest look at the vendor landscape on best audit management software in Saudi Arabia.

Explore the platform or request a demo.

Sources