Plenty of audit functions in the Kingdom can produce a risk-based annual plan. Far fewer can answer the question SAMA's rules actually ask, which is a different one: can you show that every auditable unit in the bank will be reached within a defined cycle, and that the cycle is driven by a documented risk framework?
That is a coverage question, not a planning question, and it is where a lot of otherwise well-run functions are thin. It sits inside the wider stack of rules governing internal audit in the Kingdom.
What the rules require
SAMA's internal auditing principles set out the expectation in unusually concrete terms.
Four obligations, and each one fails differently.
1. The universe has to be complete, not convenient
"All operational units, products, services, systems, risks and processes" is a broader definition than most audit universes actually carry. A universe assembled from the org chart will list departments. It will not necessarily list products — a specific financing product with its own control profile — or systems, or the risks that cut across several departments at once.
The common failure is quiet: a universe that looks complete because everything on it has been audited, while the things missing from it have never been considered at all.
2. The risk framework has to be formal
SAMA asks for an official framework for assessing each unit's risk, and names the factors it expects to see weighed: prior audit assessments, time since the last audit, risk level, and complexity.
Note the second one. Time since last audit is a risk factor in its own right, which is the regulator saying that coverage decay is a risk even where nothing else has changed. A scoring model that only reflects inherent risk, and never ages, will systematically under-rate the units nobody has looked at in three years.
3. The universe has to be reviewed annually
This converges with Standard 9.4 of the IIA 2024 Standards, which requires the risk assessment underpinning the plan to be documented and reviewed at least annually. SAMA asks the same of the universe: an annual completeness-and-coverage review.
A universe maintained in a workbook makes this an exercise in re-keying. Someone re-scores entities by hand, re-versions the plan, and hopes nobody asks to see how the previous version differed.
4. The cycle has to be evidenced
This is the requirement that most rewards a system and most punishes a spreadsheet. A three-to-four-year cycle means coverage is a claim about the past and the future simultaneously: what has been audited, when, and what the rotation says comes next.
Answering "which units have not been audited within the cycle, and why" should take a query, not a fortnight of reconciliation. When the external quality assessment arrives — SAMA requires one at least every five years — that is exactly the question that gets asked.
What good looks like
A function that meets these four obligations comfortably tends to share the same shape:
- The universe is a living register of entities, products, systems and risks, not a tab in the planning workbook.
- Each entity carries weighted risk factors — including time since last audit — that re-score continuously rather than annually.
- The plan is generated from that scoring, with version history against committee approval.
- Coverage against the cycle is a standing report: what is in the universe, what has been reached, what is overdue, and how the multi-year rotation resolves it.
That is precisely the job VistaPlan does inside ControlVista's audit management software — the universe stays alive, the plan is derived from it with a traceable trail, and coverage against a multi-year cycle is a live view rather than an annual reconstruction. The Kingdom-specific detail is on our audit management software for Saudi Arabia page.
Explore VistaPlan or request a demo.