Most conversation about financial regulation in the Kingdom concerns cybersecurity and data: the NCA's controls, SAMA's Cyber Security Framework, the PDPL. Those matter. But for a Chief Audit Executive at a Saudi bank, none of them is the document that governs your function.
That document is SAMA's Principles of Internal Auditing for Local Banks Operating in Saudi Arabia, effective 26/4/1443H — 1 December 2021 — and applying to every local bank in the Kingdom. It is one of three layers governing internal audit in Saudi Arabia, and by some distance the most prescriptive. It is short, specific, and considerably more prescriptive than most functions treat it.
The nine principles
The framework is organised around nine principles, and the ordering is deliberate: it starts with the people who are supposed to protect the function's independence, not with the function itself.
| # | Principle |
|---|---|
| 1 | Board responsibilities for internal audit |
| 2 | Responsibilities of the audit committee towards the unit |
| 3 | Roles and responsibilities of executive management regarding internal audit |
| 4 | Key characteristics of the unit |
| 5 | Internal audit policy |
| 6 | Organisation, tasks and responsibilities of the unit |
| 7 | Scope of the unit's work |
| 8 | The unit's relationship with second-line-of-defence units and external auditors |
| 9 | Internal audit of the bank's subsidiaries |
Three principles are spent on the board, the committee and executive management before the rules turn to the audit unit at all. That is the same instinct behind Domain III of the 2024 Global Internal Audit Standards: an audit function's independence is a condition others must establish, not something the CAE can create alone.
The reporting line is not a matter of preference
SAMA states it plainly: the head of internal audit reports functionally to the audit committee and administratively to the CEO.
That split is the entire mechanism of independence. Functional reporting — the plan, the findings, the opinion, the budget — runs to a committee the executive does not sit on. Administrative reporting — day-to-day logistics — runs to the CEO. When those two lines get confused in practice, and the committee only ever sees what management has already reviewed, the structure is intact on paper and hollow in operation.
What the audit committee actually owns
Under Principle 2, the committee's responsibilities are concrete rather than advisory. It recommends board approval of the unit's organisational structure, recommends the appointment and dismissal of its head, reviews the audit plan and strategy, approves the function's performance indicators, and ensures corrective actions are implemented on time.
And one requirement that catches functions out: the committee must arrange an independent external quality assessment at least once every five years. That is not a soft expectation. It is a periodic, external verdict on whether the function does what it claims — and it converges with the QAIP requirements in the IIA 2024 Standards.
The policy is a control document, not a formality
Principle 5 requires an internal audit policy that addresses purpose, scope, organisational position, authority, relationships with other units, and the function's right to access records and escalate to the audit committee.
Read that list again as a set of controls rather than a table of contents. Each item is something a supervisor can test. "Right to access records" is either evidenced by engagements that reached the data they needed, or contradicted by a trail of access that was refused and never escalated.
What this means for how the function is run
None of these principles is difficult to agree with. The difficulty is evidencing them on demand, years after the fact, across a whole audit universe.
A function running on spreadsheets and email can assert that the committee approved the plan, that findings were tracked to closure, and that the reporting line held. Producing the trail is another matter — and the external quality assessment every five years is precisely the moment somebody asks for it.
That is the case for running the lifecycle inside audit management software built around the standard rather than adjacent to it: the plan carries version history against committee approval, sign-off is captured as the work happens rather than reconstructed, and coverage against the universe is a live view instead of an annual reassembly. The Saudi-specific deployment and residency detail sits on our audit management software for Saudi Arabia page, and the vendor landscape on best audit management software in Saudi Arabia.
Explore VistaPlan or request a demo.
Sources
- SAMA Rulebook — Principles of Internal Auditing for Local Banks Operating in Saudi Arabia
- SAMA Rulebook — Principle (9): Internal Audit of the Bank's Subsidiaries
- Pinsent Masons — Saudi Central Bank introduces new principles for internal auditing and compliance
- IIA — 2024 Global Internal Audit Standards