Last updated
What’s inside
SAMA's Cybersecurity Framework requires Level 3 maturity across all regulated entities, but audit-green does not mean secure. Institutions that satisfied SAMA's MFA requirement with SMS OTP did exactly what the framework asked and left the underlying risk intact.
This whitepaper traces how Saudi financial institutions arrived at that position, and what genuine alignment with SAMA's identity requirements actually demands.
It covers:
Why SMS OTP satisfies SAMA's MFA requirement without addressing the risk that requirement was designed to mitigate
How centralized identity repositories created by KYC and AML compliance obligations became the attack surface SAMA's Cloud Policy is trying to prevent
What genuine SAMA alignment requires at the identity layer, and why legacy IAM investments leave it uncovered
The architectural alternative that meets NIST IAL3 and AAL3 standards while removing the centralized PII store entirely
How 1Kosmos delivers phishing-resistant, biometrically verified authentication built for SAMA-regulated environments
Audit-compliant and secure are not the same thing
An institution operating with interceptable MFA and a centralized identity store can pass a SAMA audit and still be one compromised credential away from a breach that affects every customer on record.
The compliance criteria as written do not catch this. SAMA's framework pushes toward a higher standard, and most audit processes miss the distinction.
Closing that gap requires replacing password-and-OTP architectures with FIDO2-certified, biometrically verified authentication, and replacing centralized PII databases with decentralized architectures that remove the honeypot before it becomes a target.
Download the whitepaper
The full threat data, compliance analysis, architectural framework, and implementation guidance for SAMA-regulated financial institutions are inside.
Download the whitepaper for a complete look at what SAMA's Cybersecurity Framework demands at the identity layer, and how 1Kosmos delivers it.

