21
Regulations covered
273
Rules extracted
1,615
Obligations scored
Largely Compliant
FATF rating
| Capital | Riyadh |
| Population | 36.9M |
| GDP (USD) | $1.1T |
| Currency | Saudi Riyal (SAR) |
| Region | Middle East |
| CPI Score | 52/100 |
| Assessment body | FATF |
| Assessment year | 2024 |
| Overall compliance | Largely Compliant |
| Overall effectiveness | Moderate |
| FATF profile | View source → |
We cover 21 Saudi Arabia regulations with 273 rules and 1,615 obligations scored
Saudi framework for voluntary and regulated carbon credit markets under the Global Carbon Credit Organisation of Merit. Applies to project developers, validators, and market participants in Saudi Arabia.
Saudi environmental protection regulations covering pollution control, waste management, and environmental impact assessments. Applies to industrial facilities and businesses operating in Saudi Arabia.
Saudi national framework targeting tree planting, land restoration, emissions reduction, and marine habitat protection under Vision 2030. Applies to government entities and participating private sector organisations.
Saudi ESG and sustainability disclosure requirements aligned with Vision 2030 covering environmental, social, and governance metrics. Applies to listed companies and large enterprises in Saudi Arabia.
Requires listed companies in Saudi Arabia to disclose environmental, social, and governance information.
Saudi Capital Market Authority rules on board composition, shareholder rights, disclosure, and internal controls for listed companies. Applies to companies listed on the Saudi Exchange (Tadawul).
Saudi employment law governing employment contracts, wages, working hours, leave entitlements, and termination procedures. Applies to employers and employees in the private sector in Saudi Arabia.
NCA cybersecurity controls for cloud computing services covering cloud governance, identity management, and data protection. Applies to organisations using or providing cloud services in Saudi Arabia.
NCA cybersecurity controls for critical national infrastructure covering industrial control systems and operational technology security. Applies to operators of critical systems in Saudi Arabia.
NCA cybersecurity controls for data governance, classification, protection, and privacy across the data lifecycle. Applies to national organisations handling sensitive data in Saudi Arabia.
NCA baseline cybersecurity controls covering governance, defence, resilience, and third-party security for national organisations. Applies to government and critical private sector entities in Saudi Arabia.
NCA cybersecurity controls for remote work covering device security, secure connectivity, and data protection during telework. Applies to national organisations enabling remote work in Saudi Arabia.
SAMA anti-money laundering and counter-terrorism financing requirements covering customer due diligence, transaction monitoring, and suspicious activity reporting. Applies to financial institutions regulated by SAMA.
SAMA framework for open banking covering API standards, data sharing consent, and third-party provider accreditation. Applies to banks and fintech companies operating in Saudi Arabia.
ZATCA e-invoicing regulations requiring electronic generation, validation, and integration of invoices through the FATOORA platform. Applies to VAT-registered taxpayers in Saudi Arabia.
Establishes cybersecurity requirements for financial institutions supervised by the Saudi Arabian Monetary Authority, covering governance, risk management, access control, and incident response. Applies to banks, insurance companies, and finance companies operating in Saudi Arabia.
Regulates the collection, processing, disclosure, and retention of personal data in Saudi Arabia, establishing data subject rights and controller obligations. Applies to organizations processing personal data of individuals within the Kingdom of Saudi Arabia.
Run probabilistic risk scores across 1,615 Saudi Arabia obligations. See exactly where your gaps are.
Get started