17- The institution issued these principles under the powers granted to it and its supervisory and regulatory responsibility as follows:
A. The Law of the Saudi Arabian Monetary Authority, issued by Royal Decree No. (23) dated 23/05/1377 AH.
B. The Banking Control Law, issued by Royal Decree No. (M/5) dated 22/02/1386 AH.
C. The Anti-Money Laundering Law issued by Royal Decree No. (M/20) dated 05/02/1439 AH and its executive regulations issued under the decision of the Presidency of State Security No. (14525) dated 11/02/1439 AH.
D. The Anti-Terrorism Crimes and Financing Law issued by Royal Decree No. (M/21) dated 12/02/1439 AH and its executive regulations issued under the decision of the Council of Ministers No. (228) dated 02/05/1440 AH.
18 - The institution issued these principles as the first update to the compliance guide for banks operating in the Kingdom of Saudi Arabia, issued under Circular No. 56202 / M A T / 787 dated 19/12/1429 AH. This issuance is part of the institution's efforts aimed at continuously improving and addressing banking regulatory issues and enhancing sound practices in banking institutions, and the continuous affirmation that bank officials should be convinced that compliance policies and procedures are effective and implemented, and that senior management has appropriate corrective procedures to address any instances of non-compliance or deficiencies when detected.
19- Compliance with regulations and instructions begins at the top of the hierarchy, where the Chairman and members of the Council and senior management must be role models in managing work and compliance.
20- Good compliance from senior management requires a continuous affirmation that a culture based on high standards of integrity and professional ethics must prevail. Compliance should be an integral part of the bank's culture and should not be limited to the compliance unit staff only, as the responsibility for compliance lies with every individual working in the bank, and this responsibility should be an integral part of the bank's operations and all operational activities, achieving high standards in executing its work through its continuous endeavor to adhere to the spirit and text of the law. It should be taken into account that the results of the bank's actions related to shareholders, clients, employees, and its market environment may lead to significant negative reactions affecting its reputation and causing harm, even if there is no actual violation of the regulations.
21- The standards of trust and integrity are the core values and the highest rank in the relationship between the bank and its clients, and the most important pillars upon which the bank builds its reputation with its clients and the entities it deals with. Reputation protection should be a constant characteristic in the minds of managers and employees in all their activities. They must exhibit a high level of trust, integrity, and professionalism when performing their assigned tasks, and their actions must always comply with the text and spirit of the regulations and instructions governing the banking sector and its personnel.
22- These principles establish a framework for compliance governance in the bank consisting of the Council and its responsibility to approve the compliance policy and oversee the management of non-compliance risks, senior management and its responsibility to manage non-compliance risks, and the compliance unit and its responsibility for the overall coordination of compliance and supporting senior management.
23- These principles initially define the responsibilities placed on the Council and senior management regarding compliance as a primary importance, followed by the principles that should support the compliance unit within the bank.
24- Compliance systems, rules, and standards include issues such as: adherence to appropriate market practice standards, managing conflicts of interest, treating clients fairly, ensuring the suitability of advice provided to clients, and covering specific areas such as: anti-money laundering, combating the financing of terrorism, preventing the proliferation of weapons, the Know Your Customer principle, combating financial fraud, combating corruption, and addressing reports of violations.
25- Compliance systems, rules, and standards are based on multiple sources, including the regulations and instructions applicable to the banking sector under the supervision of the institution, the regulations and instructions overseen by other official authorities with jurisdiction, or in other countries where banks conduct their operations, prevailing banking customs, business practice rules supported by sector institutions, internal conduct rules applicable to bank employees, standards of integrity and ethical conduct, and relevant requirements issued by international organizations and groups specialized in formulating policies governing the supervision of banking and financial institutions, such as the Basel Committee on Banking Supervision and others.
26- Compliance principles require that the compliance unit be independent and adequately supported with resources, that its responsibilities be clearly defined, and that its activities be subject to independent and periodic review by the internal audit unit. This will be elaborated in principles (5) to (8) below in more detail, all reflecting the effectiveness of the compliance unit's work.
27- The compliance unit and function in banks are among the most important foundations and success factors, as they play a crucial role in maintaining the bank's reputation and credibility and protecting the interests of shareholders and depositors, and providing protection from penalties. This is achieved through its contributions as follows: .
● Mitigating non-compliance risks, particularly systemic risks, reputational risks, and financial penalty risks.
● Strengthening the relationship with regulatory and supervisory authorities and considering their communicated observations to periodically identify and address deficiencies before they escalate.
● Contributing to establishing principles of sound management and governance in banks.
● Ensuring compliance with what is issued by supervisory and regulatory authorities in particular and competent authorities in general from regulations and instructions.
● Creating appropriate mechanisms and frameworks to combat money laundering, financing of terrorism, preventing the proliferation of weapons, financial fraud, and corruption, and providing insights and advice to address and correct deficiencies and violations.
● Taking necessary actions to address reports received from bank personnel and stakeholders regarding violations consistent with the reporting policy for violations at financial institutions issued by the institution to ensure objective and escalating treatment and to formulate a corrective action plan.
● Upholding values and professional practices in banking work.
● Raising awareness among bank employees and clarifying the positives and negatives regarding their compliance and the risks of non-compliance with the regulations and instructions issued by the relevant regulatory and supervisory authorities.
28- The bank must organize its compliance unit in such a way that prioritizes managing non-compliance risks in a manner consistent with its risk unit strategy.
29- It should be recognized that the extent of the compliance framework and the diversity and complexity of compliance rules and their sources place the responsibility for managing non-compliance risks and verifying compliance levels and establishing necessary controls to ensure compliance, whether at the level of work procedures or technical systems and data protection, on senior management and all operational units (groups and business sectors) through doing what is necessary for review and ensuring effective and continuous application, while the role of the compliance unit is limited to identifying, communicating, and explaining the regulations and instructions to business sectors immediately upon receiving them from the supervisory and regulatory authorities and other competent entities and obtaining confirmation from them, ensuring their inclusion in policies and procedures, and conducting continuous monitoring to identify, discover, and assess non-compliance risks periodically and report violations of compliance systems, rules, and standards and raise reports regarding non-compliance risks and violations.
30- The compliance principles apply to all commercial banks operating in the Kingdom and their branches and locations in foreign countries where they conduct banking operations unless they conflict with the regulations and instructions of those countries, representing the minimum necessary to achieve effective compliance in general and the compliance unit and its function in particular, and the institution expects adherence to higher sound practices.
31- These principles should be read and applied alongside a number of related instructions for the unit's operations, including but not limited to the following:
● The main principles of governance in banks and financial institutions operating in the Kingdom of Saudi Arabia.
● Principles of conduct and work ethics in financial institutions.
● Anti-Money Laundering and Combating the Financing of Terrorism Guide.
● Banking account rules.
● Regulatory rules for the operation of self-supervisory units and committees.
● Anti-Financial Fraud Guide.
● Internal control guidelines.
● Framework for Sharia governance for local banks and financial institutions operating in the Kingdom.
● Reporting policy for violations at financial institutions.
● Instructions issued regarding risk management.
● Requirements for appointment to leadership positions in financial institutions subject to the institution's supervision.
● Instructions for outsourcing tasks to third parties.