SAMA transaction monitoring requirements, mapped to system features
Section 7 of SAMA's Anti-Money Laundering and Counter-Terrorism Financing Guide (circular 18318/486, November 2019) covers the monitoring of transactions and activities. Below: what it requires, what that means for a monitoring system, and which parts Marqib's pilot build covers.
Reviewed · Educational material, not legal advice.
Legal basis
Section 7 rests on Article 13 of the Anti-Money Laundering Law and Article 69 of the Law on Combating Terrorism Crimes and its Financing. Both require the financial institution to monitor transactions, documents and data continuously against what it knows of the customer, with particular attention to unusual transactions and to higher money-laundering and terrorist-financing risk.
Marqib is not yet deployed in Saudi Arabia, and goAML filing for the Kingdom is on the roadmap. This page is for firms assessing their monitoring against SAMA's text.
Requirement by requirement
| SAMA requires | What the system should do | In Marqib |
|---|---|---|
| Monitoring measures based on the risk assessment, documented and approved at senior management level (7.1). | Rules and thresholds on record, with an approval trail. | Threshold changes proposed, backtested and approved by a second MLRO; each approval in the audit log. |
| Risk-based monitoring: enhanced for high-risk customers; simplified for low-risk, but no customer drops out of monitoring (7.2, 7.3). | Customer risk drives rule scope and queue order. | Customer risk score from static and dynamic factors, used to order the queue. New in the pilot build. |
| Tools that detect unusual transactions, patterns and activity at the time of execution or before, with adequate staff (7.4a). | Detection timing suited to each product; pre-execution controls where needed. | Marqib runs overnight on end-of-day data and does not screen transactions before execution. Pair it with pre-execution controls where 7.4(a) requires them. |
| Indicators and patterns matched to the firm's risks and to current methods, kept up to date (7.4b, 7.9). | A typology library the firm can extend, with a record of which typology each rule covers. | Six deterministic typology rules and a coverage matrix; firm-specific rules in the same framework. |
| Electronic systems, because manual monitoring alone is not enough, integrated with core systems and linked to customer risk classification (7.5). | Automated monitoring on the firm's full data, fed from core systems. | Reads end-of-day files from the trading platform, CRM and payment systems; each case carries the customer's risk band. |
| Periodic testing of the monitoring tools, with documented results (7.6). | Repeatable tests with stored results. | Rule backtests with above- and below-the-line comparison, stored against the threshold version they tested. |
| Ongoing monitoring until the relationship ends; customer information and risk category updated from the results (7.7). | Monitoring results feed back into customer risk. | The dynamic part of the risk score uses cases, STRs, turnover against declared turnover, and linked clients. |
| Trained staff; no reliance on systems alone (7.8). | Case files a trained reviewer decides on. | Every case goes to a named reviewer; maker-checker with reason codes; nothing is filed without approval. |
| Key positions that could be targeted for ML/TF identified and their holders monitored (7.10). | Monitoring of staff in sensitive roles. | Not covered: an internal control outside Marqib's data. |
Paragraph 7.6 says the tools are tested "periodically (Once a year a maximum)". We read that as at least once a year; confirm the reading against SAMA's text or with your adviser.
Language models
Section 7 does not mention language models. In Marqib, detection is rule-based and deterministic; where drafting is enabled, the model only writes text from evidence rows, with identifiers tokenised first.
Sources
- SAMA Rulebook, AML/CTF Guide, Section 7: Monitoring of Transactions and Activities
- SAMA Rulebook, The Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) Guide
Questions
Does SAMA require real-time monitoring?
Paragraph 7.4(a) asks for tools that detect unusual transactions at the time of execution or before, commensurate with the risks identified. How far that applies to each product follows from the firm's risk assessment. Overnight monitoring alone may not meet it for every product.
Is manual monitoring acceptable?
Not on its own. Paragraph 7.5 says manual monitoring alone is not sufficient and requires effective electronic systems commensurate with the firm's risk.