A Saudi bank asked us a question worth writing down: "We're SAMA-regulated. Does the NCA's ECC apply to us as well, and if it does, are we running two programmes?"
The answers are probably yes and definitely not. Here is how to reason about it.
Two supervisors, two mandates
SAMA — the Saudi Central Bank — supervises licensed financial institutions: banks, insurers, finance companies, fintechs, payment service providers and money exchangers. Its BCM Framework is a business continuity mandate, examined through routine supervisory cycles, with findings tracked to closure.
The NCA — the National Cybersecurity Authority — owns national cybersecurity policy. The Essential Cybersecurity Controls apply to government bodies and Critical National Infrastructure operators, with continuity appearing inside the Cybersecurity Resilience domain.
The two are complementary rather than competing. Neither supersedes the other, and being examined by one is not a defence with the other.
Working out whether both apply
The practical test for a financial institution:
| Situation | SAMA BCM | NCA ECC |
|---|---|---|
| SAMA-licensed, not CNI-designated | Applies | Not mandatory (often adopted voluntarily) |
| SAMA-licensed and meets CNI criteria | Applies | Applies |
| Government-owned financial entity | Applies if licensed | Applies |
| Fintech / PSP, small, not CNI | Applies | Not mandatory, increasingly expected commercially |
The determining variable is Critical National Infrastructure designation, not size or licence type. Large banks operating payment rails, core clearing functions or systemically important services are the population most likely to sit under both. If you are unsure of your own designation, that is a question for your regulatory affairs function and the NCA directly — not one to infer from a table.
Where the two overlap
Substantially, in the resilience space. Both want:
- Critical services identified and prioritised
- A business impact analysis with defensible recovery objectives
- Continuity and disaster recovery plans that are current and owned
- An exercise programme with evidence of execution
- Findings tracked to closure
- Governance with named accountability above the BCM function
If you have built a SAMA-grade BCM programme, you already have the artefacts. What changes under ECC is the scenario emphasis — cyber-driven disruption becomes a first-class case rather than one risk among many.
Where they diverge
Four differences that matter operationally.
Sector specificity. SAMA's expectations are banking-shaped: committee composition, periodic submissions, Arabic documentation, data residency, examination cycles. ECC is sector-neutral and applies the same controls across government, energy, telco and healthcare.
The cyber lens. SAMA's BCM Framework treats cyber as one disruption cause among several. ECC's continuity expectations exist because of cyber threat — every resilience control is read through a compromise scenario.
Third-party emphasis. Both care about vendors, differently. SAMA's concern is concentration risk and outsourcing governance in financial services. ECC's third-party domain is supply-chain security and third-party incident response.
How you're examined. SAMA examines through supervisory cycles with sampled evidence and a findings-and-closure process practitioners know well. NCA supervisory review is a different rhythm with different reviewers. Prepare the same evidence; expect different questions about it.
Running one programme for two supervisors
The failure mode is a second parallel programme — a "cyber continuity" workstream running alongside the SAMA programme, with its own BIA, its own plans and its own exercise calendar. It doubles the maintenance burden and produces contradictory artefacts within two quarters. When two versions of the same recovery objective disagree, both supervisors have a finding.
The workable structure:
- 1
One BCMS, one artefact set
A single management system produces the BIA, the plans, the exercises and the improvement register. Build it to ISO 22301 structure — both frameworks accept it as the underlying machinery.
- 2
Scenario coverage as the union of both
Your scenario library covers SAMA's operational disruptions and ECC's compromise cases. Same critical services, wider scenario set, one BIA.
- 3
Two mapping layers, not two programmes
Maintain a mapping from artefacts to SAMA requirements, and a second mapping to ECC resilience expectations. The artefacts are shared; only the mappings are supervisor-specific.
- 4
One evidence repository, two views
Assemble a SAMA submission pack and an ECC evidence pack from the same source of record. If preparing either requires reconstruction, that is the problem to fix first.
- 5
Governance that names both
The BCM committee charter should name both supervisory obligations explicitly. Split governance is where dual-regulated programmes drift apart.
The SAMA BCM committee charter guide covers the governance layer; extending its scope statement to name NCA obligations is a small edit with disproportionate value at review time.
What each supervisor asks first
Useful for prioritising if you're preparing for both:
- SAMA tends to open on governance and currency — is there an active committee, when did it last meet, when was the BIA last refreshed, when was the plan last exercised. The opening-meeting script covers the pattern.
- NCA ECC review tends to open on scenario coverage and recovery integrity — can you restore from clean backup, have you tested it, what happens if the recovery environment is compromised.
Both close on the same thing: findings raised, owned and closed. A programme that can show a closed loop satisfies the hardest question either supervisor asks.
Where tooling helps
One platform holding one artefact set, capable of producing supervisor-specific views. The SAMA BCM compliance software mapping covers the SAMA side requirement by requirement; the NCA ECC resilience controls page covers the ECC resilience domain and is explicit about the ECC domains that belong to your security stack rather than a BCM platform.
Frequently asked questions
Does SAMA compliance mean we're covered for NCA ECC?
No. A SAMA-grade BCM programme covers most of the structural expectations of the ECC resilience domain, but ECC's cyber framing adds requirements around backup integrity, clean recovery and the incident-response handoff. It also covers four other domains a BCM programme does not touch at all.
Are we CNI just because we're a bank?
Not automatically. Designation depends on criteria around systemic importance and the services operated, not licence type alone. Larger institutions operating payment rails or clearing functions are the most likely population. Confirm designation formally rather than inferring it.
Should we maintain separate evidence packs?
Separate packs, yes — assembled from one shared repository. Separate source artefacts, no. The packs are views; duplicating the underlying BIA or plan set creates drift that produces findings with both supervisors.