Requirements
What the regulation expects

Mandatory for SAMA member organisations
Banks, insurance, financing and credit bureaus. Cryptography and IAM are the two controls a KMS is bought against.
Cryptographic standard as configuration
3.3.9 expects a defined, approved and implemented crypto standard. Attach platform configuration as the implementation record.
Privileged access without standing rights
JIT elevation and time-boxed impersonation instead of permanent admin, with session revocation across the cluster.
Periodic access review with a starting point
Privilege-creep audit output so the review starts from findings, not a blank spreadsheet.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Enforced approved solutions catalogue, key states for archive and recovery, exportable inventory for examiners.
Learn moreMicrosoft 365 Customer Key & DKE
Customer-held keys for mail and files that sit alongside core banking controls.
Learn moreSQL & database encryption
External key control for database encryption without redesigning every application first.
Learn moreKey themes
Where independent key control fits
Map product evidence to the SAMA Rulebook control text. The two controls below are the ones that typically drive a KMS purchase.
3.3.9 Cryptography
Approved solutions, restrictions, and key lifecycle including archiving and recovery, enforced as catalogue plus key states rather than a document alone.
3.3.5 Identity and access management
Need-to-know / least privilege, MFA for sensitive systems, privileged and remote access management, and dated access review reports.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
