SAMA Cloud Compliance: What Banks Need to Check Before Moving to the Cloud
By Hafiya Kadhija 29-08-2026 2
Cloud adoption is transforming the banking industry by helping financial institutions improve scalability, operational efficiency, innovation, and customer services. However, moving banking workloads to the cloud also introduces new cybersecurity, data protection, third-party, and regulatory considerations. Saudi Central Bank cybersecurity compliance should therefore be considered from the beginning of any cloud migration strategy, rather than treated as a requirement to address after implementation.
For banks operating in Saudi Arabia, cloud adoption requires careful planning, risk assessment, vendor due diligence, contractual controls, data protection, access management, monitoring, business continuity, and exit planning. A structured approach helps banks take advantage of cloud technology while maintaining appropriate security and regulatory controls.

Why Is Cloud Compliance Important for Banks?
Banks manage highly sensitive information, including customer data, financial transactions, authentication credentials, and confidential business information. Moving this information to a cloud environment changes how systems are hosted, accessed, monitored, and managed.
Cloud environments can introduce risks such as:
Unauthorized access
Data exposure
Misconfigured cloud resources
Third-party security weaknesses
Inadequate monitoring
Data residency concerns
Service availability issues
Vendor dependency
Difficulties during provider exit
Cloud compliance helps banks establish appropriate controls to manage these risks and demonstrate that security requirements remain effective after migration.
1. Conduct a Cloud Security Risk Assessment
Before moving workloads to the cloud, banks should perform a detailed cybersecurity risk assessment.
The assessment should identify the type of information being moved, the systems involved, potential threats, security requirements, and the possible impact of a cloud-related incident.
Banks should consider:
Data sensitivity
Business-critical applications
Customer information
Regulatory requirements
Cloud service model
Access requirements
Potential attack scenarios
Service availability
Third-party dependencies
The risk assessment should not be a one-time activity. Cloud environments change continuously, so risks should be reviewed when systems, services, vendors, or configurations change.
2. Perform Cloud Service Provider Due Diligence
Choosing a cloud service provider is one of the most important decisions in a banking cloud migration.
Banks should evaluate the provider's security capabilities before signing an agreement or transferring sensitive information.
Vendor due diligence should examine areas such as:
Cybersecurity controls
Security certifications
Data protection practices
Identity and access management
Encryption capabilities
Security monitoring
Incident response
Business continuity
Disaster recovery
Vulnerability management
Subcontractor management
Data center locations
Audit and assessment capabilities
Banks should also understand the provider's responsibilities and distinguish them from the bank's responsibilities under the cloud shared-responsibility model.
3. Check Data Residency and Data Location
Data location is a critical consideration for banks moving to cloud infrastructure.
Before selecting a cloud service, organizations should understand where their data will be stored, processed, and backed up. They should also determine whether data may be transferred to other geographic locations through replication, disaster recovery, support operations, or subcontractors.
Banks should document:
Primary data storage locations
Backup locations
Disaster recovery locations
Data processing locations
Cross-border data transfers
Subcontractor access
Data deletion processes
Data residency requirements should be incorporated into cloud architecture, contracts, risk assessments, and ongoing monitoring.
4. Review Cloud Contracts Carefully
A cloud provider contract should clearly define cybersecurity and operational responsibilities.
Banks should avoid relying solely on standard vendor terms without evaluating whether those terms address their regulatory and security requirements.
Important contractual areas may include:
Security responsibilities
Data ownership
Confidentiality
Data location
Incident notification
Security monitoring
Audit rights
Assessment rights
Business continuity
Disaster recovery
Subcontractor requirements
Data return
Secure data deletion
Termination rights
Contractual security requirements should align with the bank's risk assessment and internal policies.
5. Strengthen Identity and Access Management
Cloud environments can involve administrators, employees, contractors, service accounts, applications, and third-party users.
Strong identity and access management is therefore essential.
Banks should implement appropriate controls such as:
Role-based access
Least-privilege permissions
Multi-factor authentication
Privileged access management
Strong password controls
Regular access reviews
Automated account deprovisioning
Separation of duties
Monitoring of privileged activity
Access should be granted according to business requirements and removed promptly when it is no longer necessary.
6. Protect Data Through Encryption and Segregation
Sensitive banking information should be protected throughout its lifecycle.
Encryption can help protect data both while it is being transmitted and while it is stored. Banks should understand the encryption capabilities provided by the cloud provider and determine how encryption keys are managed.
Key management considerations include:
Who controls encryption keys
Where keys are stored
Who can access keys
How keys are rotated
How key access is monitored
What happens to keys when services are terminated
Banks should also ensure that their data is logically separated from other customers' data within shared cloud environments.
7. Establish Cloud Security Monitoring
Moving infrastructure to the cloud does not eliminate the need for security monitoring.
Banks should have appropriate visibility into cloud activity, including authentication events, administrative actions, configuration changes, network activity, and security alerts.
Monitoring should help identify:
Suspicious login attempts
Privilege escalation
Unauthorized configuration changes
Unusual data access
Malicious activity
Abnormal network traffic
Potential data leakage
Logs should be appropriately protected, retained, and reviewed according to the bank's security and operational requirements.
8. Plan for Business Continuity and Disaster Recovery
Cloud adoption should support resilience rather than create a single point of failure.
Banks should determine how critical services will continue operating if the cloud provider experiences an outage, cyber incident, connectivity problem, or other disruption.
Cloud disaster recovery planning should consider:
Recovery time objectives
Recovery point objectives
Backup strategies
Replication
Alternative infrastructure
Network dependencies
Application dependencies
Disaster recovery testing
Recovery plans should be tested periodically to determine whether critical services can actually be restored within the required timeframes.
9. Maintain Audit and Assessment Rights
Banks need sufficient visibility into the security practices of their cloud providers.
Contracts should address appropriate rights to conduct or obtain security reviews, audits, assessments, and examinations.
Where direct audits are not practical, banks may need alternative evidence such as independent assessment reports, security certifications, penetration testing summaries, control reports, or other assurance documentation.
The objective is to maintain sufficient oversight of the provider's security environment.
10. Prepare a Cloud Exit Strategy
One of the most overlooked areas of cloud compliance is exit planning.
Before entering a cloud agreement, banks should understand how they would migrate away from the provider if the relationship ended.
An effective exit strategy should address:
Data retrieval
Data migration
Application migration
Backup recovery
Contract termination
Transition responsibilities
Service continuity
Secure data deletion
Verification of deletion
Banks should ensure that they can retrieve their information in an appropriate format and that the provider has clearly defined obligations when the relationship ends.
Common Cloud Compliance Mistakes Banks Should Avoid
Several mistakes can increase cloud security and compliance risks.
1. Moving Too Quickly
Migrating workloads without completing risk assessments and security reviews can create unnecessary exposure.
2. Assuming the Provider Handles Everything
Cloud security is generally a shared responsibility. Banks remain responsible for understanding and managing their own security obligations.
3. Ignoring Data Location
Organizations should understand where information is stored, processed, replicated, and backed up.
4. Relying Only on Certifications
Security certifications can provide useful assurance, but banks should also assess whether the provider's controls address their specific risks and requirements.
5. Forgetting Exit Planning
A cloud strategy should consider not only how to move into the cloud but also how to safely transition away from a provider.
Cloud Compliance Checklist for Banks
Before moving a banking workload to the cloud, organizations should ask:
Has a cloud security risk assessment been completed?
Has the cloud provider undergone appropriate due diligence?
Is the data classification documented?
Are data locations understood?
Are security responsibilities clearly defined?
Does the contract contain appropriate cybersecurity requirements?
Are access controls and MFA implemented?
Is sensitive data appropriately protected?
Are cloud activities monitored?
Are incident response procedures defined?
Are business continuity and disaster recovery plans tested?
Are audit and assessment rights addressed?
Is there a documented cloud exit strategy?
Can the bank retrieve and securely delete its data when required?
Conclusion
Cloud computing can provide significant benefits to banks, but successful cloud adoption requires security and compliance to be built into the migration process from the beginning. Risk assessment, provider due diligence, data residency, contractual controls, identity management, encryption, monitoring, resilience, audit rights, and exit planning should all form part of a comprehensive cloud compliance strategy.
For banks in Saudi Arabia, the goal should not simply be to move applications and data to the cloud. The objective is to create a secure, resilient, well-governed cloud environment that protects customer information and supports regulatory expectations.
By reviewing cloud providers carefully, documenting responsibilities, continuously monitoring security controls, and regularly reassessing cloud risks, banks can reduce exposure while taking advantage of the flexibility and scalability that cloud technology provides.