By the iVoiceUp Compliance Team
First issued in August 2019, SAMA's Whistle Blowing Policy for Financial Institutions remains in force and sets the minimum controls for receiving and processing violation reports at financial institutions supervised by the Saudi Central Bank. SAMA required institutions to implement the policy within three months of its issuance and submit a compliance plan within one month.
For financial institutions reviewing their whistleblowing arrangements in 2026, the policy provides a detailed framework covering governance, reporting channels, the unit responsible for handling reports, whistleblower protection, case processing, record keeping, automated reporting and performance monitoring.
1. A Board-Approved Whistleblowing Policy
SAMA requires financial institutions to establish a whistleblowing policy approved by the board of directors. Where an institution does not have a board, the policy must be approved by the CEO or general director. The policy must also be reviewed annually.
Institutions are required to submit periodic reports to the board and audit committee covering cases received and the actions taken. They must also raise awareness among employees and stakeholders, encourage reporting, explain whistleblowing responsibilities and communicate the available reporting channels.
This places whistleblowing within the institution's formal governance structure and gives senior management and oversight bodies visibility into how reports are being handled.
2. An Independent Unit for Receiving and Processing Reports
SAMA requires financial institutions to establish an independent administrative unit to receive and process violation reports, with a reporting line to the compliance department.
The requirement gives the whistleblowing function a defined place within the institution's structure. It also becomes particularly important when a report concerns a manager, senior executive or another person within the normal reporting hierarchy.
The reporting channel and the function responsible for processing reports therefore need to work together: employees and stakeholders need a secure way to submit concerns, while the institution needs an appropriately designated function to receive, assess and process them.
3. The Scope Goes Beyond Financial Fraud
SAMA's whistleblowing framework covers a broad range of potential violations. Its listed cases include financial and administrative corruption, breaches of laws and internal policies, environmental and workplace health and safety violations, misuse of institutional property and assets, abuse of power, circumvention of laws, conflicts of interest, unlawful disclosure of confidential information, serious negligence and concealment of violations.
The policy also covers unlawful, unethical and unprofessional conduct alongside fraud, embezzlement and corruption.
For financial institutions, this means the reporting mechanism needs to accommodate different forms of misconduct and provide a process for directing each report to the appropriate assessment or investigation route.
4. Confidential Reporting Channels
SAMA requires financial institutions to provide effective reporting channels that protect the confidentiality of information. Employees and stakeholders must be informed about the available channels, with the policy specifying a minimum of a direct telephone number, website, postal service and email address.
The framework addresses both accessibility and confidentiality. Employees and relevant stakeholders need to know where and how they can raise a concern, while the institution needs controls that protect the information submitted through those channels.
For institutions using several reporting routes, maintaining consistent confidentiality and case-handling controls across those channels can become an important operational consideration.
5. Whistleblower Protection and Responsibilities
SAMA requires financial institutions to protect whistleblowers from retaliation and maintain confidentiality around the whistleblower's identity and the information contained in the report throughout the processing of the case. Information about a whistleblower may only be disclosed to competent authorities, such as investigation or judicial authorities, in accordance with the policy.
The framework also places responsibilities on whistleblowers. They are expected to avoid rumours and unfounded allegations, refrain from malicious reporting, exercise due diligence, provide relevant details and supporting documentation where appropriate, report violations promptly and maintain confidentiality.
At the same time, a good-faith report that cannot ultimately be substantiated should not, on that basis alone, result in action against the whistleblower. SAMA's framework is designed to encourage reporting while setting expectations around responsible use of the reporting mechanism.
6. What Institutions Must Do When a Report Arrives
SAMA sets requirements for the institution's response once a report has been submitted.
Reports must be taken seriously regardless of their nature, language, adequacy of information, impact or importance. The institution must take measures to protect the whistleblower, notify the whistleblower that the report has been received and, where possible, communicate the decision made.
Reports must also be referred to the department responsible for control and investigation, whether inside or outside the institution as appropriate. Where a violation is proven, corrective action must be taken. Relevant reports and documents, including recordings, must be retained for the periods required by applicable laws and instructions.
These requirements place responsibility on the institution for the full handling of a case after submission, including follow-up and documentation.
7. SAMA Requires a Defined Case-Processing Workflow
SAMA requires institutions to establish internal instructions for the objective and progressive processing of reports and for developing corrective action plans. Institutions must also define the individuals authorized to handle reports and establish mechanisms for approving and supervising the processing function.
The policy identifies several stages of report processing, including:
- Receiving the report.
- Conducting an initial assessment.
- Establishing a verification plan.
- Documenting the rationale supporting the processing decision.
- Deciding how the report will be processed.
- Following up on implementation of the decision.
- Maintaining records.
This gives financial institutions a defined workflow for moving from an allegation to assessment, investigation, decision-making and follow-up.
8. The Process Must Be Automated and Measurable
SAMA also requires financial institutions to establish an automated reporting system.
The system must provide visibility into information including the channel through which reports were received, the total number of reports, reports by subject, the number of reports that have been processed and those still in progress, and the type of processing involved. The system must also be capable of generating reports covering processing stages requested by SAMA.
The framework further requires a key performance indicator for each stage of the institution's working procedures, allowing the institution to measure whether the requirements of each procedure are being met.
For compliance teams, this creates a need for visibility across the reporting lifecycle : where reports came from, what they concern, where they are in the process and how the reporting function is performing.
What This Means for Financial Institutions in 2026
SAMA's framework combines governance, reporter protection and operational case management. Financial institutions need a board-approved policy, an independent reporting and processing function, accessible reporting channels, confidentiality safeguards, defined case-handling procedures, appropriate record keeping, automated reporting capabilities and performance monitoring.
For institutions reviewing their arrangements in 2026, these requirements provide a practical basis for assessing whether their current reporting infrastructure supports the processes established in their whistleblowing policy.
Where iVoiceUp Fits
Technology can support the operational side of these requirements by providing a dedicated environment for confidential reporting, communication and case management.
iVoiceUp provides anonymous reporting with identity-protection measures including no IP storage, no device IDs and encrypted submissions. The platform supports anonymous two-way follow-up, allowing organizations to communicate with reporters while protecting their anonymity.
For case managers, iVoiceUp provides a centralized workspace for triage, assignment, investigation stages , evidence tracking, follow-up and activity history. Its platform also supports automatic case routing, role-based access controls, dashboards, processing-time metrics and exportable reports.
These capabilities can support several operational areas addressed by SAMA's framework, including confidential reporting, protection of reporter identity, structured case handling, follow-up, record keeping and visibility over reporting activity.
For financial institutions , iVoiceUp can provide the technology layer supporting the implementation of their SAMA whistleblowing processes. The institution remains responsible for its governance arrangements, investigations, decisions, corrective actions and wider regulatory obligations.
See how iVoiceUp can support your institution's SAMA whistleblowing requirements. Talk to our team .
