KYC Compliance in Saudi Arabia: SAMA Rules, Nafath and Onboarding

KYC Compliance in Saudi Arabia: SAMA Rules, Nafath and Onboarding

Saudi Arabia runs one of the most demanding compliance environments in the region — and one of the most digitally mature. The Kingdom pairs strict AML obligations with national digital identity infrastructure that, used properly, makes verification faster than almost anywhere else in the world. This guide covers what regulated businesses must do, and how to do it without destroying conversion.

General information, not legal advice. Confirm current requirements against SAMA and CMA publications before relying on them.

Who regulates what

  • SAMA (Saudi Central Bank) supervises banks, finance companies, insurers, payment service providers and licensed fintechs
  • CMA (Capital Market Authority) oversees investment firms and capital market participants
  • SAFIU (Saudi Arabian Financial Investigation Unit) is the financial intelligence unit that receives suspicious transaction reports

Saudi Arabia’s Anti-Money Laundering Law, issued by Royal Decree and subsequently updated, sits above these — establishing offences, penalties and the general duty to know your customer.

Core obligations

Customer due diligence

Regulated entities must verify customer identity through reliable, independent sources before establishing a relationship, understand the purpose and intended nature of that relationship, and assign a risk rating that drives ongoing treatment.

For corporate customers, beneficial ownership identification is explicit and verified against official registry data. Collecting a commercial registration is not sufficient — you must establish the natural persons behind the entity.

Enhanced due diligence

Applies to politically exposed persons, non-residents, complex ownership structures and customers connected to higher-risk jurisdictions. Expect source of wealth and source of funds evidence, senior management sign-off, and more frequent review.

Record retention

Saudi Arabia’s retention expectation is notably longer than much of the region — records must be kept for a minimum of ten years. That has real architectural consequences: your storage, indexing and retrieval design has to assume a decade of data, retrievable on request.

Suspicious transaction reporting

Reports go to SAFIU, and the obligation is not threshold-based. Any transaction that gives rise to suspicion must be reported regardless of amount, and urgent cases require immediate escalation.

Penalties

The AML Law provides for substantial financial penalties running into millions of riyals, alongside criminal liability and imprisonment in serious cases. Supervisory action against licences is a live risk for regulated entities.

Nafath and Absher: the digital identity advantage

This is what makes Saudi Arabia different. The Kingdom operates mature national digital identity infrastructure:

  • Absher — the government services platform holding verified citizen and resident identity data
  • Nafath — the national single sign-on layer that lets a user authenticate against that verified identity

For onboarding, Nafath collapses what would otherwise be a multi-step document-and-selfie flow into an authentication event against a government-verified record. Where it is available and appropriate for the customer segment, it is faster and more reliable than document-based verification.

But it does not cover everything, and treating it as the whole answer is a mistake. You will still need document-based verification for:

  • Non-residents and foreign nationals outside the national identity system
  • Corporate onboarding, where beneficial owners may sit outside the Kingdom
  • Supporting documentation — commercial registrations, trade licences, proof of address, source of funds evidence
  • Fallback when the national service is unavailable or the customer cannot complete it

The practical architecture is Nafath first, document verification as the parallel path — not one or the other.

Where Saudi programmes struggle

Arabic document processing at volume. Commercial registrations, national ID cards, and supporting paperwork are Arabic-language and often bilingual. Generic OCR handles them poorly, producing extraction errors that surface later as data quality problems in screening.

Transliteration in screening. Arabic names render inconsistently in Latin script across sanctions and PEP lists. Systems tuned for exact matching either miss genuine hits or flag everything.

Ten-year retention. Programmes built with a five-year assumption quietly fail their first decade-old retrieval request.

Onboarding friction. Saudi Arabia has one of the highest smartphone penetration rates in the world and correspondingly low tolerance for slow digital journeys. A verification flow that takes minutes loses customers a ten-second flow keeps — with no compliance benefit whatsoever.

What good looks like

  1. Nafath integration as the primary path for eligible customers
  2. Document authentication with native Arabic OCR for everyone else, and for all supporting documentation
  3. Biometric verification with liveness detection where document-based verification is used, to defeat presentation and injection attacks
  4. Screening tuned for Arabic name variation, with contextual risk scoring rather than raw string matching
  5. Perpetual monitoring that re-screens on list changes and behavioural triggers
  6. Ten-year audit trail designed in from the start

Frequently asked questions

Is Nafath mandatory for KYC in Saudi Arabia?

Nafath is widely used and, for many consumer flows, the expected route. It is not a universal substitute for due diligence — corporate onboarding, non-residents and supporting documentation still require conventional verification.

How long must records be retained?

A minimum of ten years, which is longer than the five-year baseline common elsewhere in the region. Design your data architecture around the longer period.

Does SAMA permit fully remote onboarding?

Digital onboarding is well established in the Saudi market. The regulatory question is not whether the customer was physically present but whether identity was reliably verified and the process is auditable.

What triggers enhanced due diligence?

PEP status, non-resident status, complex or opaque ownership, connections to higher-risk jurisdictions, and unusual transaction patterns relative to the customer’s profile.

Is Saudi Arabia on the FATF grey list?

Saudi Arabia is a FATF member. Listing status changes following mutual evaluations — check the current FATF statement directly rather than relying on secondary summaries.

How iPass helps

iPass was built for Arabic-first markets. Our OCR and intelligent document processing reads Arabic commercial registrations, national IDs and handwritten documents natively rather than through a translation layer. Identity verification adds biometric matching and liveness detection for the paths Nafath doesn’t cover. AML screening and perpetual KYC handles Arabic transliteration variance with contextual scoring that cuts false positives.

See pricing or talk to our team.

Related guides