As a financial services company operating in today’s globalized economy, it is critical for SAIB to identify, measure, aggregate, and effectively manage risks, including efficiently allocating regulatory capital to support the Balance Sheet and derive an optimal risk and return ratio. SAIB strives to ensure that significant and measurable risks are identified, quantified, and managed proactively and to enhance risk-adjusted returns and provide financial comfort and stability to the Bank’s many customers and other stakeholders.
Moreover, the Bank’s stakeholders, including regulators and rating agencies, expect the Bank to have a clear and well-defined Risk Management Framework in place that adequately addresses the various dimensions of the Bank’s business. To this end, SAIB has a comprehensive set of policies that deal with all aspects of risk management and complies with regulatory requirements.
The Board-approved Risk Management Policy Guide is the overarching policy document and conforms with SAMA Guidelines. The Policy covers in depth the risks the Bank is exposed to and describes the risk governance structures and risk management policies in place for the Management, monitoring, and control of the risks through the Board-approved Risk Appetite Framework, Credit Policy Guide, and Treasury Policy Guide.
The Board-approved Risk Appetite Framework (RAF) lays out how the Bank manages its risks in a structured, systematic, and transparent manner by incorporating comprehensive risk management into its organizational structure, risk measurement, and monitoring processes. The RAF is aligned with the Bank’s strategy, business planning, capital planning, and policies and documents approved by the Board of Directors. The RAF complies with the Financial Stability Board’s “Principles for an effective Risk Appetite Framework” dated November 18, 2013, as adopted by SAMA. The RAF includes the following key characteristics:
The Board of Directors is responsible for establishing Corporate Governance processes, approving the Risk Appetite and related risk management frameworks, and for approving and implementing policies to ensure compliance with SAMA Guidelines, accounting and reporting standards, and best industry practices including Basel Guidelines.
The Board of Directors has approved the Group’s Risk Management Guide Policy as an overarching Risk Policy Guide under which the Group has a suite of policies including:
The Board-approved IFRS 9 Governance Framework Policy addresses the Group’s IFRS 9 Approach and Methodology Policy, which is supplemented with additional management level policies including an IFRS 9 Data Management and Control Framework Policy, and the IFRS 9 Governance Framework, as well as related accounting and operating procedures.
The Board of Directors is supported by the Board Risk Committee, a sub-committee of the Board, responsible for recommending policies and other documents for Board approval and for monitoring risks within the Bank.
At the Management level, the Bank operates various committees including an Enterprise Risk Management Committee, a Credit Committee, and an Asset Liability Committee, which are responsible for various areas of risk management.
A Management level Expected Credit Loss Committee linked to the Bank’s IFRS 9 Governance and Framework Policy also operates, which is responsible for all aspects of IFRS 9 including expected credit losses.
At the departmental level, SAIB has a Risk Management Group headed by the Chief Risk Officer, who is supported by Assistant General Managers in charge of Risk Management, Credit Risk Review, Credit Administration, and Collections.
The Bank’s Internal Audit Function reports to the Audit Committee of the Board of Directors and provides an independent validation of business and support units’ compliance with risk policies and procedures and the adequacy and effectiveness of the Risk Management Framework on a Bank-wide basis.
The following provides a description of the Bank’s significant risks including how the Bank manages these risks:

Credit risk arises from the potential a borrower or counterparty will fail to meet their financial obligations to the Bank. The exposure to credit risk stems primarily from loans and advances, investments, and due from banks and other financial institutions. Credit risk is also present in off-balance sheet financial instruments such as Letters of Credit, Acceptances, Guarantees, Derivatives, and Commitments to extend credit.
The Bank has a comprehensive framework for managing credit risk, including an independent credit risk review function and credit risk monitoring process. The Bank assesses the probability of default of counterparties using internal rating tools and supplements these with external ratings from major rating agencies, where available.
The Bank continues to improve the overall credit risk control function through further investment in a post-sanction review process to mitigate potential credit losses that may arise.
Market risk is the risk that fair value or future cash flows of financial instruments will fluctuate due to changes in market variables such as commission rates, foreign exchange rates, and equity prices.
Commission rate risk arises from the possibility that changes in commission rates will impact either the fair values or the future cash flows of financial instruments. The Board of Directors has established commission rate gap limits for defined time periods. The Bank routinely monitors its positions and uses hedging strategies to ensure maintenance of positions within established gap limits.
Currency risk can arise from fluctuations in prevailing foreign currency exchange rates on the Bank’s financial position and cash flows. The Board of Directors sets limits on the level of exposure by currency and in total for both overnight and intra-day positions, which are independently monitored.
Equity price risk is the risk of a decrease in fair values of equities in the Bank’s investment portfolio as a result of possible changes in levels of equity indices and the value of individual shares. The Board of Directors sets limits on the level of exposure to each industry, and overall portfolio limit, which are independently monitored.

Liquidity risk is the risk of the Bank being unable to meet its net funding requirements when needed and at an acceptable cost. Liquidity risk can be caused by market disruptions or credit rating downgrades for the Bank, which may cause certain sources of funding to dry-up unexpectedly.
The Bank’s Management carefully monitors the maturity profile of its assets and liabilities to ensure that adequate liquidity is maintained on a daily basis. The Daily Liquidity Coverage Ratio, Net Stable Funding Ratio, and the Loans to Deposit Ratio are also monitored regularly and independently to ensure compliance with SAMA Guidelines. The Bank also conducts regular liquidity stress testing under a variety of scenarios which cover both normal and more severely stressed market conditions. All liquidity policies and procedures are subject to review and approval by the Bank’s Asset and Liability Committee.

Operational risk arises from inadequacies or failures in internal processes, people, systems, or from external events.
SAIB’s Operational Risk Management Framework and Policy provides a bank-wide definition of operational risk and lays down tools and processes by which operational risks are identified, assessed, monitored, and controlled. The key components of the framework include the Risk and Control Self-Assessment (RCSA), Key Risk Indicators (KRIs), Scenario Analysis, and Incident Management, which are comprehensively documented in the Bank’s operational risk procedures.
The continuous assessment of operational risks and their controls across all the Bank’s business and support units are monitored through RCSA exercises, close monitoring of agreed action plans as a result of the RCSA exercises, and establishing an Operational Risk Appetite for the Bank as a whole. This includes monitoring the operational risk losses incurred on an ongoing basis and taking corrective actions to eliminate or minimize such losses in the future. Global major loss incidents across the banking industry are also duly analyzed to assess their impact if these are incurred in the Bank. The Bank’s KRIs cover all the business and support units to facilitate proactive monitoring and management of operational risks.

Financial crimes are considered a significant risk for financial institutions and all stakeholders (including customers, staff, shareholders, counterparties etc.). Occurrence of such crimes can have a significant negative impact on the Bank and its reputation.
The Bank continues to enhance its Fraud Management Framework which the Fraud Prevention and Detection Department (FPDD) operates within. The Fraud Risk Management Framework defines the principles of identification, assessment, escalation, investigation, resolution, reporting, and corrective action on fraud-related issues. It lays down an approach for procedures related to tools and methods engaged by FPDD to protect the Bank from exposure to financial crime. FPDD presents their findings and recommended actions to the Financial Fraud Control Committee (FFCC) on a regular basis.

The Cyber and Information Security Risk landscape continues to be dynamic and challenging. The Bank proactively addresses on-going cyber Security challenges and deploys dynamic defenses using multiple countermeasures for prevention, detection, and response. The Bank has also deployed various security measures using the defence in-depth and multilayer security principle to ensure the effectiveness of the overall security posture of the Bank.
The Bank has also strengthened its existing governance structure by implementing industrial security best practices that ensures confidentiality, integrity, privacy, and availability, which are treated as an integral part of all business and technical processes. The Bank also continually ensures the alignment of the information security and business objectives through the implementation of the Cyber and Information Security Strategy, which is supervised and monitored by the Information Security Steering Committee. Also, the Bank is continuously enhancing the security culture through various awareness and training programs targeting staff and customers.
The Bank also constantly performs security assurance assessments on the Bank’s systems and applications to ensure that the Bank’s business services are secure and reliable. Furthermore, the Bank conducts independent internal and external audits by reputable vendors to ensure the effectiveness of implemented security controls and compliance with regulatory and international standards such as the SAMA cyber security framework (CSF), National cybersecurity authority (NCA), SARIE, SWIFT and Payment Card Industry Data Security Standard (PCI DSS), The result of the audit exercises proves that the Bank complies with regulations and security standards and shows that the Bank’s security posture is up to industrial standards and is satisfactory.
The Bank has a 24/7/365 Security Operation Centre (SOC) which continuously monitors and responds to cyber security threats and attacks in a timely manner. As a result of implemented security measures, the Bank has been resilient to numerous cyber-attacks targeting the Middle East and Saudi Arabia with no cyber and information security-related downtime or operational losses incurred during 2020.
The Bank recognizes the importance of planning for Business Continuity. An effective Business Continuity Plan (“BCP”) facilitates in mitigating a serious disruptive incident in a controlled, timely, and structured manner.
Since February 2020, the Bank, like all other organizations around the world, faced the impact of the COVID-19 Pandemic, and this was managed successfully due to the Bank’s strong business continuity infrastructure. Through the Corona Virus Response Committee, which acted as a command centre for the Pandemic impact, the Bank was able to comply with all government regulations on time, manage work from home procedures smoothly, and maintain all premises with required precautionary procedures.
During 2020, the Bank further strengthened the testing of its BCPs and procedures. Detailed tests were completed on different occasions. In September 2020, the Bank successfully conducted a continuous five day disaster recovery test of all critical IT systems by switching and operating them from the Bank's Disaster Recovery Centre (DRC) at once. No dependency on the Bank’s Main Data Centre (MDC) was noted, knowing that the test considered a cyber-security scenario that required the Bank to simulate the need for all backup environments (IT Systems and buildings).
The Bank was able to accomplish ISO 22301 requirements and obtained a certificate from the International Organization for Standardization – 22301 (ISO 22301) which mainly related to Resilience and Business Continuity. ISO released the latest version of the standard in 2019. SAIB is one of the first Saudi banks certified with this new version. Being an ISO 22301 Certified Organization provides more assurance to our customers, shareholders, stakeholders, regulators, Management and staff, vendors, suppliers, and partners that the Bank is a resilient Organization with a strong business continuity program that provides a safe environment against disruptions, disasters, or crises.