Saudi Arabia (SA)
Lead Signal
This cycle establishes the full Saudi Arabia baseline across the World Payments Monitor's thirteen-module spine, and the picture that emerges is of a mature, unitary, regulator-led payments environment whose direction of travel is unmistakably liberalising. Saudi Arabia operates a single licensing perimeter under SAMA (Saudi Central Bank), which is the sole licensing and supervisory authority for payment systems and PSPs under the Law of Payments and Payment Services (Royal Decree M/26, 22/03/1443H) and its Implementing Regulation effective 13/06/2023G, which repealed and replaced the 30/01/2020 PSP framework. There is no federal/state split to navigate: the entire Kingdom's payments licensing perimeter runs through one statute and one regulator. For any operator contemplating market entry, the gateway is explicit and binary in structure — a bank-PSP route under the Banking Control Law M/5, or a non-bank PI/EMI authorisation route under the Law of Payments and Payment Services.
That non-bank route is itself tiered. The SAMA non-bank PSP licence taxonomy comprises four licence types with capital thresholds: Micro PI (SAR 1m, capped at SAR 20,000 per customer per month), Major PI (SAR 3m, cross-border permitted), Micro EMI (SAR 2m) and Major EMI (SAR 10m); the PI/EMI distinction turns on whether the entity may issue electronic money. The Major PI tier is the cross-border route, and the per-customer caps on the Micro tier directly shape how a low-cost entrant can scale. This four-tier ladder, distinct from the bank-PSP route, is the analytical spine of how non-bank capital reaches the Saudi market, and it is the structural fact that frames every other module in this baseline.
Outlook
The defining structural tension in the Saudi baseline is the asymmetry between an actively liberalising fintech market and a settlement layer that remains bank-restricted. SARIE RTGS participation is limited to certified banks, which means non-bank PSPs require a sponsoring bank — a material market-access constraint that sits beneath every non-bank licensing and product story above. Watch items for forthcoming cycles are the stablecoin framework, which remains proposed-not-enacted under SAMA and CMA design and is registered on the regulatory horizon with a 2026 window, and the maturation of the BNPL segment toward public-market exit signalled by Tabby's IPO preparation. The over-arching direction is liberalising regulator-led market development under the Vision 2030 Financial Sector Development Programme, but the bank-versus-non-bank access boundary remains the constraint to track.
Other Developments
The conduct and safeguarding layer is equally codified. Under the Implementing Regulation's consumer-protection provisions, EMIs must issue and redeem electronic money at par value, and activities requiring a pooled customer-funds account fall within the defined scope of payment services under Article 5-1, requiring a SAMA licence and adherence to fund-handling requirements. This pooled-account segregation discipline governs how non-bank EMIs hold and protect customer money, a mechanism distinct from bank-PSP deposit protection. On redress, the SAMACARES complaints channel was replaced by the Complaint Management System per SAMA Circular 1185, effective 1/7/2025G, alongside updated Debt Collection Regulations.
Digital money sits in a more provisional state. E-money is licensed under the EMI regime, but private cryptocurrencies and stablecoins remain outside the formal regulatory perimeter; a late-2025 ministerial announcement of nationally regulated stablecoins under joint SAMA and CMA oversight remains at policy-design stage with no licensing, reserve-backing or redemption rules published. This is a proposal, not an enacted framework, and it must be read as such. On central bank money, SAMA continues wholesale-focused CBDC experimentation with local banks and fintechs building on the 2019 Project Aber pilot with the UAE, and in 2024 SAMA joined the BIS-hosted mBridge multi-CBDC project at MVP stage for cross-border interbank settlement; no decision to introduce a CBDC has been made.
The operating-environment fundamentals are well-developed. Operational resilience rests on the mandatory maturity-based SAMA Cyber Security Framework (v1.0, May 2017), the Business Continuity Management Framework, and the Cyber Resilience Fundamental Requirements operating as a licensing and sandbox gate, with board-level accountability. On rails, mada, the national debit scheme operated by SAMA subsidiary Saudi Payments, is mandated on every Saudi bank card, with SAMA capping the mada debit MSC at 0.80% (roughly SAR 40 per transaction) and adding effective-2025 caps on international card fees of 2%. The sarie Instant Payment System, owned by SAMA and launched in 2021, provides a 24/7 low-value overlay supporting alias identifiers, while AFAQ provides GCC cross-currency cross-border RTGS settlement, its cross-currency service having launched 10 December 2020 with Saudi and Bahrain participation from December 2021.
The commercial-intelligence picture is dominated by the BNPL segment. Saudi BNPL Tamara secured up to $2.4bn in asset-backed Shariah-compliant financing from Goldman Sachs, Citi and Apollo-managed funds, announced at Money20/20 Riyadh on 15 September 2025, with $1.4bn immediately deployable. Tamara also became the first fintech startup to receive a full consumer finance licence from SAMA on 3 March 2025, covering both consumer finance and BNPL activities. Saudi BNPL Tabby raised a $160m Series E at a $3.3bn valuation led by Blue Pool Capital and Hassana Investment Company in March 2025, with a Saudi IPO reportedly underway.
Cross-Monitor Connections
The Kingdom's AML/CFT surface is carried in this monitor as Sentinel-sourced provenance only. The Sentinel feed records that KSA AML/CFT rests on the Anti-Money Laundering Law (Royal Decree M/20) and the Law on Combating the Financing of Terrorism (M/21), with the SAMA AML/CTF Guide setting risk-based expectations, that Saudi Arabia joined FATF in June 2019 as the first Arab and 37th member, and that it is not on the FATF increased-monitoring (grey) list as of 13 February 2026. Any original illicit-finance, sanctions-evasion or mutual-evaluation analysis for Saudi Arabia is a cross-reference to the Financial Intelligence Monitor and not a conclusion of this monitor.
Domains
14 regulatory modules · click to expand the full sub-briefLicensing, Authorisation & Market Access
ConfirmedSaudi Arabia operates a unitary licensing regime with no federal/state split.
Correspondent Banking, Settlement & Access
ConfirmedThe analytical spine of this module is the bank-versus-non-bank settlement-access asymmetry.
Commercial Intelligence (M&A, Investment & Product)
HighThe Saudi commercial-intelligence picture this cycle is dominated by the BNPL segment, carried as three discrete trailing-12-month events.
Conduct, Safeguarding & Promotions
ConfirmedThe conduct and safeguarding layer in Saudi Arabia is codified through the Implementing Regulation's consumer-protection and e-money redemption provisions.
Stablecoins & Digital Money
ConfirmedDigital money in Saudi Arabia divides cleanly between what is licensed and what is not. E-money is licensed under the EMI regime, but private cryptocurrencies and stablecoins remain outside the formal regulatory perimeter.
Operational Resilience & Critical Infra
ConfirmedOperational resilience in Saudi Arabia rests on a layered, mandatory regime.
Full per-domain detail — all 14 modules
W1aConfirmedLicensing, Authorisation & Market Access
see this theme across all jurisdictions →5 claimsSaudi Arabia operates a unitary SAMA-supervised payments licensing regime under the Law of Payments and Payment Services (Royal Decree M/26, 22/03/1443H) and its Implementing Regulation (effective 13/06/2023G), which repealed and replaced the January 2020 PSPR. Non-bank PSPs apply for one of four licences — Micro PI, Major PI, Micro EMI, Major EMI — with PI/EMI distinguished by whether the entity may issue electronic money. The framework draws on EU PSD2 concepts. SAMA is the sole authorising body; licensing proceeds via in-principle approval then final licensing. Banks operate under the separate Banking Control Law (M/5). No federal/state split applies (unitary state).
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Licensing, Authorisation & Market Access
Saudi Arabia operates a unitary licensing regime with no federal/state split. SAMA (Saudi Central Bank) is the sole licensing and supervisory authority for payment systems and PSPs under the Law of Payments and Payment Services (Royal Decree M/26, 22/03/1443H) and its Implementing Regulation effective 13/06/2023G, which repealed and replaced the 30/01/2020 PSP framework. This single primary statute governs the entire Kingdom's payments licensing perimeter, and it establishes a binary structural choice for market entrants: a bank-PSP route under the Banking Control Law M/5, or a non-bank PI/EMI authorisation route under the Law of Payments and Payment Services.
The non-bank route is itself tiered. The SAMA non-bank PSP licence taxonomy comprises four licence types with capital thresholds: Micro PI (SAR 1m, capped at SAR 20,000 per customer per month), Major PI (SAR 3m, cross-border permitted), Micro EMI (SAR 2m) and Major EMI (SAR 10m); the PI/EMI distinction turns on whether the entity may issue electronic money. The Major PI tier is the designated cross-border route, and the per-customer monthly cap on the Micro PI tier directly shapes how a low-cost entrant can scale before stepping up to the Major tier. Capital thresholds and per-customer caps thus directly shape market-access strategy for non-bank entrants, and they keep the non-bank PI/EMI route analytically distinct from the bank-PSP route under the Banking Control Law M/5. These capital thresholds and activity caps rest in part on specialist law-firm commentary corroborated against the SAMA implementing regulation.
Outlook
The licensing perimeter is stable and codified, and the binary bank-versus-non-bank distinction is the structural fact framing every downstream module in the Saudi baseline. Future cycles should watch for any capital-threshold or activity-cap revisions to the four-tier taxonomy, and for the entry of newly licensed non-bank operators ascending the Micro-to-Major ladder.
Saudi Arabia operates a unitary SAMA-supervised payments licensing regime under the Law of Payments and Payment Services (Royal Decree M/26, 22/03/1443H) and its Implementing Regulation (effective 13/06/2023G), which repealed and replaced the January 2020 PSPR. Non-bank PSPs apply for one of four licences — Micro PI, Major PI, Micro EMI, Major EMI — with PI/EMI distinguished by whether the entity may issue electronic money. The framework draws on EU PSD2 concepts. SAMA is the sole authorising body; licensing proceeds via in-principle approval then final licensing. Banks operate under the separate Banking Control Law (M/5). No federal/state split applies (unitary state).
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
W12ConfirmedCorrespondent Banking, Settlement & Access
see this theme across all jurisdictions →4 claimsAll interbank settlement is managed by SAMA via the SARIE RTGS (live May 1997), which provides immediate-finality settlement in central bank money for interbank transfers, customer credit transfers and direct debits; all domestic clearing systems (mada/SPAN, SADAD, sarie, ACH cheque clearing) net-settle over SARIE. SARIE participation is restricted to banks meeting SAMA-acceptable systems, procedures and certified staff (~23 participants plus SAMA). Cross-border correspondent access uses SWIFT messaging, with AFAQ (GCC cross-currency RTGS via Gulf Payments Company) and Buna (Arab Monetary Fund) providing regional alternatives that reduce reliance on traditional correspondent banking. SAR is pegged 3.75/USD; cross-border SAR movement requires licensed bank participation. SAMA participates in BIS, FSB and FATF.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Correspondent Banking, Settlement & Access
The analytical spine of this module is the bank-versus-non-bank settlement-access asymmetry. SARIE (live since May 1997) is the SAMA-operated RTGS providing immediate-finality settlement in central bank money; all domestic clearing systems — mada/SPAN, SADAD, sarie and ACH — net-settle over SARIE. Participation is restricted to banks meeting SAMA-certified systems, procedures and staff, at roughly 23 participants plus SAMA. Because participation is bank-restricted, non-bank PSPs do not hold direct SARIE accounts and require a sponsoring bank for settlement — a structural market-access constraint that sits beneath every non-bank licensing and product story in the Saudi baseline.
Cross-border settlement uses SWIFT, with AFAQ and Buna as regional alternatives. SAMA joined the BIS mBridge project as a full participant at MVP stage in June 2024, and the SAR is pegged at 3.75/USD. The non-bank PSP settlement-access gap is captured here under the methodology-mandated W12 lens.
Outlook
The bank-restricted settlement layer is the central structural constraint of the Saudi market, set against an otherwise liberalising fintech environment. Evidence does not specify whether any indirect or sponsored access scheme exists for licensed non-bank PIs/EMIs, leaving the precise mechanism for non-bank settlement reach uncertain — a priority gap for future cycles.
All interbank settlement is managed by SAMA via the SARIE RTGS (live May 1997), which provides immediate-finality settlement in central bank money for interbank transfers, customer credit transfers and direct debits; all domestic clearing systems (mada/SPAN, SADAD, sarie, ACH cheque clearing) net-settle over SARIE. SARIE participation is restricted to banks meeting SAMA-acceptable systems, procedures and certified staff (~23 participants plus SAMA). Cross-border correspondent access uses SWIFT messaging, with AFAQ (GCC cross-currency RTGS via Gulf Payments Company) and Buna (Arab Monetary Fund) providing regional alternatives that reduce reliance on traditional correspondent banking. SAR is pegged 3.75/USD; cross-border SAR movement requires licensed bank participation. SAMA participates in BIS, FSB and FATF.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
W13HighCommercial Intelligence (M&A, Investment & Product)
see this theme across all jurisdictions →4 claimsTrailing-12-month commercial activity is led by the BNPL/fintech segment. Tamara secured up to $2.4bn asset-backed Shariah-compliant financing (Goldman Sachs/Citi/Apollo, Sept 2025) and obtained Saudi Arabia's first full SAMA consumer-finance licence (March 2025). Tabby raised a $160m Series E at a $3.3bn valuation (March 2025) and is preparing a Saudi IPO (HSBC/JPM/Morgan Stanley engaged); Tabby earlier acquired digital-wallet startup Tweeq. PIF-linked Sanabil and SNB Capital remain key local backers. Money20/20 first ran in Riyadh in 2025.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Commercial Intelligence (M&A, Investment & Product)
The Saudi commercial-intelligence picture this cycle is dominated by the BNPL segment, carried as three discrete trailing-12-month events. First, an investment event: Saudi BNPL Tamara secured up to $2.4bn in asset-backed Shariah-compliant financing from Goldman Sachs, Citi and Apollo-managed funds, announced at Money20/20 Riyadh on 15 September 2025, with $1.4bn immediately deployable and refinancing a prior $500m facility — the largest disclosed KSA fintech debt event in the trailing twelve months. Second, an investment event: Saudi BNPL Tabby raised a $160m Series E at a $3.3bn valuation led by Blue Pool Capital and Hassana Investment Company in March 2025, with a Saudi IPO reportedly underway (HSBC, JP Morgan and Morgan Stanley engaged); Tabby had earlier acquired digital-wallet startup Tweeq, making it MENA's most valuable fintech at $3.3bn. Third, a licensing milestone rendered as a product event with value not publicly disclosed: Tamara became the first fintech startup to receive a full consumer finance licence from SAMA on 3 March 2025, covering both consumer finance and BNPL activities.
Together these events signal deep institutional capital backing the BNPL segment and its maturation toward public-market exit, with Tamara's first-mover full consumer-finance licence positioning it ahead of BNPL peers on the SAMA authorisation ladder.
Outlook
The BNPL/fintech segment is the escalating commercial-intelligence theme for Saudi Arabia, advancing the Major M&A tracker. The most significant forward signal is Tabby's reported IPO preparation, which would mark the segment's transition toward public-market exit; future cycles should track the IPO process and any further institutional debt or equity events across the leading BNPL operators.
Trailing-12-month commercial activity is led by the BNPL/fintech segment. Tamara secured up to $2.4bn asset-backed Shariah-compliant financing (Goldman Sachs/Citi/Apollo, Sept 2025) and obtained Saudi Arabia's first full SAMA consumer-finance licence (March 2025). Tabby raised a $160m Series E at a $3.3bn valuation (March 2025) and is preparing a Saudi IPO (HSBC/JPM/Morgan Stanley engaged); Tabby earlier acquired digital-wallet startup Tweeq. PIF-linked Sanabil and SNB Capital remain key local backers. Money20/20 first ran in Riyadh in 2025.
Evidence — 4 structured claims
Key facts
- Content Tier
- D
- Sentinel Feed
- False
Event Findings
Conduct and safeguarding for KSA PSPs sit within the Implementing Regulation of the Law of Payments and Payment Services, which includes dedicated parts on consumer protection, financial inclusion, e-money issuance/redemption, outsourcing and risk. EMIs must redeem e-money at par and safeguard funds (pooled account discipline applies to PSP customer funds per SAMA rules). Conduct obligations cover governance, fit-and-proper senior appointments, framework-contract disclosure and ongoing financial reporting. Promotions/advertising norms are layered onto specific regimes (e.g. BNPL advertising transparency rules). SAMA is the supervising authority.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Conduct, Safeguarding & Financial Promotions
The conduct and safeguarding layer in Saudi Arabia is codified through the Implementing Regulation's consumer-protection and e-money redemption provisions. EMIs must issue and redeem electronic money at par value, and activities requiring a pooled customer-funds account fall within the defined scope of payment services under Article 5-1, requiring a SAMA licence and adherence to fund-handling requirements. This pooled customer-funds account discipline is the safeguarding mechanism — a segregation regime governing how non-bank EMIs hold and protect customer money, distinct from bank-PSP deposit protection. Conduct obligations layered on top include fit-and-proper requirements, beneficial-ownership disclosure at the 10% threshold, and quarterly and annual reporting.
On consumer redress, the SAMACARES complaints channel was replaced by the Complaint Management System per SAMA Circular 1185, effective 1/7/2025G, alongside updated Debt Collection Regulations. This standardised complaints channel serves as the ombudsman-equivalent route for both bank and non-bank PSP conduct complaints, and it affects the conduct-compliance operating model for all SAMA-supervised payment firms.
Outlook
Safeguarding via pooled-account segregation and par-value redemption is the live conduct discipline for non-bank EMIs, and the Complaint Management System now standardises redress across the supervised population. Future cycles should monitor any extension of conduct or financial-promotion obligations, noting that financial-promotion enforcement is a methodology under-indexed surface.
Conduct and safeguarding for KSA PSPs sit within the Implementing Regulation of the Law of Payments and Payment Services, which includes dedicated parts on consumer protection, financial inclusion, e-money issuance/redemption, outsourcing and risk. EMIs must redeem e-money at par and safeguard funds (pooled account discipline applies to PSP customer funds per SAMA rules). Conduct obligations cover governance, fit-and-proper senior appointments, framework-contract disclosure and ongoing financial reporting. Promotions/advertising norms are layered onto specific regimes (e.g. BNPL advertising transparency rules). SAMA is the supervising authority.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
E-money is regulated and licensed (EMI regime under the Law of Payments and Payment Services), but private cryptocurrencies and stablecoins remain outside the formal regulatory perimeter. Since a 2018 standing-committee declaration, virtual currencies are not approved/licensed, and banks are barred from crypto business absent SAMA approval. No stablecoin classification, reserve, redemption or attestation rules are in force. In late 2025 a minister announced plans to develop nationally regulated stablecoins under joint SAMA + CMA oversight — this is a policy-design-stage proposal, NOT enacted. Wholesale CBDC (digital riyal) research continues (Project Aber, mBridge MVP).
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Stablecoins & Digital Money
Digital money in Saudi Arabia divides cleanly between what is licensed and what is not. E-money is licensed under the EMI regime, but private cryptocurrencies and stablecoins remain outside the formal regulatory perimeter. A late-2025 ministerial announcement of nationally regulated stablecoins under joint SAMA and CMA oversight remains at policy-design stage with no licensing, reserve-backing or redemption rules published. This must be read as proposed-not-enacted: the e-money definition explicitly excludes virtual assets, and banks have been barred from crypto absent SAMA approval since a 2018 standing-committee declaration. No enacted stablecoin perimeter means digital-money market access remains confined to the licensed EMI route, and stablecoin issuance is not yet a permitted payment instrument in the Kingdom.
On central bank money, SAMA continues wholesale-focused CBDC experimentation with local banks and fintechs, building on the 2019 Project Aber pilot with the UAE; in 2024 SAMA joined the BIS-hosted mBridge multi-CBDC project at MVP stage for cross-border interbank settlement. No decision to introduce a CBDC has been made, and the research remains wholesale rather than retail in orientation.
Outlook
The stablecoin framework is registered on the regulatory horizon with a 2026 window under SAMA and CMA design, but no in-force classification, reserve, redemption or attestation rules yet exist; the late-2025 announcement must not be over-indexed as enacted. Wholesale CBDC and mBridge participation signal a future cross-border settlement architecture relevant to correspondent-banking strategy, and both should be tracked as design-stage developments.
E-money is regulated and licensed (EMI regime under the Law of Payments and Payment Services), but private cryptocurrencies and stablecoins remain outside the formal regulatory perimeter. Since a 2018 standing-committee declaration, virtual currencies are not approved/licensed, and banks are barred from crypto business absent SAMA approval. No stablecoin classification, reserve, redemption or attestation rules are in force. In late 2025 a minister announced plans to develop nationally regulated stablecoins under joint SAMA + CMA oversight — this is a policy-design-stage proposal, NOT enacted. Wholesale CBDC (digital riyal) research continues (Project Aber, mBridge MVP).
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Operational resilience for SAMA-regulated entities (banks, PSPs, finance and insurance firms) rests on the SAMA Cyber Security Framework (v1.0, May 2017), the Business Continuity Management Framework, and the Cyber Resilience Fundamental Requirements (CRFR) which applies as a licensing/sandbox gate. The CSF is a mandatory, maturity-based model spanning governance, risk, asset/data protection, access control, incident management, third-party risk and business continuity, with board-level accountability. The BCM framework mandates MAO/RTO/RPO definitions, crisis management and testing. PDPL (2023, enforced Sept 2024) adds data-protection obligations supervised alongside SAMA.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Operational Resilience & Critical Infrastructure
Operational resilience in Saudi Arabia rests on a layered, mandatory regime. The maturity-based SAMA Cyber Security Framework (v1.0, May 2017), the Business Continuity Management Framework with its MAO/RTO/RPO measures, and the Cyber Resilience Fundamental Requirements together constitute the resilience regime, with the CRFR operating as a licensing and sandbox gate and board-level accountability throughout. The CRFR sets minimum cyber-resilience licensing requirements for sandbox and licence applicants, making resilience compliance a precondition for market entry rather than an ongoing-supervision afterthought. The Personal Data Protection Law, enforced from September 2024, adds a data-protection layer supervised by SDAIA with SAMA and NCA involvement.
This CSF/BCM/CRFR stack is a functional KSA analogue to DORA-style resilience obligations, and compliance is a precondition for licensing and sandbox entry across both the bank-PSP and non-bank PI/EMI populations.
Outlook
The resilience regime is established and mandatory, with the CRFR acting as a hard gate at the licensing stage. Future cycles should watch for framework version updates and for the interaction between SAMA resilience supervision and SDAIA-led PDPL enforcement as the data-protection regime matures.
Operational resilience for SAMA-regulated entities (banks, PSPs, finance and insurance firms) rests on the SAMA Cyber Security Framework (v1.0, May 2017), the Business Continuity Management Framework, and the Cyber Resilience Fundamental Requirements (CRFR) which applies as a licensing/sandbox gate. The CSF is a mandatory, maturity-based model spanning governance, risk, asset/data protection, access control, incident management, third-party risk and business continuity, with board-level accountability. The BCM framework mandates MAO/RTO/RPO definitions, crisis management and testing. PDPL (2023, enforced Sept 2024) adds data-protection obligations supervised alongside SAMA.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Domestic card routing runs through mada, the national debit scheme operated by Saudi Payments (a SAMA subsidiary), mandated on every Saudi bank card; international Visa/Mastercard co-badge for cross-border and credit. Interchange/MSC is capped by SAMA: mada debit MSC limited to 0.80% (capped ~SAR 40 per transaction), with effective-2025 caps on international card fees (2%) and free e-wallet top-ups via credit cards. EMVco-compliant unified QR (ISO 20022) and tokenised/biometric mada acceptance are in force. ZATCA 'Fatoora' e-invoicing imposes parallel compliance on merchant systems.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Scheme & Network Compliance
The scheme layer in Saudi Arabia is anchored by a mandatory domestic rail. mada, the national debit scheme operated by Saudi Payments (a SAMA subsidiary), is mandated on every Saudi bank card; SAMA caps the mada debit MSC at 0.80% (roughly SAR 40 per transaction), with effective-2025 caps on international card fees of 2% and free e-wallet top-ups via credit cards. Domestic routing flows through mada, with Visa and Mastercard co-badging for cross-border and credit transactions. The unified QR is built on ISO 20022 and EMVco standards, and mada runs natively in Apple Pay, Samsung Pay and Google Pay.
Mandatory mada routing and the capped MSC directly shape acquirer economics and merchant-cost structures across the Kingdom's card market, applying to both bank and non-bank participants in the card ecosystem.
Outlook
The mandatory domestic-routing model with a capped interchange-equivalent is a stable structural feature. Future cycles should track any further adjustment to the MSC cap or international-fee caps, and the continued migration of co-badged and tokenised acceptance onto the mada rail.
Domestic card routing runs through mada, the national debit scheme operated by Saudi Payments (a SAMA subsidiary), mandated on every Saudi bank card; international Visa/Mastercard co-badge for cross-border and credit. Interchange/MSC is capped by SAMA: mada debit MSC limited to 0.80% (capped ~SAR 40 per transaction), with effective-2025 caps on international card fees (2%) and free e-wallet top-ups via credit cards. EMVco-compliant unified QR (ISO 20022) and tokenised/biometric mada acceptance are in force. ZATCA 'Fatoora' e-invoicing imposes parallel compliance on merchant systems.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Domestic instant rail is sarie (Instant Payment System, launched 2021), a 24/7 low-value (≤ SAR 20,000) overlay settling through the SARIE RTGS, supporting alias identifiers (mobile, national ID, Iqama, email). For cross-border, Saudi Arabia is a founding participant in AFAQ — the GCC cross-currency RTGS (live December 2021, operated via Gulf Payments Company owned by the six GCC central banks) — and connects to Buna (Arab Monetary Fund multilateral platform). SWIFT remains the primary international correspondent messaging layer. SAR is not freely convertible and is pegged at 3.75/USD; cross-border SAR movements require licensed bank participation. KSA hosts one of the world's largest remittance corridors.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Payment Corridor Dynamics
Saudi Arabia's corridor architecture combines a domestic instant rail with regional cross-border settlement layers. The sarie Instant Payment System, owned by SAMA and launched in 2021, is a 24/7 low-value (up to SAR 20,000) overlay settling through the SARIE RTGS, supporting alias identifiers (mobile, national ID, Iqama, email, unified commercial number) for transfers up to SAR 2,500 without adding a beneficiary. This alias-based instant rail is the basis for Pay-by-Bank open-banking initiation that bypasses card networks, underpinning lower-cost account-to-account acquiring alternatives.
Regionally, AFAQ is the GCC cross-currency cross-border RTGS service owned and managed by the six GCC central banks via Gulf Payments Company; the cross-currency service launched 10 December 2020, with Saudi and Bahrain participation from December 2021. A caveat applies here: the December 2021 date refers to Saudi/Bahrain participation, not the AFAQ system launch on 10 December 2020. SAMA operates the domestic RTGS interface to the AFAQ central component, and Saudi Arabia also connects to Buna, the Arab Monetary Fund platform. SWIFT remains the primary international correspondent layer, and the SAR is pegged at 3.75/USD and is not freely convertible.
Outlook
AFAQ and Buna reduce reliance on traditional correspondent banking for GCC and regional FX clearing, relevant to corridor cost and access. The launch-versus-participation date distinction for AFAQ would benefit from a primary SAMA confirmation in future cycles; the standing position carries the caveat in the interim.
Domestic instant rail is sarie (Instant Payment System, launched 2021), a 24/7 low-value (≤ SAR 20,000) overlay settling through the SARIE RTGS, supporting alias identifiers (mobile, national ID, Iqama, email). For cross-border, Saudi Arabia is a founding participant in AFAQ — the GCC cross-currency RTGS (live December 2021, operated via Gulf Payments Company owned by the six GCC central banks) — and connects to Buna (Arab Monetary Fund multilateral platform). SWIFT remains the primary international correspondent messaging layer. SAR is not freely convertible and is pegged at 3.75/USD; cross-border SAR movements require licensed bank participation. KSA hosts one of the world's largest remittance corridors.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
The KSA payments market is dominated by SAMA's subsidiary Saudi Payments operating the national rails (mada, SADAD, sarie, Esal) and by a concentrated bank-acquiring layer alongside fast-growing fintechs. Al Rajhi Bank leads merchant acquiring (~41% of POS terminals); Geidea dominates POS/softPOS hardware (~75% share); STC Bank (formerly STC Pay) is a fully licensed digital bank leading wallets, P2P and remittances; SNB is prominent in card payments and instant transfers. The Vision 2030 Financial Sector Development Programme targets growth from 82 fintechs (2020) to 525 by 2030, with 216 fintechs and SAR 2.7bn funding by end-2023. Electronic payments hit 79% of retail transactions in 2024, beating the 70% target early.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Industry Structure & Commercial Dynamics
The Saudi payments market is concentrated around state-owned rails and bank-led acquiring. The market is dominated by SAMA subsidiary Saudi Payments, which operates the mada, SADAD, sarie and Esal rails; Al Rajhi Bank leads acquiring at roughly 41% of POS terminals, Geidea dominates POS and softPOS hardware at roughly 75%, STC Bank leads wallets, P2P and remittances, and SNB is prominent in cards and instant transfers. The Vision 2030 Financial Sector Development Programme targets 525 fintechs by 2030, with 216 firms and SAR 2.7bn in funding recorded by end-2023, and electronic payments reached 79% of retail transactions in 2024 — exceeding the FSDP's 70% digital-payment target early.
The concentrated acquiring and hardware layer (Al Rajhi, Geidea) sitting alongside state-owned rails defines the competitive dynamics that any new entrant must navigate. These market-concentration figures rest on specialist commentary rather than a primary statistical anchor.
Outlook
Market structure is established and concentrated, with a fast-growing licensed fintech segment developing beneath the dominant incumbents. The concentration figures (Al Rajhi ~41% acquiring, Geidea ~75% POS hardware) rest on Tier-3 specialist commentary without a SAMA primary statistical anchor, so precise current shares are not independently confirmable and should be treated as indicative pending primary corroboration.
The KSA payments market is dominated by SAMA's subsidiary Saudi Payments operating the national rails (mada, SADAD, sarie, Esal) and by a concentrated bank-acquiring layer alongside fast-growing fintechs. Al Rajhi Bank leads merchant acquiring (~41% of POS terminals); Geidea dominates POS/softPOS hardware (~75% share); STC Bank (formerly STC Pay) is a fully licensed digital bank leading wallets, P2P and remittances; SNB is prominent in card payments and instant transfers. The Vision 2030 Financial Sector Development Programme targets growth from 82 fintechs (2020) to 525 by 2030, with 216 fintechs and SAR 2.7bn funding by end-2023. Electronic payments hit 79% of retail transactions in 2024, beating the 70% target early.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Payments-related enforcement in KSA is administrative and supervisory rather than common-law litigation-driven. SAMA publicly announces penalties against financial institutions and maintains 'Instructions for Publishing Banking Penalties'. The CMA actively pursues market manipulation and securities fraud (e.g. May 2025 referral of suspects to Public Prosecution; Oct 2023 SAR 4.2m fines on two companies). The Anti-Financial Fraud and Breach of Trust Law (with Executive Regulations) criminalises fraud with penalties up to 7 years and SAR 5m. PDPL breaches carry fines up to SAR 5m supervised by SDAIA/SAMA. Payments disputes under the Law of Payments must first undergo a 30-day amicable settlement before judicial referral.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Legal & Litigation
Payments enforcement in Saudi Arabia is administrative and supervisory rather than common-law litigation-driven. SAMA publicly announces penalties and maintains 'Instructions for Publishing Banking Penalties'. The Anti-Financial Fraud and Breach of Trust Law criminalises fraud with penalties up to 7 years' imprisonment or SAR 5m. Payments disputes must undergo a 30-day amicable settlement before judicial referral, a structural feature that shapes dispute-resolution exposure for payment firms. Separately, the CMA pursues securities-fraud enforcement, and PDPL breaches carry penalties up to SAR 5m.
The mandatory 30-day amicable settlement and the administrative penalty model together define how enforcement and dispute resolution operate across both bank and non-bank supervised firms.
Outlook
The enforcement model is assessed as stable and administrative in character. Future cycles should track published SAMA penalty actions and any evolution in the amicable-settlement requirement as a leading indicator of supervisory posture toward payment firms.
Payments-related enforcement in KSA is administrative and supervisory rather than common-law litigation-driven. SAMA publicly announces penalties against financial institutions and maintains 'Instructions for Publishing Banking Penalties'. The CMA actively pursues market manipulation and securities fraud (e.g. May 2025 referral of suspects to Public Prosecution; Oct 2023 SAR 4.2m fines on two companies). The Anti-Financial Fraud and Breach of Trust Law (with Executive Regulations) criminalises fraud with penalties up to 7 years and SAR 5m. PDPL breaches carry fines up to SAR 5m supervised by SDAIA/SAMA. Payments disputes under the Law of Payments must first undergo a 30-day amicable settlement before judicial referral.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Acquiring is bank-led, dominated by Al Rajhi (~41% POS share) with Geidea providing the bulk of POS/softPOS hardware (~75%). mada integration is effectively mandatory for domestic card acceptance, alongside dual integration with Visa/Mastercard for cross-border. SAMA caps the mada debit MSC at 0.80% (~SAR 40 cap) protecting merchant margins. SAMA has issued new merchant-acquirer licences and opened QR/Tap-to-Phone acceptance, driving POS terminal counts past 1 million. Merchants must also integrate POS/ERP with ZATCA's 'Fatoora' e-invoicing portal (phased rollout, cryptographic stamps, penalties for non-compliance). Open-banking pay-by-bank is emerging as a lower-cost acquiring alternative.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Merchant Acquiring & Risk
Merchant acquiring in Saudi Arabia is bank-led and concentrated, with Al Rajhi at roughly 41% of POS terminals and Geidea at roughly 75% of hardware. mada integration is effectively mandatory for domestic card acceptance, sitting alongside dual Visa and Mastercard integration, and SAMA's 0.80% mada MSC cap protects merchant margins. Merchants must integrate POS and ERP systems with ZATCA 'Fatoora' e-invoicing, which uses cryptographic stamps and is being rolled out in phases. Open-banking Pay-by-Bank is emerging as a lower-cost alternative to card acceptance. BNPL providers such as Tabby and Tamara are SAMA-regulated and embedded across checkout; POS counts have passed one million, and POS card transactions grew from 2.9bn in 2020 to 10.4bn in 2024.
The dual mada-plus-international integration requirement plus ZATCA Fatoora compliance defines the acquiring-onboarding cost and operating burden for the Saudi market. Merchant-acquiring operational detail is a methodology under-indexed surface, captured here at standing-brief tier.
Outlook
The acquiring layer is bank-led, concentrated and operationally demanding, with the card-bypass Pay-by-Bank alternative the most significant emerging competitive vector. Future cycles should track Pay-by-Bank adoption against card volumes and the continued phasing of ZATCA e-invoicing obligations.
Acquiring is bank-led, dominated by Al Rajhi (~41% POS share) with Geidea providing the bulk of POS/softPOS hardware (~75%). mada integration is effectively mandatory for domestic card acceptance, alongside dual integration with Visa/Mastercard for cross-border. SAMA caps the mada debit MSC at 0.80% (~SAR 40 cap) protecting merchant margins. SAMA has issued new merchant-acquirer licences and opened QR/Tap-to-Phone acceptance, driving POS terminal counts past 1 million. Merchants must also integrate POS/ERP with ZATCA's 'Fatoora' e-invoicing portal (phased rollout, cryptographic stamps, penalties for non-compliance). Open-banking pay-by-bank is emerging as a lower-cost acquiring alternative.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
KSA innovation is regulator-led under Vision 2030's FSDP. SAMA launched the Open Banking Framework (Open Banking Policy Dec 2020; framework launched Nov 2022), with the Open Banking Lab (2022/2023) for conformance testing; Account Information Services then Payment Initiation Services (PIS, major update Sept 2024) are in production. SAMA runs a Regulatory Sandbox issuing limited test licences (open banking platforms XSquare/NeotTek, P2P lender MoneyMoon approved). The 'View My Bank Accounts' fraud-prevention service launched May 2024. CBDC research (wholesale, mBridge) and Tarabut/Sharia-compliant micro-lending pilots continue. STC Pay's conversion to a full digital bank exemplifies product build-out.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Product Innovation & Market Development
Saudi Arabia's open-banking surface is operational and maturing. SAMA launched the Open Banking Policy in December 2020, the Open Banking Lab in May 2022 and the framework in November 2022; Account Information Services and then Payment Initiation Services — with a major PIS update in September 2024 — are now in production. A 'View My Bank Accounts' fraud-prevention service launched in May 2024. The sandbox has approved XSquare and NeotTek for open banking and MoneyMoon for P2P lending, and only SAMA-authorised firms may use the APIs. Pay-by-Bank is operational, pulling funds via sarie and bypassing card networks, and STC Pay has converted to a fully licensed digital bank as STC Bank.
Operational PIS and Pay-by-Bank open a card-network-bypass product surface and a SAMA-authorised TPP market-access route across both bank and non-bank participants.
Outlook
The open-banking product surface is established and in production, with Pay-by-Bank the central card-bypass innovation to monitor. Future cycles should track sandbox graduations into the licensed market and the competitive impact of newly converted digital banks such as STC Bank.
KSA innovation is regulator-led under Vision 2030's FSDP. SAMA launched the Open Banking Framework (Open Banking Policy Dec 2020; framework launched Nov 2022), with the Open Banking Lab (2022/2023) for conformance testing; Account Information Services then Payment Initiation Services (PIS, major update Sept 2024) are in production. SAMA runs a Regulatory Sandbox issuing limited test licences (open banking platforms XSquare/NeotTek, P2P lender MoneyMoon approved). The 'View My Bank Accounts' fraud-prevention service launched May 2024. CBDC research (wholesale, mBridge) and Tarabut/Sharia-compliant micro-lending pilots continue. STC Pay's conversion to a full digital bank exemplifies product build-out.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Consumer protection is embedded in the Implementing Regulation (Part 5) and SAMA conduct rules, with a centralised Complaint Management System (replacing SAMACARES, effective 1/7/2025G) as the ombudsman-equivalent route. BNPL — large and consumer-facing (Tabby, Tamara, MIS Pay licensed/permitted by SAMA) — is regulated under the Rules for Regulating BNPL Companies (Decision 450360390000, 05/06/1445H), defining BNPL as no-term-cost consumer financing with SAR 5m minimum capital, credit limits, advertising transparency, conflict-of-interest and AML/CTF obligations. The 'View My Bank Accounts' service (May 2024) addresses account-verification fraud. There is no UK-style mandatory APP-fraud reimbursement scheme in force; sarie incorporates recipient account verification as a practical anti-error safeguard.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Consumer Protection & APP Fraud
Buy-now-pay-later is regulated in Saudi Arabia as a consumer-finance subcategory. BNPL falls under the Rules for Regulating BNPL Companies (Decision 450360390000, 05/06/1445H) as no-term-cost consumer financing under the Finance Companies Control Law, requiring a SAMA-licensed joint-stock company with SAR 5m minimum capital, 50% Saudization, credit limits, advertising transparency, conflict-of-interest controls and AML/CTF obligations. Tabby, Tamara and MIS Pay are permitted or licensed without taking deposits. These rules define the consumer-finance licensing and conduct perimeter for the largest KSA fintech segment.
On authorised-push-payment fraud, there is no UK-style mandatory APP-fraud reimbursement scheme in force; sarie recipient-account verification serves as a practical anti-error safeguard, and the Complaint Management System is the redress route. The absence of a mandatory reimbursement scheme is recorded as not-applicable-in-regime.
Outlook
The BNPL consumer-finance perimeter is established and codified, and it governs the conduct of the Kingdom's largest fintech segment. No mandatory APP-fraud reimbursement scheme is in force, so the consumer remedy for authorised-push-payment fraud beyond sarie recipient-account verification remains unspecified — a methodology under-indexed surface to watch. The SAR 5m capital and Saudization thresholds rest partly on Tier-3 commentary; primary corroboration would raise confidence.
Consumer protection is embedded in the Implementing Regulation (Part 5) and SAMA conduct rules, with a centralised Complaint Management System (replacing SAMACARES, effective 1/7/2025G) as the ombudsman-equivalent route. BNPL — large and consumer-facing (Tabby, Tamara, MIS Pay licensed/permitted by SAMA) — is regulated under the Rules for Regulating BNPL Companies (Decision 450360390000, 05/06/1445H), defining BNPL as no-term-cost consumer financing with SAR 5m minimum capital, credit limits, advertising transparency, conflict-of-interest and AML/CTF obligations. The 'View My Bank Accounts' service (May 2024) addresses account-verification fraud. There is no UK-style mandatory APP-fraud reimbursement scheme in force; sarie incorporates recipient account verification as a practical anti-error safeguard.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
sentinel.position: KSA's AML/CFT regime rests on the Anti-Money Laundering Law (Royal Decree M/20, 5/2/1439H) and the Law on Combating the Financing of Terrorism (M/21, 12/2/1439H), with implementing regulations and the SAMA AML/CTF Guide. SAMA supervises risk-based AML/CTF compliance for banks, PSPs and fintechs, with the Saudi Financial Intelligence Unit (SAFIU) receiving STRs. Saudi Arabia joined FATF in June 2019 (first Arab/37th member) and is a founding MENAFATF member; it is not on the FATF increased-monitoring (grey) list as of February 2026. SAMA also enforces Rules for Implementation of Targeted Financial Sanctions.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
AML/CFT & Financial Crime
This module is sourced from the Sentinel feed, and the World Payments Monitor carries provenance only; original illicit-finance analysis is routed to the Financial Intelligence Monitor as a cross-monitor flag. Per the Sentinel feed (sentinel.gi://rulebook.sama.gov.sa), KSA AML/CFT rests on the Anti-Money Laundering Law (Royal Decree M/20, 5/2/1439H) and the Law on Combating the Financing of Terrorism (M/21), with the SAMA AML/CTF Guide setting risk-based expectations. SAFIU receives suspicious-transaction reports. Saudi Arabia joined FATF in June 2019 as the first Arab and 37th member, is a founding MENAFATF member, and is not on the FATF increased-monitoring (grey) list as of 13 February 2026. SAMA also enforces Rules for the Implementation of Targeted Financial Sanctions.
FATF non-grey-list status and SAMA risk-based AML supervision are baseline compliance facts for any Saudi payments operator. Any original illicit-finance, sanctions-evasion or mutual-evaluation analysis for the Kingdom belongs to the Financial Intelligence Monitor.
Outlook
The AML/CFT baseline is Sentinel-sourced and stable as of the February 2026 FATF list. Future updates to this module follow the Sentinel feed; substantive illicit-finance assessment is referred to the Financial Intelligence Monitor.
sentinel.position: KSA's AML/CFT regime rests on the Anti-Money Laundering Law (Royal Decree M/20, 5/2/1439H) and the Law on Combating the Financing of Terrorism (M/21, 12/2/1439H), with implementing regulations and the SAMA AML/CTF Guide. SAMA supervises risk-based AML/CTF compliance for banks, PSPs and fintechs, with the Saudi Financial Intelligence Unit (SAFIU) receiving STRs. Saudi Arabia joined FATF in June 2019 (first Arab/37th member) and is a founding MENAFATF member; it is not on the FATF increased-monitoring (grey) list as of February 2026. SAMA also enforces Rules for Implementation of Targeted Financial Sanctions.
Evidence — 7 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- True