Financial Services and FinTech Market Entry in Saudi Arabia
Saudi Arabia’s financial sector is regulated according to the specific activity being performed. Payments, lending, insurance, banking, investment management, securities advisory, crowdfunding, digital assets and financial technology platforms can fall under different regulators and licensing frameworks.
Establishing the Saudi company is only the first step. Regulated firms must also satisfy capital, governance, compliance, technology, cybersecurity and operational requirements before commencing business.

Key Regulatory Authorities

1. Saudi Central Bank
The Saudi Central Bank, commonly known as SAMA, regulates activities including:
- Banking and deposit-taking activities
- Payment institutions and electronic money institutions
- Consumer finance, microfinance and other financing activities
- Insurance and insurance-related activities
- Open banking services
- Certain financial technology platforms and products
Payment providers may require authorisation as a micro or major Payment Institution, or as a micro or major Electronic Money Institution, depending on the services and scale of the operation. SAMA commenced formal licensing of open banking service providers in March 2026 following the earlier regulatory sandbox phase.
2. Capital Market Authority
The Capital Market Authority regulates securities-related activities, including:
- Dealing in securities
- Arranging investments
- Investment management and fund operation
- Securities advisory
- Custody services
- Capital market platforms and certain crowdfunding models
Any company carrying out a regulated securities business in Saudi Arabia must obtain the relevant CMA authorisation. The licensing route depends on the exact activities the applicant intends to conduct.
Typical Approvals and Requirements

1. Regulatory Classification
The proposed product, platform and revenue model must first be analysed to determine:
- Whether the activity is regulated
- Which regulator has jurisdiction
- The appropriate licence category
- Whether the company can operate as a technology provider rather than a regulated financial institution
- Whether sandbox testing or full licensing is required
2. Initial or In-Principle Approval
Many regulated financial businesses must obtain an initial regulatory approval before completing the full operational build-out.This stage may require:
- Detailed business plan
- Financial projections
- Ownership and group structure
- Source of funds information
- Governance framework
- Product and customer journey documentation
- Risk and compliance frameworks
- Technology architecture
- Outsourcing arrangements
3. Capital Requirements
Minimum capital varies substantially according to the licence.For example, SAMA currently identifies minimum initial capital requirements of:
- SAR 1 million for a micro Payment Institution
- SAR 3 million for a major Payment Institution
- SAR 2 million for a micro Electronic Money Institution
- SAR 10 million for a major Electronic Money Institution
Higher capital or financial resources may be required depending on the activity, risk profile and regulator assessment.
4. Governance and Senior Management
Regulators may assess and approve:
- Board members
- Chief executive or general manager
- Compliance officer
- Money laundering reporting officer
- Risk officer
- Finance officer
- Technology and cybersecurity leadership
- Other controlled or registered functions
The regulator will typically evaluate the qualifications, experience, independence and fitness of key individuals.
5. AML, Compliance and Consumer Protection
Regulated firms must implement frameworks covering:
- Anti-money laundering and counter-terrorist financing
- Know Your Customer procedures
- Sanctions screening
- Transaction monitoring
- Suspicious transaction escalation
- Customer complaints
- Consumer disclosures
- Data retention
- Conflicts of interest
- Regulatory reporting
6. Technology, Data and Cybersecurity
Digital financial businesses may also require:
- Cybersecurity controls aligned with the relevant regulatory framework
- Data-hosting and data-governance arrangements
- Business continuity and disaster recovery systems
- Penetration testing and security assessments
- Technology audit and system readiness testing
- Personal data compliance
- Approval of material outsourcing arrangements
7. Commencement of Business Approval
Receiving an initial licence does not always allow immediate trading. The regulator may require the applicant to demonstrate that its people, systems, capital, policies and premises are fully operational before granting final commencement approval.
CMA licensing announcements, for example, distinguish between regulatory licensing and completion of the requirements necessary to commence business.
How We Support
We support financial services & FinTech companies with:
01
Regulatory activity assessment
02
SAMA and CMA regulatory pathway assessment
03
Saudi entity and ownership structuring
04
Business plan and application coordination
05
Governance and controlled-function planning
06
AML and compliance framework coordination
07
Operational readiness support and regulator engagement
08
Post-licensing operational readiness support


