CMA Compliance Documentation for Capital Market Institutions in Saudi Arabia
The Capital Market Authority requires extensive documentation from authorised persons. Here's what's required, common inspection findings, and how to review CMA compliance documentation.
Saudi Arabia's Capital Market Authority regulates the largest stock exchange in the Middle East. Tadawul's market capitalisation exceeds SAR 10 trillion, with a growing number of listed companies driven by Vision 2030's privatisation and IPO agenda. Every CMA-authorised person — from investment banks to asset managers to brokerage firms — must maintain documented compliance frameworks that satisfy increasingly rigorous CMA inspections.
The CMA's regulatory approach has matured significantly since Vision 2030's launch. Inspection frequency has increased, enforcement has become more active, and documentation expectations have risen. Authorised persons that maintained minimal compliance documentation under the previous regime are now facing findings that require substantial remediation.
CMA Authorisation Categories
| Category | Activities | Documentation Intensity |
|---|---|---|
| Dealing | Buying, selling, managing securities transactions | High |
| Managing | Discretionary portfolio management | High |
| Arranging | Arranging deals, advising on mergers/acquisitions | High |
| Advising | Investment advice to clients | Medium-High |
| Custody | Safekeeping of securities | High |
Each category carries specific documentation requirements in addition to the core compliance documentation that all authorised persons must maintain.
Core Compliance Documentation
1. Compliance Manual
The foundation document for every CMA-authorised person.
| Section | Requirements |
|---|---|
| Regulatory framework | Capital Market Law, Authorised Persons Regulations, relevant CMA rules and instructions |
| Organisational structure | Compliance function, reporting lines, compliance officer appointment |
| Client classification | Categories (institutional, qualified, retail), classification procedures, ongoing monitoring |
| Conduct of business | Fair dealing, best execution, suitability, disclosure obligations |
| AML/CFT | Anti-money laundering programme under the Anti-Money Laundering Law and CMA Rules |
| Market conduct | Insider trading prevention, market manipulation prevention, personal dealing |
| Conflict of interest | Identification, management, disclosure, Chinese walls |
| Complaints handling | Procedures aligned with CMA requirements |
| Record keeping | Retention requirements, formats, accessibility |
| Business continuity | BCP and disaster recovery plans |
| Reporting | Regulatory reporting obligations to the CMA |
2. Client Classification Documentation
The Authorised Persons Regulations require documented client classification:
| Client Type | Documentation Required |
|---|---|
| Institutional client | Verification of institutional status, acknowledgement of reduced protections |
| Qualified client | Evidence meeting qualification criteria (net assets, professional experience, or relevant certifications) |
| Retail client | Full suitability assessment, risk disclosure, product suitability documentation |
Reclassification: Clients may request reclassification. Documentation must evidence: the request, assessment against criteria, approval or rejection with rationale, and client acknowledgement of changed protections.
3. AML/CFT Documentation
Required under the Anti-Money Laundering Law and CMA's Anti-Money Laundering and Counter-Terrorist Financing Rules:
| Document | Requirement |
|---|---|
| Risk assessment | Institutional ML/TF risk assessment covering customers, products, geographies, delivery channels |
| CDD policies | Customer identification, verification, beneficial ownership, ongoing monitoring |
| Enhanced due diligence | EDD procedures for high-risk customers, PEPs, correspondent relationships |
| Transaction monitoring | Monitoring programme documentation, alert investigation procedures |
| STR procedures | Suspicious transaction reporting to the Financial Investigation Unit (SAFIU) |
| Sanctions screening | Screening programme against UN, local, and relevant international sanctions lists |
| Training programme | AML/CFT training curriculum, records, and assessment |
| Compliance officer appointment | Designated AML/CFT compliance officer with documented responsibilities |
4. Suitability and Advisory Documentation
For authorised persons providing investment advice:
| Document | Requirement |
|---|---|
| Client profile | Financial situation, investment objectives, risk tolerance, investment knowledge and experience |
| Suitability assessment | Documented analysis linking the recommendation to the client's profile |
| Product due diligence | Analysis of recommended products' risks, costs, and features |
| Risk disclosure | Written disclosure of material risks to the client |
| Recommendation record | Record of every recommendation made, including rationale |
5. Best Execution Documentation
| Document | Requirement |
|---|---|
| Best execution policy | Execution factors, order handling procedures, venue selection |
| Execution analysis | Periodic analysis of execution quality |
| Client disclosure | Best execution policy disclosed to clients |
| Order records | Complete records of all orders with timestamps |
Common CMA Inspection Findings
Finding 1: Inadequate Client Classification
Clients classified without proper documentation, particularly for qualified client status. Missing evidence of net asset verification, professional experience documentation, or client acknowledgement of classification and associated protections.
Finding 2: AML/CFT Programme Deficiencies
Risk assessments that don't reflect the authorised person's specific risk profile. CDD records with incomplete beneficial ownership identification. Transaction monitoring without documented investigation procedures for alerts.
Finding 3: Suitability Gaps
Investment recommendations without documented suitability analysis, or suitability assessments that are generic rather than client-specific. The CMA increasingly scrutinises the quality of suitability documentation, not just its existence.
Finding 4: Outdated Compliance Manual
Compliance manuals that don't reflect current CMA rules and instructions. The CMA regularly issues new rules, amendments, and circulars — compliance manuals must be updated accordingly.
Finding 5: Insufficient Conflict of Interest Management
Conflicts identified but not documented, managed, or disclosed. Missing conflicts register. No evidence of periodic conflict reviews.
Reviewing CMA Compliance Documentation
Compliance Manual Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Completeness | 3 | All Authorised Persons Regulations requirements addressed |
| Currency | 3 | References current CMA rules, instructions, and circulars |
| Specificity | 2 | Reflects the authorised person's specific activities and risk profile |
| Practicality | 2 | Procedures detailed enough for staff to follow consistently |
| Consistency | 1 | No contradictions between sections or with other policy documents |
AML/CFT Documentation Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Risk-based approach | 3 | Programme proportionate to the authorised person's ML/TF risk profile |
| CDD completeness | 3 | All client files contain required identification and verification |
| Transaction monitoring | 2 | Monitoring rules documented, alerts investigated with records |
| Training | 2 | All relevant staff trained with documented attendance |
| Reporting | 1 | STR procedures documented, compliance officer designated |
Frequently Asked Questions
How often does the CMA inspect authorised persons?
The CMA conducts risk-based inspections. Higher-risk authorised persons (larger client bases, more complex activities) face more frequent inspections. All authorised persons should maintain inspection-ready documentation at all times. The CMA also conducts thematic reviews targeting specific compliance areas across the industry.
What are the consequences of CMA findings?
The CMA can impose corrective measures, financial penalties, suspension of activities, or revocation of authorisation. Penalties can be substantial. The CMA publishes enforcement actions, creating significant reputational consequences.
How does Saudi AML/CFT regulation compare internationally?
Saudi Arabia is a FATF member and has undergone mutual evaluation. The AML framework aligns with FATF Recommendations. Recent amendments have strengthened beneficial ownership requirements, PEP identification, and virtual asset regulation. The framework is increasingly comparable to international standards.
Can AI review help with CMA compliance documentation?
AI review can check compliance manuals for completeness against Authorised Persons Regulations requirements, verify currency of regulatory references, assess CDD documentation completeness, and check consistency across policy documents. Regulatory adequacy assessment requires qualified compliance professionals familiar with CMA expectations.
Key Takeaways
- CMA documentation requirements have increased significantly under Vision 2030's regulatory modernisation.
- Client classification documentation is the most common inspection finding — proper documentation of classification criteria and client acknowledgement is essential.
- AML/CFT programmes must be risk-based and reflect the authorised person's specific risk profile.
- Suitability documentation must be client-specific — generic assessments are increasingly cited in inspections.
- Update compliance manuals whenever the CMA issues new rules, amendments, or circulars.
- AI review checks completeness, currency, specificity, and consistency — regulatory adequacy requires qualified compliance professionals.
This article is for informational purposes only. CMA regulatory requirements evolve through new rules, instructions, and circulars. Consult a qualified compliance professional or legal adviser for guidance specific to your authorised person category and activities.