Skip to main content

Instant SMS Notification Service

No: 321000009006 Date(g): 23/3/2011 | Date(h): 18/4/1432

Translated Document

Referring to the steady increase in the use of electronic channels by banks operating in the Kingdom and in continuation of what has been implemented in SAMA's Circular No. 40690/MAT/789 dated 15/08/1430 H regarding the application of multiple identity verification standards for electronic banking services and in the interest of SAMA in continually enhancing the level of protection for banking services provided to customers by banks operating in the Kingdom, and continuing to SAMA's approach for adopting the latest globally applied protection technologies in this regard (Best Practice), and given that providing instantaneous notification services to customers through SMS can help reduce financial fraud crimes, in addition to increasing the level of trust in banking channels (E-Trust) and enhancing the level of transparency between banks and their customers , and after studying the recommendations of the Banking Committee for Information Security (BCIS) on the subject.

We inform you that the bank must implement an automated notification service through SMS for all banking transactions conducted on personal bank accounts and credit card accounts (both credits and debits), while taking precautionary measures to prevent the misuse of the content of the text messages sent to customers, including, for example, the following procedures:

  • The current account balance is not included in the text message.
  • Masking the full credit card number, current account number, or ATM card number in accordance with the specifications outlined in the Payment Card Industry Data Security Standard (PCI DSS).
  • The text should include the date, time, amount, and type of transaction.
  • The bank is committed to automatically activating the service for all customers, while notifying them of the option to request its cancellation in writing if they do not wish to have it.
  • To provide the service to all bank customers without charging them any additional fees, while taking into account the need to inform customers before implementing it.
  • Adherence to the implementation of these requirements must be completed by no later than 1/9/2011G.