ألزم البنك المركزي السعودي «ساما» المؤسسات المالية باتخاذ 4 إجراءات لرفع مستوى الجاهزية استعداداً للمخاطر والتهديدات المحتملة المصاحبة للحوسبة الكمية.
وشدد «ساما» في تعميم على ضرورة إجراء تقييم للمخاطر المصاحبة للحوسبة الكمية على المستوى المؤسسي بما يتواءم مع إجراءات إدارة المخاطر المؤسسية لدى المؤسسة المالية، ووضع خطط عمل لمعالجة المخاطر الناتجة عن التقييم؛ على أن تشمل المخاطر التشغيلية والقانونية والتنظيمية والإستراتيجية بما يشمل الكوادر البشرية، وذلك بنهاية الربع الأول من عام 2027م.
دقة وشمولية الإجراءات
وأكد «ساما» ضرورة التأكد من دقة وشمولية الإجراءات لحصر وتصنيف كافة الأصول التشفيرية الخاصة بالمؤسسة المالية بنهاية الربع الرابع من العام 2026م، مع مراعاة القادم بحد أدنى: تحديد البيانات والنظم والخدمات المرتبطة بالأصول التشفيرية وتصنيفها من حيث الحساسية وأولوية انتقالها إلى الحلول التشفيرية المقاومة للحوسبة الكمية، وكذلك تقييم مستوى المرونة التشفيرية لأصول ذات الأولوية وتحديد القيود والتحديات وأوجه الاعتمادية على الأطراف الثالثة.
وطالب بوضع الخطط والمبادرات لتحقيق المستوى اللازم من المرونة التشفيرية أو الحلول البديلة المناسبة لكافة الأصول ذات الأولوية.
وشدد البنك المركزي السعودي على ضرورة إدراج مخاطر الحوسبة الكمية بنداً ثابتاً للمراقبة الدورية ضمن أعمال اللجنة الإشرافية لأمن المعلومات ولجنة المخاطر المنبثقة عن مجلس الإدارة لدى المؤسسة المالية - حيثما انطبق ذلك- والرفع بالتحديات والتوصيات لمجلس الإدارة أو من في حكمه.
المحافظة على الاستقرار النقدي
وذكر «ساما» أن إلزام المؤسسات المالية باتخاذ تلك الإجراءات يأتي ضمن صلاحيات البنك المركزي السعودي المنوطة، والهادفة إلى المحافظة على الاستقرار النقدي، وكذلك دعم استقرار القطاع المالي، وتعزيز الثقة به، إضافة إلى دعم النمو الاقتصادي، من خلال وضع التعليمات والإجراءات الكفيلة بحماية عملاء المؤسسات المالية، ووضع وإدارة السياسات الاحترازية واتخاذ الإجراءات والتدابير اللازمة للمؤسسات المالية، واتخاذ الإجراءات والتدابير اللازمة للمساهمة في مواجهة الاضطرابات والأزمات الاقتصادية والمالية، المحلية والإقليمية والعالمية، واتخاذ الإجراءات والتدابير المناسبة للحد من ارتكاب الجرائم المرتبطة بالمؤسسات المالية.
وأشار إلى استمرار جهوده الإشرافية والرقابية الرامية إلى تعزيز المتانة التشغيلية في القطاع المالي وما تبين من أهمية رفع مستوى الجاهزية استعداداً للمخاطر والتهديدات المحتملة المصاحبة للحوسبة الكمية
The Saudi Central Bank "SAMA" has mandated financial institutions to take 4 measures to enhance their readiness for potential risks and threats associated with quantum computing.
SAMA emphasized in a circular the necessity of conducting a risk assessment related to quantum computing at the institutional level, in line with the risk management procedures of the financial institution. It also called for the development of action plans to address the risks identified in the assessment; these should include operational, legal, regulatory, and strategic risks, including human resources, by the end of the first quarter of 2027.
Accuracy and comprehensiveness of measures
SAMA confirmed the need to ensure the accuracy and comprehensiveness of the measures to inventory and classify all cryptocurrency assets of the financial institution by the end of the fourth quarter of 2026, taking into account at a minimum: identifying the data, systems, and services related to cryptocurrency assets and classifying them in terms of sensitivity and priority for transitioning to quantum-resistant cryptographic solutions, as well as assessing the level of cryptographic resilience for priority assets and identifying constraints, challenges, and dependencies on third parties.
It called for the development of plans and initiatives to achieve the necessary level of cryptographic resilience or suitable alternative solutions for all priority assets.
The Saudi Central Bank stressed the importance of including quantum computing risks as a permanent item for periodic monitoring within the activities of the information security oversight committee and the risk committee arising from the board of directors of the financial institution—where applicable—and reporting challenges and recommendations to the board of directors or its equivalent.
Maintaining monetary stability
SAMA stated that mandating financial institutions to take these measures falls within the powers of the Saudi Central Bank, aimed at maintaining monetary stability, supporting the stability of the financial sector, and enhancing confidence in it, in addition to supporting economic growth by establishing instructions and measures that protect the clients of financial institutions, managing precautionary policies, and taking necessary actions and measures for financial institutions, as well as taking appropriate actions and measures to contribute to addressing economic and financial disruptions and crises, whether local, regional, or global, and taking appropriate actions and measures to reduce the commission of crimes related to financial institutions.
It pointed out the continuation of its supervisory and regulatory efforts aimed at enhancing operational resilience in the financial sector and the importance of raising the level of readiness for potential risks and threats associated with quantum computing.