Regulatory Compliance in Saudi Arabia: Frameworks, Governance, and Implementation A Systematic Review of the Post-Vision 2030 Regulatory Environment (2017–2025)
Keywords:
Aml/Cft, Anti-Corruption, Corporate Governance, Cybersecurity, Data Protection, Regulatory Compliance, SaudiArabia, Tax Compliance, Vision 2030Abstract
This systematic review provides a picture of the Saudi regulatory compliance environment after Vision 2030 (2017–2025), combining official regulatory instruments and peer-reviewed empirical literature. The review examines changes in the compliance governance landscape and proposes a comprehensive compliance governance framework for Saudi organizations. The study uses a systematic qualitative content analysis coupled with regulatory mapping across six compliance domains: financial regulation and anti-money laundering; corporate governance and disclosure; data protection; cybersecurity; anti-corruption; and taxation. After a structured search in Google Scholar, Scopus, Web of Science, HeinOnline, Westlaw, and official regulatory databases (SAMA, CMA, SDAIA, NCA, ZATCA, Nazaha), 50 sources have been selected using explicit criteria: peer-reviewed articles and official regulatory documents/legal frameworks published between 2017 and 2025; non-academic commentary; and obsolete pre-2017 instruments were excluded. The results demonstrate a clear evolution from fragmented and sanction-oriented regulatory environment to consolidated and risk-based system, characterized by specialized regulators, codified rulebook, digital compliance infrastructure, and harmonization with international standards set by Basel, FATF, G20, and OECD. Moreover, the review highlights implementation issues including regulatory fragmentation, insufficient compliance capacity, disproportional impact on small and medium-sized enterprises, and inconsistency of enforcement. Based on the results of the systematic review, the paper proposes an Integrated Compliance Governance Framework (ICGF) consisting of four pillars: regulatory intelligence; risk-based control environment; integrity culture and accountability; and technology-enabled assurance with a phased implementation roadmap. This review is the first comprehensive systematic effort to outline the post-Vision 2030 Saudi compliance architecture and provides a useful tool for regulators and organizational leadership.