Digital Transformation Standards
Digital Transformation Standards
Basic Standards
19 March 2024
1. Introduction 4
2. Objectives 5
7. Appendices 119
7.4 High Orders, Council of Ministers Resolutions and Relevant Circulars 124
7.6 List of relevant government agencies according to the scope of standards 138
raising quality of services, enhancing beneficiary experience of such services, supporting digital transformation and
contributing to increasing investment returns and the value of the national economy, in order to achieve the
aspirations of our ambitious vision 2030 to reach advanced levels in the field of digital government.
Since the Digital Government Authority (DGA) is the competent authority for all matters related to digital government,
and the national reference in its affairs, and based on its competence to regulate the activities of digital government
in government agencies, as stipulated in Article (3) of the Digital Government Authority Regulations issued by the
Council of Ministers’ Resolution No. (418) dated 25/07/1442 AH,. Referring to the provisions of the fifth and sixth
paragraphs of Article (4) of the aforementioned Regulations, which state on the functions and competencies of the
Digital Government Authority, involving: “Issuance of metrics, indicators, tools and reports, to measure the
performance of Government Agencies and their capabilities in the field of digital government and beneficiary's
satisfaction, as well as to follow up on Government Agencies’ compliance with decisions and high orders issued in
relation to digital government transactions, in accordance with the frameworks and standards set by the DGA.”
From this standpoint, the Digital Government Authority (DGA) has developed the third issue of the "Digital
Transformation Basic Standards" document, as one of the standards issued by the DGA, and government agencies
must adhere to its provisions. It is also the primary tool for measuring the performance and capabilities of government
agencies in the field of digital government; through the Digital Transformation Measurement Index. The document
included the controls and standards drawn from the DGA’s Regulations, High Orders, Council of Ministers’ Resolutions
and circulars issued in this regard. The document is one of the regulatory documents for the digital government
regulatory framework, and it contributes effectively to creating a regulatory environment that supports sustainable
government digital transformation. It also enhances the capabilities of government agencies and improve their level
of performance and effectiveness, which in turn will be reflected in accelerating the pace of government digital
transformation.
The document clarifies the methodology for measuring digital transformation and its basic levels. The digital
transformation standards are one of those levels that apply the "concept of digital transformation" by strategically
transforming and developing business models to digital models based on data and advanced technologies.
This document aims to define the digital transformation standards by clarifying their compliance
requirements and supporting documents for each standard, in order to achieve the following:
The Digital Government Authority (DGA) has developed the "Digital Transformation Measurement Methodology" in
this document by integrating the standards derived from High Orders, Council of Ministers’ Resolutions, circulars and
the digital transformation standards into one section under the name "Digital Transformation Basic Standards". Figure
(1) shows the result of merging the two sections. This merger aims to improve alignment with international
experiences in measuring digital transformation and provide a unified reference framework that supports the concept
of Whole-of-Government, and standardize and simplify standards and avoid repetition of some (related) topics, which
previously appeared in both sections. "Creativity in Digital Transformation" has also been developed previously to
become one of the digital transformation standards in this document, under the name of "Research and Innovation".
It includes aspects related to institutional innovation and innovative solutions to enable Government agencies to
improve their readiness towards adopting innovation and sustaining the innovative environment, in addition to
measuring the impact of sustaining innovative solutions and following up on their continuous improvement.
2. Digital Transformation
Standards
1. Sections: They represent the first level of the methodology and main component of the digital transformation
process that reflects the strategic directions of digital government. There are ten main sections, including a
2. Axes: They represent the second level of the methodology. Axes are related to the topic of the section it drawn
upon. They are twenty-three axes, and each axis includes a number of digital transformation standards.
3. Standards (Digital Transformation Standards): They represent the third level of the methodology. The
standards are a set of metrics, rules and controls governing processes and tasks related to digital government.
5.1 5.10
5.4
Digital Culture Systems that 5.16 5.19 Data
Digital support digital Beneficiary Governance and
and 5.8
Transformation transformation 5.14 Digital Participation Management 5.22
Environment
Planning Services Institutional
Risks
Quality Innovation
Management
5.15 Digital
5.9 Channels 5.23
Business and Innovative
5.3 5.6 Continuity Services 5.18 Solutions
5.12 Cloud 5.21 Open
Beneficiary
Institutional Building Architecture Data
Experience
Architecture Competencies
from High Orders, Council of Ministers’ Resolutions, circulars and digital transformation standards into one section.
The card included the "number and text of the standard" related to the axis, in addition to the "objective" of applying
the standard and the expected results. The card also included the “compliance requirements” that explain and clarify
the main requirements for applying the standard (with sequential or non-sequential conditions or specific steps).
The standard card contains "proof documents" that clarify the mechanism for verifying the application of the
standard, whether it is (a report, document, attachment of a specific plan, forms or certificate), as stipulated in the
document. The card highlights the orders, decisions, circulars and the like related to digital transformation. The card
specifies the relevant government agencies, which must apply that standard; the scope may include all government
agencies or allocated to specific agencies. These agencies have been identified and updated in the list of government
Standard
Text of the Standard
Number
Objective Objective and expected impact
<Requirement1>
Compliance
<Requirement2>
Requirements
<...>
Scope
Defining government entities for which the standard is applicable
The DGA has prepared this document to define the digital transformation standards that government
agencies must apply and adhere to, in accordance with the following:
It includes three main axes aimed at developing strategic plans for digital transformation, according to the
following:
• Digital transformation planning.
• Digital Transformation governance.
• Institutional structure.
It includes three main axes aimed at enhancing digital culture of the Agency's employees, according to the
following:
• Digital Culture and Environment.
• Developing digital transformation leaders.
• Building competencies.
It includes a main axis aimed at designing and documenting work procedures and processes in the government
agency, according to the following:
• Work procedures.
It includes two main axes aimed at enhancing the agency's ability to identify risks that would affect the
continuity of digital government services, according to the following:
• Risks Management.
• Business Continuity.
•
It includes three main axes aimed at fulfilling requirements of the application and systems architecture that
support digital transformation, according to the following:
• Systems supporting digital transformation.
• Technical services infrastructure.
• Cloud architecture.
It includes a main axis aimed at promoting the application of the whole-of-government approach, according to
the following:
• Whole-of-government platforms.
It includes two main axes aimed at identifying all channels through which the agency can provide the services, according
to the following:
• Digital services quality.
• Digital channels and services.
It includes three main axes aimed at enhancing the role of the beneficiary and transforming it to an effective partner in
the development and improvement of digital government services, according to the following:
• Beneficiary participation.
• enhancing the relationship with the beneficiary.
• Beneficiary experience.
It includes three main axes aimed at implementing the regulations and standards related to government data and its
development mechanism, according to the following:
• Data governance and management.
• Data usage and availability.
• Open data.
It includes two main axes aimed at adopting innovation and sustaining the innovative environment, according to the
following:
• Institutional innovation.
• Innovative solutions.
The axis includes the development of a digital transformation plan and a roadmap developed by the government agency for the
development of basic systems and processes, to define the agency's vision and the strategic objectives that the agency wishes to
achieve from digital transformation.
Developing a strategic plan for digital transformation to be in line with the DGA’ strategy and the
Objective
objectives of the Saudi Vision 2030.
Supporting 1) Attaching the approved strategic plan for digital transformation, which includes all compliance
documents requirements of the standard, to be approved within a period not exceeding 36 months.
Related Orders,
▪ Council of Ministers’ Resolution No. (40) dated 27/02/1427 AH, Paragraph No. (16).
Resolutions and
Circulars
Supporting 1) Attaching the approved implementation plan for digital transformation, which includes all
documents compliance requirements of the standard, to be approved within a period not exceeding 12 months.
Related Orders,
▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Resolutions and
Circulars
Establishment of a unit for managing digital transformation projects to ensure efficiency of digital
Objective
projects, and follow up the digital transformation progress.
1) Attaching a document proving that the agency has established an office to manage digital
transformation projects.
Supporting
2) Attaching the approved structure of the digital transformation projects management unit to clarify
documents
the limits of powers and responsibilities.
3) Providing a copy of the report pages that prove that the agency has included the digital
transformation measurement report in its annual report.
Related Orders,
▪ Council of Ministers’ Resolution No. (40) dated 27/02/1427 AH, Paragraph No. (22).
Resolutions and
▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs(1), (10) and (18).
Circulars
Developing a general framework for digital transformation governance that aims to follow up on the
Objective
implementation of digital transformation plans and ensure the achievement of the objectives.
1) Developing a digital transformation governance framework that covers all initiatives and
processes related to digital transformation.
2) Defining the monitoring and measurement mechanism, and the periodic reporting forms, through
which progress in the implementation of digital transformation initiatives and projects will be
measured.
Compliance 3) Identifying departments and committees responsible for governance and change processes,
Requirements including the governance and management of shared products and services.
4) Unifying the departments supervising information technology under a general department
named the General Department of Information Technology and linked to the chief officer or his
representative, and allocating a properly qualified general manager.
5) Formatting the e-Transactions/Digital Transformation Committee under the chairmanship of the
chief officer or his representative and membership of the relevant departments/ agencies.
1) Attaching an approved governance framework that fulfills the compliance requirements related
to this standard and clarifies the mechanisms for following on up implementation and measuring
performance.
2) Attaching evidences proving that the agency has identified the departments and committees
responsible for governance and change processes, including the governance and management of
shared products and services.
3) Attach the agency's organizational structure, showing the unification of the departments
Supporting supervising information technology under one general department.
documents 4) The decision to appoint the IT general manager or a statement from the Enterprise Resource
Management System stating that a Saudi qualified person has been appointed at this position.
5) Submitting a decision to form an internal committee concerned with everything related to e-
government transactions or digital transformation, with a clarification of the administrative
positions of the committee members and membership of the chief officer for each department
concerned with e-government transactions, and chief officer responsible for information
technology and administrative development. It shall be headed by the agency's chief officer or
his representative. The main tasks of this committee include the supervision and follow up on the
Attaching documents and samples that prove the agency's compliance with the requirements of
applying this standard:
1) 3 Samples of initiative cards.
2) 3 Samples of periodic performance reports.
Supporting
3) 3 Samples of minutes of meetings.
documents
4) 3 Samples of corrective decisions and actions.
5) Attaching samples of the documents proving that the agency has a methodology, policies and
processes for managing the projects.
6) Attaching samples of project management forms that meet the requirements of applying this
standard.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (10).
Circulars
Implementing mechanisms for governance of initiatives and joint projects between the agencies to
Objective achieve the objectives in the digital transformation, control the progress of the implementation
processes and take the necessary corrective actions.
Attaching documents and samples that prove the agency's compliance with the requirements of
applying this standard:
Supporting 1) Shared Governance Mechanism.
documents 2) Sample of the decisions to form joint committees.
3) 3 samples of periodic performance follow up reports.
4) 3 Samples of minutes of meetings.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
The axis includes practices and controls to study the current state of the government agency, and build a roadmap for the
transition to the future state to achieve alignment between the business sector (services and procedures), information
technology (data, applications, and infrastructure), and the government agency’s strategic objectives.
Establishing the Enterprise Architecture Unit to support the recognition of strategic objectives and
Objective
digital transformation.
1) Launching a project for the Enterprise Architecture at the agency through an internal team or
through external consultants.
2) Establishing an organizational unit for the Enterprise Architecture to be directly linked to the
Compliance
agency’s senior management, or to the unit supervising digital transformation.
Requirements
3) Forming a committee for the governance of Enterprise Architecture.
4) Developing or adopting a model for the Enterprise Architecture unit to interact with other
administrative/ organizational units.
5) Preparing and approving Enterprise Architecture policies and procedures.
Accreditation certificate in the event that the agency obtains the national Enterprise Architecture
accreditation certificate (third or fourth level) within a period not exceeding two years from the date of
its issuance. The certificate can be accepted as a proof document within a maximum of three months
from its expiry date.
If this certificate is not available, the agency must provide the following:
1) An approved document proving the launch of an Enterprise Architecture project at the agency
Supporting through an internal work team or through external consultants. This document shall include the
documents Enterprise Architecture scope and the time plan of the project.
2) An approved document proving the establishment of an administrative unit for the Enterprise
Architecture.
3) An approved document of the formation of a governance committee and structure and mechanism
of its work.
4) An approved document for the interaction model between the Enterprise Architecture unit and
other administrative/ organizational units at the agency.
5) An approved document of the Enterprise Architecture policies and procedures.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (9).
Circulars
Applying the Enterprise Architecture practice and enhancing institutional work by taking advantage of
Objective
Enterprise Architecture methodologies in digital transformation.
1) Determining the applied Enterprise Architecture methodology such as Nora or other methodologies
to be valid for application and identifying and building the general model of the Enterprise
Architecture components (Metamodel).
2) Developing objectives, requirements and challenges and aligning them with strategic objectives.
3) Documenting the current state of business architecture, application architecture, data architecture
and technical architecture at the agency, and the documentation level required (conceptual, logical,
physical).
4) Developing documents on the future status of the business architecture, application architecture,
data architecture and technical architecture at the agency, based on the strategic objectives of the
agency's digital transformation, while benefiting from the international references appropriate to
Compliance
the agency's work nature and the services it provides.
Requirements
5) Listing and analyzing the gaps between the current and future status and classifying them into
interconnected working groups.
6) Developing a roadmap for digital transformation to implement the initiatives and projects resulting
from the gap analysis process. The roadmap shall include the following points:
Accreditation certificate in the event that the agency obtains the national Enterprise Architecture
accreditation certificate (third or fourth level) within a period not exceeding two years from the date of
its issuance. The certificate can be accepted as a proof document within a maximum of three months
from its expiry date.
If this certificate is not available, the agency must provide the following:
documents 2) Alignment document between the Enterprise Architecture’s objectives and the agency's strategic
objectives.
3) Current state documents of business architecture, application architecture, data architecture and
technical architecture at the agency.
4) Future state documents of business architecture, application architecture, data architecture and
technical architecture and alignment with the Enterprise Architecture’s objectives.
6) Document of the agency's digital transformation roadmap, indicating (initiatives and projects,
performance indicators, schedule, and follow-up and measurement mechanisms).
7) Samples of indicator board, reports and components of the Enterprise Architecture repository.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (9).
Circulars
Enhancing the Enterprise Architecture’s role in following up and implementing the digital
Objective
transformation map.
1) Benefiting from the technical systems and Enterprise Architecture repository to reflect the data of
Enterprise Architecture components and follow up the implementation processes related to the
roadmap.
2) Monitoring and updating the Enterprise Architecture components continuously.
3) Implementing digital transformation initiatives and projects in alignment with the concerned
Compliance departments.
Requirements 4) Issuing periodic reports on the implementation of Enterprise Architecture through technical
systems and Enterprise Architecture repository, and measuring performance indicators.
5) Working continuously, through the unit responsible for Enterprise Architecture, to study and
analyze periodic reports and take preventive and corrective decisions and actions necessary to
achieve the digital transformation’s objectives at the agency, based on the approved governance
framework.
Accreditation certificate in the event that the agency obtains the national Enterprise Architecture
accreditation certificate (third or fourth level) within a period not exceeding two years from the date
of its issuance. The certificate can be accepted as a proof document within a maximum of three
months from its expiry date.
If this certificate is not available, the agency must provide the following:
Supporting 1) Sufficient samples of technical systems and Enterprise Architecture repository proving the agency's
documents compliance with the application requirements related to this standard (3 samples).
2) Samples of periodic reports issued from technical systems and Enterprise Architecture repository
(3 samples).
3) Official minutes and documents proving that the agency has studied and analyzed periodic reports
and performance indicators and taken the necessary corrective and preventive decisions and
actions (3 samples).
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
Enhancing the Enterprise Architecture unit's role in sustaining digital transformation/ financial planning
Objective
participation/ achievement of strategic objectives.
1) Developing digital transformation plans on an ongoing basis to benefit from and take advantage of
previous stage results to achieve the agency's objectives and enhance the utilization of technology,
and enable the agency to accurately measure performance through periodic reports issued by the
Compliance
Enterprise Architecture unit and the Enterprise Architecture repository.
Requirements
2) Using and applying the latest technologies in implementing digital transformation plans.
3) Monitoring performance indicators and governance processes, by providing proactive reports to
senior management that contribute to improving performance, reducing costs and financial and
time resources, and achieving the Enterprise Architecture's benefits and values.
Accreditation certificate in the event that the agency obtains the national Enterprise Architecture
accreditation certificate (fourth level) within a period not exceeding two years from the date of its
issuance. The certificate can be accepted as a proof document within a maximum of three months from
its expiry date.
Supporting
If this certificate is not available, the agency must provide the following:
documents
1) Documents proving that the agency has developed and updated digital transformation plans on an
ongoing basis, based on the Enterprise Architecture’s reports.
2) Documents proving that the agency has employed the latest technologies to improve Enterprise
Architecture practice and digital transformation.
3) Periodic reports of the institutional structure on follow-up and impact assessment.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
The axis includes practices and programs that raise the familiarity level of digital transformation concepts and adopt these
concepts in the organization to contribute to the promotion of digital culture among the government agency’s employees.
5.4.1 Preparing Studies and Programs for the Promotion of Digital Culture and Environment
Identifying the level of awareness among the government agencies’ employees of digital
Objective
transformation and preparing the studies and programs necessary to raise this awareness.
1) Preparing a study to determine the level of awareness of the agency's employees about digital
transformation and its importance, and their familiarity with digital transformation plans and
initiatives and their completion rates, as well as the fields of digital transformation. Then,
identifying the gaps in this regard at the different levels within the agency.
Compliance 2) Preparing awareness programs for the government agency's employees on the importance of
Requirements digital transformation processes, to include:
a. Identification of the targeted groups and objectives to raise awareness of digital
transformation among the agency's employees in various units and administrative levels.
b. Choosing the means and channels that will be used in the programs aimed at raising awareness
of digital transformation and the schedule for implementing these programs.
1) Attach documents proving that the agency has studied the level of awareness of its employees
Supporting about digital transformation.
documents 2) Attaching awareness programs document prepared by the agency to raise awareness of its
employees about digital transformation, which meets the requirements of applying this standard.
Related Orders,
▪ Council of Ministers’ Resolution No. (40) dated 27/02/1427 AH, Paragraph No. (16).
Resolutions and
▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, Paragraph No. (3).
Circulars
1) Implementing awareness programs for the government agency’s employees on the importance
of digital transformation, and establishing the activities and events necessary in this respect.
2) Organizing awareness workshops for the agency’s employees on the need to abide by laws and
regulations related to controls of using information and communication technologies.
3) Organizing events to introduce the agency’s employees to digital transformation plans and
Compliance
initiatives and their completion rates through various channels.
Requirements
4) Implementing awareness activities involving leaders aimed at increasing employees' adoption of
digital transformation process and active contribution (Leader’s driven Digital adoption).
5) Preparing periodic reports on the activities and events implemented to raise awareness and
follow up them by the e-Government Committee - Digital Transformation Committee – at the
agency or by other committees acting on their behalf, and taking corrective measures.
1) Three samples proving that the agency has fulfilled the compliance requirements related to this
standard with regard to informing its employees of the importance of digital transformation
processes, and the need to abide by laws and regulations related to the controls of using
Supporting information and communication technologies, and digital transformation plans and initiatives
documents and their completion rates.
2) Three samples demonstrating the participation of leaders in awareness-raising activities.
3) A sample of completion reports, committee minutes and corrective decisions related to digital
transformation awareness-raising programs that meet the compliance requirements of this
standard.
▪ Council of Ministers’ Resolution No. (40) dated 27/02/1427 AH, Paragraph No. (16).
Related Orders,
▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Paragraph No. (4) of Clause
Resolutions and
(Ninth).
Circulars
▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (3).
Promoting the adoption of technical tools to improve the daily or regular activities of the agency's
Objective
employees.
1) Providing a mechanism to respond to the employees’ requests of any software or licenses that
support digital tools used by the agency's employees in their daily tasks.
Compliance
2) Organize training workshops or short courses for these digital tools.
Requirements
3) Training the authorized employees of the agency on the use of information systems and
resources.
1) Attaching the mechanism or proof of practice that meets the compliance requirements of this
Supporting standard.
documents 2) Attaching photos and completion reports of workshops and courses and evidences that the
agency's employees have applied these tools and used information systems and resources.
Related Orders,
▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Paragraph No. (1) of Clause
Resolutions and
(Ninth).
Circulars
The axis includes the concept of developing leadership and executive skills in the field of digital transformation in a way that
enhances human, technical and operational capabilities of the government agency.
1) Preparing an analytical study of the current situation and identifying the training needs of digital
transformation leaders at the agency, and the needs of digital leadership competencies and
national competencies specialized in the fields of digital government business.
2) Preparing a plan for developing digital transformation leaders at the agency, and raising their
performance level in the areas of digital government business, to include the following:
a. Specifying the programs, courses and activities necessary for developing digital
transformation leaders. These programs shall be theoretical, applicable and of a long-term
Compliance
nature.
Requirements
b. Identifying names and positions of digital transformation leaders participating in these
programs and activities.
c. Setting a schedule for implementing these programs.
d. Developing criteria and methodology for selecting digital transformation leaders to qualify
them. This includes Investing in qualifying future leaders. Leaders shall be from different
sectors, departments, sections and fields to support digital transformation, and are not limited
to IT departments.
Supporting 1) Analytical study of the current situation that meets the compliance requirements of this standard.
documents 2) A plan for developing digital transformation leaders at the agency, and raising their performance
level in the areas of digital government business that meet the requirements of this standard.
▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Paragraphs No. (1) and (3) of
Related Orders, Clause (Ninth).
Resolutions and ▪ Council of Ministers’ Resolution No. (418) dated 25/07/1442 AH, Paragraph No. (11) of Article (4)
Circulars of the Digital Government Authority's Regulations.
▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph (2).
1) Identifying and approving a mechanism for follow-up and measurement, and preparing periodic
follow-up reports for the plan, which include, at a minimum, the following:
a. Detailed list of approved training programs that have been implemented (providers and
implementation dates).
Compliance
b. Training courses certificates.
Requirements
2) Issuing periodic follow-up reports of the plan by the e-Government Transactions Committee –
Digital Transformation Committee – at the agency or by other committees acting on their behalf.
3) Studying and analyzing periodic reports and issuing decisions and corrective actions based on the
results of follow-up periodic reports.
1) The mechanism adopted to follow up and measure the impact of digital transformation leadership
qualification programs (including the list of training programs and samples of certificates, 3
samples at least).
Supporting 2) A sample of periodic follow-up reports to implement the digital transformation leadership
documents qualification plan.
3) A sample of minutes proving that the e-Government Transactions Committee - Digital
Transformation Committee – has studied the periodic reports, followed up on the implementation
and took corrective decisions.
Related Orders, ▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Paragraph No. (3) of Clause
Resolutions and (Ninth).
Circulars ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph (2).
Involving qualified leaders in the digital transformation process and motivating them to effectively
Objective
make decisions in the agency.
1) Involving qualified leaders in the field of digital transformation in committees active in digital
Compliance transformation process and decision-making processes, and benefiting from their experiences and
Requirements qualifications in implementing strategic initiatives in digital transformation.
2) Appointing new qualified leaders to leadership positions, if any.
1) Sample of the decisions to form committees active in digital transformation process, and
Supporting
identifying the names of qualified leaders involved in supporting digital transformation.
documents
2) Sample of the decisions to appoint qualified leaders, if any.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
Activating the exchange of experiences between leaders within the agency or with external parties
Objective
and recruiting national competencies specialized in digital government business.
Supporting 1) A list of the names of leaders who were recruited/ seconded from/ to other agencies.
documents 2) Sample of workshops and conferences held with other government agencies.
▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Paragraphs No. (1) and (3) of
Related Orders, Clause (Ninth).
Resolutions and ▪ Council of Ministers’ Resolution No. (418) dated 25/07/1442 AH, Paragraph No. (11) of Article (4)
Circulars of the Digital Government Authority's Regulations.
▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph (2).
The axis includes the standards and requirements for developing the process of building human capacity and competencies and
enabling workforce to deal with digital technologies and solutions that enhance their innovation capabilities to develop tasks,
business and services using the latest digital solutions and technologies.
1) Preparing an analytical study of the current state of the levels and capabilities of the agency’s
employees in digital government business.
2) Preparing a competency building plan to develop the agency employees’ skills and raise their
performance level in the fields of digital government, and updating this plan periodically to
include:
Compliance a. Objectives of the competency building plan, to be compatible with the agency's strategy
Requirements and its digital transformation plan.
b. Training and employment programs, training fields and their levels (basic, intermediate,
advanced) and job specializations, noting that short courses and workshops are not
appropriate in this field.
c. Those targeted by these programs and their numbers.
d. Schedule of these programs and performance indicators.
▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Paragraphs No. (1) and (3) of
Related Orders, Clause (Ninth).
Resolutions and ▪ Council of Ministers’ Resolution No. (418) dated 25/07/1442 AH, Paragraph No. (11) of Article (4)
Circulars of the Digital Government Authority's Regulations.
▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph (2).
1) Identifying and approving a mechanism for follow-up and measurement, and preparing periodic
follow-up reports for the plan, which include, at a minimum, the following:
a. Detailed list of the training programs that have been implemented (providers and
implementation dates) and experiences that have been employed - according to the
approved competency building plan.
Compliance
b. Copies of training programs certificates, CVs and affiliation statements for the experiences
Requirements
that have been recruited.
2) Issuing periodic follow-up reports of the plan by the e-Government Transactions Committee –
Digital Transformation Committee – at the agency or by other committees acting on their behalf.
3) Studying and analyzing periodic reports and issuing decisions and corrective actions based on
the results of periodic follow-upreports.
1) The mechanism adopted to follow up and measure the impact of competencies building
programs in the field of digital transformation that meet the compliance requirements of this
standard (3 samples).
Supporting 2) A sample of periodic follow-up reports to implement the competencies building plan in the field
documents of digital transformation.
3) A sample of meeting minutes proving that the e-Government Transactions Committee - Digital
Transformation Committee – has studied the periodic reports, followed up on the
implementation and took corrective decisions.
▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Paragraphs No. (1) and (3) of
Related Orders, Clause (Ninth).
Resolutions and ▪ Council of Ministers’ Resolution No. (418) dated 25/07/1442 AH, Paragraph No. (11) of Article (4)
Circulars of the Digital Government Authority's Regulations.
▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph (2).
Activating cooperation with other government agencies to build the competencies of the agency's
Objective
employees at the intermediate and lower job levels.
documents 2) A sample of follow-up reports for joint competencies building programs that meet the compliance
requirements of this standard.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
The axis includes the standards and requirements of the process through which work procedures and processes in the
government agency are designed and documented. Work procedures are designed in a clear sequence according to Laws,
Regulations and responsibilities specified in the agency's organizational structure, in order to enable automation and digital
transformation.
1) Identifying all procedures and processes within the agency to include, at a minimum, the
following:
a. Name and brief description of the process or procedure.
Compliance b. Department/ unit owning the procedure.
Requirements c. Classification of each procedure (main, supporting, administrative).
d. Degree of importance of each procedure according to a mechanism established by the
agency.
e. Specifying the level of automation (fully automated, partially automated, traditional).
Supporting
1) Attaching the procedures document that meet the compliance requirements of this standard.
documents
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
1) Documenting the administrative works and procedures of the processes and procedures clearly
and accurately and approving them by the chief officer at the agency or his representative.
2) Developing cards to document all processes and procedures clearly and accurately, and
approving them by the chief officer at the agency or his representative. These cards shall
include the following elements:
a. Name of process and procedure.
b. Unified and unique code for the process or procedure.
c. A brief description of the process or procedure.
Compliance d. Person in charge of the process or procedure (agency/ department/ sector).
Requirements e. Classification of the process or procedure (main, administrative, supporting).
f. Level of importance.
g. A procedure flow diagram showing the functions and roles (BPMN) or a documentation
method.
h. Performance indicators for the process or procedure at the activity level within the
procedure.
3) Measuring the procedures performance through the approved indicators for each process or
procedure in the card that has been developed.
4) Periodic follow up of the procedure performance and identification of improvement
opportunities.
1) Attaching documents proving that the administrative works and procedures of processes and
procedures have been documented and approved by the chief officer in the agency or his
representative.
2) Attaching various samples (3 samples) from different departments (outside the procedures and
Supporting
processes of IT Department) of procedures documentation cards that meet the compliance
documents
requirements of this standard.
3) Attaching various samples (3 samples) of reports showing that the agency has measured the
approved performance indicators.
4) Attaching various samples (3 samples) of periodic follow-up reports showing the
improvements made to the processes or procedures.
Related Orders,
▪ Council of Ministers’ Resolution No. (40) dated 27/02/1427 AH, Paragraph No. (10).
Resolutions and
▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph (6).
Circulars
1) Redesigning and continuously improving the administrative works and procedures of the
agency's services and works, to include the following:
a. Justifications for improvements made to each procedure according to qualitative and
quantitative analysis.
Compliance b. Adopting a mechanism for numbering improved copies and update date.
Requirements c. Documenting the areas of improvement implemented on the process or procedure, the
expected impact of this improvement and its measurement mechanism by updating
performance indicators and its follow up mechanism.
d. Involving relevant departments and units in improvement processes.
e. Linking digital services to and benefiting from improved procedures.
1) Attaching 5 diverse and recent samples of re-engineered procedures in accordance with the
compliance requirements, showing the following:
a. Justifications for improvements made to each procedure according to qualitative and
quantitative analysis.
Supporting
b. A mechanism for numbering improved copies and update date.
documents
c. Areas of improvement implemented on the process or procedure, the expected impact of
this improvement and its measurement mechanism.
d. Departments involved in improving and redesigning procedures.
e. Services associated with improved procedures.
Related Orders,
Resolutions and ▪ Council of Ministers’ Resolution No. (40) dated 27/02/1427 AH, Paragraph No. (11).
Circulars
1) Automation of processes and procedures, and automation process shall include performance
indicators of each process.
2) Utilizing all available modern technologies to automate processes and procedures (such as
Compliance
RPA, Low-Code technologies, etc.).
Requirements
3) Developing follow-up screens that issue periodic reports to monitor the implementation of
automated processes and procedures, and measure performance indicators in real time.
4) Issuing periodic reports showing the success rates of partially or fully automated processes and
procedures to identify the levels of progress in automating processes and procedures.
1) Attaching diverse and recent samples of the automated procedures screens (5 samples).
2) Attaching evidences proving that the agency used modern technologies to automate processes
Supporting and procedures.
documents 3) Attaching diverse samples (3 samples) of follow-up screens that measure performance
indicators in real time.
4) Sample of periodic follow-up reports that allow to monitor the success rates of automated
processes and procedures (3 samples).
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (7).
Circulars
The axis includes standards and requirements to enhance the agency's ability to identify risks that will affect the continuity of
digital government services and to understand, analyze and address these risks to ensure business continuity at government
agencies and proactive identification of risks.
Establishing components and elements for governance of risks management system, and defining
Objective the roles, responsibilities and powers of those concerned to support the implementation of the risk
management system within the agency effectively, in line with the agency's strategic objectives.
1) Establishing an administrative unit responsible for the risks management system adopted by
the agency, in line with the approved organizational structure.
2) Appointing an officer to manage the risks management system with sufficient competencies
and powers.
3) Defining roles and responsibilities for the risks management system.
4) Assigning a team to carry out the roles, responsibilities and tasks in the risks management
system, based on the needs and business of the agency.
5) The agency's senior management shall establish an internal steering committee to supervise
the agency's risks management system, chaired by the chief officer at the agency or his
representative.
6) Developing the charter of the steering committee responsible for the risks management
Compliance
system, after its approval and circulation by the agency's senior management.
Requirements
7) Conducting the meetings of the steering committee periodically.
8) Creating and adopting a risk management policy in line with the agency's objectives and
sharing it with stakeholders.
9) Creating and adopting a risk management framework document and sharing it with
stakeholders.
10) Creating and adopting risks management procedures and sharing it with stakeholders.
11) Creating a risk register form for all administrative units in the agency and updating it
periodically, to include the following:
a. Risk identifier.
b. Risk owner.
c. Risk description.
d. Root causes and consequences of the risk.
13) Assessing the maturity level of the current risks management system in the agency, and
determining the maturity level to be reached within a specified period of time.
14) Creating and adopting risks management strategy.
15) Implementing the roadmap to achieve the risk management objectives and reach the targeted
maturity level.
16) Creating the risks leaders document in the agency to coordinate, implement and follow up on
risk management works and submit relevant reports.
17) Creating risks reporting document.
18) Implementing reporting mechanism with standardized forms and channel for reporting risks.
19) Creating a dashboard to display the agency's risk statistics, including, but not limited to
(number of risks, risks ratings, risk assessment, etc.).
20) Creating and adopting a document of levels of acceptance and risk tolerance for the agency in
line with the agency’s strategic directions and objectives, and sharing it with stakeholders.
1) Attaching the approved organizational structure of the administrative unit responsible for the
risk management system, and everything needed to meet compliance requirements.
2) Attaching the decision to appoint the risk management system administrator.
Supporting 3) Attaching a document that documents the roles and responsibilities of the administrative unit
documents responsible for the risks management system.
4) Attaching samples of the job description of the risks management system staff.
5) Attaching the decision to form the steering committee responsible for overseeing the risks
management system and everything needed to meet the compliance requirements.
6) Attaching the charter of steering committee responsible for overseeing the approved risks
Documents required from the concerned government agencies specified in Appendix No. 7.6
13) Attach the assessment report of the maturity level of the agency's current risk management
system.
14) Attaching a documented and approved risk management strategy, and everything needed to
meet the compliance requirements.
15) Attaching documents that demonstrate that the roadmap has been implemented to achieve
risks management objectives.
16) Attaching the approved risks leaders document, in accordance with the compliance
requirements of this standard.
17) Attaching the approved risks reporting document.
18) Attaching the documents proving the application of the risks reporting mechanism.
19) Attaching sample of the risk information display boards used in the agency.
20) Attaching the levels of acceptance and tolerance of approved risks document, in accordance
with the compliance requirements of this standard.
Related Orders, ▪ Digital Government Authority’s Circular No. (2044) dated 28/12/1443 AH, on Risks
Resolutions and Management Controls.
Circulars ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (19).
All government agencies and the concerned government agencies specified in Appendix No. 7.6, as
Scope
indicated in this card.
1) Understanding the work environment to identify internal and external risks and threats at the
level of the agency and administrative units by holding workshops with risks owners.
2) Issuing and documenting the risk register, to include:
a. Identification of internal and external risks and threats and reflect them in the agency's risk
register.
b. Analysis and assessment of internal and external risks and threats and reflect them in the
agency's risk register.
c. Identifying appropriate treatment plans for each risk.
3) Sharing and approving the risks register of the relevant administrative unit by the risks owners
Compliance
and the chief officer of the administrative unit.
Requirements
4) Submitting periodic reports showing the results of the risks assessment to the steering
committee responsible for the risks management system and stakeholders based on the
approved frequency in the risks management framework.
5) Identifying, analyzing and assessing the most important risks or major risks at the agency's level
using a top-down or bottom-up methodology.
6) Specifying the appropriate treatment plans for the most important risks or major risks at the
agency's level and the implementation completion date.
7) Identifying key risk indicators (KRIs) at the agency level.
1) Attaching a sample of documents proving that workshops have been convened with the risk
owners, in accordance with the compliance requirements of this standard.
Supporting 2) Attaching the updated risks register, in accordance with the compliance requirements of this
documents standard.
3) Attaching a sample of the documents proving the sharing and approving the risks register of the
relevant administrative unit by the risk owners and the chief officer of the administrative unit.
4) Attaching samples of reports showing the results of risks assessment to the steering committee
responsible for the risks management system.
5) Attaching a register of the most important risks or major risks. This register shows the
appropriate treatment plans at the agency level and the implementation completion dates.
6) Attaching Key Risks Indicators (KRIs) document.
Related Orders, ▪ Digital Government Authority’s Circular No. (2044) dated 28/12/1443 AH, on Risks Management
Resolutions and Controls.
Circulars ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (19).
All government agencies and the concerned government agencies specified in Appendix No. 7.6, as
Scope
indicated in this card.
1) Updating the agency's risks register by those responsible for risks management, to include:
a. Periodically controlling and monitoring the status of the agency's identified internal and
external risks.
b. Monitoring addressed controls and plans and evaluating their effectiveness periodically.
c. Periodically following up on the implementation rates of risks treatment plans within the
specified time period.
Compliance 2) Submitting risk reports to senior management, internal and external committees and
Requirements stakeholders based on the approved frequency in the risks management framework, including,
but not limited to, the following:
a. Comprehensive risks status report.
b. Top risks report.
c. Key risk indicators report.
3) Periodically update the most important risks or key risks, and key risk indicators (KRIs).
1) Attaching documents proving the periodic updating of the risks register, which meets the
Supporting compliance requirements of this standard.
documents 2) Attaching adequate samples of comprehensive risk status reports that have been submitted to
senior management, internal and external committees and stakeholders, which meet the
compliance requirements of this standard.
3) Attaching samples of documents proving the periodic update of the most important risks, and
samples of key risk indicators (KRIs).
Related Orders, ▪ Digital Government Authority’s Circular No. (2044) dated 28/12/1443 AH, on Risks Management
Resolutions and Controls.
Circulars ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (19).
All government agencies and the concerned government agencies specified in Appendix No. 7.6, as
Scope
indicated in this card.
1) Analyzing training needs in cooperation with the administrative unit concerned with human
resources within the agency to understand the training requirements of risks management.
2) Developing and implementing a training plan for risk management staff and risk leaders
commensurate with the roles and responsibilities stipulated in the agency's risks management
system.
3) Developing and implementing a plan for risks management awareness campaigns for the
agency's employees to promote risk culture, using one of the following activities:
a. Awareness messages through different communication channels.
Compliance
b. Global and local risks reports and newsletters.
Requirements
c. Awareness workshops, meetings and open discussions.
d. Risks Awareness Week.
e. Digital education platforms.
4) Reviewing and updating the awareness campaigns plan and promoting risks management
culture in the agency on an annual basis.
5) Developing and implementing a training plan for risks leaders that correspond to the roles and
responsibilities stipulated in the agency's risks management system.
1) Attaching the training needs report in cooperation with the administrative unit concerned with
Supporting
human resources.
documents
2) Attaching the training plan for risks management employees, and samples of documents
proving the implementation of the training plan for risks management employees.
Documents required from the concerned government agencies specified in Appendix No. 7.6
5) Attaching the training plan and samples of documents proving the implementation of the
training plan for risks management leaders.
Related Orders, ▪ Digital Government Authority’s Circular No. (2044) dated 28/12/1443 AH, on Risks Management
Resolutions and Controls.
Circulars ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (19).
All government agencies and the concerned government agencies specified in Appendix No. 7.6, as
Scope
indicated in this card.
Reviewing risks management procedures and processes to improve the agency's capacity, raise the
Objective
effectiveness level of risks management system and apply best practices and standards.
1) Reviewing and updating the documents of the risks management system periodically according to the
approved review mechanism for each document or when a fundamental change occurs to the agency's
strategic or operational objectives, to include the following:
a. Risks management policy.
b. Risks management strategy.
c. Risks management framework.
d. Risks management procedures.
e. Acceptance and tolerance levels of risks document.
Compliance
2) Using and developing standardized forms to implement risk management processes at the agency
Requirements level, including, but not limited to (risk register, risk escalation and acceptance forms, risk reports,
risk dashboards).
3) Reviewing the effectiveness of implementing and applying the risk management system on an annual
basis, using one of the following review methods:
a. Self-assessment
b. KPI assessment
c. Internal or external audit/ review.
4) Reporting the review results of effectiveness of implementing and applying risks management system,
and compliance assessment results to senior management and steering committee responsible for the
risk management system, to ensure that appropriate corrective actions are taken.
5) Preparing a mechanism for archiving and storing the risk management system data and documents to
ensure the business continuity of the administrative unit.
6) Implementing and developing an annual plan to assess the level of compliance with relevant
regulatory controls.
1) Attaching documents proving the risk management system documents have been reviewed and
updated, in accordance with the compliance requirements of this standard.
2) Attaching the models for implementing risk management processes used in the agency.
3) Attaching the annual report of the review results of the effectiveness of implementing and applying
the risk management system.
Supporting 4) Attaching evidence on reporting the review results of effectiveness of implementing and applying
documents risks management system, and compliance assessment results to senior management and steering
committee responsible for the risk management system, to ensure that appropriate corrective
actions are taken.
Documents required from the concerned government agencies specified in Appendix No. 7.6
5) Attach a document clarifying the mechanism of archiving and storing the risk management system
data and documents in the agency.
6) Attaching the annual plan to assess the level of compliance with relevant regulatory controls.
Related Orders, ▪ Digital Government Authority’s Circular No. (2044) dated 28/12/1443 AH, on Risks Management
Circulars ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (19).
All government agencies and the concerned government agencies specified in Appendix No. 7.6, as
Scope
indicated in this card.
1) Appointing an officer to manage the business continuity system who has the competencies and
powers to manage the business continuity system.
2) Appointing a team to carry out the roles and responsibilities in the business continuity
management system, consisting of a sufficient number of qualified employees.
3) Establishing a steering committee responsible for following up the implementation of the
business continuity management system in the agency, chaired by the head of the agency or his
deputy. The steering committee shall have the necessary powers to support the business
continuity system.
Compliance 4) Developing the charter of the steering committee responsible for the business continuity
Requirements system, after its approval and circulation by the agency's senior management.
5) Developing and approving the business continuity policy and reviewing it periodically, or when
a fundamental change occurs in the operation environment or the agency's strategic objectives.
6) Establishing and approving the agency's business continuity management framework.
7) Enhancing business continuity management system by allocating responsibilities and roles to
the system, to clarify:
a. Those responsible for business continuity plans of concerned departments.
b. Coordinators for business continuity plans from the concerned departments (business
continuity leaders).
c. Recovery team of technical and communication disasters of business continuity system.
Related Orders, ▪ Digital Government Authority’s Circular No. (1878) dated 24/09/1443 AH, on Business
Resolutions and Continuity Management Standards.
Circulars ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (19).
1) Analyzing training needs in collaboration with HR to develop training requirements for business
continuity management system skills.
2) Ensuring that employees have been trained on multiple skills to manage business continuity
system, and developing job succession plans (to avoid single points of failure) of business
continuity system activities.
3) Implementing a program to deploy the culture of business continuity in the agency; through
Compliance
training and specialized workshops for all parties participating in the business continuity system
Requirements
at least once a year, and when a fundamental change occurs in the agency operations.
6) Convening awareness workshops for business continuity leaders at the agency level.
1) Attaching the approved plan or document that includes the training needs and training
requirements of business continuity for the employees of the unit concerned with the
management of the business continuity system.
2) Attaching evidences on the implementation of awareness workshops and campaigns on
business continuity management, showing that the employees have been trained on multiple
skills to manage the business continuity system, and the job succession plan for the business
documents 3) Attaching evidences on the implementation of special training awareness programs for those
involved and participating in the business continuity system.
Documents required from the concerned government agencies specified in Appendix No. 7.6
4) Providing evidences on sharing the approved business continuity policy with internal
stakeholders.
5) Providing evidences on convening awareness workshops on business continuity management
for senior management at the agency level.
6) Providing evidences on convening awareness workshops for business continuity leaders at the
agency level.
Related Orders, ▪ Digital Government Authority’s Circular No. (1878) dated 24/09/1443 AH, on Business
Resolutions and Continuity Management Standards.
Circulars ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (19).
All government agencies and the concerned government agencies specified in Appendix No. 7.6, as
Scope
indicated in this card.
1) Inclusion of all internal and external processes and procedures carried out by the agency,
determining internal and external approvals, and appointing a staff for the processes and
procedures that have been included.
2) Analyzing the impact of the business interruption using the agency’s approved interruption
impact assessment matrix, according to the extent of acceptance of impact and risks adopted by
the agency, and reviewing the analysis of the business interruption impact at least annually, or
when a fundamental change occurs in the agency’s operations or strategic objectives.
3) Specifying the targeted recovery period of critical business services, and recovery time
objectives (RTO).
4) Determining the human, logistical and technical resources, infrastructure and alternative
procedures necessary to implement the service or procedure after the interruption.
5) Submitting a comprehensive report on business interruption impact analysis to the steering
Requirements 6) Assessing and reviewing risks and threats to the continuity of the agency's business on an
ongoing basis, and aligning them with the agency's approved risk management methodology.
7) Identifying and monitoring risks and threats that may interrupt or disrupt the priority operations
and actions of the agency, and aligning them with the relevant parties.
8) Determining the impacts of internal and external risks on the agency’s operations and
procedures.
9) Identifying and evaluating controls applied to deal with the risks and threats that affect the
continuity of the agency’s business.
10) Determining the appropriate additional or compensatory controls to confront risks and threats
that affect the continuity of the agency’s business.
11) Presenting the risk and threat assessment results to the business continuity steering committee,
as part of the results of analyzing business interruption impact analysis, for approval.
12) Determining the Medium-Term Development Plan (MTDP) for business interruption of products,
services, processes and activities, and Minimum Business Continuity Objective (MBCO).
13) Classifying the importance level of government platforms and applications and adhering to the
targeted recovery times for each level, according to the interruption impact assessment matrix
issued by the Digital Government Authority through (Raqmi) portal.
Documents required from the concerned government agencies specified in Appendix No. 7.6
9) Sample of business interruption impact analysis results reports, including recovery time
objectives (RTO), Medium-Term Development Plan (MTDP) and Minimum Business Continuity
Objective (MBCO), as approved by the steering committee or stakeholders.
10) Evidences on the classification of the importance level of government platforms and
applications and adhering to the targeted recovery times for each classification, according to the
interruption impact assessment matrix issued by the Digital Government Authority through
(Raqmi) portal.
Related Orders, ▪ Digital Government Authority’s Circular No. (1878) dated 24/09/1443 AH, on Business
Resolutions and Continuity Management Standards.
Circulars ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (19).
All government agencies and the concerned government agencies specified in Appendix No. 7.6, as
Scope
indicated in this card.
Related Orders, ▪ Digital Government Authority’s Circular No. (1878) dated 24/09/1443 AH, on Business
Resolutions and Continuity Management Standards.
Circulars ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (19).
All government agencies and the concerned government agencies specified in Appendix No. 7.6, as
Scope
indicated in this card.
1) Preparing and approving business continuity plans based on approved business continuity
management strategies.
2) Reviewing and testing business continuity plans at least once a year, or when a fundamental
change occurs at the agency.
3) Finding alternative backup centers for storing data, and centers for sensitive systems for storing,
operating and testing data in accordance with the international standards.
4) Identifying key objectives of the ICT disaster recovery plan including dependencies on external
suppliers and any outsourced services.
5) Creating ICT recovery plans to restore digital platforms, applications, services and data in a
timely manner to achieve the recovery time objectives (RTO) of the agency.
6) Defining backup and recovery methods and procedures to restore system operations quickly and
effectively after a service interruption.
7) Communicating with the Digital Government Authority in the event of an interruption of digital
services according to the user guide to report the interruption of digital government services
Compliance
through (Raqmi) portal.
Requirements
8) Documenting events in the event of an interruption of operations, explaining the responsibilities
and powers related to the collection, approval and updating of activity records, job test results
and data, lessons learned and post-incident report.
9) Ensuring that information security and cybersecurity regulations are activated at all times,
especially when activating the ICT disaster recovery plan for alternative sites.
10) Testing and reviewing ICT disaster recovery plans at least once a year, or when a fundamental
change occurs to the agency's IT infrastructure, to ensure its readiness in the event of any
interruption.
11) Creating and approving incidents response plan.
12) Reviewing and testing the incident response plan periodically at the agency.
13) Establishing and approving a media communication and response plan, including procedures for
dealing with relevant external parties.
14) Reviewing and testing the media response plan periodically at the agency.
1) Attach sufficient samples of the agency’s approved business continuity plans to meet all
compliance requirements
2) Attaching evidences on the review of the business continuity plans and samples of reports of
business continuity plans testing results.
3) Attaching maintenance and operation contracts that include the alternative disaster recover
(DR) centers for keeping data, and centers for sensitive systems for keeping data and operating
and testing the procedures, in accordance with the international standards adopted by the
agency.
4) Attaching sample of ICT disaster recovery plans associated with the agency's digital platforms,
applications, services, and data that meet the compliance requirements of this standard.
5) Attaching the backup and recovery procedures document for the defined processes within the
business interruption impact.
Supporting
6) Attaching adequate samples showing reporting of digital services interruption to the Digital
documents
Government Authority.
7) Attaching a sample of the event documentation record in the event of interruptions or during
the periodic tests of plans.
8) Attaching adequate samples proving the activation of information security and cybersecurity
controls during the activation or testing IT disaster recovery plans or evidence on reviewing the
cybersecurity of plans.
9) Attaching adequate samples of reports illustrating the testing and review of technical and
communications disaster recovery plans.
10) Attaching the agency's incident response plan document approved by authorized person to meet
the compliance requirements.
11) Attaching reports showing testing results of incident response plans.
Documents required from the concerned government agencies specified in Appendix No. 7.6
12) Attaching the agency's media response plan document approved by the stakeholder.
13) Attaching reports showing testing results of media response plans.
▪ Council of Ministers’ Resolution No. (82) dated 22/03/1431 AH, Recommendation (14).
▪ Digital Government Authority’s Circular No. (1878) dated 24/09/1443 AH, on Business
Related Orders,
Continuity Management Standards.
Resolutions and
▪ Digital Government Authority’s Circular No. (1533) dated 23/05/1443 AH, on reporting the
Circulars
interruption of digital government services issued to all government agencies.
▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph (19).
All government agencies and the concerned government agencies specified in Appendix No. 7.6, as
Scope
indicated in this card.
Objective the application of business continuity policy and achievement of business continuity management
objectives.
1) Creating a table of all tests and exercises for the various business continuity plans, and approving it
Compliance by the business continuity steering committee on an annual basis.
Requirements 2) Implementing the tests and exercises approved by the business continuity steering committee.
3) Documenting the official post-exercise report or planned test.
4) Sharing post-training or testing reports with members of the business continuity steering committee.
1) Attaching the annual tests and exercises document or table approved by the business continuity
steering committee.
Supporting
2) Attaching sample of approved test or exercises reports.
documents
3) Attaching evidences on the documentation of the official post-exercise report or planned test.
4) Attaching evidences on sharing test and exercise reports with the business continuity steering
committee.
Related Orders, ▪ Digital Government Authority’s Circular No. (1878) dated 24/09/1443 AH, on Business Continuity
Circulars ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (19).
1) Reviewing the business continuity management system periodically (at least annually) through
an internal or external auditor who has sufficient qualifications and experience to implement
Compliance this task.
Requirements 2) Sharing the results of internal and external audits with the business continuity committee to
ensure that corrective action are taken.
3) Ensuring that business continuity plans, ICT recovery plans, media response plan and incident
response plan are developed and updated based on the outputs of the verification phase.
Related Orders, ▪ Digital Government Authority’s Circular No. (1878) dated 24/09/1443 AH, on Business
Resolutions and Continuity Management Standards.
Circulars ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (19).
The axis includes standards and requirements for the applications and institutional systems architecture that support normal and
digital transformation business.
1) Implementing key systems for planning government resources and issuing user guides.
2) Issuing periodic reports from the key systems for planning government resources.
3) Providing all self-services to its employees through the electronic portal or smart device
Compliance applications, and issuing user guides.
Requirements 4) The agency provides all self-services to external beneficiaries through the electronic portal or
smart device applications, and issues user guides.
5) Cooperation and participation with internal departments to achieve integration between
government resources systems and related systems of external agencies.
1) One sample of screens and user guides for each part of the resource systems (Human Resources
Management System, Financial System, Procurement and Supply System, Custody and Inventory
Management System, Supplier Management System).
2) 3 Samples of periodic reports issued from the key systems for planning government resources.
Supporting
3) 3 Samples of self-services provided to internal beneficiaries and user guides.
documents
4) 3 Samples of self-services provided to external beneficiaries and user guides.
5) 3 Samples and explanation of complete procedures that illustrate the process of linking and
integrating the agency's resources management systems and internal systems and related
systems in external parties.
Related Orders,
Resolutions and ▪ Council of Ministers’ Resolution No. (40) dated 2/27/1427 AH, Paragraph No. (12).
Circulars
Objective Using Digital Project Management Systems in All Aspects of Digital Projects
1) The agency uses digital systems and tools to manage projects and digitize the processes of
requesting, planning, controlling, monitoring and following up projects, tasks and schedules.
2) Linking digital systems and tools related to projects management with systems for following
up strategic plans and initiatives, financial and procurement systems, control and accounting
Compliance systems, and human resources systems adopted in the agency.
Requirements 3) Controlling the powers of the project management team and other departments to which they
belong through the technical system used.
4) Issuing periodic reports showing the control of tasks related to projects management with
other departments in the agency. These reports indicate the completion rate of each
department.
1) 4 Samples of project management digital systems screens (project request, planning, follow-
up and reporting, deliverables) that meet the compliance requirements of this standard.
2) One sample showing all the interfaces and integrations between the project management
Supporting system and other internal systems.
documents 3) 3 Samples of the technical system showing the control of the powers of the project
management team and other departments.
4) 3 Samples of periodic reports showing the control of tasks related to projects management with
other departments in the agency. These reports indicate the completion rate of each
department.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (10).
Circulars
Linking and using document management and archiving systems for all transactions, and ensuring
Objective
the preservation and quick access to the documents and data.
1) Implementing the National Center for Archives and Records’ preservation and destruction
policies, and developing what is necessary to ensure their compatibility with the regulations
and procedures followed in the agency.
2) Keeping and archiving the agency's documents, contracts, decisions, letters and data
Compliance
electronically.
Requirements
3) Linking the document management and archiving system to all basic and supporting digital
systems and controlling powers.
4) Issuing periodic reports showing the percentage of departments benefiting from e-archiving
systems.
1) Providing preservation and destruction policies adopted in the agency, which are consistent
with the National Center for Archives and Records’ policies.
2) 3 Samples of documents preservation and archiving systems’ screens used in the agency.
Supporting
3) One sample showing all the interfaces and integrations between the archiving system and all
documents
key and supporting digital systems.
4) Sample of use reports showing the percentage of departments benefiting from e-archiving
systems.
▪ High Order No. (57231) dated 10/11/1439 AH, Clause (First).
Related Orders,
▪ Council of Ministers’ Resolution No. (40) dated 27/02/1427 AH, Paragraph No. (3).
Resolutions and
▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Sub-paragraph (A), Paragraph
Circulars
No. (1) of Clause (Ninth).
Developing and documenting the customer relations management (CRM) processes across
Objective different channels and following up the progress of those requests and notes to address them as
soon as possible.
1) Using CRM systems with all its components and activating call centers and technical support,
in order to ensure a rapid response to the requirements, complaints and suggestions of
beneficiaries of all segments, and raise their level of satisfaction.
Compliance 2) Linking CRM systems to infrastructure management systems, communication channels with
Requirements beneficiaries, and customer experience systems.
3) Activating digital tools and modern technologies to automate support and rapid response
operations.
4) Activating knowledge management tools to support the relationship officer's access to the
information in a smooth and fast manner.
1) 3 Samples of CRM systems screens.
2) 3 Samples of tickets opened via several different channels.
Supporting 3) Sample digital tools used to interact with the beneficiary, for example: Smart Assistant (Chat
documents bot).
4) Sample of knowledge base used to support the relationship officer's access to the information
in a smooth and fast manner.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (17).
Circulars
Activating the role of e-transactions and correspondence in the government agencies’ regular work
Objective
and correspondence, and ensuring their confidentiality.
1) Submitting a recent report for the last 6 months from the agency's email server showing the
number of messages.
2) Submitting copy of the disclaimer statement that was included in the e-mails of the agency's
employees.
Supporting
3) Submitting copy of the hosting contracts in the event that a contract was concluded with an
documents
agency to host the e-mail. The contracts shall include the required standards and controls
according to the Guide to Controls of Using Information and Communication Technologies.
4) Submitting an official document certified by the authorized person, in the event that e-mail
servers are hosted within the agency’s data centers.
Related Orders, ▪ Council of Ministers’ Resolution No. (40) dated 27/02/1427 AH, Paragraph No. (13).
Resolutions and ▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Paragraphs No. (1, 3, 4, 5, 6)
Circulars of Clause (Third).
The axis includes the standards and compliance requirements of an institutional methodology that includes a set of policies,
procedures and methods for the provision of technical services to beneficiaries.
1) Developing the objectives and scope of work for the technical services and infrastructure
management system in order to achieve the agency’s strategic objectives in digital
transformation process.
2) Adopting specific policies and standards for management of technical services and
infrastructure in accordance with international best practices, such as ISO20000: ITIL.
Compliance
3) Establishing an overall-quality administrative unit to measure and monitor the quality of IT
Requirements
operations and infrastructure management.
4) Developing official and technical policies to control the use of employees of the agency's
technological assets.
5) Setting controls and rules for the agency's employees when using their personal devices for
work purposes.
1) Attaching documents proving that the agency has committed to developing the objectives and
scope of work for the technical services and infrastructure management system.
2) Attaching documents proving that the agency has adopted specific policies and standards for
management of technical services and infrastructure in accordance with international best
Supporting practices.
documents 3) Attaching the organizational structure of the General Administration of Information
Technology showing the establishment of a unit concerned with overall-quality.
4) Attaching policies adopted to control the use of agency's employees of its technological assets.
5) Attaching controls and rules related to the use of personal devices of employees for work
purposes.
Related Orders, ▪ High Order No. (48310) dated 26/11/1435 AH, Paragraph No. (1).
Resolutions and ▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Clause (Fifth) and Paragraph
Circulars No. (1) of Clause (Sixth).
1) Attaching adequate documents and samples from the systems screens that prove the agency's
commitment to automating all technological services and infrastructure management
processes, while clarifying the modern technologies and systems used.
2) Attaching documents that show the documentation of the results of all development stages of
technologies supporting the digital government's businesses.
3) Attaching periodic reports that measure, study and analyze the performance of operations of
managing technological services and infrastructure.
Supporting 4) Attaching the hosting contracts, including the clauses stipulated in the Guide to the Controls of
documents Using Information and Communication Technologies in Government Agencies issued by the
Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, or an official document from
the authorized person, including hosting all the agency's platforms, systems and databases
within the agency's data centers or through other government agencies, or through hosting
service providers licensed by the Communications, Space & Technology Commission.
5) Providing the approved mechanism or a copy of the system screens used in the agency, through
which it ensures that users comply with the approved controls regarding the use of
technological assets and computers in the agency, and prevent the use of unlicensed software.
Related Orders,
▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Paragraph No. (3) of Clause
Resolutions and
(Second) and Paragraph No. (2) of Clause (Sixth).
Circulars
1) Attaching the necessary documents and samples from the systems screens and periodic
reports that prove that the agency has committed to achieving integration between
technological services system and other systems of the agency.
2) Attaching the necessary documents and samples from the systems screens and periodic
Supporting documents reports that prove that the agency has committed to achieving internal integration between
technological systems, and indicate the control of performance indicators for the integration
process.
3) Attaching documents showing that the agency has achieved integration with other
government agencies regarding the digital government's works.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
Enhancing opportunities to reuse government software, while providing the opportunity to view
and publish the source code, thus opening the field for cooperation between government
Objective
agencies, unifying standards among them, increasing transparency, ending the monopoly of
suppliers, and reducing the difficulties of integrating software from more than one source.
1) Issuing the government license for free and open source government software
2) Inventory of open source software that you want to share with government agencies.
Inventory data shall include the following elements: Software asset (product/ tool),
description, programming language, use licenses “if any”, sharing possibility, and availability
of documentation related to open source software.
3) Promoting opportunities to reuse open source government software.
4) Implementing the approved mechanism for purchasing or developing government software,
according to the following steps:
a. Step One: Evaluating and studying the government software available in the repository
for use, in coordination with the DGA.
b. Step Two: If the evaluation and study report concluded that there are no software that
meets the needs, the government agency may search for ready-made software, giving
preference to free and open source software, in coordination with the DGA.
c. Step Three: If there are no software that meets the needs, the government agency then
can build its own software.
Compliance
5) Applying the following provisions and rules related to contracting for building government
Requirements
software, as follows:
a. The supplier delivers the source code and related documents to the government agency.
b. Unspecified rights to the source code and its accessories shall be secured to allow for
reuse, copying, modification and distribution between government agencies, without the
need for the original supplier, while providing an open source for public use of the source
code for all government agencies.
c. The supplier must have high-level quality certificates in the required field of work.
d. A contracting priority is to be given to national suppliers who meet the requests and
technical conditions of the government agency.
e. An emphasis is to be put on government agencies if an additional development of the
process of purchasing commercial software is made. It must be stipulated during the
contracting process that the ownership or right to use this development shall be all
transferred to the government.
Preparing the departments concerned with open source software to interact with the
information software community.
1) Submitting the government license for free and open source government software
Supporting documents 2) Submitting the free open source software inventory document, in accordance with the
compliance requirements of the standard, and the schedule for uploading this document to
▪ Council of Ministers’ Resolution No. (14) dated 02/01/1443 AH, as stipulated in the following
paragraphs and topics, and in particular:
Related Orders, ▪ Paragraph No. (1) of Clause ()B): Purpose of the Rules).
Resolutions and ▪ Paragraph No. (2) and (5) of Clause (H: Rules Implementation Considerations).
Circulars ▪ Clause (D: Government Software Purchase Considerations).
▪ Clause (E: Provisions for contracting to build government software).
▪ Clause (F: Software Deployment Considerations.
All government agencies, except for security and military agencies, that are subject to special
Scope
provisions, as stipulated in their bylaws, regulations or internal regulations.
Achieving efficiency of spending and optimal use of government agencies’ budgets, and emphasizing
Objective the importance of adhering to the methods, procedures and provisions stipulated in the Government
Tenders and Procurement Law.
1) The government agency shall secure its needs of Internet services and digital circuits through the
Framework Agreement for Internet Services and Digital Circuits through the e-market of Etimad
platform.
In the event that the agency does not secure its needs through the Framework Agreement for
Compliance
Internet Services and Digital Circuits (for any reason), the agency shall then achieve the following:
Requirements
1) Offer bids for telecommunications services, whether public expenditures, programs or projects, on
Etimad platform.
2) Register its contracts related to telecommunications services, whether public expenditures,
programs or projects, on Etimad platform.
1) Attaching copy of the electronic marketplace of Etimad platform showing the reference number
and status of the purchase order. The order status shall be:
a. Order completed.
b. Waiting for supply.
c. Pending payment.
Supporting documents
In the event that the agency does not secure its needs through the electronic marketplace, it must
achieve the following:
1) Attaching screenshot of Etimad platform showing the reference number of the bid and its status.
2) Attaching screenshot of Etimad platform showing the contract reference number, contract name
and related bid number.
▪ Royal Decree No. (M/128) dated 13/11/1440 AH, approving the Government Tenders and
Related Orders, Procurement Law.
Resolutions and ▪ Circular of His Excellency the Minister of Finance No. (49989) dated 12/02/1442 AH, Clause (First).
Circulars ▪ Circular of His Excellency the Minister of Finance No. (46973) dated 05/12/1443 AH,.
▪ Circular of His Excellency the Minister of Finance No. (1748) dated 14/01/1445 AH,.
Compliance 1) Submitting an inventory of all DGA’s telecommunications departments in the inventory form
Requirements available on "Raqmi" Platform, and continuously updating the inventory lists.
1) Attaching copy of the inventory form uploaded to the agency's website, including all digital
Supporting documents circuits within the agency. The inventory of digital circuits will be verified through the
agency's checklists.
▪ Circular of His Excellency the Minister of Finance No. (49989) dated 12/02/1442 AH, Clause
(Second).
Related Orders,
▪ Digital Government Authority’s Circular No. (916) dated 15/01/1443 AH,.
Resolutions and
▪ Council of Ministers’ Direction notified under His Excellency the President of the Royal Court
Circulars
Letter No. (8102) dated 03/02/1444 AH, regarding finding solutions for the governance of
communication services.
1) The government agency shall use the clause related to the Unified Framework Agreement No.
(339000113).
In the event that the agency does not use the clause related to the Unified Framework
Compliance Agreement for Digital Circuits Services (for any reason), the agency shall then achieve the
Requirements following:
1) Use the telecommunications services item for the designated purposes, namely: digital
circuits services with an economic classification of (221136) or the Internet services with an
economic classification of (221134).
1) Attaching screenshot of Etimad platform showing the economic classification number used,
Supporting documents the reference number of the contract /invoice, and the name of the contract/ invoice related
to Internet services or digital circuits.
▪ Royal Decree No. (M/128) dated 13/11/1440 AH, approving the Government Tenders and
Procurement Law.
Related Orders,
▪ Circular of His Excellency the Minister of Finance No. (49989) dated 12/02/1442 AH, Clause
Resolutions and
(First).
Circulars
▪ Circular of His Excellency the Minister of Finance No. (46973) dated 05/12/1443 AH,.
▪ Circular of His Excellency the Minister of Finance No. (1748) dated 14/01/1445 AH,.
Scope All government agencies linked to the general budget of the state.
The axis includes standards and requirements for using cloud resources, applications and operations that are appropriate for the
agency's current and future businesses.
Related Orders,
▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Resolutions and
▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Clause (Fourth).
Circulars
All government agencies - with the exception of security and military agencies and the Saudi
Scope
Central Bank from the application scope of all Cloud Architecture" axis's standards.
1) Preparing a plan for adopting cloud computing and integrating data centers that includes
targets, measurement indicators and scope of work. This plan shall include the following:
a. List of applications classified as migrable data for cloud computing and mechanism
followed.
b. Cloud Reference architecture model for cloud computing adoption.
c. Migration plan and timeline for migration of applications, software, technological
Compliance resources and services to the cloud computing, indicating the targeted dates.
Requirements d. The percentage of adopting current and targeted cloud services for the coming years to
2) Preparing a report on the list of projects supporting the Cloud Transformation Plan for the year
2024-2025 and the status of progress in the implementation, to include the following:
a. Number of IT projects associated with cloud computing and their total budget.
b. Scope of work (overall) and status and budget of projects associated with cloud computing.
c. Status of projects (implementation timeframe), for example: on the track or late.
1) Attaching an updated plan for transformation towards cloud services and integration of data
centers for a period of at least two years, and this plan shall meet the compliance requirements
of the standard.
Supporting documents 2) Attaching a report of the list of projects supporting cloud transformation plan for the year 2024-
2025, and this report shall meet the compliance requirements of the standard.
3) Updating the “Government Cloud Services Needs Inventory” questionnaire will be verified
through internal checklists.
Related Orders, ▪ Digital Government Authority’s Circular No. (102) dated 09/02/1444 AH, on preparing a plan
Resolutions and for transformation towards cloud solutions.
Circulars ▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Clause (Fourth).
All government agencies - with the exception of security and military agencies and the Saudi
Scope
Central Bank from the application scope of all Cloud Architecture" axis's standards.
1) Aligning the agency's policies and regulations with the policies and regulations issued by the
Digital Government Authority and cloud computing-related entities.
Compliance 2) Using cloud tools and systems to meet business needs and applications on the cloud, ensuring
Requirements improved performance and reduced costs.
3) Preparing, studying and analyzing reports related to controlling usage, costs, performance and
risks in the cloud computing environment.
1) Attaching evidences on the agency's commitment to aligning its policies and regulations with
those related to cloud computing.
2) Attaching 3 samples of screens of cloud tools and systems used that meet the compliance
Supporting documents
requirements of this standard.
3) Attaching reports related to controlling usage, costs, performance and risks in the cloud
computing environment, showing their study and analysis.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
All government agencies - with the exception of security and military agencies and the Saudi
Scope
Central Bank from the application scope of all Cloud Architecture" axis's standards.
The axis includes standards and requirements for applying electronic systems and services provided by government agencies. It
targets other government agencies to provide joint government services and solutions, which can be linked to and used to
enhance the whole-of-government concept.
Linking to systems and services provided by other government agencies and promoting the use of
Objective
government agencies of joint technological solutions and infrastructures.
1) Studying and analyzing other government systems and services and determining the agency's
needs of data and jobs periodically.
2) Preparing a plan for linking to shared systems and services, to include the following:
a. A list of shared systems and services to which they have been linked, and to which they
will be linked in the future.
Compliance b. Agency's objectives from linking to each system or service.
Requirements c. Services to be provided or availed through the linking process.
d. Data sets that can be availed through the linking process.
e. Who in charge of the linking process, whether a person, a committee or an administrative
unit.
f. Linking process schedule.
g. A mechanism to follow up on the implementation of the linking plan and performance
indicators allocated to follow up the linking process.
1) Attaching documents proving study and analysis of other government systems and services and
determination of the agency's needs of data and jobs periodically.
Supporting 2) Attaching an approved plan for linking to shared systems and services that proves the agency's
documents commitment to studying and analyzing the government systems and services that it wishes to
link to, and planning the linking process in accordance with the compliance requirements of
this standard. Attaching the decision to appoint the person responsible for each of the shared
systems and services used by the agency.
Related Orders,
▪ Digital Government Authority’s Circular No. (1339) dated 15/11/1444 AH, on Whole-of-
Resolutions and
Government Platforms Controls.
Circulars
Ensuring the implementation of linking to, and maximizing the use of, shared government
Objective
platforms.
1) Implementing linking plans in accordance with the approved mechanisms and schedules and
issuing reports thereon.
2) Adopting the National Unified Access “NAFATH” for digital services that require a digital
identity features or functions.
3) Reusing data available from the National Unified Access “NAFATH”.
4) Adopting various e-payment portals, such as (Tahseel) and(SADAD) for digital services that
need e-collection or e-payment features or functions.
Compliance 5) Taking advantage of the services available in the Unified Electronic Government Procurement
Requirements Portal “Etimad”.
6) Linking to the electronic control system of the General Bureau for Auditing.
7) Issuing periodic reports to follow up on the linking to each service/ system, to include, at a
minimum, the following:
a. Volume of data exchanged.
b. Analysis of peak use times.
c. Number of operations carried out and rejected.
d. Uploaded support tickets cases.
1) Attach periodic reports showing the implementation of linking plans according to the approved
mechanisms and schedules.
2) Attaching adequate samples and screenshots proving the agency's linking to the National
Unified Access “NAFATH” (3 samples).
3) Attaching Reports showing the reuse of data available from the National Unified Access
“NAFATH”.
4) Attaching adequate samples and screenshots proving the agency's use of various e-payment
Supporting documents
portals, such as (Tahseel) and (SADAD) in the digital services it provides (3 samples).
5) Attaching adequate samples and screenshots proving the agency's use of the services available
in the Unified Electronic Government Procurement Portal “Etimad” (3 samples).
6) It is not required to attach proof of linkage to the Electronic Control System "Shamil", and
verification is done through the compliance lists issued by the General Bureau for Auditing.
7) Attaching sample of periodic reports related to the follow-up of the link to each service/
system, in order to meet compliance requirements of this standard.
Related Orders, ▪ High Order No. (57231) dated 10/11/1439 AH, Clauses (Third) and (Seventh).
Resolutions and ▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Paragraph No. (2) of Clause
Scope All government agencies, and the Saudi Central Bank is exempt from Requirements No. 5 and 6.
1) Studying and analyzing periodic reports and the extent to which the agency's objectives have
been achieved from the linkage processes that have taken place and benefit from shared data.
2) Continuous follow-up of new systems and services to ensure that the infrastructure and all
Compliance
services associated with the shared systems and services are built properly to ensure their
Requirements
continuous operation.
3) Making appropriate decisions based on the periodic reports related to shared systems and
services.
1) Attaching reports proving the study and analysis of the periodic reports and the extent to which
the agency's objectives have been achieved from the linkage processes that have taken place
and benefit from shared data.
Supporting
2) Attaching reports showing the continuous follow-up of new systems and services, in accordance
documents
with the compliance requirements of this standard.
3) Attaching samples of minutes of meetings and decisions taken by the agency based on the
periodic reports.
Related Orders,
▪ Digital Government Authority’s Circular No. (1339) dated 15/11/1444 AH, on Whole-of-
Resolutions and
Government Platforms Controls.
Circulars
Managing shared systems and services, including procedures that help to facilitate linking of
beneficiary government agencies, managing the requests received in this regard, maintaining their
Objective
levels of operation and maintenance to ensure continuous operation according to the users’ needs, and
ensuring the effectiveness and ease of use.
1) Publishing clear instructions on the procedures for benefiting from shared systems and services on
their digital platforms, to include - at a minimum - the following:
a. Eligibility for use, conditions and requirements for linking to and benefiting from the platform.
b. Procedures for submitting requests for linking to and benefiting from the platform.
2) Determining the mechanism for receiving requests for linking and benefiting from shares systems
and services, and taking a decision on those requests within a period not exceeding ten working
days from the date of submitting the request, while adhering to the following:
a. The mechanism for receiving linking requests should be automated.
b. Providing the necessary technical support to the beneficiary government agency through more
than one communication channel until the completion of linking and benefiting from the
platform, if the request is approved.
c. Approving the assignment of the system administrator nominated by the beneficiary
Compliance
government agency to link during the specified period.
Requirements
d. Informing the beneficiary government agency of the reasons for the rejection decision within
the specified period, if the linking request is rejected within a period to be agreed upon
between the two parties.
e. Determining the period required to respond to internal inquiries and support requests from the
beneficiary government agency's employees.
3) Inclusion of use agreement, including the consequences of misuse of information systems and
resources and electronic links of relevant laws and regulations.
4) Preparing service level agreements (SLAs) to ensure the availability of the system around the clock
and sustainability and availability of the service through more than one electronic channel to
provide the beneficiary government agencies with the service. Preparing operating procedures
documents for all operations and detailing the service level agreements for support services on the
platform.
1) Attaching copy of the instructions on the procedures for benefiting from shared systems and
services in accordance with the compliance requirements of this standard.
Supporting 2) Attaching the mechanism for receiving requests for linking to and benefiting from shared systems
documents and services that meet the compliance requirements of this standard.
3) Attaching copy of the Use Agreement.
4) Attach copies of the Service Level Agreements (SLA).
5.13.5 Monitoring the performance of shared systems and services (by concerned agencies)
Monitoring the performance of shared systems and services and conducting periodic audit on their
Objective
compliance with the specifications and regulations issued by the DGA.
1) Identifying a department within the agency’s organizational structure to audit and follow up on the
performance of shared systems and services.
2) Developing an operating model for managing and organizing the business of shared systems and
Compliance services, which includes roles and responsibilities, governance model, and work procedures.
Requirements
3) Monitoring the usage data according to a comprehensive methodology determined by the
concerned entity, and drawing conclusions and insights from those data and benefiting therefrom.
4) Developing an audit and follow-up mechanism to evaluate the functionality and use cases of shared
systems and services and measure compliance with these standards.
1) Attaching the organizational structure and description of tasks for the department in charge of
auditing and following up on the performance of shared systems and services.
2) Attaching the operating model for managing and organizing the works of shared systems and
services in accordance with the compliance requirements of this standard.
Supporting documents
3) Attaching documents and samples of reports, minutes of meetings and decisions that prove that
the agency is following up on usage data.
4) Attaching an audit and follow-up mechanism that evaluates the functions of shared systems and
services and their use cases.
Related Orders,
Resolutions and ▪ Digital Government Authority’s Circular No. (1339) dated 15/11/1444 AH, on Whole-of-Government
Managing relationship with government agencies benefiting from shared systems and services to
Objective
enhance their participation in the platform development.
2) Providing the necessary training programs and tools for the system administrator assigned by the
beneficiary government agency.
Compliance
Requirements 3) Providing technical support services to the beneficiary government agencies to provide support
with regard to the use and operation of shared systems and services.
4) Preparing an annual roadmap to develop shared systems and services and improve user
satisfaction.
1) Attaching evidences on conducting promotional campaigns to introduce the shared systems and
services.
2) Attaching training programs carried out by the owners in favor of the beneficiaries.
Supporting documents
3) Attaching evidences on the provision of technical support services to the beneficiary government
agencies to provide support with regard to the use and operation of shared systems and services.
4) Attaching copy of the roadmap for developing shared systems and services.
Related Orders,
Resolutions and ▪ Digital Government Authority’s Circular No. (1339) dated 15/11/1444 AH, on Whole-of-Government
1) Listing the agency's existing platforms and reporting them to the Digital Government Authority.
2) Obtaining the DGA’s prior approval before establishing or launching any platform.
Compliance
3) Registering the information of agency's all digital services in the service designated for this
Requirements
purpose on the "Raqmi" portal and updating it continuously.
4) Exporting e-stamp for all approved and registered platforms.
Compliance requirements to be met by the agencies concerned with “the plan to consolidate and
integrate the agency's platforms”, as specified in Appendix No. 7.6
Compliance 5) Preparing an executive plan to consolidate and integrate the agency’s platforms within the
Requirements sector’s work plan, which shows the list of platforms to be integrated and the services to be
transferred, as well as transformation completion date.
6) Developing a mechanism to follow up on the implementation of the integration plan and
preparing periodic follow-up reports that show the progress of implementation, including the
time frame for launching products and services included in the sector platform roadmap.
7) Closing access to platforms that have been integrated or their services transferred within the
consolidated platform and closing their domains, if any.
8) Closing inactive and unused domains, if any.
9) Closing temporary platforms which are no longer needed, if any.
Documents to be submitted by government agencies concerned with “the plan to consolidate and
integrate the agency's platforms”, as specified in Appendix No. 7.6
1) Attaching a document proving the study and analysis of the current status of the agency's
platforms.
Supporting
2) Attaching proof of reviews carried out to all agency's platforms and domains.
documents
3) Attaching the future vision of the agency's digital landscape within the relevant sector.
4) Attaching proof of obtaining the DGA’s approval on the future vision and implementation plan.
5) Attaching an executive plan to consolidate and integrate the agency’s platforms within the
sector’s work plan, which shows the list of platforms to be integrated and the services to be
transferred, as well as transformation completion date.
7) Attaching a list showing the platforms and domains that have been closed, while clarifying the
reasons for closure.
8) Attaching a report showing the closure of inactive and temporary platforms (if not applicable,
an approved document of the same is attached, and the validity of the data will be verified
through the DGA's checklists).
Scope Agencies specified in Annex 7.6, and all government agencies as indicated in this card.
1) Registering the domain names of the agency's websites in accordance with the regulations and
rules issued by the Saudi Network Information Center at the Communications, Space &
Technology Commission.
2) Adopting the sixth version of the Internet Protocol (IPv6) and activating the Domain Name
Compliance System Secure Extension (DNSSEC) to protect domains and reduce risks and cyberattacks.
Requirements 3) Improving visibility of websites and digital platforms on search engines by applying the Guide
to Search Engine Optimization Basics for Websites and relevant regulations issued by the
Authority.
4) Improving the content of websites and digital platforms on search engines by applying the
Guide to Search Engine Optimization Basics for Websites and relevant regulations issued by the
Authority.
1) Submitting an official document certified by the authorized person that includes a list of links to
the agency's websites and electronic services, specifying the main link to the agency's website.
Supporting
2) Submitting documents proving the adoption of the sixth version of the Internet Protocol IPv6 .
documents
3) Requirements 3 and 4 do not require attaching any document or proof, and the auditor visits the
agency's website to prove and verify compliance with the requirements.
▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Paragraph No. (1) of Clause
(Second) of the controls of using information and communication technologies in government
Related Orders,
agencies.
Resolutions and
▪ Royal Decree No. (M/106) dated 02/11/1443 AH, approving the Communications and
Circulars
Information Technology Act, its executive regulations, and registration regulations and rules
drawn up thereon.
The axis includes the standards and requirements for the application of frameworks and models that ensure the effective
operation, follow-up and control of all types of digital services.
Developing comprehensive standards to measure the quality of digital services from a technical and
Objective
operational point of view.
1) Defining standards and a framework for the quality of digital services to be evaluated periodically
according to these standards.
Compliance
2) Adopting indicators that measure the selected standards, provided that these indicators are
Requirements
numerically measurable in their entirety.
3) Determining the mechanism for setting targets for operation and service levels, and the mechanism
for measuring thereof.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (5).
Circulars
Utilizing digital systems to effectively and immediately monitor the quality of digital services and make
Objective
appropriate decisions.
1) Developing digital systems and tools that measure the quality of digital services according to its approved
indicators and standards.
2) Developing real-time monitors for selected indicators, and authorizing products/ applications managers
for real-time monitoring.
Compliance
3) Issuing periodic reports on quality of digital services.
Requirements
4) Sharing reports with governance committees associated with service management and quality, and
discussing findings periodically.
5) Taking the necessary actions and decisions to improve the services based on the reports and results
submitted to the competent committees, in accordance with the governance mechanism followed.
1) Attaching adequate samples and screenshots of the systems used to measure quality of services.
2) Attaching 5 samples of real-time monitors for the selected indicators, and clarifying the use powers.
3) Attaching 3 samples of periodic reports to follow up the quality of digital services.
Supporting
4) Attaching proofs of sharing reports with governance committees associated with service management
documents
and quality.
5) Attaching 3 samples of decisions and minutes of meetings that prove the activation of the mechanism to
monitor the services quality and take appropriate decisions.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
Objective Linking digital services quality procedures to relevant departments and systems.
1) Linking quality plans and practices to business continuity policies in accordance with governance
framework.
Compliance 2) Linking reports and corrective actions to infrastructure management practices in accordance with
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
Objective Identifying priority digital services and raising their maturity level.
1) Identifying strategic and operational targets to increase the utilization rates of each of the digital
government services classified as a priority.
Compliance 2) Developing the service to achieve the highest possible level of maturity and integration.
Requirements 3) Providing the service on all possible channels and employing emerging technologies as much as
possible in providing the service.
4) Measuring and reporting usage rates of each prioritized service.
1) Attaching the reports that prove the strategic and operational targets to increase the utilization rates
of each of the digital government services classified as a priority.
2) Attaching the reports that show the level of maturity and integration of priority services.
Supporting documents
3) Attaching adequate samples that show the availability of all priority services on all possible
channels, and employing emerging technologies as much as possible in the provision of the service.
4) Attaching the reports that show the measurement of usage rates of priority services.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
It includes all channels through which the agency can provide services, and identifies the appropriate channels for the beneficiaries
categories and their familiarity with technology.
Automating all services and procedures provided by government agencies (non-digital services or
services provided through branches) and developing a development plan for these services in
Objective
cooperation with the sector leader, in order to reduce the interference of the human factor and
complete digital transformation in the Saudi government sector.
1) Listing, registering and updating non-automated government services on “Raqmi” Portal.
2) Designing non-automated government services procedures, taking into account the
Compliance identification of the targeted platform, based on the sector's objectives to integrate
Requirements government platforms and apply best beneficiary experience.
3) Developing an executive plan to automate non-automated government services at the agency.
4) Obtaining the DGA's approval on the design of executive plan and procedures for launch.
1) Attaching an inventory document for all non-automated government services.
2) Attaching the designs of non-automated government services procedures that agency seeks to
automate.
Supporting documents
3) Attaching the executive plan for the launch of government services, based on the approved
procedures.
4) Attaching the DGA's approval on the design of executive plan and procedures for launch.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (16).
Circulars
Objective Providing services through digital channels and developing the plans necessary in this regard.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
Following up on the provision of services through the appropriate digital channels, and following up
Objective
the beneficiaries interaction with these services.
1) Implementing plan to make services available through digital channels (including call center).
2) Including clear information about digital services, to include the following:
a. An overview of the service.
b. Channels available to provide the service.
c. Services provisions requirements.
d. Policies, systems and procedures associated with the service.
e. Targeted user segments.
f. Service launch date.
3) Providing digital services to all beneficiaries segments to ensure that people with special needs
can access the services.
4) Linking these services to the National Unified Portal for Government Services, so that the
Compliance beneficiary accesses to a seamless, satisfying and integrated digital experience.
Requirements 5) Linking digital services to beneficiary satisfaction measurement systems automatically, and
preparing a mechanism to make their data and statistics available; for making them available to
the relevant agencies in digital form.
6) Monitoring the services that have been launched, and issuing periodic reports on the approved
performance indicators for each service and in each of the call center channels (voice, mail, instant
messaging, video for deaf).
7) Studying and analyzing services on an ongoing basis and studying extent to which the services
can be provided through various electronic channels, and taking the necessary steps to improve
services and increasing use of electronic channels.
8) Including statistics in the agency's annual reports on the actions taken to provide and improve
services, to include the following:
a. Time taken to complete services for beneficiaries.
b. Beneficiaries' satisfaction with the digital services provided.
1) Attaching periodic reports that show the follow-up of the implementation of executive plan to
provide services to beneficiaries.
Supporting 2) Attaching a service catalogue that meets the compliance requirements of this standard.
documents 3) Attaching proofs of the provision of the service to different groups to ensure that persons with
special needs can access these services.
4) Attaching reports that prove that these services have been linked to the National Unified Portal
for Government Services.
Related Orders, ▪ Council of Ministers’ Resolution No. (40) dated 27/02/1427 AH, Paragraph No. (15).
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (4).
Circulars ▪ Royal Order No. (17850) dated 16/03/1441 AH, Clause (Second).
Objective Achieving integration between various digital channels that provide services to beneficiaries.
1) Integration between service delivery channels to enable the beneficiary to implement his
services without interruption through the various channels used to provide the same service.
2) Consistently making the services available across multiple channels according to the suitability
Compliance
of channels for user segments and their familiarity with the technology.
Requirements
3) Providing access to the agency’s websites and portals from various devices and browsers in
accordance with the (RWD) principle.
4) Including beneficiary care centers as service delivery channels and linking them to beneficiary
relationship management systems.
1) Attaching 3 samples showing the integration between service delivery channels and provision of
the same service through more than one channel.
2) Attaching 3 samples showing the availability of services consistently across multiple channels
Supporting
and their suitability for all user segments.
documents
3) Attaching adequate samples proving the availability of access to the agency's sites and portals
from various devices and browsers.
4) Attaching adequate samples showing the process of linking and integrating between beneficiary
care centers and beneficiary relationship management systems.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
It ensures that the beneficiary's role is enhanced and transformed into an effective partner in the development and improvement
of digital government services by identifying his views and ideas about the experience of obtaining such services, which helps
government agencies in understanding the beneficiaries experiences.
Objective Sharing public information and promoting transparency across all government sectors.
1) Availability of the agency's necessary information on its website, and such information shall
include the following:
a. Administrative reference for non-independent government agencies.
b. Contact numbers, e-mail, and any additional electronic means to communicate with the
beneficiaries of government services.
c. Privacy statement, property rights, and disclaimer statement that the agency does not
assume any legal responsibility for the use of data or information published on its websites.
d. Use agreement, including the consequences of misuse of information systems and resources
Compliance
and electronic portal of relevant laws and regulations.
Requirements
e. Most prominent activities and achievements in its field of work.
f. An updated copy of the information necessary for the services provided to beneficiaries.
g. Information about its social media accounts.
2) Publishing laws and regulations related to the agency's business.
3) Publishing general information about the government agency, its establishment, tasks,
objectives, regulations and policies related to its field of supervision.
4) Publishing links of the websites of any national/local government institutions/agencies related
to the agency's business.
Supporting 1) It does not require attaching any document or proof, and the auditor visits the agency's website
documents to prove and verify the availability of the required information.
▪ Council of Ministers’ Resolution No. (40) dated 127/02/1427 AH, Paragraph No. (15).
Related Orders, ▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Paragraph No. (2) of Clause
Resolutions and (Second) of the controls of using information and communication technologies in government
Circulars agencies.
▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Availability of channels and topics for beneficiaries to share their views, feedbacks and
Objective
suggestions.
1) Listing the necessary and appropriate electronic channels for the beneficiaries, which enable
them to share their views, feedbacks and suggestions about the services provided, including
Requirements 2) Survey on draft regulations, laws and policies through "Istitlaa" platform, including (bidding
and tendering, implementation, results and decision).
3) Posting e-participation topics and opportunities on ("Tafaul" platform), and on the
government agency's website (as applicable).
4) Developing an approved mechanism to benefit from the beneficiaries’ views and
participation, including the development of a course of action for beneficiaries’ feedback
according to different ratings.
5) Identifying performance indicators to respond to feedbacks and notify the beneficiary of the
time required to study the feedback or suggestion.
1) Continuous and periodic follow-up of beneficiaries participation, and monitoring all opinions,
participations, complaints, and suggestions.
2) Giving the beneficiary a reference number for the feedback or suggestion and the results of
Compliance
study.
Requirements
Compliance requirements to be met by the government agencies benefiting from digital reporting,
as specified in Appendix No. 7.6.
3) Processing digital reports submitted by the Digital Government Authority in accordance with
the Service Level Agreement.
Related Orders, ▪ Digital Government Authority’s Circular No. (311) dated 16/03/1445 AH, on E-Participation
Resolutions and Controls.
Circulars ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
All government agencies and the concerned government agencies specified in Appendix No. 7.6,
Scope
as indicated in this card.
Presenting the e-participation results, and benefit from beneficiaries’ participation in the decision-
Objective
making process, and launching and improving services.
1) Considering the beneficiaries’ views, and encouraging them to continue to participate in all
design stages of digital government services.
2) Issuing periodic reports received from various channels dedicated to beneficiaries’
participation.
Compliance
3) Benefiting from beneficiaries’ participation in the process of developing and improving the
Requirements
services provided and making the necessary decisions based on these views and experiences.
4) Publishing the results of consultations and e-participation on what has been presented on the
government agency's official channels, and through specialized e-participation platforms:
“Tafaul” Platform and “Istitlaa” Platform
1) Attaching 4 samples (one for each quarter) to prove that the views of the beneficiaries have
been considered.
Supporting 2) Attaching 4 samples (one for each quarter) of the periodic reports.
documents 3) Attaching 4 samples (one for each quarter) to prove that the beneficiaries’ participations have
been utilized.
4) Attaching sample of the results of the consultations and e-participation published.
Related Orders,
▪ Digital Government Authority’s Circular No. (311) dated 16/03/1445 AH, on E-Participation
Resolutions and
Controls.
Circulars
The axis applies a clear approach to the process of managing communication with the beneficiaries and marketing the agency's
services using modern means and methods to improve the procedures of supporting and enhancing the relationship with the
beneficiaries in the government agency.
1) Developing an approved program to market the agency's services and enhance its relationship
with the beneficiaries of their various classifications, taking into account the quality of
channels through which services are provided. The program to enhance the relationship with
the beneficiary includes the following points:
a. List of services that the agency aims to market, taking into account priority digital services.
b. The targeted groups of the plan to strengthen the relationship and market the services.
Compliance c. Electronic channels used in marketing operations and relationship enhancement.
Requirements d. Means and events that will be carried out for marketing and enhancing relationship with
the beneficiary.
e. The schedule approved for holding these events.
f. Performance indicators through which the success of these events will be measured.
g. Periodic reports to be issued on these events.
2) Applying controls related to social media issued by the Ministry of Media and relevant
authorities.
1) Attach the approved program to enhance relationship with the beneficiary, which proves the
Supporting agency's commitment to the compliance requirements of this standard.
documents 2) Attaching sample of regulations and controls related to participation in its social media.
Related Orders, ▪ Council of Ministers’ Resolution No. (555) dated 23/09/1440 AH, Clause (Eighth)
Resolutions and ▪ Royal Court Circular No. (47746) dated 29/06/1445 AH, regarding the approval of controls of
Circulars media use of social media in government agencies.
1) Implementing the approved marketing programs, campaigns and activities to raise the
beneficiaries’ awareness of the agency's digital services and ways to obtain the services
through various channels.
2) Monitoring and measuring the approved performance indicators that measure the objectives
Compliance of the program to strengthen the relationship with the beneficiary and the extent to which they
Requirements achieve the desired goals, and measuring the extent of progress in programs implementation.
3) Studying and analyzing the periodic reports resulting from the implementation of the program
to strengthen the relationship with the beneficiary, and benefiting from these reports in
developing marketing activities, improving service level and taking appropriate decisions in
this regard.
1) Attaching adequate reports and screenshots that prove that the agency has implemented the
approved programs to strengthen the relationship with the beneficiary, including all products
and platforms (whether for individuals or agencies).
2) Attaching the periodic reports that measure the success of programs to strengthen the
Supporting relationship with the beneficiary in achieving the objectives, and clarifying the completion
documents rates.
3) Attaching minutes and official documents proving that the agency has studied and analyzed
the periodic reports resulting from the implementation of programs to strengthen the
relationship with the beneficiary, and took decisions that contribute to the development of its
marketing programs.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (13).
Circulars
Achieving cooperation and integration with other government agencies with regard to enhancing
Objective
relationship with the beneficiary.
1) Achieving cooperation with other government agencies in marketing shared services, and
enhancing the relationship with beneficiaries through integration of programs and activities
Compliance
related to shared services.
Requirements
2) Carrying out joint marketing campaigns with the government agencies concerned with the
services provided, and including these activities within the programs to enhancing
relationship with the beneficiary.
1) Attaching adequate documents and samples of reports, minutes of meetings and decisions
that prove that the agency has committed to achieving cooperation and integration with other
agencies in the field of marketing shared services and enhancing relationship with the
Supporting documents
beneficiary.
2) Attach adequate documents and samples of reports, minutes of meetings and decisions that
prove that the agency has conducted joint marketing campaigns with the government
agencies concerned with the services provided.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
The axis ensures that the beneficiary interacts with the government agency during all stages of providing the service, by
adopting the principles of creative, interactive and visual design, and ease of access and use, to ensure the sustainability and
continuity of the relationship.
Establishing foundations of beneficiary centrality to ensure the optimal use of digital government
Objective
services and adopting them by beneficiaries
1) Developing policies that enable the adoption of the concept of beneficiary centrality in the
provision of digital government services, such as the policy of "access to information and digital
government services", and the policy of "e-participation" and publishing these policies in the
Compliance channels through which digital government services are provided, taking into account their
Requirements comprehensiveness, clarity of formulation and method of presentation.
2) Developing a strategy for the provision of digital services that takes into account the concept
of beneficiary centrality, and developing the plans, programs and follow up mechanisms
required to implement the strategy.
Supporting 1) Attaching policies and strategies that support the adoption of the beneficiary centricity in the
documents provision of digital government services.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
1) The agency has a vision to measure and improve the beneficiary's experience.
2) Identifying performance indicators associated with measuring and improving the beneficiary
experience, to include the following:
a. Accessibility for the service.
Compliance b. Identical service level in all channels.
Requirements c. Caring of the content.
d. Ease of usage.
e. Importance of the service and the beneficiary's benefit period.
f. Reliability.
g. Efficiency.
1) Attaching an approved document specifying the agency's vision for the beneficiary's
Supporting
experience and specifying the approved indicators to achieve this vision, according to the
documents
compliance requirements of this standard.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
Objective Studying the beneficiary's experience to improve it, and setting standard targets in this respect.
1) Conducting a preliminary study of the beneficiary's digital experience to improve it, to include:
a. Objectives of the improvement process based on the study of beneficiary experience and
Compliance satisfaction assessment.
Requirements b. List of tools used to measure the beneficiary's experience.
c. Methodologies for measuring the impact of applying beneficiary-centric practices and
developing the beneficiary experience.
Supporting 1) Attaching an approved document proving that the agency has studied the beneficiary's digital
documents experience, which meets the compliance requirements of this standard.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
Objective Applying digital tools for measuring and following up on the beneficiary's experience.
1) Employing the necessary digital tools and technologies to measure the beneficiary's experience
and behavior during the performance of the service, directly or indirectly, to include:
a. Tools to track the performance indicators that have been prepared.
Compliance b. Tools that allow the creation of beneficiary satisfaction reports for those services.
Requirements 2) Studying and analyzing the reports resulting from the digital tools and technologies used to
measure the beneficiary's experience, and using them to improve the services.
3) Comparisons according to performance indicators that measure the beneficiary experience, as
approved for improved services before and after improvement.
1) Attaching adequate samples of reports and tool screens used to measure beneficiary
satisfaction and follow up on performance indicators, which prove the agency's commitment
to the application of digital tools for measuring and following up on the beneficiary's
experience.
Supporting
2) Attaching proof of studying and analyzing the reports resulting from the digital tools and
documents
technologies used to measure the beneficiary's experience, and using them to improve the
services،
3) Attach reports showing comparisons of improved services before and after improvement,
according to approved performance indicators for measuring the beneficiary experience.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
Identifying all life journeys that consist of key activities represented in several digital services
Objective between more than one government agency in cooperation with the sector's leader, to achieve a
unified integrated life experience from the beneficiary's perspective.
1) Visualizing the future perception of the agency digital scene based on the beneficiary's life
Compliance journeys, according to the type of targeted group.
Requirements 2) Service journey flowchart.
3) Developing an executive plan to adopt and apply life journeys to the agency's digital scene.
1) Attaching the agency's future vision to identify the beneficiaries life journeys that meet the
Supporting compliance requirements of this standard.
documents 2) Attaching services journey flowchart.
3) Attaching an executive plan to apply life journeys to the agency's digital scene.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (16).
Circulars
The axis includes the standards and requirements for applying a set of models, policies, systems and standards that relate to the
data collected in the government agency, and how they are dealt with, starting from their definition and the mechanism of
collecting, storing, arranging, integrating and using them in the agency.
1) Establishing an independent data governance and management unit to fully supervise the
Compliance agency's data governance and management.
Requirements 2) Adopting an organizational framework for data governance and management that clarifies roles
and responsibilities, and monitors compliance with policies and rules.
1) Attaching documents proving that the agency has committed to establishing a data
Supporting
management and governance unit.
documents
2) Organizational framework for data management and governance unit.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
1) Analyzing the current data situation in the agency, and identifying the most important gaps and
difficulties encountered.
2) Developing a data governance and management strategy that includes all necessary plans with
regard to the agency's data.
3) Developing and aligning the agency’s policies and regulations with the national systems and
regulations for data governance and management (including Personal Data Protection Law and
Compliance its executive regulations, policies of the National Data Management Office, policies of the
Requirements National Information Center, and policies issued by the National Cybersecurity Authority in this
regard), and committing to and applying the same.
4) Obliging employees to abide by standards related to privacy protection through declarations
and terms of use agreements.
5) Developing data monitoring reports and following up on compliance with data governance and
management policies and rules and on the implementation of decisions taken to develop and
update these policies and rules.
▪ Personal Data Protection Law issued by Royal Decree No. (M/19) dated 09/02/1443 AH, as
amended by Royal Decree No. (M/148) dated 05/09/1444 AH, and its executive regulations
Related Orders,
issued on 29/02/1445 AH,.
Resolutions and
▪ Council of Ministers’ Resolution No. (40) dated 27/02/1427 AH, Paragraph No. (8).
Circulars
▪ Council of Ministers’ Decision No. (555) dated 23/09/1440 AH, Paragraph No. (5) of Clause
(Ninth).
Enhancing the level of compliance with data governance and management requirements by
Objective classifying data and building its structure, and making use of modern digital systems to analyze data
and support decision-making.
1) Classification of the government agency’s data, in accordance with the relevant laws,
regulations and rules.
2) Building and modeling the government agency’s data structure.
Compliance
3) Issuing, studying and analyzing periodic reports to monitor compliance with policies and rules
Requirements
on data governance and management.
4) Making use of modern data analysis digital systems, and supporting business decision making in
other departments.
1) Attaching sample of data record showing classification levels given to various datasets.
2) Attaching sample of data structure and modeling.
Supporting 3) Attaching sample of follow-up reports that demonstrate commitment to the periodic review of
documents the data recorded in the databases.
4) Attaching (3 samples) proving that the agency has used data analysis technologies and business
intelligence in decision-making.
Related Orders,
Resolutions and ▪ Council of Ministers’ Resolution No. (40) dated 27/02/1427 AH, Paragraphs No. (2) and (6).
Circulars
The axis includes standards and requirements for the application of models and processes aimed at sharing and making data
available through the necessary digital infrastructure, while enabling access to open data.
1) Develop the data use strategy to include the vision and objectives of data use and utilization,
and be aligned and emanate from the agency's data governance and management strategy.
Compliance 2) Preparing an executive plan that clarifies the initiatives and projects necessary to activate the
Requirements data use strategy in a way that enhances the inherent value of data.
3) Identifying performance indicators and issuing follow-up reports on the implementation, study
and analysis of the plan.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
1) Availability of the agency's shared data on the government service bus (GSB), and providing
these data to the government agencies free of charge, if requested.
2) Including statistics in the agency's annual reports on its commitment to share data with other
government agencies, including exchange volume of the agency's shared data on the
government service bus (GSB).
3) Developing a policy to give and revoke access to the agency's data, as needed.
4) Documenting all endpoints and information related to requests and responses on “Raqmi”
Compliance platform.
Requirements 5) Monitoring the APIs performance, logging events and analyzing logs to identify errors and
improve performance.
6) Issuing periodic follow-up reports on application programming interfaces (APIs) showing, at a
minimum, the following:
a. Number of interfaces that provide real-time data.
b. Number of open APIs for various segments of beneficiaries, including private sector,
individuals, researchers, entrepreneurs and innovators).
c. Detailed list of agencies with whom data was shared.
1) The availability of the agency's shared data on the government services bus (GSB) will be verified
through the Link Lists, and the availability of shared data will be verified through the Link Lists.
2) Providing copy of the agency annual report showing statistics related to sharing data with other
government agencies.
Supporting 3) Attaching copy of the policy for granting and revoking access to the agency's data.
documents 4) Documentation of endpoints will be verified through the APIs tool on “Raqmi” platform.
5) Attaching documents and samples of systems screens and periodic reports proving that the
agency has monitored the systems performance logs.
6) Attaching copy of the periodic follow-up reports of APIs, in accordance with the compliance
requirements of this standard.
▪ Council of Ministers’ Resolution No. (40) dated 27/02/1427 AH, Paragraphs No. (4), (5) and (7).
Related Orders, ▪ High Order No. (17850) dated 16/03/1441 AH, Clauses (Second) and (Third).
Resolutions and ▪ High Order No. (7732) dated 12/02/1440 AH, Clause (Fifth).
Circulars ▪ Digital Government Authority’s Circular No. (754) dated 26/05/1445 AH, regarding inventory of
application programming interfaces
Achieving effective implementation and optimal application of data analysis, and using forecasting
Objective
models to derive future patterns and trends from data.
1) Attaching adequate documents and samples of reports and tool screens used for advanced data
Supporting analysis.
documents 2) Attaching reports showing the use of predictive models and decisions made based on the
advanced data analysis.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
The axis includes the standards and requirements for the application of procedures, systems and models that maximize use of
data and support decision-making.
Related Orders,
▪ High Order No. (7732) dated 12/02/1440 AH, Clause (Fifth).
Resolutions and
▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraph No. (8).
Circulars
Objective Continuous reviews and updates of open datasets published, according to approved plans.
1) Developing channels and mechanisms to receive researchers' requests for open data.
2) Reviewing published datasets and updates made to them, and issuing periodic reports showing
Compliance the results of review and volume of demand for open datasets and the usage rate.
Requirements 3) Studying and analyzing user requests to update and respond to datasets.
4) Making appropriate decisions related to updating open datasets based on the results of reviewing
datasets and studying users’ requests.
1) Attaching adequate samples of screenshots showing the channels and mechanisms that have
been provided to receive researchers' requests for open data.
2) Attaching adequate samples of periodic reports showing the review results of published datasets
and the updates made to them that meet the compliance requirements of this standard (3
Supporting
samples).
documents
3) Attaching adequate samples of reports showing the study, analysis and response to user requests
(3 samples).
4) Attaching adequate samples of decisions taken based on the analysis and study of periodic
reports and user requests (3 samples).
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
Analyzing and evaluating the extent to which other agencies and individuals benefited from the open
Objective
datasets that have been published.
1) Conducting analytical studies that clarify the key factors related to the usefulness of published
open data and the value of this data to beneficiaries.
Compliance
2) Analyzing the use cases of published open datasets, and the extent to which stakeholders benefit
Requirements
from these data, indicating the relationship with the agency's open datasets.
3) Developing the API manual for the open dataset made available by the agency.
1) Attaching adequate samples of analytical studies showing key factors related to the usefulness
of open data published.
Supporting
2) Attaching adequate samples of analytical studies showing use cases for open datasets that meet
documents
the compliance requirements of this standard (3 samples.)
3) Attaching the Open Data API User Manual.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
The axis includes practices and procedures that enable the agency to raise its readiness towards adopting innovation and
sustaining the innovative environment in of digital government.
1) Including innovation as a pillar in the agency's digital transformation strategy, and setting goals
and indicators to activate and align the concept of innovation with the agency's strategic
objectives and identify recognition requirements.
Compliance 2) Identifying and aligning innovation initiatives and projects with the agency’s strategic priorities
Requirements and objectives.
3) Adopting mechanisms for cooperation, communication and partnership with national or
international research, development and innovation bodies, centers and laboratories to benefit
from experiences and capabilities to activate innovation in the agency and adopt innovative
solutions.
1) Attaching the part that clarifies the role of innovation and the associated objectives and indicators
Supporting in the agency’s digital transformation strategy.
documents 2) Attaching a document specifying the agency’s innovation initiatives and projects.
3) Attaching a mechanism or framework for partnership and cooperation with research,
development and innovation centers and laboratories.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
Adopting innovation methodologies and concepts to ensure the development and sustainability of
Objective the innovative environment and contribute to the innovation and sustainability of innovative
products, services and solutions.
1) Sample of a report proving the adoption of the agency of the innovative design methods and
concepts, to include the following:
a. Methodology used and methods of application.
b. Examples of outputs.
2) A report proving the adoption of the agency of the open innovation methodology, to include the
Supporting following:
documents a. Methods and means used, such as hackathons or competitions (priority is given to
hackathons that are conducted in partnership with the competent authorities and centers for
such events).
b. Number of participants in the open innovation events.
c. Attaching adequate samples showing these events have been convened.
3) A report showing cooperation with entities specialized in the fields of innovative design and open
innovation, such as hackathons.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
1) Forming an administrative unit, committee or specialized team to stimulate and adopt innovation
and its concepts within the agency.
2) Activating the unit/ committee and approving its procedures and processes with the relevant
Compliance departments and committees, to include the following:
Requirements a. Issuing decisions in the field of digital innovation.
b. Defining unit/committee procedures and processes.
c. Listing digital innovation initiatives and projects within the agency.
3) Organizing events and activities to spread the environment and culture of innovation in the
agency, through training and awareness and knowledge-raising workshops.
1) Attaching the structure, roles and responsibilities of the administrative unit/ committee.
2) Attaching a report proving the activation of the competent department or committee, to include
the following:
a. Sample of decisions taken by the unit/ committee.
Supporting
b. Procedures and processes adopted for this unit/ committee.
documents
c. Cards of digital innovation initiatives and projects within the agency, and implementation
follow-up reports.
3) Attaching an achievement report to the events and activities that have been implemented to
spread the environment and culture of innovation in the agency, including methods, means and
number of beneficiaries.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
1) Activating a clear innovation management mechanism that show the full journey from idea and
design to development and implementation.
2) Generating, inventorying and collecting applicable innovative ideas that fits with the agency’s
strategic focus areas and priorities, to include the following:
a. Identifying areas of innovation (such as innovation in digital products and services provided
Compliance
to beneficiaries, innovation in the agency's internal procedures, or innovation in business
Requirements
models).
b. Identifying innovation source (such as hackathons or research studies).
c. Identifying emerging technologies or innovative models to be used in development.
d. Identifying ideas that will be transformed into innovative products in 2024.
e. Determining the expected impact of the ideas that will be transformed into innovative
products.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
The axis includes standards and requirements for developing and implementing innovative solutions to achieve added value,
measuring impact for sustainability of innovative solutions and following up on their continuous improvement in digital
government.
1) Attaching a prototype for the innovative solution (Maximum two prototypes), including all data
and detailed information about the solution and the technologies and concepts used in its
Supporting
design and building, with an explanation of the developments and improvements that have
documents
been made during the current period, if it was previously submitted.
2) Attaching an achievement report to implement and apply the solution and its beneficiary
segment.
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
1) Developing a methodology for measuring the impact of applying the innovative solutions that
details the targeted groups, and identifies the types of expected impacts (economic, social,
financial, functional, ...), whether it is a positive or a negative impact.
2) Evaluating the impacts resulted from the application of innovative solutions, to include the
following:
Compliance
a. Impact on beneficiaries (it includes beneficiary segments, verification percentages, and
Requirements
inventory studies and methodologies).
b. Financial impact (it includes reducing costs and achieving returns, as well as exploiting and
improving resources).
c. Impact on the agency (it includes business models, performance improvement and
operational efficiency).
d. The local, regional or international awards received by the innovative solution
Related Orders,
Resolutions and ▪ Royal Court Circular No. (6262) dated 26/01/1445 AH, paragraphs No. (1) and (18).
Circulars
Term Definition
Digitally and strategically transforming and developing business standards and models that would
Digital Transformation
rely on data, technologies, and ICT.
Ministries, authorities, public institutions, councils, national centers including any additional form
Government Agency
of a public entity.
A policy defines the course or principles of action to guide and determine present and future actions
Policy and it specifies what Government Agencies are required to do Policies can have related standards
that provide more information for agencies.
Standards A set of rules and controls regulating the operations and tasks related to the digital government.
Specify the conditions government agencies must comply with and what they must do to achieve
Controls
the objectives and general provisions stated in the policy associated with them.
Provides examples showing the implementation mechanism of the of policies and standards in
Guidelines
place.
Practices and controls to analyze the as-is state of Government Agency, and develop a roadmap for
transition to the to-be state to realize alignment between business sector (services and procedures),
Enterprise Architecture
information technology (data, implementations, and infrastructure) and strategic objectives of the
Government Agency.
The resources, capabilities, procedures, and actions necessary to continue providing core services
Business Continuity
and products at pre-determined levels and within an acceptable time frame in the event of
A document that specifies the general framework for managing, coordinating and directing
Business Continuity resources, capabilities, human and technical capabilities, and procedures to respond to
Plans interruptions and resume operations to provide necessary products and basic services, and recover
as quickly as possible for the continuity of the agency’s business.
Re-designing the processes, procedures and work provided by the institution or agency with the
"Business Process aim of creating development in terms of quality, quick completion, cost and service, in line with the
Reengineering" (BPR) institution’s vision. The procedure engineering process may require restructuring and arranging the
entire institution or part of it, including establishing or closing entire organizational units.
Processes through which the steps of procedures for the services provided are determined, and
Procedures
these procedures are drawn and represented in order to study, analyze, and develop their
Documentation
performance.
Business Process A structured process that an organization or agency uses to develop the procedures and services it
Improvement (BPI) provides and make them more efficient and productive.
Organized processes and procedures imposed by the compliance requirements of a new system or
plan to move individuals or institutions from their current situation to a better situation. This is done
Change Management through specific and deliberate steps that take into account the nature of the institution, its ability
to develop and the surrounding circumstances. Change usually passes through three main steps:
namely: preparing for change, managing change, and sustaining change.
Data architecture includes for example: data classification, data exchange, a list of data used in the
Data Architecture entity, the definition of its sources and associated databases
Data that any individual can freely use, without technical, financial or legal restrictions, as well as
reuse and publish it, taking into account the requirements of the legal license under which this data
Open Data
was published.
A set of data often corresponds to the contents of one database table or statistical data matrix,
Data Set where each column in such table represents a specific variable, and each row represents one
element in the involved data set.
Government Services A unified platform used for Government shared services that are continuously updated and provides
Bus (GSB) integration between Government Entities quickly and securely.
A set of transactions linked to each other to perform a complete function provided by the
government agency to the beneficiary through digital channels such as digital portals and smart
Digital Service
device applications so that they have one main exit defined and specified. A group of services can
be linked together to form a digital product.
Involves all channels through which the Government Agency can provide services. For example, the
Service Delivery Channel Government Agency's head office, portal, telephone and automated answering machine, smart
device implementations, or service kiosks.
Any electronic service aimed at verifying the validity and integrity of electronic transactions and
Digital Trust Service
the identity of customers, including (e-signature, e-stamp, timestamp, etc.).
Systems and services provided by a Government Agency targeting other Government Agencies to
Shared Systems & provide services and solutions that support the implementation of the "Whole of Government
Services Concept" and provide Government Digital Services that are beneficiary-focused, seamless, end- to-
end, and avoid duplication.
A Comprehensive approach aims to unify the efforts of different units and government entities to
Whole-of-Government
achieve one purpose.
Any Government entity that owns the Government Shared Systems and Services, whether it
Owner
manages and operates it directly or through another Operating Entity
Any entity manages or operates the Government Shared Systems and Services through a
Operator
contracting relationship with the Owning Entity.
Government agencies that own shared government systems and services, whether the platform is
Responsible
developed, managed and operated by them or by others. These are the entities that work to enable
Government Agency
government agencies to benefit from their shared systems and services
Digital interaction and participation that allows the beneficiaries to provide their feedback, share
Electronic Participation their ideas and suggestions about specific topic related to society, this includes conducting voice of
customer studies, to improve government services that revolves around the beneficiary needs.
Beneficiary's interaction with the Government during all stages of service delivery, through
Beneficiary Experience adoption of creative, interactive and visual design principles, accessibility and usage, to ensure
sustainability and continuity of the relationship.
Citizens, residents, visitors, government agencies, private sector, and not-for-profit sector, inside or
Beneficiary outside Saudi Arabia that required to interact with a government entity to receive any of the
services offered in Saudi Arabia.
A model which enables convenient, on-demand network access to a shared pool of configurable
Cloud Computing computing resources (e.g. networks, servers, storage, applications, and services) that can be rapidly
provisioned and released with minimal management effort or service provider interaction
Modern technologies that support digital government works, which have achieved a qualitative
Emerging Technologies leap in digital transformation, and are still subject to development, such as artificial intelligence,
the Internet of Things, the block chain, etc.
Application A set of commands, functions, objects, and protocols developed to be used by programmers to
Programming Interfaces develop software, or to interact with other systems and/or software.
Digital Transformation Measurement (Qiyas) workshop shall be launched via an introductory workshop for which all
representatives of covered Government Agencies shall be invited to attend, review updates to Digital Transformation
Measurement (Qiyas) cycle, get familiar with the adopted methodology, and respond to answers and inquiries related to Digital
Transformation Measurement (Qiyas) during the workshop.
2) Making the System Available to the Government Agencies to Submit their Responses
Digital Transformation Measurement (Qiyas) System shall be made available to the liaison officer or his representative at the
Government Agencies to review compliance cards, begin responding to them and attach required certificates for question
cards. The question card shall state all details from the standard, legal reference, supporting documents and answer options,
keeping in mind the following requirements for the supporting documents.
Requirements
• Attached strategies and plans shall be valid and approved and shall include all elements and components to be met in the
• Attached decisions and directions shall be enforceable, valid, issued and approved by the authorized person in the
Government Agency.
request.
• Attached studies and surveys shall clarify all adopted methodologies of data collection and analysis and shall include
• Methodologies, policies, controls, and standards shall be valid, approved and applied at the Government Agency and shall
• The authorized person shall be responsible of the document content and the owner of the document. When the authorized
person signs and affixes his name on the document, the document will be considered approved.
This stage shall include auditing and assessment as per the verification mechanism. The verification process shall be carried
out by a team dedicated to answers of Government Agencies, which shall review the attached certificates of each card and
insert notes, if any, below each compliance card to be reviewed by the liaison officer or his representative at the target
Government Agencies. Notes shall refer to the additional required certificates or to failure to meet the required compliance
standards.
Government Agencies shall be granted an additional period to address the comments that the team inserted, review comments
on each question card and re-attach the required certificates if required.
This stage shall include auditing and final assessment of answers of the Government Agencies and final notes of the participant
Government Agencies.
6) Reporting
After completion of results auditing, reports of participant Government Agencies shall be issued, after addressing comments
on the assessment. Reports shall include compliance levels and ratios and detailed content about comparisons of total results
of the Government Agency to the ones of the other agencies. Reports shall be made available on the system, and the senior
official at the Government Agency shall be advised of the result, and then, results of Government Agencies shall be presented
to His Royal Highness.
• Virtual meetings.
Levels of compliance with the Standard are determined via one of the following compliance levels:
In case of request or inquiry by one of the Government Agencies, such requests shall be handled as per the following procedures
and mechanism:
Such requests and inquiries shall be processed within (3) working days.
• Objection provision
• Reference to evidence achieving the standard. Each evidence shall be covered by the attachments uploaded on the system.
Log in the Digital Transformation Measurement (Qiyas) via QR Code or via the following link:
The figure below shows the list of High Orders, Council of Ministers Resolutions, and Circulars related to digital
transformation in the basic standards document for digital transformation after being updated.
Royal Order No. (8189/MB) Council of Ministers’ Resolutions Electronic Transactions Law issued Council of Ministers’ Resolution
dated 19/06/1426 AH, No. (40) dated 27/02/1427 AH, by Royal Decree No. (M/18) dated No. (240) dated 23/07/1428 AH,
Forming Committees for approving the controls for the 08/03/1428 AH, as amended by Organizing
Electronic Transactions application of e-government Council of Ministers’ Resolution Information Technology works
Council of Ministers’ High Order No. (41990) dated High Order No. (48310) dated High Order No. (11904) dated
Resolution No. (82) dated 11/10/1435 AH, on the use of 26/11/1435 AH, on Total Quality 05/03/1437 AH, regarding
22/03/1431 AH, digital certificates and Management posting on the Saudi National
10/11/1439AH, on the 12/02/1440AH, on Shared No. (555) dated 23/09/1440 AH, 13/11/1440 AH, approving the
Electronic Control System Platforms, Business Continuity regarding the controls of using Government Tenders and
technologies in government
agencies
High Order No. (17850) dated Council of Ministers’ Resolution Council of Ministers’ Resolution Royal Decree No. (M/106) dated
16/03/1441 AH, on the No. (418) dated 25/07/1442 AH, No. (14) dated 02/01/1443 AH, on 02/11/1443 AH, approving the
inventory and documentation approving the Digital Free and Open Source Government Communications and
government agencies
(22424) dated 09/04/1443 dated 13/11/1443 AH, which notified under His Excellency the dated 26/01/1445AH, regarding
AH, on seeking the views of includes the application of the President of the Royal Court Letter transaction related to the
public and government concept of e-participation and No. (8102) dated 03/02/1444 AH, eighth and ninth annual reports
agencies on the unified polling public’s opinions in regarding finding solutions for the to measure government digital
to economic and
nature.
Governance of all items 07/11/1442 AH, based on its based on its Regulations dated 15/01/1443 AH,
Services Council of Ministers’ Ministers’ Resolution No. digital circuits and other
(418) dated 25/07/1442 AH,
Resolution No. (418) dated telecommunications services
25/07/1442 AH,
Digital Government
agencies
You can access document details (except for Circulars) by visiting National Center for Archives and Records website on the following link: (www.ncar.gov.sa)
Establishing an overall-quality
administrative unit in the
High Order No. (48310) dated
telecommunications and Technological
26/11/1435 AH, Paragraph No. 4.1.3 5.11 5.11.1 3
information technology centers Services Infrastructure
(1).
and computer departments of
the government agency.
Council of Ministers’
Resolution No. (40) dated
27/02/1427 AH, Paragraph
No. (17) of Electronic Formation of e-Government Digital Transformation
4.2.1 5.2 5.2.1 5
Government Transactions Transactions Committee Governance
Regulations.
Digital Government
Authority’s Circular No. (378)
Whole-of-government
dated 02/06/1444 AH, on Linking to the Unified National 5.13 5.13.2
4.3.3 platforms 3
activation of electronic Access Platform "NAFAD"
payment channels and unified
access.
Digital Government
Authority’s Circular No. (378)
dated 02/06/1444 AH, on Link to Direct Online Payment
4.3.4 4
activation of electronic Service “Tahseel”
payment channels and unified
access.
Council of Ministers’
Resolution No. (555) dated
23/09/1440 AH, Paragraph
No. (1) of Clause (Second) of
the controls of using
Registering the domain names
information and
of the agency's websites in
communication technologies
accordance with the regulations
in government agencies. 4.4.1 Whole-of-government
and rules issued by the Saudi 5.13 5.13.10 1
Telecommunications Law platforms
Network Information Center at
issued by the Council of
the Communications, Space &
Ministers’ Resolution No.
Technology Commission
(592) dated 01/11/1443 AH,
and its executive regulations,
and the regulations and rules
for registration derived
therefrom.
Council of Ministers’
Availability of the necessary
Resolution No. (555) dated Beneficiary
4.4.2 information on the government 5.16 5.16.1 1
23/09/1440 AH, Paragraph participation
agency’s website.
No. (2) of Clause (Second) of
Council of Ministers’
Resolution No. (555) dated
23/09/1440 AH, Paragraph
Hosting the agency's websites,
No. (3) of Clause (Second) of Technological
4.4.3 information and services within 5.11 5.11.2 4
the controls of using Services Infrastructure
Saudi Arabia
information and
communication technologies
in government agencies.
Digital Government
Authority’s Circular No. (1533)
dated 23/05/1443 AH, on
Reporting interruption of
reporting the interruption of 4.4.4 Business Continuity 5.9 5.9.5 7
digital government services
digital government services
issued to all government
agencies.
Council of Ministers’
Resolution No. (40) dated
27/02/1427 AH, Paragraph
Using e-mail and electronic
No. (13).
means of communication in the
Council of Ministers’ 4.6.1 1
government agency's
Resolution No. (555) dated
businesses.
23/09/1440 AH, Paragraphs
No. (1) and (3) of Clause
(Third).
Council of Ministers’
Including in e-mails a disclaimer Systems that support
Resolution No. (555) dated 5.10 5.10.5
4.6.2 regarding the contents of public digital transformation 2
23/09/1427 AH, Paragraph
or private government e-mails
No. (4) of Clause (Third).
Council of Ministers’
Resolution No. (555) dated Hosting government email
4.6.3 4
23/09/1427 AH, Paragraph servers within Saudi Arabia
No. (5) of Clause (Third).
Council of Ministers’
Writing down the user's
Resolution No. (555) dated
4.6.4 government email address on 3
23/09/1427 AH, Paragraph
the business card only
No. (6) of Clause (Third).
Council of Ministers’
Resolution No. (14) dated The government agency
02/01/1443 AH, Paragraph obtains the government license
4.8.1 1
No. (5) of Clause (H: Rules for free and open source
Implementation software
Considerations).
Council of Ministers’
Resolution No. (14) dated Promoting opportunities to
02/01/1443 AH, Paragraph 4.8.2 reuse government software
No. (1) of Clause (B: Purpose of available for use
the Rules).
3
Council of Ministers’
The government agency applies
Resolution No. (14) dated
the approved mechanism for
02/01/1443 AH, Clause (D: 4.8.3
purchasing government
Government Software
software
Purchase Considerations). Technological
5.11 5.11.4
Council of Ministers’ Services Infrastructure
Government agency applies the
Resolution No. (14) dated
provisions and rules related to
02/01/1443 AH, Clause (E: 4.8.4 4
contracting to build
Provisions for contracting to
government software
build government software).
Council of Ministers’
Resolution No. (14) dated Listing the government
02/01/1443 AH, Paragraph agency's open source software
4.8.5 2
No. (2) of Clause (H: Rules that it wishes to share with the
Implementation government agencies
Considerations).
Council of Ministers’
Resolution No. (40) dated
Keeping and archiving the
27/02/1427 AH, Paragraph
agency's documents, contracts,
No. (3).
decisions, letters and data
Council of Ministers’
electronically, and linking them Systems that support
Resolution No. (555) dated 4.9.1 5.10 5.10.3 2&3
to its financial and digital transformation
23/09/1440 AH, Sub-
administrative systems in an
paragraph (A), Paragraph No.
automated system for ease of
(1) of Clause (Fifth).
access to them.
High Order No. (57231) dated
10/11/1439 AH, Clause (First).
Developing a specific
Council of Ministers’
mechanism to update the
Resolution No. (40) dated
4.9.3 information and data recorded 5.19.2 4
27/02/1427 AH, Paragraph
in the agency's databases to
No. (6).
ensure its accuracy
Providing adequate
information on the services the
agency provides and their
Council of Ministers’ places, the services procedures,
Resolution No. (40) dated and the agency's systems and Digital Channels and
4.10.1 5.15 5.15.3 2
27/02/1427 AH, Paragraph executive regulations and Services
No. (15). public versions through its
website or through other
appropriate electronic access
channels
High Order No. (11904) dated Agencies survey their existing Whole-of-government
4.10.2 5.13 5.13.8 1
05/03/1437 AH,. platforms with the Digital platforms
Digital Government
Authority’s Circular No.
Obtaining the DGA’s prior
(5589/42/1) dated
approval before establishing or
07/11/1442 AH, based on its
4.10.3 launching any platform 2
Regulations issued by the
Council of Ministers’
Resolution No. (418) dated
25/07/1442 AH,.
Council of Ministers’
Implementing and using
Resolution No. (40) dated Systems that support
4.10.6 government GRP systems 5.10 5.10.1 1
27/02/1427 AH, Paragraph digital transformation
effectively
No. (12)
Digital Government
Authority’s Circular No. (102)
Developing a plan to adopt
dated 09/02/1444 AH, on
4.12.1 cloud computing services and Cloud Architecture 5.12 5.12.2 1
preparing a plan for
integrate data centers
transformation towards cloud
solutions.
Digital Government
Authority’s Circular No. (1878)
Building and managing a 5.9.1 to
dated 24/09/1443 AH, on 4.13.1 Business Continuity 5.9 All requirements
business continuity system 5.9.7
Business Continuity
Management Standards.
# Question Answer
What is Digital Transformation? Digitally and strategically transforming and developing business standards and models that would
1
rely on data and technologies.
What is Compliance? Full compliance with the implementation of standards through detailed compliance requirements
2
that fall under each standard.
What is meant by the measurement Measurement of compliance with standards and requirements related to digital transformation,
3 of compliance using digital and determination of compliance levels for each standard.
transformation standards?
What are regulatory references for Referring to the Council of Ministers Resolution No. (418), dated 25/07/1442 AH, approving DGA’s
the measurement of compliance? Bylaw, which stipulates in Article (4/5 and 6) that DGA undertakes the following functions and
duties: Issuing measurements, indicators, tools, and reports to measure the performance of
Government Agencies and their capabilities in the field of digital government, and the beneficiary’s
satisfaction therewith; Following-up on the compliance of Government Agencies with the decisions
and orders issued on digital government transactions, according to frameworks and standards
4
developed by DGA, together with E-Government Transaction Implementation Rules issued by virtue
of the Council of Ministers Resolution No. (40), dated 27/02/1427 AH, as amended by the Council of
Ministers Resolution No. (252), dated 16/07/1431 AH, where Article (22) stipulates that: “Each
Government Agency shall measure the extent of transformation to e-government transactions every
six (6) months according to indicators developed by the Program. Such indicators shall be included
in the annual report of the Government Agency, and copies thereof shall be sent to the Program”.
How the measurement of current Vision 2030 aims to transform the Government of Saudi Arabia into a high-performance government
digital transformation aligns with that features effectiveness, transparency, and accountability. From this perspective, the digital
5
objectives of the Saudi Vision 2030? transformation process is one of Vision 2030 key commitments, as the Vision emphasized the need
to continue expanding the scope of digital services provided to include other services such as
Who is responsible for compliance DGA, by monitoring compliance levels periodically based on a specific methodology. DGA submits
6 measurement? periodic reports to officials in Government Agencies and a general report to HRH, as stipulated in E-
Government Transaction Implementation Rules.
Which Government Agencies All Government Agencies qualified for measurement, according to the approved Criteria for
7
undergo measurement? Nomination of Agencies.
Is there compatibility between the Digital transformation-related standards were developed based on a comprehensive study of a set
measurement of digital of international reference models in the process of digital transformation, which included a number
transformation in its latest version of key international indicators and frameworks. During such a study, comparisons were made for
and global reference models? pillars and stages that this process goes through, in addition to pillars used in compliance
8
measurement. Based on the outcomes of such study, a perception of pillars through which digital
transformation and compliance with modern standards can be measured in the context of Saudi
Arabia was concluded. Therefore, the updated framework of DTS is fully compatible with global
reference models.
What is meant by an approved The approved document means that it has been approved by an authorized person or a higher
document for the attachment? committee within the Government Agency that has the power required for approval according to the
9 type of document. For example, the document of the strategic plan for digital transformation must
be approved by the head of the Government Agency, to be attached with evidence of its approval
i.e., signatures and seals or official letters.
What are the requirements to be met The attached strategies and plans shall be valid and approved, and shall include all elements and
10
in the attached strategies and plans? components to be available as per best practices.
What are the requirements to be met Attached decisions and directives shall be effective, valid, issued and approved by the authorized
11
in decisions and directives? person in the Government Agency
What are the requirements to be met The attached reports must be issued by the concerned department and include all information
12
in attached reports? referred to in the report request.
What are the requirements to be met Attached studies and surveys shall explain methodologies used in data collection and analysis
13
in attached studies and surveys? processes, and to include results and recommendations concluded therefrom.
What are the requirements to be met Methodologies, policies, controls, and standards shall be valid, approved, and applied in the
14 in the attached methodologies, Government Agency, as well as developed in accordance with best practices.
policies, controls and standards?
What is meant by samples requested Samples vary according to the requirements of the standard and the required supporting
as part of supporting documents? documents, which could be, including but not limited to:
• Sample templates and tools for business impact analysis (Sample can be reports, tables
15
or matrices).
• Samples from risk assessment study (Sample can be reports based on risk identification
and analysis matrix).
Shall reports be recent, whether for In general, attachments must be with recent dates proving that the Government Agency is working
minutes of meetings or effectively in implementing practices related to digital transformation and decision-making, as this
correspondence, where most of cannot be proven through, for example, documents of meetings that took place more than a year
16
which may be relatively old, and no ago, which indicates lack of effective and continuous work in the field related to the required
meetings were held recently at a later documents.
time?
Who is responsible for approving The authorized person is responsible for content of the document and is considered the Owner
17 documents and how are they thereof, and by signing and putting his name, the document is considered approved.
approved?
If the Government Agency forms a In case the committee formed in the Government Agency conforms to Control No. (17) of the
committee concerned with digital Council of Ministers Resolution No. (40), dated 27/02/1427 AH, then the Government Agency may
transformation, is the Government not be required to form another committee.
18
Agency required to form another In case the formation of the digital transformation committee does not conform to the
committee for e-government aforementioned Resolution, the Government Agency shall form an e- government committee as
transactions? stipulated in the Resolution.
Some requirements do not apply Requirements that do not apply to the Government Agency must be issued by the legislator or what
directly to the Government Agency, is excluded by His Highness on implementation of the content of the High Order, and in the second
what is the applicable mechanism in section, it is by the Government Agency's proving of its exclusion and the acceptance of the national
19 this case? team. This option was made available in the tenth measurement (not applicable) with the
opportunity for the Government Agency to attach evidence that this decision or standard does not
apply to the Government Agency. The acceptance of this matter remains within the powers of the
national Qiyas team.
What is meant by Digital Service Standards guarantee the effective operation and monitoring of digital services, as there are many
Quality Standards? different frameworks for monitoring the quality of digital services. It is required that they include all
20
digital aspects and are not limited to the opinions of beneficiaries and the level of satisfaction with
digital services only, standards can for include example (availability, portability, reliability, etc.)
You can view more frequently asked questions by logging in the measurement system, as they are updated on the
system continuously.
The list includes the relevant government agencies as clarified within the scope of standards, according to the following:
Relevant agencies under
Agencies Agencies Agencies
Relevant agencies the standard (5.13.9)
responsible for benefitting leading life
under the standards Consolidating and Agencies responsible
Concerned government shared systems from the digital journey
of the two axes(5.8) integrating agency’s for “developing
# agencies according to and services reporting program
"Risk Management" platforms and closing priority services”
the scope of standards under (5.13.4), service under under
and (5.9) "Business platforms and domains under Standard (5.14.4)
(5.13.5) and Standard Standard
Continuity" that are no longer
(5.13.6) standards. (5.16.3) (5.18.5).
needed”
Ministry of
1 Communication and √ √ √
Information Technology
2 Ministry of Investment √ √ √ √
Ministry of Economy
3 √
and Planning
4 Ministry of Media √ √ √
• Providing
Ministry of
subscription and
5 Environment, Water and √ √ √
payment of water
Agriculture
bills services.
• Creation of a
business/
entreprise
6 Ministry of Commerce √ √ √
• Issuance of a
commercial
register.
• Apply for a
7 Ministry of Education √ √ government √ √
scholarship.
Ministry of Islamic
9 Affairs, Dawah and √ √
Guidance
11 Ministry of Defense √
13 Ministry of Sports √ √ √ √
14 Ministry of Tourism √ √ √ √
16 Ministry of Health √ √ √ √
18 Ministry of Energy √ √ √ √
• Issuing marriage
contracts
• Registering land
ownership
19 Ministry of Justice √ √ • Notarial services √ √
(managing and
following up cases
with the courts
electronically).
▪ Electronic
Payment
Platform
(Tahseel)
• e-Government
▪ Electronic Procurement
Payment Platform
20 Ministry of Finance √ √
Platform (Sadad) • e-payment of √
Platform/e- costs
Government
Procurement
System
(Tenders)
• Applying for
government jobs
• Providing services to
needy groups: Poor,
people with
disabilities, elderly
Ministry of Human • Applying for
21 Resources and Social √ √ financial aid for √ √
Development people with special
needs
• Applying for
maternity and
newborn aids
• Applying for child
aids
23 Ministry of Culture √ √ √
• Unified National
Access Platform
(NAFAD)
• Government
Services Bus (GSB)
Saudi Authority for Data • Government
24 and Artificial √ Secure Network √
Intelligence (SDAIA) (GSN) Platform
• Data Market
Platform
Government
Cloud (G-Cloud)
Platform
General Entertainment
28 √ √
Authority
• Paying taxes
electronically
• Submitting VAT and
Zakat, Tax and Customs GST return or
29 √ √
Authority equivalent
• Electronic invoices
• Submit income tax
return
General Authority of
30 √
Civil Aviation
• Providing
General Authority for
geographical and
32 Survey and Geospatial
geospatial information
Information
systems electronically
34 Transport General √ √
Communications, Space
35 and Technology √ √
Commission
• Providing
Water and Electricity subscription and
36 √
Regulatory Authority payment of electricity
bills services.
Capital Market
38 √ √
Authority (CMA)
Saudi Standards,
44 Metrology and Quality √
Organization
• Notice of change of
45 Saudi Post √ residential
address
Council of Cooperative
48 √
Health Insurance (CCHI)
Social Development
50 √
Bank
Saudi Industrial
51 √
Development Fund
Human Resources
53 √ √ √
Development Fund
54 Board of Grievances √
•A unified national
Digital Government
59 √ platform for
Authority (DGA)
government services
National Center of
61 √
Meteorology
Electronic
General Bureau for
62 Monitoring
Auditing
Platform (SHAMIL)
65 Taibah, University √
Jizan Region
67 √
Municipality
Madinah, Region
68 √
Municipality
Qassim Region
69 √
Municipality
Al Jouf Region
70 √
Municipality
Al Baha Region
71 √
Municipality
Jeddah, Governorate
72 √
Municipality
Taif Governorate
73 √
Municipality
Al-Ihsa Governorate
74 √
Municipality
Eastern Province
75 √
Municipality
Holy Capital
76 √
Municipality
Tourism Development
79 √
Fund – TDF