
A Risk-Based Regulatory Mandate
SAIS jurisdiction is a regulatory matter rooted in national risk.
The Supreme Authority for Industrial Security (SAIS), formerly known as HCIS, is not a general approval layer for every facility that includes a fence, a guard house, a CCTV system, a warehouse, or an industrial-looking process. Its mandate applies to facilities whose security, safety, fire protection, and operational continuity may have consequences beyond the facility itself.
This distinction is essential to understanding why some projects fall under SAIS oversight while others remain outside its regulatory jurisdiction.
SAIS does not regulate projects merely because they are large, expensive, technically complex, or privately important to their owners. Its concern is connected to the strategic role of the facility, the sector in which it operates, the nature of its activities, the materials it handles, the dependencies it supports, and the consequences that may result from disruption, misuse, inadequate protection, or operational failure.
Strategic Sectors, Not Ordinary Business Categories
The official sectoral foundation of SAIS oversight reflects this logic.
SAIS supervision covers strategic sectors such as petroleum, electricity, petrochemicals, water, industrial services, communications, mining, gas, civil explosives, chemical manufacturing, metal manufacturing, and ports. These sectors are not ordinary business categories. They represent systems that support national security, economic continuity, essential services, industrial production, public safety, environmental protection, and the stability of critical operations.
Function and Consequence, Not Appearance
For this reason, SAIS jurisdiction should not be understood as a question of building type alone.
Two projects may look similar on drawings but have very different regulatory significance. A warehouse used for ordinary commercial distribution is not the same as a warehouse storing regulated chemicals, explosives, sensitive industrial materials, or critical spare parts serving a strategic facility. An electrical room inside a normal commercial building is not the same as an electrical facility supporting a major industrial, energy, water, or port operation.
SAIS does not regulate appearance. It regulates consequence.
Ownership alone does not determine whether a project falls under SAIS. A privately owned facility may be subject to SAIS if its function, sector, stored materials, operational role, or connection to critical infrastructure brings it within the regulated framework. Conversely, a large and valuable project may remain outside SAIS jurisdiction if it does not fall within the relevant strategic sectors or does not carry consequences that justify SAIS oversight.
Being outside SAIS jurisdiction does not mean that a project is outside regulation.
Such projects may still be subject to other authorities, codes, permits, civil defense requirements, client standards, insurance conditions, security expectations, or sector-specific obligations. The difference is that SAIS-regulated projects are brought into a national industrial security framework where security, safety, fire protection, compliance, inspection, operational readiness, and coordination with government entities are treated as part of a unified governance system.
Why Jurisdiction Matters in Project Planning
The practical impact of jurisdiction is significant.
When a project is subject to SAIS oversight, security cannot be treated as a late-stage add-on. It affects early planning, site layout, access philosophy, zoning, perimeter strategy, interface with operations, security systems, control room assumptions, emergency coordination, documentation, and readiness for inspection and certification. The project is expected to demonstrate not only that security elements exist, but that they are aligned with the regulatory logic of protecting a strategic facility.
Misunderstanding jurisdiction creates two opposite risks.
The first risk is underestimating SAIS involvement. This happens when a project team assumes that SAIS is irrelevant because the project is privately owned, described as a warehouse, classified internally as a support facility, or not yet operational. If the facility is later confirmed to be within SAIS scope, the project may face redesign, late documentation, approval delays, fragmented responsibilities, and avoidable compliance pressure.
The second risk is overestimating SAIS involvement. This happens when every industrial or semi-industrial project is treated as if it must follow the full SAIS pathway without first understanding its sector, function, and regulatory status. This can create unnecessary cost, excessive documentation, and confusion between good security practice and formal SAIS compliance.
Early Clarity Before Design Decisions
The correct approach is to clarify the regulatory position early.
SAIS jurisdiction is not a label added at the end of a project. It is a project governance consideration that should be understood before security design, engineering assumptions, procurement strategies, and approval schedules become fixed. Early clarity allows the owner, consultant, designer, contractor, and operator to determine whether the project requires formal SAIS alignment, general security advisory support, or a different regulatory pathway.
Beyond the Facility Boundary
This is the deeper meaning of SAIS jurisdiction.
SAIS becomes relevant when a facility forms part of a strategic sector or carries consequences that connect its protection to national security, economic continuity, public safety, environmental protection, or the uninterrupted operation of critical services.
It should not be seen as an external approval obstacle. It should be understood as a national governance framework applied to facilities whose protection matters beyond their physical boundary.
At Saudi Ansary Security Consultancy LLC (SASECON), we maintain a valid SAIS Security Consulting Qualification and support owners, developers, designers, and contractors in understanding the regulatory position of industrial and critical infrastructure projects. Our role is to help project teams distinguish between general security requirements and formal SAIS / HCIS compliance obligations, and to align project planning with the level of governance expected for regulated facilities.
In Part 3 of this series, we will examine why SAIS compliance must begin early in the project lifecycle, before security becomes difficult, expensive, or disruptive to integrate.
