
SAIS approval for a regulated project begins with the Business Criteria Analysis (BCA).
It does not begin with selecting security systems, preparing drawings, or deciding where cameras, gates, barriers, or control rooms should be placed. Those decisions must follow the regulatory basis of the project, not precede it.
The purpose of the BCA is to determine the facility category.
For industrial facilities subject to SAIS oversight, categorization is made across five categories. For military manufacturing facilities under the supervision of the General Authority for Military Industries (GAMI), where SAIS security and safety requirements apply, categorization is made across four categories.
This categorization is the starting point of the approval path.
The approved category defines the applicable security and safety requirements for the project. It determines the level of protection expected, the regulatory depth of the security design, and the basis upon which the project’s physical security and safety measures must be developed.
For this reason, facility categorization is not a supporting exercise.
It is the decision that gives the project its regulatory direction.
A SAIS-regulated project cannot properly commence before the facility category is approved, because the project cannot yet know the requirements it must be designed to meet. Without the approved category, the owner, designer, contractor, and security consultant would be working without the regulatory foundation that should guide the project.
The category affects the project in practical terms.
It influences the security concept, perimeter approach, access control philosophy, security zoning, surveillance strategy, safety interfaces, documentation requirements, and operational readiness expectations. It also helps define the level of coordination required between the project team and the applicable regulatory process.
This is why the BCA must come before the project moves forward.
The issue is not only whether the facility will eventually have security and safety systems. The issue is whether those systems are based on the correct approved category from the beginning.
When categorization is addressed early, the project proceeds on a clear regulatory basis. The owner understands the applicable requirements. The designer works from the correct assumptions. The contractor receives a clearer scope. The project team avoids treating SAIS compliance as a late correction to decisions that should have been guided by the approved category from the start.
This is the practical meaning of early SAIS compliance.
It begins with knowing what the facility is, how SAIS categorizes it, and what security and safety requirements follow from that categorization.
At Saudi Ansary Security Consultancy LLC (SASECON), we approach SAIS-regulated projects from this starting point. Our work begins with understanding the facility, preparing the Business Criteria Analysis (BCA), supporting the categorization process, and aligning the applicable security and safety requirements with the project’s design and approval path.
This is where successful SAIS compliance begins: with the right classification, the right regulatory basis, and a project team that understands how those requirements should shape the project before commencement.
In Part 4 of this series, we will examine how the SAIS project stages structure the path from facility categorization to design approval and operational readiness.
