Qatar - AI Guidelines for Banks

Qatar Central Bank Artificial Intelligence Guideline for QCB‑licensed Entities

Qatar

RAI-QA-NA-QCBAIXX-2024
Effective: 4 Sep 2024
In Force(In Force)As published at qcb.gov.qa

Qatar - AI Guidelines for Banks is In Force in Qatar, according to qcb.gov.qa. We have not yet been able to confirm the status.

GuidelineGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

The Qatar Central Bank (QCB) issued the 'Artificial Intelligence Guideline' on 4 September 2024 to regulate AI use by QCB‑licensed entities. The Guideline requires entities to implement governance, risk management, human oversight, registers, approval for high‑risk systems, data governance, security controls, customer transparency and recourse mechanisms, and to disclose AI activity to QCB.

Summary

On 4 September 2024, the Qatar Central Bank (QCB) published the 'Artificial Intelligence Guideline' to regulate the development, procurement, outsourcing and operation of AI systems by QCB‑licensed entities. The Guideline takes a risk‑based approach and identifies specific obligations for governance, board and senior management accountability, an AI governance policy, enterprise risk management integration, and the creation and maintenance of an AI Register. Entities must classify AI systems (including a 'High‑Risk' designation), maintain lifecycle documentation, and obtain QCB approval prior to launching new AI systems and before signing any purchase, licensing or outsourcing agreements for High‑Risk AI. Human oversight protocols are mandatory for all AI systems; high‑risk and fully autonomous systems face the strictest requirements, including prior approval, guardrails and the ability for trained supervisors to intervene or shut down systems.

The Guideline requires rigorous data governance: separate training/validation/testing datasets, checks for bias, data quality controls, and use of privacy‑preserving techniques where feasible in accordance with Qatar Personal Data Privacy Protection Law (Law No. 13 of 2016). Outsourcing rules require due diligence, Board approval, contractual clauses for audit rights and exit arrangements, and contingency planning. Security measures include TRiSM (AI Trust, Risk & Security Management) programs, DLP tools, anomaly detection, protections against model‑integrity and prompt‑injection attacks, and compliance with sector‑specific security regulations.

Operational requirements include approvals for training and testing results (especially for High‑Risk systems), documentation of model design and assumptions, monitoring systems and audit logs, versioning and archiving of datasets, and annual disclosure of the full AI Register to QCB. For customer‑facing AI, the Guideline mandates customer notification, plain‑language disclosure of AI use, consent (for non‑high‑risk at minimum), information on how decisions are made and whether they are reversible, visible feedback channels, recourse and review mechanisms, and consideration of opt‑out options depending on risk and feasibility.

Enforcement is through QCB supervisory powers; non‑compliance may trigger remedial directions, requests for revocation or modification, audits, and disciplinary/enforcement measures per QCB instructions and penalties framework. Entities can request exemptions from QCB but must provide documented business cases and record approved waivers. The Guideline references compliance with secondary regulations such as the Personal Data Privacy Protection Law, QCB Sector‑Specific Security Regulation, the Cloud Computing Regulation (2024), and existing QCB technology risk circulars. The document is aimed at aligning domestic financial sector AI oversight with international best practice while preserving financial stability, customer protection and data privacy.

Full article

Read full text ↗

Overview

The QCB Artificial Intelligence Guideline (issued 4 September 2024) sets mandatory expectations for QCB‑licensed entities that develop, procure, outsource, operate or provide AI systems. It adopts a risk‑based lifecycle approach requiring corporate governance, board and senior management accountability, dedicated AI governance functions, an AI Register and prior QCB approval for material changes and High‑Risk AI. The Guideline also prescribes human oversight protocols, data governance and TRiSM security programs, disclosure and customer recourse mechanisms, outsourcing controls, documentation and monitoring, and alignment with Qatar's data protection law. The primary text is published by QCB: Artificial Intelligence Guideline (QCB) and appears as Annex 160 to QCB Instructions to Banks 2024: QCB Instructions to Banks 2024 (Annex index). The Guideline aims to foster responsible innovation while protecting customers, financial stability and data privacy.

Definitions

The Guideline defines key terms used throughout, such as 'AI Model', 'AI System', 'High‑Risk AI', 'Human Oversight', 'Material AI Portfolio', 'Provider', 'User', 'Register', 'Training/Validation/Testing Data' and 'AI TRiSM'. 'High‑Risk AI' covers systems with potential to cause significant negative impact on operations, the financial system or individuals (e.g., affecting access to financial services, employee decisions, or processing sensitive personal information). Human Oversight protocols are classified into AI‑assisted decision‑making, human exception oversight and fully autonomous AI, with escalating controls for systems with less human control.

Governance and Institutional Framework

The Guideline places accountability with the Board of Directors (BOD) and senior management. Boards must approve AI risk appetite and exposures, assess governance structures, assign clear lines of accountability, and ensure resourcing. Senior management must include members knowledgeable in technology/AI risk and be responsible for assessment, monitoring and allocation of responsibilities across AI lifecycle activities. Entities are required to establish (or designate) a function to oversee AI, create committees for assessing AI use cases, and adopt an AI Governance Policy covering audits, documentation, role allocation, training, and controls. QCB oversight powers allow it to review policies and require sandbox evaluation. See the QCB original Guideline for the corporate governance clauses: QCB AI Guideline (Annex 160).

Key Focus Areas

The Guideline’s substantive obligations fall into several focus areas: 1) Risk management: risk assessments, criticality analysis, identification of 'High‑Risk' systems and integration into enterprise risk frameworks; 2) Register & approvals: maintaining a full AI Register and annual disclosure to QCB, and prior QCB approval for new or materially modified AI systems and for purchase/licensing/outsourcing of High‑Risk AI; 3) Human oversight: mandatory oversight protocols, supervisor training and tools, stop/kill switch requirements for fully autonomous systems, and defined human exception monitoring processes; 4) AI lifecycle and data governance: separate training/validation/testing datasets, quality checks, bias testing, independent validation where appropriate, archiving of original datasets and version control; 5) Outsourcing: due diligence, Board approval, contractual audit and exit clauses, confidentiality and continuity protections; 6) Security/TRiSM: model security, DLP, anomaly detection, defenses against prompt injection and query attacks, and alignment with sector security rules; 7) Transparency & customer protection: notification, plain language disclosures, instructions for use, ability to request review and corrective action, and opt‑out considerations; 8) Monitoring and documentation: ongoing monitoring systems, audit logs, versioning and robust documentation of design choices, metrics and validation results.

Implementation Framework

Entities must implement the Guideline proportionate to size, complexity and materiality of AI use. Required elements include a documented framework for High‑Risk AI (written policies, procedures and instructions covering design, verification, testing, development quality assurance and post‑launch reviews), a TRiSM program for security and trust, an AI Register capturing classification, provider details, human oversight protocol, contract dates and third‑party assessments, and Board‑approved outsourcing decisions. Entities acting as Providers must be able to supply QCB the full lifecycle and technical data for user entities. For High‑Risk systems, entities must submit training, validation and testing outcomes for QCB review and may be directed into a sandbox for further evaluation prior to approval.

Monitoring and Evaluation

Entities must maintain auditable records of AI system performance, establish monitoring systems that collect operational experience and outcomes (including provider reports), perform periodic risk assessments and reviews, and document the date of most recent audits and next planned audits. Monitoring must include automated and human controls to detect drift, bias and technical anomalies; entities must report serious incidents to QCB when a causal link (or reasonable likelihood) is established. Regular performance metrics, model‑version logs, and archived datasets must be retained to allow retrospective review.

Penalties, Liability, and Appeals

The Guideline itself references QCB’s supervisory and enforcement toolkit; non‑compliance may trigger QCB directions, audits, mandatory remediation, fines or other administrative measures under the QCB Law and Instructions. Entities remain principal for acts or omissions of outsourcing providers. Exemptions may be requested from QCB with documented business justification and an expiration date; QCB approval is required for exemptions. For customer disputes, the Guideline requires internal review mechanisms, two‑choice processes for customers affected by AI decisions (resubmit data or request human review), and standard complaint handling. Specific monetary penalties are governed by QCB sanctions frameworks and other applicable laws (including personal data protection penalties under Law No. 13 of 2016).

Relationship to Other Instruments

The Guideline sits within QCB’s Instructions to Banks and connects to multiple secondary instruments. It explicitly requires compliance with: QCB Sector‑Specific Security Regulation; Law No. 13 of 2016 on Personal Data Privacy Protection; QCB Technology Risks Circulars (e.g., January 2018); QCB Cloud Computing Regulation 2024 (where cloud AI is used); and other QCB regulations/guidelines. Entities must align AI policies with national data protection obligations and applicable sector rules. The Guideline supplements—not replaces—existing legal obligations such as the QCB Law, data protection law, cloud and cybersecurity regulations, and contractual/regulatory outsourcing rules.

International Alignment

The Guideline reflects international best practice and aligns conceptually with risk‑based AI frameworks (e.g., EU AI Act approach to high‑risk systems, UK & Hong Kong financial sector AI guidance, and NIST risk management principles). It emphasizes lifecycle governance, human oversight, bias mitigation, documentation and monitoring which are common features in leading international AI regulatory instruments. QCB’s approach to registers, pre‑approval for high‑risk deployments and sandboxing parallels measures seen in other prudential and financial sector regulator guidance globally. QCB also cross‑references privacy law obligations consistent with international data protection norms.

Implementation Timeline

EventDate
Publication / Issuance by QCB2024-09-04
Effective date (entry into force)2024-09-04
Annual AI Register disclosure (recurring)Annually (upon QCB request)

Sources and References

SourceType
Artificial Intelligence Guideline (QCB Annex 160)Primary Source
QCB Instructions to Banks 2024 (Annex index)Primary Source
Qatar Press Agency - QCB issues AI GuidelinePrimary/Official Press

Requirements for a company

What an organisation has to do under Qatar - AI Guidelines for Banks, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

12
  • Obtain prior QCB approval for new or materially modified High-Risk AI systems.QCB-licensed entities deploying High-Risk AI systems.
  • Report serious AI incidents to QCB when a causal link or reasonable likelihood is established.QCB-licensed entities operating AI systems.
  • Obtain Board approval for AI outsourcing decisions, including contractual audit and exit clauses.QCB-licensed entities outsourcing AI systems.
  • Ensure full compliance with Qatar's Law No. 13 of 2016 on Personal Data Privacy Protection.QCB-licensed entities processing personal data with AI.
  • Establish an AI Governance Policy covering audits, documentation, roles, training, and controls.QCB-licensed entities using AI systems.
  • Maintain a comprehensive AI Register and disclose it annually to QCB upon request.QCB-licensed entities using AI systems.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Qatar - AI Guidelines for Banks, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1QCB-licensed entities deploying High-Risk AI systems.Obtain prior QCB approval for new or materially modified High-Risk AI systems.
“prior QCB approval for new or materially modified AI systems and for purchase/licensing/outsourcing of High‑Risk AI”
Before placing on marketKey Focus AreasCritical
2QCB-licensed entities operating AI systems.Report serious AI incidents to QCB when a causal link or reasonable likelihood is established.
“entities must report serious incidents to QCB when a causal link (or reasonable likelihood) is established.”
—Monitoring and EvaluationCritical
3QCB-licensed entities outsourcing AI systems.Obtain Board approval for AI outsourcing decisions, including contractual audit and exit clauses.
“Board approval, contractual audit and exit clauses, confidentiality and continuity protections”
Before outsourcingKey Focus AreasCritical
4QCB-licensed entities processing personal data with AI.Ensure full compliance with Qatar's Law No. 13 of 2016 on Personal Data Privacy Protection.
“Law No. 13 of 2016 on Personal Data Privacy Protection”
—Relationship to Other InstrumentsCritical
5QCB-licensed entities using AI systems.Establish an AI Governance Policy covering audits, documentation, roles, training, and controls.
“adopt an AI Governance Policy covering audits, documentation, role allocation, training, and controls.”
—Governance and Institutional FrameworkCritical
6QCB-licensed entities using AI systems.Maintain a comprehensive AI Register and disclose it annually to QCB upon request.
“maintaining a full AI Register and annual disclosure to QCB”
Annually (upon QCB request)Key Focus AreasCritical
7QCB-licensed entities operating AI systems.Implement mandatory human oversight protocols, including training, tools, and stop/kill switches for autonomous systems.
“mandatory oversight protocols, supervisor training and tools, stop/kill switch requirements for fully autonomous systems”
—Key Focus AreasCritical
8QCB-licensed entities using AI systems.Conduct AI risk assessments, criticality analysis, and integrate identified risks into enterprise frameworks.
“risk assessments, criticality analysis, identification of 'High‑Risk' systems and integration into enterprise risk frameworks”
—Key Focus AreasCritical
9QCB-licensed entities using AI systems.Implement a TRiSM security program covering model security, data loss prevention, and anomaly detection.
“a TRiSM program for security and trust”
—Key Focus AreasCritical
10QCB-licensed entities developing or operating AI systems.Implement data governance for AI lifecycle, including separate datasets, quality checks, bias testing, and archiving.
“separate training/validation/testing datasets, quality checks, bias testing, independent validation where appropriate”
—Key Focus AreasImportant
11QCB-licensed entities whose AI systems interact with customers.Provide customers with plain language disclosures, instructions for use, and mechanisms for review and corrective action.
“notification, plain language disclosures, instructions for use, ability to request review and corrective action”
—Key Focus AreasImportant
12QCB-licensed entities operating AI systems.Maintain auditable records of AI system performance and establish monitoring systems for operational experience and outcomes.
“Entities must maintain auditable records of AI system performance, establish monitoring systems that collect operational experience”
—Monitoring and EvaluationImportant

© Regulations.AI · updated on 20 Sep 2026