Qatar KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Qatar.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Portable implementation guide
Get the PDF checklist
11 control areas · 40 implementation checks
Last reviewed: 30 September 2026 · Version 1.0
Download the checklistDirect answer
What does the Qatar compliance checklist cover?
The Qatar checklist translates primary KYC, KYB and AML rules into 11 control areas and 40 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary framework
- Law No. 20 of 2019, as amended; Decision No. 41 of 2019
- FIU and reporting
- QFIU; ESTR for connected entities, approved manual route otherwise or for urgent cases
- STR timing
- Promptly once there are grounds to suspect; follow current QFIU and sector instructions
- CDD occasional-transaction threshold
- QAR 50,000 or more, including linked operations; lower wire-transfer rules may apply
- AML retention
- At least 10 years, with the statutory start event depending on record class
- Company BO declaration
- 20% ownership or voting control test, then effective/legal control, then legal representative fallback
- Privacy
- Law No. 13 of 2016 on Protecting Personal Data Privacy
- FATF public lists
- Not listed at 19 June 2026
Implementation detail
Qatar compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingClassify the entity, activity and geographic regime before assigning controls.3 items+
Determine whether each activity is a financial institution, DNFBP or other reporting entity.
- Implementation action
- Map services, customer flows and Qatar nexus to Law No. 20 of 2019, Decision No. 41 of 2019 and the sector rules for QCB, QFCRA, QFMA, MoCI or Ministry of Justice supervision.
- Evidence to retain
- Perimeter memo, service and funds-flow maps, legal analysis and authority confirmation.
- Primary citation
- Law No. 20 of 2019, article 1; Decision No. 41 of 2019; applicable supervisory rules
Obtain the required licence or registration before regulated activity.
- Implementation action
- Identify the competent authority and secure each activity-specific licence, registration or approval; record conditions and territorial limits.
- Evidence to retain
- Licence matrix, approvals, conditions register and renewal calendar.
- Primary citation
- Law No. 13 of 2012; applicable QCB, QFCRA, QFMA and MoCI frameworks
Separate onshore and Qatar Financial Centre requirements.
- Implementation action
- Apply the national law and the correct sector overlay; use QFCRA AML/CFT Rules for an authorised QFC firm and do not transpose QFC mechanics to an onshore entity.
- Evidence to retain
- Entity-location analysis, rule mapping and documented supervisory contacts.
- Primary citation
- QFCRA Anti-Money Laundering and Combating the Financing of Terrorism Rules 2019
02Governance and ML/TF risk assessmentGovernance must be risk-based, documented and demonstrably effective.4 items+
Maintain an enterprise ML/TF risk assessment.
- Implementation action
- Assess customers, countries, products, delivery channels, transactions, technology and emerging risks; update for material change and national or supervisory findings.
- Evidence to retain
- Methodology, current assessment, data sources, approvals and change log.
- Primary citation
- Law No. 20 of 2019, articles 8 and 15; Decision No. 41 of 2019
Maintain proportionate policies, systems and internal controls.
- Implementation action
- Document CDD, monitoring, reporting, recordkeeping, sanctions, employee screening, training, independent review and escalation controls.
- Evidence to retain
- Approved programme, control map, procedures, training and issue register.
- Primary citation
- Law No. 20 of 2019, article 18; applicable supervisory instructions
Appoint an empowered compliance officer and deputy where required.
- Implementation action
- Document independence, authority, access, competence, reporting lines and coverage; obtain or notify supervisory approval where the applicable sector rules require it.
- Evidence to retain
- Appointment, fit-and-proper file, authority matrix, minutes and regulatory correspondence.
- Primary citation
- Law No. 20 of 2019, article 18; applicable sector rules
Independently test the AML/CFT framework.
- Implementation action
- Use a suitably qualified, independent function to test design and operation at a frequency proportionate to risk and track remediation to closure.
- Evidence to retain
- Review plan, independence assessment, report, management response and closure testing.
- Primary citation
- Law No. 20 of 2019, article 18; applicable supervisory rules
03Natural-person identificationCDD covers the customer, beneficial owner and any person acting for the customer.4 items+
Apply CDD when a business relationship begins or a statutory trigger arises.
- Implementation action
- Identify and verify before establishment, or under a documented lawful timing exception, and apply CDD to occasional transactions of QAR 50,000 or more, linked operations, qualifying wire transfers, suspicion and doubts about prior data.
- Evidence to retain
- Trigger analysis, identity record, verification result, relationship purpose and completion timestamp.
- Primary citation
- Law No. 20 of 2019, articles 9-12; Decision No. 41 of 2019, preventive-measures provisions
Verify identity from reliable and independent sources.
- Implementation action
- Obtain official identity attributes and validate authenticity, expiry and person-to-document linkage using methods proportionate to impersonation and fraud risk.
- Evidence to retain
- Identity attributes, source provenance, validation results, fraud checks and exception rationale.
- Primary citation
- Law No. 20 of 2019, articles 9-11; QCB AML/CFT Instructions 2020
Identify representatives and verify authority.
- Implementation action
- Identify the person acting for the customer, verify identity and validate the legal mandate before accepting instructions.
- Evidence to retain
- Representative KYC, mandate, authority checks and instruction limits.
- Primary citation
- Law No. 20 of 2019, article 10; Decision No. 41 of 2019
Do not proceed when required CDD cannot be completed.
- Implementation action
- Decline or terminate the relationship or transaction as required and consider an STR without disclosing the assessment to the customer.
- Evidence to retain
- CDD failure record, restriction or exit decision, STR assessment and communications review.
- Primary citation
- Law No. 20 of 2019, articles 11, 16 and 21
04KYB, registries, and beneficial ownershipRegistry evidence supports, but does not replace, natural-person ownership and control analysis.4 items+
Verify the legal person or arrangement and its powers.
- Implementation action
- Collect current legal name, form, registration number, address, governing documents, directors, partners or trustees and validate them through reliable official sources.
- Evidence to retain
- UER or commercial-register evidence, constitutional documents, officer list and discrepancy resolution.
- Primary citation
- Law No. 20 of 2019, articles 9-11; Law No. 1 of 2020
Identify the AML beneficial owner through ultimate ownership and effective control.
- Implementation action
- Trace layered, nominee and legal-arrangement structures to the natural persons who ultimately own or control the customer or on whose behalf activity occurs; do not rely on a percentage alone.
- Evidence to retain
- Ownership chart, control analysis, declarations, source documents and verified identities.
- Primary citation
- Law No. 20 of 2019, article 1 and articles 9-11
Apply the company-register declaration cascade correctly.
- Implementation action
- For commercial-company UER purposes identify natural persons with at least 20% direct or indirect capital or voting control; if none, identify effective or legal controllers; if none, identify the legal representative.
- Evidence to retain
- BO register, calculation, control analysis, fallback rationale and filing receipt.
- Primary citation
- Law No. 1 of 2020; Decision No. 12 of 2020; MoCI Beneficial Owner Guide
Maintain and update mandatory company records.
- Implementation action
- Keep basic, beneficial-owner and partner or shareholder registers current; designate the required Qatar-resident information contact and file changes through the competent route.
- Evidence to retain
- Registers, supporting documents, designation, update log and submissions.
- Primary citation
- Law No. 1 of 2020; Decision No. 12 of 2020; MoCI business-services guidance
05PEPs, EDD, and remote onboardingEnhanced measures attach to high-risk and specified circumstances.3 items+
Identify politically exposed persons and related persons.
- Implementation action
- Screen customers and beneficial owners for domestic, foreign and international-organisation PEP status and applicable family or close-associate relationships; apply approval, source and monitoring measures required by risk and sector rules.
- Evidence to retain
- Screening, relationship map, senior approval, source corroboration and review history.
- Primary citation
- Law No. 20 of 2019, articles 15 and 17; Decision No. 41 of 2019
Apply enhanced due diligence to higher-risk relationships.
- Implementation action
- Obtain additional information on customer, ownership, purpose, source of wealth and source of funds; increase monitoring and obtain senior approval where required.
- Evidence to retain
- Risk trigger, additional CDD, source evidence, approval and monitoring plan.
- Primary citation
- Law No. 20 of 2019, articles 13 and 15; Decision No. 41 of 2019
Control non-face-to-face and technology risk.
- Implementation action
- Validate documents and liveness, prevent impersonation, test vendors, establish fallback review and apply enhanced measures where risk remains elevated.
- Evidence to retain
- Method assessment, vendor diligence, test results, exceptions and fraud cases.
- Primary citation
- Decision No. 41 of 2019; applicable supervisory instructions
06Monitoring and suspicious transaction reportingOngoing scrutiny and prompt escalation support reporting to QFIU.4 items+
Keep CDD current and monitor activity continuously.
- Implementation action
- Review customer and beneficial-owner information, examine transactions against purpose, profile, risk and expected source of funds, and document unusual-activity outcomes.
- Evidence to retain
- Monitoring scenarios, alerts, case decisions, refresh records and quality testing.
- Primary citation
- Law No. 20 of 2019, article 14
Escalate suspicion without waiting for proof.
- Implementation action
- Assess completed, attempted and proposed activity promptly; record the facts, grounds and time at which suspicion was formed.
- Evidence to retain
- Alert chronology, information reviewed, suspicion decision and decision-maker.
- Primary citation
- Law No. 20 of 2019, article 21; QFIU STR Guidance 2024
Report suspicious transactions promptly to QFIU.
- Implementation action
- Use ESTR when electronically connected; otherwise or for urgent cases use the current approved manual route and form. Follow current QFIU and sector timing instructions rather than inventing a fixed universal deadline.
- Evidence to retain
- Suspicion timestamp, STR, submission receipt, route rationale and corrections.
- Primary citation
- Law No. 20 of 2019, article 21; QFIU Reporting Entities page; QFIU STR Guidance 2024
Prevent tipping off and protect report information.
- Implementation action
- Restrict knowledge of STRs and related requests, control communications and disclose only where legally permitted.
- Evidence to retain
- Access controls, disclosure register, legal review, training and incident log.
- Primary citation
- Law No. 20 of 2019, article 22
07Payments, wires, thresholds, and virtual assetsThreshold and licensing rules depend on the product, sector and transaction type.5 items+
Apply the QAR 50,000 occasional-transaction CDD threshold in its proper context.
- Implementation action
- Aggregate linked operations and apply CDD at or above the threshold; apply CDD regardless of amount where suspicion or identity-data doubt exists.
- Evidence to retain
- Aggregation logic, transaction samples, conversion rules and CDD outcomes.
- Primary citation
- Decision No. 41 of 2019; Law No. 20 of 2019, articles 9-12
Apply sector-specific precious-metals cash restrictions.
- Implementation action
- For covered precious-metal, stone and jewellery transactions, implement the QAR 50,000 scope and cash prohibition under the applicable MoCI framework; do not generalise it to all sectors.
- Evidence to retain
- Product classification, payment controls, aggregation tests and refusal records.
- Primary citation
- Law No. 4 of 2022; MoCI Circular No. 7 of 2024
Carry and review required wire-transfer information.
- Implementation action
- Collect, validate, transmit and retain prescribed originator and beneficiary information and establish risk-based procedures for missing or incomplete fields.
- Evidence to retain
- Field matrix, message samples, validation rules, repair queue and dispositions.
- Primary citation
- Law No. 20 of 2019, article 12; Decision No. 41 of 2019; QCB AML/CFT Instructions 2020
Obtain payment-service approval before launch.
- Implementation action
- Classify wallets, payment aggregation, merchant acquiring, remittance and related services under the current QCB licensing framework and meet safeguarding, governance and technology conditions.
- Evidence to retain
- Product memo, QCB approval, conditions, safeguarding records and test results.
- Primary citation
- Law No. 13 of 2012; QCB Payment Services Regulation
Treat virtual-asset activity as a separately controlled perimeter.
- Implementation action
- Do not offer or facilitate virtual-asset services from or into Qatar without current written analysis of QCB and, where relevant, QFC restrictions or permissions and explicit regulatory confirmation.
- Evidence to retain
- Service and wallet-flow map, legal opinion, authority correspondence, geofencing and monitoring tests.
- Primary citation
- QCB supervisory instructions; QFCRA virtual-asset notices; FATF-MENAFATF Qatar MER 2023
08Targeted financial sanctionsTargeted financial sanctions apply independently of an STR decision.3 items+
Screen UN and national designations and ownership or control.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding and on list changes; test aliases and controlled entities, not exact names only.
- Evidence to retain
- List versions, update logs, configuration tests, match analysis and dispositions.
- Primary citation
- Law No. 27 of 2019; Decision No. 1 of 2020
Freeze designated assets immediately and without prior notice.
- Implementation action
- For UN or sanctions-committee designations, freeze immediately and without delay, no later than 24 hours, and follow the competent notification route; apply national designations immediately upon announcement.
- Evidence to retain
- Designation receipt, match analysis, freeze timestamp, report and authority correspondence.
- Primary citation
- Law No. 27 of 2019, article 39; Decision No. 1 of 2020
Do not make funds or related services available to designated persons.
- Implementation action
- Block direct and indirect provision, including through owned or controlled entities or persons acting on their behalf, unless prior competent authority permission applies.
- Evidence to retain
- Ownership analysis, blocked activity, licence or permission and conditions monitoring.
- Primary citation
- Law No. 27 of 2019, article 39
09Records and regulator accessTen years is the national baseline, but the clock depends on the record.3 items+
Retain transaction records for at least ten years.
- Implementation action
- Keep domestic and international transaction records sufficient to reconstruct activity for at least ten years from completion, subject to longer holds or authority directions.
- Evidence to retain
- Retention schedule, transaction sample, trigger calculation, legal hold and deletion log.
- Primary citation
- Law No. 20 of 2019, article 19
Retain CDD and relationship records for the statutory period.
- Implementation action
- Keep identity, verification, account, correspondence and analysis records for at least ten years after the relationship ends or occasional transaction completes, as applicable.
- Evidence to retain
- End date, archive sample, retrieval test and deletion approval.
- Primary citation
- Law No. 20 of 2019, article 19
Produce records promptly to competent authorities.
- Implementation action
- Maintain secure, retrievable and readable records and test authorised production while preserving confidentiality and chain of custody.
- Evidence to retain
- Access matrix, retrieval test, production log and chain-of-custody record.
- Primary citation
- Law No. 20 of 2019, articles 19, 32 and 41
10Privacy, biometrics, and transfersAML processing does not remove personal-data obligations.4 items+
Process personal data transparently for a lawful purpose.
- Implementation action
- Define the purpose and legal basis, provide required information to individuals, limit collection and use, maintain accuracy and implement data-subject request procedures.
- Evidence to retain
- Data inventory, purpose map, notices, request log and accuracy controls.
- Primary citation
- Law No. 13 of 2016, articles 3-15
Protect special-nature data and biometrics.
- Implementation action
- Identify special-nature data, obtain the competent permission where article 16 requires it, document necessity and proportionality, and apply heightened security, access and deletion controls.
- Evidence to retain
- Data classification, permission analysis, privacy assessment, access logs and deletion tests.
- Primary citation
- Law No. 13 of 2016, articles 16-17
Control processors, security and personal-data incidents.
- Implementation action
- Contract for instructions, confidentiality, security, incident escalation, return and deletion; maintain appropriate technical and organisational safeguards and evidence incident response.
- Evidence to retain
- Processor contract, risk review, security tests, incident chronology and remediation.
- Primary citation
- Law No. 13 of 2016, articles 8-15
Assess cross-border data flows before transfer or remote access.
- Implementation action
- Document the statutory transfer route, recipient safeguards and any restrictions or competent-authority requirements; preserve access for lawful AML supervision.
- Evidence to retain
- Transfer map, legal assessment, contract, recipient diligence and monitoring.
- Primary citation
- Law No. 13 of 2016, including cross-border data-flow provisions
11Practical evidence packsEvidence should reconstruct onboarding, reporting and launch decisions end to end.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, authority, KYB, beneficial ownership, PEP, sanctions, purpose, risk, privacy, approvals and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack and retrieval result.
- Primary citation
- Operational control supporting Law No. 20 of 2019, articles 8-19
Maintain a reconstructable QFIU and sanctions case pack.
- Implementation action
- Link activity, alert, suspicion chronology, STR, receipt, confidentiality, asset restrictions and authority communications.
- Evidence to retain
- Complete sampled case pack, timeline and controlled-access record.
- Primary citation
- Operational control supporting Law No. 20 of 2019, articles 19-22 and Law No. 27 of 2019
Maintain a launch and change pack.
- Implementation action
- Record perimeter, licences, programme approval, reporting connectivity, sanctions, privacy, vendors, testing and controlled uncertainties before launch or material change.
- Evidence to retain
- Signed launch pack, source register, tests, approvals and uncertainty log.
- Primary citation
- Official sources listed below
Primary-source register
18 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law No. 20 of 2019 on Combating Money Laundering and Terrorism FinancingQatar Financial Information Unit · Primary legislation
- AML/CFT legislation and amendments libraryQatar Financial Information Unit · Official legislation library
- Council of Ministers Decision No. 41 of 2019Al Meezan Legal Portal · Primary delegated legislation
- AML/CFT Instructions for Financial Institutions 2020Qatar Central Bank · Official supervisor instructions
- Instructions to BanksQatar Central Bank · Official supervisor library
- QFIU reporting entities and filing routesQatar Financial Information Unit · Official FIU guidance
- Instructions on Suspicious Transaction Reporting Requirements, April 2024Qatar Financial Information Unit · Official FIU guidance
- QFIU role and functionsQatar Financial Information Unit · Official FIU information
- QFCRA AML/CFT Rules 2019Qatar Financial Centre Regulatory Authority · Official sector rules
- Local investor laws and Unified Economic Register materialsMinistry of Commerce and Industry · Official legislation library
- Business services, AML/CFT and beneficial ownershipMinistry of Commerce and Industry · Official registry and supervisor guidance
- Law No. 27 of 2019 on Combating TerrorismAl Meezan Legal Portal · Primary legislation
- Decision No. 1 of 2020 on targeted financial sanctionsQatar Financial Information Unit · Primary implementing decision
- Law No. 13 of 2016 on Protecting Personal Data PrivacyAl Meezan Legal Portal · Primary legislation
- Financial Crimes Enforcement ManagementQatar Central Bank · Official supervisor information
- FATF-MENAFATF Mutual Evaluation of Qatar 2023FATF · Authoritative assessment
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
Direct answers
Qatar KYC, KYB and AML questions
Who receives suspicious transaction reports?+
QFIU is the national FIU. Connected reporting entities use ESTR; entities not yet connected, and urgent cases, use QFIU's current approved manual route and form.
When must an STR be filed?+
A reporting entity must report promptly once grounds for suspicion arise. The checklist does not invent one fixed universal number of days; follow Law No. 20 of 2019, current QFIU guidance and the applicable sector instructions.
Is there an occasional-transaction CDD threshold?+
Yes. The national framework uses QAR 50,000 or more for covered occasional transactions, including linked operations. Wire transfers, suspicion and doubts about prior identification can trigger CDD independently and at lower amounts.
How is beneficial ownership determined?+
AML CDD requires the natural persons who ultimately own or effectively control the customer or on whose behalf activity occurs. For the company registry, the declaration cascade starts at 20% capital or voting control, then effective or legal control, then the legal representative fallback.
How long are AML/CFT records kept?+
The national baseline is at least ten years. The clock depends on the record, including transaction completion or the end of the business relationship.
How quickly must designated assets be frozen?+
Law No. 27 of 2019 requires immediate freezing without prior notice for relevant designations and states a maximum of 24 hours for UN or sanctions-committee listings. Operational controls should act as soon as a true match is established, not wait for the outer limit.
Can a payment or wallet service launch without QCB review?+
Do not assume so. Map the actual payment, wallet, acquiring or remittance service to the current QCB licensing framework and obtain the required approval before launch.
Are virtual-asset services freely permitted?+
No general permission should be inferred. Obtain current written analysis of QCB and any QFC restrictions or permissions and explicit regulatory confirmation for the actual service and customer flow.
What privacy law applies to digital identity data?+
Law No. 13 of 2016 applies to personal-data processing. Special-nature data, including biometric and health-related categories, requires heightened assessment and may require competent permission.
Is Qatar on a FATF public list?+
No. Qatar was absent from the FATF increased-monitoring and call-for-action lists dated 19 June 2026. That does not make every Qatar relationship low risk.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 30 September 2026. Confirm the regulated perimeter, current supervisory instructions, filing channel, sanctions designation, privacy position and any Qatar Financial Centre overlay with the competent authority and qualified Qatar counsel before launch.