AI governanceQatarSheet 15

AI governance in Qatar.

Qatar has done something most of the region has not: it told its financial institutions, in writing, what governed AI has to look like. The work now is proving you do it.

§ 01The picture

What actually applies in Qatar.

In September 2024 the Qatar Central Bank issued an AI Guideline for QCB Licensed Entities, aligned to the Third Financial Sector Strategy and the FinTech Strategy. It is the most concrete AI instrument in the GCC financial sector, and it is unusually specific about what it expects.

A licensed entity is required to hold a defined AI strategy, to conduct risk assessment, and to disclose prescribed information about its AI systems. The Guideline sets out lifecycle management, requires each system to be classified as High-Risk or Standard, and requires human oversight protocols appropriate to that classification.

Read carefully, that is not an ethics statement. It is a governance architecture with a classification scheme at its centre, and classification schemes are load-bearing: every downstream control, every oversight protocol and every disclosure hangs off whether a system was tiered correctly in the first place. An institution that classifies casually will find the error propagated through every control it built on top.

Alongside it sits the Personal Data Privacy Protection Law (Law No. 13 of 2016) for AI that processes personal data, and the National AI Strategy, launched in 2019 and aligned to Qatar National Vision 2030.

§ 02Standing

Why this practice fits the QCB Guideline.

The QCB Guideline asks for four things that this practice already specifies in published work: an AI strategy, a risk assessment, a risk classification, and human oversight proportionate to the tier.

The MESA Framework answers the first two structurally. Strategy is Layer 2, the Strategic Compass, owned at board level and expressed as an explicit AI risk appetite. Assessment runs across all four layers with maturity scored per layer, so a report can tell a QCB-licensed entity which layer is failing rather than issuing a single grade nobody can act on.

Classification and oversight are Layer 3. The published Playbook specifies a model risk discipline built on six pillars with a ten-dimension risk classification, and the Five-Gate Deployment Model, which is a gating mechanism where a classification determines what a system must clear before it ships and who is authorised to stop it. A High-Risk versus Standard split maps onto that directly; what most institutions lack is not the two labels but the evidence trail proving a label was applied deliberately and reviewed since.

The book maps QCB alongside SAMA, CBUAE, SDAIA, DIFC, ADGM and AAOIFI, with Sharia governance treated as part of the regulatory floor rather than an overlay.

§ 03The work

What a Qatari engagement looks like.

1

Fit Call, 30 minutes, free

Scope, timing and whether this is the right instrument at all. If it is not, you will be told so on the call.

2

The Teardown, two weeks

Fifty questions across the four MESA layers, up to eight stakeholder interviews, every finding traced to evidence. Readout on day ten. No production data leaves your environment.

3

Board-ready output

A gap report scored per layer, a Now, Next and Later roadmap with owners and effort bands, and a one-page board summary.

4

Retainer, optional

Monthly advisory while you execute the roadmap, with an annual re-score against the original baseline.

Fees are fixed and shared on the Fit Call once scope is clear. Engagements run in English, remotely by default, and on site where an engagement requires it.

§ 04Questions

What Qatari institutions ask.

Does the QCB AI Guideline apply to us?

It applies to QCB Licensed Entities. The Qatar Central Bank issued it in September 2024, aligned to the Third Financial Sector Strategy and the FinTech Strategy. If you are licensed by the QCB and you operate AI systems, you are expected to hold a defined AI strategy, to conduct risk assessment, to classify each system as High-Risk or Standard with lifecycle management around it, to apply human oversight appropriate to that classification, and to disclose prescribed information about your systems. Confirm the detail of your obligations with counsel; what an assessment gives you is the gap list and the order to fix it in.

How do we classify a system as High-Risk or Standard defensibly?

By making the classification a documented decision rather than a label. A defensible classification records the dimensions assessed, the evidence behind each, who decided, when, and what would trigger a reclassification. The Playbook specifies a ten-dimension risk classification feeding a six-pillar model risk discipline, and the Five-Gate Deployment Model so the tier determines what the system must clear before release. The failure mode is not choosing the wrong tier once. It is choosing a tier and never revisiting it while the system changes underneath the label.

What does human oversight actually require in practice?

More than a named reviewer. Oversight is real when the reviewer has the information required to disagree, the authority to stop the system, and a record showing both were exercised. That means the decision surfaced to a human is explainable at the point of review, the intervention is logged, and the reviewer is not structurally incentivised to approve. An oversight protocol that produces one hundred percent approval rates is not oversight; it is a signature step, and it will read as one under examination.

How does this relate to the PDPPL?

AI systems processing personal data in Qatar sit under the Personal Data Privacy Protection Law, Law No. 13 of 2016, in addition to the QCB Guideline where the entity is licensed. In practice the two meet at the same place: the ability to explain an automated decision affecting an individual, and to produce the record behind it. Governance built only for the sectoral guideline tends to leave the data-subject-facing obligations underserved, which is a gap an assessment surfaces early.

Do you have an office in Qatar?

No. Dr. Nabeel A. Khan is an independent consultant based in Winnipeg, Canada, with active advisory engagements across the GCC and fifteen years of MENA practice. Qatari clients are served remotely and on site as an engagement requires. The regional depth is documented rather than asserted: the published Enterprise Playbook maps QCB alongside the other GCC supervisory regimes and carries a foreword from the Kuwait Institute for Scientific Research.

§ 05Start

Find out where you actually stand.

The framework is published and the method is documented in full. What an engagement adds is the examination: which of your four layers is failing, with the evidence attached.

Fin · Qatar
Book the 30-minute Fit Call →