Money laundering is now a top priority for regulators in Qatar. As the country grows its financial sector and expands the Qatar Financial Centre (QFC), regulators are enforcing Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT) rules more strictly. The penalties for getting it wrong have grown too.
If your business is regulated by the Qatar Central Bank (QCB) or licensed within the QFC, AML compliance is not optional paperwork. It is a legal duty backed by inspections, reporting requirements, and real financial and licensing consequences. This guide explains who needs to comply, what the law requires, and how businesses in Qatar can build a compliance programme that holds up under review.
The Legal Framework Behind AML in Qatar
Qatar’s AML/CFT rules come from Law No. (20) of 2019 on Combating Money Laundering and Terrorism Financing. This law was later amended by Decree Law No. 19 of 2021 and updated further through 2025. It aligns Qatar with the standards set by the Financial Action Task Force (FATF), the global body that sets AML/CFT benchmarks.
Unlike countries with a single AML regulator, Qatar splits oversight across several authorities depending on the sector:
- Qatar Central Bank (QCB). The main regulator for banks, exchange houses, insurers, and other licensed financial institutions operating outside the QFC. QCB issues binding AML/CFT instructions and runs regular on-site and off-site inspections.
- Qatar Financial Centre Regulatory Authority (QFCRA). The independent regulator for firms authorised to operate in or from the QFC. It applies its own Anti-Money Laundering Rulebook, aligned with international standards.
- Ministry of Commerce and Industry (MOCI). Supervises Designated Non-Financial Businesses and Professions (DNFBPs) outside the QFC. This includes auditors, accountants, real estate agents, and dealers in precious metals.
- National Anti-Money Laundering and Terrorism Financing Committee (NAMLC). Coordinates Qatar’s national AML/CFT strategy across all authorities.
- Qatar Financial Information Unit (QFIU). Qatar’s financial intelligence unit. It receives and reviews Suspicious Transaction Reports (STRs) from banks, financial institutions, and DNFBPs, and shares findings with law enforcement.
Who Actually Needs to Comply?
AML/CFT rules cover more than just banks. Businesses in Qatar that typically need to comply include:
- Banks, exchange houses, and credit institutions
- Insurance companies and intermediaries
- Investment and asset management firms
- Money service businesses
- Real estate agents and developers
- Dealers in precious metals and stones
- Auditors, accountants, and legal professionals
- Trust and company service providers (TCSPs)
- Non-profit organisations that handle donations or grants
If your business is licensed by the QFC or regulated by QCB, you are almost certainly covered by these rules. MOCI is also expanding these requirements to accountants and auditors operating outside the QFC, which is directly relevant to firms offering audit and assurance services in Qatar.
Core Compliance Obligations
Whether your business is regulated by QCB or QFCRA, the basic building blocks of an AML/CFT programme are similar.
1. Risk Based Assessment
Businesses must carry out and document a formal AML/CFT risk assessment. This means looking at your risk by customer type, product, location, and how services are delivered. It should be a real evaluation of your business, not a generic checklist.
2. Customer Due Diligence (CDD) and KYC
Businesses must verify a customer’s identity before starting a business relationship. This includes identifying ultimate beneficial owners (UBOs), generally anyone who holds 10% or more of shares or voting rights. Higher risk customers need Enhanced Due Diligence (EDD).
3. Sanctions and PEP Screening
Firms must screen customers and transactions against international sanctions lists, and check for Politically Exposed Persons (PEPs), who need extra scrutiny.
4. Transaction Monitoring
Ongoing monitoring is needed to catch unusual patterns or activity that does not match a customer’s known profile.
5. Suspicious Transaction Reporting (STR)
Any suspicious activity must be reported to the QFIU without delay. Telling a customer that a report has been filed about them is a separate legal offence.
6. Governance and Training
Regulated entities must appoint a compliance officer, often called a Money Laundering Reporting Officer (MLRO), keep internal AML/CFT policies, and give staff regular training in line with FATF standards.
7. Record Retention
Customer identification, transaction, and CDD records must generally be kept for at least five years.
Penalties for Non-Compliance
Both QCB and QFCRA actively enforce these rules. This includes financial penalties, licence restrictions, and public settlement notices for firms with weak AML/CFT controls. For QFC-licensed entities, a weak AML programme can also delay or block new licence approvals, since QFCRA checks governance and control frameworks as part of the approval process.
Building a Practical AML Programme
For most SMEs and mid-sized firms in Qatar, the biggest gap is not deliberate non-compliance. It is usually an outdated or generic policy that does not match the business’s actual risk, or a CDD process that is not followed consistently in practice. A practical AML programme should:
- Be reviewed and updated every year, or whenever the business’s risk changes
- Have clear ownership under a named compliance officer
- Include documented CDD steps that your team can actually follow, not just a policy binder
- Be checked periodically through an independent review, the same idea behind our guide on internal vs external audit in Qatar and which one your business needs
AML compliance also connects to wider governance work. Controls such as beneficial ownership checks, documented risk assessments, and board level oversight overlap with the due diligence expected during company formation in Qatar, and with the standards enforced through MOCI’s oversight of auditors.
How Kreston SVP Can Help
Meeting AML/CFT obligations across QCB, QFCRA, and MOCI frameworks takes more than a template policy. It takes local regulatory knowledge combined with practical steps. Kreston SVP’s audit and assurance and advisory teams work with QFC-licensed and QCB-regulated businesses to build AML/CFT programmes that satisfy regulators without slowing down daily operations. We also offer ICV certification and financial management advisory services.
If your business needs an AML/CFT compliance review or a fresh risk assessment ahead of a QFCRA or QCB inspection, contact Kreston SVP to speak with our advisory team.
Frequently Asked Questions
Who needs AML compliance in Qatar?
Any business regulated by the Qatar Central Bank (QCB) or licensed within the Qatar Financial Centre (QFC) needs an AML/CFT programme. This also applies to Designated Non-Financial Businesses and Professions (DNFBPs) such as auditors, accountants, real estate agents, and dealers in precious metals, who are supervised by the Ministry of Commerce and Industry (MOCI).
What law governs AML/CFT in Qatar?
Qatar’s AML/CFT framework is set out in Law No. (20) of 2019 on Combating Money Laundering and Terrorism Financing. It was later amended by Decree Law No. 19 of 2021 and updated further through 2025. The law aligns Qatar with international standards set by the Financial Action Task Force (FATF).
What is the difference between QCB and QFCRA AML oversight?
QCB regulates banks, insurers, exchange houses, and other financial institutions operating outside the Qatar Financial Centre. QFCRA is the independent regulator for firms licensed to operate in or from the QFC, and it applies its own Anti-Money Laundering Rulebook. Both authorities issue binding instructions and run inspections, but they oversee different groups of regulated entities.
What is a Suspicious Transaction Report (STR) and who do I report to?
An STR is a required filing made when a business notices activity that does not match a customer’s known profile, or that looks suspicious for another reason. In Qatar, STRs go to the Qatar Financial Information Unit (QFIU), which reviews the report and shares its findings with law enforcement. Telling the customer that a report has been filed is a separate legal offence known as tipping off.
Who counts as an Ultimate Beneficial Owner (UBO) under Qatar’s AML rules?
Under Qatar’s AML/CFT framework, a UBO is generally anyone who holds 10% or more of a company’s shares or voting rights, or who otherwise controls the entity. Regulated businesses must identify and verify UBOs as part of Customer Due Diligence (CDD) before starting a business relationship.
How long must AML records be kept in Qatar?
Regulated entities in Qatar must generally keep customer identification, transaction, and Customer Due Diligence (CDD) records for at least five years, in line with QCB and QFCRA record keeping requirements.
What happens if a business fails to comply with AML rules in Qatar?
Non-compliance can lead to financial penalties, licence restrictions, and public settlement notices from QCB or QFCRA. For QFC-licensed entities, weak AML controls can also delay or block new licence approvals, since QFCRA checks governance and compliance frameworks as part of the approval process.



