Qatar Central Bank’s DLT Guideline: approval before use, no anonymous users, and no permissionless networks for now
When a business line proposes putting a process on a blockchain, the first compliance question at a firm regulated by the Qatar Central Bank is not about the technology. It is whether the QCB has approved the application. The QCB's Distributed Ledger…
When a business line proposes putting a process on a blockchain, the first compliance question at a firm regulated by the Qatar Central Bank is not about the technology. It is whether the QCB has approved the application. The QCB’s Distributed Ledger Technology (DLT) Guideline says an entity must notify the QCB in writing of any planned DLT application and must receive QCB approval before using it.
The guideline carries the short title “Distributed Ledger Technology (DLT) Guideline” for 2024 and states that it enters into force as of 22 July 2024. It defines the QCB Law as Law No. (13) of 2012, and it is written for the “Entity”, which it defines as an organization regulated by the Qatar Central Bank. A firm that is not regulated by the QCB falls outside that definition.
A guideline whose requirements bind
The title says guideline. The purpose section says something stronger.
The QCB states that it issues specific requirements where relevant and that, although this is a guideline, those requirements have the same force as a requirement in a QCB-issued regulation. Elsewhere it leaves room: an entity is allowed flexibility to achieve its objectives based on principles rather than rules, except where requirements are specified, and it shall make every effort to comply with the guideline as part of its regulatory obligations.
In practice, read each “must” as a requirement and each “should” as a principle you will be expected to explain your approach to.
Who and what it covers
The scope is wide. The guideline covers the interaction with or use of DLT by an entity in any form, and it applies only to an entity providing or using DLT, or proposing to use it. Blockchain is treated as one form of DLT, not the whole of it.
Two scope statements deserve to be read together:
- The QCB “strongly encourages” entities to inform it of all potential DLT applications and to present fully worked out proposals.
- Currently, the QCB would not permit permissionless DLT networks. The guideline defines a permissionless network as one with no restrictions on participation, where any entity can join as a validator node and validate transactions. Its annexure repeats the position for an entity that becomes a participant in a permissionless network and for one that sets one up.
The word “currently” is the QCB’s own. The guideline does not say when or whether that position will change.
The control an MLRO will care about most
The financial crime content of the guideline is short and unambiguous. It sits in the design review of the DLT assessment:
> “The Entity must ensure that any DLT application they interact with has > appropriate KYC controls and does not allow any anonymous or pseudonymous > Users”
The same paragraph requires that the distributed logs of records and any off-chain records are traceable, and that anonymity and pseudonymity are avoided. Note the reach of “interact with”. The test is not limited to a ledger the entity builds or operates itself.
Three further provisions belong on the financial crime team’s list.
Monitoring the ledger. As part of its security and privacy practices, an entity must review the distributed log of records and transactions within the ledger to identify suspicious patterns and connections and to monitor any anomalous activity.
The existing AML/CFT framework still applies. Part C lists what an entity must comply with alongside the QCB Law and the guideline. Under the heading for KYC, AML, CFT and the financing of proliferation it names the provisions of Law No. (20) of 2019 on Combating Money Laundering and Terrorism Financing, the instructions related to AML/CFT issued in May 2020, and any other circulations issued by the controllers and law enforcement bodies in Qatar. The guideline does not restate those obligations; it points to them.
Digital onboarding has its own rulebook. The same list includes the E-KYC Regulation, in the event an entity onboards customers digitally. It also lists Law No. (13) of 2016 on Personal Data Privacy Protection, the sector-specific security regulations, the QCB’s Technology Risks Circular of January 2018, and the Cloud Computing Regulation if the entity is looking to adopt cloud computing deployments.
Approval, and the notifications around it
The approval rule has more than one trigger.
- Before use. An entity must notify the QCB in writing in a timely manner of any planned DLT application and must receive QCB approval prior to use.
- On a major change. Any major change in an application is subject to the same requirement.
- When an application becomes material. An entity must notify the QCB in writing immediately if a DLT application not previously classified as material becomes classified as material.
- Applications already running. The annexure says an entity must disclose all existing applications to the QCB, and the QCB will determine the approval process for their continuing use or termination.
Internal tools are not exempt. The annexure applies the DLT assessment to internal tools handling administrative tasks, and says any new DLT application must be disclosed to the QCB and approved prior to solution go-live.
Before go-live the entity should also conduct an operational readiness check. For material risk applications this should be performed by an independent third party, and the entity should submit the assessment report to the QCB for approval.
“Material” is a defined term. A material DLT application is one which, in the event of a service failure or security breach, has the potential to impact the entity’s business operations, reputation or profitability, or its ability to manage risk and comply with applicable laws and regulations. It is also one that involves customer information and, in the event of unauthorized access, disclosure, loss or theft of that information, may have a negative impact on the entity’s customers.
The register the QCB will ask for
An entity must develop a register with a complete inventory of all DLT applications and maintain it on a regular basis. It must disclose the full register to the QCB on an annual basis, and upon request.
For each application the register must record whether it is built, purchased, licensed or outsourced, and the entity must affirm the nature of the DLT arrangements, its own role, whether the application is material, and a category reflecting its nature or functional use. Where the application is purchased, licensed or outsourced, the register adds provider details, including the name of the provider, its country of registration, the next contract renewal date and the governing law of the provider. It must also hold a detailed description of all material DLT applications and the date of the most recent risk assessment or audit of each.
The guideline adds that an entity should prove its compliance with its own policies and any externally imposed regulations by recording all relevant activity on an immutable audit trail.
Who is accountable
The board of directors and senior management are accountable for ensuring that effective internal controls, audit and risk management practices are implemented. The board is responsible for approving the level of DLT exposures to be tolerated in the overall risk framework, deciding whether existing governance structures are fit for purpose, and assigning clear lines of accountability and responsibility.
Senior management is responsible for the assessment, understanding and monitoring of the entity’s reliance on DLT. It should either establish a function overseeing DLT and participation in external DLT networks or delegate that responsibility to an existing function. Two requirements under this heading matter to assurance teams:
- DLT applications must be auditable: the entity must maintain appropriate evidence and records so that its internal control and audit functions, external auditors, regulators and other authorities can conduct their audits and reviews.
- DLT applications must be reviewed by the appropriate internal risk management function prior to launch, and monitored afterwards.
The legal and outsourcing questions
The DLT assessment includes a review of regulatory and legal issues. The entity must verify whether any of the application’s activities, services or products require licensing, approval or registration with the QCB. It must identify who is in charge of claims or malfunctions and the applicable jurisdiction, and it must have an analysis or legal opinion on the legal effects of using this type of DLT and any related smart contracts or tokens.
On keys and custody, the entity must select or approve the security solution chosen to protect private keys, whether it self-custodies or appoints a qualified custodian, and must evaluate the procedures in place for lost or stolen keys and develop key recovery plans.
Outsourcing carries its own approvals. An entity that outsources any activity to support its DLT operations should ensure regular due diligence on the provider and obtain prior consent from the QCB. It must obtain approval from its board of directors to outsource any function in relation to the use of a DLT, and document it. The service agreement should, at a minimum, include the entity’s right to terminate if the provider fails to comply with the conditions imposed or the QCB directs it to do so, and the QCB’s right to audit the provider’s accounts. The entity remains responsible as the principal for all the acts of omission or commission of its outsourcing service providers.
Three things worth doing
- Ask for the DLT register. If the firm is regulated by the QCB and nobody can produce an inventory of DLT applications with a materiality flag against each one, that is the first gap. The register is due to the QCB annually and on request.
- Put the KYC test into vendor and consortium due diligence. For every ledger the firm interacts with, record how users are identified, whether any anonymous or pseudonymous user can transact, and whether on-chain and off-chain records can be traced. Keep the answer with the DLT assessment.
- Check the approval trail. For each application, find the written notification to the QCB and the approval. Then check whether any change since was major, and whether any application has become material without the QCB being told.
Sources
This article draws on the following sources. Follow the links for the original text.
AML compliance financial-crime intermediate jurisdiction-briefing know-your-regulator qatar