Qatar Financial Centre: the QFCRA expects a sanctions programme, and Qatar’s domestic list must be on it
A screening tool that carries the UN list and whatever the vendor ships by default is not, on its own, what the QFC Regulatory Authority is asking for. Its Guidance on the Implementation of an Effective Sanctions Compliance Programme, marked V1.0 and dated…
A screening tool that carries the UN list and whatever the vendor ships by default is not, on its own, what the QFC Regulatory Authority is asking for. Its Guidance on the Implementation of an Effective Sanctions Compliance Programme, marked V1.0 and dated 2025, asks each firm to decide which sanctions it applies, write that decision down, have it signed off, and screen against the result. Two lists are not a matter of choice: the UN Security Council list and Qatar’s Domestic Sanctions List.
The guidance is written for firms in the Qatar Financial Centre. Its glossary defines “firm” as a financial institution, a DNFBP or a Designated Token Service Provider operating in the QFC. If your entity is licensed outside the Centre, this document is not addressed to you.
What kind of document this is
Fix its status before you map it to your procedures.
It is guidance. The QFCRA says it provides guidance to assist firms in developing, enhancing or implementing a sanctions compliance programme, that it does not address every possible scenario, and that it should not be interpreted as legal advice. Firms must develop their own programme and policies, procedures, systems and controls (PPSC) appropriate to the nature, scale and complexity of their business.
Its language is firm all the same. Much of the document is written in “must”. The one Qatari statutory provision it footnotes is Article (32) of Law No. (27) of 2019 on Combating Terrorism, against the Domestic Sanctions List. Read the rest as the Regulatory Authority’s stated expectations of a QFC firm.
It is not a standalone text. It says it supplements earlier guidance and should be read with the QFCRA’s guidance on the Effective Implementation of Targeted Financial Sanctions, its Guidance for Countering Proliferation Financing and its Guidance on the Risk-Based Approach. The regulatory framework for UN sanctions sits in the first two. This document is about the programme around them.
Three things every QFC firm must screen against
The guidance sets out what is not negotiable. Qatar is committed to enforcing UN Security Council resolutions to combat terrorism, terrorism financing and the proliferation of weapons of mass destruction, and it also has a domestic terrorist, terrorist financing and sanctions list, the Domestic Sanctions List. That list was established and published by the National Counter Terrorism Committee (NCTC). The Public Prosecutors Office (PPO) may also issue alerts or freeze orders from time to time.
The guidance then puts all three together in paragraph 7:
> “All firms must comply with the UNSC sanctions list, Qatar’s domestic sanctions > list and any PPO alerts or freezing orders.”
The screening duty follows from it. Firms must have an effective and appropriate screening system to check customers and their financial transactions against the UNSC list, the State of Qatar domestic sanctions list and any other lists the firm has identified in its sanctions risk assessment, and must be able to screen customers against any PPO alerts or freezing orders.
The PPSC checklist adds the plumbing. Among the key requirements it lists are registration with the NCTC (for UNSC and domestic sanctions), procedures to screen, action and respond to NCTC alerts, and QFCRA alerts (UNSC, domestic sanctions and PPO freezing orders), with procedures to screen, action and respond, including via the ESS.
Everything else is your risk assessment, not the QFCRA’s list
The guidance is candid about where the QFCRA’s remit stops. The frameworks for “other” international or “global” sanctions depend on the relevant jurisdictions’ obligations and are not explicitly regulated by the QFCRA. The Regulatory Authority says it cannot advise which customers, entities, persons, currencies, funds and assets from or with those jurisdictions firms can transact with, except those mandated by the UNSC and Qatar’s domestic lists.
That is not permission to ignore them. Breaching another jurisdiction’s regime may result in a penalty that may impact the firm’s business and operations in Qatar, so the guidance says all firms must assess their sanctions risks and implement appropriate mitigation. It gives the example of US unilateral sanctions that in some cases impose secondary sanctions on third-country firms, noting that US dollar correspondent banking relationships can be particularly relevant, and says the EU and the UK have imposed similar regimes that could affect firms transacting in euros or pounds or with persons and entities those jurisdictions list.
Two consequences for the programme:
- Every firm does the assessment. All QFCRA firms must undertake a sanctions risk assessment and have appropriate PPSC, the guidance says, regardless of the nature, scale and complexity of the firm’s business. It accepts that the programme will differ across the QFC population, because not every firm has correspondent banking arrangements, holds foreign funds or assets, or transacts outside Qatar. The answer can be small; it cannot be absent.
- Look at your own balance sheet too. Firms should assess whether any investments, funds or assets they hold in their own right or in trust may breach international sanctions requirements.
Sanctions also sit outside the AML/CFT box. Firms must ensure sanctions risks are considered as part of the broader operational risk or financial crime compliance programme, because sanctions compliance is broader than AML/CFT obligations. The risk assessment and programme should be documented and articulate the rationale for decisions. They can live in another policy or stand alone, and group or head office policies can be used provided they cover Qatar’s and the UNSC’s sanctions obligations.
Your own sanctions list, signed off
Paragraph 19 is the one to hold your screening configuration against. Firms need to develop and implement their own sanctions list based on their risk assessment; it is mandatory to include the UNSC and Qatar’s domestic list; the firm must identify which other international and global sanctions it will apply; and senior management should sign off the approved list.
Where a vendor or service provider does the screening, the firm must ensure the system is accurate and current and reflects the firm’s agreed list. Firms maintaining lists manually need sufficient resources and documented procedures for collating, updating and maintaining them. The QFCRA does not endorse any vendor or screening system, but it discourages relying only on manual systems, because sanctions lists are dynamic and constantly changing.
Who, when and how to screen
Two controls, not one. Screening should incorporate transaction screening and customer (name) screening, including the customer’s connected parties, during onboarding and across the life of the relationship.
Connected parties are spelled out. The guidance lists directors, controllers, major shareholders, beneficial owners, authorised signatories, managers, trustees, settlors, powers of attorney and any individual or entity that exercises control over the customer. Identification details of customers, connected parties, persons acting on the customer’s behalf and beneficial owners should be held in the customer database for ongoing name screening, so the firm can promptly find existing customers who become subject to sanctions later.
Timing has four triggers.
- Before the business relationship begins.
- Throughout it, including real-time screening of customer transactions and their counterparties. If a firm does not screen in real time, it should articulate why and the risks of not doing so, and apply mitigation to the gaps.
- Immediately after the publication of any UNSC sanctions, NCTC domestic sanctions alerts, or PPO orders on local designations or freezing measures.
- At trigger events, such as changes to the customer or connected parties (directors, controllers, major shareholders, company name, jurisdiction) or as global events dictate.
Exact-match screening is discouraged. Generally, exact name searches should be avoided; firms should consider name variants and partial matches, particularly for names written in foreign languages, and screening protocols such as fuzzy matching, calibrated to the firm’s risk profile. The guidance expects more alerts as a result: those alerts must be checked, the staff doing it should have access to CDD information, and records of all screening alerts and actions should be kept, including the clearing of false positives.
The checklist, and what it asks you to decide in advance
Paragraph 23 gives a 17-item checklist of key requirements for the PPSC, which the QFCRA says is not exhaustive. Beyond the list, the screening protocols and the name-matching rules, it asks the firm to settle ahead of time what happens on a match:
- who is responsible, and reporting to senior management;
- the decision on what action is taken, with the options named as closing the account, blocking the transaction, freezing the account, reporting to the QFCRA, considering an STR, and what contact is made with the customer, if any, consistent with the tipping-off requirements.
It also asks for role-specific staff training, testing of the PPSC, the screening list and the screening systems, governance and oversight including breaches, and a defined review cycle. The PPSC must be approved and signed off by senior management and/or the Board.
The minimum cadence
Paragraph 26 turns this into a calendar. The QFCRA recommends the following “best practices” as a minimum:
- a sanctions risk assessment at least annually, reviewed when there are significant changes such as in the customer base, products, services, distribution channels or jurisdictions;
- PPSC reviewed at least annually and aligned to the risk assessment;
- reporting to senior management whenever a trigger event occurs, such as a positive name match, a test failure or a breach, and reporting to the Board or governing body regularly and at least annually;
- staff training at least annually, or whenever the PPSC changes materially;
- screening systems tested regularly, with independent testing by the internal and/or external auditor at least annually.
The guidance adds that the people who build, run and oversee the programme must be appropriately trained and skilled, with resources and support from senior management, and that the programme should have established roles and escalation protocols for matches, failures and breaches.
Three things worth doing
- Pull the approved sanctions list and read its sign-off. It should name the UNSC list and Qatar’s Domestic Sanctions List, state which other regimes the firm applies and why, and carry senior management approval. Then confirm that the vendor configuration matches it.
- Test the domestic leg end to end. Check that the firm is registered with the NCTC, that NCTC and PPO alerts reach someone who can act on them, and that screening runs immediately after publication rather than at the next batch.
- Put the paragraph 26 cadence in the compliance calendar: annual risk assessment, annual PPSC review, annual training, annual independent testing of the screening system, and a written trigger for reporting a positive match to senior management.
Sources
This article draws on the following sources. Follow the links for the original text.
AML compliance financial-crime intermediate jurisdiction-briefing know-your-regulator qatar