Security & compliance · Qatar

Edrak and the Qatar Central Bank

The QCB sets what licensed financial institutions must do about technology risk, cybersecurity and outsourcing. Edrak is built for those conversations: your permissions, your data location, a full record, and contracts written for regulated outsourcing.

QCB
Financial regulator. Sets technology risk, cybersecurity and outsourcing requirements for licensed institutions.
Applies to
Banks, insurers, finance companies and payment providers licensed by the QCB. Sector-specific requirements.
Where Edrak stands
Edrak supports licensed institutions as a technology provider. We map our controls to the QCB's technology risk and cloud requirements and structure contracts to fit its outsourcing rules. The QCB does not certify vendors.

The QCB requirements

Four instruments shape what a licensed institution needs from a technology provider. They bind the licensed institution.

  • Tech risk

    Technology Risk Circular

    Governance, IT risk management, cybersecurity controls and incident reporting.

  • Cloud

    Cloud Computing Requirements

    Conditions for using cloud services, including data location and regulator approval.

  • Outsourcing

    Outsourcing Requirements

    Due diligence, contract terms, audit rights and exit for material outsourcing.

  • Fintech

    Fintech and Digital Strategy

    Expectations for digital services, including AI, under the national fintech strategy.

How Edrak supports your QCB obligations

The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.

  • Outsourcing and materiality

    Edrak: Contract terms, exit and data-return provisions, and audit rights are written to fit financial-sector outsourcing rules.

    You: Materiality assessment and any regulator notification or approval.

  • Identity and access

    Edrak: Signs in through your identity provider and inherits the permissions people already hold. It cannot see data a user could not see.

    You: Identities, roles, and joiner, mover and leaver processes.

  • Data location

    Edrak: Runs in Edrak Cloud in your chosen region, in your own cloud account, or on-premises. Your data is used for your business only.

    You: Choosing the deployment that meets QCB data-location expectations.

  • Records

    Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.

    You: Retention aligned to QCB requirements and audit access.

  • Resilience

    Edrak: Defined availability targets, tested recovery, and workflows that pause safely when something goes wrong.

    You: Business-continuity plans and recovery objectives.

  • Incidents

    Edrak: A named security contact, notification commitments and support for your investigation, agreed in contract.

    You: Incident handling and QCB notification.

For your security and compliance teams

We share a requirement-by-requirement mapping to the QCB frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.

Talk to our team

The QCB issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Requirements apply to institutions licensed by the regulator. Edrak supports your obligations as a technology provider to a regulated institution. Confirm applicability with your compliance team.