Security & compliance · Qatar
Edrak and the Qatar Central Bank
The QCB sets what licensed financial institutions must do about technology risk, cybersecurity and outsourcing. Edrak is built for those conversations: your permissions, your data location, a full record, and contracts written for regulated outsourcing.
- QCB
- Financial regulator. Sets technology risk, cybersecurity and outsourcing requirements for licensed institutions.
- Applies to
- Banks, insurers, finance companies and payment providers licensed by the QCB. Sector-specific requirements.
- Where Edrak stands
- Edrak supports licensed institutions as a technology provider. We map our controls to the QCB's technology risk and cloud requirements and structure contracts to fit its outsourcing rules. The QCB does not certify vendors.
The QCB requirements
Four instruments shape what a licensed institution needs from a technology provider. They bind the licensed institution.
Tech risk
Technology Risk Circular
Governance, IT risk management, cybersecurity controls and incident reporting.
Cloud
Cloud Computing Requirements
Conditions for using cloud services, including data location and regulator approval.
Outsourcing
Outsourcing Requirements
Due diligence, contract terms, audit rights and exit for material outsourcing.
Fintech
Fintech and Digital Strategy
Expectations for digital services, including AI, under the national fintech strategy.
How Edrak supports your QCB obligations
The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.
Outsourcing and materiality
Edrak: Contract terms, exit and data-return provisions, and audit rights are written to fit financial-sector outsourcing rules.
You: Materiality assessment and any regulator notification or approval.
Identity and access
Edrak: Signs in through your identity provider and inherits the permissions people already hold. It cannot see data a user could not see.
You: Identities, roles, and joiner, mover and leaver processes.
Data location
Edrak: Runs in Edrak Cloud in your chosen region, in your own cloud account, or on-premises. Your data is used for your business only.
You: Choosing the deployment that meets QCB data-location expectations.
Records
Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.
You: Retention aligned to QCB requirements and audit access.
Resilience
Edrak: Defined availability targets, tested recovery, and workflows that pause safely when something goes wrong.
You: Business-continuity plans and recovery objectives.
Incidents
Edrak: A named security contact, notification commitments and support for your investigation, agreed in contract.
You: Incident handling and QCB notification.
For your security and compliance teams
We share a requirement-by-requirement mapping to the QCB frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.
Talk to our teamThe QCB issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Requirements apply to institutions licensed by the regulator. Edrak supports your obligations as a technology provider to a regulated institution. Confirm applicability with your compliance team.

