Qatar Central Bank (QCB) · Qatar

Qatar Central Bank Technology Risk and Cyber Security Regulations compliance software

Qatar Central Bank's binding technology-risk and cyber security regulations for banks and for insurers — each licensee population sees only the text addressed to it.

At a glance
  • RegulatorQatar Central Bank
  • PopulationsBanks (Technology Risks, 2018) · Insurance (Cyber Security Regulation)
  • Domains9 per population — governance, HR, legal & compliance, procurement, risk, BCM, circulars, IT operations, enterprise security
  • Controls712 across both populations; each licensee answers its own set
QCB CyberAvailable
Overview

What QCB Cyber requires

Who it applies to

  • Banks licensed by Qatar Central Bank
  • Insurance companies licensed by Qatar Central Bank
  • Group compliance functions overseeing more than one QCB-regulated entity
  • Providers of outsourced technology services to QCB licensees, in support of their clients' assessments

Qatar Central Bank regulates technology risk and cyber security in the financial sector through sector-specific binding regulations: the Technology Risks regulation for banks, issued in January 2018, and the Cyber Security Regulation for the insurance sector. Each sets out governance, human resources, legal and compliance, procurement, risk management, business continuity, circular compliance, IT operations and enterprise security requirements for the licensees it addresses.

The two texts follow the same nine-part structure but diverge in their detail, because a bank's exposure and an insurer's are not the same. An assessment that merges them either asks an insurer about correspondent-banking controls or lets a bank skip what QCB actually wrote for it.

GRCLens carries the regulation as one framework with two licensee populations. A tenant declares its sector when the framework is enabled, and from then on sees only the domains and controls QCB addressed to it — 712 controls in total across both sets, of which a bank or an insurer answers its own.

In the platform

How GRCLens supports QCB Cyber

QCB Cyber runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Sector-scoped assessment

Banks and insurers are separate populations under one framework. The sector picker decides which domains a tenant sees; nothing is answered against a text QCB did not write for that licensee.

Nine domains, QCB's wording

Organisation and governance, human resources, legal and compliance, procurement, risk management, business continuity, QCB circular compliance, IT operations and enterprise security — each control carrying its regulation reference.

Evidence reused across frameworks

A QCB licensee that also runs ISO/IEC 27001, PCI DSS or the Qatar PDPPL attaches evidence once; the shared control model reuses it wherever the same control applies.

Group oversight

A group with a bank and an insurer sees both entities in the enterprise view, each assessed against its own population, with one board-level summary.

Questions

QCB Cyber frequently asked questions

Which QCB regulation does GRCLens assess?

The Technology Risks regulation for banks (2018) and the Cyber Security Regulation for the insurance sector, held as one framework with two licensee populations. QCB's separate 2022 instructions for payment service providers and financial services operators are not part of this catalogue.

We are a bank. Will we see the insurance controls?

No. The tenant's sector is set when the framework is enabled and the assessment shows only the domains QCB addressed to that sector.

Does GRCLens replace QCB's own reporting?

No. It runs the assessment and holds the evidence; the exports give the compliance function what it needs to complete QCB's returns and answer an examiner.

Talk to us about QCB Cyber

Security Solution Consultants provides QCB cyber compliance advisory alongside the platform, so you can combine tooling with hands-on expertise.