HomeFrameworksQCB Cloud Computing
Qatar Central Bank (QCB) · Qatar

Qatar Central Bank Cloud Computing Regulation compliance software

QCB's binding cloud computing regulation for its licensees, in force since 15 April 2024 — 141 controls across 19 domains, from strategy and due diligence through key management, exit planning and exemptions.

At a glance
  • RegulatorQatar Central Bank (QCB)
  • InstrumentCloud Computing Regulation — in force 15 April 2024
  • Structure19 domains, 141 controls, each citing its section
  • Data localisationPII and financial information processed within Qatar only
QCB Cloud ComputingAvailable
Overview

What QCB Cloud Computing requires

Who it applies to

  • Banks, insurers and other entities licensed by Qatar Central Bank entering a cloud arrangement
  • Entities negotiating a Material Arrangement requiring prior QCB approval
  • Compliance functions managing sub-contractor due diligence and flow-down obligations
  • Providers of outsourced cloud services to QCB licensees, in support of their clients' assessments

Qatar Central Bank's Cloud Computing Regulation, in force since 15 April 2024, governs how QCB-regulated entities plan, contract for, secure and exit cloud computing arrangements. It requires QCB's approval before entering any cloud arrangement, and specifically before signing or materially modifying a Material Arrangement, and it restricts processing of personal and financial information to within Qatar.

The regulation runs from strategy and corporate governance through a cloud governance policy and register, entity outsourcing planning, due diligence on the cloud arrangement and on its sub-contractors, contractual considerations, post-implementation review, compliance assessments, access and audit rights, business continuity, termination and exit planning, key management governance, data protection, cloud security testing, exemptions and compliance with secondary regulations — 141 controls across nineteen domains.

Exit is treated as its own obligation, not an afterthought: a documented exit plan covering both a stressed and a managed exit is mandatory, the provider must be contractually committed to assist rather than impede it, and on any termination the entity has the right to retrieve all its data, including backups, with the provider then required to remove it from its own environment. GRCLens carries every section as its own control, citing the regulation's section number.

In the platform

How GRCLens supports QCB Cloud Computing

QCB Cloud Computing runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

QCB approval as a tracked control

The approval required before any cloud arrangement, and specifically before signing or materially modifying a Material Arrangement, is its own control with the approval reference recorded against it.

Exit and termination as controls, not a plan on file

The stressed and managed exit plan, the provider's contractual assistance duty, and the data-retrieval and removal rights on termination are separately assessed, matching how QCB actually structured the obligation.

Sub-contractor flow-down

Register disclosure and contractual flow-down apply to sub-processors that touch data, not just the primary provider — tracked as its own domain rather than folded into the primary due-diligence control.

Reused with the QCB banking and insurance framework

A QCB licensee already assessed against the Technology Risk and Cyber Security regulations shares its governance and third-party evidence with this cloud-specific catalogue.

Questions

QCB Cloud Computing frequently asked questions

Does every cloud arrangement need QCB approval?

Yes — the regulation requires QCB approval prior to entering any Cloud Arrangement, with a further, specific approval required before signing or materially modifying a Material Arrangement.

Can PII or financial data be processed outside Qatar in the cloud?

No. The regulation requires personal data and financial information to be processed within Qatar only.

What does the regulation require before a contract ends?

A documented exit plan covering both a stressed and a managed exit, with the provider contractually committed to assist rather than impede it. On termination, the entity can retrieve all its data including backups, and the provider must then remove it from its own environment.

Talk to us about QCB Cloud Computing

Security Solution Consultants provides Qatar QCB cloud compliance advisory alongside the platform, so you can combine tooling with hands-on expertise.