Does QCB Artificial Intelligence Guideline require Risk Assessment?
Qatar • enforcing
Yes — 1 provision
Requirements at a glance
This regulation imposes 9 specific requirements for Risk Assessment across 1 provision:
- AI strategy — Firms must establish and periodically review an AI strategy aligned with business objectives
- Governance accountability — The board and senior management remain accountable for AI outcomes (7.1). The responsible oversight function must use or create appropriate committees to assess AI use cases before implementation (7.5); clause 7.4 guidance on establishing or delegating the function remains context
- Risk management — Identify, assess, and mitigate AI risks including bias, discrimination, privacy, security, and lack of transparency
- High-risk categorization — Identify and categorize high-risk AI systems based on guideline criteria; apply stricter scrutiny
- Pre-approval as Provider — QCB approval is required before the Entity launches a new AI system as a Provider and before material modification of an existing one (11.1)
- High-risk pre-approval — QCB approval is required before signing any high-risk AI purchase, licensing or outsourcing agreement, in line with QCB outsourcing guidelines and recommendations (11.2)
- Sandbox evaluation — Before approval, QCB may direct a particular AI system for further evaluation in a sandbox (11.3)
- AI register — Maintain an updated register of all AI systems in use
- Governance resources — AI governance functions must understand their roles and responsibilities and have the training, resources and guidance needed to discharge them (8.1)
AI Governance and Risk Management
The guideline sets requirements and guidance for QCB-regulated entities. Clause 11.1 requires approval before launching a new AI system as a Provider or materially modifying an existing one. Clause 11.2 separately requires approval before signing a high-risk purchase, licensing or outsourcing agreement. QCB may direct sandbox evaluation before approval under clause 11.3. No comparative claim that this is the first GCC regulation is established here.
Penalties qualification: Penalties not specified in the guideline. Non-compliance is subject to QCB's general supervisory and enforcement powers over licensed entities.
Requirements
| Requirement | Details |
|---|---|
| AI strategy | Firms must establish and periodically review an AI strategy aligned with business objectives |
| Governance accountability | The board and senior management remain accountable for AI outcomes (7.1). The responsible oversight function must use or create appropriate committees to assess AI use cases before implementation (7.5); clause 7.4 guidance on establishing or delegating the function remains context |
| Risk management | Identify, assess, and mitigate AI risks including bias, discrimination, privacy, security, and lack of transparency |
| High-risk categorization | Identify and categorize high-risk AI systems based on guideline criteria; apply stricter scrutiny |
| Pre-approval as Provider | QCB approval is required before the Entity launches a new AI system as a Provider and before material modification of an existing one (11.1) |
| High-risk pre-approval | QCB approval is required before signing any high-risk AI purchase, licensing or outsourcing agreement, in line with QCB outsourcing guidelines and recommendations (11.2) |
| Sandbox evaluation | Before approval, QCB may direct a particular AI system for further evaluation in a sandbox (11.3) |
| AI register | Maintain an updated register of all AI systems in use |
| Governance resources | AI governance functions must understand their roles and responsibilities and have the training, resources and guidance needed to discharge them (8.1) |