2019-01-01
Added · Updated
The Executive Regulations establish definitions for key terms such as Politically Exposed Persons and Beneficial Owners, and mandate that financial institutions and designated non-financial businesses and professions conduct risk assessments and implement anti-money laundering programs. The text requires enhanced due diligence for high-risk clients, including Politically Exposed Persons, and simplified due diligence for low-risk scenarios, while setting a 50,000 QAR threshold for verifying identities in occasional transactions. It further regulates correspondent banking relationships, third-party reliance, and the identification of beneficial owners through ownership thresholds and control mechanisms.
Cabinet Decision No. (41) of 2019 Issuing the Executive Regulations of the Anti-Money Laundering and Combating the Financing of Terrorism Law Issued by Law No. (20) of 2019
The Cabinet, Having reviewed the Constitution, And the Anti-Money Laundering and Combating the Financing of Terrorism Law issued by Law No. (20) of 2019, And the Amir's Decision No. (29) of 1996 concerning Cabinet decisions submitted to the Amir for ratification and issuance, And upon the proposal of the Chairman of the National Committee for Combating Money Laundering and Financing of Terrorism, Has decided as follows:
Article (1) The provisions of the Executive Regulations of the aforementioned Anti-Money Laundering and Combating the Financing of Terrorism Law, attached to this Decision, shall be applied.
Article (2) All competent authorities shall, each within their respective purview, implement this Decision. It shall be applied from the day following the date of its publication in the Official Gazette.
Abdullah bin Nasser bin Khalifa Al Thani Prime Minister
We ratify this Decision and issue it.
Tamim bin Hamad Al Thani Emir of the State of Qatar
Issued at the Diwan Amiri on: 29/04/1441 AH Corresponding to: 26/12/2019 AD
The Executive Regulations of the Anti-Money Laundering and Combating the Financing of Terrorism Law
Chapter One Definitions
Article (1) In the application of the provisions of these Regulations, the following words and phrases shall have the meanings indicated alongside each, unless the context requires otherwise: The Law: The Anti-Money Laundering and Combating the Financing of Terrorism Law issued by Law No. (20) of 2019. Politically Exposed Persons (PEPs): Individuals entrusted with or who have been entrusted with prominent public functions in the State or in a foreign country, such as Heads of State or Government, politicians, high-ranking government officials, judicial and military officials, senior executives of state-owned companies, members of parliamentary councils, and important officials of political parties, as well as senior management members such as directors, deputy directors, and board members, or positions equivalent to them in international organizations. Beneficial Owner: The natural person who ultimately owns or controls the customer on a final basis, through an ownership share or voting rights, or the natural person on whose behalf a transaction is conducted, whether by agency, guardianship, power of attorney, or any other form of representation, as well as the person who ultimately exercises actual and final control over a legal person or legal arrangement, including the person who exercises ultimate actual control by any means.
Correspondent Payment Accounts: Correspondent accounts used directly by third parties to conduct commercial activity primarily on their own behalf. Issuing Financial Institution: The financial institution that initiates the telegraphic transfer and receives funds upon receipt of a telegraphic transfer request on behalf of the originator. Beneficiary Financial Institution: The financial institution that receives the telegraphic transfer from the Issuing Financial Institution directly or through an intermediary financial institution, and makes the funds available to the beneficiary. Intermediary Financial Institution: The financial institution that, in a payment chain or coverage, receives and transfers the telegraphic transfer on behalf of the Issuing Financial Institution and the Beneficiary Financial Institution or another intermediary financial institution. False Declaration: Providing incorrect information regarding the value of currency or negotiable instruments, or precious metals or stones, being transported, or providing other incorrect information relevant to the declaration required by or from customs authorities, including failure to submit the declaration as required. Money or Value Transfer Service Agent: Any person who provides money or value transfer services on behalf of a money or value transfer service provider, whether under a contract with them or under their management.
Chapter Two Preventive Activities, Operations, and Measures
Section One Activities and Operations of Financial Institutions
Article (2) The activities and operations conducted by a financial institution as a business include the following: -1- Accepting deposits and other payable funds from the public. -2- Lending, including consumer loans and mortgages, with or without recourse, and financing commercial operations, including the purchase of export documents and the purchase of debts, with or without recourse. -3- Financial leasing, excluding financial leasing related to consumer products. -4- Money or value transfer services, excluding the provision of messages or other support systems to financial institutions solely for money transfers. -5- Issuing or managing payment instruments, such as credit and debit cards, checks, traveler's checks, money orders, bank drafts, electronic funds, payment orders, and bank bills. -6- Financial guarantees and commitments. -7- Activities related to securities. -8- Dealing in:
-9- Participation in the issuance of securities and providing financial services related to such issuance. -10- Individual or collective management of financial portfolios. -11- Safekeeping and management of funds or cash on behalf of or for the benefit of others. -12- Other operations for investing, managing, or operating funds or cash on behalf of or for the benefit of others. -13- Underwriting or saving in life insurance and other types of investment-related insurance, including those provided by insurance agents and brokers. -14- Exchange of cash or currencies. -15- Any other activity or operation specified by a Cabinet Decision, upon the proposal of the Committee.
Section Two Preventive Measures
Article (3) Financial institutions and specified non-financial businesses and professions must identify, assess, and understand their money laundering and terrorism financing risks, commensurate with the nature of their business and size, in accordance with the following: -1- Documenting risk assessments and any underlying information so that they are able to present their basis, supervise it, and update it continuously. -2- Making the risk assessment report available to the competent regulatory authority periodically within the period specified, and upon request by this authority. -3- Considering all relevant risk factors before determining the risk mitigation measures to be applied and the type of these measures.
Article (4) When identifying risks in accordance with the previous Article, financial institutions and specified non-financial businesses and professions must consider the risks identified in the National Risk Assessment, in addition to the following factors: -1- Risk factors related to customers, beneficial owners of customers, and beneficiaries of transactions conducted by customers.
-2- Risk factors related to countries and geographical areas. -3- Risk factors related to the products and services provided by financial institutions and specified non-financial businesses and professions, transactions, and delivery channels. -4- Risk factors related to the purpose of the customer opening the account or establishing the business relationship. -5- Risk factors related to the level of deposits, volume of operations, and transactions. -6- Risk factors related to the initiation of the relationship with the customer and the supply of operations.
Article (5) Financial institutions and specified non-financial businesses and professions must identify and assess money laundering and terrorism financing risks that may arise from the development of new products or professional practices, including new means of providing services or products or operations arising from the use of new technologies or under development on new or previously existing products, before launching or using these products, practices, or technologies, and taking appropriate measures to manage and mitigate these risks.
Article (6) Financial institutions and specified non-financial businesses and professions must establish anti-money laundering and combating the financing of terrorism programs that include the necessary policies, procedures, and controls, taking into account risks and business size. These programs must include the following: -1- Appropriate compliance management arrangements, including the appointment of a compliance officer at the management level. -2- Taking measures to ensure appropriate screening for high standards of competence when appointing employees. -3- A continuous training program for employees. -4- An independent audit unit to test the anti-money laundering and combating the financing of terrorism system.
Article (7) Financial groups and specified non-financial businesses and professions must apply anti-money laundering and combating the financing of terrorism programs to all branches and majority-owned subsidiaries. In addition to the measures stipulated in the previous Article, these programs must include the following: -1- Applying policies and procedures for the exchange of information required for customer due diligence and money laundering and terrorism financing risk management. -2- Providing necessary information to Group-level Compliance, Audit, and Anti-Money Laundering and Combating the Financing of Terrorism officers regarding operations, accounts, and transactions from branches and subsidiaries, when necessary for anti-money laundering and combating the financing of terrorism purposes, including information and analyses on transactions and activities that appear unusual or suspicious, and suspicious transaction reports and their underlying information. -3- Providing the information referred to in the previous paragraph to branches and subsidiaries when appropriate, whenever it is suitable for risk management. -4- Applying adequate safeguards regarding confidentiality and the use of exchanged information, including safeguards against tipping off.
Article (8) Financial groups, financial institutions, and specified non-financial businesses and professions must ensure that their foreign branches and majority-owned subsidiaries apply anti-money laundering and combating the financing of terrorism measures in accordance with the requirements imposed in the State when the minimum anti-money laundering and combating the financing of terrorism requirements in the host country are less stringent than those applied in the State, to the extent permitted by the laws and regulations of the host country.
-2- If the host country does not allow the appropriate implementation of specific anti-money laundering and combating the financing of terrorism measures consistent with those applied in the State, financial groups, financial institutions, and specified non-financial businesses and professions must apply additional appropriate measures to manage money laundering and terrorism financing risks on foreign branches and majority-owned subsidiaries, and inform the competent regulatory authority in the State thereof. -3- If the additional measures are insufficient, the competent authorities in the State should consider taking other supervisory measures, including imposing additional controls on financial groups, financial institutions, and specified non-financial businesses and professions, and requiring them, if necessary, to cease operations in the host country.
Article (9) Financial institutions and specified non-financial businesses and professions must consider the relative importance of risks and existing customers when applying due diligence measures in the cases stipulated in Articles (10) and (11) of the Law, and take these measures regarding existing business relationships at the time, at the time of taking them, and the adequacy of the data obtained.
Article (10) Financial institutions and specified non-financial businesses and professions must take due diligence measures when conducting occasional financial transactions equivalent to or exceeding fifty thousand Qatari Riyals (50,000), and must take appropriate measures to detect transactions split into small amounts that equal in total the amount specified in the previous paragraph. Real estate brokers must apply the aforementioned measures to their real estate transactions.
Article (11) Dealers in precious metals or precious stones are subject to the obligations stipulated in the Law when concluding cash transactions with their customers equivalent to or exceeding fifty thousand Qatari Riyals (50,000).
Article (12) If financial institutions and specified non-financial businesses and professions suspect, during the establishment of a business relationship with a customer or during the course of this relationship, or when conducting occasional transactions, that the transactions are related to money laundering or terrorism financing, they must do the following: -1- Identify and verify the identity of the customer and the beneficial owner, whether the customer is permanent or occasional, regardless of any exemption or specific threshold in effect. -2- Submit a suspicious transaction report to the Unit.
Article (13) Financial institutions and specified non-financial businesses and professions must identify and verify the customer's identity using original documents or data from a reliable and independent source, by collecting the following information as a minimum: -1- Regarding natural persons: Obtaining the full name of the person, as recorded in official proofs, the address of residence or local address, date and place of birth, and nationality. -2- Regarding legal persons or legal arrangements: Obtaining the name and legal form of the person, its establishment deed, the powers and regulations governing the legal person or legal arrangement, the names of persons holding senior management positions, the registered office address, and the principal place of business if different from the registered office address. Financial institutions and specified non-financial businesses and professions must, regarding customers who are legal persons or legal arrangements, understand the customer's ownership structure and control, and verify the identity of beneficial owners in accordance with the provisions of Articles (15) and (17) of these Regulations.
And they must collect any additional information and verify it, according to the degree of risk posed by the customer. And financial institutions and specified non-financial businesses and professions must, regarding all customers, do the following: -1- Understand the nature of the customer's business or pattern of activity. -2- Ensure that any person claiming to act on behalf of the customer is authorized. -3- Thereby, identifying and verifying their identity, in accordance with the provisions of items (1) and (2) of the first paragraph of this Article. -4- Understand the purpose and nature of the business relationship, and where necessary, obtain information related to this purpose.
In this regard: -a- Scrutinizing transactions throughout the duration of the relationship to ensure consistency with the institution's knowledge of the customer, their pattern of activity, and the risks they pose, and if necessary, the source of funds. -b- Ensuring that documents, data, or information obtained under due diligence measures are appropriate and continuously updated, by reviewing existing records, especially for high-risk customer categories.
Article (14) Financial institutions and specified non-financial businesses and professions must, in cases where regulatory authorities allow the establishment of a business relationship before verifying the customer's identity, adopt risk management procedures regarding the circumstances under which they can benefit from the business relationship.
Article (15) Financial institutions and specified non-financial businesses and professions must, regarding customers who are legal persons, identify the beneficial owner and take reasonable measures to verify their identity using relevant information or data derived from a reliable source, as follows: -1- Identifying the natural person or natural persons who ultimately hold an effective controlling ownership share of not less than (20%) of the shares of the legal person, or voting rights therein, and taking reasonable measures to verify their identity. -2- In cases where the beneficial owner cannot be identified, or when there is suspicion that the natural person holding controlling shares is not the beneficial owner according to the previous item, or when no natural person exercises control through ownership share, financial institutions and specified non-financial businesses and professions must identify the natural person or natural persons who exercise actual or legal control or supervision, by any means, directly or indirectly, in the legal person or legal arrangement or executive bodies or the General Assembly, or on the operation of the legal person or other instruments of control or supervision. -3- In the event that no natural person is identified according to the provisions of the previous two items, financial institutions and specified non-financial businesses and professions must identify the natural person holding a senior management position in the legal person and verify their identity. Financial institutions and specified non-financial businesses and professions must not accept a customer, execute a transaction, or continue a business relationship if they are unable to identify at least one natural person meeting the requirements of this Article. In this case, they must terminate the business relationship with existing customers and submit a suspicious report to the Unit.
Article (16) If the customer, or the holder of the controlling share, or a company listed on the stock exchange is subject to disclosure requirements that ensure sufficient transparency in verifying the beneficial owner, or a subsidiary that holds a controlling share therein, it is permissible not to identify any shareholder or beneficial owner in those companies, and when this is not achieved, identity data can be obtained from records available to the public, or from the customer, or from any other reliable source.
Article (17) Financial institutions and specified non-financial businesses and professions must, regarding customers who are investment funds, identify the beneficial owner and take reasonable measures to verify their identity, by identifying the beneficiaries or category of beneficiaries, and any other natural person who exercises actual and final control over the investment fund directly or indirectly. They must, regarding other legal arrangements, identify the natural persons holding equivalent positions. Financial institutions and specified non-financial businesses and professions must also take the necessary measures to identify the customer if they are represented or represented in another type of legal arrangement.
Article (18) In addition to the customer due diligence measures set out in the Law and these Regulations, financial institutions must apply the following additional due diligence measures regarding beneficiaries of life insurance policies and other insurance products: -1- Regarding named beneficiaries: Obtaining the name of the person, whether a natural person, legal person, or legal arrangement. -2- Regarding beneficiaries who are named by characteristics, category, or other means: Obtaining sufficient information about the beneficiary, allowing the financial institution to ascertain that they will be able to identify the beneficiary at the time of payout.
-3- Verifying the identity of the beneficiary in both of the above cases at the time of payout. In cases where financial institutions are unable to carry out the measures referred to in this Article, they must submit a suspicious report to the Unit.
Article (19) Financial institutions must consider the beneficiary of a life insurance policy as a risk factor when determining the extent to which enhanced customer due diligence measures apply. If they determine that the beneficiary is a legal person or legal arrangement representing a high risk, they must take enhanced due diligence measures, which include reasonable measures to identify and verify the beneficial owner of the insurance policy at the time of payout.
Article (20) When relying on third-party financial institutions and specified non-financial businesses and professions to carry out the due diligence measures stipulated in the Law and these Regulations, financial institutions and specified non-financial businesses and professions must do the following: -1- Immediately obtain the necessary information related to the aforementioned measures. -2- Ensure that the third party will provide customer identification data and other documents related to those measures without delay upon request. -3- Verify that the third party is regulated and supervised or monitored, and complies with customer due diligence measures and record-keeping in accordance with the Law and these Regulations. -4- Consider the available information regarding the level of money laundering and terrorism financing risks in the countries where the third parties relied upon are located.
Article (21) When financial institutions and specified non-financial businesses and professions rely on a third party that is part of the same group, regulatory authorities, whether in the State or the host country, may consider the requirements referred to in the previous Article to be met in the following cases: -1- The application by the aforementioned group of customer due diligence measures and record-keeping, and anti-money laundering and combating the financing of terrorism programs, in accordance with the Law and these Regulations. -2- Supervision by competent authorities to verify the group's application of these measures and programs. -3- Adequate reduction of high country-specific risks through the group's policies on anti-money laundering and combating the financing of terrorism.
Article (22) Financial institutions and specified non-financial businesses and professions must apply appropriate enhanced due diligence measures commensurate with the degree of risk to business relationships and transactions with customers, including financial institutions and specified non-financial businesses and professions from countries that the Financial Action Task Force calls for action against, and which the Committee publishes on its website on the Internet.
Article (23) Financial institutions and specified non-financial businesses and professions must take other measures in implementation of Article (13) of the Law, in a manner that ensures appropriate countermeasures commensurate with the degree of risk specified in instructions issued by regulatory authorities, based on Financial Action Task Force data, or measures determined independently by the Committee.
Article (24) The Committee issues instructions related to weaknesses in anti-money laundering and combating the financing of terrorism systems in other countries. The Committee is responsible for informing regulatory authorities and competent authorities of these instructions and publishing them on its website on the Internet. Regulatory authorities are responsible for informing financial institutions and specified non-financial businesses and professions thereof.
Article (25) Financial institutions and specified non-financial businesses and professions must, to the greatest extent possible and reasonably, study the background and purpose of all complex or unusual transactions, and all patterns of unusual transactions that have no clear economic or legal purpose. When money laundering or terrorism financing risks are high, financial institutions and specified non-financial businesses and professions must apply enhanced due diligence measures, in accordance with the identified risks, and in particular, increase the level of monitoring of the business relationship to identify unusual or suspicious activities or transactions. Enhanced due diligence measures include in particular the following: -1- Obtaining additional information about the customer, including occupation, asset size, and information available through public databases and open sources, and regularly updating customer and beneficial owner identification data. -2- Obtaining additional information about the nature of the expected business relationship. -3- Obtaining information about the source of funds or the customer's source of wealth. -4- Obtaining information about the reasons for the expected or conducted transactions. -5- Obtaining senior management approval to initiate or continue the business relationship. -6- Applying enhanced monitoring of the business relationship by increasing the number and periods of supervision and selecting transaction patterns that require further examination and review. -7- Making the initial payment through an account in the customer's name at a private bank with similar due diligence standards.
Article (26) If money laundering or terrorism financing risks are low, financial institutions and specified non-financial businesses and professions may, based on what the regulatory authority determines, apply simplified due diligence measures that take into account the nature of these risks and are proportional to low risk factors, including the following: -1- Verifying the identity of the customer and beneficial owner after establishing the business relationship, such as account operations if they exceed the threshold amount determined for the business relationship. -2- Reducing the frequency of customer identity updates. -3- Reducing the degree of ongoing due diligence and transaction scrutiny, based on a reasonable amount determined. -4- Not collecting information or implementing specific measures to understand the nature or purpose of the business relationship, while retaining the inference from the type of transactions being conducted or the existing business relationship. Simplified measures may relate only to transaction cutting or ongoing monitoring, and these measures must not be applied when there is suspicion of money laundering or terrorism financing, or when special high-risk situations are met.
Article (27) Financial institutions and specified non-financial businesses and professions must put in place suitable risk management systems that enable them to know whether the customer or beneficial owner is a Politically Exposed Person (PEP), or a family member or close associate thereof. They must also take the following additional due diligence measures: -1- Obtaining senior management approval before establishing or continuing a business relationship, regarding existing customers. -2- Taking reasonable measures to know the source of wealth and funds of customers and beneficial owners who are Politically Exposed Persons (PEPs), or their family members or close associates. -3- Applying strict and continuous monitoring of their business relationship.
Article (28) The family members of a Politically Exposed Person (PEP) include any natural person related to them by blood or marriage up to the second degree.
And a close associate of a Politically Exposed Person (PEP) includes any natural person who is a partner with them in a legal person or legal arrangement, or a beneficial owner of a legal person or legal arrangement owned or effectively controlled by a Politically Exposed Person (PEP), or any person who has a close professional or social relationship with them.
Article (29) Financial institutions must take reasonable measures before payout regarding life insurance policies to determine whether the beneficiary or beneficial owner is a Politically Exposed Person (PEP). They must also, in the event of high risks, inform senior management before payout, conduct a thorough examination of the business relationship with the holder of this policy, and submit a suspicious transaction report to the Unit.
Article (30) Financial institutions must, when establishing cross-border correspondent banking relationships or any similar relationships, do the following: -1- Collect sufficient information to understand their business well, and through available information, conduct due diligence to recognize their reputation and the level of supervision they are subject to, including whether they have been subject to investigation regarding money laundering or terrorism financing or supervisory action. -2- Evaluate the controls used by the respondent institution to combat money laundering and terrorism financing. -3- Obtain senior management approval before establishing a new correspondent banking relationship. -4- Understand the responsibilities of each institution in the field of combating money laundering and terrorism financing clearly.
Article (31) Regarding correspondent payment accounts, financial institutions must be convinced that the respondent bank: -1- Has carried out the due diligence measures stipulated in the Law and these Regulations regarding customers who can access its accounts directly.
-2- Is able to provide relevant due diligence information regarding customers upon request by the correspondent bank.
Article (32) Financial institutions issuing wire transfers must do the following: -1- Obtain information regarding the sender and beneficiary when executing wire transfers equal to or exceeding (3,500) three thousand and five hundred riyals, verify it, and ensure that such information includes the following: -a- The full name of the sender and beneficiary. -b- The account number of the sender and beneficiary, or the payment identification number in the absence of an account number, provided that this number allows financial institutions to trace the transaction. -c- The sender's address, national ID number, customer ID number, or date and place of birth, and this information must be included in the message or payment form accompanying the transfer. -2- In cases where the information referred to in the previous clause is late, the beneficiary financial institution and competent authorities may, through other means, allow the financial institution to supplement the information regarding the transaction by updating the wire transfer account number or payment identification number, provided that these two numbers allow tracing the transaction to the sender or beneficiary, within three working days from the date of receiving the request, whether from the competent authorities. The General Auditor may require the immediate submission of this information. -3- Ensure that cross-border wire transfers that are less than the amount specified in clause (1) of this article include the name of the sender and beneficiary, and the account number of each or the payment identification number that allows tracing, and in this case, the issuing financial institution is not required to verify the accuracy of the information. -4- Unless there is suspicion of money laundering or terrorism financing, where multiple cross-border wire transfers issued by one sender are aggregated in a transfer file to be transferred to beneficiaries, the file must contain the required and accurate information about the sender of the transfer.
and complete information about the beneficiary, allowing these transactions to be fully traced in the country of the beneficiary financial institution, and they must include the sender's account number or payment identification number. -5- Refrain from executing wire transfers if the requirements stipulated in this article are not met.
Article (33) Intermediary financial institutions, when executing wire transfers, must: -1- Ensure that all information regarding the sender and beneficiary accompanies the wire transfer. -2- Take reasonable measures consistent with direct processing to identify wire transfers that do not include the required information about the beneficiary or sender.
Article (34) The beneficiary financial institution must take reasonable measures to identify cross-border wire transfers lacking the required information about the sender or beneficiary, which may include the following sequential procedures for execution, or follow-up procedures during execution, if possible. For cross-border wire transfers exceeding (3,500) three thousand and five hundred riyals, the beneficiary financial institution must verify the identity of the beneficiary, if not done previously, and collect it during the verification process, in accordance with the requirements stipulated in the Law.
Article (35) Issuing, intermediary, and beneficiary financial institutions must retain all information regarding the sender and beneficiary, including the sender's account and payment identification number, for at least ten years from the date of completion of any transaction. In the event that technical restrictions prevent the retention of the required information regarding the sender of the transfer and the beneficiary accompanying the cross-border transfer with the wire transfer.
The relevant analyst at the intermediary financial institution must retain all information received from the issuing financial institution or from another intermediary financial institution, for at least ten years.
Article (36) Intermediary and beneficiary financial institutions must establish effective risk-based policies and procedures to determine when to execute, reject, or suspend wire transfers that do not include the required information about the beneficiary or sender, and appropriate follow-up procedures.
Article (37) Money or value transfer service providers must do the following: -1- Comply with all relevant requirements in the Law and the Executive Regulations, whether they conduct their business themselves or through their agents. -2- Maintain an updated list of their agents and make it available to the competent regulatory authority. -3- Include their agents and partners in their anti-money laundering and counter-terrorism financing programs. -4- Monitor their compliance with them.
Article (38) If a money or value transfer service provider controls the transfer party, the payer, and the beneficiary, they must comply with the following: -1- Take into account all information issued by the source of the transfer and the beneficiary. -2- Determine the necessity of submitting a report on the suspicious transaction or not, and submit a report on suspicious wire transfers in all countries associated with them, and provide all relevant information regarding the transaction to the Unit.
Article (39) Financial institutions and specified non-financial businesses and professions must report suspicious transactions, in accordance with the form approved by the Unit, and the instructions and guidelines issued by it.