Custodial wallet / SaaS in Qatar
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is not permitted in Qatar.
Verdict Details
- Permitted
- no
- Local entity required
- No
- Licensing burden
- None
- Last updated
- 2026-07-13
AML Obligations
- Law No. (20) of 2019 on Combating Money Laundering and Terrorist Financing applies to any entity dealing with virtual assets, even in the absence of a dedicated license (qa.aml.law-no-20-of-2019, qa.licensing.the-qcb-has-also-been)
- CDD required: obtain and verify customer name, address, DOB, nationality, official ID for natural persons (qa.aml.natural-persons-obtain-and-verify)
- CDD required for legal persons: name, legal form, proof of incorporation, registered address, directors/senior management details, ownership/control structure (qa.aml.legal-personsarrangements-obtain-and-verify)
- Beneficial ownership identification for any natural person owning/controlling 25% or more (qa.aml.beneficial-ownership-identification-identify-and)
- Source of Funds and Source of Wealth analysis required for high-risk customers/transactions (qa.aml.source-of-funds-and-source)
- Ongoing transaction monitoring to detect unusual or suspicious activity (qa.aml.ongoing-monitoring-continuously-monitor-the)
- PEP screening and enhanced due diligence (qa.aml.politically-exposed-persons-peps-implement)
- Sanctions screening against UNSC and national sanctions lists (qa.aml.sanctions-screening-screen-customers-and)
- Enhanced Due Diligence for high-risk scenarios including cross-border virtual asset transfers (qa.aml.enhanced-due-diligence-edd-apply, qa.aml.cross-border-virtual-asset-transfers)
- Suspicious Transaction Reports (STRs) must be filed immediately to the Qatar Financial Information Unit (QFIU) with no tipping-off (qa.aml.report-suspicious-activity-immediately-report, qa.aml.reporting-body-all-strs-must, qa.aml.no-tipping-off-prohibited-from-disclosing)
- Record-keeping: minimum 5 years for customer identification data, transaction records, and business correspondence (qa.aml.customer-identification-data-all-records, qa.aml.transaction-records, qa.aml.duration-records-must-be-maintained)
Key Restrictions
- QFCRA Financial Services Rulebook Rule 2.1.3(1) prohibits any firm from undertaking a 'Financial Service or other activity relating to a Virtual Asset' (qa.licensing.rule-2131-of-the-fsru)
- The prohibition covers custodial wallet / SaaS services that involve digital representations of value that can be traded, transferred, or used for payment/investment (qa.licensing.the-qfcra-glossary-defines-virtual)
- The only carve-out is for digital representations of fiat currencies, securities, and other financial assets already covered under the QFCRA framework — tokenized securities may be permissible if regulated as securities (qa.licensing.exceptionsnuances-the-prohibition-explicitly-excludes)
- No specific crypto custody license exists; no 'qualified custodian' framework for digital assets (qa.licensing.current-status-there-is-no, qa.licensing.current-status-there-are-no)
Key Risks
- Direct regulatory prohibition (QFCRA Rule 2.1.3(1)) makes operating a custodial wallet / SaaS for virtual assets unlawful in the QFC — this creates immediate enforcement exposure
- While Law No. 20 of 2019 on AML/CFT applies to virtual assets broadly, the prohibition on the activity itself creates a compliance paradox (qa.licensing.the-qcb-has-also-been)
- No segregation, insurance, proof-of-reserves, or cold-storage rules exist because the activity is prohibited — any operation would be wholly unregulated and unprotected (qa.licensing.current-status-since-dedicated-crypto, qa.licensing.current-status-there-are-no)
- Qatar is a FATF member and applies UN sanctions — enforcement for unlicensed VASP activity could involve asset freezing and criminal penalties (qa.enforcement.legal-basis-qatar-implements-un)
- Tokenized securities (if structured as regulated securities) may be a narrow exception, but this would require a full QFC financial services license and is not a path for general crypto custody
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Rule 2.1.3(1) of the FSRU states: "A Firm must not undertake a Financial Service or other activity relating to a Virtual Asset."
The QFCRA Glossary defines "Virtual Asset" broadly as "any digital representation of value that can be digitally traded or transferred and used for payment or investment purposes, but does not include digital representations of fiat currencies, securities and other financial assets that are already covered by the QFCRA’s regulatory framework."
Current Status: There are no specific licenses for dedicated cryptocurrency custody businesses in Qatar. This is because the QFCRA prohibits firms from engaging in activities related to Virtual Assets, as detailed above.
Exceptions/Nuances: The prohibition explicitly excludes "digital representations of fiat currencies, securities and other financial assets that are already covered by the QFCRA’s regulatory framework." This means that if a tokenized security (e.g., a security issued on a blockchain) is regulated as a traditional security under QFCRA rules, then a licensed firm within the QFC could potentially custody such a tokenized security under its existing securities custody license. However, this is distinct from general cryptocurrency custody.
Current Status: Since dedicated crypto custody businesses are not licensed, there are no specific rules for the segregation of client cryptocurrency assets.
Current Status: There are no specific licenses for dedicated cryptocurrency custody businesses in Qatar. This is because the QFCRA prohibits firms from engaging in activities related to Virtual Assets, as detailed above.
Current Status: There is no specific regulatory definition for a "qualified custodian" for cryptocurrencies or digital assets in Qatar.
The QCB has also been a leader in implementing Law No. (20) of 2019 on Combating Money Laundering and Terrorist Financing, which, following FATF guidelines, includes virtual assets within its scope. This means that while direct licensing might be absent, any entity dealing with virtual assets (even if prohibited for most financial services firms) would be subject to strict AML/CFT obligations.
Law No. (20) of 2019 on Combating Money Laundering and Terrorist Financing: This is the foundational law establishing the AML/CFT framework, defining offenses, obligations for reporting entities, and the powers of regulatory and law enforcement bodies. It aligns Qatar's framework with the latest FATF Recommendations.
Natural Persons: Obtain and verify the customer's name, permanent address, date of birth, nationality, and official identification document number (e.g., QID, passport).
Legal Persons/Arrangements: Obtain and verify the entity's name, legal form, proof of incorporation/establishment, registered address, details of directors/senior management, and the full structure of ownership and control.
Beneficial Ownership Identification: Identify and verify the identity of the beneficial owner(s) – any natural person(s) who ultimately own or control 25% or more of the legal person, or on whose behalf a transaction is being conducted.
Source of Funds and Source of Wealth: For high-risk customers or transactions, obtain information on the source of funds (where the funds came from for a specific transaction) and the source of wealth (the overall economic activity that generates the customer's total net worth). This is particularly crucial in the virtual asset space.
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring for unusual or suspicious activities.
Politically Exposed Persons (PEPs): Implement procedures to determine if a customer or beneficial owner is a PEP. Apply enhanced due diligence (EDD) measures to PEPs, their family members, and close associates.
Sanctions Screening: Screen customers and transactions against national and international sanctions lists (e.g., UNSC sanctions).
Enhanced Due Diligence (EDD): Apply EDD for higher-risk scenarios, which often include:
Cross-border virtual asset transfers.
Report Suspicious Activity: Immediately report any transaction, attempted transaction, or funds where there are reasonable grounds to suspect that they are linked to money laundering or terrorist financing.
Reporting Body: All STRs must be submitted to the Qatar Financial Information Unit (QFIU).
No Tipping-Off: Prohibited from disclosing to the customer or any third party that a suspicious transaction report has been filed or that an investigation is underway.
Customer Identification Data: All records obtained during CDD, including identification documents, verification data, and beneficial ownership information.
Evidence fact qa.aml.transaction-records not found (may have been renamed).
Duration: Records must be maintained for a minimum of five (5) years from the date of the transaction or the end of the business relationship, whichever is later.
Legal Basis: Qatar implements UN Security Council Resolutions through its domestic legal framework, primarily Law No. 20 of 2019 on Combating Money Laundering and Terrorist Financing. This law mandates compliance with UN sanctions, including the freezing of funds and assets of designated individuals and entities.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Not permitted — QFCRA Rule 2.1.3(1) prohibits any firm from undertaking a financial service or activity relating to a Virtual Asset, which includes custodial wallet / SaaS operations, with no dedicated crypto custody license or qualified-custodian framework available; only narrow carve-outs for tokenized regulated securities exist.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?