Most of the commentary on Qatar's new governance code for listed companies has been about the board: a 7–11 member range, ESG indicators, a sustainability report, a new risk and compliance committee. For a Chief Audit Executive, the more consequential changes sit in two places the headlines skipped — the article on the board's committees and the chapter on internal control.
This is what the Code says about the audit committee and internal audit, what is genuinely new compared with 2016, and what it does not say.
The instrument
QFMA Board Decision No. 5 of 2025 issued the Governance Code for Listed Companies. It was signed on 4 August 2025, published in the Official Gazette on 17 August 2025, and took effect the following day. It repeals the 2016 Code for companies listed on the Main Market.
Main Market companies must comply in full. Companies on the secondary market apply it on a comply-or-explain basis. The decision gave companies one year from publication to bring themselves into line — a window that ran to August 2026 and that QFMA's chairman has the power to extend.
The official English translation notes that the Arabic text prevails where the two differ. Where a provision below matters to how you run your function, read it in Arabic.
The audit committee, as the Code now defines it
The Code makes three board committees mandatory: Audit; Risk Management and Compliance; and Nomination, Remuneration and Incentives. Each is made up of board members only, and the audit committee's duties may not be merged with any other committee's.
| Requirement | What the 2025 Code sets |
|---|---|
| Size | Set by the board, minimum three members |
| Chair | Must be an independent board member |
| Independence | A majority of members must be independent |
| Expertise | Members must have financial, accounting and auditing experience |
| Exclusivity | An audit committee member may not sit on any other committee |
| Board chair | May not sit on any of the mandatory committees |
| Meetings | At least four a year, with minutes |
The committee's duties are concrete. It reviews internal audit, external audit and regulator reports and follows up on remediation; reviews the effectiveness of internal control and of financial control and accounting practices; reviews and approves interim and annual financial statements before they reach the board; and recommends the external auditor's appointment, fees and scope.
On internal audit specifically, it recommends to the board the selection, appointment and termination of the Internal Audit Director, the function's budget, and the evaluation of its staff. The board approves the appointment. And the committee reviews and approves the audit plan every year.
The reporting line is now unambiguous
Under the 2016 Code, the internal auditor was appointed by the board and answerable to it. The 2025 Code is more specific, and it lines up with how the IIA Standards describe independence:
- Internal audit staff are independent of senior management in their appointment, performance evaluation, and pay and incentives.
- They report directly to the audit committee, which also oversees their qualifications and training.
- The Internal Audit Director reports to the committee at least quarterly on the scope of audit work, findings and violations, the actions taken, and accountability.
- The Director informs management of findings and follows them up.
The provision to read in Arabic first
Article 7 also asks the CEO, the Internal Audit Director and the external auditor to certify that the quarterly, semi-annual and annual financial statements give a true and fair view, and refers to effective internal controls over the financial reporting process.
Read literally in the English translation, that puts the head of internal audit alongside management on a financial-statement certification. The IIA Standards expect internal audit to stay objective and not to take on management responsibilities, so how a Director satisfies this matters. Before building a process around it, read the Arabic text, agree the interpretation with the audit committee, and record it in the internal audit charter.
What is genuinely new — and what isn't
| Topic | 2016 Code | 2025 Code |
|---|---|---|
| Audit committee meetings | At least six a year | At least four a year — a lower floor |
| Committee exclusivity | Only the audit committee chair barred from other committees | Every audit committee member barred |
| Member expertise | "Necessary experience" | Financial, accounting and auditing experience |
| Risk oversight | Within the audit committee's duties | Moved to a separate Risk Management and Compliance Committee |
| Internal audit reporting line | Appointed by, and answerable to, the board | Reports directly to the audit committee; independent of management on hiring, evaluation and pay |
| Annual audit plan | No equivalent provision | Audit committee reviews and approves it each year |
| Escalation to QFMA | Not in the Code | Internal Audit Director notifies QFMA of serious violations |
| Quarterly reporting to the committee | Required | Retained |
Two continuities are worth noting. The external auditor still reports on the adequacy and effectiveness of internal control and on compliance with the Code, to the General Assembly and to QFMA. And the annual governance report must still disclose internal control deficiencies — in whole or in part — and how they were remediated.
The move of risk oversight into a separate committee, with its own Chief Risk Officer and Chief Compliance Officer, is the boundary worth being clear about. Those are management's second-line functions. The audit committee coordinates with the risk committee; internal audit gives independent assurance over what both oversee.
What the Code does not say
Several things are commonly attributed to it that the text does not support:
- It does not reference the IIA Standards, require an internal audit charter, or require an external quality assessment. Those obligations come from the Standards themselves if the function claims conformance.
- It does not require an ICOFR or SOX-style audit opinion on internal control over financial reporting.
- It does not make whistleblowing an audit committee duty. Reports go to the board chair or a committee the chair authorises, or directly to QFMA.
- The audit committee does not appoint the Internal Audit Director. It recommends; the board approves.
What this means for how the function is run
None of these requirements is hard to agree with. The work is in evidencing them on demand: that the committee approved this year's plan, that every quarterly report covered scope, findings, actions and accountability, that a serious violation was assessed and escalated (or assessed and not), and that the Director's evaluation and pay sat outside management's hands.
A function running on spreadsheets and email can assert all of that. An audit management system built around the audit committee — where the plan approval, the quarterly pack and the finding history come from the same record — can show it. That is the gap ControlVista's audit management software for Qatar is designed to close.
Sources
- QFMA, Board Decision No. (5) of 2025 Concerning the Issuance of Governance Code for Listed Companies — official English translation, hosted by ECGI: governance-code-for-listed-companies-2025.pdf
- QFMA, Governance Code for Companies and Legal Entities Listed on the Main Market (2016) — official English translation, hosted by ECGI: 2016 Code
- Charles Russell Speechlys, "The new Corporate Governance Code for listed companies" (September 2025): article
