Banking Law And Group-Wide Risk Management Kuwait .

1. Introduction

Group-wide risk management means identifying, measuring, monitoring and controlling risks across an entire banking group rather than examining only the licensed bank as a separate entity.

A Kuwaiti banking group may contain:

Parent bank → domestic subsidiaries → foreign subsidiaries → overseas branches → investment companies → finance companies → special-purpose entities → other controlled entities.

A weakness in one entity can affect the financial condition, liquidity, reputation or regulatory compliance of the rest of the group. Kuwait's framework therefore combines the Central Bank of Kuwait (CBK) Law, prudential instructions, corporate-governance requirements, consolidated supervision, capital and liquidity requirements, concentration controls, internal controls and cooperation with foreign supervisors.

An important statutory provision is Article 78 of Law No. 32 of 1968, which expressly permits the CBK to inspect branches, companies and banks operating abroad that are subsidiaries of Kuwaiti banks and provides for coordination with foreign banking supervisors.

2. Meaning of Group-Wide Risk

Suppose a Kuwaiti Bank A owns:

  • Finance Company B in Kuwait;
  • Bank C in another GCC state;
  • Investment Company D;
  • technology subsidiary E; and
  • several overseas branches.

Looking only at Bank A's individual balance sheet could produce an incomplete picture.

For example, Bank C could suffer major credit losses while Investment Company D holds highly leveraged positions. At the same time, Bank A might have guaranteed obligations of both companies.

A proper assessment therefore requires:

Entity-level risk + intra-group risk + consolidated exposure + contagion risk = group-wide risk assessment.

This is the central concept behind consolidated banking supervision.

3. Statutory Foundation — Law No. 32 of 1968

The principal banking legislation is Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business, as amended.

Article 71 gives the CBK authority to issue instructions to banks where necessary to ensure the sound progress of banking.

Article 72 permits the CBK to establish rules concerning liquidity and solvency, including ratios involving banks' own funds, liabilities, liquid assets, guarantees and acceptances.

These provisions provide the statutory foundation for extensive prudential supervision.

4. Article 78 and Consolidated Supervision

Article 78 is particularly significant for banking groups.

It authorises the CBK to inspect not only regulated banks and financial institutions in Kuwait but also:

branches, companies and banks operating abroad that are subsidiaries of Kuwaiti banks.

Such inspections are coordinated with the relevant foreign central bank or banking supervisory authority.

This means that supervision does not necessarily stop at Kuwait's geographical border.

For a Kuwaiti banking group:

Kuwaiti parent bank

Foreign subsidiary

Foreign branch

Relevant group risks

may all become important to CBK supervision.

5. Information Sharing Between Regulators

Group-wide risk management becomes especially difficult when subsidiaries operate in several countries.

Article 78 also permits information exchanges between the CBK and other central banks or banking supervisory authorities for the purposes of aggregate supervision of banks, branches and subsidiaries.

Thus, if a Kuwaiti bank owns an overseas banking subsidiary, the structure can involve:

CBK as home supervisor

Foreign regulator as host supervisor

Banking group

Such cooperation helps supervisors identify risks that would otherwise remain hidden within separate jurisdictions.

6. Role of the Board of Directors

Group-wide risk management begins with the board.

The CBK's corporate-governance framework places substantial responsibility on bank boards concerning governance and risk management. In its 2019 amendments, the CBK specifically reinforced risk-management governance and the role of boards, while also introducing compliance governance within the bank's overall risk-management framework.

The board should therefore understand not merely the parent bank's individual risks but the material risks created by the group's structure and activities.

A practical governance structure is:

Board of Directors

Board Risk Committee

Group Chief Risk Officer

Group Risk Management Function

Subsidiary risk functions

Business units

Consolidated reporting to senior management and board

7. Group Risk Appetite

A banking group should establish a risk appetite indicating how much risk it is prepared to accept while pursuing its strategy.

This may cover:

  • credit risk;
  • market risk;
  • liquidity risk;
  • interest-rate risk;
  • operational risk;
  • cyber risk;
  • concentration risk;
  • country risk;
  • compliance risk;
  • legal risk;
  • reputational risk; and
  • strategic risk.

The problem with a purely entity-level approach is that each subsidiary might remain within its individual limit while the group as a whole becomes excessively exposed to the same risk.

8. Example of Group Concentration

Assume:

Bank A lends KWD 40 million to Corporate Group X.

Its subsidiary lends another KWD 25 million.

A foreign banking subsidiary provides KWD 20 million.

An investment subsidiary purchases KWD 15 million of bonds issued by X.

Examined separately, each exposure might appear manageable.

But group-wide exposure is:

40 + 25 + 20 + 15 = KWD 100 million.

Group-wide risk management therefore requires aggregation of connected exposures where required by the applicable prudential framework.

9. Centralised Risk Information

Article 83 permits the CBK to establish a Centralized Risks System. Its purposes include helping banks evaluate the financial positions of persons seeking credit and enabling the CBK to monitor banking-credit trends.

The CBK's Surveillance Department also analyses financial statements, identifies risks affecting banking and financial sectors, monitors sector-wide risk trends and cooperates with foreign regulators concerning consolidated supervision and information exchange.

This illustrates an important principle:

Effective risk management requires reliable consolidated information.

10. Credit Risk

Credit risk is the possibility that a borrower or counterparty will fail to perform its obligations.

At group level, banks need to consider whether apparently separate exposures are economically connected.

For example:

Company A owns Company B

Company B guarantees Company C

Company C depends on Company A for revenue.

Treating all three as completely independent could underestimate the group's real economic exposure.

Consequently, connected-counterparty analysis is important to consolidated credit-risk management.

11. Liquidity Risk

Liquidity risk is another major group-wide issue.

A parent bank may appear liquid while a foreign subsidiary experiences a serious liquidity shortage.

The group must consider:

  • where liquidity is located;
  • whether funds can legally be transferred;
  • currency mismatches;
  • collateral availability;
  • foreign regulatory restrictions;
  • intra-group funding;
  • emergency liquidity requirements; and
  • stress conditions.

Thus:

Group liquidity ≠ simply adding all cash balances together.

Some liquidity can be trapped within subsidiaries or jurisdictions.

12. Market Risk

Group-wide market risk includes exposures to:

interest rates + foreign currencies + securities prices + commodity-related exposures + other market variables.

A subsidiary might hold a position that offsets or amplifies a position held by the parent.

Therefore, consolidated risk systems should identify both:

gross exposure

and, where legally and prudentially appropriate,

net exposure.

13. Operational Risk

A banking group may share:

  • IT infrastructure;
  • data centres;
  • payment systems;
  • employees;
  • outsourcing providers;
  • cybersecurity infrastructure;
  • compliance systems; and
  • business-continuity facilities.

This creates interdependence.

A cyber incident affecting one common technology provider can potentially disrupt several entities simultaneously.

Group-wide operational-risk management therefore requires the bank to understand common dependencies, not merely incidents occurring within each individual legal entity.

14. Intra-Group Transactions

Intra-group transactions can create significant contagion risk.

Examples include:

  • parent-to-subsidiary loans;
  • subsidiary deposits with parent;
  • guarantees;
  • derivatives;
  • asset transfers;
  • management-service arrangements;
  • shared technology;
  • cross-collateralisation; and
  • capital support.

Consider:

Parent Bank → KWD 100 million loan → Subsidiary

and

Parent Bank → guarantee of subsidiary debt.

If the subsidiary fails, the parent may suffer both the direct credit exposure and the guarantee exposure.

Group-wide systems should therefore prevent risks from being hidden through internal transactions.

15. Related-Party and Conflict Risk

Banking groups can also create conflicts of interest.

A bank might provide favourable financing to:

  • controlling shareholders;
  • directors;
  • affiliated companies;
  • sister companies; or
  • other related parties.

Article 69 of the CBK Law specifically restricts loans, advances and guarantees in favour of bank directors without prior General Assembly permission and requires such transactions to be subject to the conditions and rules applied to other customers.

This illustrates the wider principle that group relationships must not undermine prudent credit decision-making.

16. Capital Adequacy

A banking group requires sufficient capital to absorb losses.

Group-wide capital assessment prevents a group from creating the appearance of strong capital through repeated use of the same capital resources across different entities.

Conceptually:

Parent capital → subsidiary investment → subsidiary capital

should not automatically be treated as two completely independent layers of loss-absorbing capital at consolidated level.

This is why regulatory consolidation is critical.

The CBK's conventional-bank instructions cover prudential subjects including liquidity, credit concentration, financial statements and credit classification.

17. Islamic Banking Groups

Group-wide risk management also applies to Islamic banking groups.

Article 97 authorises the CBK Board to establish rules for Islamic banks concerning:

  • liquidity;
  • solvency;
  • capital adequacy;
  • asset-risk provisioning; and
  • organisation of business.

Article 98 also permits limits relating to activities, equity holdings in companies and participation in individual projects.

Islamic banking groups may additionally need to manage risks arising from Sharia-compliant structures and investment arrangements.

18. Complex Group Structures

Complexity can itself create risk.

Consider:

Bank


Holding Company


Finance Subsidiary


SPV


Foreign Subsidiary


Joint Venture

As the number of layers increases, it can become harder for the board, risk function, auditors and regulator to understand where risks are located.

The CBK corporate-governance framework expressly addresses group structures and banks with complex structures as governance subjects. Kuwaiti banks' published governance frameworks reflect these requirements.

19. Three Lines of Defence

A practical group risk-management system commonly uses three levels.

First line — Business functions

Business units originate and manage risks.

Second line — Risk and compliance

Independent risk-management and compliance functions establish frameworks, monitor limits and challenge business decisions.

Third line — Internal audit

Internal audit independently evaluates whether governance, controls and risk-management processes operate effectively.

The board ultimately remains responsible for ensuring that these arrangements function adequately.

20. Stress Testing

Group-wide stress testing asks what would happen if several risks occurred simultaneously.

For example:

Oil-price shock

economic slowdown

corporate defaults

property-price decline

credit losses

foreign subsidiary losses

liquidity pressure

capital deterioration.

Testing only one subsidiary at a time could fail to reveal this chain reaction.

Group-wide stress testing therefore attempts to identify correlated losses and contagion.

21. Recovery Planning

Group-wide risk management should also consider severe financial distress.

A recovery plan may examine:

  • capital raising;
  • asset sales;
  • reduction of risk-weighted assets;
  • liquidity generation;
  • disposal of subsidiaries;
  • restrictions on dividends;
  • reduction of exposures;
  • contingency funding; and
  • operational continuity.

The critical question is not merely:

“Can the parent survive?”

It is also:

“Can the banking group continue performing critical functions during severe stress?”

22. Role of the CBK

The CBK's supervisory functions include preparing prudential regulations, analysing information submitted by regulated entities, conducting inspections, identifying emerging problems and aligning supervisory procedures with international standards.

Its surveillance function additionally monitors systemic risk and cooperates with host-country regulators on consolidated supervision.

Therefore:

Bank manages risk internally

while

CBK supervises whether the framework is adequate and prudential requirements are satisfied.

23. Case Law

A qualification is important. There is not a large publicly accessible body of Kuwaiti Court of Cassation judgments specifically deciding modern “group-wide risk management” or Basel consolidated-supervision disputes.

It would therefore be inaccurate to describe ordinary loan cases as direct group-risk-management precedents. The following Kuwait authorities provide analogous judicial principles relevant to banking regulation, group entities, corporate personality, contractual exposures and regulated financial activity.

Case 1 — Kuwait Court of Cassation, Appeal No. 508/2016

Facts and issue

The dispute concerned a bank loan, changes in interest and the relationship between contractual terms and CBK requirements.

Principle

The case illustrates that banking relationships do not operate exclusively according to private contractual terms. Applicable CBK regulation must also be considered.

Group-wide risk relevance

A banking group cannot justify a risky intra-group transaction merely by saying that the transaction is contractually valid.

A transaction may simultaneously engage:

contract law + banking regulation + prudential requirements.

Thus, group risk policies must take regulatory limits into account even where every group entity has formally agreed to the transaction.

Case 2 — Kuwait Court of Cassation, Appeal No. 1180/2009

Issue

This authority concerned banking lending and CBK requirements affecting interest rates.

Principle

Mandatory banking regulation can constrain private contractual arrangements.

Group-wide relevance

Suppose a parent bank establishes a common lending policy for all subsidiaries.

Internal group policy cannot override mandatory requirements applicable to the regulated entity.

Therefore:

Group policy < mandatory banking regulation.

This becomes particularly important where different subsidiaries operate in different jurisdictions.

Case 3 — Kuwait Court of Cassation, Appeal No. 1384/2019

Judgment of 22 February 2024

The Court addressed loans granted by banks in the ordinary course of banking activity.

Principle

Loans made by banks as part of ordinary banking activity are commercial banking transactions regardless of the borrower's status or ultimate purpose.

Group-risk relevance

A bank's exposure does not lose its banking character merely because financing is channelled to:

  • an affiliate;
  • corporate subsidiary;
  • project company; or
  • another commercial undertaking.

Risk-management systems should therefore analyse the economic substance of financing exposures rather than relying only upon labels.

Case 4 — Kuwait Court of Cassation, Appeal No. 3656/2023

Judgment of 11 June 2024

Issue

This case involved a banking-loan relationship, closure of the relevant loan account and calculation of amounts claimed.

Principle

The contractual and statutory framework, together with reliable financial evidence, is important when establishing amounts arising from a banking relationship.

Group-wide relevance

A banking group should be able to reconstruct its exposures:

Entity → counterparty → facility → principal → interest/profit → collateral → guarantee → outstanding amount.

Without reliable group data, management cannot accurately determine consolidated exposure.

The case is therefore useful by analogy for the importance of reliable financial records, although it was not itself a consolidated-risk case.

Case 5 — Kuwait Court of Cassation, Appeal No. 14/2022

Judgment of 23 September 2025

Issue

The case concerned investment arrangements entered into without the necessary financial regulatory authorisation.

Principle

The Court treated relevant mandatory financial-sector requirements as connected with economic public order, with significant consequences for activities conducted without required authorization.

Group-wide relevance

A banking group cannot circumvent regulation simply by moving an activity into:

subsidiary → affiliate → SPV → related company.

Each entity's actual activity and applicable licensing framework must be considered.

Group structure therefore cannot legitimately be used to disguise regulated activity.

Case 6 — Kuwait Court of Cassation, Commercial Appeal No. 808/2000

Judgment of 16 June 2001

This authority has been cited in Kuwaiti banking-law discussions concerning bank lending and contractual/statutory interest.

Principle

Banking financial obligations must be determined within the applicable contractual and statutory framework.

Group-wide relevance

Where a banking group has numerous intercompany loans, deposits and financing arrangements, the legal terms governing each exposure remain important.

Consolidation for risk-management purposes does not erase the underlying legal obligations of individual companies.

This creates an important distinction:

Accounting/risk consolidation ≠ disappearance of separate legal obligations.

Case 7 — Kuwait Court of Cassation, Civil Appeal No. 479/2004

Judgment of 19 September 2005

The dispute involved a banking current account and the interest applicable after closure of the account.

Principle

The legal status and maturity of a banking obligation can affect the financial consequences attached to it.

Group-wide relevance

Accurate group-risk measurement requires exposures to be correctly classified according to their legal and financial characteristics.

For example:

performing loan ≠ defaulted exposure ≠ guarantee ≠ derivative ≠ closed current account balance.

An inaccurate classification can distort consolidated risk information.

Case 8 — Kuwait Court of Cassation, Appeal No. 449/2006

Judgment of 20 January 2009

This case is useful for the cross-border dimension of banking groups.

The Court considered the law applicable to the legal status of a foreign company and applied the law associated with the company's principal effective place of management.

Group-wide relevance

A Kuwaiti banking group may own subsidiaries incorporated and operating abroad.

Those entities may therefore be affected by:

Kuwait consolidated supervision

plus

foreign company law

plus

host-state banking regulation.

Group-wide risk management must recognise these overlapping legal systems.

24. Separate Legal Personality Versus Consolidated Supervision

One of the most important concepts is the distinction between corporate law and prudential supervision.

Suppose:

Kuwaiti Bank A owns 100% of Subsidiary B.

Under company law, B ordinarily remains a separate legal person.

But for prudential purposes, regulators may still need to examine A and B together.

Therefore:

Separate legal personality does not prevent consolidated risk supervision.

Conversely:

Consolidated supervision does not automatically abolish separate legal personality.

This distinction is crucial when analysing guarantees, insolvency, intra-group loans and liability.

25. Practical Group-Wide Risk Framework

A well-managed Kuwaiti banking group can structure the process as follows:

Step 1 — Map the group

Identify parent, branches, subsidiaries, affiliates, SPVs and material investments.

Step 2 — Identify risks

Credit, market, liquidity, operational, legal, compliance, cyber, concentration, country and reputational risks.

Step 3 — Aggregate exposures

Identify connected counterparties and intra-group exposures.

Step 4 — Establish limits

Set entity and consolidated risk limits.

Step 5 — Monitor

Produce reliable and timely risk reports.

Step 6 — Stress test

Assess severe but plausible scenarios.

Step 7 — Escalate breaches

Material limit breaches should reach senior management and, where appropriate, the board.

Step 8 — Correct

Reduce exposures, increase capital/liquidity, hedge risks or change business strategy.

Step 9 — Report

Provide appropriate information to the CBK and other supervisors.

26. Example

Assume Kuwait Bank K has:

EntityRisk exposure
Parent bankKWD 200m
Kuwait finance subsidiaryKWD 75m
Foreign bank subsidiaryKWD 100m
Investment subsidiaryKWD 50m

Looking only at the parent produces an apparent exposure of:

KWD 200 million.

But the relevant consolidated economic exposure could potentially reach:

KWD 425 million

before considering eliminations, guarantees, hedges, regulatory treatment and other applicable adjustments.

If all entities are exposed to the same corporate group or economic sector, the risk may be substantially more concentrated than the parent's standalone balance sheet suggests.

27. Cross-Border Supervision

Cross-border banking groups create an additional layer:

Home supervisor — CBK

Kuwaiti parent

Foreign subsidiary

Host supervisor

Article 78 expressly provides the statutory basis for CBK inspection of foreign subsidiaries of Kuwaiti banks and regulatory coordination.

Historically, international assessments have nevertheless identified areas in which Kuwait's consolidated and cross-border supervisory framework could be strengthened, particularly formalisation of powers concerning group entities and deeper cooperation with foreign supervisors.

That historical assessment should not automatically be treated as a description of every aspect of the framework in 2026, because supervisory practices and rules can develop over time.

28. Why Group-Wide Management Matters

A bank can be individually sound while its wider group contains serious vulnerabilities.

For example:

Foreign subsidiary suffers losses

Parent provides emergency funding

Parent liquidity declines

Credit rating deteriorates

Funding becomes expensive

Depositor/market confidence weakens

Entire group comes under pressure.

This is called contagion risk.

The purpose of group-wide supervision is partly to identify this chain before losses threaten the regulated bank.

29. Key Legal Principles

The Kuwait framework can therefore be summarised through several principles:

  1. The board retains responsibility for effective risk governance.
  2. Risk should be considered across material group entities, not merely the parent bank.
  3. Foreign subsidiaries can fall within the CBK's consolidated supervisory reach.
  4. Credit, liquidity, market, operational and concentration risks should be aggregated appropriately.
  5. Intra-group transactions can create contagion and conflicts of interest.
  6. Separate corporate personality does not prevent consolidated prudential supervision.
  7. Consolidated supervision does not automatically make the parent legally liable for every subsidiary obligation.
  8. Mandatory regulatory requirements cannot be avoided merely through contractual or corporate structuring.
  9. Reliable consolidated data are essential to effective risk management.
  10. Cross-border groups require cooperation between home and host regulators.

30. Conclusion

Group-wide risk management is a fundamental component of banking supervision in Kuwait. Its statutory foundation is particularly visible in Law No. 32 of 1968, including Articles 71, 72 and 78. Article 78 is especially significant because it permits CBK inspection of overseas branches, companies and banks that are subsidiaries of Kuwaiti banks and facilitates information exchange with foreign supervisors for aggregate supervision.

The CBK's corporate-governance framework reinforces this structure by emphasising board responsibility, risk-management governance, compliance governance, internal controls and appropriate oversight of group and complex corporate structures.

In practical terms, the framework is:

Board oversight → group risk appetite → consolidated identification → exposure aggregation → capital and liquidity management → internal controls → stress testing → reporting → CBK consolidated supervision.

The Kuwait Court of Cassation cases discussed above should be used carefully. They do not constitute eight direct judgments on Basel-style group-wide risk management. Rather, they establish or illustrate surrounding principles involving mandatory banking regulation, regulated financial activities, lending obligations, financial evidence, foreign companies and the relationship between private banking arrangements and the supervisory framework. Those principles provide the judicial background against which Kuwait's statutory and regulatory system of group-wide risk management operates.

 

 

LEAVE A COMMENT