Banking Law And Operational Risk Regulation Kuwait .

Banking Law and Operational Risk Regulation in Kuwait

1. Introduction

Operational risk regulation in Kuwait forms an important part of the supervisory framework administered by the Central Bank of Kuwait (CBK). It addresses the possibility of losses arising from inadequate or failed internal processes, people, systems, technology, or external events.

CBK's operational-risk instructions expressly recognize risks arising from electronic data processing, e-banking, security breaches, internal and external fraud, misuse of customer information, money laundering, supplier disputes, natural disasters and legal risks.

The framework is therefore much wider than merely "IT risk."

A useful formula is:

Operational Risk = People + Processes + Systems + External Events + Legal/Compliance Failures

For Kuwaiti banks, operational-risk management is connected with:

  • Law No. 32 of 1968 concerning the Currency, Central Bank of Kuwait and Organization of Banking Business;
  • CBK supervisory instructions;
  • internal-control requirements;
  • corporate-governance rules;
  • capital-adequacy requirements;
  • cybersecurity and electronic-banking controls;
  • AML/CFT requirements;
  • business-continuity arrangements;
  • customer-protection requirements.

2. Legal Foundation: Law No. 32 of 1968

The principal banking statute is Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organization of Banking Business, as amended.

The law gives CBK extensive regulatory and supervisory powers over banks.

Article 54 defines banking activity broadly, including receiving deposits, granting loans, issuing and collecting cheques, foreign-exchange activities and other banking operations.

This broad definition matters because operational risk can arise across practically every banking function.

3. CBK's Supervisory Powers

CBK's supervisory framework allows it to monitor banks':

  • financial condition;
  • internal controls;
  • risk management;
  • governance;
  • compliance;
  • operational systems.

Article 82 requires banks to provide CBK with requested data, information and statistics, subject to the confidentiality rules established by the law.

Article 84 is particularly relevant to operational risk because the external auditor's annual report must address the adequacy of the internal-control systems applied by the bank.

This demonstrates that internal control is not simply an optional management practice; it is part of the regulatory architecture.

4. CBK's Definition of Operational Risk

CBK's instructions adopt the Basel-oriented concept of operational risk.

Operational risk is essentially the risk of loss resulting from:

  1. inadequate or failed internal processes;
  2. inadequate or failed personnel;
  3. inadequate or failed systems; or
  4. external events.

CBK specifically identifies:

  • electronic-data-processing risks;
  • electronic-banking risks;
  • security/confidentiality breaches;
  • internal and external fraud;
  • misuse of customer information;
  • risks arising from mergers and system changes;
  • money-laundering risks;
  • illegal activities;
  • physical damage;
  • natural disasters;
  • supplier disputes;
  • employment claims; and
  • legal risks. 

5. Operational-Risk Management Framework

CBK requires banks to establish an operational-risk-management framework covering the risks arising from their activities.

The framework should contain policies and procedures for:

FunctionPurpose
IdentificationFind operational risks
AssessmentDetermine probability and impact
MonitoringTrack risk exposures
ControlReduce or prevent losses
MitigationReduce consequences
ReportingInform management/board
ReviewIndependently assess controls

CBK's instructions state that the board or senior management must be informed of deviations resulting from non-compliance with established policies. Senior management must ensure consistent application of operational-risk systems and continuously monitor significant exposures.

6. Board and Senior Management Responsibility

Operational risk is ultimately a governance issue.

The board should establish an appropriate risk-management structure, while senior management implements it.

CBK's governance framework has been developed to strengthen the role of boards and board committees. In 2019, CBK amended its corporate-governance rules to introduce independent directors into bank boards and board committees.

This is important because operational failures frequently arise from governance weaknesses rather than from technology alone.

For example:

Board failure to understand cyber risk

↓

Insufficient investment

↓

Weak controls

↓

Fraud/system failure

↓

Customer and bank losses

7. Internal Control

Internal control is one of the central pillars of operational-risk regulation.

A bank should maintain controls concerning:

  • authorization;
  • segregation of duties;
  • reconciliation;
  • transaction monitoring;
  • access rights;
  • employee supervision;
  • audit;
  • fraud detection;
  • information security;
  • reporting.

Article 84 specifically requires the auditor to express an opinion on the adequacy of the bank's internal-control systems.

8. Operational Risk and Capital Adequacy

Operational risk is also connected to capital adequacy.

CBK recognizes that a bank's exposure cannot always be adequately represented merely through a simple income-based measurement because operational risk may arise from:

  • system failures;
  • electronic-security intrusions;
  • internal/external embezzlement;
  • particular products;
  • particular services.

Banks must therefore use a methodology appropriate to the complexity and diversification of their activities and consider whether capital is sufficient to cover operational risk.

This represents an important principle:

Operational risk can create financial loss and therefore must be reflected in the bank's risk-bearing capacity.

9. Legal Risk

CBK expressly treats legal risk as part of operational risk.

Legal risk can result from:

  • inability to enforce contracts;
  • inadequate documentation;
  • missing customer authorizations;
  • unsigned contracts;
  • defective legal arrangements;
  • regulatory non-compliance.

CBK's instructions expressly identify losses resulting from the bank's inability to enforce contracts or other rights as legal risks.

Thus:

Operational risk → Legal risk → Financial loss

is a recognized regulatory relationship.

10. Electronic Banking and Technology Risk

The growth of:

  • mobile banking;
  • internet banking;
  • electronic transfers;
  • digital payments;
  • APIs;
  • electronic authentication;

has increased operational risk.

CBK's framework specifically identifies electronic-data processing, e-banking and systems-security risks as operational risks.

Banks therefore need:

  • access controls;
  • authentication;
  • encryption;
  • transaction monitoring;
  • system redundancy;
  • cybersecurity;
  • incident-response procedures;
  • backup systems;
  • recovery plans.

11. Fraud Risk

Fraud is explicitly recognized within Kuwait's operational-risk framework.

Fraud can be:

Internal

Committed by:

  • employees;
  • managers;
  • officers;
  • insiders.

External

Committed by:

  • hackers;
  • customers;
  • organized criminals;
  • fraudulent counterparties.

The regulatory response should include:

  • segregation of duties;
  • authorization controls;
  • transaction monitoring;
  • employee screening;
  • whistleblowing mechanisms;
  • audit;
  • fraud analytics.

12. Outsourcing Risk

Modern Kuwaiti banks may rely on:

  • cloud services;
  • payment processors;
  • IT vendors;
  • cybersecurity providers;
  • telecommunications networks;
  • software suppliers.

Outsourcing does not eliminate the bank's responsibility for managing the resulting operational risk.

CBK has historically emphasized the need for governance and risk monitoring concerning activities outsourced by banks.

A bank therefore needs:

  1. vendor due diligence;
  2. contractual safeguards;
  3. service-level requirements;
  4. audit rights;
  5. cybersecurity requirements;
  6. contingency arrangements;
  7. monitoring;
  8. exit/transition plans.

13. Business Continuity

Operational-risk regulation necessarily includes continuity planning.

A bank should be able to continue critical operations despite:

  • cyberattacks;
  • power failures;
  • telecommunications failures;
  • natural disasters;
  • system failures;
  • pandemics;
  • geopolitical emergencies;
  • supplier failures.

CBK stated in March 2026 that Kuwaiti banks had strengthened risk-management systems, business-continuity and emergency plans, digital infrastructure and regular drills to maintain continuity during emerging circumstances.

This provides a contemporary example of how operational resilience is being treated by the regulator.

14. Exceptional Circumstances

Article 75 of the Central Bank Law provides that where exceptional circumstances threaten banking operations, the CBK Governor, with the required approval, may order banks temporarily to close and suspend operations; reopening is then subject to the statutory procedure.

This provision illustrates that operational stability is regarded as a matter of broader financial-system importance rather than merely a private contractual issue between a bank and its customers.

15. Islamic Banks

Operational-risk regulation also applies to Islamic banks.

CBK maintains separate instructions for Islamic banks, including instructions concerning:

  • internal control;
  • risk management;
  • customer relationships;
  • AML/CFT;
  • governance;
  • Sharia supervisory arrangements. 

Article 93 of the Central Bank Law requires each Islamic bank to have an independent Sharia Supervisory Board consisting of at least three members.

Accordingly, Islamic banks have an additional layer of governance risk:

ordinary operational risk + Sharia-compliance risk.

16. Operational Risk and Customer Protection

Operational failures can directly affect customers.

Examples include:

  • unauthorized withdrawals;
  • erroneous transfers;
  • ATM failures;
  • card-processing errors;
  • account-access failures;
  • disclosure of confidential information;
  • payment-system disruptions.

Therefore, operational-risk controls also protect customers.

This is especially significant in electronic banking, where a technical failure may immediately affect thousands of customers.

17. Operational Risk and Confidentiality

Banking information is highly sensitive.

Article 83 establishes the Centralized Risks System and restricts disclosure of information obtained through that system. Unauthorized disclosure may attract imprisonment, a fine or both, together with dismissal from employment under the provision.

This demonstrates that information security has both:

  • regulatory significance, and
  • potential legal/penal consequences.

18. Regulatory Sanctions

Article 85 provides CBK with several measures where a bank violates the Central Bank Law, CBK instructions or related requirements.

Possible measures include:

  1. warning;
  2. financial penalties;
  3. temporary suspension of certain operations;
  4. prohibition of particular activities;
  5. removal/replacement of responsible senior employees;
  6. determining that a responsible board member is unfit for board membership. 

This is important because operational-risk regulation is enforceable.

19. Criminal Dimension

Operational-risk failure does not automatically constitute a crime.

There is a distinction between:

Regulatory failure

Example:

A bank fails to maintain an adequate operational-risk framework.

Possible result:

  • CBK enforcement;
  • corrective measures;
  • financial penalties;
  • restrictions.

Criminal conduct

Example:

An employee deliberately manipulates bank records to steal customer funds.

Possible result:

  • criminal prosecution;
  • imprisonment;
  • fine;
  • civil compensation.

The facts must satisfy the elements of the particular offence.

20. Case Law

Kuwaiti reported case law does not generally use the modern Basel terminology of "operational risk" in the way regulatory documents do. Consequently, the most useful cases are those dealing with banking controls, forged instruments, payment authentication, employee conduct and bank liability.

Case 1 — Kuwait Court of Cassation, Commercial Appeal Nos. 503 & 515/2002, Judgment 26 April 2003

The Kuwait Court of Cassation recognized that the trial court has authority to assess evidence concerning alleged forgery and is not necessarily required to conduct a separate investigation when it considers the forgery allegation unsupported by sufficient evidence.

Significance

The case demonstrates the importance of evidentiary controls and documentary integrity in banking disputes.

Operational-risk connection

Banks should maintain:

  • reliable records;
  • original documents;
  • audit trails;
  • authentication evidence;
  • transaction documentation.

These records become critical when a customer disputes a transaction.

 

21. Case 2 — Kuwait Court of Cassation, Commercial Appeal No. 856/2002, Judgment 12 November 2003

The Court of Cassation reiterated principles concerning judicial assessment of evidence in forgery disputes.

The case is significant because it recognizes the court's ability to determine whether the documentary evidence establishes forgery without automatically requiring every proposed investigative procedure.

Operational-risk significance

A bank's internal records and authentication procedures can become crucial evidence in determining whether a transaction was genuine.

This reinforces the importance of:

  • recordkeeping;
  • document controls;
  • signature verification;
  • transaction histories.

 

22. Case 3 — Kuwait Court of Cassation, Commercial Appeals Nos. 503 & 515/2002

In the banking-forgery jurisprudence, the Court emphasized that the court may evaluate the available evidence of forgery and determine whether the alleged alteration has been established.

Legal principle

The existence or absence of a separate technical investigation does not automatically determine the outcome; the decisive issue is whether the evidence establishes the relevant facts.

Operational-risk relevance

Banks therefore need reliable evidence capable of demonstrating:

  • who authorized a transaction;
  • how the authorization was verified;
  • what documents were presented;
  • what employees did;
  • what system controls operated.

 

23. Case 4 — Kuwait Court of Cassation, Criminal Case Concerning Forged Bank Instruments and Bank of Kuwait Finance House

A significant criminal decision concerned forged cheques and transfer instructions presented to Kuwait Finance House.

The Court held that where bank employees accepted and processed a forged instrument, the document could qualify as a bank document for purposes of the relevant forgery provision because the employee's intervention and approval formed part of the banking process.

The case involved forged signatures and banking transfer documentation, and the Court upheld the legal characterization of the forgery.

Operational-risk significance

This case is highly relevant to:

  • payment authorization;
  • employee controls;
  • transaction verification;
  • segregation of duties;
  • fraud prevention.

It shows that operational controls around payment processing have legal consequences.

24. Case 5 — Kuwait Court of Cassation, Criminal Appeal No. 209/2012, Judgment 14 April 2013

The Court dealt with forgery of bank documents and held that the offence is established by intentional alteration of truth through legally recognized means with the intention of using the document for its altered purpose, where the alteration is capable of causing harm.

The Court also emphasized that actual eventual loss is not necessarily required where the legally relevant potential for harm already exists.

Operational-risk significance

This is important for preventive controls.

A bank should not wait until actual financial loss occurs before treating suspicious document manipulation as a serious operational event.

25. Case 6 — Kuwait Court of Cassation, Commercial Banking Forged-Cheque Jurisprudence

The Court of Cassation has also developed principles concerning liability where a bank pays a forged cheque.

The Court has recognized, under the relevant Kuwaiti commercial-law provisions, that the drawee bank can bear the loss resulting from payment of a cheque carrying a forged drawer's signature, subject to the customer's own fault or negligence and the particular circumstances of the transaction.

Operational-risk significance

This directly illustrates the relationship:

authentication failure → improper payment → financial loss → allocation of liability.

The case law therefore complements CBK's regulatory emphasis on internal controls and operational-risk management.

26. Case 7 — Kuwait Court of Cassation, Forged Cheques and Bank Transfer Instructions

Another reported Court of Cassation decision involved forged cheques and transfer orders presented through Bank of Kuwait and Gulf Bank processes.

The Court emphasized that where bank personnel intervene in accepting and processing documents, the banking character of the documents and the associated forgery consequences can become legally significant.

Relevance

This demonstrates why banks need effective:

  • maker-checker controls;
  • employee authorization limits;
  • signature verification;
  • transaction monitoring;
  • fraud escalation procedures.

27. Case 8 — Qatar Court of Cassation: Comparative Caution

A reported decision concerning forged cheques established a principle that the drawee bank normally bears responsibility for payment on a forged signature where the customer's own serious fault is not established.

However, this particular decision is Qatari, not Kuwaiti.

It should therefore be used only as comparative Gulf banking jurisprudence, not as Kuwaiti precedent.

This distinction is important in academic work.

28. Case-Law Table

AuthoritySubjectOperational-risk lesson
Kuwait Cassation, Commercial Appeals 503 & 515/2002Forgery evidenceDocument controls
Kuwait Cassation, Commercial Appeal 856/2002Evidence of forgeryAudit/document reliability
Kuwait Cassation, Criminal forgery caseForged bank instrumentsEmployee/payment controls
Kuwait Cassation, Criminal Appeal 209/2012Forgery of bank documentsPreventive fraud controls
Kuwait Cassation, forged-cheque jurisprudenceBank payment liabilityAuthentication controls
Kuwait Cassation, forged cheque/transfer caseBanking-document forgeryTransaction verification
Qatar Cassation, 82/2012Forged cheque liabilityComparative Gulf principle

The first six are Kuwaiti authorities/principles; the last is expressly comparative and should not be cited as Kuwaiti law.

29. Operational Risk in Electronic Banking

The traditional cheque cases remain relevant even as banking becomes digital.

The legal question changes from:

"Was the signature genuine?"

to:

"Was the electronic instruction genuinely authorized?"

Modern controls therefore need to authenticate:

  • passwords;
  • OTPs;
  • biometrics;
  • devices;
  • digital signatures;
  • transaction behavior;
  • payment beneficiaries.

The underlying legal principle remains similar:

The bank must establish that the payment instruction is authentic and properly authorized.

30. Cybersecurity as Operational Risk

CBK expressly treats security violations and electronic-banking risks as operational risks.

A cybersecurity framework should therefore cover:

Prevention

  • firewalls;
  • encryption;
  • authentication;
  • access controls.

Detection

  • fraud monitoring;
  • anomaly detection;
  • intrusion detection.

Response

  • incident escalation;
  • account blocking;
  • customer notification.

Recovery

  • backup systems;
  • disaster recovery;
  • restoration of critical services.

31. Operational Risk from Employees

Employees can create operational risk through:

  • negligence;
  • unauthorized transactions;
  • fraud;
  • disclosure of confidential information;
  • inadequate verification;
  • bypassing controls.

The regulatory response includes:

  • segregation of duties;
  • employee authorization limits;
  • monitoring;
  • internal audit;
  • disciplinary procedures;
  • whistleblowing.

The criminal forgery jurisprudence demonstrates why employee participation in banking-document processing can have serious legal consequences.

32. Operational Risk from External Events

External events include:

  • natural disasters;
  • terrorism;
  • infrastructure failure;
  • telecommunications failure;
  • cyberattacks;
  • supplier failure;
  • geopolitical disruption.

CBK's operational-risk instructions expressly include external events and physical damage among relevant risks.

This requires business-continuity planning.

33. Three Lines of Defence

A useful framework for Kuwaiti banks is:

First line — Business units

They own and manage operational risk.

Second line — Risk and compliance

They identify, measure and monitor risks.

Third line — Internal audit

It independently assesses whether controls actually operate.

The board and senior management provide overall governance.

34. Role of Internal Audit

Internal audit should assess:

  • whether operational-risk policies exist;
  • whether controls operate;
  • whether employees follow procedures;
  • whether incidents are reported;
  • whether weaknesses are corrected;
  • whether outsourcing is properly controlled;
  • whether cybersecurity controls work.

This complements Article 84's requirement concerning auditor reporting on internal controls.

35. Operational Risk and Corporate Governance

Corporate governance is fundamental because major operational failures can result from:

  • weak board oversight;
  • inadequate risk culture;
  • poor reporting;
  • conflicts of interest;
  • insufficient independence;
  • failure to challenge management.

CBK's governance framework specifically emphasizes boards, committees, internal and external audit, risk management and outsourcing controls.

36. Operational Risk and Islamic Banking

Islamic banks face additional operational considerations.

Examples include:

  • Sharia-compliance controls;
  • Sharia Supervisory Board oversight;
  • documentation of Islamic contracts;
  • profit-distribution systems;
  • investment-account management;
  • asset ownership requirements in certain structures.

Article 93 requires an independent Sharia Supervisory Board for Islamic banks.

Thus operational-risk management must integrate both:

prudential banking controls + Sharia governance.

37. Regulatory Enforcement Structure

Where an operational failure violates CBK requirements, the regulator can respond through Article 85 measures.

The regulatory sequence may be:

Risk identified

↓

CBK examination

↓

Finding of deficiency

↓

Corrective action

↓

Financial penalty/restriction if necessary

↓

Possible management accountability

This creates a preventive rather than purely punitive approach.

38. Difference Between Operational Risk and Credit Risk

Operational RiskCredit Risk
Failed processBorrower default
Employee fraudCounterparty default
IT failureNon-payment
CyberattackCredit deterioration
Documentation errorInsolvency
System failureCollateral deficiency
External eventCredit concentration

CBK treats operational risk as a distinct risk category rather than merely another form of credit risk.

39. Difference Between Operational Risk and Market Risk

Market risk concerns losses arising from movements in:

  • interest rates;
  • foreign exchange;
  • securities prices;
  • commodities.

Operational risk instead concerns failures in the infrastructure through which banking activities are conducted.

For example:

Wrong FX trade because of a system/process failure → operational risk.

Correctly executed FX trade that loses value because exchange rates move → market risk.

40. Practical Example

Suppose a Kuwaiti bank's payment system has a security weakness.

An employee exploits the weakness and transfers KD 500,000 to an unauthorized account.

Regulatory questions

  • Did the bank have appropriate access controls?
  • Was segregation of duties effective?
  • Was the risk identified?
  • Was management informed?
  • Was the incident reported?
  • Were fraud controls operating?

Civil questions

  • Who bears the customer's financial loss?
  • Was the transaction properly authorized?
  • Did the bank breach its contractual obligations?

Criminal questions

  • Did the employee intentionally commit fraud or another offence?
  • Was there document forgery?
  • Did other employees knowingly assist?
  • Did management participate in or facilitate the offence?

Thus one operational incident can simultaneously produce:

regulatory + civil + criminal consequences.

41. Current Regulatory Direction

Kuwait's regulatory direction increasingly emphasizes resilience.

CBK's current organizational structure includes a Corporate Risk Resilience Department, whose responsibilities include developing comprehensive risk-management frameworks, resilience practices, crisis preparedness and continuity of critical operations.

In March 2026, CBK publicly emphasized the continuity of banking operations and the resilience of the banking sector, specifically referring to risk-management systems, business-continuity plans, emergency plans, digital infrastructure and regular drills.

This shows the movement from traditional "operational risk management" toward a broader operational resilience concept.

42. Important Legal Principles

The Kuwaiti framework can be summarized through the following principles:

1. Operational risk is a regulated banking risk

CBK expressly requires banks to establish operational-risk-management frameworks.

2. Internal controls are mandatory governance infrastructure

Article 84 requires auditing of the adequacy of internal-control systems.

3. Technology creates operational risk

Electronic banking, data processing and security breaches are expressly recognized.

4. Fraud is operational risk

Internal and external embezzlement/fraud are expressly included.

5. Legal risk is part of operational risk

Defective contracts and missing authorizations can produce operational losses.

6. CBK has enforcement powers

Article 85 permits warnings, financial penalties, operational restrictions and management-related measures.

7. Operational failures can generate civil and criminal consequences

The Kuwaiti forgery and payment jurisprudence illustrates the legal consequences of failures surrounding banking instruments and authorization.

43. Conclusion

Banking Law and Operational Risk Regulation in Kuwait is built around the principle that banks must maintain systems capable of preventing, detecting, controlling and mitigating losses arising from people, processes, technology and external events.

The principal legal structure consists of:

Law No. 32 of 1968 + CBK supervisory instructions + internal-control requirements + corporate governance + capital adequacy + cybersecurity/electronic-banking controls + AML/CFT + business continuity.

The most important provisions include Articles 54, 72, 75, 82, 83, 84 and 85 of the Central Bank Law. Article 84 is particularly significant because it expressly connects banking supervision with the adequacy of internal controls, while Article 85 provides CBK with enforcement tools for regulatory violations.

The Kuwaiti Court of Cassation's banking and forgery jurisprudence further demonstrates the importance of authentication, documentary integrity, employee controls and proper payment procedures.

Therefore, the modern Kuwaiti banking-law position can be summarized as:

A bank's operational risk is not merely an internal management concern; failures in its processes, systems, employees or controls can create regulatory, contractual, civil and, where the elements of a criminal offence are established, criminal consequences.

LEAVE A COMMENT