Banking Law And Sharia Audit Compliance In Banks Kuwait .
Banking Law and Sharia Audit Compliance in Banks in Kuwait
Jurisdiction: Kuwait
1. Introduction
Sharia audit compliance is the process through which an Islamic bank verifies that its products, contracts, transactions, investments and operational practices comply with the Sharia principles applicable to the institution.
It is different from ordinary financial auditing.
A financial auditor principally asks:
Were the bank's accounts properly prepared and were transactions accurately recorded?
A Sharia auditor additionally asks:
Was the transaction itself structured and performed in accordance with the bank's applicable Sharia requirements?
In Kuwait, this matters particularly for products such as:
Murabaha;
Ijara;
Musharaka;
Mudaraba;
Istisna;
Tawarruq structures;
investment accounts;
sukuk; and
other Islamic financing arrangements.
Sharia compliance therefore forms part of governance, product control, documentation, operational risk and regulatory compliance.
2. Main Banking Law
The central banking statute is Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business, as amended.
The law provides the basic framework for banking regulation and the supervisory authority of the Central Bank of Kuwait (CBK).
Kuwait subsequently incorporated a specific framework for Islamic banking into its banking legislation.
Consequently, an Islamic bank is not simply a conventional commercial company voluntarily offering religiously labelled products.
It operates within a regulated banking framework.
3. Islamic Banking Provisions
Kuwait's banking legislation contains provisions addressing Islamic banks and the nature of their activities.
Islamic banks conduct banking activities in a manner intended to comply with Islamic Sharia.
This produces two overlapping compliance dimensions:
CBK/banking compliance
Sharia compliance.
A transaction can therefore create problems even where the customer's credit risk is acceptable if the transaction has not been structured and implemented according to the institution's applicable Sharia governance requirements.
4. Central Bank of Kuwait
The CBK has a central supervisory role.
Its regulatory framework for Islamic banks addresses matters extending beyond basic licensing, including governance and control arrangements.
For a Sharia audit system, relevant regulatory concerns include:
independence;
competence;
documentation;
internal controls;
reporting;
board oversight;
Sharia governance; and
corrective action.
The current CBK instructions should always be checked for the exact requirements applicable to a particular bank and transaction.
5. Sharia Supervisory Board
A core component of Islamic banking governance is the Sharia Supervisory Board (SSB) or equivalent Sharia supervisory body required under the applicable framework.
Its function is different from management.
Management asks:
Is the product commercially attractive?
Risk management asks:
What credit, market and operational risks arise?
Legal counsel asks:
Is the contract legally enforceable?
The Sharia supervisory function asks:
Does the product and its implementation satisfy the applicable Sharia principles?
All four questions can matter simultaneously.
6. Sharia Audit Versus Sharia Supervision
These concepts should be distinguished.
Sharia supervision
Usually involves reviewing and approving products, contracts and structures from a Sharia perspective.
Sharia audit
Examines whether actual transactions and operations followed the approved requirements.
For example, an SSB might approve a Murabaha structure.
The Sharia audit then examines whether actual transactions followed that structure.
Thus:
approval ≠ implementation.
7. Example: Murabaha
Assume a customer wants equipment worth KD 100,000.
The approved structure requires:
bank purchases equipment;
bank obtains the required ownership/possession;
bank sells it to customer;
sale price is KD 110,000;
customer pays over an agreed period.
The Sharia auditor should not merely confirm that the paperwork says “Murabaha.”
The audit should examine whether the required transaction sequence actually occurred.
If the customer effectively received cash without the required asset transaction taking place, a serious compliance question may arise.
8. Substance and Documentation
Sharia audit therefore involves both:
documents
and
commercial substance.
Auditors may examine:
purchase orders;
invoices;
ownership evidence;
agency agreements;
sale agreements;
payment records;
transaction timing;
asset descriptions;
customer documentation.
A properly named contract cannot cure an operational sequence that contradicts its approved structure.
9. Ijara Audit
Under an Ijara arrangement, the bank may acquire an asset and lease it to a customer.
The Sharia audit may therefore examine:
asset ownership → lease execution → rental calculation → maintenance obligations → insurance arrangements → transfer mechanics.
For example, if the contractual structure requires the bank to bear particular ownership-related risks but the operational documents automatically shift every such risk to the customer, the arrangement may require further Sharia review.
10. Mudaraba
In a Mudaraba, one party supplies capital while another manages the investment.
The Sharia auditor may review:
profit-sharing ratio;
treatment of losses;
management conduct;
prohibited guarantees;
investment restrictions;
expenses.
A predetermined guaranteed investment return can raise fundamental issues where it is inconsistent with the approved Mudaraba structure.
11. Musharaka
A Musharaka involves participation in an enterprise or asset.
Audit questions can include:
actual capital contribution;
profit-sharing arrangement;
loss allocation;
management rights;
purchase undertakings;
exit arrangements.
Again, contractual labels are not sufficient.
12. Istisna
Istisna is particularly useful in construction and manufacturing finance.
The bank may finance the manufacture or construction of an asset.
Sharia audit can review:
specifications → price → construction obligations → delivery → parallel Istisna arrangements.
Operational separation between contracts may be important where the bank uses parallel transactions.
13. Tawarruq
Commodity-based financing structures can involve multiple transactions.
An audit may examine whether:
commodities actually exist;
contracts are separate;
ownership transfers occur correctly;
transaction sequence is respected;
agency arrangements comply with approvals.
This is an area where automated systems can create compliance problems if transactions occur in the wrong sequence.
14. Product Approval
A strong Sharia-governance process normally begins before a product is launched.
A typical sequence is:
Business proposal
↓
Legal review
↓
Risk review
↓
Sharia review
↓
Approval
↓
System implementation
↓
Sharia audit
↓
remediation.
This is much safer than launching a product first and asking the Sharia function to examine it later.
15. Independence
The Sharia audit function needs sufficient independence.
Suppose the same sales manager who earns bonuses from Murabaha transactions controls whether those transactions are reported as Sharia-compliant.
That creates an obvious conflict.
Effective governance therefore requires appropriate separation between:
business generation
and
independent compliance/audit review.
16. Internal Sharia Audit
An internal Sharia audit function may review transaction samples and business processes across the bank.
Typical areas include:
retail finance;
corporate finance;
treasury;
investment;
sukuk;
trade finance;
deposits/investment accounts;
branches;
digital banking.
The audit plan should generally be risk based.
Higher-risk or more complex structures warrant greater attention.
17. External Sharia Audit
External Sharia review or audit can provide an additional layer of assurance where required or used within the applicable framework.
Its purpose is different from ordinary statutory financial auditing.
A conventional financial auditor may confirm that:
KD 5 million revenue was correctly recorded.
A Sharia auditor may additionally ask:
Was that KD 5 million generated through transactions complying with the approved Sharia requirements?
18. Sharia Non-Compliance Risk
A Sharia non-compliance event occurs where a transaction or activity fails to satisfy applicable Sharia requirements.
Potential consequences can include:
corrective action;
contract restructuring;
customer remediation where legally appropriate;
purification or charitable disposal of impermissible income where required under applicable Sharia decisions;
governance escalation;
regulatory consequences;
reputational damage.
The precise remedy depends on the nature of the violation and the applicable Sharia and legal framework.
19. Sharia Non-Compliant Income
Suppose an Islamic bank discovers that a category of income was generated through a transaction inconsistent with the applicable Sharia approval.
It should not simply treat the issue as an accounting error.
The bank needs to determine:
what went wrong;
which transactions were affected;
the amount involved;
the applicable Sharia treatment;
whether customers were affected;
whether disclosure is required;
what controls must change.
This is why Sharia auditing interacts with financial accounting and compliance.
20. Board Responsibility
Sharia compliance cannot be delegated entirely to individual scholars.
The bank's board and senior management remain responsible for maintaining an effective governance framework within their respective legal responsibilities.
The structure should therefore connect:
Board
↓
Sharia governance
↓
management
↓
Sharia compliance/review
↓
internal audit
↓
business units.
Deficiencies identified by auditors should reach a sufficiently senior level to ensure remediation.
21. Conflict of Interest
Conflicts can arise if Sharia personnel:
design a product;
approve it;
implement it;
audit it;
determine whether their own work was correct.
Governance should therefore create appropriate functional separation.
Complete organizational separation may not always be practical, but independent challenge is important.
22. Record Keeping
Sharia compliance requires evidence.
A bank should preserve records showing:
what was approved
when it was approved
which contract version was used
how the transaction occurred
who authorized exceptions
what corrective action followed.
Without adequate records, demonstrating compliance to regulators or courts becomes much more difficult.
23. Digital Islamic Banking
Sharia auditing is increasingly a technology issue.
Suppose a digital Murabaha platform automatically performs:
purchase → customer sale
within milliseconds.
The system must still maintain the legally and Sharia-relevant sequence.
Software should therefore be tested against the approved transaction workflow.
A coding error can become a compliance error across thousands of transactions.
24. Artificial Intelligence
AI may be used for:
credit assessment;
customer service;
transaction monitoring;
fraud detection;
product recommendations.
But AI cannot simply override approved Sharia parameters.
For example, an AI system should not automatically modify contractual pricing or transaction sequencing in a way that creates a structure different from that approved by the relevant Sharia authority.
Human governance remains important.
25. Outsourcing
An Islamic bank may outsource:
cloud services;
transaction processing;
commodity platforms;
software;
payment functions.
But outsourcing does not necessarily transfer the bank's regulatory responsibilities.
If a third-party commodity platform causes thousands of Tawarruq transactions to occur incorrectly, the bank may still face compliance consequences.
Contracts with providers should therefore include audit access, control standards, incident reporting and remediation mechanisms appropriate to the service.
26. AML/CFT
Sharia compliance does not replace AML obligations.
Law No. 106 of 2013 concerning Anti-Money Laundering and Financing of Terrorism, as amended, remains relevant.
An Islamic bank must therefore satisfy both:
Sharia requirements
and
AML/CFT requirements.
A transaction does not become legally acceptable merely because it is Sharia compliant.
Likewise, an AML-compliant transaction is not necessarily Sharia compliant.
27. Capital Markets and Sukuk
If a Kuwaiti bank issues, arranges or invests in sukuk, the Capital Markets Authority framework under Law No. 7 of 2010 and its Executive Bylaws may also become relevant.
The institution may therefore face:
CBK requirements + CMA requirements + contractual requirements + Sharia governance.
The exact combination depends on the activity and instrument.
28. Sukuk Audit
A sukuk audit can examine whether:
eligible assets actually exist;
asset transfers occurred as represented;
distributions follow the approved structure;
purchase undertakings operate properly;
proceeds are used for permissible purposes;
investor documentation accurately describes the structure.
A sukuk certificate should not be treated as Sharia compliant merely because its title contains the word “sukuk.”
29. Conventional and Islamic Windows
Where financial groups contain both conventional and Islamic operations, controls may be necessary to avoid inappropriate mixing of:
funds;
income;
accounts;
contracts;
products.
Operational segregation can therefore form an important part of Sharia compliance.
The precise legal requirements depend on the institution's licensed structure and current CBK framework.
Case Law
Published Kuwaiti judicial decisions dealing specifically with internal Sharia audit failures in banks are difficult to identify reliably in accessible English-language sources.
It would therefore be misleading to invent six “Kuwaiti Sharia audit cases.”
Several genuine comparative Islamic-finance cases nevertheless illustrate important legal issues. They are not binding Kuwaiti precedents.
30. Kuwait Finance House (Malaysia) Berhad v JRI Resources Sdn Bhd [2019]
This decision of the Federal Court of Malaysia is highly useful comparatively because it considered the role of Malaysia's Sharia Advisory Council in Islamic-finance disputes.
The case demonstrates that a jurisdiction can create a formal institutional mechanism for resolving Sharia questions within its financial legal system.
Relevance to Kuwait
It illustrates why Islamic banks need clear institutional Sharia governance rather than leaving complex Sharia determinations to ordinary operational staff.
It is Malaysian, not Kuwaiti, precedent.
31. Shamil Bank of Bahrain EC v Beximco Pharmaceuticals Ltd [2004] EWCA Civ 19
This English Court of Appeal case concerned financing documentation referring both to English law and principles of Sharia.
The court treated the governing-law issue through conventional private international law.
Kuwait relevance
The case demonstrates why Islamic-finance documentation should clearly identify:
governing law;
contractual obligations;
Sharia approval mechanisms;
consequences of non-compliance.
A vague statement that a contract is “subject to Sharia” may not by itself resolve legal disputes.
This is English law, not Kuwaiti precedent.
32. The Investment Dar Company KSCC v Blom Development Bank SAL [2009] EWHC 3545 (Ch)
This case is particularly relevant because The Investment Dar was a Kuwaiti company, although the litigation occurred before the English High Court.
The dispute involved an Islamic-finance arrangement and raised questions including corporate authority and the Sharia characterization of the transaction.
Audit lesson
A Sharia audit should examine not only the form of the transaction but whether the institution possesses the authority to undertake it and whether the structure matches its approved activities.
The decision is an English judgment involving a Kuwaiti entity, not a Kuwaiti court judgment.
33. Beximco — Importance of Contract Drafting
The Shamil Bank decision also demonstrates a second important principle: Sharia governance and enforceable contractual drafting must work together.
An Islamic bank should not assume that an external court will reconstruct the Sharia intentions of the parties from broad wording.
Audit therefore needs to check that approved structures are accurately translated into contractual documents.
34. Investment Dar — Corporate Authority
Investment Dar v Blom also illustrates the relationship between:
Sharia governance
and
corporate capacity.
Even if a transaction has commercial logic, questions can arise if the institution's constitutional or regulatory framework restricts the activity.
A Sharia audit should therefore coordinate with legal and regulatory compliance rather than operate in isolation.
35. JRI Resources — Institutional Sharia Expertise
Kuwait Finance House (Malaysia) v JRI Resources illustrates the value of specialist Sharia expertise within a formal financial regulatory framework.
The broader lesson for Kuwait is that:
courts + regulators + Sharia bodies
perform different functions.
Internal bank auditors should not assume that they themselves possess final authority to resolve every disputed Sharia interpretation.
36. Contractual Enforceability Versus Sharia Compliance
An especially important distinction emerges from these cases.
A transaction may raise two separate questions:
Question 1
Is the contract legally enforceable?
Question 2
Does the transaction satisfy the applicable Sharia requirements?
These questions can overlap but are not identical.
For a Kuwaiti Islamic bank, a strong compliance framework must therefore involve both:
legal review
and
Sharia review.
37. Practical Audit Example
Assume a Kuwaiti Islamic bank executes 20,000 Murabaha transactions during a year.
Internal Sharia audit selects a risk-based sample.
It discovers that a software update caused some transactions to execute:
customer sale
before
bank acquisition of commodity.
The bank should investigate:
Scope
How many transactions were affected?
Cause
Was it a software sequencing error?
Sharia determination
What is the appropriate treatment under the relevant Sharia decision?
Financial impact
Was any income affected?
Customer impact
Does remediation involve customers?
Governance
Why did pre-production testing fail?
Technology
How should the workflow be corrected?
Regulatory reporting
Does the matter require notification under the applicable CBK framework?
The bank should not simply correct the software and delete the audit finding.
38. Sharia Audit Report
A strong report might classify findings according to seriousness.
For each finding it should identify:
requirement
↓
transaction tested
↓
deviation
↓
Sharia/legal consequence
↓
financial exposure
↓
responsible management
↓
corrective action
↓
deadline
↓
follow-up testing.
This makes Sharia audit an operational governance process rather than a symbolic certification exercise.
39. Principal Kuwaiti Legal Framework
| Framework | Importance |
|---|---|
| Law No. 32 of 1968, as amended | Banking regulation and CBK supervision, including the statutory Islamic-banking framework |
| CBK Islamic banking/Sharia governance instructions | Governance, supervisory and control expectations |
| Law No. 7 of 2010 | Capital markets and securities activities |
| CMA Executive Bylaws | Relevant to sukuk and regulated securities activities |
| Law No. 106 of 2013 | AML/CFT obligations |
| Civil Code, Law No. 67 of 1980 | Contracts and obligations |
| Commercial Code, Law No. 68 of 1980 | Commercial transactions |
| Bank constitutional documents and Sharia decisions | Institution-specific authority and compliance |
The latest consolidated CBK and CMA instructions should be consulted for the exact current governance, reporting and audit requirements.
40. Sharia Audit Compliance Checklist
A Kuwaiti Islamic bank should be able to answer:
Is there an appropriately constituted Sharia supervisory function?
Are its responsibilities documented?
Are new products reviewed before launch?
Are approved contract templates controlled?
Does internal Sharia audit have adequate independence?
Are auditors appropriately qualified?
Are transactions sampled on a risk basis?
Are Murabaha ownership and sequencing tested?
Are Ijara ownership obligations tested?
Are Mudaraba profit/loss arrangements reviewed?
Are Musharaka structures implemented as approved?
Are Tawarruq transactions tested operationally?
Are sukuk activities separately reviewed?
Are Sharia non-compliance events recorded?
Is affected income identified?
Is corrective treatment documented?
Are significant findings escalated?
Are technology systems tested for Sharia workflows?
Are outsourced platforms subject to controls?
Are repeat findings reported to senior governance bodies?
Conclusion
Sharia audit compliance in Kuwaiti banks is not merely a religious certification exercise. It forms part of the governance and control architecture of Islamic banking.
The central statutory foundation is Law No. 32 of 1968, as amended, together with the Central Bank of Kuwait's applicable Islamic-banking and Sharia-governance requirements. Where capital-market instruments such as sukuk are involved, Law No. 7 of 2010 and the CMA Executive Bylaws may also apply. AML/CFT, civil and commercial law remain independently relevant.
Effective Sharia compliance requires:
Sharia supervisory oversight → product approval → accurate legal documentation → operational implementation → independent review/audit → identification of non-compliance → remediation → board-level oversight.
The comparative cases Kuwait Finance House (Malaysia) v JRI Resources [2019], Shamil Bank v Beximco [2004], and The Investment Dar v Blom Development Bank [2009] demonstrate important principles concerning specialist Sharia determinations, governing law, contractual drafting and corporate authority. However, they must not be misrepresented as Kuwaiti judicial precedents.
For Kuwait specifically, the most important legal sources remain the applicable Kuwaiti statutes, current CBK instructions, CMA rules where relevant, the bank's governing documents and the decisions of its competent Sharia governance bodies.

comments