Banking Law And Sharia Audit Requirements In Banks Kuwait .

Banking Law and Sharia Audit Requirements in Banks — Kuwait

1. Introduction

Sharia audit is a central governance requirement for Islamic banks operating in Kuwait. An Islamic bank does not merely have to comply with ordinary banking rules concerning capital, liquidity, consumer protection, anti-money laundering and risk management. Its Islamic financial products and operations must also conform to the principles of Islamic Sharia applicable under Kuwait's Islamic-banking framework.

This creates two overlapping compliance systems:

Prudential/legal compliance + Sharia compliance

The Central Bank of Kuwait (CBK) plays the principal regulatory role. Kuwait's framework also recognizes institutional Sharia supervision within Islamic banks and an external/independent Sharia oversight structure intended to strengthen consistency and credibility.

Sharia audit is therefore more than a religious review of product names. It examines whether transactions are actually structured and performed consistently with the Sharia rulings governing them.

2. Legal Foundation of Islamic Banking in Kuwait

Kuwait's Islamic banking framework is principally connected with Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business, as subsequently amended.

A major development came through Law No. 30 of 2003, which introduced a specific legislative framework for Islamic banks.

Islamic banks are consequently part of Kuwait's regulated banking system rather than institutions operating outside conventional financial regulation.

They remain subject to CBK supervision concerning matters such as:

  • licensing;
  • capital adequacy;
  • liquidity;
  • credit concentration;
  • corporate governance;
  • internal controls;
  • risk management;
  • AML/CFT requirements; and
  • regulatory reporting.

In addition, their activities must comply with the Islamic principles governing their products and contracts.

3. What Is a Sharia Audit?

A Sharia audit is a systematic examination of the bank's transactions, contracts, policies, procedures and financial activities to determine whether they comply with applicable Sharia requirements and the decisions of the institution's Sharia supervisory structure.

Suppose an Islamic bank offers a Murabaha financing product.

The audit should not simply ask:

Is the contract called “Murabaha”?

It examines the economic and contractual steps underlying the transaction.

Relevant questions may include:

  • Did the bank acquire the relevant asset?
  • Was ownership properly established?
  • Was the sale sequence followed?
  • Were cost and profit appropriately identified?
  • Did contractual documentation correspond to the actual transaction?
  • Were prohibited interest-based elements introduced indirectly?
  • Were fees permissible?
  • Were late-payment arrangements handled appropriately?

Therefore, substance and implementation matter alongside documentation.

4. Sharia Supervisory Governance

An Islamic bank requires specialized Sharia governance because ordinary directors, accountants and compliance officers may not possess the necessary expertise in Islamic jurisprudence.

A Sharia supervisory body therefore examines whether products and transactions comply with Islamic principles.

Its functions can include:

  • examining proposed financial products;
  • reviewing contractual structures;
  • issuing Sharia opinions or rulings;
  • supervising implementation;
  • reviewing questionable transactions;
  • advising the board and management; and
  • reporting on Sharia compliance.

The structure helps prevent management from determining Sharia compliance solely according to its own commercial interests.

5. Internal Sharia Audit

Internal Sharia audit is part of the bank's internal control architecture.

Its function is generally to test whether departments actually implement approved Sharia requirements.

For example, assume the Sharia board approves an Ijara product subject to specific conditions.

The internal audit function may examine a sample of transactions and discover that operational staff repeatedly execute documentation in the wrong order.

Even though the product was properly approved in principle, its practical implementation may therefore be defective.

This demonstrates an important distinction:

Sharia approval ≠ continuing Sharia compliance.

Audit provides the continuing verification.

6. Independence of Sharia Audit

An effective audit cannot be completely dependent on the business department being examined.

Suppose the Islamic-finance sales department can:

  • determine the audit scope;
  • prevent auditors from reviewing files;
  • alter adverse findings; and
  • decide whether violations are reported.

The audit would have little credibility.

Consequently, Kuwait's governance approach emphasizes organizational arrangements capable of giving Sharia control functions sufficient independence, authority and access to information.

This resembles the independence expected of internal audit and compliance functions in conventional banking, although the subject of review is different.

7. External Sharia Audit

External Sharia audit adds another layer of assurance.

The purpose is to obtain independent examination of whether the bank's activities comply with applicable Sharia requirements.

This can reduce the risk of:

  • management influence;
  • inconsistent internal interpretations;
  • conflicts of interest;
  • inadequate testing; and
  • institutional bias.

An external reviewer may examine transactions, documentation, systems and the implementation of Sharia decisions.

The distinction can be summarized as:

Sharia Board → establishes/approves Sharia position

Management → implements it

Internal Sharia Audit → continuously tests implementation

External Sharia Audit → provides additional independent assurance

8. CBK Higher Sharia Supervisory Authority

An important development in Kuwait has been the establishment of a Higher Sharia Supervisory Authority at the Central Bank of Kuwait.

Its broader purpose is to strengthen the Sharia-governance environment and address issues requiring authoritative or harmonized consideration across the Islamic banking sector.

This is particularly important because individual banks can otherwise adopt differing Sharia interpretations concerning similar financial products.

Such differences can create:

  • regulatory uncertainty;
  • inconsistent customer treatment;
  • product-comparison difficulties; and
  • reputational risk for the Islamic banking industry.

Centralized oversight can therefore contribute to greater consistency.

9. Relationship With the Board of Directors

The existence of Sharia specialists does not mean that the bank's board can disregard Sharia compliance.

The board remains responsible for ensuring that an effective governance and control system exists.

Accordingly, the board should ensure that:

  • Sharia governance structures are properly established;
  • qualified personnel are appointed;
  • auditors receive adequate resources;
  • findings reach the appropriate governance level;
  • management corrects identified deficiencies; and
  • material Sharia-compliance risks are addressed.

The board therefore has an institutional governance responsibility, even though specialized scholars determine technical Sharia questions.

10. Role of Senior Management

Senior management must translate Sharia requirements into operational procedures.

For example, management may need to ensure that:

  • approved contracts are used;
  • transaction sequences are correctly programmed into IT systems;
  • staff receive appropriate training;
  • prohibited fees are not charged;
  • income requiring special treatment is identified;
  • audit findings are corrected; and
  • new products are not launched before required approval.

Sharia compliance consequently operates throughout the bank rather than exclusively inside a Sharia department.

11. Audit of Murabaha Transactions

Murabaha provides a useful example.

Suppose a customer wants equipment costing KWD 20,000.

An Islamic bank acquires the equipment and subsequently sells it to the customer for KWD 23,000 payable over an agreed period.

The Sharia audit could examine whether:

  1. the bank actually acquired the asset;
  2. the sequence of contracts was correct;
  3. ownership and relevant risk existed as required;
  4. the customer's purchase contract was properly executed;
  5. the KWD 3,000 profit was transparent;
  6. documentation reflected the real transaction; and
  7. late-payment arrangements complied with the applicable Sharia ruling.

If the bank merely advanced KWD 20,000 and demanded KWD 23,000 without genuinely implementing the sale structure, serious Sharia-compliance questions could arise.

12. Audit of Mudaraba

In a Mudaraba, one party provides capital while another manages the venture.

Audit issues can include:

  • allocation of profits;
  • treatment of losses;
  • manager remuneration;
  • unauthorized guarantees;
  • investment restrictions;
  • expenses; and
  • whether contractual terms alter the essential risk-sharing structure.

For example, a guaranteed fixed investment return may require particularly careful examination because it could undermine the risk-sharing characteristics upon which the arrangement was approved.

13. Audit of Musharaka

In Musharaka arrangements, parties contribute capital and participate in an investment or venture.

The audit may investigate:

  • capital contributions;
  • profit-sharing ratios;
  • allocation of losses;
  • management arrangements;
  • purchase undertakings;
  • valuation; and
  • exit mechanisms.

In a diminishing Musharaka used for property financing, the audit may also verify whether ownership units are actually transferred according to the approved structure.

14. Audit of Ijara

Ijara structures require particular attention to the distinction between ownership and use of an asset.

Relevant audit issues can include:

  • ownership of the leased asset;
  • lease documentation;
  • rental calculations;
  • maintenance responsibilities;
  • insurance/takaful arrangements;
  • purchase undertakings; and
  • transfer of ownership at the end of the arrangement.

A product called an “Islamic lease” does not become Sharia-compliant simply because conventional loan terminology has been removed.

15. Sukuk and Investment Activities

Banks may participate in Sukuk as issuers, arrangers, investors or intermediaries.

Sharia review may consider:

  • the underlying assets;
  • investor rights;
  • ownership structure;
  • distribution arrangements;
  • purchase undertakings;
  • guarantees;
  • use of proceeds; and
  • treatment of default.

This area can become legally complex because the transaction simultaneously engages commercial law, banking regulation, securities law and Sharia governance.

16. Sharia Non-Compliance Risk

Sharia non-compliance is a genuine banking risk.

Possible consequences include:

  • invalid or questionable income from a Sharia perspective;
  • customer claims;
  • regulatory intervention;
  • reputational damage;
  • required corrective measures;
  • product withdrawal;
  • financial adjustments; and
  • loss of confidence among depositors and investors.

For an Islamic bank, reputation is particularly significant because customers may choose the institution specifically because it represents its products as Sharia-compliant.

17. Treatment of Non-Compliant Income

Where an audit identifies income generated through a transaction that does not comply with the applicable Sharia requirements, the matter cannot necessarily be treated simply as ordinary bank profit.

Depending on the applicable Sharia determination and regulatory arrangements, the bank may have to identify the affected income and apply the required treatment, which can include purification or disposal for appropriate charitable purposes rather than recognition as distributable profit.

This reinforces the importance of accounting systems capable of tracing affected transactions.

18. Documentation and Audit Trail

A strong Sharia audit requires reliable evidence.

Banks should therefore maintain appropriate records concerning:

  • contracts;
  • Sharia approvals;
  • board decisions;
  • transaction documents;
  • asset purchases;
  • ownership transfers;
  • customer instructions;
  • calculations;
  • exceptions;
  • corrective actions; and
  • previous audit findings.

An auditor cannot reliably determine whether a transaction followed the required sequence if the bank lacks an adequate audit trail.

Digital banking makes this especially important because transaction steps may be automated.

19. Sharia Audit and Technology

Modern Islamic banking increasingly operates through:

  • mobile applications;
  • automated financing platforms;
  • digital onboarding;
  • smart workflows;
  • electronic contracts; and
  • algorithmic decision systems.

Sharia audit therefore increasingly involves systems auditing.

For example, if a Murabaha platform automatically executes the customer's sale before the bank completes the required acquisition step, thousands of transactions could potentially repeat the same structural defect.

Technology can therefore reduce human error while simultaneously magnifying a badly programmed compliance error.

20. Relationship With AAOIFI Standards

The Accounting and Auditing Organization for Islamic Financial Institutions (AAOIFI) has developed important Sharia, accounting, auditing and governance standards for Islamic finance.

AAOIFI standards are highly influential internationally.

However, it is important to distinguish:

AAOIFI standard-setting from binding Kuwaiti law and CBK requirements.

A standard becomes legally significant in Kuwait according to the manner in which Kuwaiti legislation, CBK requirements, contractual documentation or the relevant Sharia-governance structure recognizes or incorporates it.

Therefore, one should not automatically state that every AAOIFI standard is independently binding on every Kuwaiti bank.

Case Laws

Important qualification

There is limited publicly accessible Kuwaiti reported case law specifically dealing with internal or external Sharia-audit requirements of Islamic banks. Kuwaiti judgments are also not published through a comprehensive public precedent database comparable to some common-law jurisdictions.

It would therefore be inaccurate to invent six Kuwaiti “Sharia audit cases.”

The following genuine judicial authorities address closely related issues concerning Islamic finance contracts, Sharia characterization, banking obligations and judicial treatment of Islamic financial structures. Most are comparative authorities and are not binding precedents in Kuwait.

Case 1: Shamil Bank of Bahrain EC v Beximco Pharmaceuticals Ltd [2004] EWCA Civ 19

This is one of the best-known Islamic-finance cases.

The financing documentation provided for English law while also referring to the principles of Sharia.

The English Court of Appeal concluded that the contractual governing-law clause did not make general Sharia principles an independently applicable system of law governing the contract.

Relevance to Kuwait

The case demonstrates why Islamic banks need precise contractual drafting and institutional Sharia supervision.

Courts determine contractual rights according to applicable law. Sharia compliance therefore cannot safely depend upon vague references alone.

For Kuwaiti banks, proper Sharia review before execution helps ensure that the legal documentation accurately implements the structure approved by Sharia authorities.

Case 2: The Investment Dar Company KSCC v Blom Developments Bank SAL [2009] EWHC 3545 (Ch)

This authority is particularly relevant because The Investment Dar was a Kuwaiti Islamic investment company.

The dispute concerned a Wakalah arrangement, and arguments were raised concerning whether the transaction complied with the company's constitutional restrictions relating to Sharia.

The English High Court proceedings illustrate the serious legal difficulties that can emerge when a financial institution later questions the Sharia validity or corporate authority underlying its own transaction.

Audit significance

A robust Sharia-governance process should identify structural concerns before execution, rather than allowing them to emerge after a dispute occurs.

This is one of the most useful comparative cases for understanding why Kuwaiti Islamic institutions need strong ex-ante Sharia review and continuing audit.

Case 3: Dana Gas PJSC v Dana Gas Sukuk Ltd [2017] EWHC 2928 (Comm)

The dispute became internationally significant after Dana Gas challenged aspects of the enforceability/Sharia compliance of its Sukuk arrangements.

The English proceedings concerned contractual obligations under English-law documents, while related proceedings existed in other jurisdictions.

Relevance

The controversy demonstrates a fundamental risk in Islamic finance:

Sharia interpretation + contractual enforceability + governing law can produce different legal questions.

Strong Sharia audit and product governance can reduce the possibility that an institution issues a financial instrument and later alleges that its own structure is Sharia-defective.

Case 4: Islamic Investment Company of the Gulf (Bahamas) Ltd v Symphony Gems NV [2002] All ER (D) 171

The dispute concerned a Murabaha financing arrangement.

The English court approached the dispute through the contractual obligations established by the financing documents.

Relevance

The case illustrates why Islamic banks need documentation that accurately reflects the commercial and Sharia structure of Murabaha.

Internal Sharia audit should therefore examine both the contractual documentation and actual transactional steps.

Case 5: Beximco Pharmaceuticals Ltd v Shamil Bank of Bahrain EC — first-instance proceedings, later considered in Shamil Bank v Beximco

The underlying litigation provides another useful illustration of disputes involving Islamic financing documentation.

The important lesson is that referring generally to Sharia does not eliminate the need for a clearly identified governing law and enforceable contractual obligations.

For Kuwaiti Islamic banks, Sharia governance and legal review must therefore work together.

A Sharia-compliant product that is legally defective creates risk; equally, a legally enforceable document that fails the institution's applicable Sharia requirements creates a different form of risk.

Case 6: Bank Kerjasama Rakyat Malaysia Bhd v Emcee Corporation Sdn Bhd [2003] 2 MLJ 408

This Malaysian decision is frequently discussed in Islamic-finance jurisprudence.

The court dealt with enforcement in the context of Islamic banking and emphasized the legal character of the banking transaction rather than treating the matter as requiring the civil court itself to function as a Sharia tribunal.

Relevance to Kuwait

Although Malaysian law differs substantially from Kuwaiti law, the case demonstrates the institutional importance of determining Sharia questions through the appropriate specialist mechanisms.

This supports the logic behind specialized Sharia supervisory and audit structures within Islamic financial institutions.

21. What These Cases Actually Establish

The cases must be used carefully.

CaseMain relevance
Shamil Bank v BeximcoSharia references and governing-law certainty
Investment Dar v BlomSharia compliance, corporate authority and Kuwaiti Islamic finance
Dana Gas SukukSharia characterization versus contractual enforceability
Symphony GemsMurabaha documentation and enforcement
Beximco/Shamil litigationInteraction of Islamic structure and ordinary contract law
Bank Rakyat v EmceeJudicial treatment of Islamic banking obligations

They do not collectively create Kuwait's Sharia-audit regime.

The binding Kuwaiti requirements must instead be determined primarily from Kuwaiti banking legislation, current CBK regulations/instructions and the governance requirements applicable to the particular Islamic bank.

22. Practical Example

Suppose a Kuwaiti Islamic bank launches a new digital Murabaha product.

The governance process could operate as follows:

Stage 1 – Product development:
Management develops the commercial structure.

Stage 2 – Legal review:
Lawyers determine whether the contracts comply with Kuwaiti law and applicable regulatory requirements.

Stage 3 – Sharia review:
The relevant Sharia authority examines the structure and specifies the conditions necessary for Sharia compliance.

Stage 4 – Implementation:
The bank programs those requirements into its digital platform.

Stage 5 – Internal Sharia audit:
Auditors sample completed transactions and test whether the required sequence actually occurred.

Stage 6 – External assurance:
Independent Sharia review provides an additional assessment of compliance.

Stage 7 – Remediation:
Any breach is documented, escalated and corrected, with affected income receiving the treatment required by the applicable Sharia determination.

This illustrates why Sharia audit is a continuous governance process, not a one-time certificate obtained when a product is launched.

23. Relationship With Conventional Internal Audit

The two functions overlap but are not identical.

A conventional internal auditor might conclude:

“The transaction was properly authorized, accurately recorded and complied with the bank's accounting procedures.”

A Sharia auditor might nevertheless identify:

“The contractual sequence did not comply with the Sharia conditions approved for the product.”

Conversely, a transaction could comply with Sharia requirements but violate a CBK prudential requirement.

Islamic banks therefore need both systems.

24. Regulatory Importance

Failure to maintain effective Sharia governance can become relevant to ordinary banking supervision because it can indicate weaknesses in:

  • governance;
  • internal controls;
  • operational risk;
  • compliance;
  • reputation management;
  • product approval; and
  • board oversight.

Consequently, Sharia audit should not be regarded as isolated from prudential regulation.

For an Islamic bank, it forms part of the institution's overall governance and control environment.

Conclusion

Sharia audit requirements in Kuwaiti banks form a specialized component of Kuwait's Islamic-banking governance system. Islamic banks must combine ordinary prudential compliance with credible mechanisms for ensuring that their products, contracts and actual transactions conform to applicable Sharia requirements.

The framework involves the Central Bank of Kuwait, bank-level Sharia supervision, internal Sharia control and audit, independent assurance mechanisms, boards of directors and senior management. The CBK's higher-level Sharia supervisory architecture further strengthens consistency across the sector.

Cases such as Shamil Bank v Beximco, Investment Dar v Blom, Dana Gas Sukuk, Symphony Gems,* and *Bank Rakyat v Emcee illustrate why Sharia approval, contractual drafting, governing law and actual implementation must work together. Of these, Investment Dar v Blom has an especially significant Kuwaiti connection, but it remains an English court decision rather than a Kuwaiti precedent.

The central principle is therefore:

Sharia approval determines how the product should operate; Sharia audit verifies whether the bank actually operates it that way.

Where publicly reported Kuwaiti judicial authority is unavailable, comparative Islamic-finance cases should be clearly identified as persuasive illustrations rather than presented as binding Kuwait case law.

LEAVE A COMMENT