Banking Law And Technology Ethics Boards In Banks Kuwait .

Banking Law and Technology Ethics Boards in Banks in Kuwait — Detailed Explanation with Case Laws

Jurisdiction: Kuwait

Technology ethics boards in banks are internal governance bodies designed to supervise the ethical and legal risks created by technologies such as artificial intelligence (AI), automated credit scoring, biometric identification, cloud computing, algorithmic fraud detection, digital banking, customer profiling, cybersecurity systems and generative AI.

In Kuwait, there is no general banking rule requiring every bank to establish a committee formally called a “Technology Ethics Board.” The concept is better understood as a governance mechanism through which a bank can satisfy existing obligations relating to board oversight, operational risk, cybersecurity, customer protection, privacy, outsourcing, AML/CFT and—in Islamic banks—Sharia governance.

Therefore, the legal question is not merely whether a bank has an ethics committee. The important question is whether its governance structure provides effective accountability for technology-related risks.

1. Principal Legal Framework

Technology governance within Kuwaiti banks is influenced principally by:

  • Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organization of Banking Business, as amended;
  • regulations and supervisory instructions issued by the Central Bank of Kuwait (CBK);
  • Law No. 20 of 2014 concerning Electronic Transactions;
  • Law No. 63 of 2015 concerning Combating Information Technology Crimes;
  • Law No. 106 of 2013 regarding Anti-Money Laundering and Combating the Financing of Terrorism;
  • CBK cybersecurity and information-security requirements;
  • CBK corporate-governance requirements for banks;
  • CBK consumer-protection principles;
  • applicable telecommunications and privacy/data-protection requirements;
  • outsourcing and cloud-computing requirements; and
  • Sharia governance requirements applicable to Islamic banks.

International standards such as the Basel Committee's corporate-governance principles are also highly influential in understanding good banking governance.

2. Why Banks Need Technology Ethics Governance

Banks increasingly make decisions through software rather than exclusively through human employees.

Consider an automated lending platform that evaluates:

  • income;
  • transaction history;
  • employment;
  • debt;
  • repayment history;
  • location-related information; and
  • behavioural indicators.

The algorithm may approve Customer A but reject Customer B.

That creates several questions:

Was the information accurate?

Was the algorithm properly tested?

Was the decision unfairly influenced by irrelevant characteristics?

Can the decision be explained?

Who is accountable if the algorithm is wrong?

A technology ethics board can provide governance over these questions before technological risks become customer losses or regulatory violations.

3. Technology Ethics Board Is Not a Substitute for the Board of Directors

Creating a specialist committee does not remove the responsibilities of a bank's board and senior management.

A bank cannot simply argue:

“The algorithm caused the problem, so nobody in management is responsible.”

Technology is a tool operated within the institution's governance structure.

Ultimate responsibility for sound governance remains with the persons and bodies to whom Kuwaiti banking law and CBK regulations assign those responsibilities.

A technology ethics committee therefore generally works under the wider board-governance structure, rather than replacing it.

4. Possible Composition

A strong technology ethics board could include representatives from:

  • technology;
  • cybersecurity;
  • compliance;
  • legal;
  • risk management;
  • internal control;
  • data governance;
  • consumer protection;
  • model-risk management;
  • AML/CFT; and
  • relevant business functions.

An Islamic bank may additionally need coordination with its Sharia supervisory governance structure where technology affects Sharia-compliant products.

The advantage of a multidisciplinary structure is that technological decisions are not evaluated solely by software engineers.

An application can be technically excellent while still creating legal or ethical problems.

5. Artificial Intelligence in Credit Decisions

AI-based lending is one of the strongest arguments for establishing technology ethics oversight.

Suppose Bank K introduces an AI system that predicts default probability.

The system recommends:

  • Applicant A — approve;
  • Applicant B — approve;
  • Applicant C — reject.

The bank should be able to determine why those outcomes occurred.

A technology governance body could require:

data-quality testing → model validation → fairness assessment → legal review → cybersecurity review → human escalation mechanism → post-deployment monitoring.

A high predictive accuracy rate alone is not enough.

6. Explainability

Some machine-learning systems operate in ways that are difficult for ordinary customers—and sometimes even bank employees—to interpret.

This creates an explainability problem.

If an automated system rejects a customer, freezes a transaction or assigns an unusually high risk score, a regulated institution should understand the basis upon which the system operates sufficiently to satisfy its legal and risk-management obligations.

Technology ethics governance can therefore establish requirements concerning:

  • model documentation;
  • decision logs;
  • testing methodology;
  • data sources;
  • model limitations;
  • human review; and
  • escalation procedures.

7. Algorithmic Bias and Fairness

Algorithms learn from data.

Historical data can contain distortions.

For example, suppose historical lending decisions systematically disadvantaged a particular category of customers. An AI trained blindly on those decisions may reproduce the same pattern.

The bank therefore needs to distinguish between:

legitimate credit-risk differentiation

and

unjustifiable algorithmic discrimination or unfair treatment.

A technology ethics board can require periodic testing for anomalous or unfair outcomes.

8. Human Oversight

A fundamental governance principle is human accountability.

Banks should identify situations where automated recommendations require human intervention.

Examples can include:

  • unusually large credit decisions;
  • high-risk customers;
  • sanctions alerts;
  • disputed fraud blocks;
  • vulnerable customers;
  • abnormal algorithmic results; and
  • decisions capable of causing substantial customer harm.

“Computer says no” should not become a complete governance framework.

9. Customer Data and Privacy

Modern banking technology depends upon enormous quantities of customer data.

A bank may possess:

  • identity information;
  • account balances;
  • spending patterns;
  • salary information;
  • device identifiers;
  • payment histories;
  • investment information; and
  • authentication data.

An ethics board can evaluate whether proposed technological use of such data has an adequate legal and business justification.

The relevant questions include:

Do we need this data?

Are customers adequately informed?

Who can access it?

How long is it retained?

Can the same objective be achieved with less information?

Is a third-party technology provider receiving it?

10. Biometric Banking

Banks increasingly use biometric technologies such as:

  • facial verification;
  • fingerprints;
  • voice recognition; and
  • behavioural authentication.

Biometric data can improve fraud prevention, but compromise of such information creates serious risks.

A password can be changed.

A person's face or fingerprint cannot be replaced in the same manner.

Technology ethics governance should therefore subject biometric projects to particularly careful necessity, security and proportionality analysis.

11. Cybersecurity

Technology ethics cannot be separated from cybersecurity.

An innovative service that exposes customers to unacceptable cyber risk is not responsibly governed.

Kuwaiti banks must operate within CBK cybersecurity and operational-risk requirements.

A technology governance committee could monitor:

  • penetration testing;
  • privileged access;
  • encryption;
  • incident response;
  • authentication;
  • ransomware preparedness;
  • vulnerability remediation;
  • third-party security; and
  • disaster recovery.

Cybersecurity therefore becomes both a technical and governance issue.

12. Outsourcing and Cloud Computing

A bank may use external providers for:

  • cloud infrastructure;
  • AI models;
  • payment processing;
  • customer verification;
  • cybersecurity;
  • analytics; and
  • software-as-a-service applications.

But outsourcing technology does not necessarily outsource regulatory responsibility.

Before adopting a third-party AI or cloud system, the bank should consider:

vendor risk → information security → confidentiality → data location → business continuity → audit/access rights → regulatory requirements → exit strategy.

A technology ethics board can provide an additional review layer for high-risk outsourcing.

13. Generative AI

Generative AI creates newer governance problems.

Bank employees might use generative AI for:

  • drafting reports;
  • analysing documents;
  • coding;
  • customer-service assistance;
  • compliance research; and
  • summarizing internal information.

Potential problems include inaccurate outputs, confidential-data leakage, cybersecurity weaknesses and excessive reliance on generated answers.

A responsible bank can classify AI applications by risk.

For example:

Low risk: drafting non-sensitive internal text.

Medium risk: summarizing controlled internal documents.

High risk: automated customer lending or compliance decisions.

Greater risk should produce stronger human and governance oversight.

14. AML/CFT Technology

Banks increasingly use algorithms to detect suspicious financial behaviour.

Technology can identify:

  • unusual transfers;
  • rapid movement of funds;
  • transaction structuring;
  • anomalous payment patterns; and
  • relationships between apparently unrelated accounts.

However, poor models can generate thousands of meaningless alerts or fail to identify genuinely suspicious conduct.

Technology ethics and compliance governance therefore need to address model effectiveness as well as automation efficiency.

AML responsibility cannot simply be delegated to an algorithm.

15. Islamic Banking

Technology governance has an additional dimension in Kuwaiti Islamic banks.

Suppose an AI system automatically recommends financing products.

The algorithm must not merely optimize profitability. Its operation must remain consistent with the institution's applicable Sharia governance framework.

Technology teams may therefore need coordination with the bank's Sharia supervisory function.

For example:

AI product design → legal review → risk review → technology review → Sharia review → deployment.

Automation should not change the substantive character of a Sharia-compliant product without appropriate oversight.

16. Consumer Protection

Digital transformation can create significant customer benefits, but it can also generate:

  • misleading interfaces;
  • difficult cancellation processes;
  • hidden automated decisions;
  • unauthorized transactions;
  • inaccessible complaint procedures; and
  • excessive behavioural manipulation.

A technology ethics board can review products from the customer's perspective before deployment.

An important principle is:

legal compliance is the minimum standard; responsible technology governance should also consider foreseeable customer harm.

17. Technology Incident Reporting

Technology failures can quickly become banking crises.

Suppose a software update causes thousands of customers to see incorrect balances.

The institution needs an established procedure covering:

detection → containment → management escalation → legal/regulatory assessment → customer protection → recovery → investigation → remediation.

Serious incidents may also trigger regulatory notification obligations under applicable CBK rules.

Technology ethics governance should therefore continue after deployment rather than ending when a system is approved.

Case Laws and Judicial Authorities

There is limited publicly accessible Kuwaiti case law specifically concerning “technology ethics boards” in banks. That is unsurprising because this is primarily an emerging corporate-governance concept rather than a traditional standalone cause of action.

Accordingly, comparative decisions involving automated decision-making, banking technology, privacy and institutional accountability are useful—but they should not be mislabelled as Kuwaiti precedents.

18. Case 1 — CJEU, SCHUFA Holding (Scoring)

Case C-634/21, OQ v Land Hessen, 7 December 2023

This is one of the most important modern cases concerning automated financial scoring.

SCHUFA generated creditworthiness scores used by financial institutions. The Court examined when automated scoring can amount to an automated individual decision where third parties give the score a determining role.

Kuwait relevance

A Kuwaiti bank using automated credit scoring should not assume that purchasing a score from a technology provider eliminates the bank's governance responsibility.

It illustrates the need for:

  • explainability;
  • human oversight;
  • model governance; and
  • clear responsibility for consequential automated decisions.

19. Case 2 — CJEU, SCHUFA Holding (Discharge from Remaining Debts)

Joined Cases C-26/22 and C-64/22, 7 December 2023

The Court considered retention and processing of financial information by a private credit-information agency.

The judgment emphasized limits on retaining and using financially sensitive personal information.

Kuwait relevance

Banks should not assume that because data were lawfully obtained, they may be stored and reused indefinitely for every future AI application.

Lawful collection does not automatically justify unlimited secondary use.

20. Case 3 — CJEU, UI v Österreichische Post

Case C-300/21, 4 May 2023

The Court addressed compensation for infringements of data-protection rights.

It held, among other things, that infringement alone does not automatically create a right to compensation without damage, while EU law does not impose a minimum seriousness threshold for non-material damage.

Comparative significance

Banks implementing AI and data-intensive technology should treat privacy governance as substantive risk management rather than a documentation exercise.

Poor technology governance can ultimately create financial liability as well as regulatory risk.

21. Case 4 — CJEU, Google Spain

Case C-131/12, Google Spain SL and Google Inc. v AEPD and Mario Costeja González, 13 May 2014

The Court examined responsibilities arising from automated processing and organization of personal information by a search engine.

Although unrelated to Kuwaiti banking directly, the judgment became a major authority on the responsibilities associated with large-scale automated personal-data processing.

Banking lesson

Organizations controlling sophisticated technology systems can bear legal responsibility for how those systems process personal information.

The existence of an algorithm does not eliminate organizational accountability.

22. Case 5 — CJEU, Digital Rights Ireland

Joined Cases C-293/12 and C-594/12, 8 April 2014

The Court invalidated the EU Data Retention Directive because of disproportionate interference with fundamental privacy rights.

Comparative lesson

Collecting enormous amounts of information simply because technology makes collection possible is not automatically justified.

For a bank's technology ethics committee, this supports the principle of data minimization and proportionality.

23. Case 6 — CJEU, La Quadrature du Net

Joined Cases including C-511/18, C-512/18 and C-520/18, 6 October 2020

The Court examined large-scale retention of electronic communications data for security purposes.

The judgments stressed necessity and proportionality in technologically enabled surveillance.

Kuwait relevance

Although the case concerns European communications law rather than Kuwaiti banking law, its governance lesson is valuable:

technical capability does not itself establish legal necessity.

Banks should therefore distinguish what technology can collect from what the institution legitimately needs to collect.

24. Case 7 — UK Supreme Court, Lloyd v Google LLC

[2021] UKSC 50

The case concerned large-scale processing of internet users' data and claims for damages.

The Supreme Court addressed important questions concerning mass data-processing claims and compensation.

Banking relevance

Large technology platforms and banks share an important characteristic: a single system can process information relating to millions of individuals.

Consequently, one defective technological design can create systemic rather than isolated compliance risk.

25. Case 8 — UK Court of Appeal, Quoine Pte Ltd v B2C2 Ltd

[2020] SGCA(I) 02 is actually the authoritative Singapore Court of Appeal decision in this litigation.

The case arose from algorithmic cryptocurrency trading and examined contracts automatically executed by computer systems.

The Court rejected simplistic attempts to attribute ordinary human knowledge directly to algorithms and examined the intentions and knowledge of the programmers in the relevant legal context.

Importance for banking technology

The decision demonstrates a difficult question increasingly relevant to automated banking:

When software performs the transaction, whose knowledge and intention matter legally?

This strengthens the argument for maintaining documented human responsibility for algorithm design, deployment and monitoring.

26. Three-Lines-of-Defence Model

Technology ethics governance can fit naturally within banking risk management.

First line: business and technology teams own the system and its risks.

Second line: risk, compliance, cybersecurity, privacy and model-governance functions independently challenge the system.

Third line: internal audit assesses whether governance and controls actually work.

The technology ethics board can coordinate major questions without undermining the independence of these functions.

27. Recommended Approval Process

For a high-risk AI banking system, a strong Kuwaiti governance model could operate as:

Business proposal

↓

Technology feasibility assessment

↓

Data/privacy assessment

↓

Cybersecurity assessment

↓

Legal and regulatory review

↓

Model validation and fairness testing

↓

AML/CFT review where relevant

↓

Sharia review where applicable

↓

Technology Ethics Board recommendation

↓

Senior management/board approval where required

↓

Controlled deployment

↓

Continuous monitoring and periodic revalidation

This produces an auditable decision trail.

28. Board Documentation

Documentation is crucial.

If a regulator later asks why an AI lending system was approved, the bank should ideally be capable of producing records explaining:

  • intended purpose;
  • data used;
  • testing performed;
  • identified risks;
  • model limitations;
  • cybersecurity assessment;
  • customer-impact analysis;
  • persons approving deployment;
  • human-override mechanisms; and
  • post-deployment monitoring.

An undocumented ethics committee provides little regulatory value.

29. When Technology Should Be Rejected

An ethics board should possess meaningful escalation authority.

A system should not automatically be deployed merely because it increases revenue or reduces staffing costs.

Deployment may need to be postponed or rejected where, for example:

  • cybersecurity risk is unacceptable;
  • customer information cannot adequately be protected;
  • critical decisions cannot be sufficiently explained;
  • model testing reveals material unfairness;
  • the vendor refuses necessary audit rights;
  • regulatory compliance cannot be demonstrated; or
  • an Islamic banking application creates unresolved Sharia issues.

An effective committee must therefore be capable of saying no, not merely documenting approval.

30. Regulatory Direction

Technology ethics boards are likely to become increasingly relevant as banking moves toward:

AI-driven credit → biometric banking → open APIs → cloud infrastructure → automated AML → generative AI → autonomous financial agents.

The legal framework may continue to evolve, but existing principles already impose substantial governance responsibilities.

Banks should therefore not wait for legislation expressly titled “AI Ethics Board Law.”

Traditional duties concerning governance, risk management, cybersecurity, customer protection and regulatory accountability can already apply to new technologies.

Conclusion

Kuwait does not presently need a statute expressly called a “Technology Ethics Boards in Banks Act” for technology governance to have legal significance. Existing banking, CBK governance, cybersecurity, AML/CFT, electronic-transactions and customer-protection obligations already require banks to exercise responsible oversight over technological systems.

A technology ethics board can provide an effective institutional mechanism for integrating these obligations.

Its central principles should be:

accountability + human oversight + data governance + cybersecurity + explainability + fairness + customer protection + model validation + third-party risk + continuous monitoring.

For Islamic banks, Sharia governance adds another important dimension.

Because reported Kuwaiti judicial precedent specifically addressing banking AI ethics committees remains limited, comparative authorities should be identified as such rather than presented as Kuwait cases. *SCHUFA (C-634/21), the related SCHUFA cases, Google Spain, Digital Rights Ireland, La Quadrature du Net, Lloyd v Google, Quoine v B2C2 and Österreichische Post* collectively demonstrate the emerging judicial principle most relevant to Kuwait:

A regulated institution does not cease to be legally accountable merely because an important decision has been delegated to software.

For Kuwaiti banks, the safest governance model is therefore technology innovation under identifiable human responsibility, with the board retaining ultimate oversight and specialist technology ethics governance providing structured review of high-risk systems.

LEAVE A COMMENT