Banking Law And Group-Wide Risk Management Kuwait .
1. Introduction
Group-wide risk management means identifying, measuring, monitoring and controlling risks across an entire banking group rather than examining only the licensed bank as a separate entity.
A Kuwaiti banking group may contain:
Parent bank → domestic subsidiaries → foreign subsidiaries → overseas branches → investment companies → finance companies → special-purpose entities → other controlled entities.
A weakness in one entity can affect the financial condition, liquidity, reputation or regulatory compliance of the rest of the group. Kuwait's framework therefore combines the Central Bank of Kuwait (CBK) Law, prudential instructions, corporate-governance requirements, consolidated supervision, capital and liquidity requirements, concentration controls, internal controls and cooperation with foreign supervisors.
An important statutory provision is Article 78 of Law No. 32 of 1968, which expressly permits the CBK to inspect branches, companies and banks operating abroad that are subsidiaries of Kuwaiti banks and provides for coordination with foreign banking supervisors.
2. Meaning of Group-Wide Risk
Suppose a Kuwaiti Bank A owns:
- Finance Company B in Kuwait;
- Bank C in another GCC state;
- Investment Company D;
- technology subsidiary E; and
- several overseas branches.
Looking only at Bank A's individual balance sheet could produce an incomplete picture.
For example, Bank C could suffer major credit losses while Investment Company D holds highly leveraged positions. At the same time, Bank A might have guaranteed obligations of both companies.
A proper assessment therefore requires:
Entity-level risk + intra-group risk + consolidated exposure + contagion risk = group-wide risk assessment.
This is the central concept behind consolidated banking supervision.
3. Statutory Foundation — Law No. 32 of 1968
The principal banking legislation is Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business, as amended.
Article 71 gives the CBK authority to issue instructions to banks where necessary to ensure the sound progress of banking.
Article 72 permits the CBK to establish rules concerning liquidity and solvency, including ratios involving banks' own funds, liabilities, liquid assets, guarantees and acceptances.
These provisions provide the statutory foundation for extensive prudential supervision.
4. Article 78 and Consolidated Supervision
Article 78 is particularly significant for banking groups.
It authorises the CBK to inspect not only regulated banks and financial institutions in Kuwait but also:
branches, companies and banks operating abroad that are subsidiaries of Kuwaiti banks.
Such inspections are coordinated with the relevant foreign central bank or banking supervisory authority.
This means that supervision does not necessarily stop at Kuwait's geographical border.
For a Kuwaiti banking group:
Kuwaiti parent bank
↓
Foreign subsidiary
↓
Foreign branch
↓
Relevant group risks
may all become important to CBK supervision.
5. Information Sharing Between Regulators
Group-wide risk management becomes especially difficult when subsidiaries operate in several countries.
Article 78 also permits information exchanges between the CBK and other central banks or banking supervisory authorities for the purposes of aggregate supervision of banks, branches and subsidiaries.
Thus, if a Kuwaiti bank owns an overseas banking subsidiary, the structure can involve:
CBK as home supervisor
↔
Foreign regulator as host supervisor
↔
Banking group
Such cooperation helps supervisors identify risks that would otherwise remain hidden within separate jurisdictions.
6. Role of the Board of Directors
Group-wide risk management begins with the board.
The CBK's corporate-governance framework places substantial responsibility on bank boards concerning governance and risk management. In its 2019 amendments, the CBK specifically reinforced risk-management governance and the role of boards, while also introducing compliance governance within the bank's overall risk-management framework.
The board should therefore understand not merely the parent bank's individual risks but the material risks created by the group's structure and activities.
A practical governance structure is:
Board of Directors
↓
Board Risk Committee
↓
Group Chief Risk Officer
↓
Group Risk Management Function
↓
Subsidiary risk functions
↓
Business units
↓
Consolidated reporting to senior management and board
7. Group Risk Appetite
A banking group should establish a risk appetite indicating how much risk it is prepared to accept while pursuing its strategy.
This may cover:
- credit risk;
- market risk;
- liquidity risk;
- interest-rate risk;
- operational risk;
- cyber risk;
- concentration risk;
- country risk;
- compliance risk;
- legal risk;
- reputational risk; and
- strategic risk.
The problem with a purely entity-level approach is that each subsidiary might remain within its individual limit while the group as a whole becomes excessively exposed to the same risk.
8. Example of Group Concentration
Assume:
Bank A lends KWD 40 million to Corporate Group X.
Its subsidiary lends another KWD 25 million.
A foreign banking subsidiary provides KWD 20 million.
An investment subsidiary purchases KWD 15 million of bonds issued by X.
Examined separately, each exposure might appear manageable.
But group-wide exposure is:
40 + 25 + 20 + 15 = KWD 100 million.
Group-wide risk management therefore requires aggregation of connected exposures where required by the applicable prudential framework.
9. Centralised Risk Information
Article 83 permits the CBK to establish a Centralized Risks System. Its purposes include helping banks evaluate the financial positions of persons seeking credit and enabling the CBK to monitor banking-credit trends.
The CBK's Surveillance Department also analyses financial statements, identifies risks affecting banking and financial sectors, monitors sector-wide risk trends and cooperates with foreign regulators concerning consolidated supervision and information exchange.
This illustrates an important principle:
Effective risk management requires reliable consolidated information.
10. Credit Risk
Credit risk is the possibility that a borrower or counterparty will fail to perform its obligations.
At group level, banks need to consider whether apparently separate exposures are economically connected.
For example:
Company A owns Company B
Company B guarantees Company C
Company C depends on Company A for revenue.
Treating all three as completely independent could underestimate the group's real economic exposure.
Consequently, connected-counterparty analysis is important to consolidated credit-risk management.
11. Liquidity Risk
Liquidity risk is another major group-wide issue.
A parent bank may appear liquid while a foreign subsidiary experiences a serious liquidity shortage.
The group must consider:
- where liquidity is located;
- whether funds can legally be transferred;
- currency mismatches;
- collateral availability;
- foreign regulatory restrictions;
- intra-group funding;
- emergency liquidity requirements; and
- stress conditions.
Thus:
Group liquidity ≠ simply adding all cash balances together.
Some liquidity can be trapped within subsidiaries or jurisdictions.
12. Market Risk
Group-wide market risk includes exposures to:
interest rates + foreign currencies + securities prices + commodity-related exposures + other market variables.
A subsidiary might hold a position that offsets or amplifies a position held by the parent.
Therefore, consolidated risk systems should identify both:
gross exposure
and, where legally and prudentially appropriate,
net exposure.
13. Operational Risk
A banking group may share:
- IT infrastructure;
- data centres;
- payment systems;
- employees;
- outsourcing providers;
- cybersecurity infrastructure;
- compliance systems; and
- business-continuity facilities.
This creates interdependence.
A cyber incident affecting one common technology provider can potentially disrupt several entities simultaneously.
Group-wide operational-risk management therefore requires the bank to understand common dependencies, not merely incidents occurring within each individual legal entity.
14. Intra-Group Transactions
Intra-group transactions can create significant contagion risk.
Examples include:
- parent-to-subsidiary loans;
- subsidiary deposits with parent;
- guarantees;
- derivatives;
- asset transfers;
- management-service arrangements;
- shared technology;
- cross-collateralisation; and
- capital support.
Consider:
Parent Bank → KWD 100 million loan → Subsidiary
and
Parent Bank → guarantee of subsidiary debt.
If the subsidiary fails, the parent may suffer both the direct credit exposure and the guarantee exposure.
Group-wide systems should therefore prevent risks from being hidden through internal transactions.
15. Related-Party and Conflict Risk
Banking groups can also create conflicts of interest.
A bank might provide favourable financing to:
- controlling shareholders;
- directors;
- affiliated companies;
- sister companies; or
- other related parties.
Article 69 of the CBK Law specifically restricts loans, advances and guarantees in favour of bank directors without prior General Assembly permission and requires such transactions to be subject to the conditions and rules applied to other customers.
This illustrates the wider principle that group relationships must not undermine prudent credit decision-making.
16. Capital Adequacy
A banking group requires sufficient capital to absorb losses.
Group-wide capital assessment prevents a group from creating the appearance of strong capital through repeated use of the same capital resources across different entities.
Conceptually:
Parent capital → subsidiary investment → subsidiary capital
should not automatically be treated as two completely independent layers of loss-absorbing capital at consolidated level.
This is why regulatory consolidation is critical.
The CBK's conventional-bank instructions cover prudential subjects including liquidity, credit concentration, financial statements and credit classification.
17. Islamic Banking Groups
Group-wide risk management also applies to Islamic banking groups.
Article 97 authorises the CBK Board to establish rules for Islamic banks concerning:
- liquidity;
- solvency;
- capital adequacy;
- asset-risk provisioning; and
- organisation of business.
Article 98 also permits limits relating to activities, equity holdings in companies and participation in individual projects.
Islamic banking groups may additionally need to manage risks arising from Sharia-compliant structures and investment arrangements.
18. Complex Group Structures
Complexity can itself create risk.
Consider:
Bank
↓
Holding Company
↓
Finance Subsidiary
↓
SPV
↓
Foreign Subsidiary
↓
Joint Venture
As the number of layers increases, it can become harder for the board, risk function, auditors and regulator to understand where risks are located.
The CBK corporate-governance framework expressly addresses group structures and banks with complex structures as governance subjects. Kuwaiti banks' published governance frameworks reflect these requirements.
19. Three Lines of Defence
A practical group risk-management system commonly uses three levels.
First line — Business functions
Business units originate and manage risks.
Second line — Risk and compliance
Independent risk-management and compliance functions establish frameworks, monitor limits and challenge business decisions.
Third line — Internal audit
Internal audit independently evaluates whether governance, controls and risk-management processes operate effectively.
The board ultimately remains responsible for ensuring that these arrangements function adequately.
20. Stress Testing
Group-wide stress testing asks what would happen if several risks occurred simultaneously.
For example:
Oil-price shock
↓
economic slowdown
↓
corporate defaults
↓
property-price decline
↓
credit losses
↓
foreign subsidiary losses
↓
liquidity pressure
↓
capital deterioration.
Testing only one subsidiary at a time could fail to reveal this chain reaction.
Group-wide stress testing therefore attempts to identify correlated losses and contagion.
21. Recovery Planning
Group-wide risk management should also consider severe financial distress.
A recovery plan may examine:
- capital raising;
- asset sales;
- reduction of risk-weighted assets;
- liquidity generation;
- disposal of subsidiaries;
- restrictions on dividends;
- reduction of exposures;
- contingency funding; and
- operational continuity.
The critical question is not merely:
“Can the parent survive?”
It is also:
“Can the banking group continue performing critical functions during severe stress?”
22. Role of the CBK
The CBK's supervisory functions include preparing prudential regulations, analysing information submitted by regulated entities, conducting inspections, identifying emerging problems and aligning supervisory procedures with international standards.
Its surveillance function additionally monitors systemic risk and cooperates with host-country regulators on consolidated supervision.
Therefore:
Bank manages risk internally
while
CBK supervises whether the framework is adequate and prudential requirements are satisfied.
23. Case Law
A qualification is important. There is not a large publicly accessible body of Kuwaiti Court of Cassation judgments specifically deciding modern “group-wide risk management” or Basel consolidated-supervision disputes.
It would therefore be inaccurate to describe ordinary loan cases as direct group-risk-management precedents. The following Kuwait authorities provide analogous judicial principles relevant to banking regulation, group entities, corporate personality, contractual exposures and regulated financial activity.
Case 1 — Kuwait Court of Cassation, Appeal No. 508/2016
Facts and issue
The dispute concerned a bank loan, changes in interest and the relationship between contractual terms and CBK requirements.
Principle
The case illustrates that banking relationships do not operate exclusively according to private contractual terms. Applicable CBK regulation must also be considered.
Group-wide risk relevance
A banking group cannot justify a risky intra-group transaction merely by saying that the transaction is contractually valid.
A transaction may simultaneously engage:
contract law + banking regulation + prudential requirements.
Thus, group risk policies must take regulatory limits into account even where every group entity has formally agreed to the transaction.
Case 2 — Kuwait Court of Cassation, Appeal No. 1180/2009
Issue
This authority concerned banking lending and CBK requirements affecting interest rates.
Principle
Mandatory banking regulation can constrain private contractual arrangements.
Group-wide relevance
Suppose a parent bank establishes a common lending policy for all subsidiaries.
Internal group policy cannot override mandatory requirements applicable to the regulated entity.
Therefore:
Group policy < mandatory banking regulation.
This becomes particularly important where different subsidiaries operate in different jurisdictions.
Case 3 — Kuwait Court of Cassation, Appeal No. 1384/2019
Judgment of 22 February 2024
The Court addressed loans granted by banks in the ordinary course of banking activity.
Principle
Loans made by banks as part of ordinary banking activity are commercial banking transactions regardless of the borrower's status or ultimate purpose.
Group-risk relevance
A bank's exposure does not lose its banking character merely because financing is channelled to:
- an affiliate;
- corporate subsidiary;
- project company; or
- another commercial undertaking.
Risk-management systems should therefore analyse the economic substance of financing exposures rather than relying only upon labels.
Case 4 — Kuwait Court of Cassation, Appeal No. 3656/2023
Judgment of 11 June 2024
Issue
This case involved a banking-loan relationship, closure of the relevant loan account and calculation of amounts claimed.
Principle
The contractual and statutory framework, together with reliable financial evidence, is important when establishing amounts arising from a banking relationship.
Group-wide relevance
A banking group should be able to reconstruct its exposures:
Entity → counterparty → facility → principal → interest/profit → collateral → guarantee → outstanding amount.
Without reliable group data, management cannot accurately determine consolidated exposure.
The case is therefore useful by analogy for the importance of reliable financial records, although it was not itself a consolidated-risk case.
Case 5 — Kuwait Court of Cassation, Appeal No. 14/2022
Judgment of 23 September 2025
Issue
The case concerned investment arrangements entered into without the necessary financial regulatory authorisation.
Principle
The Court treated relevant mandatory financial-sector requirements as connected with economic public order, with significant consequences for activities conducted without required authorization.
Group-wide relevance
A banking group cannot circumvent regulation simply by moving an activity into:
subsidiary → affiliate → SPV → related company.
Each entity's actual activity and applicable licensing framework must be considered.
Group structure therefore cannot legitimately be used to disguise regulated activity.
Case 6 — Kuwait Court of Cassation, Commercial Appeal No. 808/2000
Judgment of 16 June 2001
This authority has been cited in Kuwaiti banking-law discussions concerning bank lending and contractual/statutory interest.
Principle
Banking financial obligations must be determined within the applicable contractual and statutory framework.
Group-wide relevance
Where a banking group has numerous intercompany loans, deposits and financing arrangements, the legal terms governing each exposure remain important.
Consolidation for risk-management purposes does not erase the underlying legal obligations of individual companies.
This creates an important distinction:
Accounting/risk consolidation ≠ disappearance of separate legal obligations.
Case 7 — Kuwait Court of Cassation, Civil Appeal No. 479/2004
Judgment of 19 September 2005
The dispute involved a banking current account and the interest applicable after closure of the account.
Principle
The legal status and maturity of a banking obligation can affect the financial consequences attached to it.
Group-wide relevance
Accurate group-risk measurement requires exposures to be correctly classified according to their legal and financial characteristics.
For example:
performing loan ≠ defaulted exposure ≠ guarantee ≠ derivative ≠ closed current account balance.
An inaccurate classification can distort consolidated risk information.
Case 8 — Kuwait Court of Cassation, Appeal No. 449/2006
Judgment of 20 January 2009
This case is useful for the cross-border dimension of banking groups.
The Court considered the law applicable to the legal status of a foreign company and applied the law associated with the company's principal effective place of management.
Group-wide relevance
A Kuwaiti banking group may own subsidiaries incorporated and operating abroad.
Those entities may therefore be affected by:
Kuwait consolidated supervision
plus
foreign company law
plus
host-state banking regulation.
Group-wide risk management must recognise these overlapping legal systems.
24. Separate Legal Personality Versus Consolidated Supervision
One of the most important concepts is the distinction between corporate law and prudential supervision.
Suppose:
Kuwaiti Bank A owns 100% of Subsidiary B.
Under company law, B ordinarily remains a separate legal person.
But for prudential purposes, regulators may still need to examine A and B together.
Therefore:
Separate legal personality does not prevent consolidated risk supervision.
Conversely:
Consolidated supervision does not automatically abolish separate legal personality.
This distinction is crucial when analysing guarantees, insolvency, intra-group loans and liability.
25. Practical Group-Wide Risk Framework
A well-managed Kuwaiti banking group can structure the process as follows:
Step 1 — Map the group
Identify parent, branches, subsidiaries, affiliates, SPVs and material investments.
↓
Step 2 — Identify risks
Credit, market, liquidity, operational, legal, compliance, cyber, concentration, country and reputational risks.
↓
Step 3 — Aggregate exposures
Identify connected counterparties and intra-group exposures.
↓
Step 4 — Establish limits
Set entity and consolidated risk limits.
↓
Step 5 — Monitor
Produce reliable and timely risk reports.
↓
Step 6 — Stress test
Assess severe but plausible scenarios.
↓
Step 7 — Escalate breaches
Material limit breaches should reach senior management and, where appropriate, the board.
↓
Step 8 — Correct
Reduce exposures, increase capital/liquidity, hedge risks or change business strategy.
↓
Step 9 — Report
Provide appropriate information to the CBK and other supervisors.
26. Example
Assume Kuwait Bank K has:
| Entity | Risk exposure |
|---|---|
| Parent bank | KWD 200m |
| Kuwait finance subsidiary | KWD 75m |
| Foreign bank subsidiary | KWD 100m |
| Investment subsidiary | KWD 50m |
Looking only at the parent produces an apparent exposure of:
KWD 200 million.
But the relevant consolidated economic exposure could potentially reach:
KWD 425 million
before considering eliminations, guarantees, hedges, regulatory treatment and other applicable adjustments.
If all entities are exposed to the same corporate group or economic sector, the risk may be substantially more concentrated than the parent's standalone balance sheet suggests.
27. Cross-Border Supervision
Cross-border banking groups create an additional layer:
Home supervisor — CBK
↕
Kuwaiti parent
↕
Foreign subsidiary
↕
Host supervisor
Article 78 expressly provides the statutory basis for CBK inspection of foreign subsidiaries of Kuwaiti banks and regulatory coordination.
Historically, international assessments have nevertheless identified areas in which Kuwait's consolidated and cross-border supervisory framework could be strengthened, particularly formalisation of powers concerning group entities and deeper cooperation with foreign supervisors.
That historical assessment should not automatically be treated as a description of every aspect of the framework in 2026, because supervisory practices and rules can develop over time.
28. Why Group-Wide Management Matters
A bank can be individually sound while its wider group contains serious vulnerabilities.
For example:
Foreign subsidiary suffers losses
↓
Parent provides emergency funding
↓
Parent liquidity declines
↓
Credit rating deteriorates
↓
Funding becomes expensive
↓
Depositor/market confidence weakens
↓
Entire group comes under pressure.
This is called contagion risk.
The purpose of group-wide supervision is partly to identify this chain before losses threaten the regulated bank.
29. Key Legal Principles
The Kuwait framework can therefore be summarised through several principles:
- The board retains responsibility for effective risk governance.
- Risk should be considered across material group entities, not merely the parent bank.
- Foreign subsidiaries can fall within the CBK's consolidated supervisory reach.
- Credit, liquidity, market, operational and concentration risks should be aggregated appropriately.
- Intra-group transactions can create contagion and conflicts of interest.
- Separate corporate personality does not prevent consolidated prudential supervision.
- Consolidated supervision does not automatically make the parent legally liable for every subsidiary obligation.
- Mandatory regulatory requirements cannot be avoided merely through contractual or corporate structuring.
- Reliable consolidated data are essential to effective risk management.
- Cross-border groups require cooperation between home and host regulators.
30. Conclusion
Group-wide risk management is a fundamental component of banking supervision in Kuwait. Its statutory foundation is particularly visible in Law No. 32 of 1968, including Articles 71, 72 and 78. Article 78 is especially significant because it permits CBK inspection of overseas branches, companies and banks that are subsidiaries of Kuwaiti banks and facilitates information exchange with foreign supervisors for aggregate supervision.
The CBK's corporate-governance framework reinforces this structure by emphasising board responsibility, risk-management governance, compliance governance, internal controls and appropriate oversight of group and complex corporate structures.
In practical terms, the framework is:
Board oversight → group risk appetite → consolidated identification → exposure aggregation → capital and liquidity management → internal controls → stress testing → reporting → CBK consolidated supervision.
The Kuwait Court of Cassation cases discussed above should be used carefully. They do not constitute eight direct judgments on Basel-style group-wide risk management. Rather, they establish or illustrate surrounding principles involving mandatory banking regulation, regulated financial activities, lending obligations, financial evidence, foreign companies and the relationship between private banking arrangements and the supervisory framework. Those principles provide the judicial background against which Kuwait's statutory and regulatory system of group-wide risk management operates.

comments