Banking Law And Ict Risk Management Regulation Kuwait .

Banking Law and Identity and Access Governance in Kuwait

1. Introduction

Identity and Access Governance, commonly called IAG, is the legal, managerial and technical system through which a bank determines:

  • Who may access its systems and data;
  • What information or functions that person may access;
  • How the person’s identity is verified;
  • Who approves the access;
  • How privileged access is monitored;
  • When access must be suspended or removed; and
  • How the bank proves that its controls operated correctly.

In Kuwait, identity and access governance is not regulated by one separate statute. It arises from several connected sources, particularly:

  1. The Central Bank of Kuwait regulatory framework;
  2. The CBK Cyber and Operational Resilience Framework;
  3. The Electronic Transactions Law;
  4. The Cybercrime Law;
  5. Data privacy regulations;
  6. Banking confidentiality obligations;
  7. Anti-money-laundering and customer-identification requirements; and
  8. General contractual, civil and employment-law duties.

For a Kuwaiti bank, identity governance is therefore more than an information-technology issue. It is part of banking supervision, operational resilience, customer protection, privacy, fraud prevention and senior-management accountability.

The Central Bank of Kuwait introduced its banking-sector Cybersecurity Framework in 2020. In December 2025, it launched the updated Cyber and Operational Resilience Framework, or CORF, for local banks and financial institutions.

2. Meaning of Identity and Access Governance

Identity governance manages the complete life cycle of every digital identity connected with the bank.

This includes:

  • Customers using mobile or internet banking;
  • Bank employees;
  • Directors and senior managers;
  • System administrators;
  • Contractors and consultants;
  • Cloud-service personnel;
  • FinTech partners;
  • Payment-service providers;
  • Software robots and automated accounts;
  • Application programming interfaces;
  • Service and machine accounts; and
  • Emergency or “break-glass” accounts.

Identity management answers the question: Who is the user?

Access management answers: What is the user allowed to do?

Identity governance answers the wider questions:

  • Why does the user need that access?
  • Who approved it?
  • Is the access still necessary?
  • Is it inconsistent with the user’s other powers?
  • Has it been used suspiciously?
  • Can the bank produce evidence of all decisions?

3. Main Legal Framework in Kuwait

3.1 Central Bank of Kuwait Law and supervisory authority

Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business gives the CBK extensive authority over banks and regulated financial institutions.

Under this supervisory structure, banks are expected to maintain effective:

  • Internal-control systems;
  • Risk-management arrangements;
  • Information-security controls;
  • Operational-resilience measures;
  • Outsourcing supervision;
  • Customer-information safeguards; and
  • Governance and audit arrangements.

Weak access controls may therefore be treated as a failure of internal governance even when no money has yet been stolen.

The CBK may require corrective action and may use its supervisory or enforcement powers where a bank’s systems create unacceptable operational, cybersecurity or customer-protection risks.

3.2 CBK Cyber and Operational Resilience Framework

The CBK framework is the most directly relevant regulatory source for banking identity governance.

A compliant access-control system should ordinarily cover:

  • Unique user identification;
  • Strong authentication;
  • Multi-factor authentication;
  • Role-based or attribute-based access;
  • Least-privilege access;
  • Privileged-access management;
  • Segregation of duties;
  • Periodic access reviews;
  • Prompt account deactivation;
  • Control of remote access;
  • Logging and monitoring;
  • Third-party access;
  • Emergency access;
  • Incident response; and
  • Independent testing.

The framework should be read as a governance obligation rather than a simple technology checklist. A bank cannot establish compliance merely by purchasing identity-management software. It must demonstrate that access decisions are risk-based, approved, reviewed, monitored and enforced.

3.3 Electronic Transactions Law No. 20 of 2014

Law No. 20 of 2014 recognises electronic records, transactions and signatures. It is especially relevant to:

  • Online banking;
  • Electronic customer instructions;
  • Digital signatures;
  • Electronic records;
  • Authentication processes;
  • Integrity of electronic communications; and
  • Proof of electronic transactions.

The CBK’s electronic-payment oversight and instructions operate under this legal framework.

A bank relying on an electronic instruction should be capable of proving:

  1. How the user was identified;
  2. Which authentication factors were used;
  3. Whether the registered device was recognised;
  4. Whether the transaction was altered;
  5. When the transaction was authorised;
  6. Whether risk alerts were generated; and
  7. Whether the audit record is complete and reliable.

A correct password alone may not conclusively establish genuine customer consent if there is evidence of credential theft, account takeover or control failure.

3.4 Cybercrime Law No. 63 of 2015

The Cybercrime Law criminalises forms of unlawful access to computer systems, networks and electronic data. It also covers more serious conduct involving interference, misuse or acquisition of protected information.

The law is relevant where:

  • An outsider uses stolen banking credentials;
  • An employee accesses accounts without a business purpose;
  • A contractor retains access after termination;
  • Privileged credentials are shared;
  • Customer data is copied or disclosed;
  • Access records are altered;
  • Malware is used to obtain credentials; or
  • An authorised user deliberately exceeds permitted access.

Unlawful access can therefore create criminal exposure for the individual. It may also reveal a separate regulatory failure by the bank if inadequate controls made the offence possible.

3.5 Data Privacy Protection Regulation

Kuwait’s data-protection regime requires organisations handling personal data to implement suitable organisational and technical safeguards.

For banks, relevant personal data may include:

  • Civil ID details;
  • Passport information;
  • Account numbers;
  • Transaction records;
  • Credit information;
  • Salary details;
  • Device identifiers;
  • Location information;
  • Biometric templates;
  • Authentication logs; and
  • Fraud-monitoring profiles.

Identity governance supports privacy compliance because it limits personal-data access to persons who have a defined and legitimate purpose.

The bank should be able to establish:

  • The identity of every person accessing customer information;
  • The purpose of that access;
  • The information viewed or changed;
  • The date and duration of access;
  • Any download or disclosure;
  • The authorising manager; and
  • The retention period for the audit record.

3.6 Banking secrecy and confidentiality

Banks owe strict confidentiality obligations concerning customer accounts and financial information.

Access by an employee is not automatically lawful merely because the employee works for the bank. The employee must normally have a genuine business need.

For example, a teller who searches for a relative’s account without serving that customer may breach internal policy and confidentiality requirements even if the information is not disclosed to anyone else.

The bank should therefore combine role-based access with:

  • Need-to-know restrictions;
  • Behavioural monitoring;
  • Alerts for access to celebrity or high-risk accounts;
  • Monitoring of bulk downloads;
  • Restrictions on printing and external storage;
  • Data-loss-prevention controls; and
  • Disciplinary procedures.

3.7 Anti-money-laundering requirements

Identity governance also supports AML and counter-terrorist-financing compliance.

Banks must ensure that only authorised personnel can:

  • Create or amend customer profiles;
  • Change risk classifications;
  • Approve high-risk customers;
  • Clear sanctions alerts;
  • Close suspicious-activity alerts;
  • Modify beneficial-owner information;
  • Approve exceptional transactions; and
  • Submit regulatory reports.

One person should not be able to create a customer, approve the customer, suppress an AML alert and release a high-value transaction without independent review.

4. Core Legal Principles

4.1 Least privilege

Every user should receive only the minimum access necessary for the user’s duties.

For example, a call-centre employee may need to view limited customer information but should not ordinarily be able to:

  • Change payment limits;
  • Release transfers;
  • Alter AML classifications;
  • Download complete customer databases; or
  • Access encryption keys.

4.2 Need-to-know access

Access should depend on a genuine business purpose, not merely the employee’s grade or department.

Even senior officers should not automatically receive unrestricted access to customer information.

4.3 Segregation of duties

Conflicting powers should be divided among different people.

Important examples include:

ActivityRequired separation
Creating a paymentSeparate from payment approval
Creating a user accountSeparate from approving its privileges
Developing softwareSeparate from deploying it into production
Investigating alertsSeparate from deleting audit records
Onboarding a customerSeparate from final high-risk approval
Managing encryption keysSeparate from using protected data

4.4 Strong authentication

Higher-risk access should require more than a reusable password.

Appropriate measures may include:

  • Multi-factor authentication;
  • Hardware security keys;
  • Device binding;
  • Biometric verification;
  • Risk-based authentication;
  • Transaction signing;
  • One-time credentials; and
  • Out-of-band confirmation.

Authentication strength should increase with the sensitivity of the account, data or transaction.

4.5 Privileged-access management

Administrator accounts create exceptional risk because they can alter systems, users, controls and logs.

Banks should implement:

  • Separate administrator and ordinary accounts;
  • Password vaults;
  • Time-limited privileges;
  • Approval before privileged sessions;
  • Session recording;
  • Command monitoring;
  • Restrictions on shared accounts;
  • Immediate rotation of exposed credentials; and
  • Independent review of administrator activity.

4.6 Joiner–mover–leaver controls

The identity life cycle should address:

  • Joiners: access granted only after documented approval;
  • Movers: old access removed when duties change; and
  • Leavers: access disabled immediately when employment or engagement ends.

Failure to remove old access creates “privilege accumulation,” under which an employee retains powers from several previous positions.

4.7 Access certification

Managers and system owners should periodically confirm that each user still needs each entitlement.

High-risk access may require more frequent review, particularly:

  • Core-banking access;
  • SWIFT access;
  • Payment-release authority;
  • Database-administrator access;
  • Cloud-administrator access;
  • Customer-data export rights;
  • AML override powers; and
  • Security-log access.

Certification must involve meaningful verification. A manager who automatically approves a long list without examination does not provide effective control.

5. Customer Identity and Digital Banking

Customer identity governance begins during onboarding and continues throughout the banking relationship.

Onboarding

The bank should verify:

  • The customer’s official identity;
  • Authenticity of identification documents;
  • Beneficial ownership;
  • Authority of representatives;
  • Mobile-number ownership where relevant;
  • Risk classification; and
  • Whether enhanced due diligence is required.

Account access

The bank should control:

  • Device registration;
  • Password creation and reset;
  • Biometric enrolment;
  • Addition of beneficiaries;
  • Changes to contact information;
  • Transaction-limit changes;
  • Recovery of locked accounts; and
  • Replacement of registered devices.

High-risk changes

A criminal who controls an account may first change the customer’s mobile number, email address or registered device. These changes should therefore require strong verification and generate immediate alerts through an existing trusted channel.

Transaction monitoring

A transaction may pass the formal authentication process and still be suspicious. Relevant warning signs include:

  • A new device;
  • An unfamiliar country;
  • Impossible travel;
  • Several failed logins;
  • Addition of a new beneficiary;
  • An immediate high-value payment;
  • Unusual time of access;
  • Multiple transactions just below a control threshold; or
  • A sudden increase in payment limits.

6. Third-Party and Cloud Access

Outsourcing does not transfer the bank’s regulatory responsibility.

Contracts with cloud providers, FinTech companies, payment processors and technology vendors should address:

  • Named and uniquely identified users;
  • Multi-factor authentication;
  • Least privilege;
  • Restrictions on subcontractors;
  • Access from approved locations;
  • Logging and session monitoring;
  • Incident notification;
  • Return or deletion of credentials;
  • Access revocation on termination;
  • Audit rights;
  • Regulatory access; and
  • Exit arrangements.

The bank should maintain a central register of all third-party identities. Vendor access should normally be temporary, purpose-specific and automatically expire unless renewed.

7. Relevant Case Laws

Kuwaiti judicial decisions dealing specifically with modern banking identity governance are not widely published in accessible form. The following foreign judgments are therefore comparative and persuasive examples, not binding precedents in Kuwait. They show how courts analyse authentication, access controls, suspicious transactions and data-security failures.

Case 1: Patco Construction Co. v People’s United Bank

684 F.3d 197, United States Court of Appeals for the First Circuit, 2012

Facts

Criminals obtained the customer’s online-banking credentials and initiated fraudulent electronic transfers. The bank’s security system detected high-risk features but continued processing the transactions.

Decision

The court held that the bank’s security procedure was commercially unreasonable. The bank had configured challenge questions in a way that increased the possibility that malware could capture the answers. It also failed to respond adequately to risk warnings.

Importance for Kuwait

This case demonstrates that merely having authentication technology is insufficient. A Kuwaiti bank must configure and operate its system properly.

Relevant lessons include:

  • Respond to risk scores and unusual behaviour;
  • Do not rely only on passwords or static questions;
  • Escalate anomalous transactions;
  • Review the effectiveness of authentication controls; and
  • Contact customers where high-risk activity is detected.

Case 2: Experi-Metal Inc. v Comerica Bank

United States District Court, Eastern District of Michigan, 2011

Facts

A phishing attack allowed criminals to initiate numerous fraudulent transfers from a commercial customer’s account.

Decision

The court concluded that the bank did not act in good faith when it continued processing a rapid series of unusual transactions despite obvious warning signs.

Importance for Kuwait

Authentication is only one part of the bank’s duty. Even where valid credentials are used, the bank should examine the surrounding conduct.

A Kuwaiti bank should detect:

  • Abnormally rapid payments;
  • Multiple new beneficiaries;
  • Payments inconsistent with the customer’s profile;
  • Unusual destination countries; and
  • Repeated transfers after risk alerts.

Case 3: Choice Escrow and Land Title, LLC v BancorpSouth Bank

754 F.3d 611, United States Court of Appeals for the Eighth Circuit, 2014

Facts

The customer suffered a fraudulent electronic transfer. The bank had offered a dual-control security arrangement, but the customer declined to use it.

Decision

The court found in favour of the bank. The security procedure was considered commercially reasonable, and the customer had rejected an available additional safeguard.

Importance for Kuwait

Customers also have security responsibilities. However, a Kuwaiti bank should not use this principle to avoid its regulatory duties.

The bank should document:

  • Which security options were offered;
  • Whether the customer understood them;
  • Why any control was declined;
  • Whether the remaining security was appropriate; and
  • Whether mandatory controls were improperly treated as optional.

Case 4: Shames-Yeakel v Citizens Financial Bank

677 F. Supp. 2d 994, United States District Court, Northern District of Illinois, 2009

Facts

Criminals obtained access to the customers’ home-equity credit facility through online credentials. The customers alleged that the bank failed to use adequate security measures.

Decision

The court allowed the negligence claim to proceed, recognising that a bank could owe a duty to protect customers from reasonably foreseeable online-banking fraud.

Importance for Kuwait

A bank may face civil exposure in addition to regulatory action when weak security causes customer loss.

The case supports the use of:

  • Multi-factor authentication;
  • Transaction monitoring;
  • Customer alerts;
  • Secure credential-reset procedures; and
  • Immediate fraud-response mechanisms.

Case 5: ADS Associates Group, Inc. v Oritani Savings Bank

219 N.J. 496, Supreme Court of New Jersey, 2014

Facts

Fraudsters used compromised credentials to make an unauthorised electronic transfer. The dispute concerned the allocation of loss and the legal rules applicable to payment orders.

Decision

The court emphasised that specialised electronic-transfer legislation governed the loss-allocation question and limited attempts to bypass that statutory scheme through general negligence claims.

Importance for Kuwait

This case demonstrates the importance of identifying the correct legal basis of a banking claim.

A Kuwaiti dispute may involve several overlapping questions:

  • Was the transaction legally authorised?
  • Was the electronic record reliable?
  • Did the bank follow CBK requirements?
  • Did the customer breach agreed security duties?
  • Was there negligence?
  • Was there unlawful system access?
  • Did the bank respond properly after notification?

Case 6: Chavez v Mercantil Commercebank, N.A.

701 F.3d 896, United States Court of Appeals for the Eleventh Circuit, 2012

Facts

A fraudulent payment order was issued from a customer’s account. The dispute involved whether the bank could treat the payment instruction as effective against the customer.

Decision

The court examined the statutory allocation of loss for unauthorised payment orders and the operation of agreed security procedures.

Importance for Kuwait

A contract cannot be viewed in isolation. The bank must prove that its procedures were legally valid, commercially and operationally appropriate, and correctly followed in the particular transaction.

Case 7: Various Claimants v Wm Morrison Supermarkets plc

[2020] UKSC 12, United Kingdom Supreme Court

Facts

A dissatisfied employee deliberately copied and published personal data belonging to other employees. The claimants sought to make the employer vicariously liable.

Decision

The Supreme Court held that the employer was not vicariously liable on the particular facts because the employee acted for personal revenge rather than in the ordinary course of employment.

Importance for Kuwait

The case shows the danger of insider access. Even where an organisation ultimately avoids vicarious liability, it may face investigation, litigation, reputational harm and remediation costs.

Kuwaiti banks should use:

  • Data-access monitoring;
  • Bulk-download alerts;
  • Segregation of duties;
  • Restrictions on removable media;
  • Data-loss-prevention tools; and
  • Investigation of unusual employee activity.

Case 8: Lloyd v Google LLC

[2021] UKSC 50, United Kingdom Supreme Court

Facts

The claimant attempted to bring a representative claim concerning the alleged unlawful collection of browser data.

Decision

The Supreme Court rejected the damages claim in the form presented because individual damage or distress could not simply be assumed for every member of the proposed class.

Importance for Kuwait

The judgment distinguishes between:

  • A breach of data-protection requirements;
  • Proof of individual harm; and
  • The calculation of compensation.

For a Kuwaiti bank, absence of proven customer loss does not necessarily mean there was no regulatory breach. Inadequate access governance may justify supervisory action even before customers prove financial damage.

8. Liability arising from access-governance failures

Regulatory liability

The CBK may intervene where weak access controls threaten:

  • Customer funds;
  • Confidential information;
  • Payment systems;
  • Operational continuity;
  • Financial stability; or
  • Public confidence.

Possible consequences may include remediation orders, enhanced supervision, restrictions, sanctions or action against responsible management, depending on the applicable legal provision and seriousness of the breach.

Civil liability

A customer may allege:

  • Breach of contract;
  • Negligence;
  • Breach of confidentiality;
  • Failure to follow a payment mandate;
  • Improper execution of an unauthorised transaction; or
  • Failure to respond after receiving notice of fraud.

Criminal liability

Individuals may face criminal investigation for:

  • Unlawful system access;
  • Credential theft;
  • Data acquisition;
  • Fraud;
  • Interference with systems;
  • Disclosure of confidential information; or
  • Manipulation of electronic records.

Employment liability

Employees who misuse access may face:

  • Suspension;
  • Dismissal;
  • Loss of professional responsibilities;
  • Civil recovery proceedings; or
  • Criminal referral.

Senior-management responsibility

Senior management cannot treat identity governance as an issue belonging exclusively to the IT department.

Management should approve:

  • Access-control policy;
  • Risk appetite;
  • Privileged-access standards;
  • Major exceptions;
  • Third-party-access arrangements;
  • Remediation priorities; and
  • Reporting to the board.

9. Recommended Governance Structure

A Kuwaiti bank should establish the following allocation of responsibilities:

FunctionPrincipal responsibility
Board of directorsOversight, risk appetite and accountability
Senior managementImplementation and adequate resources
Chief information security officerSecurity standards and monitoring
IT departmentTechnical operation of identity systems
Business ownerApproval of legitimate business access
Human resourcesAccurate joiner, mover and leaver information
ComplianceRegulatory interpretation and monitoring
Risk managementIndependent risk assessment
Internal auditIndependent testing and assurance
Data-protection functionPersonal-data access and privacy controls
Vendor managementThird-party identity and access supervision

No single function should control the entire process without independent review.

10. Minimum Compliance Checklist

A strong Kuwaiti banking identity-governance programme should include:

  1. A complete inventory of human and machine identities.
  2. Unique user IDs and prohibition of unnecessary shared accounts.
  3. Multi-factor authentication for remote and sensitive access.
  4. Least-privilege and need-to-know access.
  5. Segregation of conflicting duties.
  6. Formal access requests and approvals.
  7. Automated joiner, mover and leaver processes.
  8. Immediate termination of access for departing personnel.
  9. Periodic access certification.
  10. Privileged-access vaulting and session monitoring.
  11. Strong controls over password and device resets.
  12. Customer alerts for significant account changes.
  13. Risk-based transaction authentication.
  14. Centralised and tamper-resistant audit logs.
  15. Monitoring of abnormal access behaviour.
  16. Time-limited vendor access.
  17. Regular testing of emergency accounts.
  18. Investigation and documentation of access violations.
  19. Defined record-retention periods.
  20. Board-level reporting of significant access risks and incidents.

11. Conclusion

Identity and access governance in Kuwait is an essential component of banking law, cybersecurity, privacy, payment security and operational resilience.

A bank must do more than verify usernames and passwords. It must be able to demonstrate that:

  • Every identity is legitimate;
  • Every access right has a documented purpose;
  • Sensitive privileges are independently approved;
  • Conflicting powers are separated;
  • High-risk activities are continuously monitored;
  • Suspicious transactions are escalated;
  • Access is removed promptly when no longer required; and
  • Reliable evidence is retained for regulators, courts and investigators.

The comparative cases show that courts examine the complete security environment—not merely whether the correct credentials were entered. The decisive questions are often whether the bank’s controls were reasonable, whether warning signs were ignored, whether stronger safeguards were available, and whether the bank acted promptly and in good faith.

For Kuwait-regulated banks, effective identity and access governance should therefore be treated as a continuing legal and governance obligation, supported by board oversight, technical controls, independent assurance and documented accountability.

LEAVE A COMMENT