Banking Law And Identity And Access Governance Kuwait .

Banking Law and Identity and Access Management in Financial Institutions — Kuwait

1. Introduction

Identity and Access Management, commonly called IAM, is the system through which a financial institution identifies users, authenticates them, grants appropriate access rights, monitors their activities and removes access when it is no longer required.

In Kuwait, IAM is not merely an internal IT function. Weak access controls may create regulatory, civil, criminal, privacy, anti-money-laundering and operational-resilience liability. Banks must therefore control the digital identities of:

  • Employees and senior management
  • Customers using digital banking services
  • Contractors and temporary workers
  • Outsourcing and cloud-service providers
  • FinTech and payment-service partners
  • Software applications, APIs and automated processes
  • System administrators and other privileged users

A failure in IAM can allow an attacker, dishonest employee or compromised service provider to access accounts, alter payment instructions, disclose confidential information or interrupt essential banking services.

2. Principal Legal and Regulatory Framework in Kuwait

A. Central Bank of Kuwait Law

Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organization of Banking Business gives the Central Bank of Kuwait, or CBK, extensive authority to regulate and supervise banks and other regulated financial institutions.

The CBK may issue mandatory instructions concerning:

  • Internal control systems
  • Risk management
  • Corporate governance
  • Protection of customer information
  • Electronic banking
  • Outsourcing arrangements
  • Cybersecurity
  • Business continuity
  • Operational resilience
  • Reporting of material incidents

A bank’s failure to establish adequate IAM controls may therefore be treated as a failure of internal control, governance or risk management, even if no particular customer loss has yet occurred.

B. CBK Cybersecurity Framework for the Kuwaiti Banking Sector

The 2020 CBK Cybersecurity Framework established sector-wide cybersecurity expectations for Kuwaiti banks. It treats cybersecurity as an enterprise risk requiring board and senior-management oversight.

IAM-related expectations under this approach include:

  • Unique identification of every user
  • Authentication proportionate to the risk
  • Role-based or attribute-based access controls
  • Least-privilege access
  • Segregation of incompatible duties
  • Privileged-access management
  • Periodic review and recertification of permissions
  • Prompt removal of access after resignation, dismissal or transfer
  • Secure management of remote access
  • Monitoring and logging of access events
  • Control over third-party and outsourced access
  • Protection of authentication credentials
  • Incident-response procedures for compromised accounts

C. CBK Cyber and Operational Resilience Framework

The CBK’s Cyber and Operational Resilience Framework, introduced in 2025, moves regulated institutions from basic cybersecurity compliance toward resilience and maturity.

For IAM, this means that a bank should not only prevent unauthorized access. It must also be able to detect compromised identities, contain misuse, recover critical services and demonstrate that access controls continue to function during disruption.

A resilience-oriented IAM program should include:

  • Strong identity governance throughout the employment lifecycle
  • Phishing-resistant multifactor authentication for high-risk access
  • Privileged access through controlled administrative gateways
  • Emergency-access procedures with retrospective review
  • Continuous monitoring for unusual login behaviour
  • Resilient identity infrastructure with tested recovery arrangements
  • Controls over machine identities, service accounts, certificates and APIs
  • Incident exercises involving stolen credentials and administrator compromise
  • Mapping of access dependencies supporting critical banking services

D. Electronic Transactions Law

Kuwait Law No. 20 of 2014 concerning Electronic Transactions recognizes electronic records, electronic signatures and electronic transactions subject to the applicable legal conditions.

For banks, reliable authentication is important when determining:

  • Whether an electronic instruction is attributable to the customer
  • Whether an electronic signature is valid
  • Whether a transaction was altered
  • Whether the authentication method was reasonably reliable
  • Whether transaction records can be admitted as evidence

Successful use of a password or one-time code is relevant evidence, but it does not automatically prove genuine customer authorization. The surrounding circumstances, authentication design, warnings, device information, transaction history and fraud indicators may also be relevant.

E. Cybercrime Law

Law No. 63 of 2015 concerning Combating Information Technology Crimes criminalizes various forms of unauthorized access, interference, misuse of electronic systems and unlawful acquisition or disclosure of data.

A person who steals credentials, exceeds authorized access or uses another person’s electronic identity may incur criminal liability. Employees may also face liability where they deliberately use legitimate credentials for an unauthorized purpose.

The existence of criminal conduct does not necessarily remove the bank’s regulatory or civil exposure. The bank may still be questioned about whether reasonable access controls could have prevented or detected the misconduct.

F. Data Privacy Protection Regulation

CITRA Resolution No. 42 of 2021 introduced Kuwait’s Data Privacy Protection Regulation. It applies to covered public and private service providers that collect, process or store personal data.

IAM supports data-protection compliance by ensuring that:

  • Personal data is available only to authorized persons
  • Permissions correspond to legitimate business purposes
  • Access to sensitive data is logged
  • Former employees cannot continue accessing customer records
  • Third-party access is restricted and monitored
  • Security incidents can be investigated
  • Data is protected against unauthorized disclosure, alteration or destruction

Poor IAM may therefore constitute both a cybersecurity failure and a violation of data-protection obligations.

G. Anti-Money-Laundering and Counter-Terrorist-Financing Law

Law No. 106 of 2013 requires financial institutions to identify and verify customers, conduct due diligence, maintain records and monitor transactions.

IAM and AML overlap in two ways:

  1. Customer identity: The bank must establish who the customer and beneficial owner are.
  2. System identity: The bank must establish which employee, system or third party accessed or changed AML records.

Access to customer-risk ratings, sanctions alerts and suspicious-transaction records should be especially restricted. An employee should not be able to suppress an alert or change customer data without authorization, logging and appropriate approval.

H. Banking Confidentiality

Kuwaiti banking law protects confidential customer and account information, subject to legally recognized exceptions. IAM is one of the principal mechanisms for preserving that confidentiality.

An employee’s general access to a banking system does not give unrestricted authority to inspect every customer account. Access should be limited according to role and legitimate business need.

3. Essential IAM Duties of Kuwaiti Financial Institutions

A. Identification and Authentication

Every human and non-human user should receive a unique identity. Shared accounts should generally be prohibited because they make individual accountability difficult.

Authentication should reflect the risk of the activity:

  • Basic internal systems may use controlled single sign-on.
  • Remote access should require multifactor authentication.
  • Privileged accounts should use stronger, preferably phishing-resistant, authentication.
  • High-risk customer transactions may require step-up authentication.
  • Password resets and device enrolment require robust identity verification.

Banks should not treat SMS-based codes as a complete fraud solution. SIM swapping, social engineering and real-time phishing can defeat such controls.

B. Authorization and Least Privilege

Access should be limited to what the person requires for assigned duties. A customer-service employee, for example, should not normally be able to create a beneficiary, approve a payment and alter the audit record.

Banks should implement:

  • Role-based access control
  • Maker-checker approval
  • Transaction-value limits
  • Restricted database access
  • Time-limited elevated privileges
  • Access recertification by business owners
  • Controls preventing users from approving their own requests

C. Segregation of Duties

No individual should control every stage of a sensitive transaction. Functions commonly requiring separation include:

  • Creation and approval of payments
  • Customer onboarding and compliance approval
  • System development and production deployment
  • Security monitoring and log administration
  • User creation and access approval
  • Reconciliation and correction of financial records

Exceptions should be documented, time-limited and supported by compensating controls.

D. Privileged Access Management

Administrator accounts create particularly serious risks. Banks should:

  • Separate ordinary and administrator identities
  • Store privileged credentials in a secure vault
  • Rotate credentials
  • Record or closely monitor privileged sessions
  • Block direct access where a controlled gateway can be used
  • Require approval for high-risk commands
  • Detect privilege escalation
  • Maintain controlled emergency accounts
  • Review emergency use immediately afterward

E. Joiner–Mover–Leaver Controls

Access rights should follow the user’s lifecycle:

  • Joiner: Access is approved before activation and based on the assigned role.
  • Mover: Old permissions are removed when duties change.
  • Leaver: Access is disabled immediately upon termination or at the authorized termination time.

The “mover” stage is frequently overlooked. Employees can gradually accumulate incompatible permissions as they change roles.

F. Customer Access and Fraud Prevention

Customer IAM should combine authentication with contextual risk analysis. Banks should examine:

  • New devices
  • Unusual locations
  • Impossible travel patterns
  • Sudden beneficiary creation
  • Abnormal transfer amounts
  • Password or mobile-number changes
  • Multiple failed authentication attempts
  • Known compromised credentials
  • Remote-access or screen-sharing indicators

A transaction passing technical authentication should not automatically override clear indications of fraud.

G. Third-Party and Outsourcing Access

Responsibility cannot simply be transferred to a technology vendor. Contracts should address:

  • Named and approved personnel
  • Least-privilege access
  • Multifactor authentication
  • Logging and monitoring
  • Security incident notification
  • Subcontractor access
  • Data-return and deletion requirements
  • Audit rights
  • Immediate revocation when personnel change
  • Access from foreign locations
  • Compliance with CBK requirements

H. Logging and Evidence

Logs should show who accessed which system, what was viewed or changed, when the activity occurred, from which device or location and whether elevated privileges were used.

Logs must be protected against alteration. Otherwise, they may carry limited evidential weight in regulatory investigations or litigation.

4. Liability Arising from IAM Failures

An IAM failure may produce several forms of liability:

Regulatory liability

The CBK may require remediation, enhanced monitoring or other supervisory measures where access controls are inadequate.

Civil liability

A customer may claim compensation where negligent authentication or access control causes unauthorized transfers, disclosure of confidential information or other measurable loss.

Contractual liability

A bank, cloud provider or outsourced processor may be liable for violating security, confidentiality or service obligations.

Criminal liability

Credential theft, unauthorized system access, fraudulent payment activity or deliberate disclosure of information may constitute criminal offences.

Employment liability

An employee may face disciplinary action or dismissal for credential sharing, unauthorized account inspection or circumvention of security controls.

Management responsibility

Senior management and the board may be criticized if they failed to establish proper governance, resources, reporting lines or risk oversight.

5. Relevant Case Laws

Published Kuwaiti judgments dealing specifically with modern IAM controls are limited and are not consistently available in public English-language databases. The following comparative cases are therefore useful persuasive authorities rather than binding Kuwaiti precedents.

1. Patco Construction Co. v People’s United Bank

United States Court of Appeals, First Circuit, 2012

Fraudsters used valid customer credentials to initiate unauthorized transfers. The bank’s system treated an unusually large number of transactions as high risk but continued processing them using challenge questions that had become vulnerable.

The court concluded that the security procedure was not commercially reasonable in its implementation.

IAM principle: Possession of correct credentials does not end the inquiry. A bank must respond appropriately to unusual transaction patterns and risk warnings.

2. Experi-Metal, Inc. v Comerica Bank

United States District Court, Eastern District of Michigan, 2011

A phishing attack allowed criminals to initiate numerous fraudulent transfers over several hours. The court found that the bank had not acted in good faith because the transaction pattern contained obvious abnormalities.

IAM principle: Authentication must operate together with behavioural monitoring, transaction limits and rapid fraud response.

3. Choice Escrow and Land Title, LLC v BancorpSouth Bank

United States Court of Appeals, Eighth Circuit, 2014

A customer declined an available dual-control security feature and later suffered losses after an employee’s credentials were compromised. The bank’s security arrangements were upheld.

IAM principle: A bank is in a stronger legal position when it offers appropriate controls, clearly documents the customer’s decision and follows agreed security procedures.

4. Shames-Yeakel v Citizens Financial Bank

United States District Court, Northern District of Illinois, 2009

The court allowed negligence allegations to proceed where a bank allegedly failed to use adequate security measures for online banking.

IAM principle: Financial institutions may owe duties extending beyond basic password authentication, particularly where stronger controls are reasonably available.

5. Philipp v Barclays Bank UK PLC

United Kingdom Supreme Court, 2023

A customer personally instructed the bank to transfer money after being deceived by fraudsters. The Supreme Court held that the bank’s ordinary duty was to execute the customer’s clear instruction and that the traditional duty to refrain from executing a suspicious agent instruction did not apply in the same way to a customer’s own valid instruction.

IAM principle: Courts distinguish between an unauthorized instruction and an authorized instruction induced by fraud. Accurate identity verification does not necessarily prevent authorized-push-payment fraud, so contractual and fraud-monitoring arrangements remain important.

6. Singularis Holdings Ltd v Daiwa Capital Markets Europe Ltd

United Kingdom Supreme Court, 2019

A company’s controlling officer instructed payments that misappropriated company funds. The financial institution was held liable for failing to act when the circumstances should have caused it to make inquiries.

IAM principle: Valid authority and credentials do not eliminate the need to question transactions where strong indicators of internal fraud exist.

7. Federal Trade Commission v Wyndham Worldwide Corporation

United States Court of Appeals, Third Circuit, 2015

Wyndham allegedly used weak passwords, inadequate network segmentation and deficient access controls, contributing to repeated data breaches. The court confirmed the regulator’s ability to pursue allegedly unreasonable cybersecurity practices.

IAM principle: Persistent access-control deficiencies can constitute an unlawful security practice even though attackers committed the immediate intrusion.

8. United States v Nosal

United States Court of Appeals, Ninth Circuit, 2012 and 2016 decisions

Former employees used another person’s credentials to obtain confidential information after their own access had been revoked. The litigation examined the legal significance of circumventing technical access restrictions.

IAM principle: Password sharing and use of another employee’s identity undermine accountability and can create serious criminal, civil and employment consequences.

9. Van Buren v United States

United States Supreme Court, 2021

A police officer had valid access to a database but used it for an improper purpose. The Supreme Court adopted a narrower interpretation of “exceeds authorized access” under the relevant US federal statute.

IAM principle: Technical authorization and permitted business use are not always identical. Banks should enforce purpose restrictions through policy, monitoring, disciplinary rules and granular technical controls.

6. Application of the Cases in Kuwait

A Kuwaiti court is not bound by these foreign judgments. However, they illustrate issues that may arise under Kuwaiti banking, contract, tort, electronic-transactions, privacy and cybercrime principles.

The cases support several practical conclusions:

  • Correct credentials are evidence, but not conclusive proof, of genuine authorization.
  • Banks should investigate transactions inconsistent with known customer behaviour.
  • Dual control is especially important for corporate banking.
  • Customer refusal of stronger security should be clearly documented.
  • Access granted to an employee must remain limited to legitimate purposes.
  • Privileged and third-party accounts require enhanced supervision.
  • Banks should preserve reliable logs to prove authorization and reconstruct incidents.
  • A criminal attack does not automatically excuse weak institutional controls.

7. Recommended Compliance Structure

A Kuwaiti financial institution should establish:

  1. A board-approved IAM policy.
  2. Clear accountability shared among business, information security, risk, compliance and internal audit.
  3. A complete inventory of human and machine identities.
  4. Role-based access supported by least privilege.
  5. Multifactor authentication for remote, privileged and high-risk access.
  6. Privileged-access vaulting and session monitoring.
  7. Automated joiner–mover–leaver processes.
  8. Quarterly or risk-based access recertification.
  9. Maker-checker controls for payments and sensitive changes.
  10. Continuous customer-transaction monitoring.
  11. Strict third-party identity controls.
  12. Protected and centrally retained audit logs.
  13. Immediate revocation procedures.
  14. Regular penetration testing and access-control testing.
  15. Scenario exercises involving credential theft and insider fraud.
  16. Prompt reporting and investigation of material incidents.
  17. Independent internal-audit review.
  18. Documented exceptions with expiry dates and compensating controls.

Conclusion

Under Kuwait’s banking framework, IAM is an essential component of cybersecurity, banking confidentiality, customer protection, AML compliance and operational resilience. Compliance requires more than passwords and one-time codes. Financial institutions must manage identities throughout their lifecycle, limit privileges, separate sensitive duties, monitor abnormal activity and retain reliable evidence.

The comparative decisions demonstrate a consistent legal lesson: a bank cannot always rely solely on technically valid credentials when surrounding circumstances indicate fraud or misuse. Conversely, a bank is better protected when it implements commercially reasonable controls, offers stronger authentication, documents customer decisions and follows its security procedures consistently.

LEAVE A COMMENT