Banking Law And Identity Fraud Prevention Measures Kuwait .

Banking Law and Identity Fraud Prevention Measures in Kuwait

1. Introduction

Identity fraud in banking occurs when a person unlawfully uses another person’s identity, Civil ID, signature, banking credentials, biometric information, payment card or electronic authentication data to obtain money, credit or financial services.

Common forms of banking identity fraud in Kuwait include:

  • Opening an account with forged identification documents;
  • Taking a loan in another person’s name;
  • Using stolen Civil ID information;
  • SIM-swap and mobile-number takeover;
  • Phishing for online-banking credentials;
  • Fraudulent activation of mobile-banking applications;
  • Forged cheques or payment instructions;
  • Impersonating bank employees;
  • Taking control of dormant accounts;
  • Creating accounts for money mules;
  • Misusing corporate signatories’ identities;
  • Using artificial intelligence to imitate voices, faces or documents.

Kuwaiti banks are expected to prevent these activities through customer due diligence, secure authentication, transaction monitoring, cybersecurity controls and prompt fraud-response procedures.

2. Principal Legal Framework

2.1 Central Bank of Kuwait Law

Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business gives the Central Bank of Kuwait, or CBK, authority to regulate and supervise banks.

The CBK can issue binding instructions concerning:

  • Customer identification;
  • Internal controls;
  • Electronic banking;
  • Payment security;
  • Cybersecurity;
  • Anti-money laundering;
  • Outsourcing;
  • Operational resilience;
  • Customer complaints;
  • Risk governance.

A bank’s failure to implement adequate identity controls can therefore result in regulatory measures even when no criminal conviction has been obtained against the fraudster.

2.2 Anti-Money Laundering Law

Law No. 106 of 2013 regarding Anti-Money Laundering and Combating the Financing of Terrorism is central to identity-fraud prevention.

Identity fraud frequently creates the infrastructure through which money laundering occurs. Stolen or synthetic identities may be used to open accounts, receive fraud proceeds, transfer funds internationally or conceal the beneficial owner.

Banks must apply risk-based customer due diligence, identify beneficial owners, monitor transactions, retain records and report suspicious transactions. CBK instructions expressly require enhanced due diligence where a customer or transaction presents a high risk.

2.3 Cybercrime Law

Law No. 63 of 2015 concerning Combating Information Technology Crimes criminalises conduct connected with:

  • Unauthorised access to computer systems;
  • Unlawful acquisition of personal data;
  • Alteration or destruction of electronic information;
  • Electronic fraud;
  • Misuse of payment information;
  • Interference with financial or governmental systems;
  • Use of information networks to commit offences.

The law provides a basis for prosecuting phishing, account takeover, credential theft and the unlawful possession or use of personal banking data.

2.4 Electronic Transactions Law

Law No. 20 of 2014 concerning Electronic Transactions, as amended by Decree-Law No. 148 of 2025, governs electronic records, communications and signatures.

The framework recognises electronic records and signatures where the statutory reliability requirements are met. It is important in identity-fraud disputes because courts may need to determine:

  • Whether an electronic instruction was attributable to the customer;
  • Whether an electronic signature was reliable;
  • Whether authentication credentials were compromised;
  • Whether an electronic record was altered;
  • Whether the bank preserved adequate technical evidence;
  • Whether the customer actually consented to the transaction.

The 2025 amendments strengthened and broadened the legal recognition of electronic documents, signatures and transactions.

2.5 Personal-Data Protection Rules

Kuwait’s data-protection framework includes the Electronic Transactions Law, Cybercrime Law and CITRA Data Privacy Protection Regulation.

Banks process particularly sensitive information, including:

  • Civil ID data;
  • Passport information;
  • Facial images;
  • Voice recordings;
  • Signatures;
  • Salary records;
  • Account and card details;
  • Device and location information;
  • Transaction histories.

Banks must adopt organisational and technical safeguards against unauthorised access, disclosure, alteration and loss of such data.

3. Customer Identification Measures

3.1 Verification of Civil ID

A bank should verify the authenticity and validity of a customer’s Civil ID rather than merely retaining a photocopy.

The process should include:

  • Checking the original or authenticated digital record;
  • Confirming that the document remains valid;
  • Comparing the photograph with the applicant;
  • Verifying the customer’s name, nationality and date of birth;
  • Confirming residential and contact information;
  • Detecting alteration, substitution or duplication;
  • Verifying information through reliable official systems where available.

Where the customer is a non-Kuwaiti resident, the bank should also verify the passport, residency status and other required documents.

3.2 Biometric Verification

Banks increasingly use facial recognition, fingerprints, liveness detection and mobile-device authentication.

Biometric verification should prevent fraud involving:

  • Printed photographs;
  • Recorded videos;
  • Face masks;
  • Deepfake video;
  • Synthetic identities;
  • Presentation attacks;
  • Stolen biometric templates.

Liveness detection should verify that the person is physically present. High-risk applications should not depend solely on a photograph uploaded by the customer.

3.3 Verification of Mobile Numbers

The registered telephone number is often used to receive one-time passwords and security alerts. Banks should verify that:

  • The number belongs to or is legitimately controlled by the customer;
  • A recent SIM replacement has not occurred;
  • The number has not been transferred immediately before a sensitive transaction;
  • The device has not suddenly changed;
  • The transaction is consistent with the customer’s normal location.

A mobile number should not be treated as conclusive proof of identity because fraudsters may obtain replacement SIM cards.

3.4 Corporate-Customer Verification

For corporate accounts, the bank must identify:

  • The company;
  • Directors and authorised representatives;
  • Persons authorised to operate the account;
  • Ultimate beneficial owners;
  • Persons exercising effective control;
  • The purpose of the business relationship.

The bank should verify board resolutions, signature authorities, powers of attorney and commercial-registration documents.

4. Beneficial-Ownership Controls

Identity fraud may be used to hide the person who actually owns or controls a business. A bank should not accept a nominee shareholder or authorised signatory as the beneficial owner without further examination.

Banks must determine:

  • Who ultimately owns the legal entity;
  • Who controls important decisions;
  • Whether ownership is indirect;
  • Whether shares are held through another company;
  • Whether a person is acting on behalf of someone else;
  • Whether the structure has a legitimate commercial purpose.

Enhanced investigation is appropriate where the ownership structure contains offshore companies, unexplained intermediaries or frequent changes of shareholders.

5. Risk-Based Customer Due Diligence

Banks should classify identity-fraud risks according to the customer, product, delivery channel and transaction.

Low-risk situations

A customer may present a relatively low risk where:

  • Identity is verified face-to-face;
  • Documents are confirmed through reliable sources;
  • The customer uses ordinary banking products;
  • Transactions are consistent with declared income;
  • No unusual geographic connection exists.

High-risk situations

Enhanced measures should be applied where:

  • The account is opened entirely remotely;
  • Documents contain inconsistencies;
  • The customer refuses to provide information;
  • The applicant’s face does not match the identification document;
  • Several accounts use the same telephone or device;
  • The customer is acting for an unidentified third party;
  • Large transfers begin immediately after account opening;
  • A dormant account suddenly becomes active;
  • The customer is a politically exposed person;
  • Funds move rapidly through several accounts;
  • Login activity originates from unusual jurisdictions.

Simplified due diligence must not be used when money laundering, terrorist financing or identity fraud is suspected.

6. Authentication of Digital Transactions

6.1 Multi-Factor Authentication

Banks should require two or more independent authentication factors, such as:

  • Something the customer knows, such as a password;
  • Something the customer possesses, such as a registered device;
  • Something inherent to the customer, such as a biometric characteristic.

A password and security question may not constitute strong independent authentication if both depend on information that can be stolen through phishing.

6.2 Transaction-Specific Authentication

For high-risk payments, authentication should be linked to:

  • The amount;
  • The beneficiary;
  • The transaction type;
  • The customer’s authenticated session.

A fraudster should not be able to change the beneficiary or transaction amount after the customer completes authentication.

6.3 Step-Up Authentication

Additional verification should be required when:

  • A new beneficiary is created;
  • The mobile number changes;
  • The customer uses a new device;
  • The password is reset;
  • Transaction limits are increased;
  • A large international payment is requested;
  • Dormant-account activity resumes;
  • Several authentication attempts fail.

6.4 Device and Behavioural Monitoring

Banks may analyse:

  • Device identity;
  • IP address;
  • Geographic location;
  • Typing speed;
  • Navigation patterns;
  • Session duration;
  • Failed login attempts;
  • Malware indicators;
  • Remote-access software.

Automated monitoring should support human review rather than operate as the sole basis for every high-risk decision.

7. Transaction-Monitoring Measures

An effective system should identify patterns associated with account takeover and identity misuse, including:

  • Immediate transfer of newly credited funds;
  • Multiple payments to unknown beneficiaries;
  • Sudden changes in transaction behaviour;
  • Login from a new country followed by a large transfer;
  • Several accounts controlled through one device;
  • Repeated transfers just below internal limits;
  • Rapid movement through mule accounts;
  • Payments inconsistent with the customer’s occupation;
  • Unusual cash withdrawals following password resets;
  • Change of contact information followed by a loan application.

The bank should generate alerts, investigate them promptly and document whether the activity was cleared, restricted or reported.

8. Payment-Card Fraud Prevention

Banks and payment providers should apply:

  • Chip-and-PIN controls;
  • Tokenisation of card details;
  • Real-time transaction monitoring;
  • Three-dimensional secure authentication;
  • Limits on contactless transactions;
  • Confirmation for unusual online purchases;
  • Immediate card-freezing facilities;
  • Merchant-risk monitoring;
  • Alerts for card-not-present transactions.

A customer should be able to report a lost card or disputed transaction at all times, rather than only during branch hours.

9. Loan and Credit Identity Fraud

Banks should prevent loans from being issued through stolen identities by verifying:

  • The applicant’s Civil ID;
  • Employment and salary information;
  • Existing credit exposure;
  • Bank-account ownership;
  • Contact information;
  • Biometric identity;
  • Authenticity of salary certificates;
  • Employer details;
  • Electronic consent.

Where the loan is completed remotely, the bank should preserve evidence showing the applicant’s authentication, consent and receipt of funds.

Payment of funds into an account opened with the same stolen identity does not prove that the victim obtained the benefit.

10. Duties After Suspected Identity Fraud

Once a bank receives a credible fraud report, it should act promptly.

Appropriate measures include:

  1. Freezing affected credentials and cards;
  2. Preventing the registration of new beneficiaries;
  3. Preserving authentication and transaction logs;
  4. Attempting to recall or trace transferred funds;
  5. Notifying receiving banks;
  6. Examining linked accounts and devices;
  7. Filing a suspicious-transaction report where required;
  8. Cooperating with law-enforcement authorities;
  9. Giving the customer a complaint reference;
  10. Investigating whether control failures contributed to the loss.

CBK consumer-protection principles require banks to exercise due diligence in handling customer complaints and grievances.

11. Allocation of Liability

Liability normally depends on how the fraud occurred and which party failed to exercise the legally required degree of care.

Bank liability may arise where:

  • The transaction was not authorised;
  • The bank ignored obvious warning signs;
  • A forged signature was accepted;
  • Authentication controls were inadequate;
  • The bank failed to block unusual activity;
  • A reported card or credential remained active;
  • Customer data was exposed through weak security;
  • The bank failed to follow its own procedures;
  • A staff member assisted or facilitated the fraud.

Customer liability may arise where:

  • The customer knowingly disclosed an OTP or password;
  • The customer acted fraudulently;
  • The customer authorised the transaction;
  • The customer deliberately allowed another person to use the account;
  • The customer unreasonably delayed reporting known fraud;
  • The customer participated in a money-mule arrangement.

However, a bank should not automatically treat use of the correct OTP as conclusive proof of genuine consent. Fraudsters can obtain authentication credentials through phishing, malware, impersonation and SIM swapping.

12. Relevant Case Laws

Published Kuwaiti judgments involving modern digital identity fraud are comparatively limited. Therefore, the following decisions are important comparative banking precedents. They are not automatically binding in Kuwait, but their principles can assist in analysing authorisation, negligence, forged mandates and fraud monitoring under Kuwaiti law.

12.1 Canara Bank v Canara Sales Corporation, Supreme Court of India, 1987

Employees used forged cheques to withdraw money from the customer’s account. The Supreme Court held that a forged cheque contains no valid customer mandate. A bank cannot debit an account merely because the forgery was difficult to detect.

Kuwait relevance: A bank ordinarily needs a valid instruction before debiting a customer’s account. A forged signature, fabricated identity or unauthorised digital instruction may not constitute a valid mandate.

12.2 Barclays Bank plc v Quincecare Ltd, English High Court, 1992

The case established that a bank may have a duty not to execute a payment instruction when it has reasonable grounds to believe that an agent is attempting to misappropriate the customer’s funds.

Kuwait relevance: If a corporate representative submits suspicious payment instructions, the bank may need to investigate rather than relying mechanically on apparent authority.

12.3 Singularis Holdings Ltd v Daiwa Capital Markets Europe Ltd, UK Supreme Court, 2019

A company director instructed the financial institution to transfer company funds for improper purposes. The institution was held liable because it ignored circumstances that should have created serious suspicion.

Kuwait relevance: Identity verification alone is insufficient. Even a genuinely identified authorised representative may be committing fraud against the account holder.

12.4 Philipp v Barclays Bank UK plc, UK Supreme Court, 2023

A customer personally instructed her bank to transfer money after being deceived by fraudsters. The Supreme Court held that the traditional Quincecare duty did not require the bank to refuse an otherwise clear instruction from the customer merely because the customer was being deceived.

However, the bank could still have duties after receiving notice of the fraud, including considering attempts to recall funds.

Kuwait relevance: There is an important distinction between an unauthorised transaction and a transaction genuinely authorised by a customer who was manipulated. The bank’s post-notification response may still affect liability.

12.5 Federal Republic of Nigeria v JPMorgan Chase Bank NA, English High Court, 2022

Large payments were made under instructions that Nigeria later alleged were connected with fraud. The court examined whether the bank had sufficient grounds to believe that the instructions were part of a scheme to defraud the customer.

The claim failed because the required standard of knowledge or suspicion was not established on the evidence.

Kuwait relevance: A large or unusual payment does not automatically make a bank liable. Liability depends on the warning signs available to the bank at the time and the reasonableness of its response.

12.6 Tai Hing Cotton Mill Ltd v Liu Chong Hing Bank Ltd, Privy Council, 1986

The case concerned forged cheques and the respective duties of a bank and customer. The court rejected the creation of an excessively broad implied duty requiring customers continuously to inspect their accounts for forgery.

Kuwait relevance: Banks should not shift their fundamental responsibility for verifying payment authority to customers through vague contractual clauses.

12.7 Royal Bank of Scotland plc v Etridge (No. 2), House of Lords, 2001

The case concerned transactions entered into under undue influence. The court explained when a bank is put on inquiry and must take reasonable steps before relying on a transaction.

Kuwait relevance: When circumstances indicate impersonation, coercion or misuse of authority, a bank may need independent confirmation rather than simply processing documents that appear formally valid.

12.8 Ashit Roy v Syndicate Bank, Karnataka High Court, 1999

A bank paid a cheque containing a forged signature. The court held that the bank failed to apply proper care in comparing the signature and could not rely simply on the customer’s alleged carelessness.

Kuwait relevance: Banks must maintain effective signature-verification procedures. The customer’s careless storage of documents does not necessarily validate a payment made without genuine authority.

13. Evidential Issues in Identity-Fraud Litigation

The bank should be able to produce reliable evidence concerning:

  • Account-opening documents;
  • Civil ID verification;
  • Biometric results;
  • Device registration;
  • IP addresses;
  • Login history;
  • OTP generation and delivery;
  • Beneficiary creation;
  • Transaction confirmation;
  • Telephone recordings;
  • Branch CCTV;
  • Fraud-monitoring alerts;
  • Internal investigation reports;
  • Customer notifications.

A bank cannot necessarily prove authorisation merely by showing that its system recorded a successful login. The court may ask whether the authentication system reliably established that the customer personally initiated and approved the disputed transaction.

Electronic records must also be preserved in a manner capable of demonstrating integrity, authenticity and an identifiable chain of custody.

14. Role of Employees and Outsourcing Providers

Banks remain responsible for managing identity risk where services are performed through:

  • Fintech companies;
  • Cloud providers;
  • Call centres;
  • Payment processors;
  • Digital-onboarding vendors;
  • Biometric-verification companies;
  • Card processors;
  • External agents.

Contracts should contain security requirements, audit rights, incident-reporting obligations and restrictions on subcontracting.

Employees with access to customer identities should be subject to:

  • Background screening;
  • Access restrictions;
  • Segregation of duties;
  • Privileged-access monitoring;
  • Mandatory leave;
  • Rotation where appropriate;
  • Confidentiality requirements;
  • Disciplinary procedures.

15. Recommended Compliance Framework

A Kuwaiti bank should maintain the following identity-fraud prevention framework:

  1. Board-approved identity and fraud-risk policy;
  2. Risk-based KYC and beneficial-ownership verification;
  3. Secure remote onboarding;
  4. Biometric liveness testing;
  5. Multi-factor authentication;
  6. SIM-swap and device-change detection;
  7. Transaction-specific confirmation;
  8. Real-time behavioural monitoring;
  9. Mule-account detection;
  10. Automated and manual sanctions screening;
  11. Enhanced controls for vulnerable customers;
  12. Employee-access monitoring;
  13. Regular penetration and fraud-scenario testing;
  14. Rapid account-freezing and fund-recall procedures;
  15. Clear customer complaint and reimbursement processes;
  16. Complete preservation of electronic evidence;
  17. Periodic reporting to senior management;
  18. Independent internal audit.

16. Conclusion

Kuwait’s identity-fraud prevention regime is based on the combined operation of banking supervision, customer due diligence, anti-money-laundering rules, electronic-transactions law, cybercrime legislation and data-protection requirements.

A bank’s obligation does not end after collecting a Civil ID or sending an OTP. It must assess whether the claimed identity is genuine, whether the person controls the registered device, whether the transaction reflects the customer’s normal behaviour and whether surrounding circumstances indicate impersonation or account takeover.

Where a disputed payment results from a forged or unauthorised instruction, the absence of a valid customer mandate is a central issue. Where the customer personally authorised a payment after being deceived, liability becomes more fact-sensitive and depends on the bank’s knowledge, contractual duties, fraud warnings and response after notification. Each case must therefore be evaluated using its particular evidence, including authentication records, transaction alerts, customer conduct and the bank’s compliance with CBK requirements.

LEAVE A COMMENT