Banking Law And Identity Theft Prevention Obligations Kuwait .
Banking Law and Identity Theft Prevention Obligations in Kuwait
1. Introduction
Identity theft occurs when a person unlawfully obtains or uses another person’s identifying information for fraud or financial gain. In banking, stolen information may be used to:
- Open an account in another person’s name
- Take control of an existing account
- Obtain a loan or credit card
- Replace a registered mobile number
- Reset digital-banking credentials
- Make unauthorized electronic transfers
- Create false companies or beneficial owners
- Impersonate a customer during remote onboarding
- Manipulate biometric or facial-recognition systems
- Convince bank employees to disclose confidential information
Kuwait does not regulate identity-theft prevention through one single banking statute. A bank’s obligations arise from a combination of Central Bank of Kuwait requirements, banking legislation, AML/CFT rules, electronic-payment regulations, cybersecurity requirements, data-protection rules, contractual duties and general civil-law principles.
Identity-theft prevention is therefore both a regulatory obligation and an important part of a bank’s duty of care toward customers.
2. Main Legal and Regulatory Framework
2.1 Law No. 32 of 1968
Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business establishes the Central Bank of Kuwait, or CBK, and gives it supervisory authority over licensed banks.
The CBK may:
- Issue binding instructions
- Examine banking records
- Inspect internal-control systems
- Require regulatory reports
- Investigate compliance failures
- Direct banks to remedy weaknesses
- Impose regulatory penalties
If identity theft occurs because a bank failed to establish adequate identification, authentication or fraud-monitoring controls, the incident may amount to more than an ordinary customer dispute. It may also indicate a failure to comply with CBK supervisory requirements.
2.2 Law No. 106 of 2013 on AML/CFT
Law No. 106 of 2013 concerning Anti-Money Laundering and Combating the Financing of Terrorism is highly relevant to identity-theft prevention.
Banks must conduct customer due diligence and identify:
- The customer
- Any person acting on the customer’s behalf
- The beneficial owner
- The purpose and intended nature of the relationship
- The source of funds in appropriate circumstances
The CBK’s AML/CFT instructions require banks to verify identity using reliable and independent information, documents or data and to apply customer due diligence according to risk.
These requirements help prevent offenders from using stolen identities to open accounts or move criminal proceeds.
2.3 Electronic Transactions Law No. 20 of 2014
The Electronic Transactions Law gives legal recognition to electronic records, electronic signatures and electronic communications.
For banks, the law makes it important to establish:
- Whether a customer gave an instruction
- Whether an electronic signature was authentic
- Whether the record was altered
- When the transaction was initiated
- Which device was used
- Whether the authentication process was completed
- Whether the audit trail is reliable
A password or one-time passcode does not necessarily prove that the real customer personally authorized a transaction. Banks should preserve additional evidence, including device data, login history, IP information, behavioural indicators and communication records.
2.4 Cybercrime Law No. 63 of 2015
Kuwait’s Cybercrime Law criminalizes several activities connected with identity theft, including unlawful access to information systems, misuse of data, electronic fraud and interference with electronic information.
Criminal liability generally falls on the thief or fraudster. However, criminal prosecution of the offender does not automatically protect the bank from:
- Regulatory proceedings
- Customer compensation claims
- Contractual disputes
- Reputational damage
- Remedial directions from the CBK
The bank’s conduct must be evaluated separately from the offender’s criminal conduct.
2.5 CBK Cybersecurity Framework
The CBK Cybersecurity Framework for the Kuwaiti Banking Sector requires regulated institutions to develop structured cybersecurity governance and controls.
It covers areas such as:
- Identity and access management
- Authentication
- Protection of customer information
- Security monitoring
- Incident management
- Third-party security
- Cyber-risk assessment
- Business continuity
- Employee awareness
- Independent assurance
The framework requires banks to evaluate their inherent cyber risk and comply with baseline control requirements.
Identity theft is directly connected with cybersecurity because attackers frequently obtain customer identities through phishing, malware, credential stuffing, database breaches and social engineering.
2.6 Cyber and Operational Resilience Framework
The CBK’s Cyber and Operational Resilience Framework, introduced in 2025, advances the regulatory system from foundational cybersecurity compliance toward a resilience-first and maturity-oriented model.
A bank must be capable of:
- Preventing identity-based attacks
- Detecting account compromise
- Restricting the spread of an incident
- Preserving critical banking services
- Recovering affected systems
- Communicating with customers
- Investigating the incident
- Learning from control failures
2.7 Electronic-Payment Regulations
CBK instructions regulating electronic payments require regulated payment institutions to maintain governance, security, due-diligence and operational controls.
Due care must be taken when customer data and information are obtained or updated.
These obligations are especially relevant to:
- Mobile wallets
- Payment applications
- Electronic-money accounts
- Online transfers
- Payment cards
- Merchant accounts
- Remote customer onboarding
- Payment-service agents
2.8 Data Protection Regulation
CITRA’s Data Privacy Protection Regulation applies to public- and private-sector service providers that collect, process or store personal data and user-related content.
Banks must apply appropriate safeguards to personal data that could be used for impersonation, including:
- Civil identification details
- Passport information
- Contact details
- Account numbers
- Biometric information
- Authentication credentials
- Transaction records
- Device identifiers
A data-security failure may facilitate identity theft even if no money is immediately removed from an account.
3. Customer Identification Obligations
3.1 Identification at Account Opening
Before establishing a relationship, a bank should obtain and verify sufficient information about the customer.
For an individual, this normally includes:
- Full legal name
- Civil identification or passport information
- Nationality
- Date of birth
- Residential address
- Contact details
- Occupation or business activity
- Specimen signature, where applicable
- Purpose of the account
- Expected account activity
For companies, the bank should verify:
- Legal existence
- Commercial registration
- Registered address
- Directors and authorized representatives
- Ownership and control structure
- Ultimate beneficial owners
- Authority of persons opening or operating the account
The bank should not accept documents merely because they appear complete. It must consider whether they are authentic, current and consistent with other available information.
3.2 Remote and Digital Onboarding
Digital onboarding creates additional identity-theft risks because the bank does not meet the applicant physically.
Appropriate controls may include:
- Verification against authoritative databases
- Document authenticity examination
- Facial comparison
- Liveness detection
- One-time password confirmation
- Verification of the registered telephone number
- Device fingerprinting
- Detection of virtual cameras and manipulated media
- Screening for repeated use of the same device
- Manual review of high-risk applications
Deepfake technology makes simple facial comparison insufficient for higher-risk onboarding. Banks should employ anti-spoofing controls and escalate suspicious cases for human review.
3.3 Beneficial-Ownership Verification
Identity theft can also occur through false corporate identities. A person may use stolen documents to appear as a director, shareholder or authorized signatory.
Banks must look beyond the company’s formal name and identify the individuals who ultimately own or control it. Complex ownership, nominee shareholders or unexplained foreign entities may require enhanced verification.
3.4 Ongoing Customer Due Diligence
Identity verification does not end when the account is opened. Banks should:
- Keep customer information current
- Reverify identity after material changes
- Examine unusual account behaviour
- Confirm changes to telephone numbers or email addresses
- Reassess dormant accounts before reactivation
- Investigate changes to authorized signatories
- Review beneficial ownership periodically
A sudden request to change both contact details and transaction limits is an important warning sign.
4. Authentication and Account Security
4.1 Multi-Factor Authentication
Banks should not rely entirely on a password. Multi-factor authentication combines two or more elements:
- Something the customer knows, such as a password
- Something the customer possesses, such as a registered device
- Something inherent to the customer, such as a biometric characteristic
However, multi-factor authentication is not automatically secure. Criminals may defeat it through:
- SIM-swap attacks
- Remote-access malware
- Social engineering
- Real-time phishing
- Push-notification fatigue
- Theft of authentication tokens
- Compromise of a customer’s email account
Banks should therefore use risk-based and transaction-specific controls.
4.2 Transaction Monitoring
A transaction may require further examination when it involves:
- A new or unknown device
- An unusual geographical location
- Multiple failed login attempts
- A new beneficiary followed by a large transfer
- Rapid depletion of an account
- A transfer inconsistent with the customer’s history
- An unusual change in contact information
- Access at an abnormal time
- Several customers using the same device
- Movement of funds through newly opened accounts
Monitoring systems should produce meaningful alerts. A bank may be criticized if its system identifies a high-risk transaction but employees fail to review the alert.
4.3 Protection Against SIM-Swap Fraud
In SIM-swap fraud, a criminal obtains control of the victim’s mobile number and intercepts authentication messages.
Preventive measures can include:
- Detection of recent SIM replacement
- Cooling-off periods after changing a mobile number
- Additional verification before large transfers
- Alerts through more than one communication channel
- Restrictions on simultaneous contact and password changes
- Coordination with telecommunications providers
Possession of a one-time password should not be treated as conclusive evidence of customer authorization when other warning signs exist.
4.4 Call-Centre Security
Criminals frequently impersonate customers during telephone calls. Call-centre employees should not authenticate callers using easily discoverable information such as date of birth or address alone.
Banks should:
- Limit the information employees may disclose
- Use secure authentication questions
- Detect repeated failed verification attempts
- Escalate unusual requests
- Prevent employees from asking customers to disclose complete passwords or passcodes
- Record relevant calls in accordance with applicable law
5. Employee and Insider Controls
Identity theft can be committed or assisted by bank employees. Banks should therefore maintain:
- Pre-employment screening
- Role-based access
- Segregation of duties
- Privileged-account monitoring
- Restrictions on copying customer data
- Data-loss prevention controls
- Monitoring of bulk customer searches
- Prompt termination of access when employment ends
- Confidential reporting channels
- Disciplinary procedures
An employee should not be able to obtain a complete customer identity profile without a genuine business purpose.
6. Data-Breach and Incident-Response Duties
When identity information has been compromised, the bank should promptly:
- Contain unauthorized access.
- Preserve system logs and other evidence.
- Identify affected customers and information.
- Block or monitor exposed accounts.
- Reset compromised credentials.
- Examine recent transactions and account changes.
- notify senior management and relevant control functions.
- Make required regulatory reports.
- Inform customers when legally required or necessary for protection.
- Coordinate with law-enforcement authorities.
- Remedy the weakness that caused the incident.
The bank should not wait for customers to lose money before responding. Exposure of identification data can create continuing risks, including fraudulent loans and future account takeover.
7. Allocation of Loss and Bank Liability
The fact that valid credentials were used does not necessarily prove customer responsibility.
Liability may depend on:
- Whether the customer actually authorized the transaction
- Whether the bank’s controls complied with CBK requirements
- Whether warning signs were present
- Whether the customer protected their credentials
- Whether the customer promptly reported the fraud
- Whether the bank acted after receiving notice
- Whether an employee or vendor contributed to the fraud
- Whether the bank can produce a reliable audit trail
- Whether contractual terms are valid and sufficiently clear
A contractual provision placing every transaction made with correct credentials on the customer may not necessarily excuse the bank’s own negligence or regulatory failure.
There is no universal rule that every identity-theft loss must automatically be reimbursed by a Kuwaiti bank. Each case requires examination of authorization, causation, customer conduct, contractual terms and the bank’s compliance with its legal duties.
8. Relevant Case Laws
Published Kuwaiti judgments specifically addressing modern digital identity theft are limited. The following comparative cases are not binding in Kuwait, but they provide useful principles for interpreting banking duties, fraud controls and allocation of loss.
8.1 Patco Construction Co. v People’s United Bank
United States Court of Appeals, First Circuit, 2012
Criminals obtained Patco’s online-banking credentials and made several fraudulent electronic transfers. The bank’s system classified the transfers as high risk but did not apply effective additional verification.
The court concluded that the bank’s security procedures were not commercially reasonable. Repeated use of security questions also increased the possibility that malware would capture the answers.
Relevance to Kuwait: Correct credentials should not end the investigation. Kuwaiti banks should evaluate unusual devices, locations, transaction values and customer behaviour.
8.2 Choice Escrow and Land Title, LLC v BancorpSouth Bank
United States Court of Appeals, Eighth Circuit, 2014
Fraudsters used stolen credentials to send an unauthorized wire transfer. The bank had offered dual-control security, but the customer declined it.
The court found that the bank had offered commercially reasonable security procedures and ruled in its favour.
Relevance to Kuwait: A bank should offer security proportionate to the risk and retain evidence that the customer was informed about available protections. Customers also have responsibilities regarding security controls.
8.3 Experi-Metal, Inc. v Comerica Bank
United States District Court, 2011
A phishing scheme resulted in numerous fraudulent payment orders. Although the criminal used valid credentials, the frequency and pattern of transactions were highly abnormal.
The court determined that the bank failed to act in good faith because it did not adequately respond to obvious warning signs.
Relevance to Kuwait: Authentication and transaction monitoring must operate together. A bank should intervene when payment behaviour is clearly inconsistent with the customer’s profile.
8.4 Shames-Yeakel v Citizens Financial Bank
United States District Court, 2009
The customers alleged that the bank used inadequate online-banking security and failed to adopt stronger authentication despite regulatory guidance.
The court allowed the negligence claim to continue because inadequate security could have contributed to the loss.
Relevance to Kuwait: Failure to implement CBK-required or generally accepted safeguards may support an allegation that the bank failed to exercise reasonable care.
8.5 Banco del Austro v Wells Fargo Bank
United States Court of Appeals, Second Circuit, 2017
Hackers compromised a bank’s system and sent fraudulent SWIFT payment instructions. The case concerned responsibility for executing the fraudulent instructions and allocation of loss between financial institutions.
Relevance to Kuwait: Banks must secure payment credentials, monitor cross-border instructions and establish clear security procedures with correspondent banks.
8.6 Singularis Holdings Ltd v Daiwa Capital Markets Europe Ltd
United Kingdom Supreme Court, 2019
A company’s controlling officer instructed the bank to make payments that misappropriated company funds. The bank processed the instructions despite circumstances suggesting fraud.
The bank was found liable for failing to make appropriate inquiries.
Relevance to Kuwait: Even where an apparently authorized person gives the instruction, a bank may need to investigate when objective circumstances suggest fraud or abuse of authority.
8.7 Philipp v Barclays Bank UK PLC
United Kingdom Supreme Court, 2023
A customer was deceived by fraudsters but personally instructed the bank to make the transfers. She argued that the bank should have recognized the scam and refused the instructions.
The Supreme Court held that the traditional duty concerning fraudulent instructions by an agent did not apply in the same way when the customer personally gave a clear instruction.
Relevance to Kuwait: A distinction must be made between an unauthorized transaction and an authorized transaction induced by fraud. Nevertheless, banks remain subject to regulatory fraud-prevention and monitoring obligations.
8.8 Tecnimont Arabia Ltd v National Westminster Bank PLC
England and Wales Court of Appeal, 2022
Fraudsters compromised email communications and substituted their own bank-account details. Funds were consequently transferred to a fraudulent account.
The court declined to impose an unrestricted duty on a receiving bank in favour of a person who was not its customer.
Relevance to Kuwait: Paying banks and customers should independently verify changes to beneficiary details. Receiving banks should also detect mule-account behaviour through effective customer due diligence and monitoring.
9. Practical Compliance Programme for Kuwaiti Banks
A strong identity-theft prevention programme should include:
- Reliable customer and beneficial-owner verification.
- Risk-based digital-onboarding controls.
- Liveness and anti-deepfake detection.
- Multi-factor and transaction-specific authentication.
- Device and behavioural analysis.
- Monitoring for unusual payment activity.
- Enhanced controls for changes to customer contact details.
- Cooling-off periods for high-risk account changes.
- Verification of new beneficiaries.
- Protection against SIM-swap fraud.
- Employee access monitoring.
- Secure storage and encryption of identity documents.
- Third-party and cloud-provider oversight.
- Rapid customer reporting channels.
- Immediate account restriction where compromise is suspected.
- Tested incident-response procedures.
- Preservation of reliable transaction evidence.
- Periodic independent security testing.
- Regular staff and customer-awareness training.
- Board oversight of major identity-fraud risks.
Conclusion
Kuwaiti banks have extensive obligations to prevent identity theft even though those obligations are distributed across different laws and regulatory instruments. The principal requirements arise from CBK supervision, AML/CFT customer due diligence, cybersecurity standards, electronic-payment rules, data-protection requirements and the bank’s general duty to exercise professional care.
A bank must do more than collect an identification document or confirm a one-time password. It should establish that the identity is genuine, protect the information obtained, monitor the account throughout the relationship and respond to circumstances suggesting impersonation or fraud.
Because published Kuwaiti case law on digital identity theft remains limited, comparative cases are useful but only persuasive. A Kuwaiti court would ultimately decide liability under Kuwaiti legislation, CBK instructions, contractual terms and the particular facts of the incident.

comments