Banking Law And Monetary Policy Transmission Banking Spain .
Banking Law and Model Risk Governance in Banking — Kuwait
1. Introduction
Model risk governance refers to the systems through which a bank controls the risks created by mathematical, statistical, economic, algorithmic and artificial-intelligence models.
Modern Kuwaiti banks may use models for:
credit scoring and lending decisions;
expected-credit-loss calculations;
capital adequacy;
liquidity forecasting;
market and interest-rate risk;
stress testing;
fraud detection;
AML transaction monitoring;
customer-risk classification;
pricing;
cybersecurity;
portfolio management; and
increasingly, artificial intelligence and machine learning.
Kuwait does not currently have one standalone statute called a Model Risk Governance Law. Instead, model governance arises from the broader framework established by the Central Bank of Kuwait (CBK) under Law No. 32 of 1968, together with CBK requirements concerning corporate governance, risk management, internal controls, prudential supervision, information systems and operational resilience. Article 71 of the CBK Law gives the Central Bank authority to issue instructions necessary to ensure the sound conduct of banking business.
Accordingly, a model used by a bank should not be viewed merely as software. If its output affects lending, capital, risk measurement or customers, its weaknesses can become a banking-law and governance issue.
2. Meaning of Model Risk
Model risk is the possibility that a bank suffers financial, regulatory, operational or reputational harm because a model is incorrect, poorly designed, improperly implemented or used for a purpose for which it was not designed.
Consider a credit model that predicts whether customers will repay loans.
The model could fail because:
Input data are inaccurate → assumptions become unreliable → predictions become distorted → lending decisions become unreliable → credit losses increase.
Model risk can therefore arise even where the software operates exactly as programmed.
The underlying model itself may simply be wrong.
3. CBK's Supervisory Foundation
The CBK's regulatory framework for conventional banks contains extensive rules and instructions dealing with banking supervision, risk, credit, financial statements, internal controls and other prudential matters.
Under Article 71 of Law No. 32 of 1968, the CBK possesses broad authority to issue instructions to banks where necessary to ensure the sound progress of banking.
This provides the regulatory foundation through which model-related weaknesses can be addressed even without a separate statute devoted exclusively to model risk.
A bank therefore cannot reasonably argue that an algorithm falls outside prudential governance merely because the CBK framework does not give every statistical technique a separate regulatory category.
4. Board Responsibility
Model governance ultimately begins with the board of directors.
The CBK's governance framework emphasises the board's responsibility for the bank's financial soundness and places particular importance on risk-management governance. The 2019 governance reforms strengthened board independence, risk governance and compliance governance.
This principle has major consequences for model risk.
The board does not need to calculate every regression coefficient or understand every line of AI code.
However, it should ensure that the institution has an adequate system for controlling models.
That system should establish:
ownership → development → approval → independent validation → deployment → monitoring → reporting → remediation → retirement.
Ultimate accountability cannot simply be transferred to data scientists or an external software supplier.
5. Risk Management Function
CBK governance principles require effective risk-management structures.
The risk-management function should be sufficiently independent and capable of identifying, measuring, monitoring and controlling risks affecting the institution. CBK-derived governance arrangements also give risk management appropriate access to board-level oversight.
For model governance, this means that a business unit seeking to deploy a profitable model should not necessarily be the only body deciding whether that model is reliable.
There should be effective challenge.
For example:
Business unit develops lending model → independent risk function challenges assumptions → validation tests performance → weaknesses are reported → authorised body decides whether deployment is acceptable.
This separation reduces conflicts of interest.
6. Model Inventory
An effective governance framework should maintain an accurate model inventory.
The bank should know:
what models exist;
where each model is used;
who owns it;
what data it uses;
what decisions it influences;
when it was validated;
whether it is internally developed or supplied by a third party;
what limitations have been identified; and
whether remediation is outstanding.
Without a model inventory, senior management cannot reliably determine the institution's aggregate model exposure.
Models should also normally be classified according to materiality.
A minor marketing model does not necessarily require the same governance intensity as a model determining billions of dinars of credit exposure or regulatory capital.
7. Model Development
Banks should establish controlled development standards.
A model-development file should normally explain:
the purpose of the model;
methodology;
data sources;
assumptions;
limitations;
variables;
statistical techniques;
testing methodology;
expected use; and
circumstances in which the model should not be used.
Documentation is legally important because governance cannot depend entirely on the knowledge of the employee who originally developed the model.
If that employee leaves, the bank must still understand its own risk-management system.
8. Data Quality
A sophisticated model can produce unreliable results when trained or operated on poor-quality information.
Banks should therefore control:
completeness;
accuracy;
consistency;
relevance;
timeliness;
duplication;
missing information; and
data transformations.
This is particularly important for AI and machine-learning systems.
Historical information can contain patterns that cease to represent present economic conditions.
A model that performed extremely well during stable economic conditions may perform badly after a major economic shock.
9. Independent Model Validation
Validation is one of the most important components of model-risk governance.
A bank should not assume that a model is reliable simply because its developer says that it works.
Validation can examine:
Conceptual soundness — Is the methodology reasonable?
Data — Are the inputs reliable?
Implementation — Was the methodology correctly converted into software?
Performance — Do predictions correspond sufficiently with actual outcomes?
Sensitivity — How does the model respond to changed assumptions?
Limitations — Where is the model likely to fail?
Benchmarking — How does it compare with reasonable alternatives?
The greater the model's materiality, the stronger the independent challenge should generally be.
10. Model Validation Is Not a One-Time Exercise
Approval does not end model governance.
Suppose a credit-scoring model is validated in 2026.
By 2028:
borrower behaviour may have changed;
economic conditions may differ;
new products may exist;
data quality may have changed; and
customer populations may be different.
The original validation may therefore no longer provide sufficient assurance.
Banks need ongoing monitoring and periodic revalidation.
11. Internal Controls
The CBK has long maintained specific instructions concerning internal control systems and risk management.
Its governance principles emphasise appropriate organisational structures, defined responsibilities, segregation of duties, controls against operational risk and board accountability for the institution's financial integrity.
Model governance should therefore fit into the broader internal-control architecture.
A basic three-level arrangement can be expressed as:
Business/model owner → risk and compliance oversight → internal audit.
Internal audit should be sufficiently independent to evaluate whether the governance framework itself operates effectively.
12. Model Changes
Banks also require change controls.
Suppose a credit model originally uses 20 variables.
A development team introduces another 15 variables and changes the algorithm.
The bank should determine whether the modification constitutes a material model change.
Material changes may require:
documentation;
testing;
validation;
approval; and
updated monitoring thresholds.
Otherwise, a previously validated model can gradually become a substantially different, unvalidated system.
13. Model Overrides
Human employees sometimes override model results.
Overrides can be legitimate.
For example, a model may not capture an unusual but genuine feature of a customer's circumstances.
However, uncontrolled overrides create governance problems.
A bank should therefore record:
who overrode the model + why + what decision resulted + whether repeated override patterns exist.
A high override rate can indicate either that staff are bypassing controls or that the model itself is unreliable.
14. Artificial Intelligence and Machine Learning
AI increases the importance of model governance.
Traditional models may be relatively transparent.
Machine-learning systems can be more complex and may change substantially as data and techniques evolve.
Important risks include:
lack of explainability;
unstable outputs;
inappropriate training data;
automation bias;
data leakage;
inaccurate outputs;
cybersecurity vulnerabilities;
uncontrolled model changes; and
excessive dependence on external providers.
The CBK's supervisory architecture now expressly includes oversight of financial technologies and information systems, while its operational-resilience approach has evolved toward a resilience-focused supervisory framework.
Therefore, AI model governance should be integrated with banking risk governance rather than treated as an isolated technology project.
15. Third-Party Models
Banks frequently purchase software and models from vendors.
Outsourcing the technology does not eliminate the bank's responsibility.
Before relying on an external model, appropriate governance can include examining:
methodology;
vendor competence;
validation evidence;
data requirements;
cybersecurity;
contractual access;
audit rights;
performance monitoring;
incident management;
model updates; and
exit arrangements.
The bank must understand the material limitations of a model sufficiently to use it safely.
"Vendor supplied it" is not a satisfactory risk-management methodology.
16. Stress Testing
Model risk is particularly important in stress testing.
Stress-testing models estimate how a bank may perform during adverse economic conditions.
They may examine:
borrower defaults;
property-price declines;
interest-rate movements;
liquidity pressures;
market losses; and
concentration risks.
If the assumptions are excessively optimistic, the institution can underestimate the amount of capital or liquidity necessary to withstand stress.
For this reason, governance should challenge assumptions rather than merely verify mathematical calculations.
17. Expected Credit Loss Models
Expected-credit-loss calculations depend heavily on modelling.
Banks must estimate future credit deterioration rather than simply record losses after they occur.
Important model inputs can include:
probability of default;
loss given default;
exposure at default;
macroeconomic forecasts; and
scenario weights.
Model errors can consequently affect both risk management and published financial information.
This makes model governance relevant not merely to risk teams but also to accounting, audit and board oversight.
18. Cyber and Operational Resilience
Model risk increasingly overlaps with technology and cyber risk.
The CBK's Cyber and Operational Resilience Framework reflects a progression from foundational cybersecurity requirements toward a resilience-oriented supervisory model. Its objective includes enabling regulated entities to anticipate, withstand, recover from and adapt to disruptions.
For models, resilience means banks should consider what happens if:
the model becomes unavailable;
input data become corrupted;
an external provider fails;
model output becomes unreliable;
software is compromised; or
an automated decision system must be shut down.
Banks therefore need fallback arrangements for sufficiently critical models.
19. Case Law and Judicial Principles
A significant qualification is necessary.
Published Kuwaiti case law specifically labelled "model risk governance" is extremely limited.
Kuwait has not developed a body of six reported Court of Cassation judgments specifically addressing AI-model validation or banking model-risk frameworks.
It would therefore be inaccurate to invent six Kuwaiti "model risk" cases.
The legally sound approach is to use established Kuwaiti banking and commercial judicial principles that govern the consequences of model-generated banking decisions, supplemented by the CBK regulatory framework.
The following six case-law principles/categories are especially relevant.
Case-Law Principle 1 — Bank's Professional Duty of Care
Kuwaiti banking jurisprudence recognises that banks conduct specialised professional activities and their contractual responsibilities are assessed according to the applicable banking relationship, contractual obligations and relevant professional standards.
Application to model risk
A bank cannot necessarily escape responsibility for an erroneous transaction simply by showing that an automated system generated the decision.
The relevant legal question remains whether the bank fulfilled the duties imposed upon it.
Model makes decision ≠ responsibility transfers to model.
This principle is fundamental to automated banking.
20. Case-Law Principle 2 — Credit Facilities and Documentary Evidence
Kuwaiti Court of Cassation banking disputes frequently turn on the contractual documents establishing credit facilities, account balances, securities and repayment obligations.
The courts examine the actual legal relationship rather than relying solely upon a party's internal classification of the transaction.
Model-risk relevance
A bank's internal credit model may classify a customer as:
Risk Grade 7.
That classification does not itself rewrite the customer's legal rights.
The underlying loan agreement, applicable banking rules and legally relevant evidence continue to determine the contractual relationship.
21. Case-Law Principle 3 — Expert Evidence in Complex Banking Accounts
Complex banking disputes in Kuwait can involve accounting or technical experts where determination of balances and financial relationships requires specialised analysis.
Courts remain responsible for deciding the dispute, while expert evidence assists with technical matters.
Model-risk relevance
This becomes especially important when a dispute concerns:
model calculations;
interest calculations;
credit-loss estimates;
algorithmic transaction classification; or
complex account reconciliation.
Banks therefore need documentation capable of explaining how important calculations were produced.
An unexplained output may be significantly harder to defend than a properly documented methodology.
22. Case-Law Principle 4 — Contractual Good Faith and Proper Performance
Kuwaiti contractual law requires contractual obligations to be performed consistently with their legal content and applicable good-faith principles.
Model-risk relevance
Suppose a bank uses an automated system to administer a financing contract.
The fact that the system automatically produces a result does not necessarily make that result contractually correct.
If the model applies:
the wrong rate;
the wrong customer data;
an incorrect contractual assumption; or
an unauthorised charge,
the contractual question remains whether the bank correctly performed the agreement.
Automation is a method of performance, not an independent legal defence.
23. Case-Law Principle 5 — Causation and Banking Loss
In banking damages disputes, liability requires examination of the connection between the alleged wrongful conduct and the claimed loss.
Model-risk relevance
An inaccurate model does not automatically establish that every subsequent customer loss was caused by the model.
A claimant may still need to establish the legally relevant causal relationship.
For example:
Model defect → incorrect decision → legally recognised loss.
If independent factors caused the loss, causation becomes more difficult.
This is important because model-risk incidents can involve multiple contributing causes.
24. Case-Law Principle 6 — Regulatory Requirements and Bank-Customer Relationships
Kuwaiti banking disputes must also be understood within the CBK's supervisory framework.
The CBK separately maintains instructions addressing banks' relationships with customers, internal controls, risk management and other regulated banking activities. Its Islamic-banking regulatory catalogue, for example, expressly identifies internal-control/risk-management instructions and bank-customer relationship instructions as distinct supervisory areas.
Model-risk relevance
A bank deploying automated systems therefore operates simultaneously under:
contract law + banking supervision + internal-control requirements + customer-protection requirements.
A model cannot be assessed solely as a private software tool.
25. Why Six Direct Kuwaiti Model-Risk Cases Cannot Properly Be Listed
This distinction is academically important.
A paper claiming cases such as:
"Kuwait Court of Cassation — AI Credit Model Case"
or
"Kuwait Supreme Court — Machine Learning Validation Case"
without a verifiable judgment would create false authority.
The available Kuwaiti framework instead shows that model risk is presently governed primarily through regulation and general legal principles, while direct reported litigation on modern banking-model governance remains limited.
Consequently, the six categories above should be described as relevant Kuwaiti case-law principles, not falsely represented as six reported judgments specifically deciding model-risk governance.
26. Practical Governance Structure
A strong Kuwaiti bank could organise model governance as follows:
Board of Directors
Approves overall risk appetite and governance architecture.
Board Risk Committee
Provides focused oversight of material risk and significant model exposure.
Senior Management
Implements policies and allocates resources.
Chief Risk Officer
Maintains independent risk oversight.
Model Owners
Take responsibility for individual models.
Independent Validation
Challenges methodology, assumptions, data and performance.
Compliance
Examines regulatory consequences.
Information Technology/Cybersecurity
Controls technical implementation and resilience.
Internal Audit
Independently evaluates whether the entire framework functions as intended.
This architecture is consistent with the CBK's wider emphasis on board responsibility, risk governance and internal controls.
27. Model Lifecycle
Model governance should cover the entire lifecycle:
Identification
↓
Development
↓
Documentation
↓
Independent validation
↓
Approval
↓
Implementation
↓
Performance monitoring
↓
Periodic revalidation
↓
Modification
↓
Retirement
A bank that validates a model only before initial deployment does not adequately control lifecycle risk.
28. Model-Risk Appetite
Banks should determine how much model risk they are prepared to accept.
This can include thresholds concerning:
validation findings;
overdue validations;
unresolved weaknesses;
performance deterioration;
data-quality failures;
unauthorised models;
manual overrides; and
dependence on third parties.
Material breaches should be escalated to appropriate senior management and, where sufficiently important, board-level committees.
29. Example
Assume a Kuwaiti bank develops an AI credit model for personal financing.
The system examines thousands of customer characteristics and predicts default risk.
It approves:
Customer A — low risk
and rejects:
Customer B — high risk.
Six months later, the bank discovers that a data-processing error caused the model to use outdated income information for thousands of customers.
The problem is not merely an IT defect.
It potentially creates:
Model risk — predictions were unreliable.
Credit risk — unsuitable borrowers may have received financing.
Operational risk — defective data entered production systems.
Compliance risk — customer treatment may require investigation.
Legal risk — contractual or customer disputes could arise.
Reputational risk — customers may lose confidence.
Governance risk — management must explain why controls failed.
The bank should therefore identify affected decisions, correct the data, test the model, evaluate customer consequences, determine whether regulatory escalation is required and investigate the control failure.
30. Relationship with Islamic Banking
Model governance is equally important for Islamic banks.
The CBK maintains specific supervisory instructions for Islamic banks, including internal-control and risk-management requirements.
Models used for Islamic financing therefore need to operate within both ordinary prudential controls and the institution's applicable Sharia governance arrangements.
For example, an automated pricing or financing system should not silently transform the economic or contractual structure approved for an Islamic banking product.
Technology must implement the legally approved product rather than redefine it.
31. Regulatory Consequences
Weak model governance can create several regulatory consequences.
Depending on the circumstances, the CBK could focus on:
deficient internal controls;
inadequate risk management;
unreliable regulatory reporting;
inappropriate credit-risk measurement;
weak governance;
technology deficiencies;
operational-resilience weaknesses; or
customer-treatment problems.
The CBK's supervisory authority under Article 71 is intentionally broad, permitting instructions designed to ensure sound banking operations.
The absence of a statute bearing the title "Model Risk Act" therefore does not mean model failures are outside banking supervision.
32. Documentation
Documentation is particularly important because it creates accountability.
For each material model, records should ordinarily identify:
Purpose: Why does the model exist?
Owner: Who is responsible?
Method: How does it work?
Data: What information does it use?
Assumptions: What does it assume?
Limitations: Where might it fail?
Validation: Who independently tested it?
Approval: Who authorised deployment?
Monitoring: How is deterioration detected?
Changes: What has been modified?
Retirement: When should use stop?
Without this information, effective board oversight and independent review become considerably more difficult.
33. Overall Legal Position
Kuwait's approach to model risk is presently best understood as principles-based banking supervision rather than a standalone model-risk code.
Its legal foundations include:
Law No. 32 of 1968 and the CBK's supervisory authority;
CBK Corporate Governance Instructions;
CBK internal-control and risk-management requirements;
prudential rules concerning credit and banking risk;
information-technology and cybersecurity requirements;
operational-resilience requirements;
bank-customer obligations; and
general Kuwaiti contractual and banking-law principles.
The CBK's 2019 governance amendments specifically reinforced risk-management governance and board responsibility, while its more recent operational-resilience architecture reflects the increasing regulatory importance of technology-dependent banking.
Conclusion
Model risk governance in Kuwaiti banking is fundamentally an accountability system.
Banks increasingly depend on models for credit, capital, liquidity, fraud detection, stress testing and automated decision-making. Yet responsibility for those decisions remains within the regulated banking institution.
The appropriate framework therefore requires:
Board oversight + independent risk management + controlled model development + reliable data + independent validation + documentation + continuous monitoring + internal audit + escalation and remediation.
Kuwait does not yet provide a large published body of judicial decisions specifically dealing with AI or statistical model-risk governance. Accordingly, it would be misleading to manufacture six supposedly direct "model-risk cases." The legally defensible case-law analysis instead relies on established Kuwaiti judicial principles concerning professional banking duties, credit documentation, expert evidence, contractual performance, causation and the relationship between banking regulation and customer obligations.
The core principle is straightforward: a bank may automate a calculation or decision, but it does not automate away its legal and regulatory responsibility for controlling the risks created by that decision-making system.

comments