Banking Law And Open Banking Legal Frameworks Kuwait .
Banking Law and Open Banking Legal Frameworks in Kuwait
1. Introduction
Open banking is the controlled sharing of banking information and payment functionality between banks and authorised third-party service providers through secure digital interfaces, usually Application Programming Interfaces (APIs). The central idea is that banking data should not remain locked inside a customer's bank where the customer has properly authorised its use.
Kuwait has been developing its own open-banking model under the supervision of the Central Bank of Kuwait (CBK). Importantly, Kuwait should not simply be described as having copied the European PSD2 model. Its system is being developed through Kuwait's existing banking legislation, electronic-transactions rules, electronic-payment regulation, cybersecurity requirements and a dedicated CBK open-banking initiative.
A major development occurred on 4 June 2025, when the CBK announced a Draft Open Banking Regulatory Framework. The CBK stated that the project is intended to establish regulatory legislation together with security, technical and operational standards for open banking. It also stated that implementation would occur in phases after adequate testing.
Because the framework is comparatively new, there is not yet a substantial body of reported Kuwaiti judicial decisions specifically interpreting open-banking APIs. Older banking cases nevertheless establish principles concerning customer authorisation, regulatory compliance, contractual liability and payment instructions that are highly relevant to future open-banking disputes.
2. Existing Banking-Law Foundation
The legal framework for open banking does not exist separately from ordinary Kuwaiti banking regulation.
The Central Bank of Kuwait is the principal regulator of banking activities. Banks and regulated financial institutions remain subject to CBK supervision even when financial services are delivered through mobile applications, APIs or FinTech platforms.
This creates an important principle:
Digital delivery does not remove an activity from banking regulation.
For example, where a customer authorises a FinTech application to obtain account information from a bank, the fact that the information moves through an API does not eliminate the bank's regulatory obligations concerning confidentiality, security and customer protection.
Similarly, outsourcing a technical function to a FinTech company does not necessarily allow a regulated institution to outsource its regulatory responsibility.
3. The CBK Draft Open Banking Regulatory Framework
The most important direct development is the CBK's 2025 Draft Open Banking Regulatory Framework.
According to the CBK, open banking would allow local banks to share customer information with CBK-licensed Open Banking Service Providers, provided that the customer has explicitly approved the sharing.
The framework therefore revolves around three participants:
Customer → Bank → Licensed Open Banking Service Provider
The customer's permission is the legal gateway allowing information to move between these participants.
The CBK has indicated that the framework is intended to regulate not merely commercial relationships but also the security, technical and operational architecture supporting open banking.
4. Account Information Services
One major category of open-banking activity concerns access to account information.
A customer may, for example, maintain accounts with several Kuwaiti banks.
Instead of accessing each banking application separately, an authorised service could potentially combine permitted information into one interface.
The CBK has identified potential services including consolidated information concerning customers' local bank accounts, expense tracking and tools suggesting spending or saving plans.
Legally, this creates important questions concerning:
what information may be accessed;
how long access remains valid;
whether information may be stored;
whether it may be analysed;
whether it may be transferred further;
how customer permission can be withdrawn; and
responsibility where information is accessed improperly.
Accordingly, open banking is not simply a technology issue. It is also a question of legal authority over financial information.
5. Payment Initiation
Open banking can go beyond simply viewing account information.
The CBK's announced model also contemplates the creation of payment orders from bank accounts, including payments for bills, online purchases and transfers to individuals, as well as standing and future-dated payments.
This produces a more complicated legal chain:
Customer → Open Banking Provider → API → Bank → Payment System → Recipient
If something goes wrong, the law must determine where responsibility lies.
For example, the dispute might concern whether the customer genuinely authorised the transaction, whether the provider transmitted the correct instruction or whether the bank correctly executed it.
Clear allocation of responsibility is therefore one of the essential functions of an effective open-banking framework.
6. Electronic Transactions Law
Kuwait's Law No. 20 of 2014 concerning Electronic Transactions forms another important part of the legal environment.
The CBK explains that its electronic-payment regulatory framework operates under this legislation and that the law gives the CBK oversight over electronic-payment transactions and authority to issue binding instructions in this field.
This matters for open banking because many important legal acts occur electronically.
Examples include electronic customer instructions, digital consent, online authentication and electronic transaction records.
Open banking therefore needs legally reliable evidence showing:
who acted + what was authorised + when authority was given + what transaction followed.
7. Electronic-Payment Regulation
In May 2023, the CBK updated Kuwait's Instructions for Regulating the Electronic Payment of Funds.
The regulatory framework covers matters including governance, risk management, anti-money-laundering controls, cybersecurity, business continuity and customer protection.
These requirements are highly relevant to open banking because payment-initiation services may interact directly with regulated payment infrastructure.
Open banking therefore sits within a broader regulated digital-payment ecosystem rather than operating as an entirely separate technological market.
8. Customer Consent
Consent is one of the central legal concepts in open banking.
The CBK expressly describes customer information as being shared with licensed providers with explicit customer approval.
Meaningful consent should allow the system to determine precisely what the customer authorised.
For example, permission to view an account balance should not automatically be treated as permission to initiate payments.
Similarly:
permission to access data ≠ unlimited permission to use data.
A properly designed system therefore needs records showing the scope and duration of the customer's authority.
9. Licensing and Regulatory Supervision
Open banking cannot safely operate on the assumption that every technology company should automatically receive direct access to bank accounts.
The CBK's announced framework contemplates licensed Open Banking Service Providers.
Licensing allows the regulator to establish entry requirements concerning matters such as governance, technical capability, financial resources, operational resilience, cybersecurity and compliance.
It also creates regulatory accountability.
A provider handling sensitive banking information is therefore not merely an ordinary software company when it performs a regulated financial function.
10. Regulatory Sandbox and Wolooj
Kuwait has used supervised experimentation as part of developing its FinTech framework.
In 2022, the CBK approved testing of an open-banking product within its Regulatory Sandbox using volunteer customers. The product provided analytical services concerning transactions across different bank accounts together with electronic-payment functionality.
The CBK subsequently developed the Wolooj Innovation Hub. Its sandbox framework provides controlled testing of FinTech products and evaluates matters including regulatory compliance, security, confidentiality, privacy and operational efficiency.
This demonstrates Kuwait's gradual approach:
Innovation → supervised testing → regulatory evaluation → controlled market implementation.
11. Cybersecurity and Operational Resilience
Cybersecurity is particularly important because open banking creates additional technological connections between financial institutions.
An API could potentially become a route through which an attacker attempts to obtain account information or initiate fraudulent transactions.
Consequently, an open-banking system needs strong controls relating to authentication, API security, encryption, monitoring, access management, incident response and audit trails.
The CBK's electronic-payment regime already expressly incorporates cybersecurity, risk-management and business-continuity requirements.
Open banking therefore requires both legal permission and technical security.
Relevant Kuwaiti Case Law
An important qualification is necessary. There is not yet a readily accessible body of six Kuwait Court of Cassation judgments specifically interpreting the CBK's new Open Banking Regulatory Framework. The following are therefore supporting Kuwaiti banking-law authorities, not six direct “open-banking cases.” Their established principles are useful for understanding how courts may approach authorisation, API transactions, contractual responsibility and regulatory compliance.
12. Kuwait Court of Cassation — Commercial Appeal No. 37/2005, 31 January 2006
This reported banking case concerned payment involving a cheque bearing a forged customer signature.
The important principle is the distinction between the appearance of authorisation and genuine customer authority. A banking instruction may look formally valid while still lacking genuine authorisation.
Open-Banking Relevance
The same principle can apply technologically to passwords, electronic signatures, authentication credentials or API payment instructions.
The essential question remains:
Did the customer genuinely authorise the transaction?
Open-banking systems therefore require reliable authentication and evidence of customer authority.
13. Kuwait Court of Cassation — Commercial Appeal No. 424/2001
This reported authority also concerned banking transactions involving allegedly forged customer authority.
The case reinforces the legal distinction between genuine authority and an instruction that merely appears to have been authorised.
Open-Banking Relevance
Suppose an API receives what appears to be a valid payment instruction.
Technical acceptance alone may not necessarily settle every legal issue.
A later dispute could require examination of the customer's authority, authentication records and transaction history.
The principle therefore supports strong digital audit trails.
14. Kuwait Court of Cassation — Commercial Appeal No. 430/2001
This authority has been reported in connection with disputed banking instructions and questions concerning genuine customer authority.
Its significance lies in the professional responsibility associated with banks dealing with customer funds.
Open-Banking Relevance
In an API environment, several participants can become involved:
Customer → FinTech Provider → Bank → Payment Network
The legal system must therefore identify which participant was responsible for authentication, transmission and execution.
Open-banking contracts should clearly allocate those responsibilities.
15. Kuwait Court of Cassation — Commercial Appeal No. 1838/2023, 28 December 2023
This reported dispute involved bank transfers allegedly executed without the signatures required from authorised persons. Questions concerning compliance with banking requirements were also raised.
Open-Banking Relevance
The case demonstrates why reliable evidence of transaction authority matters.
In digital banking, equivalent evidence may include authentication logs, API records, timestamps, electronic mandates and transaction identifiers.
Open banking therefore makes trustworthy electronic recordkeeping particularly important.
16. Kuwait Court of Cassation — Commercial Appeal No. 1809/2023, 28 December 2023
This connected banking dispute also involved contested banking transactions and questions surrounding proper authority.
Open-Banking Relevance
The principle translates naturally to API banking.
Where a transaction is disputed, the parties may need to demonstrate:
who initiated it;
what authority existed;
which system authenticated the person;
what instruction was transmitted; and
whether the bank executed that instruction correctly.
Consequently, API architecture should preserve evidence capable of reconstructing the complete transaction chain.
17. Kuwait Court of Cassation — Appeal No. 508/2016
This banking authority concerned the interaction between contractual banking arrangements and applicable CBK regulatory requirements.
The broader principle is important: private banking contracts operate within mandatory financial regulation.
Open-Banking Relevance
A bank and FinTech company cannot simply use a private API agreement to contract out of mandatory CBK requirements.
Therefore:
Private Open-Banking Contract + Mandatory CBK Regulation = Legal Operating Framework
Where the two conflict, mandatory regulatory requirements may restrict contractual freedom.
18. Liability Allocation
The case law illustrates why liability allocation will become one of the most important open-banking issues.
Consider an unauthorised payment.
Several possible failures exist:
Customer device compromised
↓
FinTech authentication failure
↓
API transmission problem
↓
Bank execution failure
The legal question cannot automatically be answered by saying that “the API failed.”
The precise source of failure must be established.
Contracts and regulatory rules therefore need to define responsibility between banks, service providers and customers while preserving mandatory customer protections.
19. Data Protection and Banking Confidentiality
Open banking creates an apparent tension.
Traditional banking law protects customer information, while open banking deliberately allows information to move outside the customer's original bank.
These concepts are compatible only when sharing occurs through lawful authority and appropriate safeguards.
The basic model becomes:
**Confidential banking information
explicit customer authority
licensed recipient
secure API
limited permitted purpose
= controlled open-banking data sharing**
If any important element is absent, legal and regulatory concerns become much greater.
20. Competition and Innovation
Open banking can reduce technological barriers between customers and financial-service providers.
The CBK has expressly linked its initiative with collaboration between banks and FinTech firms and the development of innovative banking services.
Customers could potentially compare financial products more easily, consolidate information from different institutions or use specialised applications without transferring their primary banking relationship.
This can encourage innovation while maintaining CBK supervision over regulated financial activities.
21. AML and KYC
Open banking does not eliminate anti-money-laundering or customer-identification requirements.
Indeed, interconnected systems may require particularly clear identification of which institution performs which compliance function.
A FinTech provider's participation does not automatically release the regulated bank from obligations imposed upon it.
This is another reason why contracts between banks and open-banking providers must clearly define compliance responsibilities.
22. Dispute Resolution and Evidence
Future open-banking disputes are likely to depend heavily upon digital evidence.
Relevant evidence may include:
API logs;
authentication records;
customer-consent records;
timestamps;
transaction identifiers;
device information;
communications between the bank and provider; and
records showing withdrawal or expiry of authority.
Consequently, open-banking regulation is closely connected with electronic evidence and record-retention requirements.
A reliable system should allow the transaction to be reconstructed from customer consent through final execution.
23. Present Regulatory Position
Kuwait's open-banking regime should therefore be understood as an evolving regulatory structure rather than a completely mature standalone code.
The CBK had already tested open-banking functionality in its sandbox in 2022.
It then announced the Draft Open Banking Regulatory Framework in June 2025, explaining that the project would establish regulatory, technical, security and operational standards. The CBK also stated that final implementation would proceed in phases following adequate testing.
Accordingly, when analysing a particular open-banking transaction, lawyers should consider not merely a document carrying the label “open banking,” but the complete body of applicable banking, electronic-payment, electronic-transactions, cybersecurity, contractual and customer-protection rules.
24. Conclusion
Kuwait is developing a regulatory model in which open banking operates inside the supervised banking system rather than outside it.
The principal regulator is the Central Bank of Kuwait, and the emerging framework is built around licensed service providers, explicit customer approval, secure APIs, electronic-payment regulation, cybersecurity controls and supervised FinTech innovation.
The practical legal structure can be summarised as:
Customer Consent
↓
Licensed Open-Banking Provider
↓
Secure API
↓
Regulated Bank
↓
CBK Supervision
The older Kuwait Court of Cassation authorities remain important because technological change does not eliminate fundamental banking-law questions. Courts will still need to determine whether a customer genuinely authorised a transaction, whether the relevant institution complied with mandatory regulation, whether reliable records exist, and which participant was legally responsible for a failure.
Thus, Kuwait's emerging open-banking framework represents not the replacement of traditional banking law, but its extension into an interconnected digital financial environment.
Case-law note: The six authorities discussed above are supporting Kuwaiti banking cases rather than judgments directly interpreting the 2025 Draft Open Banking Regulatory Framework. Public English-language access to full Kuwaiti judgments is limited, so original Arabic reports should be checked before using case numbers or propositions in formal litigation or academic citation.

comments