Banking Law And Critical Technology Infrastructure Supervision Kuwait .
Banking Law and Critical Technology Infrastructure Supervision in Kuwait
Introduction
Critical technology infrastructure in banking includes core-banking systems, payment gateways, ATM and card networks, mobile-banking applications, cloud platforms, identity and authentication tools, data centres, SWIFT connectivity, and cyber-security operations. If one of these systems fails or is compromised, the result may be payment disruption, theft, loss of confidential data, and wider loss of confidence in Kuwait’s financial system.
In Kuwait, supervision is not based on one single “critical technology infrastructure” statute. It is a combined framework led principally by the Central Bank of Kuwait (CBK), supported by the Communications and Information Technology Regulatory Authority (CITRA), the Electronic Transactions Law, and cybercrime legislation.
Legal and Regulatory Framework
The foundational banking statute is Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business. It gives the CBK supervisory authority over banks and enables it to issue prudential and operational instructions. This authority extends beyond capital and liquidity: a bank cannot safely conduct regulated banking business if its technology, payment operations, outsourcing arrangements, or cyber controls are unsafe.
The CBK therefore supervises critical banking technology through its instructions to licensed banks, finance companies, payment-service providers, and fintech participants. In practice, the CBK expects institutions to maintain:
- Board-level accountability for technology and cyber risk;
- Clear IT governance, risk assessments, and internal audit;
- Segregation of duties and access controls;
- Secure authentication for digital banking and payments;
- Fraud monitoring and incident response;
- Business-continuity and disaster-recovery capability;
- Vendor, cloud, and outsourcing oversight; and
- Timely reporting of material incidents to the regulator.
The legal standard is not simply “install cyber-security software.” A bank must show that its controls are proportionate to the criticality of the service. A system supporting retail payments, customer authentication, or the bank’s core ledger requires stronger resilience, testing, backup, monitoring, and recovery arrangements than an ordinary internal application.
Law No. 20 of 2014 concerning Electronic Transactions gives legal effect to electronic records, electronic signatures, and electronic contracting. This is vital to online banking because a customer’s digital instruction may be legally valid even without a handwritten signature. However, legal validity depends on reliability: the bank should be able to demonstrate the integrity of the record, the identity/authentication method used, and an adequate audit trail. Kuwait’s Ministry of Justice recognises that the Court of Cassation maintains and publishes judgments and technical materials, although many decisions are not readily available in English.
Law No. 63 of 2015 on Combating Information Technology Crimes criminalises unlawful access, interception, data manipulation, and other misuse of information systems. For banks, it is both a criminal-enforcement tool and a compliance risk: a cyberattack may create obligations to preserve evidence, cooperate with investigators, secure customer data, and restore affected systems. The law remains a central part of Kuwait’s cybercrime framework.
CITRA, established under Law No. 37 of 2014, also matters because banks rely on telecommunications networks, cloud connectivity, SMS alerts, mobile channels, and internet service providers. The CBK supervises the financial institution; CITRA regulates important communications and technology infrastructure around it. This means a major outage or breach can involve overlapping regulatory attention.
Supervisory Focus Areas
A bank’s board remains ultimately responsible. It may delegate operations to a chief information officer, cyber-security team, or cloud provider, but it cannot delegate accountability. The board should approve risk appetite, identify critical services, receive incident reporting, and ensure independent testing.
Outsourcing is especially important. If a bank uses a foreign cloud provider, fintech vendor, managed-security provider, or software-as-a-service platform, it should conduct due diligence before contracting. The agreement should cover data confidentiality, audit rights, security standards, service availability, subcontracting controls, incident notification, data return, and an exit plan. A cloud contract that prevents the bank or CBK from reviewing relevant records creates a serious supervisory weakness.
Operational resilience is equally important. Banks should identify the maximum tolerable downtime for each critical service, test disaster recovery, maintain segregated backups, and conduct realistic cyber-incident exercises. Recovery is not complete merely because systems are switched back on; the bank must verify data integrity, reconcile transactions, and communicate accurately with customers and the CBK.
Case Law
Published Kuwait technology-banking decisions are limited, particularly in English. Still, the following authorities illustrate the relevant principles.
Kuwait Court of Cassation, KCC 1229/2017. This case concerned forged bank statements and a cheque dispute. Its importance is evidential: banking records are powerful evidence, but they are not immune from allegations of forgery, theft, or unauthorised use. In modern digital banking, secure system logs, authentication records, access histories, and transaction trails are therefore essential.
Kuwait Court of Cassation, Appeal No. 1838/2023. Reported commentary describes a dispute involving alleged forged banking transfers and whether authorised signatures and bank procedures were properly established. The lesson is that a bank facing a disputed digital instruction must prove its control environment and authority-verification process, rather than merely rely on the existence of a transfer entry. This reported case should be checked against the official Arabic judgment before being relied upon in litigation.
Electronic fraud and criminal proceeds cases. Kuwait’s criminal courts have treated the use of proceeds known to arise from electronic fraud as a separate and serious offence. This supports a bank’s duty to monitor suspicious digital transactions, preserve evidence, and escalate suspected mule-account activity.
CPD Middle East LLC v United Arab Bank PJSC. Although not a technology case, the Kuwait Court of Cassation’s rejection of the final cassation appeal in 2024 demonstrates the court’s role in enforcing banking obligations and guarantees according to the evidential record. It reinforces the practical importance of clear records, authority controls, and defensible documentation in bank disputes.
Conclusion
Kuwait’s approach is regulator-led rather than contained in a single critical-infrastructure law. The CBK is the central supervisor for banking technology risk; CITRA regulates surrounding communications infrastructure; the Electronic Transactions Law supports the validity and proof of digital banking activity; and the Cybercrime Law addresses unlawful attacks and data misuse.
For a Kuwaiti bank, compliance means being able to prove four things: its critical systems are identified, its controls are effective, its vendors are supervised, and it can continue or recover essential services without compromising customers or the financial system.

comments