Banking Law And Embedded Finance Models Kuwait .

Banking Law and Embedded Finance Models in Kuwait

Introduction

Embedded finance refers to the integration of financial services into non-bank digital platforms, applications and commercial ecosystems. Instead of requiring a customer to visit a bank separately, financial functionality may be incorporated directly into an e-commerce platform, mobile application, payroll system, marketplace or other digital service.

Examples include embedded payments, digital wallets, Buy Now Pay Later arrangements, payment gateways, account-information services and financing offered during an online purchase.

Kuwait does not presently regulate all embedded-finance arrangements under a single law titled “Embedded Finance Law.” The applicable framework instead consists of the Central Bank of Kuwait Law, Electronic Transactions Law, AML/CFT legislation, CBK electronic-payment instructions, banking outsourcing and technology controls, consumer-protection requirements and contractual law.

The critical legal question is whether the embedded service constitutes a regulated banking, payment, e-money or credit activity and which licensed entity remains responsible to the customer.

Central Bank of Kuwait Regulatory Framework

The Central Bank of Kuwait supervises banking and relevant financial activities under Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business.

A technology platform cannot avoid banking regulation merely by presenting regulated financial services through an application belonging to a retailer or other non-bank business.

Where the underlying activity amounts to deposit-taking, lending, payment services or another regulated activity, the appropriate authorization and regulatory structure must exist.

Embedded-finance models in Kuwait therefore commonly rely upon cooperation between:

licensed banks;

financing companies;

electronic-payment service providers;

electronic-money providers;

technology companies; and

commercial platforms.

The allocation of functions between these participants should be clearly documented.

Electronic Payment Framework

Law No. 20 of 2014 concerning Electronic Transactions provides an important statutory basis for electronic payments.

The CBK subsequently established regulatory requirements for electronic-payment activities and substantially updated those requirements in 2023.

The framework recognizes different categories of regulated payment activity and establishes requirements relating to:

Corporate governance, ensuring appropriate management oversight.

Risk management, requiring institutions to identify and control operational and financial risks.

AML/CFT, requiring customer identification and transaction-monitoring arrangements.

Cybersecurity, protecting payment infrastructure and customer information.

Business continuity, ensuring that important services can continue following technological disruption.

Customer protection, ensuring appropriate treatment of users.

These requirements are fundamental where payment functionality is embedded inside a third-party platform.

Embedded Payment Model

Embedded payments allow customers to complete transactions without moving separately to a traditional banking interface.

For example, an online marketplace may integrate a regulated payment provider so that customers can pay within the marketplace application.

The merchant platform may control the customer experience, but the regulated payment institution remains responsible for complying with applicable financial requirements within the scope of its regulated activities.

Contracts should therefore clearly determine:

which entity processes the payment;

which entity holds customer funds;

which party authenticates customers;

responsibility for payment errors;

chargebacks and refunds;

data processing responsibilities; and

complaint handling.

Embedded E-Money and Digital Wallets

Electronic money represents another important embedded-finance structure.

A digital platform may incorporate wallet functionality operated by a properly authorized provider.

The legal structure becomes particularly important where customers maintain stored value rather than simply initiating individual card payments.

Customer funds, operational funds and settlement arrangements must be handled consistently with applicable CBK requirements.

A commercial platform should not create the impression that it independently provides regulated e-money services where the service is actually supplied by another licensed entity.

Embedded Lending

Embedded lending allows financing to be offered directly during a commercial transaction.

A customer purchasing goods or services may be offered credit at checkout without separately visiting a financial institution.

However, technological convenience does not remove the underlying regulatory character of lending.

Where a bank or financing company provides the credit, it remains subject to applicable lending, customer-protection, creditworthiness and disclosure requirements.

Particular attention should be paid to the distinction between the platform acting as a technology intermediary and the regulated institution actually extending credit.

Buy Now Pay Later

BNPL is one of the clearest contemporary examples of embedded finance.

The CBK's updated electronic-payment framework brought BNPL services within its supervisory and regulatory environment.

A BNPL model generally permits a consumer to obtain goods immediately while paying the price through deferred instalments.

Legal concerns include:

affordability assessment;

transparent disclosure;

late-payment treatment;

consumer complaints;

data protection;

credit concentration; and

prevention of excessive consumer indebtedness.

BNPL should therefore not be viewed merely as an e-commerce feature. It may constitute regulated financial activity.

Open Banking and APIs

Open banking can become an important infrastructure layer for embedded finance.

Application Programming Interfaces, or APIs, may allow appropriately controlled third-party services to interact with banking systems.

This can support account aggregation, financial-management applications and payment initiation.

The CBK has permitted open-banking models to be tested through its financial-technology regulatory environment.

Open banking nevertheless creates important questions concerning customer consent, authentication, cybersecurity and allocation of liability.

A customer's consent to share information should be meaningful and sufficiently specific.

Regulatory Sandbox

The CBK's Wolooj Innovation Hub and Regulatory Sandbox provide a controlled environment for testing qualifying financial technology.

The framework can cover technologies and models associated with electronic payments, regulatory compliance, cybersecurity, open banking, artificial intelligence and other financial innovation.

Embedded-finance providers may therefore use sandbox mechanisms where an innovative model requires regulatory testing before full deployment.

Participation in a sandbox does not mean permanent exemption from banking law. The purpose is supervised experimentation while regulatory requirements and risks are evaluated.

AML and KYC Obligations

Embedded finance may make financial services almost invisible within a customer's digital journey, but AML/KYC obligations remain applicable.

Under Law No. 106 of 2013 concerning Anti-Money Laundering and Combating the Financing of Terrorism, regulated financial institutions must conduct appropriate customer due diligence.

Depending upon the service, this includes:

identifying the customer;

verifying identity;

identifying beneficial owners;

understanding the business relationship;

conducting sanctions screening; and

monitoring transactions.

A bank cannot simply assume that a commercial platform has completed adequate KYC unless the arrangement legally permits reliance and all applicable requirements have been satisfied.

Outsourcing and Third-Party Risk

Embedded finance frequently depends upon technology companies.

A fintech may provide interfaces, customer onboarding, data analytics, API technology or payment-processing infrastructure.

Nevertheless, outsourcing technical functions does not automatically transfer regulatory responsibility away from the licensed institution.

Banks should conduct appropriate due diligence before appointing important service providers.

Contracts should address:

cybersecurity;

confidentiality;

service availability;

audit rights;

access to information;

incident reporting;

subcontracting;

business continuity; and

termination.

The institution should remain capable of supervising outsourced activities.

Case Laws

Because embedded finance is comparatively new, published Kuwaiti Court of Cassation jurisprudence specifically using the expression “embedded finance” remains limited. Established banking cases nevertheless provide important principles governing authentication, payment authorization, allocation of loss and intermediary responsibility.

1. Kuwait Court of Cassation, Commercial Appeal No. 37/2005, 31 January 2006

The Court considered payment of a cheque carrying a forged customer's signature.

It held that the bank generally bears the consequences of paying an instrument containing a forged drawer signature, even where the forgery was professionally executed, unless legally relevant fault by the customer affects the allocation of loss.

This principle is important for embedded payments because the regulated financial institution must maintain reliable authentication mechanisms.

A technology interface does not eliminate responsibility for determining whether a transaction has genuinely been authorized.

2. Kuwait Court of Cassation, Commercial Appeal No. 424/2001

The Court considered banking transactions based upon forged customer authority.

It confirmed the fundamental distinction between genuine authorization and an instrument that merely appears to have been authorized.

For embedded finance, the same principle applies when authorization occurs through mobile credentials, APIs or other digital systems.

A bank should be able to demonstrate that the transaction originated from an authenticated and authorized customer.

3. Kuwait Court of Cassation, Commercial Appeal No. 430/2001

This connected banking authority also addressed forged payment instructions and responsibility for unauthorized transactions.

The judgment reinforces the professional responsibility of banks for protecting customer funds against transactions lacking genuine authority.

Embedded-finance arrangements should therefore establish precise responsibility between the customer-facing platform, payment processor and bank for transaction authentication.

4. Kuwait Court of Cassation, Commercial Appeal No. 1838/2023, 28 December 2023

This dispute involved allegations concerning six bank transfers said to have been executed without the required signatures of authorized persons.

The parties also raised questions regarding compliance with Central Bank requirements.

The case is highly relevant to modern embedded-finance systems because digital platforms must preserve reliable evidence showing who possessed authority to approve a financial transaction.

The use of API infrastructure cannot replace proper authorization controls.

5. Kuwait Court of Cassation, Commercial Appeal No. 1809/2023, 28 December 2023

The connected appeal also involved disputed bank transfers and allegations concerning lack of proper authorization.

The dispute demonstrates the importance of transaction records, account mandates and authentication evidence.

Embedded-finance platforms should therefore preserve audit trails capable of identifying the customer, device or authorized representative responsible for initiating a transaction.

6. Kuwait Court of Cassation – Forgery of Bank Documents and Transfer Orders

In a significant criminal banking decision, the Court considered forged cheques and transfer orders submitted to a Kuwaiti bank.

The Court emphasized that the legal effectiveness of a payment instruction depends upon the genuine signature or valid authority of the person entitled to operate the account.

The principle has direct modern relevance. Digital financial platforms must establish that electronic instructions genuinely originate from authorized users rather than merely accepting technically valid-looking credentials.

7. Kuwait Court of Cassation, Commercial Appeal No. 4004/2019, 11 January 2021

Although concerned with a bank guarantee rather than embedded finance, this judgment illustrates an important banking-law principle.

The Court treated the bank's undertaking under a guarantee according to its own contractual terms and distinguished it from the underlying commercial relationship.

The case is relevant to multi-party embedded-finance structures because legal responsibility depends upon identifying the separate contractual obligations undertaken by each participant.

A platform agreement cannot automatically alter the obligations that a licensed institution owes under its own banking contract.

Consumer Protection

Customers using embedded finance may believe that the non-bank application itself provides the financial service.

This creates a significant transparency problem.

The customer should be able to understand:

who actually provides the financial product;

whether the provider is regulated;

the applicable fees;

financing costs;

repayment requirements;

refund procedures;

complaint channels; and

responsibility for unauthorized transactions.

Interface design should not conceal material financial terms.

Data Governance

Embedded finance requires substantial movement of customer data between banks, fintech companies and commercial platforms.

Information-sharing arrangements should therefore provide appropriate safeguards regarding confidentiality, cybersecurity and customer consent.

Only information necessary for legitimate purposes should be available to participants.

API credentials and customer authentication information must receive particularly strong protection because compromise could permit unauthorized transactions.

Allocation of Liability

One of the most difficult issues in embedded finance is deciding who is responsible when something goes wrong.

A transaction may involve a merchant, technology platform, fintech intermediary, payment processor and bank.

Contracts should allocate responsibility for operational incidents between those parties.

However, private contracts cannot necessarily eliminate regulatory obligations owed by licensed institutions.

Where banking regulation makes the licensed bank responsible for a particular function, the bank ordinarily remains accountable to the regulator even if a technology provider performs the operational task.

Conclusion

Embedded finance in Kuwait is developing through the interaction of traditional banking, electronic payments, e-money, BNPL, fintech partnerships and open-banking technology.

Law No. 32 of 1968 establishes the fundamental banking supervisory framework, while Law No. 20 of 2014 and the CBK electronic-payment instructions regulate important parts of digital payment infrastructure. AML obligations under Law No. 106 of 2013 remain applicable even where financial services are embedded within non-bank applications.

Kuwaiti Court of Cassation jurisprudence concerning forged payment instruments, unauthorized transfers, customer authentication and independent banking obligations supplies important principles for emerging models. The central lesson is that technological integration does not eliminate legal responsibility.

A sustainable Kuwaiti embedded-finance model therefore requires proper licensing, clearly defined contractual roles, reliable customer authentication, AML/KYC controls, cybersecurity, transparent consumer disclosures, effective third-party oversight, strong audit trails and clear allocation of operational liability.

LEAVE A COMMENT