Banking Law And Operational Risk Capital Requirements Kuwait .
Banking Law and Operational Risk Capital Requirements in Kuwait
1. Introduction
In Kuwait, operational risk capital requirements form part of the Central Bank of Kuwait (CBK)'s broader prudential framework for protecting banks against losses arising from failures of people, processes, systems, technology, external events and inadequate internal controls.
The framework developed from Kuwait's implementation of Basel II and was subsequently strengthened through Basel III. The CBK adopted Basel II for conventional domestic banks from December 2005 and expressly included capital requirements for operational risk. Kuwait maintained a minimum capital-adequacy ratio of 12%, compared with the Basel minimum of 8% at that time.
The later Basel III framework increased the overall quality and quantity of regulatory capital and introduced additional buffers. CBK's approved framework ultimately established a 13% minimum capital-adequacy ratio for Kuwaiti banks, phased in from 12% in 2014 to 12.5% in 2015 and 13% from 2016.
2. Meaning of Operational Risk
Operational risk generally means the risk of loss resulting from:
- inadequate or failed internal processes;
- people;
- systems; or
- external events.
Examples include:
- employee fraud;
- cyberattacks;
- computer-system failure;
- payment-system interruption;
- documentation errors;
- processing failures;
- accounting errors;
- outsourcing failures;
- legal and compliance failures;
- physical disasters; and
- business-continuity failures.
Operational risk differs from:
| Risk | Principal source |
|---|---|
| Credit risk | Borrower/counterparty default |
| Market risk | Changes in market prices |
| Liquidity risk | Inability to meet obligations |
| Operational risk | Failed processes, people, systems or external events |
3. Statutory Foundation: Central Bank of Kuwait Law
The principal legislative foundation is Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business, as amended.
The CBK has extensive powers concerning the organisation and supervision of banking business. Its banking instructions are therefore an essential component of Kuwait's prudential banking law.
For Islamic banks, Article 97 expressly empowers the CBK Board to establish rules concerning:
- liquidity;
- solvency;
- business organisation;
- capital adequacy; and
- provisions for asset risks.
This is important because operational-risk capital requirements do not operate independently from the CBK's general supervisory powers.
4. Basel II and Operational-Risk Capital
Kuwait was an early adopter of Basel II.
The CBK adopted the Basel II framework for conventional domestic banks effective 31 December 2005. The framework contained the three Basel pillars:
Pillar 1
Minimum capital requirements.
Pillar 2
Supervisory review.
Pillar 3
Market discipline and disclosure.
The CBK specifically stated that Basel II included capital requirements for operational risk, intended to encourage banks to improve the management and monitoring of their operational exposures.
5. Operational Risk under Pillar 1
Under the Basel II approach implemented by Kuwait, operational risk was included in the calculation of risk-weighted exposure.
The CBK's published banking instructions contain a specific section entitled "Operational Risk Weighted Exposure."
The instructions require licensed banks to maintain an operational-risk-management framework and refer to CBK's:
- Guiding Principles on Sound Practices for the Management and Supervision of Operational Risk;
- Internal Control Systems requirements; and
- Risk Management Unit requirements.
Therefore, capital requirements and operational-risk management are legally interconnected.
6. Standardised Approach
Under the Basel II framework historically applied by the CBK, operational-risk capital was calculated under the Standardised Approach.
The CBK instructions expressly describe the relevant section as establishing the quantitative criteria for calculating the operational-risk capital charge under the Basel Committee's Standardised Approach.
Conceptually, the calculation can be represented as:
Operational Risk Capital Charge = Relevant Indicator × Prescribed Beta
The Standardised Approach divides banking activities into business lines and applies specified regulatory coefficients.
The purpose is to translate the bank's operational exposure into a capital requirement.
7. Qualifying Criteria
Operational-risk capital is not merely an accounting calculation.
The CBK requires banks to maintain an appropriate operational-risk-management framework.
The published CBK instructions state that licensed banks must have an operational-risk-management framework and comply with CBK requirements concerning:
- sound operational-risk management;
- internal controls; and
- establishment of a risk-management unit.
This creates an important legal principle:
A bank cannot treat operational-risk capital as a substitute for operational-risk management.
Capital absorbs losses; internal controls seek to prevent or reduce those losses.
8. Additional Capital Consequences for Weak Operational-Risk Management
One of the most important CBK provisions is the supervisory consequence of failing to satisfy the qualifying criteria.
The CBK instructions provide that where the Central Bank determines that a licensed bank no longer satisfies the qualifying requirements, it may require the bank to:
- maintain a higher capital-adequacy ratio; and/or
- comply with additional conditions.
This is a classic Pillar 2 supervisory principle.
Example
Suppose Bank A technically meets the minimum capital ratio.
However, CBK discovers:
- inadequate internal controls;
- repeated operational losses;
- weak IT controls;
- inadequate risk-management personnel;
- poor incident reporting.
The CBK can require additional prudential measures rather than treating the minimum ratio as sufficient.
9. Basel III and Kuwait
Kuwait subsequently implemented Basel III.
In 2014 the CBK approved the final Basel III capital-adequacy instructions for both conventional and Islamic banks. The framework increased regulatory capital requirements and improved the quality of capital, including stronger Common Equity Tier 1 requirements and capital buffers.
The framework also introduced:
- capital conservation buffer;
- countercyclical buffer;
- stricter Tier 2 eligibility;
- elimination of Tier 3 capital;
- additional requirements for D-SIBs;
- leverage requirements; and
- liquidity standards.
10. Operational Risk under the Current Prudential Framework
The modern CBK framework is broader than simply calculating an operational-risk charge.
Current Pillar 1, Pillar 2 and Pillar 3 requirements interact.
A recent Kuwaiti bank's Basel III Pillar 3 disclosure, for example, describes Pillar 1 as covering capital requirements for:
- credit risk;
- operational risk; and
- market risk.
Its Pillar 2 assessment also identifies additional risks such as:
- residual operational risk;
- liquidity risk;
- strategic risk;
- reputation risk;
- legal risk;
- cyber risk; and
- climate risk.
This demonstrates the distinction between quantified operational risk under Pillar 1 and broader risks assessed through ICAAP and supervisory review under Pillar 2.
11. ICAAP and Operational Risk
The Internal Capital Adequacy Assessment Process (ICAAP) is particularly important.
The bank must assess whether its regulatory capital is sufficient considering its actual risk profile.
Operational risk should therefore be assessed through:
- historical operational losses;
- scenario analysis;
- stress testing;
- cyber-risk assessment;
- fraud risk;
- outsourcing risk;
- business-continuity risk;
- legal risk;
- reputational consequences.
A recent Kuwaiti bank's Pillar 3 disclosure expressly identifies ICAAP as part of Pillar 2 and states that banks conduct stress testing based on forward-looking business projections and scenarios.
12. Stress Testing
Stress testing asks:
What happens to the bank's capital if a severe operational event occurs?
Possible scenarios include:
Scenario A – Cyberattack
A ransomware attack disables critical banking systems for several days.
Scenario B – Internal fraud
An employee causes a large financial loss.
Scenario C – Payment-system failure
Payment processing becomes unavailable.
Scenario D – Outsourcing failure
A critical technology provider becomes unavailable.
Scenario E – Combined shock
A cyberattack occurs simultaneously with a liquidity stress.
The bank estimates:
Loss → reduced profit → reduced capital → capital ratio impact.
13. Capital Adequacy Ratio
The broad capital-adequacy formula is:
CAR = Regulatory Capital ÷ Risk-Weighted Assets × 100
Operational risk contributes to the denominator through its relevant risk-weighted exposure.
Therefore:
Higher operational-risk exposure → higher risk-weighted exposure → potentially higher capital requirement.
Conversely:
Effective operational-risk controls → lower expected losses and potentially lower operational-risk exposure.
The CBK publishes capital-adequacy statistics for the Kuwaiti banking system. Its January–March 2026 data show an aggregate capital-adequacy ratio of approximately 19.2% for Kuwaiti banks, materially above the 13% minimum referenced in the CBK Basel III implementation framework.
14. Operational Loss Events
Banks should identify and classify operational losses.
Typical categories include:
| Category | Example |
|---|---|
| Internal fraud | Employee steals customer funds |
| External fraud | Cyberattack |
| Employment practices | Employee-related legal claim |
| Clients/products | Mis-selling or process failure |
| Damage to physical assets | Fire/flood |
| Business disruption | IT outage |
| Execution/process failure | Incorrect transaction |
The objective is to create a reliable loss database and identify recurring weaknesses.
15. Internal Controls
Operational-risk capital requirements are closely linked to internal controls.
A bank should maintain:
- segregation of duties;
- authorisation procedures;
- reconciliation;
- access controls;
- transaction monitoring;
- audit trails;
- cybersecurity;
- independent risk management;
- internal audit;
- business-continuity procedures.
The CBK banking-law framework also gives importance to the auditor's assessment of internal control systems. Under Article 84 of the CBK Law, the auditor's annual report includes an opinion concerning the adequacy of internal controls and provisions.
16. Operational Risk and Islamic Banks
Operational-risk capital requirements are also relevant to Kuwait's Islamic banking sector.
Article 97 of the CBK Law empowers the CBK to establish capital-adequacy standards for Islamic banks.
Islamic banks additionally face particular operational risks involving:
- Shariah-compliance processes;
- investment-account management;
- profit-distribution systems;
- Islamic financing documentation;
- commodity transactions;
- agency arrangements;
- Shariah governance.
Thus, operational risk for an Islamic bank is not limited to technology or employee errors.
17. Operational Losses and Minimum Capital
Article 92 of the CBK Law contains an especially important rule for Islamic banks.
If the capital of an Islamic bank or funds allocated to a foreign Islamic-bank branch falls below the required minimum as a result of operational losses or other reasons, the bank must cover the difference within the period specified by the CBK.
This illustrates a direct legal connection between:
operational loss → capital reduction → regulatory remediation.
18. Operational Risk and D-SIBs
Systemically important banks require stronger safeguards because operational failure can have consequences beyond the individual institution.
Basel III requirements implemented by Kuwait include additional capital requirements for domestically systemically important banks (D-SIBs).
A major operational failure at a D-SIB can potentially affect:
- payment systems;
- depositors;
- other banks;
- financial markets;
- confidence in the banking system.
Consequently, operational resilience has a systemic dimension.
19. Operational Risk and Cyber Risk
Cyber risk has become one of the most significant components of operational risk.
Examples include:
- ransomware;
- malware;
- phishing;
- denial-of-service attacks;
- account takeover;
- insider cyber incidents;
- data breaches;
- payment manipulation.
Although cyber risk is an operational-risk driver, modern CBK supervisory frameworks can also assess cyber risk separately under broader Pillar 2 risk-management processes. A current Kuwaiti bank's Pillar 3 disclosure expressly identifies cyber risk among the risks considered under its broader ICAAP framework.
20. Outsourcing Risk
Banks increasingly outsource:
- cloud computing;
- IT infrastructure;
- payment processing;
- cybersecurity;
- data storage;
- customer-support services.
Outsourcing does not remove the bank's operational responsibility.
A bank therefore needs:
- vendor due diligence;
- contractual controls;
- service-level agreements;
- data-security requirements;
- contingency arrangements;
- monitoring;
- audit rights;
- exit plans.
A major outsourcing failure can become an operational loss and affect capital adequacy.
21. Operational Risk and Corporate Governance
The board and senior management have an important role.
They should ensure:
- adequate risk appetite;
- independent risk management;
- appropriate internal controls;
- adequate capital;
- operational-loss reporting;
- stress testing;
- business continuity;
- cybersecurity;
- regulatory compliance.
Operational-risk capital is therefore part of corporate governance, not simply a finance department calculation.
22. Case Law: Important Qualification
There is an important research limitation with Kuwaiti jurisprudence.
Unlike EU jurisdictions, Kuwait does not have a large publicly accessible English-language body of judgments specifically labelled "operational-risk capital requirements."
Consequently, it would be misleading to claim that particular Kuwaiti cases directly decided whether a bank had calculated a Basel operational-risk capital charge correctly.
The more useful approach is to examine Kuwaiti Court of Cassation principles concerning banking activity, mandatory financial regulation, bank lending and protection of the financial system, and then explain their relevance to operational-risk capital regulation.
The following authorities are therefore best treated as supporting banking-law jurisprudence, rather than cases directly adjudicating a Basel operational-risk calculation.
23. Case 1 — Kuwait Court of Cassation, Appeal No. 1384/2019, Judgment of 22 February 2024
The reported decision concerned bank lending conducted in the ordinary course of banking business.
The Court recognised the specialised commercial character of banking loans.
Principle
Bank lending carried out as part of ordinary banking activity has a distinct commercial/legal character.
Relevance to operational risk
A bank's lending activity generates multiple operational processes:
- credit approval;
- documentation;
- collateral management;
- account administration;
- interest/return calculation;
- repayment monitoring.
Errors in those processes can create operational losses.
Therefore, the legal recognition of banking activity as a specialised professional activity supports the need for specialised controls and risk management.
24. Case 2 — Kuwait Court of Cassation, Commercial Appeal No. 808/2000, Judgment of 16 June 2001
This authority concerned banking lending and obligations arising from professional banking activity.
Principle
Banking transactions must be analysed according to their specialised legal and commercial character.
Operational-risk relevance
The case illustrates why banks require specialised systems for:
- transaction recording;
- contractual compliance;
- calculation of amounts due;
- documentation;
- account administration.
A failure in any of these processes can constitute an operational loss.
25. Case 3 — Kuwait Court of Cassation, Civil Appeal No. 479/2004, Judgment of 19 September 2005
This case concerned a bank current-account relationship and determination of the financial position of the account.
Principle
Accurate determination of banking-account obligations is legally significant.
Operational-risk relevance
It demonstrates the importance of:
- accurate accounting;
- reconciliation;
- transaction records;
- account closure procedures;
- calculation of financial obligations.
These are classic operational-control functions.
26. Case 4 — Kuwait Court of Cassation, Appeal No. 1912/2016, Judgment of 8 April 2018
This reported banking dispute involved credit facilities and issues concerning a restructuring arrangement.
Principle
Banking obligations and restructuring arrangements depend upon the applicable contractual and legal framework.
Operational-risk relevance
Restructuring is an area of elevated operational risk because banks must correctly manage:
- revised documentation;
- approval procedures;
- repayment schedules;
- security;
- accounting treatment;
- authority and signatures.
Failures can create direct financial losses.
27. Case 5 — Kuwait Court of Cassation, Appeal No. 197/2020, Judgment of 24 November 2021
This authority concerned the legal character of loans granted by banks in their ordinary banking activities.
Principle
Bank lending constitutes specialised banking activity and is governed by the relevant commercial and banking rules.
Operational-risk relevance
The decision reinforces the necessity for banks to maintain appropriate procedures around:
- credit approval;
- loan documentation;
- interest/return calculations;
- monitoring;
- recovery.
Operational failures in those areas can translate into financial losses and consequently affect regulatory capital.
28. Case 6 — Kuwait Court of Cassation, Appeal No. 3656/2023, Judgment of 11 June 2024
This authority concerned banking transactions, account closure and financial charges.
Principle
Banking arrangements remain subject to applicable statutory and mandatory requirements and cannot be treated solely as private contractual relationships.
Operational-risk relevance
This is important because operational-risk management operates within mandatory regulatory requirements.
A bank cannot solve a regulatory weakness merely by inserting a contractual clause transferring the risk to a customer.
29. Case 7 — Kuwait Court of Cassation, Appeal No. 14/2022, Judgment of 23 September 2025
Kuwaiti judicial materials concerning mandatory financial regulation demonstrate the Court's recognition that rules protecting the financial/economic order can have public-order significance.
This is particularly relevant where an entity undertakes regulated financial activities without appropriate authorisation.
Operational-risk relevance
It reinforces the proposition that banking regulation is not simply a matter of private contract.
Capital requirements, licensing requirements and supervisory controls serve broader objectives:
- depositor protection;
- financial stability;
- protection of third parties;
- integrity of the banking system.
The Kuwaiti Institute of Judicial and Legal Studies also reports Court of Cassation principles treating prohibitions on unauthorised banking/investment activity as connected with economic public order.
30. Case 8 — Kuwait Court of Cassation, Commercial Appeal No. 33/1981
This authority concerning a bank guarantee is useful for understanding the legal character of banking instruments.
Principle
The legal consequences of a banking instrument depend upon its legal character and contractual terms.
Operational-risk relevance
Correct legal classification is important for banks because a transaction must be correctly identified before its risks can be properly managed.
For example, an institution must distinguish among:
- loan exposure;
- guarantee exposure;
- contingent liability;
- payment obligation.
Incorrect classification can lead to inaccurate risk measurement.
31. Consolidated Case-Law Table
| Case | Main legal issue | Operational-risk relevance |
|---|---|---|
| Appeal 1384/2019, 22-02-2024 | Bank lending | Professional banking controls |
| Commercial Appeal 808/2000, 16-06-2001 | Banking obligations | Transaction/process controls |
| Civil Appeal 479/2004, 19-09-2005 | Current account | Accurate records/reconciliation |
| Appeal 1912/2016, 08-04-2018 | Credit restructuring | Documentation and approval controls |
| Appeal 197/2020, 24-11-2021 | Bank loan | Credit-process controls |
| Appeal 3656/2023, 11-06-2024 | Banking transactions/accounts | Mandatory banking rules |
| Appeal 14/2022, 23-09-2025 | Regulated financial activity | Economic public order |
| Commercial Appeal 33/1981 | Bank guarantee | Correct legal classification |
Important: these cases should not be cited as if the Kuwaiti Court of Cassation directly ruled on the Basel operational-risk capital formula. They are supporting authorities for the banking-law principles surrounding the regulatory framework.
32. Supervisory Approach of CBK
The CBK's approach combines:
Quantitative regulation
Capital must be maintained against identified risks.
Qualitative regulation
Banks must establish effective risk-management and internal-control systems.
Supervisory intervention
CBK can require higher capital or additional conditions where the bank fails relevant qualifying requirements.
Disclosure
Pillar 3 requires public disclosure, improving market discipline.
33. Operational Risk Capital vs Actual Operational Loss
These concepts should not be confused.
Capital charge
A regulatory calculation estimating the capital required to absorb operational risk.
Operational loss
An actual financial loss suffered by the bank.
For example:
A bank may have:
KD 10 million operational-risk capital requirement
but suffer:
KD 2 million actual fraud loss.
The actual loss does not automatically equal the regulatory capital charge.
Instead, the loss can influence:
- profitability;
- capital;
- risk assessments;
- ICAAP;
- supervisory review;
- future risk-management decisions.
34. Relationship with the Three Basel Pillars
Pillar 1 — Minimum Capital
Operational risk is incorporated into the quantitative capital framework.
Pillar 2 — Supervisory Review
CBK assesses whether the bank's actual operational-risk profile is adequately controlled and capitalised.
Pillar 3 — Market Discipline
Banks disclose relevant information about capital and risk management.
Thus:
Operational Risk → Pillar 1 capital → Pillar 2 assessment → Pillar 3 disclosure
35. Current Position of Kuwait's Banking Sector
CBK's latest published financial-soundness data show strong aggregate capitalisation.
For January–March 2026, the aggregate capital-adequacy ratio for Kuwaiti banks was approximately 19.2%, while Tier 1 capital represented approximately 88.7% of the capital base.
For conventional Kuwaiti banks, the reported capital-adequacy ratio was approximately 17.9% in 2021, 17.1% in 2022, 17.8% in 2023, 17.6% in 2024 and 17.2% in 2025.
These figures illustrate the capital buffer maintained by the sector, although aggregate capitalisation does not eliminate the need to manage institution-specific operational risks.
36. Legal Significance of Operational-Risk Capital Requirements
The Kuwait framework serves four principal objectives:
1. Loss absorption
Capital provides a buffer against operational losses.
2. Incentive for risk management
Banks must maintain appropriate operational-risk systems.
3. Supervisory protection
CBK can intervene when risk-management standards are inadequate.
4. Financial stability
Strong capital and operational controls reduce the probability that an operational failure will threaten the wider banking system.
37. Conclusion
Kuwait's banking law treats operational risk as an important component of prudential regulation rather than merely an internal-management issue.
The framework developed through Basel II, which introduced explicit operational-risk capital requirements, and was subsequently strengthened through Basel III, including stronger regulatory capital, capital buffers and enhanced supervisory requirements.
The CBK framework requires banks to combine:
Operational-risk management + internal controls + risk-management functions + capital + ICAAP + stress testing + supervisory review.
Particularly important is the CBK's power to require higher capital adequacy or additional conditions where a bank does not satisfy operational-risk-management qualifying criteria.
For Islamic banks, the legal framework additionally provides that capital falling below the required minimum because of operational losses must be restored within the period specified by the CBK.
The Kuwaiti Court of Cassation cases discussed above do not constitute a separate body of jurisprudence directly interpreting Basel's operational-risk formula. Their importance is instead in establishing the surrounding legal principles: banking is a specialised regulated activity; mandatory financial regulation protects the economic order; banking records and obligations must be accurately administered; and private contractual arrangements operate within the mandatory banking framework.
Accordingly, the Kuwaiti legal model can be summarised as:
Operational Risk → Regulatory Measurement → Capital Requirement → ICAAP/Stress Testing → CBK Supervisory Review → Additional Capital Where Necessary → Protection of Banking-System Stability.

comments