Banking Law And Operational Risk Capital Requirements Kuwait .

Banking Law and Operational Risk Capital Requirements in Kuwait

1. Introduction

In Kuwait, operational risk capital requirements form part of the Central Bank of Kuwait (CBK)'s broader prudential framework for protecting banks against losses arising from failures of people, processes, systems, technology, external events and inadequate internal controls.

The framework developed from Kuwait's implementation of Basel II and was subsequently strengthened through Basel III. The CBK adopted Basel II for conventional domestic banks from December 2005 and expressly included capital requirements for operational risk. Kuwait maintained a minimum capital-adequacy ratio of 12%, compared with the Basel minimum of 8% at that time.

The later Basel III framework increased the overall quality and quantity of regulatory capital and introduced additional buffers. CBK's approved framework ultimately established a 13% minimum capital-adequacy ratio for Kuwaiti banks, phased in from 12% in 2014 to 12.5% in 2015 and 13% from 2016.

2. Meaning of Operational Risk

Operational risk generally means the risk of loss resulting from:

  • inadequate or failed internal processes;
  • people;
  • systems; or
  • external events.

Examples include:

  • employee fraud;
  • cyberattacks;
  • computer-system failure;
  • payment-system interruption;
  • documentation errors;
  • processing failures;
  • accounting errors;
  • outsourcing failures;
  • legal and compliance failures;
  • physical disasters; and
  • business-continuity failures.

Operational risk differs from:

RiskPrincipal source
Credit riskBorrower/counterparty default
Market riskChanges in market prices
Liquidity riskInability to meet obligations
Operational riskFailed processes, people, systems or external events

3. Statutory Foundation: Central Bank of Kuwait Law

The principal legislative foundation is Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business, as amended.

The CBK has extensive powers concerning the organisation and supervision of banking business. Its banking instructions are therefore an essential component of Kuwait's prudential banking law.

For Islamic banks, Article 97 expressly empowers the CBK Board to establish rules concerning:

  • liquidity;
  • solvency;
  • business organisation;
  • capital adequacy; and
  • provisions for asset risks. 

This is important because operational-risk capital requirements do not operate independently from the CBK's general supervisory powers.

4. Basel II and Operational-Risk Capital

Kuwait was an early adopter of Basel II.

The CBK adopted the Basel II framework for conventional domestic banks effective 31 December 2005. The framework contained the three Basel pillars:

Pillar 1

Minimum capital requirements.

Pillar 2

Supervisory review.

Pillar 3

Market discipline and disclosure.

The CBK specifically stated that Basel II included capital requirements for operational risk, intended to encourage banks to improve the management and monitoring of their operational exposures.

5. Operational Risk under Pillar 1

Under the Basel II approach implemented by Kuwait, operational risk was included in the calculation of risk-weighted exposure.

The CBK's published banking instructions contain a specific section entitled "Operational Risk Weighted Exposure."

The instructions require licensed banks to maintain an operational-risk-management framework and refer to CBK's:

  • Guiding Principles on Sound Practices for the Management and Supervision of Operational Risk;
  • Internal Control Systems requirements; and
  • Risk Management Unit requirements. 

Therefore, capital requirements and operational-risk management are legally interconnected.

6. Standardised Approach

Under the Basel II framework historically applied by the CBK, operational-risk capital was calculated under the Standardised Approach.

The CBK instructions expressly describe the relevant section as establishing the quantitative criteria for calculating the operational-risk capital charge under the Basel Committee's Standardised Approach.

Conceptually, the calculation can be represented as:

Operational Risk Capital Charge = Relevant Indicator × Prescribed Beta

The Standardised Approach divides banking activities into business lines and applies specified regulatory coefficients.

The purpose is to translate the bank's operational exposure into a capital requirement.

7. Qualifying Criteria

Operational-risk capital is not merely an accounting calculation.

The CBK requires banks to maintain an appropriate operational-risk-management framework.

The published CBK instructions state that licensed banks must have an operational-risk-management framework and comply with CBK requirements concerning:

  1. sound operational-risk management;
  2. internal controls; and
  3. establishment of a risk-management unit. 

This creates an important legal principle:

A bank cannot treat operational-risk capital as a substitute for operational-risk management.

Capital absorbs losses; internal controls seek to prevent or reduce those losses.

8. Additional Capital Consequences for Weak Operational-Risk Management

One of the most important CBK provisions is the supervisory consequence of failing to satisfy the qualifying criteria.

The CBK instructions provide that where the Central Bank determines that a licensed bank no longer satisfies the qualifying requirements, it may require the bank to:

  • maintain a higher capital-adequacy ratio; and/or
  • comply with additional conditions. 

This is a classic Pillar 2 supervisory principle.

Example

Suppose Bank A technically meets the minimum capital ratio.

However, CBK discovers:

  • inadequate internal controls;
  • repeated operational losses;
  • weak IT controls;
  • inadequate risk-management personnel;
  • poor incident reporting.

The CBK can require additional prudential measures rather than treating the minimum ratio as sufficient.

9. Basel III and Kuwait

Kuwait subsequently implemented Basel III.

In 2014 the CBK approved the final Basel III capital-adequacy instructions for both conventional and Islamic banks. The framework increased regulatory capital requirements and improved the quality of capital, including stronger Common Equity Tier 1 requirements and capital buffers.

The framework also introduced:

  • capital conservation buffer;
  • countercyclical buffer;
  • stricter Tier 2 eligibility;
  • elimination of Tier 3 capital;
  • additional requirements for D-SIBs;
  • leverage requirements; and
  • liquidity standards. 

10. Operational Risk under the Current Prudential Framework

The modern CBK framework is broader than simply calculating an operational-risk charge.

Current Pillar 1, Pillar 2 and Pillar 3 requirements interact.

A recent Kuwaiti bank's Basel III Pillar 3 disclosure, for example, describes Pillar 1 as covering capital requirements for:

  • credit risk;
  • operational risk; and
  • market risk.

Its Pillar 2 assessment also identifies additional risks such as:

  • residual operational risk;
  • liquidity risk;
  • strategic risk;
  • reputation risk;
  • legal risk;
  • cyber risk; and
  • climate risk. 

This demonstrates the distinction between quantified operational risk under Pillar 1 and broader risks assessed through ICAAP and supervisory review under Pillar 2.

11. ICAAP and Operational Risk

The Internal Capital Adequacy Assessment Process (ICAAP) is particularly important.

The bank must assess whether its regulatory capital is sufficient considering its actual risk profile.

Operational risk should therefore be assessed through:

  • historical operational losses;
  • scenario analysis;
  • stress testing;
  • cyber-risk assessment;
  • fraud risk;
  • outsourcing risk;
  • business-continuity risk;
  • legal risk;
  • reputational consequences.

A recent Kuwaiti bank's Pillar 3 disclosure expressly identifies ICAAP as part of Pillar 2 and states that banks conduct stress testing based on forward-looking business projections and scenarios.

12. Stress Testing

Stress testing asks:

What happens to the bank's capital if a severe operational event occurs?

Possible scenarios include:

Scenario A – Cyberattack

A ransomware attack disables critical banking systems for several days.

Scenario B – Internal fraud

An employee causes a large financial loss.

Scenario C – Payment-system failure

Payment processing becomes unavailable.

Scenario D – Outsourcing failure

A critical technology provider becomes unavailable.

Scenario E – Combined shock

A cyberattack occurs simultaneously with a liquidity stress.

The bank estimates:

Loss → reduced profit → reduced capital → capital ratio impact.

13. Capital Adequacy Ratio

The broad capital-adequacy formula is:

CAR = Regulatory Capital ÷ Risk-Weighted Assets × 100

Operational risk contributes to the denominator through its relevant risk-weighted exposure.

Therefore:

Higher operational-risk exposure → higher risk-weighted exposure → potentially higher capital requirement.

Conversely:

Effective operational-risk controls → lower expected losses and potentially lower operational-risk exposure.

The CBK publishes capital-adequacy statistics for the Kuwaiti banking system. Its January–March 2026 data show an aggregate capital-adequacy ratio of approximately 19.2% for Kuwaiti banks, materially above the 13% minimum referenced in the CBK Basel III implementation framework.

14. Operational Loss Events

Banks should identify and classify operational losses.

Typical categories include:

CategoryExample
Internal fraudEmployee steals customer funds
External fraudCyberattack
Employment practicesEmployee-related legal claim
Clients/productsMis-selling or process failure
Damage to physical assetsFire/flood
Business disruptionIT outage
Execution/process failureIncorrect transaction

The objective is to create a reliable loss database and identify recurring weaknesses.

15. Internal Controls

Operational-risk capital requirements are closely linked to internal controls.

A bank should maintain:

  • segregation of duties;
  • authorisation procedures;
  • reconciliation;
  • access controls;
  • transaction monitoring;
  • audit trails;
  • cybersecurity;
  • independent risk management;
  • internal audit;
  • business-continuity procedures.

The CBK banking-law framework also gives importance to the auditor's assessment of internal control systems. Under Article 84 of the CBK Law, the auditor's annual report includes an opinion concerning the adequacy of internal controls and provisions.

16. Operational Risk and Islamic Banks

Operational-risk capital requirements are also relevant to Kuwait's Islamic banking sector.

Article 97 of the CBK Law empowers the CBK to establish capital-adequacy standards for Islamic banks.

Islamic banks additionally face particular operational risks involving:

  • Shariah-compliance processes;
  • investment-account management;
  • profit-distribution systems;
  • Islamic financing documentation;
  • commodity transactions;
  • agency arrangements;
  • Shariah governance.

Thus, operational risk for an Islamic bank is not limited to technology or employee errors.

17. Operational Losses and Minimum Capital

Article 92 of the CBK Law contains an especially important rule for Islamic banks.

If the capital of an Islamic bank or funds allocated to a foreign Islamic-bank branch falls below the required minimum as a result of operational losses or other reasons, the bank must cover the difference within the period specified by the CBK.

This illustrates a direct legal connection between:

operational loss → capital reduction → regulatory remediation.

18. Operational Risk and D-SIBs

Systemically important banks require stronger safeguards because operational failure can have consequences beyond the individual institution.

Basel III requirements implemented by Kuwait include additional capital requirements for domestically systemically important banks (D-SIBs).

A major operational failure at a D-SIB can potentially affect:

  • payment systems;
  • depositors;
  • other banks;
  • financial markets;
  • confidence in the banking system.

Consequently, operational resilience has a systemic dimension.

19. Operational Risk and Cyber Risk

Cyber risk has become one of the most significant components of operational risk.

Examples include:

  • ransomware;
  • malware;
  • phishing;
  • denial-of-service attacks;
  • account takeover;
  • insider cyber incidents;
  • data breaches;
  • payment manipulation.

Although cyber risk is an operational-risk driver, modern CBK supervisory frameworks can also assess cyber risk separately under broader Pillar 2 risk-management processes. A current Kuwaiti bank's Pillar 3 disclosure expressly identifies cyber risk among the risks considered under its broader ICAAP framework.

20. Outsourcing Risk

Banks increasingly outsource:

  • cloud computing;
  • IT infrastructure;
  • payment processing;
  • cybersecurity;
  • data storage;
  • customer-support services.

Outsourcing does not remove the bank's operational responsibility.

A bank therefore needs:

  • vendor due diligence;
  • contractual controls;
  • service-level agreements;
  • data-security requirements;
  • contingency arrangements;
  • monitoring;
  • audit rights;
  • exit plans.

A major outsourcing failure can become an operational loss and affect capital adequacy.

21. Operational Risk and Corporate Governance

The board and senior management have an important role.

They should ensure:

  1. adequate risk appetite;
  2. independent risk management;
  3. appropriate internal controls;
  4. adequate capital;
  5. operational-loss reporting;
  6. stress testing;
  7. business continuity;
  8. cybersecurity;
  9. regulatory compliance.

Operational-risk capital is therefore part of corporate governance, not simply a finance department calculation.

22. Case Law: Important Qualification

There is an important research limitation with Kuwaiti jurisprudence.

Unlike EU jurisdictions, Kuwait does not have a large publicly accessible English-language body of judgments specifically labelled "operational-risk capital requirements."

Consequently, it would be misleading to claim that particular Kuwaiti cases directly decided whether a bank had calculated a Basel operational-risk capital charge correctly.

The more useful approach is to examine Kuwaiti Court of Cassation principles concerning banking activity, mandatory financial regulation, bank lending and protection of the financial system, and then explain their relevance to operational-risk capital regulation.

The following authorities are therefore best treated as supporting banking-law jurisprudence, rather than cases directly adjudicating a Basel operational-risk calculation.

23. Case 1 — Kuwait Court of Cassation, Appeal No. 1384/2019, Judgment of 22 February 2024

The reported decision concerned bank lending conducted in the ordinary course of banking business.

The Court recognised the specialised commercial character of banking loans.

Principle

Bank lending carried out as part of ordinary banking activity has a distinct commercial/legal character.

Relevance to operational risk

A bank's lending activity generates multiple operational processes:

  • credit approval;
  • documentation;
  • collateral management;
  • account administration;
  • interest/return calculation;
  • repayment monitoring.

Errors in those processes can create operational losses.

Therefore, the legal recognition of banking activity as a specialised professional activity supports the need for specialised controls and risk management.

24. Case 2 — Kuwait Court of Cassation, Commercial Appeal No. 808/2000, Judgment of 16 June 2001

This authority concerned banking lending and obligations arising from professional banking activity.

Principle

Banking transactions must be analysed according to their specialised legal and commercial character.

Operational-risk relevance

The case illustrates why banks require specialised systems for:

  • transaction recording;
  • contractual compliance;
  • calculation of amounts due;
  • documentation;
  • account administration.

A failure in any of these processes can constitute an operational loss.

25. Case 3 — Kuwait Court of Cassation, Civil Appeal No. 479/2004, Judgment of 19 September 2005

This case concerned a bank current-account relationship and determination of the financial position of the account.

Principle

Accurate determination of banking-account obligations is legally significant.

Operational-risk relevance

It demonstrates the importance of:

  • accurate accounting;
  • reconciliation;
  • transaction records;
  • account closure procedures;
  • calculation of financial obligations.

These are classic operational-control functions.

26. Case 4 — Kuwait Court of Cassation, Appeal No. 1912/2016, Judgment of 8 April 2018

This reported banking dispute involved credit facilities and issues concerning a restructuring arrangement.

Principle

Banking obligations and restructuring arrangements depend upon the applicable contractual and legal framework.

Operational-risk relevance

Restructuring is an area of elevated operational risk because banks must correctly manage:

  • revised documentation;
  • approval procedures;
  • repayment schedules;
  • security;
  • accounting treatment;
  • authority and signatures.

Failures can create direct financial losses.

27. Case 5 — Kuwait Court of Cassation, Appeal No. 197/2020, Judgment of 24 November 2021

This authority concerned the legal character of loans granted by banks in their ordinary banking activities.

Principle

Bank lending constitutes specialised banking activity and is governed by the relevant commercial and banking rules.

Operational-risk relevance

The decision reinforces the necessity for banks to maintain appropriate procedures around:

  • credit approval;
  • loan documentation;
  • interest/return calculations;
  • monitoring;
  • recovery.

Operational failures in those areas can translate into financial losses and consequently affect regulatory capital.

28. Case 6 — Kuwait Court of Cassation, Appeal No. 3656/2023, Judgment of 11 June 2024

This authority concerned banking transactions, account closure and financial charges.

Principle

Banking arrangements remain subject to applicable statutory and mandatory requirements and cannot be treated solely as private contractual relationships.

Operational-risk relevance

This is important because operational-risk management operates within mandatory regulatory requirements.

A bank cannot solve a regulatory weakness merely by inserting a contractual clause transferring the risk to a customer.

29. Case 7 — Kuwait Court of Cassation, Appeal No. 14/2022, Judgment of 23 September 2025

Kuwaiti judicial materials concerning mandatory financial regulation demonstrate the Court's recognition that rules protecting the financial/economic order can have public-order significance.

This is particularly relevant where an entity undertakes regulated financial activities without appropriate authorisation.

Operational-risk relevance

It reinforces the proposition that banking regulation is not simply a matter of private contract.

Capital requirements, licensing requirements and supervisory controls serve broader objectives:

  • depositor protection;
  • financial stability;
  • protection of third parties;
  • integrity of the banking system.

The Kuwaiti Institute of Judicial and Legal Studies also reports Court of Cassation principles treating prohibitions on unauthorised banking/investment activity as connected with economic public order.

30. Case 8 — Kuwait Court of Cassation, Commercial Appeal No. 33/1981

This authority concerning a bank guarantee is useful for understanding the legal character of banking instruments.

Principle

The legal consequences of a banking instrument depend upon its legal character and contractual terms.

Operational-risk relevance

Correct legal classification is important for banks because a transaction must be correctly identified before its risks can be properly managed.

For example, an institution must distinguish among:

  • loan exposure;
  • guarantee exposure;
  • contingent liability;
  • payment obligation.

Incorrect classification can lead to inaccurate risk measurement.

31. Consolidated Case-Law Table

CaseMain legal issueOperational-risk relevance
Appeal 1384/2019, 22-02-2024Bank lendingProfessional banking controls
Commercial Appeal 808/2000, 16-06-2001Banking obligationsTransaction/process controls
Civil Appeal 479/2004, 19-09-2005Current accountAccurate records/reconciliation
Appeal 1912/2016, 08-04-2018Credit restructuringDocumentation and approval controls
Appeal 197/2020, 24-11-2021Bank loanCredit-process controls
Appeal 3656/2023, 11-06-2024Banking transactions/accountsMandatory banking rules
Appeal 14/2022, 23-09-2025Regulated financial activityEconomic public order
Commercial Appeal 33/1981Bank guaranteeCorrect legal classification

Important: these cases should not be cited as if the Kuwaiti Court of Cassation directly ruled on the Basel operational-risk capital formula. They are supporting authorities for the banking-law principles surrounding the regulatory framework.

32. Supervisory Approach of CBK

The CBK's approach combines:

Quantitative regulation

Capital must be maintained against identified risks.

Qualitative regulation

Banks must establish effective risk-management and internal-control systems.

Supervisory intervention

CBK can require higher capital or additional conditions where the bank fails relevant qualifying requirements.

Disclosure

Pillar 3 requires public disclosure, improving market discipline.

33. Operational Risk Capital vs Actual Operational Loss

These concepts should not be confused.

Capital charge

A regulatory calculation estimating the capital required to absorb operational risk.

Operational loss

An actual financial loss suffered by the bank.

For example:

A bank may have:

KD 10 million operational-risk capital requirement

but suffer:

KD 2 million actual fraud loss.

The actual loss does not automatically equal the regulatory capital charge.

Instead, the loss can influence:

  • profitability;
  • capital;
  • risk assessments;
  • ICAAP;
  • supervisory review;
  • future risk-management decisions.

34. Relationship with the Three Basel Pillars

Pillar 1 — Minimum Capital

Operational risk is incorporated into the quantitative capital framework.

Pillar 2 — Supervisory Review

CBK assesses whether the bank's actual operational-risk profile is adequately controlled and capitalised.

Pillar 3 — Market Discipline

Banks disclose relevant information about capital and risk management.

Thus:

Operational Risk → Pillar 1 capital → Pillar 2 assessment → Pillar 3 disclosure

35. Current Position of Kuwait's Banking Sector

CBK's latest published financial-soundness data show strong aggregate capitalisation.

For January–March 2026, the aggregate capital-adequacy ratio for Kuwaiti banks was approximately 19.2%, while Tier 1 capital represented approximately 88.7% of the capital base.

For conventional Kuwaiti banks, the reported capital-adequacy ratio was approximately 17.9% in 2021, 17.1% in 2022, 17.8% in 2023, 17.6% in 2024 and 17.2% in 2025.

These figures illustrate the capital buffer maintained by the sector, although aggregate capitalisation does not eliminate the need to manage institution-specific operational risks.

36. Legal Significance of Operational-Risk Capital Requirements

The Kuwait framework serves four principal objectives:

1. Loss absorption

Capital provides a buffer against operational losses.

2. Incentive for risk management

Banks must maintain appropriate operational-risk systems.

3. Supervisory protection

CBK can intervene when risk-management standards are inadequate.

4. Financial stability

Strong capital and operational controls reduce the probability that an operational failure will threaten the wider banking system.

37. Conclusion

Kuwait's banking law treats operational risk as an important component of prudential regulation rather than merely an internal-management issue.

The framework developed through Basel II, which introduced explicit operational-risk capital requirements, and was subsequently strengthened through Basel III, including stronger regulatory capital, capital buffers and enhanced supervisory requirements.

The CBK framework requires banks to combine:

Operational-risk management + internal controls + risk-management functions + capital + ICAAP + stress testing + supervisory review.

Particularly important is the CBK's power to require higher capital adequacy or additional conditions where a bank does not satisfy operational-risk-management qualifying criteria.

For Islamic banks, the legal framework additionally provides that capital falling below the required minimum because of operational losses must be restored within the period specified by the CBK.

The Kuwaiti Court of Cassation cases discussed above do not constitute a separate body of jurisprudence directly interpreting Basel's operational-risk formula. Their importance is instead in establishing the surrounding legal principles: banking is a specialised regulated activity; mandatory financial regulation protects the economic order; banking records and obligations must be accurately administered; and private contractual arrangements operate within the mandatory banking framework.

Accordingly, the Kuwaiti legal model can be summarised as:

Operational Risk → Regulatory Measurement → Capital Requirement → ICAAP/Stress Testing → CBK Supervisory Review → Additional Capital Where Necessary → Protection of Banking-System Stability.

LEAVE A COMMENT