Banking Law And Operational Risk Management In Islamic Banking Kuwait .
Banking Law and Operational Risk Management in Islamic Banking in Kuwait
1. Introduction
Operational risk in Islamic banking means the risk of loss resulting from inadequate or failed internal processes, people, systems, technology, legal arrangements, external events, or Shariah-compliance failures.
In Kuwait, operational-risk management for Islamic banks operates within a distinctive dual framework:
- Kuwaiti banking legislation and Central Bank of Kuwait (CBK) regulation, and
- Islamic Shariah requirements and Shariah-governance controls.
The principal statutory foundation is Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organization of Banking Business, as amended by Law No. 30 of 2003, which inserted the special statutory framework for Islamic banks. Article 86 expressly requires Islamic banks to conduct banking activities in conformity with Islamic Shariah principles.
The CBK's Islamic-bank instructions specifically include a Center of Risks System, liquidity rules, finance-concentration controls, investment/finance classification, finance-activity instructions, Shariah supervision, internal control and risk-management instructions, customer relations and AML/CFT controls.
2. Meaning of Operational Risk in Islamic Banking
Operational risk can arise from:
- employee error;
- inadequate internal controls;
- fraud;
- IT-system failure;
- cybersecurity incidents;
- inaccurate documentation;
- payment-processing errors;
- inadequate segregation of duties;
- outsourcing failures;
- legal disputes;
- regulatory non-compliance;
- Shariah non-compliance;
- defective financing documentation;
- inaccurate asset ownership records;
- inadequate collateral controls.
Islamic banks face many of the same operational risks as conventional banks, but Islamic transactions create additional operational requirements.
For example, in a Murabaha transaction the bank may need to:
Customer request → bank purchases asset → bank obtains ownership/control → bank sells asset to customer → customer pays deferred price
If the bank's systems or employees fail to properly document the acquisition and sale, the problem can become simultaneously:
- an operational-risk event;
- a contractual problem;
- a Shariah-compliance problem; and
- potentially a regulatory problem.
3. Statutory Foundation: Article 86
Article 86 of the Kuwaiti banking law recognises Islamic banks as banks conducting banking activities in accordance with Islamic Shariah.
It specifically identifies financing structures such as:
- Murabaha
- Musharakah
- Mudarabah
and permits Islamic banks to undertake banking, financial and direct-investment activities subject to Shariah and CBK controls.
Operational-risk significance
The legal form of an Islamic transaction therefore matters.
A bank's operational systems must be capable of ensuring that the actual transaction corresponds to the approved Shariah structure.
4. CBK's Risk-Management Framework
The CBK expressly lists "Instructions Concerning Internal Control System and Risk Management" among the regulatory instructions applicable to Islamic banks.
This means operational risk is not merely an internal management concern.
It forms part of the bank's prudential supervisory obligations.
A properly designed framework should cover:
| Risk area | Control |
|---|---|
| Employee error | Training and supervision |
| Fraud | Segregation of duties |
| IT failure | Backup and disaster recovery |
| Cyber risk | Security controls |
| Financing risk | Approval limits |
| Documentation | Legal review |
| Shariah risk | Shariah review/audit |
| Liquidity | Liquidity monitoring |
| Concentration | Exposure limits |
| AML | Transaction monitoring |
| Outsourcing | Vendor oversight |
| Customer complaints | Complaint-management system |
5. Corporate Governance and Operational Risk
Operational risk cannot be separated from corporate governance.
The CBK's governance framework expressly links governance with risk-management systems. The CBK's Shariah-supervisory governance material describes corporate governance as including accountability, protection of depositors' rights and development of robust risk-management systems.
The CBK also amended its corporate-governance rules in 2019 to introduce independent directors into the composition of bank boards and board committees.
Governance structure
A typical Islamic bank should therefore have:
Board of Directors
↓
Risk Committee / Board Committees
↓
Executive Management
↓
Risk Management
↓
Compliance
↓
Internal Audit
↓
Shariah Supervisory Board / Shariah governance functions
The objective is to prevent operational risk from becoming concentrated in one department.
6. Shariah Non-Compliance as Operational Risk
This is one of the most important distinctions between Islamic and conventional banking.
An Islamic bank can suffer operational loss because a transaction is executed incorrectly from a Shariah perspective.
Examples include:
- charging an impermissible amount;
- defective Murabaha documentation;
- failure to obtain ownership of an asset;
- inappropriate late-payment treatment;
- using an unapproved investment structure;
- executing a transaction differently from the Shariah-approved product.
Thus:
Shariah compliance is partly dependent upon operational execution.
A Shariah-compliant product on paper is insufficient if employees and systems execute it incorrectly.
7. Shariah Supervisory Board
Article 93 requires every Islamic bank to have an independent Shariah Supervisory Board consisting of at least three members appointed by the bank's General Assembly.
The board must provide an annual report concerning the bank's compliance with Islamic Shariah principles.
This creates an additional operational-control layer.
Its role includes:
- reviewing products;
- supervising Shariah compliance;
- identifying Shariah problems;
- reviewing transactions;
- providing opinions;
- reporting observations.
The CBK issued dedicated Shariah Supervisory Governance Instructions in 2016.
8. Higher Committee of Shariah Supervision
Law No. 3 of 2020 strengthened centralised Shariah governance by establishing the Higher Committee of Shariah Supervision at the CBK.
The Committee can:
- advise the CBK on Shariah matters;
- propose general Shariah guidelines;
- address disagreements within bank Shariah boards;
- pre-approve candidates for Shariah-board membership;
- provide Shariah opinions in matters referred by courts or arbitration centres.
Article 93 also provides that where members of an Islamic bank's Shariah Supervisory Board disagree on a Shariah ruling, the matter may be referred to the Higher Committee, which functions as the final authority on the relevant Shariah issue.
9. Operational Risk in Murabaha
Murabaha creates several operational-risk points.
Example
Suppose a customer wants machinery worth KWD 100,000.
The Islamic bank agrees to purchase it and resell it to the customer for KWD 115,000 payable over time.
The bank must properly establish:
- the customer's request;
- the bank's purchase;
- ownership/control;
- asset documentation;
- sale to the customer;
- deferred-payment obligation;
- security, where applicable.
Operational failure
If the bank's employee merely records a fictitious purchase without the bank actually acquiring the asset, the transaction may create:
- documentation risk;
- legal-enforceability risk;
- Shariah-compliance risk;
- accounting risk;
- reputational risk.
This is why operational controls are particularly important in Islamic finance.
10. Operational Risk in Ijarah
Ijarah involves leasing.
Operational controls must correctly determine:
- ownership;
- possession;
- maintenance obligations;
- insurance/takaful arrangements;
- rental calculations;
- default procedures;
- transfer arrangements.
If the bank is legally the owner of the leased asset, certain ownership-related risks cannot simply be ignored.
Consequently, operational failure in asset-management systems can become a contractual and Shariah problem simultaneously.
11. Operational Risk in Mudarabah and Musharakah
These are partnership-based structures.
Mudarabah
The bank may provide capital while another party manages the business.
Operational risk includes:
- inaccurate financial reporting;
- misuse of funds;
- inadequate monitoring;
- fraud;
- failure to verify profits;
- inadequate investment controls.
Musharakah
The bank and customer participate in an enterprise.
Operational controls should cover:
- capital contributions;
- ownership percentages;
- profit-sharing arrangements;
- loss allocation;
- valuation;
- governance;
- exit mechanisms.
Weak monitoring can therefore create both financial risk and operational risk.
12. Liquidity as an Operational-Risk Concern
Islamic banks face particular liquidity-management considerations because the availability of Shariah-compliant liquidity instruments may be more constrained than conventional instruments.
Article 97 authorises the CBK to establish rules concerning:
- liquidity;
- capital adequacy;
- asset-risk provisions;
- banking organisation.
Article 95 is particularly significant because the CBK may provide emergency financing to Islamic banks for up to six months, with a possible further extension of up to six months, using Shariah-compliant instruments and methods.
This provides a statutory mechanism for dealing with liquidity stress.
13. Deposits and Operational Risk
Article 96 makes an important distinction.
Sight deposits
Islamic banks must repay sight deposits fully when demanded, and such deposits do not bear losses.
Investment deposits
Investment-deposit holders participate in profits or losses according to the investment arrangement and applicable law.
This distinction creates an important operational requirement:
The bank's systems must correctly distinguish different categories of customer funds.
Incorrect classification can create:
- accounting risk;
- disclosure risk;
- customer-protection problems;
- Shariah risk;
- regulatory risk.
14. Capital and Operational Losses
Article 92 requires Islamic banks to maintain minimum paid-up capital and specifically provides that where capital falls below the required minimum because of operational losses or other reasons, the bank must cover the shortfall within the period specified by the CBK.
This is a particularly direct statutory connection between:
Operational loss → capital deterioration → regulatory response.
Operational risk is therefore capable of becoming a prudential problem.
15. Concentration Risk
The CBK can impose limits concerning:
- particular activities;
- equity holdings;
- individual projects;
- single-customer liabilities;
- required investment in the local market;
- deposits maintained with the CBK.
For an Islamic bank, concentration controls are important because a failure of one large Murabaha, Musharakah, real-estate or project-finance exposure can create substantial losses.
Operational controls should therefore ensure that the bank's exposure-management system accurately records every relevant exposure.
16. AML/CFT and Operational Risk
AML/CFT compliance is another important operational-risk area.
The CBK's Islamic-bank instructions expressly include AML/CFT requirements.
Operational failures can occur through:
- inadequate customer identification;
- failure to update KYC information;
- ineffective transaction monitoring;
- poor suspicious-transaction escalation;
- inadequate recordkeeping;
- insufficient employee training.
A technological AML system is therefore only as effective as its governance and monitoring.
17. Cybersecurity and Technology
Modern Islamic banks depend heavily on:
- mobile banking;
- online banking;
- automated financing;
- electronic payments;
- core banking systems;
- cloud services;
- digital identity;
- automated compliance systems.
Technology failures can cause:
- unauthorised transactions;
- service interruption;
- customer losses;
- inaccurate records;
- data breaches;
- regulatory breaches.
The CBK's broader risk-governance framework therefore needs to be read alongside its internal-control and risk-management requirements.
18. Operational Risk and Outsourcing
An Islamic bank may outsource:
- IT;
- cloud infrastructure;
- cybersecurity;
- payment processing;
- document management;
- customer service;
- data storage.
The fundamental principle is:
Outsourcing an activity does not eliminate the bank's responsibility to manage the resulting risk.
The bank therefore needs:
- due diligence;
- contractual controls;
- service-level requirements;
- business-continuity arrangements;
- audit rights;
- incident-reporting obligations;
- exit plans.
19. Case Law
A qualification is important here: Kuwaiti reported case law specifically labelled "operational risk management in Islamic banking" is relatively limited in publicly accessible English sources. It would therefore be misleading to invent six decisions as though they directly decided modern operational-risk-management questions.
The following Kuwaiti authorities are useful because they establish judicial principles relevant to banking regulation, Islamic-finance contracts, documentation, regulatory compliance and financial-sector risk.
Case 1 — Kuwait Court of Cassation, Commercial Appeal No. 366/2003
This authority is cited in Kuwaiti Islamic-finance commentary concerning the judicial treatment of Islamic financing contracts.
Principle
The legal consequences of an Islamic-finance transaction depend upon the actual contractual structure and obligations, rather than merely the label placed upon the transaction.
Operational-risk significance
An Islamic bank should therefore maintain reliable evidence showing:
- how the transaction was structured;
- what the bank purchased;
- what contractual obligations were created;
- how the transaction was executed.
This is particularly important for Murabaha and other asset-based financing.
Case 2 — Kuwait Court of Cassation, Commercial Appeal No. 320/2004
This authority has been associated with disputes involving Islamic-financing obligations.
Principle
Islamic-finance transactions remain legally enforceable commercial arrangements. Shariah compliance and contractual enforceability operate together.
Operational-risk significance
The bank's operational procedures must preserve evidence of the transaction and its contractual obligations.
In other words:
Shariah approval + defective documentation = potential enforcement problem.
The case is therefore useful as an analogous authority rather than as a case expressly deciding modern Basel-style operational-risk rules.
Case 3 — Kuwait Court of Cassation, Appeal No. 508/2016
This case concerned a banking-credit dispute involving the applicable interest rate and the relationship between contractual banking rights and CBK requirements.
Principle
Banking contracts do not operate independently of mandatory banking regulation.
Operational-risk significance
For Islamic banks, the broader principle is important:
Internal procedures and customer contracts must operate within the mandatory CBK regulatory framework.
A bank cannot rely solely upon contractual documentation while ignoring applicable regulatory requirements.
Although this was not an Islamic-finance case, it is relevant as a banking-regulatory authority, not as direct Shariah precedent.
Case 4 — KFH v Commercial Bank of Kuwait, Court of Cassation, 3 April 2016
Kuwait Finance House obtained a Court of Cassation ruling concerning approximately KWD 44.06 million against Commercial Bank of Kuwait. Contemporary reporting states that the ruling concerned repayment of that amount.
Operational-risk significance
The litigation illustrates the importance of:
- inter-bank documentation;
- accurate recording of financial obligations;
- contractual certainty;
- proper management of significant financial exposures.
For Islamic banks, inter-bank claims may involve particularly important documentation and Shariah-structuring considerations.
Case 5 — Kuwait Court of Cassation, Appeal No. 14/2022, judgment of 23 September 2025
This recent decision concerned investment arrangements undertaken without the required regulatory authorisation.
The Court considered the relationship between mandatory financial regulation and the validity of unauthorised financial arrangements. The reported analysis treats the relevant regulatory requirements as connected with economic public order.
Operational-risk significance
This principle is highly relevant to Islamic banks:
A private contract cannot simply override mandatory financial regulation.
Consequently, banks need strong controls around:
- licensing;
- authorised activities;
- product approval;
- regulatory permissions;
- employee authority;
- compliance monitoring.
Case 6 — Investment Dar Bankruptcy Litigation
The Investment Dar litigation is significant in Kuwait's Islamic-finance and financial-distress jurisprudence.
The litigation involved bankruptcy, creditor claims and substantial financial-sector exposure. Reported material identifies Court of Cassation proceedings concerning the bankruptcy position and major financial creditors.
Operational-risk significance
The case illustrates why Islamic financial institutions need:
- early-warning systems;
- exposure monitoring;
- counterparty assessment;
- collateral controls;
- recovery procedures;
- insolvency planning.
Operational risk can magnify credit and insolvency risk where a financial institution does not adequately monitor a distressed counterparty.
20. Case-Law Summary
| Case | Main subject | Operational-risk relevance |
|---|---|---|
| KCC Commercial Appeal 366/2003 | Islamic-finance contractual structure | Documentation and transaction substance |
| KCC Commercial Appeal 320/2004 | Islamic-financing obligations | Contractual enforceability |
| KCC Appeal 508/2016 | Banking contract/CBK regulation | Regulatory compliance |
| KFH v Commercial Bank, 3 Apr. 2016 | Inter-bank financial claim | Documentation and exposure management |
| KCC Appeal 14/2022 | Unauthorised financial activity | Compliance and regulatory controls |
| Investment Dar litigation | Bankruptcy/financial distress | Counterparty, recovery and crisis management |
Important: These are not six judgments all directly deciding "operational risk management." They are authorities that provide relevant judicial principles for analysing operational-risk controls in Kuwaiti Islamic banking. Public English-language access to complete Kuwaiti Court of Cassation reasoning is limited, so the original Arabic judgments should be consulted for a thesis or litigation memorandum.
21. Three Lines of Defence
An Islamic bank can organise operational-risk governance through three levels.
First line — Business units
Responsible for:
- transaction execution;
- customer verification;
- documentation;
- Shariah-approved procedures;
- day-to-day controls.
Second line — Risk and Compliance
Responsible for:
- operational-risk identification;
- risk assessments;
- regulatory compliance;
- AML;
- monitoring;
- incident management.
Third line — Internal Audit
Provides independent assurance concerning:
- controls;
- governance;
- risk-management effectiveness;
- Shariah-related processes;
- regulatory compliance.
22. Shariah Audit and Internal Audit
A particularly important feature is the distinction between:
Internal audit
and
Shariah audit/review.
Internal audit asks questions such as:
Was the transaction processed according to approved procedures?
Shariah review asks:
Was the transaction executed consistently with the applicable Shariah requirements?
The two controls complement one another.
The CBK's Higher Committee is expressly empowered to propose guidelines governing internal and external Shariah audits and the activities of Shariah-supervision bodies.
23. Operational-Risk Event Example
Consider a hypothetical Murabaha transaction.
Step 1
Customer requests an asset.
Step 2
Bank approves financing.
Step 3
Bank purchases the asset.
Step 4
Bank should properly establish ownership/control.
Step 5
Bank sells the asset to the customer.
Step 6
Customer makes deferred payments.
Suppose the employee accidentally skips Step 3.
The consequences may include:
Operational failure
↓
Bank did not execute its approved procedure
↓
Documentation problem
↓
Possible Shariah-compliance problem
↓
Possible contractual/enforcement problem
↓
Possible customer/reputational problem
↓
Potential regulatory consequences
This demonstrates why operational risk in Islamic banking is broader than ordinary administrative risk.
24. Legal Consequences of Operational-Risk Failure
Depending on the circumstances, an Islamic bank may face:
1. Regulatory action
CBK may require corrective measures or impose applicable supervisory consequences.
2. Financial loss
Fraud, errors, failed transactions or defective controls can generate direct losses.
3. Contractual liability
Customers or counterparties may challenge improperly executed transactions.
4. Shariah remediation
A transaction may require correction or other treatment under the bank's Shariah governance framework.
5. Reputational damage
Loss of confidence can be particularly significant for an institution whose business model depends upon public confidence in Shariah compliance.
6. Capital impact
Article 92 expressly recognises that operational losses can contribute to a capital shortfall requiring remediation.
25. Operational Risk vs. Shariah Risk
| Operational Risk | Shariah Risk |
|---|---|
| Employee error | Non-compliant contract |
| IT failure | Improper transaction structure |
| Fraud | Impermissible element |
| Poor documentation | Failure to satisfy Shariah conditions |
| System failure | Execution inconsistent with approved fatwa |
| Outsourcing failure | Inadequate Shariah controls |
They overlap substantially.
For example:
Employee fails to record bank's asset ownership
→ operational error
→ potentially defective Murabaha execution
→ potential Shariah issue.
26. Operational Risk vs. Credit Risk
These risks also interact.
A poorly designed credit-management system may:
- approve a weak customer;
- inadequately monitor the exposure;
- fail to detect deterioration;
- fail to enforce security;
- produce financial loss.
Thus:
Operational weakness can be the mechanism through which credit risk becomes an actual loss.
This is particularly important for large Islamic-finance transactions involving real estate, project finance and corporate Murabaha.
27. CBK's Overall Supervisory Philosophy
The Kuwait framework is not based upon one isolated operational-risk regulation.
Instead, operational risk is embedded within a broader regulatory architecture covering:
Capital
- Liquidity
- Risk management
- Internal controls
- Corporate governance
- Shariah governance
- AML/CFT
- Customer protection
- Concentration controls
- Regulatory supervision
The CBK itself describes its Shariah-supervision framework as supporting financial stability and governance of Shariah compliance in Islamic financial institutions.
28. Conclusion
The Kuwaiti legal framework treats operational risk in Islamic banking as part of a broader system of prudential regulation, internal control, corporate governance and Shariah governance.
The most important legal foundations are:
- Law No. 32 of 1968, as amended;
- Law No. 30 of 2003, which introduced the dedicated Islamic-bank framework;
- Article 86, requiring Islamic banking activities to comply with Shariah;
- Article 92, addressing capital shortfalls including those caused by operational losses;
- Article 93, establishing Shariah Supervisory Boards;
- Article 95, providing for Shariah-compliant emergency financing;
- Article 96, distinguishing sight deposits from investment deposits;
- Article 97, concerning liquidity, capital adequacy and risk provisions;
- CBK internal-control and risk-management instructions;
- CBK Shariah Supervisory Governance Instructions;
- Higher Committee of Shariah Supervision established under the 2020 reforms.
The central legal lesson is that operational risk in Kuwaiti Islamic banking is not merely an IT or administrative issue. It can affect the validity and enforceability of financing transactions, Shariah compliance, regulatory compliance, liquidity, capital adequacy, customer protection and ultimately financial stability.
In practical terms, an Islamic bank must therefore operate on the principle:
Identify risk → prevent error → maintain Shariah-compliant controls → monitor continuously → detect incidents → correct/remediate → report → learn and strengthen controls.

comments