Banking Law And Payment Facilitator Compliance Obligations Kuwait .

Banking Law and Payment Facilitator Compliance Obligations in Kuwait

1. Introduction

A payment facilitator (PayFac) is generally a business that helps merchants accept electronic payments without each merchant having to build a direct relationship with the underlying acquiring infrastructure. Depending on the structure, a facilitator may onboard merchants, process transactions, transmit payment instructions, settle funds, conduct fraud monitoring, and provide technical interfaces between merchants, banks and payment networks.

In Kuwait, however, “payment facilitator” should not be treated as a single statutory licence category in every case. The legal treatment depends on what the business actually does. A platform that merely provides software presents a different regulatory profile from an entity that receives customer money, operates payment accounts, executes transfers, provides e-money functionality or performs regulated payment activities.

The principal regulator is the Central Bank of Kuwait (CBK). Relevant requirements arise from Kuwait's banking legislation, CBK payment regulations and instructions, AML/CFT legislation, electronic-transactions rules, consumer-protection requirements, cybersecurity obligations and contractual arrangements with acquiring banks and international card networks.

2. Core banking-law framework

The foundational statute is Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business, as amended.

The legislation establishes the CBK and provides the foundation for regulation and supervision of banking activities in Kuwait.

For a payment facilitator, the first legal question should therefore be:

What activities does the business actually perform?

A typical structure is:

Customer → Merchant → Payment Facilitator → Acquiring/Payment Institution → Payment Network → Issuing Bank

Different entities have different regulatory responsibilities within this chain.

A company cannot avoid financial regulation merely by describing itself as a technology company where its actual activities amount to regulated payment services.

3. CBK payment-service regulation

The CBK has developed a regulatory framework governing electronic payment activities and payment-service providers.

Depending on the current CBK classification and the particular activities undertaken, regulatory requirements can cover matters such as:

  • licensing or registration;
  • minimum capital;
  • governance;
  • safeguarding;
  • outsourcing;
  • cybersecurity;
  • business continuity;
  • risk management;
  • consumer protection;
  • transaction monitoring;
  • record keeping; and
  • regulatory reporting.

Consequently, a PayFac entering Kuwait should conduct a regulatory perimeter analysis before launching operations.

4. Licensing and authorization

A payment facilitator must determine whether its business model requires CBK authorization.

The analysis normally considers whether the entity:

  • executes payments;
  • transfers funds;
  • receives customer money;
  • provides merchant acquiring functions;
  • maintains payment accounts;
  • provides stored-value facilities;
  • issues payment instruments;
  • provides electronic-money functionality; or
  • performs only technical services.

This distinction is critical.

Example

Company A

Provides merchants with API software but never controls funds.

Its regulatory position may differ substantially from:

Company B

Receives payments from customers, holds the proceeds temporarily and subsequently distributes money to thousands of merchants.

Company B creates much stronger payment-services, safeguarding, AML and operational-risk concerns.

5. Merchant onboarding

Merchant onboarding is one of the most important PayFac obligations.

A facilitator should know:

Who is the merchant?

This generally requires obtaining and verifying appropriate information concerning:

  • legal identity;
  • commercial registration;
  • beneficial ownership;
  • authorized representatives;
  • business activities;
  • expected transaction volumes;
  • geographic exposure;
  • products and services;
  • source and destination of funds where relevant; and
  • risk profile.

High-risk merchants require enhanced scrutiny.

The PayFac should therefore avoid treating merchant onboarding as merely a sales procedure.

It is an important financial-crime control.

6. AML/CFT obligations

Kuwait's principal AML/CFT legislation includes Law No. 106 of 2013 regarding Anti-Money Laundering and Combating the Financing of Terrorism.

Payment businesses can be exposed to laundering techniques because electronic payments permit large numbers of transactions to move rapidly.

Relevant controls can include:

  1. customer identification;
  2. beneficial-owner verification;
  3. risk classification;
  4. ongoing monitoring;
  5. enhanced due diligence;
  6. sanctions screening;
  7. suspicious-transaction detection;
  8. record retention; and
  9. appropriate reporting.

The precise obligations depend upon the entity's regulated status and activities.

7. Beneficial ownership

Knowing the merchant's registered corporate name is not necessarily sufficient.

A payment facilitator should identify the natural persons who ultimately own or control a corporate customer where required by applicable AML rules.

For example:

ABC Trading Company → Holding Company → Offshore Company → Individual X

A compliance system should not simply stop at ABC Trading Company if the applicable due-diligence rules require identification of the ultimate beneficial owner.

Opaque ownership structures should trigger additional review.

8. Transaction monitoring

Merchant approval is only the beginning.

A PayFac should continuously monitor relevant transaction activity.

Potential warning signs include:

  • sudden increases in transaction volume;
  • unusually large refunds;
  • repeated transactions of unusual values;
  • transactions inconsistent with the merchant's declared business;
  • unusually high chargeback levels;
  • unexplained cross-border activity; and
  • apparent attempts to disguise prohibited business activities.

Automated monitoring systems are commonly used because manual monitoring becomes impractical at scale.

9. Suspicious transactions

Where applicable legal thresholds are satisfied, suspicious activity may need to be reported to the competent Kuwaiti financial-intelligence authorities in accordance with AML/CFT legislation.

An important principle is that:

Suspicion does not require proof of a criminal conviction.

AML reporting systems are intended to identify suspicious circumstances before criminal liability has necessarily been judicially established.

Businesses should also respect applicable restrictions concerning inappropriate disclosure of suspicious-transaction reporting.

10. Sanctions compliance

Payment facilitators should operate effective sanctions-screening procedures.

Screening may cover:

  • merchants;
  • beneficial owners;
  • customers where required;
  • counterparties;
  • payment beneficiaries; and
  • relevant transaction information.

The facilitator should also establish procedures for potential matches.

A simplistic system that automatically approves every transaction merely because the merchant was screened when initially onboarded is inadequate for a dynamic payment environment.

11. Safeguarding merchant funds

Where a PayFac receives or controls merchant/customer funds, safeguarding becomes a major legal concern.

The fundamental objective is to prevent payment money from being treated as ordinary operating cash.

A compliant structure may require, depending on the applicable CBK framework:

  • segregation;
  • designated accounts;
  • reconciliation;
  • restrictions on use;
  • documented settlement processes; and
  • controls against insolvency or operational misuse.

Example

Suppose the facilitator processes:

KWD 5 million

for merchants.

That KWD 5 million should not simply be treated as freely available corporate working capital where the regulatory framework requires customer funds to be protected.

12. Settlement risk

Payment facilitators create settlement risk because money may pass through several entities before reaching the merchant.

For example:

Cardholder → issuer → card network → acquirer → facilitator → merchant

Compliance procedures should determine:

  • who legally receives the funds;
  • when settlement occurs;
  • who bears chargeback risk;
  • whether reserves are maintained;
  • who handles refunds; and
  • what happens if one participant becomes insolvent.

These matters should be addressed both contractually and operationally.

13. Merchant reserves

PayFacs frequently maintain reserves against merchant risks.

For example:

Merchant transaction volume = KWD 100,000
Reserve = 5%

The facilitator might retain:

KWD 5,000

to cover agreed risks such as chargebacks.

However, reserve arrangements should be clearly disclosed in merchant contracts.

The agreement should explain:

  • calculation;
  • duration;
  • permitted deductions;
  • release conditions; and
  • treatment upon termination.

14. Chargebacks and disputes

Payment facilitators must have mechanisms for handling payment disputes.

A chargeback may arise from:

  • unauthorized transactions;
  • fraud;
  • goods not delivered;
  • duplicate payments;
  • processing errors; or
  • card-network rules.

The PayFac agreement should allocate responsibility among:

Merchant – PayFac – Acquirer – Payment Network

A facilitator should also monitor merchants with unusually high dispute rates because elevated chargebacks may indicate fraud or poor merchant practices.

15. Consumer protection

Kuwaiti payment arrangements may also interact with consumer-protection legislation and CBK consumer-protection requirements.

Important principles include:

  • transparent fees;
  • clear contractual terms;
  • accessible complaint mechanisms;
  • accurate transaction information;
  • fair handling of disputes;
  • protection against unauthorized transactions; and
  • adequate disclosure.

A customer should not be presented with hidden payment charges or misleading descriptions of payment services.

16. Electronic transactions

Kuwait Law No. 20 of 2014 concerning Electronic Transactions is important for digital-payment ecosystems.

Electronic contracting raises questions concerning:

  • electronic records;
  • electronic signatures;
  • evidential reliability;
  • integrity of records;
  • authentication; and
  • electronic communications.

For PayFacs, transaction logs may later become important evidence in disputes.

Accordingly, record integrity is a legal as well as technical issue.

17. Cybersecurity

A payment facilitator is an attractive target for cyberattacks.

The platform may process:

  • payment credentials;
  • merchant information;
  • transaction histories;
  • identity information; and
  • authentication data.

Appropriate security controls commonly include:

Encryption → authentication → access controls → monitoring → incident response → recovery

Cybersecurity obligations may arise from CBK requirements, contracts with regulated banks and card-network standards in addition to general legislation.

18. PCI DSS

Where card data are processed, Payment Card Industry Data Security Standard (PCI DSS) requirements can become contractually and operationally significant.

PCI DSS is not itself Kuwait's banking statute.

Nevertheless, acquiring banks and payment networks commonly require compliance as part of participation in card-payment infrastructure.

A serious PCI failure can therefore produce consequences even independently of direct statutory sanctions.

19. Outsourcing

Payment facilitators frequently rely on third parties for:

  • cloud hosting;
  • fraud monitoring;
  • KYC;
  • customer support;
  • cybersecurity;
  • payment processing; and
  • data storage.

Outsourcing does not automatically eliminate regulatory responsibility.

The regulated entity should maintain appropriate:

  • vendor due diligence;
  • written contracts;
  • security controls;
  • audit rights;
  • service-level requirements;
  • incident procedures;
  • business-continuity arrangements; and
  • exit strategies.

20. Cross-border payments

Cross-border payment facilitation creates additional risks.

A Kuwait-based merchant might receive payments from customers in numerous jurisdictions.

This can create questions concerning:

  • foreign currencies;
  • sanctions;
  • correspondent relationships;
  • cross-border AML;
  • foreign payment regulation;
  • data transfers; and
  • settlement arrangements.

The fact that the customer is outside Kuwait does not automatically remove Kuwaiti regulatory obligations from the Kuwaiti payment provider.

21. Operational resilience

Payment platforms are critical infrastructure for merchants.

A major outage can prevent thousands of businesses from accepting payments.

Payment facilitators should therefore maintain:

  • redundancy;
  • backup systems;
  • disaster recovery;
  • incident-response plans;
  • business-continuity arrangements;
  • recovery testing; and
  • escalation procedures.

A regulated payment business must treat availability as part of financial-risk management rather than simply an IT issue.

22. Governance

The board and senior management should oversee payment risk.

An effective governance structure can include:

Board → Senior Management → Compliance → AML Officer → Risk → Internal Audit

The compliance function should have sufficient independence and resources.

Rapid commercial growth does not justify weak merchant controls.

23. Agent and sub-merchant risk

The PayFac model is particularly challenging because one regulated or supervised relationship may support thousands of smaller merchants.

Suppose:

Acquiring Bank → PayFac → 15,000 sub-merchants

The acquiring bank cannot assume that every merchant is low risk simply because the PayFac performs onboarding.

The contractual framework should therefore establish monitoring, audit, reporting and termination rights.

24. Relevant Case Law

Published Kuwaiti judgments specifically using the modern commercial term “payment facilitator” are limited. It would therefore be misleading to invent six Kuwait PayFac cases. The more useful approach is to identify established Kuwaiti judicial principles that apply to banking/payment disputes and supplement them with influential comparative payment-law jurisprudence.

Case 1 — Kuwaiti Court of Cassation: banking duty and contractual responsibility

Kuwaiti Court of Cassation jurisprudence concerning bank-customer relationships generally recognizes that banking disputes must be determined from the contractual relationship, applicable legislation and established banking obligations.

For PayFacs, the principle means that liability will depend substantially upon the facilitator's actual contractual undertaking.

If it promises settlement within a defined period but improperly withholds merchant funds, contractual liability can arise independently of broader regulatory consequences.

Case 2 — Kuwaiti Court of Cassation: electronic and documentary evidence

Kuwaiti commercial jurisprudence gives considerable importance to documentary evidence and commercial records.

For payment platforms this makes:

  • transaction logs;
  • settlement statements;
  • authorization records;
  • electronic communications; and
  • reconciliation records

particularly important in establishing what occurred.

The Electronic Transactions Law strengthens the significance of reliable electronic records.

Case 3 — Kuwaiti Court of Cassation: unauthorized banking operations

Kuwaiti banking jurisprudence generally requires courts to examine authorization and the bank's contractual duties when disputed transactions occur.

The principle is relevant to PayFac systems because transaction authentication cannot simply be assumed.

Payment businesses should preserve evidence establishing:

who initiated the transaction → how authentication occurred → what authorization was received → when settlement occurred.

Case 4 — Kuwaiti Court of Cassation: contractual interpretation in commercial banking

The Court of Cassation has repeatedly applied general principles of Kuwaiti civil and commercial law when interpreting banking agreements.

Clear drafting is therefore particularly important for:

  • settlement rights;
  • reserves;
  • refunds;
  • chargebacks;
  • suspension;
  • merchant termination; and
  • indemnification.

A PayFac should avoid relying solely on internal operating practices that are absent from its merchant agreement.

Case 5 — CJEU, C-191/17, ING-DiBa Direktbank Austria

Although an EU rather than Kuwaiti case, ING-DiBa illustrates the importance of accurately identifying whether a particular product constitutes a payment account or payment service under the relevant regulatory definition.

Its comparative lesson is useful in Kuwait:

regulatory classification depends upon the actual functionality of the product, not simply its marketing name.

Case 6 — CJEU, C-295/18, Verein für Konsumenteninformation v DenizBank AG

The case concerned payment-services contractual arrangements and contactless functionality.

Its broader comparative relevance lies in the need for clear allocation of risks and transparent contractual treatment of payment functionality.

For Kuwaiti facilitators, comparable issues arise in merchant agreements governing authorization, fraud, reversals and liability.

Case 7 — CJEU, C-616/11, T-Mobile Austria

This payment-services case concerned charges connected with the use of payment instruments.

Although it does not bind Kuwaiti courts, it illustrates how payment regulation can closely control the commercial allocation of payment-processing costs.

The comparative lesson is that PayFac pricing must be considered together with mandatory regulatory and consumer-protection requirements.

25. Important limitation concerning the cases

The distinction between binding Kuwaiti authority and comparative foreign authority is essential.

CJEU decisions do not bind Kuwaiti courts. They are useful only for comparative analysis.

Likewise, Kuwait has significantly less publicly accessible, systematically reported payment-services case law than some EU jurisdictions. Specific Court of Cassation judgment numbers should therefore be verified against an authoritative Kuwaiti legal database before being relied upon in litigation or a formal legal opinion.

26. Practical compliance model

A Kuwait PayFac could structure its compliance programme as follows:

Stage 1 – Regulatory classification
Determine whether the proposed activities constitute regulated payment services.

Stage 2 – CBK authorization
Obtain the required licence, registration or approval before conducting regulated activity.

Stage 3 – Merchant KYC
Verify identity, registration, ownership and business activity.

Stage 4 – Risk scoring
Classify merchants as low, medium or high risk.

Stage 5 – AML/sanctions screening
Screen merchants, beneficial owners and relevant transactions.

Stage 6 – Transaction monitoring
Monitor abnormal activity, fraud indicators and chargebacks.

Stage 7 – Safeguarding
Protect merchant/customer money where applicable.

Stage 8 – Cybersecurity
Protect payment systems and credentials.

Stage 9 – Settlement and reconciliation
Maintain accurate records of money received and distributed.

Stage 10 – Reporting and audit
Maintain regulatory reporting, internal audit and compliance review.

27. Key compliance risks

RiskRequired response
Unlicensed payment activityRegulatory-perimeter review
Fake merchantKYC/KYB
Hidden ownerBeneficial-owner verification
Money launderingAML monitoring
Sanctions exposureScreening
Merchant fraudTransaction monitoring
Misuse of merchant moneySafeguarding
Chargeback lossesReserve/risk controls
CyberattackCybersecurity programme
Platform outageBusiness continuity
Outsourcing failureVendor governance
Disputed transactionAuthentication records
Misleading feesTransparent disclosure
Cross-border riskEnhanced compliance review

Conclusion

Payment facilitator compliance in Kuwait should be understood as a combination of CBK payment supervision, banking law, AML/CFT controls, merchant due diligence, safeguarding, cybersecurity, electronic-transactions rules, consumer protection and contractual risk management.

The central legal principle is substance over commercial terminology. Calling a business a “PayFac,” “fintech platform,” “gateway” or “technology provider” does not determine its regulatory position. What matters is whether it actually receives funds, executes payments, provides acquiring or payment functionality, maintains accounts or otherwise performs activities falling within Kuwait's regulated financial perimeter.

For a Kuwait PayFac, the strongest compliance architecture is therefore:

CBK authorization/classification + KYB/KYC + beneficial-ownership checks + AML/CFT + sanctions screening + transaction monitoring + safeguarding + cybersecurity + settlement controls + outsourcing governance + consumer protection + audit and reporting.

And because dedicated published Kuwaiti PayFac case law remains limited, banking and commercial Court of Cassation principles should be applied carefully rather than presenting unrelated judgments as direct PayFac precedents.

LEAVE A COMMENT