CBK Warns Bank Boards of Ultimate Liability for Cybercrimes

N

Nyakundi Report

Newsroom 1 min read

Primary source Kenyan Digest archive

This archive report was first published on 16 July 2019.

On July 16, 2019, the Central Bank of Kenya (CBK) issued new rules to payment service providers, including commercial banks and technology companies, to stem cybercrime.

The guidelines warn the boards of directors that they face 'ultimate' liability in case of criminal breaches, emphasizing that they are responsible for the cybersecurity of the payment service providers.

According to the CBK, payment service providers should carry out regular independent assessment and audit functions, which shall be undertaken by internal and external audit and risk functions.

Boards of directors are ultimately responsible for the cybersecurity of payment service providers, said the CBK.

Payment service providers, including firms like Mastercard, Visa, Safaricom, Airtel, and Telkom, have 90 days to comply with the requirements.

Companies working with payment service providers are also expected to treat customer information confidentially.

Outsourcing agreements should be governed by a clearly written contract, with controls to ensure customer data confidentiality and service providers' liability in case of breach.

Next read

Sports Fund CEO Nuh Ibrahim Exposed Over Refusal to Repay Ksh 2 Million Debt as Protest Looms at Talanta Plaza

24 July 2026 · 4 min read

Sports Fund CEO Nuh Ibrahim has been exposed over his refusal to repay a KSh2 million debt to a young businessman, with a peaceful...