By The Weekly Vision Court Reporter
The High Court of Kenya has delivered a judgment reinforcing the stringent duty of care that banks owe their customers when activating digital banking channels, holding that inadequate verification processes and a failure to detect obvious anomalies can render a financial institution liable for losses arising from fraud.
Delivering judgment in Commercial Appeal No. E078 of 2026 [2026] KEHC 9414 (KLR) on 2nd July 2026, the Court drew on a long-established principle of banking law, observing that a bank is the keeper of the gate through which its customer’s money passes, and that where it is warned the gate stands open and fails to close it, it cannot later be heard to say the thief carried the right key.
The Court found that this principle applied with even greater force in the matter before it. The Respondent bank had not merely failed to close the gate after being put on notice; its systems, the Court held, had been designed in a manner that allowed a fraudster to pick the lock with relative ease.
The Court found the bank’s Know Your Customer (KYC) and onboarding procedures for new digital channels to be inherently insecure. It held that a bank’s duty of care must extend to ensuring that a significant change to an account, such as the activation of digital banking, is verified with a high degree of certainty.
The bank’s argument that the customer had already supplied personal details when the physical account was opened years earlier was rejected by the Court as circular and insufficient. Information provided a decade earlier to open a traditional account, the Court noted, is precisely the information that a fraudster who has compromised those details would possess. Such historic data, it held, does not constitute robust verification for the activation of a powerful new digital channel.
Particular weight was given to the sequence of events: the creation of a new OMNI profile on an account with no prior digital activity, followed by the transfer of KSh 1,001,000 within just sixteen minutes. The Court described this as a clear indication of systemic failure, stating it found it “incredulous” that the bank’s fraud-detection algorithms had not flagged the anomaly.
In reaching this conclusion, the Court relied on the earlier decision of the High Court in Diamond Trust Bank Kenya Ltd v Kariuki & another, Civil Appeal No. E121 of 2024 [2026] KEHC 9771 (KLR) (18th June 2026), in which it was held that a bank is expected to flag suspicious transactions. Large, rapid transfers to a new and unrelated account immediately after the activation of a digital profile on a previously dormant account, the Court found, were precisely the sort of red flags that a reasonably competent bank ought to have systems in place to detect and halt.
The judgment reinforces that banks cannot rely solely on the fact that a correct PIN or password was used, nor can they treat the initial account-opening KYC as a permanent shield. When enabling high-risk digital functionalities, the Court held, institutions are required to implement contemporaneous, robust verification and to maintain effective real-time monitoring capable of identifying and interrupting anomalous activity.
The ruling forms part of a growing body of Kenyan jurisprudence placing a proactive, rather than purely reactive, duty on financial institutions to protect customer funds in an increasingly digital banking environment.

