top of page

High Court Holds Stanbic Bank Not Liable for Mobile Banking Fraud, Rules Compromised Customer Credentials Break the Bank's Duty of Care, Dismisses UGX 68 Million Claim



Nakku Joweria v Stanbic Bank (U) Limited, Civil Suit No. 197 of 2024

High Court of Uganda at Kampala (Commercial Division). Before Hon. Lady Justice Dr. Ginamia Melody Ngwatu. Delivered 3 August 2026.

Overview

The High Court of Uganda, Commercial Division, has held that although a bank owes its customer a duty to exercise reasonable skill and care in safeguarding the customer’s account and processing transactions, the occurrence of unauthorised transactions does not, by itself, establish liability on the part of the bank.


The Court found that where a customer’s authentication credentials are compromised, the customer also bears responsibility for promptly notifying the bank of the loss or compromise of the credentials. In the absence of evidence establishing a breach of the bank’s duty of care, the bank cannot be held liable merely because unauthorised withdrawals occurred.


The Court further considered the application of fraud-detection obligations in digital banking and held that unusual transactions do not automatically trigger a duty on the bank to stop or question them. There must be reasonable grounds, based on specific and clear indicators, to believe that a payment instruction may facilitate fraud.


Facts


The Plaintiff held a savings account with the Defendant bank, account No. 903000026244, opened in 2001. Between 7 and 8 February 2023, unauthorized persons withdrew UGX 68,000,000 from the account through 17 separate transactions on the Defendant's Flexipay platform. The withdrawals used four Airtel lines unknown to the Plaintiff and occurred within a 24-hour window.


The Plaintiff stated she never enrolled on Flexipay and never authorized the withdrawals. She lost her phone on 6 February 2023, with her National ID kept behind it. She reported the loss to Airtel and MTN, and to the police, though her account of the timing shifted between her witness statement and a recorded interview with the bank. She discovered the loss of funds on 6 March 2023, when she obtained a bank statement.


The Defendant's position was that the Plaintiff's lost credentials, phone and National ID copy, were used to enroll her on Flexipay. By the time she reported the loss on 6 March 2023, the funds had already left the account. The Defendant pointed to account terms requiring prompt notification of lost credentials and argued the Plaintiff bore that responsibility. The Defendant had offered to settle for half the claimed sum, later proposing UGX 34,000,000 without admission of liability. The Plaintiff rejected the offer.


Legal Representation

For the Plaintiff

Mr. Engola Edward and Mr. Simon Peter Aliu of M/s Kimanje Nsibambi & Co. Advocates.


For the Defendant

Mr. Pius Kitamirike of M/s S&L Advocates.


Issues for determination

  1. Whether the Defendant owed a duty of care to the Plaintiff as its customer.

  2. Whether the Defendant is liable for the unauthorized withdrawals.

  3. What remedies are available to the parties.


Submissions by parties

Plaintiff's Submissions

Counsel for the plaintiff submitted that the existence of the banker-customer relationship was undisputed and that the bank consequently owed the plaintiff a duty of care.


Counsel contended that the withdrawal of UGX 68,000,000 through the Flexipay system represented a significant departure from the plaintiff's established transaction pattern.


It was submitted that the plaintiff had historically conducted transactions over the counter and had not ordinarily used digital banking services. Counsel therefore argued that the sudden occurrence of numerous withdrawals within a short period, involving different telephone numbers, constituted a sufficiently unusual pattern that ought to have triggered the bank's fraud-detection mechanisms.


Counsel further submitted that the bank had an obligation to monitor the plaintiff's account and maintain robust systems capable of detecting and preventing fraudulent transactions.


The plaintiff relied on Aida Atiku v Centenary Rural Development Bank Limited, Civil Suit No. 754 of 2020, where, according to counsel, the Court recognised that banks should be capable of identifying suspicious transactions and should have systems through which digital transactions can be traced and examined.


Counsel also pointed to several unsuccessful attempts to enrol the plaintiff's account onto Flexipay shortly before the successful transactions. It was submitted that these failed attempts were themselves warning signs which should have alerted the bank to possible fraudulent activity.


The plaintiff further contended that she had never enrolled for Flexipay and had never authorised the transactions. Counsel maintained that the plaintiff's phone had been stolen before the Flexipay registration and subsequent withdrawals occurred.


On the issue of delayed notification, counsel submitted that the plaintiff only became aware of the withdrawals when she attempted to access her money and discovered that it had been depleted. It was therefore argued that the delay in reporting the matter to the bank should not, in itself, absolve the bank of its duty to protect the customer's funds.


Counsel further relied on Excellent Assorted Manufacturers Ltd & Another v DFCU Bank Limited & Another, Civil Suit No. 338 of 2017, submitting that a customer is not required to check their bank account every day merely to ascertain whether unauthorised transactions have occurred.


The plaintiff also challenged the authenticity of an audio recording and its transcription relied upon by the bank. Counsel submitted that the maker of the recording and the person who transcribed it had not testified and that the recording appeared to terminate abruptly.


It was further submitted that the recording had not remained complete and unaltered, contrary to the requirements relating to electronic records.


Defendant's Submissions

Counsel for the defendant conceded that a bank owes its customers a duty of care but submitted that the duty was not absolute and was reciprocal. It was argued that the customer equally has contractual and legal obligations to safeguard banking credentials and to promptly report the loss of a phone, SIM card or other authentication credentials.


Counsel submitted that the plaintiff lost her phone and National Identification Card but failed to notify the bank until approximately one month later. It was contended that this failure deprived the bank of an opportunity to intervene and prevent the subsequent transactions.


The defendant further submitted that it had deployed secure banking platforms, fraud-prevention mechanisms and transaction notifications and had acted in accordance with the standard expected of a reasonable banker.


Counsel relied on Jessica Kakooza v Ecobank (U) Ltd, Civil Suit No. 44 of 2014, and submitted that the standard of negligence applicable to a bank should be determined by reference to the practices of reasonable persons carrying on the banking business.

The defendant argued that the plaintiff's own compromised credentials enabled the fraudulent transactions and that the bank's systems could not reasonably be expected to distinguish between the legitimate customer and a fraudster who possessed the customer's own authentication instruments.


Counsel further relied on Equity Bank (U) Ltd v Bamwite Augustine Muhindo, Civil Appeal No. 59 of 2025, submitting that a customer who loses a phone or SIM card linked to a bank account must promptly notify the bank because reporting the loss to the police or telecommunications provider alone is insufficient.


On the alleged suspicious transactions, the defendant submitted that there was no legal obligation requiring a bank to monitor or question the regularity of every customer transaction.


It was argued that the fact that transactions were unusual did not, without more, mean that the bank had breached its duty of care.


The defendant further submitted that the Flexipay registration and transaction process incorporated several security safeguards, including National Identification details, PINs, security questions, verification codes and SMS notifications.


It was therefore argued that the bank had adopted commercially reasonable security mechanisms and could not be held liable for fraud resulting from the compromise of the customer's own credentials.


Courts Findings

On the duty of Care and Liability

The Court held that the Defendant, as a bank, owed the Plaintiff a duty of care by virtue of the banker-customer relationship. This point was not in dispute. The determinative question was whether the Defendant breached that duty.


The defendant had conceded that a bank owes its customers a duty of care. The Court accordingly held that, by virtue of the banker-customer relationship, Stanbic Bank owed the plaintiff a duty to exercise reasonable skill and care in operating her account.

The Court stated;

“The defendant conceded that a bank owes its customers a duty of care.”

The Court further held;

“The plaintiff maintained an account with the defendant and by virtue of the banker-customer relationship, the defendant owed her a duty to exercise reasonable skill and care in the operation of her account.”

The central question was therefore not whether a duty existed, but whether the bank had breached that duty and consequently become liable for the unauthorised withdrawals.


The Court considered the circumstances surrounding the loss of the plaintiff's phone and the subsequent Flexipay registration. The plaintiff maintained that she had immediately reported the loss of her phones to Airtel and MTN and had also reported the matter to police. However, during cross-examination, she acknowledged that she had no evidence demonstrating that she had notified the telecommunications companies on the same day.


The Court also considered the audio recording in which the plaintiff had apparently stated that she reported the matter to police the following day. The Court noted that the police record introduced into evidence was dated 10 February 2023, several days after the alleged loss of the phone.


The Court further observed that the plaintiff remained in communication with the person who possessed the phone until 10 February 2023, which was inconsistent with her assertion that the SIM card had immediately been blocked.

The Court held

“I find that the plaintiff’s personal authentication credentials were compromised following the loss of her mobile phone.”

The Court relied on the reasoning in Aida Atiku v Centenary Rural Development Bank Limited, particularly the principle that customers have a corresponding responsibility to safeguard their banking information, user IDs, passwords and PINs.


The duty to Notify the Bank

A significant aspect of the judgment was the Court's finding that the customer's responsibilities do not end with maintaining confidentiality of banking credentials.

The Court relied on Equity Bank (U) Ltd v Bamwite Augustine Muhindo, observing:

“It is prudent for a customer of a bank who has lost his or her phone or the account registered SIM card/number to report the said loss to the bank as soon as possible.”

The Court further reiterated that:

“It is not enough for a customer to report the said loss to the police only.”

The Court distinguished the customer's responsibility to report a compromised account from the separate question of whether a customer must constantly monitor their account.


It noted that although a customer is not required to check their account every day, circumstances that compromise the security of the account create a corresponding obligation to notify the bank.

The Court therefore stated;

“With the loss of her phone, the plaintiff should have promptly notified not only her network providers but also the defendant.”

On the weight of the Audio Recording

The Defendant tendered an audio recording and transcript of an interview with the Plaintiff, in which she described the loss of her phone and ID. The Plaintiff challenged the recording's authenticity on the basis that it ended abruptly and that neither the recorder nor the transcriber testified.


The Court found that the recording had been admitted without objection at trial and that its content was not challenged in cross-examination, citing Browne v. Dunn (1894) 6 R. 67 HL for the principle that a party must challenge evidence in cross-examination if it intends to dispute it later. Applying section 7(4) of the Electronic Transactions Act, the Court found the recording reliable and gave it weight.


On the Compromise of Credentials

The Court found that the Plaintiff's authentication credentials, her phone and national ID, were compromised when she lost them on 6 February 2023. It found inconsistencies in her account of when she reported the loss to police and to her network providers, and noted evidence that she remained in contact with the person holding her phone after the date she claimed to have blocked her line. The Court held that whoever held her phone and ID was able to complete Flexipay registration and withdraw the funds using her own credentials.


The Suspicious Transaction Threshold

The Plaintiff argued that failed enrollment attempts and an unusual transaction pattern should have flagged the account for review. The Court held that the threshold for a duty to treat a transaction as suspicious is reached only where there are reasonable grounds, based on specific and clear indicators, to believe a payment instruction may facilitate fraud, citing Barclays Bank of Uganda Limited v. Eron Kabachwamba, Civil Appeal No. 10/2015. Unease or discomfort with a transaction's pattern, without more, does not meet this threshold. The Court found that validation codes and authentication messages were sent to the Plaintiff's own registered number throughout, and that the Defendant's systems functioned as designed.


On whether the transactions were sufficiently suspicious to trigger the Banks Duty

The plaintiff's argument was that the bank should have detected the transactions because they represented a dramatic departure from her normal banking pattern.

The Court acknowledged that a sudden change in transaction patterns may be an indicator of suspicious activity.

The Court noted that several validation codes had been sent between 4:53 p.m. and 5:00 p.m. on 7 February 2023 following failed attempts to enrol the plaintiff's account through Flexipay. There were also unsuccessful withdrawal attempts at 6:15 p.m. and 6:19 p.m.

The Court then considered the principle established in Aida Atiku, that financial institutions providing mobile banking services have an obligation to maintain secure digital banking systems and robust fraud-detection and prevention mechanisms.

The Court quoted the principle that banks:

“have a duty to put in place robust fraud detection and prevention solutions to protect their assets, systems and customers.”

It further noted that banks have a duty to take reasonable measures to ensure that their digital banking systems and technology remain secure and are regularly reviewed.

However, the Court found that this principle did not mean that every unusual transaction automatically imposed liability upon a bank.


UNUSUAL TRANSACTION DOES NOT AUTOMATICALLY MEAN SUSPICIOUS TRANSACTION

The Court relied on Barclays Bank of Uganda Limited v Eron Kabachwamba, Civil Appeal No. 10 of 2015, and adopted the principle that the for suspicion requires more than the mere fact that a transaction is unusual.

The Court quoted:

“The threshold of suspicion is only reached when there are reasonable grounds, based on specific and clear indicators, to believe that a payment instruction may facilitate fraud against the customer.”

The Court further noted that an unusual or abnormal transaction may create uneasiness, but:

“mere unease, perception of a risk of fraud or finding the transaction unusual or uncomfortable is insufficient to trigger the requisite care duty.”

Applying that principle to the case, the Court found that although there had been unsuccessful attempts preceding the successful transactions, those attempts, without more, were insufficient to impose a duty on the bank to treat the transactions as suspicious.

The Court therefore held:

“I have found no basis to conclude that there were any suspicious transactions which should have been flagged off by the defendant.”

Having considered the evidence and submissions, the Court concluded that the plaintiff's authentication credentials had been compromised following the loss of her phone.

However, the Court found no evidence establishing that the bank's required authentication procedures had been bypassed or that the bank had otherwise breached its duty of care.

The Court therefore stated:

“A bank owes its customers a duty to exercise reasonable skill and care in safeguarding their accounts and in processing transactions.”

However, the Court immediately qualified that principle by holding:

“where there is a compromise in a customer’s authentication credentials and no breach of the bank’s duty has been established, liability cannot be imposed on the bank merely because unauthorized transactions occurred.”

The Court consequently found:

“I find that the defendant is not liable for the unauthorized withdrawals on the plaintiff’s account.”


Holding

The court entered judgment for the Defendant:

  1. Declared the Defendant not liable for the unauthorized withdrawals on the Plaintiff's account.

  2. Dismissed the claim for a refund of UGX 68,000,000 with interest.

  3. Dismissed the claim for general damages.

  4. Dismissed the claim for interest at 21 percent.

  5. Dismissed the suit in full, with costs to the Defendant.


Key Takeaways

1. Banks are not automatically liable for losses arising from mobile banking fraud where the fraud results from a compromise of the customer's own authentication credentials, such as a lost phone or national ID.


2. A customer's duty to safeguard credentials and report their loss promptly is treated as a live obligation, not a passive one. Delay in reporting can defeat a claim against the bank.


3. Courts will not treat an unusual transaction pattern as automatically suspicious. Liability for failing to flag a transaction requires specific and clear indicators of fraud, not mere discomfort with the pattern.


4. Electronic recordings and data messages carry evidentiary weight once admitted without objection and left unchallenged in cross-examination, regardless of later attacks on their completeness.


5. Financial institutions should maintain and be prepared to produce clear evidence of their authentication and notification processes, including validation codes and SMS alerts, as proof that fraud detection systems functioned as designed.



 
 
 

Comments


LEAVE A REPLY

Thanks for submitting!

Writing in Notepad

Write for Us

Appointing New Writers

We're actively seeking passionate researchers and writers to join our team. If you're enthusiastic about sharing knowledge and contributing to our platform, we'd love to hear from you. Don't hesitate to apply – your expertise could make a significant impact on our community's learning experience.

Green Modern Real Estate Agent Linkedin Banner (1).jpg

SUBSCRIBE TO OUR NEWSLETTER

Be the first to know about our events, conferences, workshops, live training and consultations.

SUCCESSFULLY SUBSCRIBED!

Green Modern Real Estate Agent Linkedin Banner.jpg
bottom of page