top of page

Who Is Liable When Digital Banking Goes Wrong? What Banks and Customers Need to Know


Who Is Liable When Digital Banking Goes Wrong? What Banks and Customers Need to Know

What Nakku Joweria v Stanbic Bank Settles, and What It Leaves Open

Case Commentary | Banking Law | Digital Banking Fraud

Nakku Joweria v Stanbic Bank (U) Limited, Civil Suit No. 197 of 2024, High Court of Uganda at Kampala, Commercial Division (Dr. Ginamia Melody Ngwatu Ag J, 3 August 2026)

 

Ugandan courts have now decided several cases involving digital banking fraud, including Aida Atiku, Bamwite, Kabachwamba and Rukidi Gabigogo. A general approach is beginning to emerge.


So far, the courts have focused mainly on two questions: Did the customer compromise her own banking credentials? And did she report the loss to the bank quickly enough? Those are important questions, and in the cases decided so far, they have produced defensible results. But they leave a harder question largely unanswered: What must a bank prove about its own systems before it can say that the customer’s carelessness caused the loss?


Nakku Joweria v Stanbic Bank is the latest case to apply the existing approach. It is also the latest case to avoid that question. The facts were, Joweria lost her phone, with her national ID reportedly inside the phone case. Within 24 hours, fraudsters used her details to enrol her dormant savings account on FlexiPay and withdraw UGX 68 million through a series of unauthorised transactions on 7 and 8 February 2023. The money was sent to numbers the account had never previously transacted with.

Joweria did not notify Stanbic that she had lost her phone until a month later. The court dismissed her claim.


The result is understandable. But the reasoning leaves an important issue unresolved. The court established that Stanbic’s authentication process had been followed and that Joweria had failed to report the loss promptly. It did not ask whether the bank’s fraud detection systems should have identified the transactions anyway.

That distinction is that a bank can correctly authenticate a transaction and still fail to detect that the transaction is suspicious.


This commentary looks at that gap.


So What did the Court Decide?

Three findings were central to the court’s decision.


First, the customer’s banking details had been compromised.

Joweria lost her phone, and her national ID was at the back of it. The person who obtained the phone was therefore able to use information connected to her to enrol the account on FlexiPay and make the withdrawals.


Following Aida Atiku v Centenary Rural Development Bank, the court treated the protection of banking credentials as the customer’s responsibility. Where a customer allows another person to obtain the information needed to access an account, that can count heavily against the customer.

Second, she did not tell the bank about the lost phone.


This was perhaps the clearest problem with her case. Following Equity Bank v Bamwite, the court held that reporting the loss to the police is not enough. The bank itself must be informed, and it must be informed promptly. Joweria waited about a month. By the time Stanbic was notified, the money had already been withdrawn. That delay made it difficult for her to argue that the bank should bear responsibility for a loss that could potentially have been stopped much earlier.


Third, the bank’s authentication process had been followed.

Stanbic’s evidence showed that verification and authentication codes had been sent to Joweria’s registered phone number. The person using the phone was therefore able to complete the required authentication steps and carry out the transactions. The court treated this as evidence that the bank’s security process had worked as designed.

But there is an important distinction here.

Authentication asks whether the person making the transaction has the credentials required to make it. Fraud detection asks whether the transaction itself looks suspicious.


A person who steals a phone may be able to pass an authentication check. That does not necessarily mean the resulting transactions should look normal to the bank.

 

One factual inconsistency in the judgment

There is also an inconsistency in the judgment that is worth noting. The court’s own account of the pleaded facts says that there were seventeen unauthorised transactions. But the parties’ submissions, repeated three times in the judgment, refer to twenty-eight transactions. The judgment never explains the difference, and its final decision does not settle the figure.


That matters because the number and pattern of transactions are relevant to the question of whether the activity should reasonably have appeared suspicious.

Whether an account made seventeen or twenty-eight unusual withdrawals in a short period is not a minor detail when the court is considering whether there were “reasonable grounds” for the bank to suspect fraud.

 

What about the dormant account?

Joweria also argued that the withdrawals should have triggered the bank’s fraud controls because they were highly unusual for the account. The account had apparently been dormant or very lightly used. But it suddenly became active, was enrolled on a digital platform, and was then used for a series of withdrawals to numbers the account had never dealt with before.


The court considered this argument against the standard set in Barclays Bank v Kabachwamba: a bank does not have to treat every unusual transaction as suspicious. There must be specific and clear indicators giving reasonable grounds for suspicion. The court found that the failed enrolment attempts preceding the withdrawals were not enough, by themselves, to meet that threshold.


There were also serious problems with Joweria’s credibility. She gave inconsistent accounts about when she reported the matter to police and about whether she had lost her national ID. The court had a recording of an interview in which her account appeared to conflict with her evidence in court. That recording had been admitted without objection and was put to her during cross-examination.


Under the rule in Browne v Dunn, a party generally cannot wait until submissions to challenge evidence that was not properly challenged when it was given.

Taken together, the delay, the compromised credentials and the credibility problems made Joweria’s case difficult. The court therefore had a straightforward basis for dismissing the claim. But that leaves the more difficult question untouched.

 

2. The Question the Court Did Not Answer

The problem with Nakku is not necessarily its result. It is what the court did not need to decide in order to reach that result. The clearest example comes from another Commercial Division decision in Abacus Parenteral Drugs v Stanbic Bank.

That case shows that responsibility for a digital banking loss does not necessarily have to fall entirely on either the customer or the bank. In Abacus, the customer’s own internal controls were seriously defective. One employee was allowed both to initiate and approve payments. The court described this as gross negligence. But the bank was still held responsible for 20% of the loss.


Simply because the bank’s online banking system had failed to flag a suspicious pattern. The same account was receiving repeated payments under different, apparently false names. The significance of Abacus is therefore bigger than its facts. It shows that the Commercial Division has already accepted the possibility that both sides can contribute to a digital banking loss and that responsibility can be shared.

Nakku does not discuss that possibility.


Instead, the case effectively treats liability as an either-or question: either Joweria’s compromised credentials explain the loss, or the bank is responsible. Abacus suggests that there may be a third possibility: The customer’s conduct contributed to the loss, but the bank’s systems also failed to respond to something they should reasonably have detected.


Nakku never explains why that possibility did not arise.

 

Who has to prove what?

The cases do not appear to speak with one voice about who has to prove what when a customer says a bank’s security system failed. Most of the earlier cases focus on what the customer did after her credentials were compromised. Atiku, Bamwite and Kabachwamba are largely concerned with questions such as whether the customer protected her credentials and whether she reported the fraud promptly.


Equity Bank v Birungi approaches the issue from an earlier point. It asks what the bank had done before the disputed transaction occurred. Under Birungi, the bank must first show that the customer was properly enrolled on the relevant banking service and that the risks associated with that service had been properly explained. Only then does the question of the customer’s conduct become central.


After that first hurdle, the bank may also have to produce evidence showing how the disputed transaction was authenticated. That can include evidence such as the device used, the one-time passwords sent and used, the internet address from which the request originated, and other technical information connecting the transaction to the customer.


But Stanbic Bank v Rukidi Gabigogo takes a different approach to the burden of proof. There, the court held that once a security breach occurs at an ATM, the customer bears the burden of showing that the bank was negligent.

So there is a real question here; When a customer says, “I did not make this transaction and the bank’s systems should have detected it,” who has to prove what?

Does the customer first have to prove that the bank’s system failed? Or must the bank first show that the customer was properly enrolled, properly informed and that the transaction was properly authenticated?


Nakku does not resolve the conflict.


Interestingly, Rukidi Gabigogo is cited in the judgment, but only for the separate proposition that a bank must follow its customer’s instructions. The court does not address the burden-of-proof issue from that case. Birungi is not discussed at all. That is interesting because Birungi was decided only six weeks before Nakku. The court therefore had an opportunity to clarify which approach should govern digital banking disputes. It did not have to do so because Joweria’s own conduct provided an easier route to dismissal.

 

Why the difference matters

The difference between the two approaches becomes important when the customer’s own evidence is much stronger. Imagine a customer who never lost her national ID; reports the stolen phone to the bank immediately; never gave anyone her PIN or password; denies making the transactions; and can show that the account suddenly became active and began sending large sums to unfamiliar recipients.


Under a rule that places the burden primarily on the customer, that person may have to prove what went wrong inside the bank’s systems, something the customer may have no practical way of knowing. Under the approach in Birungi, the bank may first have to produce evidence showing how the customer was enrolled, what she agreed to, how the transaction was authenticated and what technical information connects her to it.


That could make a substantial difference.


It might still produce a result in favour of the bank. But at least the bank would have to explain what happened inside its own system. Nakku does not require that explanation.

 

3.  Authentication Is Not the Same as Fraud Detection

This is perhaps the most important point in the case. Nakku relies on the proposition from Aida Atiku that banks must maintain robust fraud detection systems. But there is a problem with how that proposition has developed in the cases. Atiku did not really test what fraud detection means in practice.


The bank in that case produced evidence showing that the customer’s SIM was linked to the relevant USSD service and that transaction alerts had been sent. It also traced the transactions to the customer’s credentials. That proves something important: the system authenticated the transactions. But it does not necessarily prove that the system was capable of detecting unusual behaviour. Those are different functions.

Authentication asks

Does this transaction have the credentials required to go through?”

Fraud detection asks:

Even though the credentials appear valid, does this transaction look so unusual that we should stop it or investigate it?”.

 

Kabachwamba takes the idea further

Barclays Bank v Kabachwamba is important because it actually discusses what robust fraud detection can involve.

The court referred to security measures such as data encryption; secure APIs; multi-factor authentication; and behavioural biometrics.

Behavioural biometrics are particularly important.


The idea is not simply to check a password or one-time code. The system learns patterns in how a customer normally uses the service and can identify behaviour that looks different. For example, a system might notice that a customer who normally makes small payments suddenly logs in, navigates through unfamiliar parts of the platform and attempts several large transfers to new recipients within a short period. That is much closer to actual fraud detection. It is also very different from simply sending an OTP to the customer’s phone.

 

What did Kabachwamba actually prove?

There is a complication. The fraud-monitoring system discussed in Kabachwamba, Falcon, was described as behavioural biometric software used for debit cards. And even there, its performance was not perfect. The system generated a flag, but the bank did not immediately reach the customer. Contact happened the following day when the customer happened to visit a branch for an unrelated reason. So even Kabachwamba does not establish exactly what a good mobile-banking fraud detection system must do. Yet Nakku adopts the Kabachwamba test for when a transaction should count as suspicious without asking the equally important question:

 

What fraud detection system did Stanbic actually have on FlexiPay?

The judgment does not show evidence from a systems analyst explaining that FlexiPay monitored behavioural patterns.

  1. It does not establish that the system could identify unusual activity on a dormant account.

  2. It does not establish whether it monitored repeated failed enrolment attempts.

  3. It does not establish whether it monitored sudden large withdrawals to previously unknown numbers.

  4. And it does not establish whether the system had any form of behavioural biometrics or comparable real-time anomaly detection.


In other words, the court decided that the bank did not have enough reason to treat the transactions as suspicious without first establishing in detail what the bank’s system was actually designed to detect.


That is the gap.

 

4. The Dormant Account Problem

The facts of Nakku make this issue particularly interesting. A dormant or rarely used account suddenly became active. The account was enrolled on FlexiPay. There were failed attempts before the successful enrolment. Large sums were then withdrawn within a short period. The money went to numbers the account had not previously dealt with. That is not the same thing as a normal customer making an unusual transaction once. It is a pattern.


The unanswered question is whether a modern digital banking system should be expected to recognise that pattern.

  1. Should a dormant account suddenly becoming active trigger a review?

  2. Should repeated failed enrolment attempts matter?

  3. Should several large transactions in quick succession trigger a warning?

  4. Should payments to entirely new recipients be treated differently?

  5. Should several of these events occurring together trigger a stronger response than any one of them would trigger on its own?

Nakku does not answer these questions. And that is understandable on its facts because Joweria’s month-long delay and the problems with her evidence meant that the court could dispose of the case without going there. But the next case may not be so easy. Imagine the same facts, except that the customer reports the stolen phone immediately. Imagine further that the bank’s records show the same sequence: failed enrolment attempts, sudden activation of a previously dormant account, unusually large transfers and unfamiliar recipients.


At that point, the question cannot simply be whether the customer protected her credentials. The question becomes whether the bank’s system should have recognised what was happening.

That is the question Uganda’s digital banking cases have not yet properly answered.

 

5. What This Means

The courts are gradually building a framework for digital banking fraud.

Atiku, Bamwite, Kabachwamba, Rukidi Gabigogo and now Nakku Joweria establish several important principles.

  1. Customers must protect their banking credentials.

  2. Customers must report suspected fraud or the loss of a device promptly.

  3. Banks are entitled to rely, to some extent, on properly authenticated transactions.

But there is another side to the relationship.


Banks are not merely passive processors of whatever instructions arrive through their systems. They operate increasingly sophisticated digital platforms and are expected to maintain fraud detection and security controls.

That part of the law is much less settled. There are at least three unresolved questions.

1. Who bears the burden of proof?

Gabigogo and Birungi appear to point in different directions about what the customer must prove and what the bank must prove.

2. Can liability be shared?

Abacus shows that the Commercial Division can divide responsibility where both the customer’s controls and the bank’s systems contributed to the loss.

Nakku does not say whether that approach applies to this kind of digital banking fraud.

3. What does “robust fraud detection” actually require?

Kabachwamba gives some clues, including behavioural monitoring and anomaly detection. But it does so in the context of card technology.

Nakku does not establish whether comparable standards apply to mobile banking, or what a bank must actually demonstrate to show that its mobile platform meets them. These questions determine who pays when a customer does everything reasonably expected of her and a fraudster still manages to get through.

 

6.  One Lesson Nakku Does Settle

For customers, there is one practical lesson that is now difficult to dispute: If your phone is lost or stolen, tell your bank immediately. Do not assume that reporting to the police is enough. Bamwite established that principle, and Nakku applies it clearly. Joweria waited about a month before notifying Stanbic. That delay severely weakened her claim and allowed the court to decide the case without having to examine the bank’s fraud detection system in any depth. There is, however, one further issue that Nakku leaves unexplored.


The relevant banking guidelines require financial service providers to maintain a 24-hour telephone line through which customers can report matters such as lost cards or suspected fraud. If prompt reporting is so important to the allocation of risk, it is reasonable to ask whether the bank should also have to show that the reporting channel was available and usable. The judgment does not appear to establish whether Stanbic proved that such a line existed, whether it was reachable, or whether Joweria could reasonably have used it when her phone was lost.

That does not excuse a month-long delay.


But it illustrates the larger point: responsibility for digital banking fraud cannot sensibly be analysed only by asking what the customer did. The bank’s systems, warnings, authentication procedures, fraud monitoring and reporting channels are part of the same security system.

 

Conclusion

Nakku Joweria v Stanbic Bank is an important decision, but it settles less than its outcome might suggest. It confirms that a customer who loses control of her banking credentials and then waits a month to notify the bank may struggle to recover a resulting loss. It also confirms that a bank may rely on the fact that its authentication procedures were followed.

But it does not settle what happens when a customer reports promptly.

  1. It does not settle who bears the burden of proving whether the bank’s systems failed.

  2. It does not settle whether a bank must first prove proper enrolment and risk disclosure before relying on the customer’s negligence.

  3. It does not settle whether the loss can be divided between the bank and customer where both contributed to it.

  4. And it does not tell us what “robust fraud detection” actually requires from a mobile-banking platform.


A bank can authenticate a transaction correctly and still miss a fraud. The real test for the next case may therefore not be simply “Who had the password?

It may be; “Given everything the bank knew about this account and this transaction, should its systems have realised that something was wrong?” However, the decision of Nakku leaves that question open.



Comments


LEAVE A REPLY

Thanks for submitting!

Writing in Notepad

Write for Us

Appointing New Writers

We're actively seeking passionate researchers and writers to join our team. If you're enthusiastic about sharing knowledge and contributing to our platform, we'd love to hear from you. Don't hesitate to apply – your expertise could make a significant impact on our community's learning experience.

Green Modern Real Estate Agent Linkedin Banner (1).jpg

SUBSCRIBE TO OUR NEWSLETTER

Be the first to know about our events, conferences, workshops, live training and consultations.

SUCCESSFULLY SUBSCRIBED!

Green Modern Real Estate Agent Linkedin Banner.jpg
bottom of page