
Stanbic Bank Kenya has been ordered to refund a customer Sh511,000 after a court found that weaknesses in its customer verification and digital onboarding systems enabled fraudsters to access and drain his account.
In a judgment that underscores the importance of stringent Know Your Customer (KYC) controls, the Small Claims Court held that the bank’s self-registration process for its OMNI digital banking platform failed to provide adequate safeguards when activating a new digital channel on an existing account.
The court in a judgment on August 25, ruled that banks have a duty of care to ensure significant changes to customer accounts, such as the activation of internet or mobile banking services, are subjected to robust identity verification.
“The loss would have been prevented if the bank had a robust verification process for new digital profiles. The delay in reporting does not excuse the bank’s structural negligence,” the court said.
Evidence showed that James Njoroge was robbed on July 13, 2025, and lost his mobile phone, identity card and other personal documents. Within hours, fraudsters used the stolen items to create a digital banking profile linked to his account and transferred more than Sh1 million.
Court records show that at 2.48 pm on the fateful day, a new OMNI profile was registered on the account. Between 3.09 pm and 3.25 pm, three transactions totalling Sh1,001,000 were processed.
The theft was reported to the bank by Mr Njoroge’s wife at 5.19 pm, after which the account was restricted. The bank later recovered Sh490,000 from a recipient account and credited it back to the customer.
Mr Njoroge, a customer of the bank for more than 10 years, told the court that he had never enrolled for mobile or internet banking and preferred conducting all his transactions physically at the branch.
He argued that the bank fundamentally altered the nature of his account relationship by allowing a stranger to activate a powerful digital banking channel, using only information contained in his stolen documents and a one-time password (OTP) sent to his stolen phone.
According to the court, the bank’s registration process relied on information such as a national identity card number, date of birth, account number and OTP authentication.
The court found that these checks fell short of the level of verification expected when introducing a new digital access channel.
“The information provided 10 years ago to open a physical account is the same information that the fraudster now possesses. It does not serve as a robust verification for a new and powerful channel,” the court said.
The court noted that banks are expected to implement stronger KYC and customer due diligence measures, including mechanisms capable of independently verifying the identity of a person seeking to activate digital banking services.
The court observed that a previously offline account with no history of digital activity was suddenly enrolled on the OMNI platform and used to transfer over Sh1 million within 16 minutes.
“Large, rapid transfers to a new, unrelated account after the activation of a digital profile on a previously dormant account are exactly the kind of red flags that a reasonably competent bank should have systems in place to detect and halt,” the court said.
Stanbic argued that the transactions were authenticated using the customer’s credentials and that it could not have known they were fraudulent. The bank also blamed Mr Njoroge for failing to report the robbery promptly, noting that nearly 11 hours elapsed between the robbery and notification.
However, the court rejected the argument, finding that Mr Njoroge had been robbed, drugged and incapacitated, and that his wife reported the matter as soon as reasonably practicable.
The court directed the lender to pay Mr Njoroge Sh511,000, together with interest at 12 percent per annum from the date the suit was filed.
The judge further held that reliance on a “closed-loop” SMS OTP system was commercially unreasonable given the well-known risks associated with stolen mobile phones and SIM cards.