Digital Mandate vs Banker's Care: Navigating Liability for Compromised Credentials in the Age of Mobile Banking.
Nakku Joweria v Stanbic Bank (U) Limited HCCS No. 197 of 2024 [2026] UGCommC 368 Judgement by Hon Lady Justice Dr. Ginamia Melody Ngwatu, Dated 3rd August 2026.
Related practiceBrief facts
The Plaintiff, Nakku Joweria, a long-standing customer of Stanbic Bank (U) Limited (the Defendant) since 2001, brought this suit alleging a breach of the banker-customer duty of care.
The dispute arose from seventeen unauthorized transactions occurring between the 7th and 8th of February 2023, resulting in the withdrawal of UGX 68,000,000 from her savings account. These withdrawals were facilitated through the Defendant’s "Flexipay" digital banking platform using four unknown Airtel mobile lines.
The Plaintiff contended that she never enrolled for the Flexipay service and that the sudden, high frequency withdrawals from her previously dormant-style account should have triggered Defendant’s detection systems.
Conversely, the Defendant asserted that the Plaintiff had lost her mobile phone and personal identification details on February 6, 2023, which were subsequently utilized by third parties to enroll her in the Flexipay service via USSD and the mobile application.
The Defendant argued that the Plaintiff failed to notify the bank of the loss of her credentials until March 6, 2023, nearly a month after the loss, thereby breaching her reciprocal duty to safeguard her authentication details.
Issues determined by Court
Court determined three issues;
Whether the Defendant owed a duty of care towards the Plaintiff as their customer.
Whether the Defendant is liable for the unauthorized withdrawals on the Plaintiff’s account.
What remedies are available to the parties.
The law relied on
The Court’s decision was grounded on a combination of statutory provisions and established judicial precedents. Primarily, the Court applied Section 7(4) of the Electronic Transactions Act to evaluate the evidential weight and authenticity of the electronic records presented, including the audio recordings and transcripts of the Plaintiff’s interview.
Additionally, Regulation 22 of the Interception of Communications Regulations 2023 was referenced concerning the legal obligation of individuals who lose their SIM cards to provide immediate notification to their telecommunications providers.
Regarding judicial precedents, the Court relied heavily on the principles articulated in Aida Atiku v Centenary Rural Development Bank Ltd (CS 754/2020), which underscores the customer’s responsibility to maintain the confidentiality of banking information and digital credentials. This was reinforced by the ruling in Equity Bank (U) Ltd v Bamwite Augustine Muhindo (CA 59/2025), establishing that reporting a loss to the police alone is insufficient to discharge a customer's duty to the bank.
Furthermore, the Court cited Barclays Bank of Uganda Ltd v Eron Kabachwamba (CA 10/2015) to define the threshold for suspicious transactions and Stanbic Bank (U) Ltd v Moses Rukidi Gabigogo (CA 28/2023) regarding the bank’s duty to obey a customer’s mandate.
The Ruling
The Court ruled in favor of the Defendant on all substantive issues. While the Judge acknowledged that the Defendant owed the Plaintiff a duty of care by virtue of the banker customer relationship, it was held that this duty was not breached.
The Court found that the unauthorized withdrawals were made possible because the Plaintiff’s personal authentication credentials (her phone and national ID) were compromised and not promptly reported to the bank.
The Judge observed that the Defendant’s Flexipay platform utilized commercially reasonable security measures, including PINs and SMS verification codes. Since the transactions were authenticated using the Plaintiff's registered details, and the bank had not been notified of the security breach, the bank was acting within its mandate to honor the payment instructions.
The Court further noted that the Plaintiff failed to provide evidence that she had notified the telecommunications providers on the day of the theft, and her delay in informing the bank until a month later was the proximate cause of the loss.
Principles highlighted in the case.
The judgment reinforces several critical principles regarding digital banking and the banker-customer relationship:
Reciprocity of Duty: While a bank owes a duty to safeguard a customer's funds, the customer owes a reciprocal duty to maintain the confidentiality of their authentication credentials (PINs, passwords, and IDs).
Notification Requirement: In the event of a security compromise (such as the loss of a linked mobile device), the customer is legally obligated to notify the bank immediately. Reporting to the police or telecommunications providers is necessary but insufficient to discharge the customer's duty to the bank.
Authentication and Mandate: A bank is generally protected when it acts upon payment instructions that are correctly authenticated using a customer’s established credentials, provided the bank has no prior notice of a compromise.
Threshold of Suspicious Transactions: The mere fact that a transaction is unusual or high frequency does not automatically impose a duty on the bank to block it, unless there are specific and clear indicators of fraud that override the bank's primary duty to obey the customer's mandate.
Evidential Weight of Electronic Records: Under the Electronic Transactions Act, electronic records (like audio recordings of interviews) carry significant weight if they are shown to be reliable and are not materially challenged in cross examination.
The Judge's Disposition.
Court found that the Plaintiff was not entitled to any of the reliefs sought, including the refund claimed, general damages or interest.
Disposition: The suit was dismissed with costs awarded to the Defendant.
Practical Commercial Takeaways
For Commercial Banks.
Adherence to Commercially Reasonable Standards: Banks should ensure that their digital platforms (like USSD and mobile apps) utilize multi-factor authentication (MFA). The Court’s acceptance of Flexipay’s security protocols suggests that following industry-standard MFA provides a robust defence against claims of negligence.
Audit Trails and Evidence Preservation: Banks must maintain comprehensive logs of all digital interactions, including validation code transmissions and registration attempts. The ability to present clear, unaltered electronic evidence (e.g., audio recordings of customer disputes) is vital for successful litigation.
Review of Terms and Conditions: Banks should explicitly outline the customer's duty to protect their linked mobile devices and credentials in their account opening documents. The "immediate notification" requirement should be highlighted as a condition precedent for bank liability in fraud cases.
Fraud Detection vs. Customer Mandate: While fraud detection is important, banks should be aware that the legal threshold for "suspicious" transactions is high. Over-blocking based on mere "unease" may conflict with the primary duty to obey a properly authenticated customer mandate.
For Bank Customers
Immediate Reporting is Paramount: In the event of a lost or stolen mobile device linked to a bank account, the user must notify the bank immediately. Relying on reports to telecommunications providers or the police is legally insufficient to protect the user from liability for unauthorized withdrawals.
Physical Security of Credentials: Users must recognize that their mobile phone and national ID are effectively the "keys" to their digital bank accounts. Compromise of these physical items, combined with a failure to report the loss, shifts the financial risk of fraud entirely to the user.
Record Keeping: When a security breach occurs, users should keep meticulous records (dates, times, and reference numbers) of all notifications made to banks and service providers. The lack of proof regarding timely notification can be fatal to a legal claim for recovery.
Account Monitoring: Even for "dormant" or low-activity accounts, users should ensure their registered contact details (mobile numbers) are current to receive real-time alerts and verification codes.