MODULE 02 CBK MANDATORY FRAMEWORK

CORF Compliance
Essentials

The Central Bank of Kuwait's Cyber and Operational Resilience Framework is now mandatory for all regulated entities. This module gives financial leaders a clear, authoritative path to understanding the requirements, mapping their current state, and building a compliance roadmap — without the noise.

18 min read
Self-assessment quiz included
CBK-aligned curriculum
// LEARNING OUTCOMES
01
Understand CORF Scope
Know exactly which entities are in scope, what tiering means for your institution, and what CBK expects.
02
Map the 6 Domains
Navigate the 33 sub-domains across Governance, Technology, Third-Party, Emerging Tech, Payments, and Resilience.
03
Assess Your Maturity Level
Use the 5-level maturity scale to honestly evaluate your current state and identify gaps against CBK benchmarks.
04
Build a Compliance Roadmap
Walk away with a practical, prioritized implementation plan aligned to CBK's Statement of Applicability process.

Why CORF Exists and Who's In Scope

CORF is the Central Bank of Kuwait's response to a clear and escalating threat: financial institutions that are operationally fragile or cyber-resilient only on paper. It mandates a minimum standard of preparedness across every entity that touches Kuwait's financial system — and it comes with teeth.

// ENTITIES IN SCOPE
Licensed Banks
Domestic & foreign, conventional & Islamic
Exchange Companies
All CBK-licensed money exchange entities
Finance Companies
Consumer, SME, and specialized finance providers
E-Payment Service Providers
Payment aggregators, acquirers, wallet operators
Credit Information Companies
Credit bureaus and reference data providers
Open Banking Service Providers
APIs, fintech partners, sandbox participants
// CONSEQUENCES OF NON-COMPLIANCE
CBK applies a tier-based supervisory approach. Institutions that fail to meet CORF requirements face escalating regulatory action: supervisory engagement, enhanced monitoring, capital surcharges, operational restrictions, and in severe cases, license review. CORF compliance is not a checkbox — it is a condition of operating in Kuwait's financial market. The cost of non-compliance is measured in regulatory risk, not just fines.

The 6 Domains, 33 Sub-Domains

CORF organizes its requirements into six interconnected domains. Each domain spans multiple sub-domains, and every sub-domain has specific maturity expectations. Understanding the map is the first step to navigating the journey.

D-01
Governance, Risk & Compliance
5 sub-domains
D-02
Technology & Operations
16 sub-domains
D-03
Third-Party Risk & Supply Chain
4 sub-domains
D-04
Emerging Technologies
4 sub-domains
D-05
Payments Security
2 sub-domains
D-06
Operational Resilience
2 sub-domains
// CBK TIERING MODEL
TIER 1
Systemically Important
Domestic systemically important banks (D-SIBs) and major payment infrastructure operators. Subject to full CORF application with enhanced oversight.
Highest supervisory intensity
TIER 2
Significant Institutions
Licensed banks and finance companies above the threshold, e-payment providers processing significant volumes. Full CORF compliance required.
Standard supervisory cycle
TIER 3
Smaller / Specialized
Exchange companies, smaller finance companies, niche providers. May have proportionate application of certain requirements — verify with CBK.
Proportionate where applicable

The 6 Domains Explained

Each domain represents a distinct capability area. The largest by scope is Technology and Operations — it covers the majority of CORF's requirements. Review all six to understand where your institution's current strengths and gaps lie.

D-01
Governance, Risk & Compliance
5 sub-domains
1.1
Cyber Governance Structure
Board accountability, CISO reporting line, governance committee structure, and oversight mechanisms. Board must have dedicated cyber expertise or access to advisors.
1.2
Cyber Risk Management Framework
Risk appetite statement, risk register, risk assessment methodology, and integration with enterprise risk management. Appetite must be board-approved and reviewed quarterly.
1.3
Policy Framework & Standards
Information security policy hierarchy, standards for data classification, access control, and acceptable use. Policies must be reviewed annually and updated following material incidents.
1.4
Regulatory Compliance Management
CBK reporting obligations, CORF self-assessment cadence, regulatory change management process. Institutions must track new CBK guidelines and update compliance posture accordingly.
1.5
Security Awareness & Training
Annual cybersecurity training for all staff, role-specific training for high-risk functions (treasury, finance, IT), board-level briefings. Training completion records must be documented.
D-02
Technology & Operations
16 sub-domains — largest domain
2.1
Asset & Configuration Management
Complete inventory of IT assets, hardware and software registers, configuration baselines, and change management process. No asset should be untracked; CMDB must be updated within defined SLA.
2.2
Identity & Access Management
Role-based access control, privileged access management, multi-factor authentication for admin accounts, periodic access review cadence. Principle of least privilege enforced across all systems.
2.3
Network Security
Network segmentation, firewall rulesets, intrusion detection/prevention, secure remote access, and monitoring for unauthorized traffic. Critical assets isolated from general corporate network.
2.4
Data Security & Encryption
Encryption at rest and in transit, key management, data leakage prevention, secure disposal of media. Customer data classified and protected according to CBK data residency requirements.
2.5
Endpoint Security
Anti-malware, endpoint detection and response (EDR), patch management, device encryption. Mobile devices and personal devices used for work must meet minimum security standards.
2.6
Vulnerability Management
Regular vulnerability scanning, patch prioritization based on risk score, remediation SLAs tied to severity, and tracking of exceptions. Critical patches within 72 hours; high within 14 days.
2.7
Logging & Monitoring
Centralized log management, SIEM deployment, correlation rules, alerting thresholds, and retention meeting regulatory requirements. Logs retained for minimum 12 months for critical systems.
2.8
Security Operations Center (SOC)
24/7 monitoring capability, incident triage process, escalation matrix, and SLA for initial triage (target: under 15 minutes for critical). In-house or contracted SOC must be documented.
2.9
Business Continuity Management
BCP framework, recovery time objectives (RTOs) and recovery point objectives (RPOs) for all critical systems, backup and recovery testing. Recovery plans tested annually at minimum.
2.10
Change Management
Formal change request process, impact assessment, approval authority matrix, rollback procedures, and post-implementation review. Emergency changes documented and reviewed within 48 hours.
2.11
Incident Management
Incident classification, response playbook, notification to CBK within required timeframe (critical incidents: 24 hours), forensic preservation, and post-incident review process.
2.12
Backup & Recovery
Backup strategy (full, incremental, differential), offsite replication, encryption of backups, regular restoration testing. RPO and RTO documented per system and tested quarterly.
2.13
Patch Management
Automated patch deployment, testing in staging before production, exception tracking, patch window management. Critical patches applied within SLA with documented justification for exceptions.
2.14
Security Testing
Annual penetration testing by qualified external firm, quarterly internal penetration testing, continuous vulnerability scanning, remediation tracking, and tabletop exercises for incident response.
2.15
Capacity & Performance Management
Capacity planning, performance monitoring, degradation alerts, scaling thresholds. Critical systems must meet performance standards under normal and peak load conditions.
2.16
Application Security
Secure development lifecycle, code review, static and dynamic application security testing (SAST/DAST), OWASP Top 10 awareness, and secure coding standards for in-house and outsourced development.
D-03
Third-Party Risk & Supply Chain
4 sub-domains
3.1
Third-Party Inventory & Classification
Complete register of all third parties with access to systems, data, or processes. Classification by criticality: strategic, tactical, operational. Critical third parties tracked with enhanced monitoring.
3.2
Due Diligence & Contracting
Security assessment prior to engagement, contractual security requirements, data processing agreements (DPAs), right to audit clauses, and termination procedures. SLAs must include security obligations.
3.3
Ongoing Monitoring & Reassessment
Annual third-party security reviews, continuous monitoring for critical vendors, incident notification requirements in contracts, and reassessment triggered by material changes to service or risk profile.
3.4
Offboarding & Contract Termination
Data return and deletion procedures, access revocation process, transitional arrangements, and documentation of third-party performance for future reference. Ensure CBK data cannot be retained post-termination.
D-04
Emerging Technologies
4 sub-domains
4.1
AI / ML Governance
AI/ML usage policy, model risk management for algorithmic decision-making, bias detection, explainability requirements for automated decisions, and AI-specific incident response. CBK expects institutions to understand what AI does in their environment.
4.2
Cloud Security
Cloud service provider assessment, shared responsibility model clarity, data residency compliance, configuration hardening, and exit strategy. Institutions remain accountable for data and decisions regardless of cloud deployment model.
4.3
Blockchain & Distributed Ledger
Smart contract risk, private key management, ledger integrity, and integration with traditional financial systems. Applies to institutions experimenting with or deploying DLT-based products.
4.4
Quantum Risk Assessment
Cryptographic inventory, quantum-readiness roadmap, identification of systems using asymmetric cryptography at risk from quantum attacks, and migration planning for post-quantum cryptography standards.
D-05
Payments Security
2 sub-domains
5.1
Payment Systems Security
PCI DSS compliance for card payment environments, SWIFT customer security program (CSP) alignment, real-time fraud monitoring, transaction anomaly detection, and secure message authentication for payment networks.
5.2
Fraud & Financial Crime Controls
AML/CFT aligned controls, fraud detection models, customer due diligence for high-risk transactions, sanctions screening, and suspicious transaction reporting. Strong alignment with CBK AML/CFT guidelines required.
D-06
Operational Resilience
2 sub-domains
6.1
Business Impact Analysis
BIA methodology, RTO/RPO per business function, critical process mapping, maximum tolerable period of disruption (MTPD), and recovery prioritization. BIA reviewed annually or following material business changes.
6.2
Scenario-Based Resilience Testing
Tabletop exercises simulating cyber attack, system failure, and third-party outage scenarios. Recovery exercises for critical functions. Lessons learned documented and fed back into BCP and investment planning. CBK may request evidence of testing.

The 5-Level Maturity Scale

CORF uses a five-level maturity model to assess institutional capability. Each sub-domain is rated independently. The goal for most institutions is Level 3 (Baseline) as a minimum, with progressive movement to Level 4 or 5 based on risk appetite and regulatory expectations for your tier.

1
Initial
Ad hoc, undocumented processes. No formal controls. Reactive to incidents as they occur.
NON-COMPLIANT
2
Ad-hoc
Some documented processes, but inconsistently applied. Gaps in coverage. No systematic testing.
AT RISK
3
Baseline
Formally documented, consistently applied. Meets CBK minimum expectations. Regular self-assessments.
MINIMUM TARGET
4
Advanced
Proactive, metrics-driven. Continuous monitoring, regular penetration testing, benchmarking against peers.
STRONG POSITION
5
Innovative
Leading practice, scenario testing, industry contribution. Fully integrated with enterprise risk framework.
LEADING PRACTICE
Maturity Self-Assessment
1. Does your institution have a formal, board-approved information security policy?
2. How is your SOC coverage structured?
3. How frequently do you conduct penetration testing?
4. How are third-party risks currently managed?
// ASSESSMENT RESULT

Your CORF Compliance Roadmap

CORF adoption is not a one-time project — it is a structured, cyclical program. Use this five-step framework to approach implementation in a way that satisfies CBK and genuinely improves your security posture.

01
Inherent Risk Profiling
Map your institution's inherent risk profile — the starting point before any controls. Consider your business model, transaction volumes, customer base, technology complexity, and third-party ecosystem. This determines which sub-domains carry the highest residual risk and which deserve priority attention.
OUTPUT: Inherent Risk Register by domain and sub-domain
TIMELINE: Weeks 1–2
02
Current State Assessment (SoA)
Use CBK's Statement of Applicability template to evaluate your current maturity across all 33 sub-domains. Be honest — gaps you document now are manageable; gaps CBK finds later are regulatory findings. Involve IT, Security, Risk, Legal, and Operations in the assessment. Cross-reference with your existing ISO 27001 or SWIFT CSP work if available.
OUTPUT: SoA with current maturity score per sub-domain
TIMELINE: Weeks 3–6
03
Gap Analysis & Remediation Planning
Map the delta between current state and target maturity. Prioritize gaps using a risk matrix: likelihood of exploitation × business impact. Focus on quick wins (low effort, high impact) in the first cycle. Document all exceptions and mitigations — CBK expects to see you have a plan for every gap, even if full remediation takes time.
OUTPUT: Gap register with remediation owners, timelines, and resource requirements
TIMELINE: Weeks 7–10
04
Remediation Execution
Execute remediation in priority order. For each gap: define the control requirement, implement or enhance the control, document the evidence, and validate through testing. Where full remediation is not possible within the assessment cycle, apply compensating controls and document the justification — CBK accepts this where the rationale is sound.
OUTPUT: Implemented controls with evidence artifacts (policies, logs, reports, test results)
TIMELINE: Weeks 11–26 (6-month cycle)
05
CBK Submission & Continuous Monitoring
Submit your CORF self-assessment to CBK on the required cadence (verify your tier's cycle — typically annual for most institutions). Continuously monitor: track remediation progress, update the maturity assessment quarterly, review new CBK guidance, and run tabletop exercises to keep your team sharp. CORF compliance is a living program, not a one-time submission.
OUTPUT: CBK submission + quarterly maturity update + annual external assessment
CADENCE: Quarterly monitoring, annual submission

Training Pathways Aligned to Your Role

ThreatAce's CORF program is built for the specific needs of financial leaders — not generic cybersecurity courses. We offer two structured pathways: one for senior leadership who need to oversee and drive compliance, and one for practitioners who need to implement and assess it.

EXECUTIVE PATHWAY
Senior Cybersecurity Leadership Program
SCLP — CORF Edition
A 4-week intensive for CISOs, CTOs, CROs, and board members who need to lead CORF compliance from the top. Goes beyond technical requirements to address governance accountability, board reporting, regulatory engagement, and cyber risk appetite definition.
// WHAT YOU GET
CORF governance obligations for board members and executive leadership
Board-level cyber risk reporting: frameworks, metrics, and board-ready formats
Regulatory engagement with CBK: what to expect, how to present, what to avoid
Building the business case for cyber investment: speaking the language of the board
Scenario-based simulation: managing a CBK supervisory visit
PRACTITIONER PATHWAY
Cyber Assessor Program
CAP — CORF Certified Assessor
A 6-week program for IT security managers, risk managers, and compliance officers who will lead the CORF self-assessment process. Covers assessment methodology, evidence collection, gap analysis, and CBK reporting standards. Includes hands-on use of the CBK SoA template.
// WHAT YOU GET
CORF SoA methodology: how to score each of the 33 sub-domains accurately
Evidence collection frameworks: what CBK expects to see and how to present it
Gap analysis workshop: hands-on prioritization using a real institution case study
CBK reporting: building a submission package that meets regulatory standards
ThreatAce certification upon completion — verifiable credential for CBK record
Both programs include access to the ThreatAce CORF toolkit: SoA template, gap register, and quarterly update checklist. Module completion recorded for your institution's training log.
// ENROLLMENT

Ready to Lead Your Institution's CORF Compliance?

Whether you're starting from zero or fine-tuning an existing program, ThreatAce gives you the knowledge, tools, and confidence to navigate CORF requirements and present a credible posture to the Central Bank of Kuwait.

ENROLL IN SCLP OR CAP VIEW OTHER MODULES
SCLP: 4 weeks · CAP: 6 weeks · Both include certification and toolkit