Economy

Bank Customer Relationship: Legal Duties And Liabilities In The Era Of Electronic Fraud -By Job Joseph

While the traditional contractual principles governing the bank-customer relationship remain relevant, the emergence of electronic fraud has introduced new legal and practical challenges. Banks have a duty to exercise reasonable care, maintain secure banking systems, protect customer information, properly authenticate transactions and respond promptly to suspected fraud. Customers, on the other hand, have a responsibility to protect their banking credentials, exercise reasonable care and promptly report suspicious transactions.

Published

on

Introduction

The relationship between a bank and its customer is one of the most important commercial relationships in the financial sector. Traditionally, this relationship has been governed mainly by the principles of contract law, with the bank generally occupying the position of debtor and the customer that of creditor. Depending on the nature of a particular transaction, however, the relationship may also assume the character of agency, trust, bailment or other recognised legal relationships. Banks owe their customers several duties, including the duty to properly execute valid mandates, exercise reasonable care and skill, maintain confidentiality and protect customer funds. Customers, on the other hand, are expected to provide accurate information, comply with the terms governing their accounts and exercise reasonable care in the use of banking services.(1) The rapid development of electronic banking has significantly changed the traditional relationship between banks and their customers. Customers can now access banking services through mobile applications, internet banking, Automated Teller Machines (ATMs), Point-of-Sale (POS) terminals and USSD platforms without physically visiting a bank. While these developments have improved convenience, speed and financial inclusion, they have also created new opportunities for fraudsters. Electronic fraud now includes phishing, identity theft, unauthorised electronic transfers, SIM-related fraud, card fraud, malware attacks and social engineering.(2) The increasing incidence of electronic fraud has therefore created difficult legal questions concerning the allocation of responsibility between banks and customers. Where money is fraudulently withdrawn or transferred from a customer’s account, it becomes necessary to determine whether the bank, the customer, the fraudster or a combination of these parties should bear the resulting loss. This article examines the legal duties of banks and customers in the era of electronic fraud, the challenges associated with determining liability and the need for further development of Nigeria’s legal and regulatory framework.

Overview of the Traditional Bank-Customer Relationship

The traditional bank-customer relationship is primarily contractual. When a customer deposits money into a bank account, the ordinary relationship created is that of debtor and creditor. The bank becomes indebted to the customer for the amount deposited and is expected to repay the customer in accordance with the terms of the banking relationship.(3) The relationship may, however, take different forms depending on the nature of the transaction. A bank may act as an agent when carrying out a customer’s instructions, as a trustee in certain circumstances, or as a bailee where particular property is entrusted to it. The legal duties of the bank therefore depend not only on the existence of the banking relationship but also on the specific transaction and circumstances involved. One of the fundamental duties of a bank is to comply with the valid mandate of its customer. Where a bank makes payment or transfers funds without proper authority, it may be liable for breach of its contractual obligations. The Supreme Court in Ndoma-Egba v African Continental Bank Plc considered the liability of a bank in relation to withdrawals allegedly made through forged cheques and emphasised the importance of the customer’s mandate in determining the bank’s obligations.(4) The traditional principles governing the relationship remain relevant in modern banking. However, the introduction of electronic banking has changed the way customer mandates are created, authenticated and executed. A handwritten signature may now be replaced by a password, PIN, OTP, token, biometric authentication or other electronic security mechanism.

Development of Electronic Banking in Nigeria

Advertisement

Electronic banking has become an essential part of Nigeria’s financial system. Customers are increasingly able to transfer funds, pay bills, withdraw money and carry out other banking transactions through electronic platforms. This development has reduced dependence on physical banking halls and has made financial services more accessible to individuals and businesses. The Central Bank of Nigeria (CBN) has developed various regulatory frameworks to support the safe operation of electronic payment channels. These include regulations and guidelines relating to electronic payment channels, payment-system risk and information security management.(5) The growth of electronic banking has produced several advantages. It has improved the speed of transactions, reduced transaction costs, promoted financial inclusion and facilitated commercial activities. However, the increased dependence on digital platforms has also created significant security risks. Fraudsters now employ sophisticated methods to obtain customers’ personal and banking information. Phishing messages, fraudulent phone calls, fake bank applications, social media impersonation and other forms of social engineering are increasingly used to deceive customers. Consequently, the legal relationship between banks and customers must now take into consideration technological risks that were not contemplated when many traditional banking principles were developed.

Challenges of Electronic Fraud in the Bank-Customer Relationship

The following are some of the major challenges affecting the bank-customer relationship in the era of electronic fraud:

 

  1. Unauthorised Electronic Transactions

Unauthorised electronic transactions constitute one of the major challenges associated with electronic banking. An unauthorised transaction occurs where money is transferred from a customer’s account without the customer’s genuine authority. Such transactions may occur where a fraudster obtains a customer’s password, PIN, OTP or other authentication information. In other circumstances, the fraud may result from weaknesses in a bank’s information technology infrastructure. The legal difficulty is determining whether the mere use of a customer’s authentication credentials is sufficient to establish that the transaction was authorised by the customer. Authentication does not necessarily mean genuine consent. A fraudster may obtain a customer’s authentication credentials through deception and use them to carry out a transaction without the customer’s knowledge or intention. Where a bank fails to establish that it exercised reasonable care in authenticating and processing the transaction, it may be held responsible for the resulting loss. However, where the customer deliberately or negligently disclosed confidential security information, the customer’s conduct may also become relevant in determining liability.

  1. Duty of Banks to Exercise Reasonable Care

Banks owe their customers a duty to exercise reasonable care and skill in carrying out banking transactions. This duty becomes particularly important in electronic banking because banks control the technological systems through which electronic transactions are processed. The standard expected from banks is not necessarily one of absolute liability for every fraudulent transaction. Rather, the question is whether the bank acted with reasonable care in the circumstances. Banks are expected to maintain appropriate systems for transaction authentication, fraud detection, cybersecurity and protection of customer information. Where a bank fails to maintain reasonable security measures and such failure contributes to a customer’s loss, the bank may face contractual, regulatory or tortious consequences.(6) The CBN Consumer Protection Framework requires financial institutions to establish policies and controls to protect consumers against fraud and unauthorised access. It also emphasises the protection of customer information and the establishment of appropriate risk-management systems.(7)

  1. Inadequate Cybersecurity Measures

Cybersecurity has become an important aspect of the legal duties of financial institutions. Banks hold large amounts of financial and personal information and are therefore attractive targets for cybercriminals. A bank is expected to take reasonable measures to protect its systems against unauthorised access, data breaches and fraudulent transactions. Such measures may include multi-factor authentication, transaction monitoring, device verification, fraud alerts, access controls and other appropriate security mechanisms. The failure of a bank to implement adequate cybersecurity measures may contribute to electronic fraud. Where such failure is established, questions may arise concerning the bank’s compliance with its contractual and regulatory obligations. The CBN has recognised information security as an important aspect of the Nigerian payment system and has introduced frameworks designed to improve risk management and security in electronic payment channels.(8)

  1. Customer Negligence

Although banks have significant responsibilities in preventing electronic fraud, customers also have corresponding duties. Customers are expected to safeguard their passwords, PINs, OTPs, cards and other security credentials. They are also expected to exercise reasonable care when responding to electronic messages, telephone calls and other communications concerning their bank accounts. Where a customer voluntarily discloses confidential banking information to a fraudster, the customer’s conduct may affect the allocation of liability. For example, where a customer receives a clear warning from a bank that its employees will never request an OTP and the customer nevertheless discloses the OTP to a person claiming to be a bank employee, the bank may argue that the customer’s negligence substantially contributed to the loss. The CBN’s consumer protection framework recognises the responsibility of customers to exercise reasonable care and promptly report suspected fraud or errors.(9) However, customer negligence should not automatically relieve a bank from responsibility. The circumstances surrounding each transaction should be examined to determine whether the bank also failed in its duties.

  1. Phishing and Social Engineering

Phishing and social engineering have become major sources of electronic fraud. Fraudsters often impersonate bank officials or other trusted persons in order to persuade customers to disclose confidential information. Unlike traditional forms of hacking, social engineering attacks exploit human behaviour rather than solely technological weaknesses. The increasing sophistication of these attacks creates difficulties in determining liability. A customer may genuinely believe that he or she is communicating with a bank representative and may disclose information without realising that the communication is fraudulent. Banks therefore have an important role to play in educating customers about emerging fraud techniques. Regular customer awareness campaigns, transaction alerts and clear warnings can help reduce the incidence of fraud.

  1. Authorised Push Payment Fraud

Another emerging challenge is Authorised Push Payment (APP) fraud. In this form of fraud, the customer personally initiates the transaction but does so because he or she has been deceived by a fraudster. For example, a fraudster may impersonate a business partner and persuade a customer to transfer money to a fraudulent account. From a technical perspective, the transaction may appear to have been authorised by the customer. APP fraud creates a difficult legal distinction between an unauthorised transaction and a transaction that was authorised as a result of deception. The CBN has recognised this emerging problem and developed an exposure draft on guidelines for handling APP fraud. The proposed framework addresses issues relating to prevention, detection, reporting and resolution of APP fraud.(10) This development demonstrates the need for Nigerian banking law to move beyond the traditional distinction between authorised and unauthorised transactions.

  1. Failure to Promptly Report Fraud

The speed with which electronic transactions occur creates another challenge. Fraudulent funds can be transferred from one account to another within seconds and may subsequently be withdrawn or moved through several accounts. Prompt reporting is therefore important for preventing further loss and increasing the possibility of recovery. Customers who discover suspicious transactions should notify their banks immediately and take appropriate steps to secure their accounts. Banks, on their part, should have effective mechanisms for receiving and responding to fraud complaints. A failure by a bank to act promptly after receiving notice of fraudulent activity may increase the loss and may become relevant in determining liability.

  1. Difficulty in Recovery of Fraudulent Funds

Recovering funds lost through electronic fraud remains a major challenge. Fraudsters may rapidly transfer stolen funds to multiple accounts, withdraw cash or convert the funds into other assets. Although banks and law-enforcement agencies may take steps to trace and freeze fraudulent funds, recovery is not always successful. The difficulty of recovery highlights the importance of prevention and early detection. Effective fraud-monitoring systems and rapid inter-bank communication can increase the possibility of stopping fraudulent transactions before the funds are dissipated.

  1. Evidential Challenges

Electronic fraud disputes also raise important evidential issues. In a traditional banking dispute, documents such as cheques and physical withdrawal slips may provide direct evidence of the transaction. Electronic transactions, however, generate digital records such as transaction logs, IP addresses, device information, authentication records, OTP records and timestamps. Banks generally possess most of this information, while customers may have limited access to it. This creates an evidential imbalance between the parties. In determining electronic fraud disputes, courts must therefore carefully examine the available electronic evidence and determine whether the bank has demonstrated that the transaction was properly authenticated and authorised. The Evidence Act 2011 provides the legal framework for the admissibility of electronic evidence in Nigeria and is consequently relevant to litigation involving electronic banking transactions.

  1. Data Protection and Confidentiality

Banks have traditionally owed customers a duty of confidentiality. This duty has become even more important in the digital era because banks process substantial quantities of personal and financial information. The Nigeria Data Protection Act 2023 provides a broader legal framework for the protection of personal data in Nigeria.(11) Financial institutions must therefore ensure that customer information is processed and protected in accordance with applicable data-protection requirements. A failure to properly protect customer information may expose a bank to regulatory consequences and may also contribute to identity theft and electronic fraud.

Regulatory Framework for Electronic Banking in Nigeria

Advertisement

The regulation of electronic banking in Nigeria is governed by several statutes, regulations and regulatory guidelines. The Banks and Other Financial Institutions Act 2020 provides an important framework for the regulation and supervision of banks and other financial institutions. The Cybercrimes (Prohibition, Prevention, etc.) Act provides criminal sanctions for various cyber-related offences. The Evidence Act 2011 governs the admissibility of electronic evidence, while the Nigeria Data Protection Act 2023 regulates the processing and protection of personal data. The CBN also plays a central role in regulating electronic payment systems. Its consumer protection framework requires financial institutions to provide mechanisms for protecting customers against fraud and for resolving complaints. The CBN Consumer Protection Framework is particularly important because it recognises that financial institutions may be required to refund customers for actual losses arising from fraud, subject to circumstances including customer negligence or fraudulent conduct.(12) The regulatory framework therefore recognises a form of shared responsibility between financial institutions and customers.

Judicial Approach to Bank-Customer Liability

The Nigerian courts have traditionally placed considerable emphasis on the bank’s duty to comply with the customer’s mandate. In Ndoma-Egba v African Continental Bank Plc, the Supreme Court considered a dispute involving withdrawals allegedly made through forged cheques and examined the responsibilities of the bank in relation to its customer’s account.(13) Similarly, in Balogun v National Bank of Nigeria Ltd, the Supreme Court considered the contractual obligations arising from the banker-customer relationship and recognised the liability of a bank for failing to honour a customer’s valid mandate in circumstances where the relevant conditions had been satisfied.(14) Although these cases arose in the context of traditional banking transactions, their underlying principles remain relevant to electronic banking. The difficulty is that electronic transactions create circumstances in which it may be difficult to determine whether a transaction represents the genuine mandate of the customer. Courts will therefore increasingly have to consider technological evidence alongside traditional principles of contract, negligence and banking law.

Recommendations

To adequately improve the protection of bank customers and strengthen the legal framework governing electronic fraud in Nigeria, the following measures are recommended:

Advertisement
  1. Review of Existing Banking Laws

The relevant laws and regulations governing electronic banking should be regularly reviewed to reflect technological developments. Particular attention should be given to electronic fraud, social engineering, APP fraud, cybersecurity and digital identity.

  1. Clearer Allocation of Liability

The law should provide clearer rules for determining when a bank should bear responsibility for fraudulent transactions and when liability should rest with the customer. The determination should take into account the conduct of both parties and the circumstances of the transaction.

  1. Strengthening Cybersecurity

Banks should continue to invest in sophisticated cybersecurity systems capable of detecting and preventing unusual transactions. Regular security audits, stronger authentication mechanisms and real-time fraud monitoring should be prioritised.

  1. Improved Customer Education

Banks and the CBN should intensify public awareness campaigns on phishing, OTP fraud, social engineering, SIM-related fraud and other emerging forms of electronic fraud.

  1. Faster Fraud Reporting and Response

Banks should establish efficient mechanisms through which customers can immediately report fraudulent transactions. Once a report is received, appropriate steps should be taken promptly to restrict further movement of the funds.

  1. Improved Inter-Bank Cooperation

Financial institutions should strengthen cooperation and information sharing concerning suspected fraudulent transactions. A coordinated system for rapidly freezing and tracing fraudulent funds would improve the chances of recovery.

  1. Protection of Customer Data

Banks should strengthen their systems for protecting personal and financial information and ensure compliance with the Nigeria Data Protection Act 2023.

  1. Development of Specific APP Fraud Regulations

Given the increasing use of social engineering, specific rules governing Authorised Push Payment fraud should be developed and implemented. Such rules should provide a clear procedure for determining responsibility among banks, customers and other payment-service providers.

  1. Strengthening Consumer Redress Mechanisms

The existing complaint and dispute-resolution mechanisms should be made more accessible and efficient. Customers should not be subjected to unnecessary delays before receiving appropriate redress where a bank is responsible for an electronic fraud loss.

  1. Promotion of Local Cybersecurity Capacity

Nigeria should encourage the development of local cybersecurity expertise within the financial sector. Greater investment in cybersecurity research, artificial intelligence and fraud-detection technologies would reduce dependence on foreign solutions and improve the resilience of the Nigerian banking system.

Conclusion

The relationship between banks and their customers has undergone significant transformation as a result of the rapid development of electronic banking. While the traditional contractual principles governing the bank-customer relationship remain relevant, the emergence of electronic fraud has introduced new legal and practical challenges. Banks have a duty to exercise reasonable care, maintain secure banking systems, protect customer information, properly authenticate transactions and respond promptly to suspected fraud. Customers, on the other hand, have a responsibility to protect their banking credentials, exercise reasonable care and promptly report suspicious transactions.

The determination of liability should therefore not be based on a rigid rule that automatically places responsibility on either the bank or the customer. Each case should be examined according to its particular circumstances, including the security measures adopted by the bank, the conduct of the customer, the nature of the fraudulent transaction and the response of the bank after the fraud was reported. The increasing development of electronic banking requires a corresponding development of Nigerian banking law. Clearer rules on unauthorised transactions, customer negligence, APP fraud, cybersecurity and consumer redress would reduce uncertainty and promote confidence in electronic banking. Ultimately, the objective should be to establish a balanced legal framework in which banks are held accountable for risks that they are reasonably capable of preventing, while customers are held responsible for losses substantially caused by their own negligence or misconduct. Such an approach will strengthen consumer protection, encourage investment in cybersecurity and contribute to the development of a safer and more reliable digital financial system in Nigeria.

 

Footnotes

Advertisement
  1. Central Bank of Nigeria, Consumer Protection Framework, 2016, particularly provisions dealing with the rights and responsibilities of consumers and financial institutions.
  2. Central Bank of Nigeria, Nigeria Electronic Fraud Forum (NeFF), noting the growth of electronic payment channels and the corresponding increase in electronic fraud.
  3. Foley v Hill (1848) 2 HLC 28; see also E P Ellinger, E Lomnicka and C Hare, Ellinger’s Modern Banking Law, 5th edn (Oxford University Press 2011).
  4. Ndoma-Egba v African Continental Bank Plc (2005) SC 40/2001.
  5. Central Bank of Nigeria, Guidelines on Operations of Electronic Payment Channels in Nigeria, 2020; Central Bank of Nigeria, Guidelines on Nigerian Payments System Risk and Information Security Management Framework, 2020.
  6. United Bank for Africa Plc v Jargaba (2007) 11 NWLR (Pt 1045) 247.
  7. Central Bank of Nigeria, Consumer Protection Framework, 2016.
  8. Central Bank of Nigeria, Guidelines on Nigerian Payments System Risk and Information Security Management Framework, 2020.
  9. Central Bank of Nigeria, Consumer Protection Framework, 2016.
  10. Central Bank of Nigeria, Exposure Draft: Guidelines for Handling Authorised Push Payment Fraud, 2025.
  11. Nigeria Data Protection Act 2023.
  12. Central Bank of Nigeria, Consumer Protection Framework, 2016.
  13. Ndoma-Egba v African Continental Bank Plc (2005) SC 40/2001.
  14. Balogun v National Bank of Nigeria Ltd (1978) NGSC

 

Job Joseph, DL, LL.B(Hons)

ABU Zaria

Leave a Reply

Your email address will not be published. Required fields are marked *

Exit mobile version