Wakilii

Abacus Parenteral Drugs Limited v Stanbic Bank (U) Limited (Civil Suit 322 of 2022)

High Court · [2025] UGCOMMC 58 · 2025 Judgment for Plaintiff (Partial) AI-generated summary ↓ Download Pin to watchlist Add to matter
Jurisdiction
Uganda
Case Type
First instance civil suit for negligence, breach of contract and breach of statutory obligations arising from unauthorised online banking transactions
Decision
Judgment entered partially in favour of the plaintiff with recovery of 20% of proven erroneous payments due to contributory negligence

Observed later treatment

Cited — treatment unverified cited in 1 (treatment unverified) Sequitur — Uganda’s citator · Derived from citing cases in the Wakilii corpus — not an assertion that this case is good law.

Citator coverage is limited to judgments in the Wakilii corpus and source-matched treatment records. Absence of a signal is not an assertion that the case remains good law.

No adverse treatment recorded Cited 1 time with no adverse treatment recorded; not yet tested on the merits. Derived from citing cases in the Wakilii corpus — a deterministic signal, not legal advice.

AI-generated summary. This summary was generated by AI from the full text of the judgment. It may contain errors or omissions—always read the source judgment before relying on it.

Holding

The court held that the defendant bank breached its contractual obligation under the online banking services agreement by failing to reject incorrect payments where beneficiary account names did not match account numbers. However, the plaintiff was found 80% contributorily negligent for merging the initiator and authoriser roles in one person, failing to maintain internal controls, and not detecting anomalies for three years. The plaintiff recovered only 20% of the proven erroneous payments (UGX 339,556,644 out of UGX 1,697,783,222).

Outcome

Judgment entered partially in favour of the plaintiff with recovery of 20% of proven erroneous payments due to contributory negligence

Facts

The plaintiff held an account with the defendant bank and obtained online banking services in 2010. Between November 2015 and March 2018, UGX 1,697,783,222 was transferred from the plaintiff's account to accounts held by one Hope Kabajjungu using incorrect beneficiary names (names of various service providers that did not match the actual account holder). The plaintiff had initially designated two employees for the online system: one to initiate transactions and another to authorise them. However, after the authoriser left in 2015, one employee (Mr. Buyemba) assumed both roles. The plaintiff discovered the erroneous payments during an audit and sued for negligence and breach of contract. The defendant argued the online system was a straight-through process where validation was the customer's responsibility and that the plaintiff was contributorily negligent.

Issues

  1. Whether the defendant breached the banker-customer relationship?
  2. Whether the plaintiff was contributorily negligent and if so to what extent?
  3. What remedies are available to the parties?

Orders

  • The defendant to pay the plaintiff the sum of UGX 339,556,644.
  • Interest awarded on the above amount at 18% per annum from the date of filing the suit till full payment.
  • Each party to bear its costs.

Rules and key headnotes

Online Banking — Bank's Duty to Reject Incorrect Payment Instructions
Under an online banking services agreement, where the bank expressly undertakes to reject instructions including payments that are incorrect or incomplete, the bank breaches its contractual obligation when it processes payments where the beneficiary account name does not match the beneficiary account number, particularly where both accounts are held within the same bank and the bank has internal capacity to verify the discrepancy.
Banker-Customer Contract — Duty of Care in Electronic Transactions
A bank has a duty to exercise reasonable care and skill in performing its mandate under a bank-customer contract. In matters of electronic transactions, this duty extends to taking reasonable measures to ensure that digital banking systems are secure, regularly reviewed and updated, and have sufficient security features including fraud detection mechanisms to flag repeated use of the same account numbers in the names of different beneficiaries.
Limitation of Liability Clauses — Strict Construction
A limitation of liability clause in a banking contract that purports to exclude liability for losses arising from fraud or incorrect payments must be strictly construed. Where such a clause is expressly limited to circumstances where the customer has not enforced electronic transactional limits, it does not apply where no evidence is led regarding failure to enforce such limits.
Contributory Negligence — Customer's Duty to Maintain Internal Controls
A customer using online banking services is contributorily negligent where it breaches its contractual obligation to maintain appropriate internal controls by merging the initiator and authoriser roles in a single individual, thereby removing the system of checks and balances, and fails to detect anomalies in account statements for three years despite having online access to statements and conducting monthly reconciliations.
Contributory Negligence — Apportionment of Loss in Fraud Cases
Where both a bank and its customer are in breach of their contractual obligations and negligent in their respective duties of care, losses attributable to fraud should be apportioned according to comparative fault, with the greater share borne by the party in the best position to prevent the fraud. A customer who fails to exercise basic financial internal controls and thereby exposes itself to fraud may be found 80% contributorily negligent.
Online Banking Systems — Shared Responsibility for Security
In online banking arrangements, while the bank has a duty to ensure system security and robust fraud detection, the customer has a corresponding duty to maintain contractually agreed internal controls. Negligent sharing of passwords or allowing dual control by a single individual constitutes a serious security lapse that exposes the customer to fraud and amounts to contributory negligence.

Legislation cited (3)

Cases cited (11)

  • Esso Petroleum Company v Uganda Commercial Bank (Supreme Court Civil Appeal No. 14 of 1992)
  • Mobil (U) Limited v Uganda Commercial Bank (1982) HCB 64
  • Yoswa Kityo v Eriya Kaddu (1982) HCB 58
  • Stanbic Bank Uganda Limited v Moses Rukidi Gabigogo (High Court Civil Appeal No. 28 of 2023)
  • Selangor United Rubber Estates Ltd v Cradock (No 3) [1968] 1 WLR 1555
  • Westminster Bank Ltd v Hilton (1926) 43 TLR
  • Olanya Hannington v Acullu Hellen (Civil Appeal No. 38 of 2016)
  • Pius Kimaiyo Langat v Co-operative Bank of Kenya Ltd (2017) eKLR
  • Sambaga v National Housing and Construction Corporation (Civil Suit No. 53 of 2016)
  • Acaye Richard v Saracen (Uganda) Limited & 2 Others (Civil Suit No. 63 of 2011)
  • Beau Townsend Ford Lincoln v Don Hinds Ford, No. 17-4177 (6th Cir. 2018)

Cases citing this judgment (1)

How later Ugandan judgments in the Wakilii corpus have cited this case. Treatment labels come from Sequitur — Uganda’s citator — each backed by a verbatim span from the citing judgment, and are not an assertion that this case is, or is not, good law.

Full judgment

↓ Download PDF

The original judgment as reported. Read the original PDF before relying on any passage.

Abacus Parenteral Drugs Limited v Stanbic Bank (U) Limited (Civil Suit 322 of 2022) [2025] UGCommC 58 (9 April 2025)
Source: this page presents Wakilii’s issue analysis and metadata for a publicly reported Ugandan judgment. Any AI-generated summary is marked as such. Judgment text is sourced from the Uganda Legal Information Institute (ulii.org). Wakilii is not affiliated with ULII.