Returns and Reverse Logistics in Iraqi E-Commerce
Returns and reverse logistics are substantial operational considerations in Iraqi e-commerce, with returns rates affected by the cash-on-delivery prevalence, customer purchasing patterns, and the broader operational environment. Effective returns operations support customer relationships and operational economics, while ineffective returns generate substantial costs and customer dissatisfaction. Operators should approach returns substantively as a core operational function rather than residual exception handling. Reverse Logistics Models Reverse logistics models in Iraqi e-commerce include returns collection by the original delivery carrier during subsequent delivery rounds, dedicated return collection by specialised reverse logistics providers, customer drop-off at designated collection points where applicable, return shipping by customers with merchant reimbursement, and broader models. The model affects both customer convenience and operational economics. COD Return Considerations Cash-on-delivery return considerations engage rejection at delivery where customers refuse the COD package, reversal of any partial payment arrangements, return collection logistics for rejected packages, treatment of repeatedly rejected COD orders, fraud and behavioural pattern monitoring, and broader COD return framework. COD adds substantial complexity to returns relative to pre-paid e-commerce returns. Return Collection Operations Return collection operations engage customer scheduling for return pickup, courier coordination for return collection, documentation at collection including return reason and product condition, transport of returns to designated facilities, customer communication during return process, and broader collection framework. Substantial return volumes require structured collection operations rather than ad-hoc handling. Return Inspection and Processing Return inspection and processing at the receiving facility engage condition assessment of returned products, comparison against original order, disposition decisions including restocking, repair, or disposal, system updates reflecting returns, customer refund processing or replacement order generation, and broader processing framework. Effective inspection affects both customer experience and inventory economics. Restocking and Inventory Handling Restocking and inventory handling for returned products engage assessment of product condition for resale viability, repackaging and relabelling for resale-ready products, inventory system updates, segregation of products requiring further handling, and broader inventory framework. Returns inventory management is operationally distinct from forward inventory management and requires specific operational capability. Disposal and Redistribution Disposal and redistribution for products not suitable for restocking engage donation to qualifying organisations where appropriate, sale through liquidation channels at reduced pricing, recycling for products with material recovery potential, disposal in accordance with environmental requirements, and broader disposition framework. Substantial returns operations generate material disposal flows requiring structured handling. Cross-Border Returns Cross-border returns face specific complexity including return transport logistics across borders, customs treatment of returned goods, applicable duties and tax treatment for returns, supplier coordination for cross-border return acceptance, and broader cross-border framework. Cross-border returns are operationally and economically substantially more challenging than domestic returns. Returns Programme Economics Returns programme economics engage the direct costs of returns operations, the inventory impact of returned products, the customer relationship impact of returns experience, the regulatory and consumer protection considerations, and broader programme framework. Effective returns programmes balance customer-friendly returns supporting relationships against operational cost discipline, with policy choices substantially affecting overall economics. How We Can Help Etihad advises on Iraqi e-commerce returns and reverse logistics, including returns policy structuring, reverse logistics contractual arrangements, response to returns-related disputes, cross-border returns positioning, and broader strategic positioning for returns operations.
Buy Now Pay Later (BNPL) in Iraqi E-Commerce
Buy Now Pay Later (BNPL) services have grown in international e-commerce as a payment option supporting consumer purchases through deferred payment arrangements. Iraqi BNPL adoption in e-commerce is at emerging stages with both domestic and international operators positioning for the market. From the e-commerce operator’s perspective, BNPL engages specific integration, commercial, and operational considerations distinct from standard payment methods. Operators should approach BNPL integration substantively given its emerging position. BNPL Models in E-Commerce BNPL services in e-commerce operate across variant models: The model affects merchant economics, consumer experience, and broader integration considerations. Iraqi BNPL Market for E-Commerce The Iraqi BNPL market reflects substantial consumer demand for credit access, limited consumer credit infrastructure relative to many international markets, growing e-commerce supporting online BNPL distribution, and emerging operator interest. E-commerce merchants considering BNPL integration should assess provider options against operational requirements and the emerging market context rather than assume mature provider landscape. Merchant-BNPL Integration Merchant integration with BNPL providers engages technical integration with the e-commerce platform supporting BNPL presentation and processing, agreement to provider commercial terms including merchant fees, settlement arrangements with the provider, allocation of operational responsibilities including consumer service, fraud and risk arrangements, and broader operational integration. Integration affects both customer experience and merchant economics. Consumer Experience BNPL consumer experience engages presentation of BNPL as a payment option at checkout, the application and approval process during checkout, the consumer’s commitment to instalment payments, ongoing payment management through the provider, and broader customer-facing experience. Effective BNPL implementation supports conversion without creating misleading impressions about the underlying credit nature of BNPL. Risk Allocation Merchant vs Provider Risk allocation between merchant and BNPL provider engages credit risk typically borne by the BNPL provider with the merchant receiving payment upon transaction, fraud risk allocation between provider and merchant, return and refund operational responsibilities, dispute handling allocation, and broader risk framework. Provider arrangements should be structured substantively rather than accept generic provider terms without review. Returns and Refunds in BNPL Returns and refunds in BNPL transactions engage specific complexity including provider involvement in refund processing, consumer payment status during returns processing, prorated adjustments for partial returns, treatment of payment failures during return processing, and broader returns framework. BNPL returns require coordination between merchant, provider, and consumer that exceeds standard payment return complexity. Customer Disputes Customer disputes in BNPL transactions engage product or service disputes affecting BNPL payment obligations, consumer financial difficulty affecting instalment payments, allegations of inadequate disclosure of BNPL terms, and broader disputes. Effective dispute handling engages coordination between merchant and provider with substantive customer engagement rather than passive deferral between the parties. Regulatory Considerations Regulatory considerations for BNPL in e-commerce engage Iraqi consumer credit framework applicability, CBI engagement with BNPL operations, consumer protection considerations for credit products, and broader regulatory framework. Regulatory framework for BNPL continues to develop globally with corresponding implications for Iraqi BNPL operations. Operators should anticipate evolving requirements alongside current practice. How We Can Help Etihad advises on BNPL in Iraqi e-commerce from both merchant and provider perspectives, including BNPL agreement structuring, operational integration support, response to BNPL-related disputes, regulatory positioning, and broader strategic positioning for BNPL in e-commerce.
Payment Gateway Licensing in Iraq
Payment gateway licensing in Iraq engages the Central Bank of Iraq framework for payment service providers, with the framework addressing the establishment and ongoing operation of payment infrastructure serving Iraqi e-commerce and broader payment needs. Operators considering payment gateway operations should approach the framework substantively at planning rather than as downstream compliance, since licensing positioning affects fundamental business viability. Payment Gateway Role Payment gateways provide infrastructure connecting merchants with payment networks including card schemes, mobile wallet operators, and banking infrastructure. The gateway function includes transaction routing and processing, authentication and security, settlement coordination, reporting and reconciliation, fraud screening, and broader payment infrastructure. Gateways operate as foundational infrastructure supporting e-commerce and broader digital payments. CBI Licensing Framework The Central Bank of Iraq licenses payment service providers under the framework for electronic payment services and broader financial activities. The framework engages corporate establishment requirements, capital adequacy, operational standards, anti-money laundering programmes, ongoing supervision and reporting, and broader regulatory framework. CBI licensing is foundational rather than optional for substantive payment gateway operations. Licensing Requirements Licensing requirements typically engage corporate establishment as a regulated Iraqi entity, minimum capital reflecting the activities pursued, governance and management standards including fit and proper considerations for senior management, operational systems and controls supporting payment activities, anti-money laundering and KYC programmes, technology and security standards, business continuity arrangements, and broader regulatory engagement. Requirements should be confirmed under current framework provisions rather than assumed based on historical positions. Capital and Operational Standards Capital and operational standards for payment gateways engage minimum capital requirements supporting financial stability, operational risk management programmes, technology infrastructure meeting CBI standards, security controls addressing payment-specific risks, customer fund protection arrangements where applicable, and broader operational framework. Standards should be matched at planning rather than treated as ongoing development. AML and KYC for Gateways Anti-money laundering and know-your-customer requirements apply substantively to payment gateways, engaging customer due diligence for merchants and broader customer relationships, transaction monitoring across the gateway’s transaction flows, suspicious transaction reporting, sanctions screening, and broader AML programme. AML compliance is foundational rather than optional, with non-compliance producing substantial regulatory consequences. Customer Relationships Payment gateway customer relationships engage merchant customers receiving gateway services, banking and card network partners supporting gateway infrastructure, technology providers supporting gateway operations, and broader stakeholders. Customer relationships should be structured substantively addressing the multi-party nature of payment infrastructure. Cross-Border Gateway Operations Cross-border gateway operations engage foreign currency considerations under the Iraqi framework, international card network participation, regional and international payment integration, and broader cross-border framework. Cross-border payment gateway operations face substantive regulatory considerations and should be structured substantively rather than rely on cross-border framing. Compliance and Audit Ongoing compliance and audit for payment gateways engage regular CBI reporting, internal audit programmes addressing operational and regulatory compliance, external audit where required, technology and security audit, AML audit, and broader compliance framework. Substantial gateway operations require dedicated compliance capability rather than ad-hoc compliance handling. How We Can Help Etihad advises on Iraqi payment gateway licensing matters, including licensing analysis and applications, ongoing compliance support, response to regulatory engagement, cross-border arrangements, and broader strategic positioning for payment infrastructure operations.
Online Payment Systems in Iraq
Online payment systems are foundational to Iraqi e-commerce operations, with payment integration affecting customer experience, operational economics, and the broader business model. The Iraqi payment landscape engages substantial cash-on-delivery use alongside growing electronic payment adoption across cards, mobile wallets, and bank transfers. E-commerce operators should approach payment integration substantively, since payment choices affect both immediate operations and longer-term scaling. Iraqi Payment Landscape for E-Commerce The Iraqi e-commerce payment landscape reflects substantial cash-on-delivery use particularly in consumer retail, growing card payment penetration through Qi Card and emerging international card programmes, expanding mobile wallet adoption through licensed providers, bank transfer infrastructure supporting higher-value transactions, and broader payment evolution. The landscape continues to develop with corresponding implications for e-commerce payment strategy. Cash-on-Delivery Operations Cash-on-delivery (COD) operations engage cash collection by the delivery operator at the point of delivery, reconciliation between collected cash and the merchant accounts, security for cash in transit and at collection points, treatment of failed deliveries and rejected orders, and broader operational discipline. COD adds operational complexity and cost relative to pre-paid e-commerce, with the trade-off being broader customer reach in the cash-preferring Iraqi market. Card and Wallet Payments Card payments in Iraqi e-commerce engage Qi Card as the substantial Iraqi domestic card programme, Mastercard and Visa international card programmes through Iraqi banks, and other card programmes. Mobile wallet payments engage licensed providers including Zain Cash, AsiaHawala, FastPay, NassPay, and emerging providers. Card and wallet integration for e-commerce engages payment processor relationships, integration with the e-commerce platform, fraud screening, and broader operational integration. Bank Transfer Integration Bank transfer payments support higher-value e-commerce transactions and an increasing share of consumer transactions, with the framework engaging payment confirmation and reconciliation, integration with banking partners, treatment of delayed or failed transfers, and broader cash management. Bank transfers offer reliability and reduced fraud exposure relative to card payments while engaging different operational integration patterns. Payment Service Provider Relationships E-commerce operators typically engage payment service providers (PSPs) for payment processing rather than building their own payment infrastructure. PSP relationships engage commercial terms including processing fees and revenue sharing, technical integration with the e-commerce platform, settlement timing and arrangements, fraud and chargeback handling, customer service for payment issues, and broader operational integration. PSP selection affects both economics and operational experience. Chargebacks and Disputes Chargebacks engage cardholder disputes resulting in reversal of paid transactions to merchant accounts, with chargebacks supporting consumer protection while creating merchant exposure to abusive use. Chargeback management engages prompt response to chargeback notifications, evidence supporting the original transaction validity, dispute through the chargeback process, and broader chargeback programme management. Substantial e-commerce operations face material chargeback exposure warranting dedicated capability. Cross-Border Payment Considerations Cross-border e-commerce payments engage Iraqi foreign exchange framework addressed in Article 5, payment infrastructure supporting international transactions, currency conversion and timing, treatment of payment failures across borders, and broader cross-border framework. Cross-border payment economics often differ substantially from domestic payments with corresponding implications for pricing and operations. Payment Security and Fraud Payment security for e-commerce engages PCI DSS compliance for card payment handling where applicable, authentication standards including multi-factor authentication, fraud screening at transaction level, secure handling of payment data including avoiding storage of sensitive payment details, and broader security framework. Security failures in payment can produce both direct losses and broader regulatory and operational consequences. How We Can Help Etihad advises on Iraqi e-commerce payment matters, including payment strategy and provider selection, PSP and banking arrangements, response to payment-related disputes including chargebacks, cross-border payment structuring, and broader strategic positioning for payment operations.
Product Registration Requirements in Iraq.
Labelling and Packaging Rules in Iraq Labelling and packaging rules govern the information provided to consumers and to supervisory authorities through the product packaging and labelling. The framework is established by the Consumer Protection Law, the Standards and Quality Control Law and the labelling standards adopted under it, sectoral instruments for specific product categories, and the broader Iraqi regulatory framework. The labelling and packaging requirements support consumer protection, product identification, traceability, and the broader supervisory function, with substantive consequences engaged for non-compliance. Arabic Language Requirement. Arabic is the official language of Iraq, and product labelling for the Iraqi market is required to be provided in Arabic for the principal information elements. The requirement engages: The product name and identification. Information concerning the producer, importer, and distributor. Composition and ingredients information. Instructions for use and safe handling. Warnings and safety information. Date marking including production and expiry dates. Storage instructions. Country of origin. Net content. Other information required by the applicable sectoral framework. Bilingual labelling, with Arabic and another language (typically English or the language of the country of origin), is the prevailing market practice and is, in general, sufficient where the Arabic information is complete and accurate. Labels in non-Arabic languages without Arabic supplementation are subject to refusal at importation and engage subsequent consumer protection and market surveillance consequences. General Labelling Elements. The general labelling requirements applicable to consumer goods engage: Product name and identification. Producer or manufacturer name and address. Country of origin. Importer or local distributor name and address. Net content (weight, volume, count) in metric units. Composition or ingredients list where applicable. Instructions for use, where the product’s use is not self-evident. Warnings and safety information. Production date, expiry date, or other date marking applicable to the product category. Batch or lot identification supporting traceability. Storage conditions where applicable. Disposal information where applicable. Date Marking. Production date (تاريخ الإنتاج) indicating when the product was manufactured. Expiry date (تاريخ انتهاء الصلاحية) indicating the last date for safe and effective use. Best before date (يفضل قبل) for products with quality but not safety implications past the date. Period after opening (PAO) for products with limited shelf life after opening. Specific date formats prescribed by the applicable framework. Country of Origin Marking. Clear marking of the country of origin in Arabic or in another language familiar to Iraqi consumers. Consistency between the marking and the underlying determination of origin under the customs framework. Specific requirements for products engaging multiple manufacturing locations. Specific considerations for assembled or processed products. False or misleading country of origin marking engages substantive consequences under the Consumer Protection Law and the Customs Law. Packaging Requirements. Materials supporting product safety and integrity. Specific materials standards for food contact packaging. Pharmaceutical packaging supporting product stability and protection. Child-resistant packaging for specific product categories. Tamper-evident packaging for specific categories. Packaging information requirements including labelling carried on the packaging. Wooden packaging requirements under ISPM-15 phytosanitary standards for international shipments. Environmental considerations for packaging where applicable. Verification at Importation and Market Surveillance. Customs inspection at importation, where labelling defects may engage refusal of clearance. COSQC verification as part of conformity assessment procedures. Ministry of Health and sectoral inspection in respect of specific product categories. Consumer protection surveillance of products in the market. Response to consumer complaints. Market sampling and verification. Non-conforming labelling and packaging engage substantive consequences including refusal of importation, removal from the market, administrative penalties, and consumer protection liability. How We Can Help. Our firm advises on labelling and packaging in Iraq, including the structuring of labels for compliance with the Consumer Protection Law and sectoral frameworks, Arabic translation arrangements, date marking strategy, country of origin marking, response to labelling non-compliance findings at importation and in market surveillance, and the conduct of disputes engaging labelling matters
Digital Bank – Capital Requirements
Digital Bank – Eligibility & Ownership Overview The ownership and eligibility rules governing Iraq’s digital banks are among the most legally significant aspects of the licensing framework. They determine who may establish a digital bank, what proportion of the institution each investor may own, what categories of investor are subject to enhanced requirements, and what legal consequences flow from non-compliance with ownership obligations. These rules are not merely administrative, they carry direct legal consequences, including the possibility of forced divestiture, restrictions on voting rights, and cancellation of the license itself. Any investor or founding group considering the establishment of a digital bank in Iraq must ensure that its proposed ownership structure is legally compliant before proceeding with any application. This article sets out the principal ownership and eligibility requirements under Iraq’s digital bank regulatory framework, with particular attention to the Qualified Institutional Investor (QII) requirement, the definition and treatment of related parties, the conditions under which ownership thresholds may be exceeded, and the legal obligations that attach to founders and institutional investors during the pilot operation phase. 1. General Ownership Cap: 9.99% Rule The foundational ownership rule under Iraq’s digital bank framework is that no individual or company including through interests held by related parties may hold a shareholding in a digital bank that exceeds 9.99% of the bank’s total shares. This cap applies to both direct and indirect holdings. Where a prospective investor holds shares through related parties, those related party holdings are aggregated with the investor’s direct holding for the purpose of calculating compliance with the 9.99% limit. The 9.99% threshold is therefore not assessed on an individual basis, it is assessed on a consolidated basis that encompasses the full network of related party interests. This aggregation rule has significant practical implications for corporate groups, family investors, and any structure involving multiple related entities or individuals. What Constitutes a Related Party Category Who Is Included Family Relationships Individuals connected by blood, marriage, or kinship up to the fourth degree including parents, children, siblings, grandparents, grandchildren, aunts, uncles, cousins, and their spouses Business Relationships Individuals or entities currently in a commercial partnership, holding shares in the same institution, serving together on the same board of directors, or where one party works for a company owned or controlled by the other Political Relationships Individuals or entities with family or business relationships with a person carrying political risk, or who are subject to the influence or control of any other party exercising power or influence The breadth of this definition means that investors with complex corporate structures, family groups with multiple members involved in the venture, or any party with political exposure must conduct a thorough related party analysis before determining their permissible ownership level. Legal advisers should note that the related party analysis is not limited to formal legal relationships, it extends to de facto control, influence, and shared economic interests. The substance of the relationship, not merely its legal form, governs the analysis. 2. Exceeding the 9.99% Threshold The framework provides a mechanism by which the 9.99% cap may be exceeded, subject to specific conditions and prior written approval from the CBI. This is not an automatic right, it is a discretionary approval that the CBI may grant or refuse. Two levels of permitted excess are established: Up to 20% General Investor Any investor other than a Qualified Institutional Investor may apply to the CBI for approval to hold up to 20% of a digital bank’s shares. The investor must submit a written application to the CBI and must satisfy the CBI that the proposed holding is appropriate in the context of the bank’s ownership structure and governance. A critical condition applies: the total aggregate shareholding of any single investor and their related parties must not exceed 20% at the time of submitting the application for increased ownership. This means that an investor who has already accumulated more than 20% through related party holdings cannot rely on this pathway. Up to 40% Qualified Institutional Investor A Qualified Institutional Investor (QII) may hold up to 40% of a digital bank’s shares. Where multiple QIIs are present in the ownership structure, and one seeks to exceed 20%, that QII’s shareholding must be larger than the shareholding of any other shareholder seeking the same exception. The 40% ceiling for QIIs is also subject to CBI approval on a case-by-case basis, and the CBI retains an absolute discretion to refuse any application regardless of whether the formal criteria are met. 3. Qualified Institutional Investor Requirement One of the most distinctive features of Iraq’s digital bank framework is the mandatory requirement for at least one Qualified Institutional Investor in the ownership structure of every digital bank. This is not optional, it is a condition of licensing. 3.1 The Mandatory QII Requirement Every digital bank in Iraq must have at least one shareholder that qualifies as a QII. That QII must hold no less than 9.999% of the bank’s shares. Failure to maintain a QII with the required minimum shareholding is a breach of the licensing conditions. 3.2 Who Qualifies as a Qualified Institutional Investor The framework sets out two categories of entity that may qualify as a QII, each subject to specific criteria: Category A: Financial Institution A financial institution qualifies as a QII if it satisfies all of the following conditions: It is licensed and not subject to any penalties, restrictions, or prohibitions, and is supervised by a financial regulatory authority in a jurisdiction that is not on the FATF grey list or black list It has operated as a financial technology company dealing directly with customers for a minimum of three years It has achieved annual revenues of not less than IQD 30 billion (or equivalent) in each of the three preceding financial years It has a minimum of 100,000 active users or customers Category B: Investment Fund An investment fund qualifies as a QII if it satisfies all of the following conditions: It manages an investment portfolio of not less
Electronic Fraud and Unauthorized Transactions in Iraqi Digital Banks
Tax Obligations of Digital Banks in Iraq Tax Planning for an Iraqi Digital Bank: Why It Must Begin Before Incorporation The tax obligations of a digital bank in Iraq are governed by the general corporate tax regime applicable to Iraqi joint stock companies, with specific considerations that arise from the nature of a digital bank’s revenue streams, its structural dependence on foreign technology vendors, and the typical profile of its investors. These considerations make early tax planning ideally as part of the pre-incorporation feasibility study significantly more valuable than tax advice sought after the structure is already locked in. The effective tax rate for an Iraqi digital bank may differ substantially from the statutory headline rate, depending on which expense categories qualify for deduction, how credit loss provisions are treated for tax purposes, how early-year losses are carried forward, and whether applicable double tax treaties reduce withholding on cross-border payments. None of these determinations can be made without a qualified tax adviser with specific experience in the Iraqi banking sector. 1. Corporate Income Tax: The Primary Tax Obligation The digital bank’s net profits are subject to corporate income tax at the rates prescribed under Iraqi income tax law for entities operating in the banking sector. The key elements of the corporate income tax position are: 1.1 Taxable Revenue Net interest margin: the difference between interest and similar income received on credit facilities extended during the pilot and full license phases, and interest and similar costs paid on deposits and any wholesale funding Fee and commission income: service charges, transaction fees, card fees, and other fee-based revenues from banking services Investment returns: income from CBI-approved investment instruments permitted during the pilot phase and from broader investment activities after full licensing 1.2 Deductible Expenses Employee salaries, benefits, and associated employment costs Depreciation and amortization of technology systems, software licenses, and other capital assets, the depreciation schedule applicable to banking technology assets should be confirmed with a tax adviser Licensing fees, regulatory fees, and deposit guarantee premiums paid to the Iraqi Deposit Guarantee Company AML/CFT compliance costs including the cost of external assessments, screening systems, and training Credit loss provisions recognized under IFRS 9 subject to any tax-specific rules governing the deductibility of provisioning in the Iraqi banking sector Professional fees: external audit, legal advisory, and compliance advisory costs 1.3 Loss Carry-Forward: Critical for Early-Stage Planning In the early phases of the bank’s operations particularly during the pilot phase when revenues are limited by deposit caps and credit restrictions, while establishment costs are at their peak, the bank is likely to generate tax losses. Under Iraqi tax law, these losses can generally be carried forward to offset taxable income in subsequent profitable years. This loss carry-forward benefit significantly affects the financial modeling of the bank’s early phases and should be explicitly incorporated into the five-year financial projections required as part of the licensing application. 2. Withholding Tax on Payments to Foreign Vendors A digital bank’s dependence on foreign technology vendors creates a specific and often underestimated tax exposure. Payments made to foreign companies for services rendered in connection with Iraq-sourced income including software licensing fees, technology royalties, professional service fees, and interest on foreign debt may be subject to Iraqi withholding tax on remittance outside Iraq. The categories most commonly affected are: Core banking system licensing fees paid to international software providers Royalties for proprietary technology incorporated in the bank’s platform Management fees or technical assistance fees paid to a parent company or affiliated entity Professional fees paid to foreign legal advisers, auditors, and consultants for services delivered remotely Interest payments on any foreign debt facility used to finance the bank’s capital or operations The applicable withholding tax rate on each payment category depends on: the nature of the payment (royalty, interest, service fee each may be treated differently), the country of residence of the recipient, and whether Iraq has a double tax treaty with that country that provides for a reduced rate or exemption. Failure to apply withholding tax where it is required creates a tax liability for the bank not the foreign vendor and may also trigger interest and penalties for late payment. 3. Foreign Investor Tax Considerations A foreign investor in an Iraqi digital bank faces a potential two-layer tax structure: corporate income tax in Iraq on the bank’s profits at the entity level, and tax in the investor’s home jurisdiction on distributions received and capital gains realized on eventual disposal of the shares. Effective tax planning for foreign investors involves analyzing four elements: Double tax treaty availability: whether Iraq has entered into a tax treaty with the investor’s home country, and what relief the treaty provides for dividends paid by Iraqi companies and capital gains realized on disposals of Iraqi company shares Foreign tax credit mechanism: whether the investor’s home jurisdiction allows Iraqi corporate taxes and withholding taxes to be credited against the home jurisdiction tax liability reducing the double-taxation effect Dividend distribution timing: the optimal timing of dividend distributions from a tax efficiency perspective for investors in countries with dividend participation exemptions, the holding period requirements and ownership thresholds required to access the exemption may influence the timing of distributions Investment structure: whether to invest directly as an individual or entity, or through an intermediate holding company jurisdiction that has favorable treaty arrangements with Iraq, the choice of structure can have a material impact on the effective tax rate on returns 4. Ongoing Tax Compliance Obligations In addition to the structural and planning considerations above, the digital bank has the following ongoing compliance obligations: Tax registration with the Iraqi tax authorities before commencing any revenue-generating operations Annual corporate income tax return filed within the deadlines prescribed under Iraqi tax law, supported by the bank’s audited financial statements Quarterly advance tax payments based on estimated annual liability failure to make timely advance payments may attract interest charges Withholding tax filing and payment on a monthly or quarterly basis for all payments to foreign vendors
Electronic Contracting and Digital Evidence for Digital Banks in Iraq
Electronic Contracting and Digital Evidence for Digital Banks in Iraq Electronic Contracting: The Legal Foundation That Every Digital Bank Builds On Every single customer relationship in a digital bank is created through electronic contracting. Account opening happens via a mobile application or website. Credit agreements are concluded by tapping an accept button. Card terms are accepted through a digital confirmation. Payment mandates are authorized by biometric authentication. There is no paper, no wet ink signature, no branch counter. This operating reality raises a set of legal questions that traditional banks simply do not face: when are these electronic contracts legally binding? How can they be proved in a dispute? How long must the records be kept? The answers matter enormously. A digital bank that cannot prove the existence and terms of its customer contracts in regulatory examinations, customer disputes, AML investigations, or litigation is in a fundamentally weak legal position, regardless of how commercially successful its operations may be. 1. When Is an Electronic Contract Legally Binding? Under the general principles of Iraqi contract law, a contract is formed by the meeting of offer and acceptance with the requisite legal capacity, lawful subject matter, and consideration. The medium through which offer and acceptance are communicated does not affect the validity of the contract unless the law specifically requires a particular form (such as a notarized document for certain property transactions). Electronic contracts are therefore legally binding under Iraqi law when four conditions are satisfied: Express manifestation of consent: the customer must have actively and demonstrably agreed to the material terms, a passive scroll-through of terms and conditions, or a pre-ticked checkbox that the customer must un-tick to opt out, does not constitute legally robust consent. Best practice and the approach most defensible in litigation is to present material terms prominently, require the customer to scroll through them before a confirmation button becomes active, and capture the confirmation as a timestamped event in the system’s audit log Verified identity: the customer’s identity must have been authenticated by a reliable method before the contract is concluded. The CBI’s mandatory biometric verification and liveness detection requirements for digital onboarding create a strong evidentiary foundation for identity at the point of account opening. For subsequent transactions, the strength of the authentication method used determines the evidentiary weight of the bank’s records Legal capacity: the bank must have verified that the customer is of legal age and has full legal capacity to enter into the contract. Age verification is an integral element of the digital KYC process Accurate timestamp: the date and time of contract conclusion must be recorded accurately through a trusted timestamp mechanism. This matters because the terms applicable to any given customer are those in force at the time of contract conclusion — and the bank must be able to prove which version of its terms was in force at any given date 2. Electronic Signatures: Three Levels of Legal Strength Not all electronic signatures carry the same evidentiary weight. The following hierarchy applies in practice: Basic electronic signature: any electronic indication of a person’s intent to be bound including a typed name, a clicked checkbox, or a digital confirmation button. Legally effective but carries limited evidentiary weight in a contested dispute, as it is difficult to prove that the specific individual signed rather than another person with access to their device Advanced electronic signature: based on asymmetric cryptography with a digital certificate issued by a recognized certification authority creates a strong technical link between the signature and the signatory’s identity. Carries substantially stronger evidentiary weight and is appropriate for high-value or legally sensitive transactions Biometric authentication: fingerprint, facial recognition, or voice biometrics linked to a verified identity document provides the strongest practical combination of identification and consent evidence for mass-market digital banking at scale. The combination of biometric authentication at onboarding and at transaction authorization creates a robust evidentiary chain for the full lifecycle of the customer relationship 3. Audit Trails as Legal Evidence Every transaction executed through a digital bank’s systems generates an audit trail: the identity of the person who initiated the transaction, the device and IP address used, the precise timestamp, the transaction parameters, any modifications made and by whom, and the system state at the time of execution. These audit trails are among the most valuable pieces of legal evidence available to a digital bank in any dispute, investigation, or proceeding. Their legal value is, however, entirely dependent on the technical integrity of the recording system. An audit trail that is technically capable of being modified after the fact has significantly diminished evidentiary value. A well-designed audit logging system must be: Tamper-evident: any modification to a log entry must be detectable and must itself be logged Immutable for the retention period: log entries must not be deletable or overwritable during the mandatory retention period Retrievable on demand: logs must be rapidly retrievable in a readable format for regulatory examinations, legal proceedings, or customer dispute resolution Comprehensive: the audit trail must capture all system events relevant to customer accounts and transactions not only successful transactions but also failed authentication attempts, blocked transactions, and system errors 4. Mandatory Record Retention Periods Record Category Minimum Retention Period Legal Basis Financial transaction records 7 years AML/CFT regulatory requirement Customer identification and account opening records 5 years after end of customer relationship Banking supervision requirement Credit decision records with supporting rationale 5 years after facility repayment Credit risk and consumer protection Complaint records and customer correspondence 5 years Consumer protection and dispute resolution Audit trails for all system events 5 years retrievable in real time Regulatory and forensic requirements Version-controlled terms and conditions Indefinitely each version with effective date Contract formation evidence
Outsourcing and Technology Providers for Digital Banks in Iraq
Outsourcing and Technology Providers for Digital Banks in Iraq Outsourcing in a Digital Bank: The Liability That Stays With the Bank A digital bank is structurally dependent on external vendors in a way that no traditional bank is. Its core banking system is operated by a software vendor. Its online platform may be built by a third-party development firm. Its cybersecurity defences are managed by a specialized security provider. Its KYC and identity verification capabilities are supplied by a fintech data company. This dependency is inherent to the digital bank model and it creates a legal liability structure that founders and boards consistently underestimate. The governing principle is straightforward and non-negotiable: the bank remains fully responsible to the CBI and to its customers for the performance of every function it has outsourced, regardless of what any commercial vendor contract says. A service level agreement, however comprehensive, does not transfer regulatory liability from the bank to the vendor. If a vendor failure causes the bank to breach a licensing condition, the bank not the vendor faces the regulatory consequences. 1. CBI’s Regulatory Framework for Outsourcing The CBI’s framework imposes the following specific requirements on outsourcing by digital banks: The bank must retain full control over decision-making in all core functions, even where operational execution has been delegated to an external provider Functions that directly affect the CBI’s ability to supervise the bank may not be outsourced in a manner that impedes the CBI’s access to information or its ability to conduct examinations The CBI has the right to conduct on-site inspections of vendor facilities and to request access to vendor records where this is necessary for its supervisory functions, vendor contracts must include provisions explicitly recognizing this right All vendor service level agreements must satisfy the technical and operational standards prescribed by the CBI, a vendor arrangement that produces availability or security levels below the CBI’s minimum standards places the bank in breach of its licensing conditions 2. Vendor Risk Classification Vendor Category Examples Required Oversight Level Critical vendors Core banking system provider, online banking platform provider Detailed SLA with financial penalties, CBI audit right, BCP integration, executable transition plan, 24-hour breach notification Security vendors Cybersecurity providers, SIEM operators, AML monitoring systems Strict data processing agreement, immediate breach notification, security certifications required Supporting vendors Digital KYC providers, identity verification services Periodic compliance review, AML compliance confirmation, data security standards verification General vendors Telecommunications providers, office software Standard commercial terms, data processing agreement if customer data is accessed 3. Mandatory Contractual Provisions for Critical Vendors 3.1 Service Level Agreements Every SLA with a critical vendor must specify: system availability guarantees consistent with CBI minimum requirements (99.5% for core banking systems, 98% for online platforms), incident severity classifications with defined maximum response and resolution times for each severity level, scheduled maintenance windows agreed in advance and notified to the bank with sufficient lead time, financial penalties that are meaningful and proportionate for availability or performance breaches, and mechanisms for the bank to escalate unresolved incidents to senior management at the vendor. 3.2 Audit and Inspection Rights Every critical vendor contract must include explicit provisions recognizing: the bank’s right to conduct or commission audits of the vendor’s facilities, systems, and records relevant to the services provided; the CBI’s right by extension of its supervisory authority over the bank to conduct inspections of vendor facilities; and the vendor’s obligation to cooperate fully with any such audit or inspection. A vendor that refuses to grant audit rights to the bank is not an appropriate vendor for a critical function in a regulated environment. 3.3 Data Protection and Security For any vendor that processes customer personal data, a Data Processing Agreement (DPA) is mandatory. The DPA must specify: the precise categories of data processed, the permitted purposes of processing, the technical and organizational security measures in place, the vendor’s obligation to notify the bank within 24 hours of discovering any security incident affecting bank data, the prohibition on sharing bank data with any other party without the bank’s prior written consent, and the obligations for data return or deletion upon termination of the arrangement. 3.4 Business Continuity and Transition Critical vendor contracts must include: a business continuity and disaster recovery plan specific to the services provided, which is consistent with and integrated into the bank’s own BCP/DRP; a transition plan specifying how services will be migrated to an alternative provider or brought in-house upon termination; a minimum transition period of not less than six months on termination for non-cause, giving the bank adequate time to migrate without service disruption. 4. Concentration Risk: The Single-Vendor Problem Complete reliance on a single vendor for any critical function creates concentration risk. Where the bank has only one vendor capable of providing a critical system or service, a failure by that vendor whether technical, commercial, or financial can cause a service disruption with no available alternative. The bank must: Maintain a documented assessment of concentration risk across its vendor portfolio Develop and maintain a practical exit strategy for every critical vendor, a plan that can realistically be executed within the transition period specified in the contract without material service disruption Report material concentration risks to the board of directors as part of the bank’s regular risk reporting cycle Consider diversification strategies for the highest-criticality functions where a single-vendor failure would cause the bank to breach its licensing conditions
Data Privacy and Banking Secrecy for Digital Banks in Iraq
Data Privacy and Banking Secrecy for Digital Banks in Iraq Data Privacy and Banking Secrecy: The Two Overlapping Legal Frameworks Every Digital Bank Must Navigate A digital bank generates more personal data per customer per day than almost any other type of financial institution. Every login, every transaction, every failed authentication attempt, every navigation path through the mobile application creates a data record. Managing this data legally and using it responsibly requires simultaneous compliance with two distinct but overlapping legal frameworks: the established principle of banking secrecy grounded in Iraqi banking legislation, and the data protection principles that govern how personal information may be collected, stored, processed, used, and protected. These two frameworks are complementary but not identical. Banking secrecy governs what information may be disclosed to third parties. Data protection principles govern how information may be used internally and externally across its full lifecycle. A bank that satisfies one without the other remains legally exposed. 1. Banking Secrecy: The Foundational Legal Obligation Banking secrecy is one of the most established principles in Iraqi banking law. It prohibits the digital bank from disclosing any information relating to its customers, their identity, their account details, their transaction history, their financial position, or any other information obtained in the course of the banking relationship to any third party, without the customer’s express written consent. Four specific exceptions to this prohibition are recognized under Iraqi law: A court order issued by a competent Iraqi court in the context of criminal or civil judicial proceedings that specifically identifies the information required A supervisory request from the Central Bank of Iraq in the exercise of its statutory oversight powers including requests made in the course of a regulatory examination or investigation A request from the competent anti-money laundering authority in the context of a formal AML/CFT investigation including requests related to suspicious transaction reports already filed by the bank Disclosure for the purpose of authorized external audit by the bank’s CBI-approved external auditor, limited to the information necessary for the audit Any disclosure outside these four exceptions regardless of the requestor’s identity or the apparent legitimacy of the purpose constitutes a serious violation of banking secrecy. This violation creates both civil liability to the affected customer for any harm caused by the disclosure, and regulatory liability to the CBI. 2. Six Principles of Lawful Data Processing Alongside banking secrecy, the digital bank must comply with the following data protection principles in all its processing of personal data. These principles govern how data is used not just whether it can be disclosed: Lawfulness and transparency: personal data may be processed only when there is a legitimate legal basis for doing so, the principal bases being the customer’s explicit consent, performance of the contract between the bank and the customer, compliance with a legal obligation, or a legitimate interest of the bank that is proportionate to the privacy intrusion and does not override the customer’s fundamental interests Purpose limitation: data collected for specified, explicit, and declared purposes may not subsequently be used for undisclosed secondary purposes using account transaction data to train a credit scoring model that was not disclosed to the customer at the time of data collection, for example, requires a fresh legal basis Data minimisation: the bank may collect only the minimum personal data necessary for the stated purpose collecting extensive lifestyle, behavioral, or social data beyond what is required for banking operations requires specific justification Accuracy: personal data must be kept accurate and up to date; inaccuracies must be corrected without undue delay, a bank that maintains demonstrably incorrect customer data and allows decisions to be made on that basis incurs liability for any resulting harm Storage limitation: personal data must not be retained for longer than is necessary for the purpose for which it was collected, or for longer than required by applicable law indefinite retention of inactive customer data without a legal basis is a data protection violation Integrity and confidentiality: appropriate technical and organizational measures must be implemented to protect personal data against unauthorized access, accidental loss, destruction, or damage the standard of protection required is proportionate to the sensitivity of the data and the potential harm from its compromise 3. Customer Rights Over Their Personal Data Every customer has the following rights with respect to their personal data held by the bank, and the bank must have operational mechanisms to respond to the exercise of these rights within a reasonable timeframe: The right of access: to obtain confirmation that the bank processes their personal data and to receive a copy of that data in a comprehensible format The right of rectification: to request correction of inaccurate personal data without undue delay The right to object: to object to the processing of their personal data in certain circumstances including processing for direct marketing purposes, where the objection is absolute The right to restriction: to request that the bank restricts its processing of their data in defined circumstances, for example, while the accuracy of the data is being contested The right to data portability: to receive their personal data in a structured, machine-readable format for the purpose of transferring it to another institution, this right is particularly significant in the banking context and directly supports competition 4. Data Classification and Iraq-Based Data Sovereignty The CBI’s Standards Booklet (Standard B7) imposes a mandatory tiered data classification system that overlays the general data protection principles with sector-specific technical requirements. Customer identity data, authentication credentials, account identifiers, and transaction data are classified at the highest sensitivity level and require mandatory encryption both at rest and in transit, with multi-layer access controls restricting access to authorized personnel only. The data sovereignty requirement is absolute: all data centres and servers used by the digital bank must be located within Iraq. Cloud hosting of core banking data outside Iraq is not permitted. This requirement directly limits the bank’s vendor choices and must be a primary criterion in any technology procurement decision.