Account Opening Software in Kenya: A Buyer's Guide for Banks, SACCOs and MFIs (2026)

How to choose account opening software in Kenya: workflow vs KYC providers vs core banking, what CBK and SASRA rules mean, a checklist and red flags.

CS
Creodata Solutions Team
Account Opening Software in Kenya: A Buyer's Guide for Banks, SACCOs and MFIs (2026)

Short answer: Account opening software runs the onboarding workflow: the forms, documents, signatories, staff review and the record. It is not the same as a KYC provider's identity-verification API or your core banking system's onboarding screen, and most Kenyan institutions need all three working together. Choose on Kenyan account kinds, entity documents, who-to-screen logic, form changes without IT projects, hosting and three-year cost.

This guide is for operations, digital, compliance and procurement teams at Kenyan banks, microfinance banks (MFBs) and SACCOs moving account opening off paper. A December 2024 CBK survey, reported in its 2025 customer due diligence guidance, found that outdated technology hinders customer verification. This is a practical guide, not legal advice; confirm requirements with your supervisor (CBK, SASRA) or adviser.

Creodata makes BAOS, account opening software for Kenyan banks and SACCOs, so we say plainly where it fits near the end. The criteria before that are the ones we would use to judge any vendor. Checked against primary sources on 8 October 2026.

What does account opening software do, and how is it different from a KYC provider?

Three kinds of product are sold as "digital onboarding" in Kenya, and each needs different tests.

Product typeWhat it doesWhat it usually does not do
Account-opening workflow softwareForms for each account kind, document checklists, signatories and mandates, staff review queues, decisions, SLA measurement and the onboarding recordVerify an ID against a government register by itself, or create the account in core banking without an integration
Identity-verification (eKYC) APIsCheck an ID against IPRS, match a KRA PIN, read documents, run selfie and liveness checksCollect a company's or chama's documents, manage signatories and mandates, or route the application through staff review
Core banking onboarding modulesCreate the customer and the account in the core system, with product set-upApplicant-facing forms for every entity type, document packs per person, or form changes without a vendor change request

Searches for "KYC providers in Kenya" or "KYC companies in Kenya" mostly return the second type. An identity check is one step: a company with three directors, two beneficial owners and four signatories needs a check on each person, and something has to work out who they are, collect their documents and keep one record. Screening, risk rating and monitoring usually sit in a fourth system, your AML software.

What do Kenyan rules mean for your requirements?

No Kenyan rule names a product. The rules say what you must capture, check and keep, for every account kind you offer.

Banks and MFBs: CBK's 2025 CDD guidance

  • Scope. CBK's 2025 Guidance on Customer Due Diligence (effective 1 September 2025) covers commercial banks, mortgage finance companies, MFBs, money remittance providers, forex bureaus, PSPs and non-deposit-taking credit providers (para 1.2), not SACCOs. See our guide to CBK's CDD guidance.
  • Verification examples. Table 3 gives IPRS checks of the ID number, serial number and name, a KRA PIN name check, facial-recognition selfies and video calls as examples, not requirements. Table 4 rates digital onboarding "medium to high" risk if not properly verified.
  • Your own policies. The POCAML Regulations 2023 require written policies for non-face-to-face relationships (reg 9) and a risk assessment before introducing new technology or a new delivery mechanism (reg 8(2)).
  • Timing. Reg 25(3) to (4) allows verification to finish after the relationship starts only as soon as reasonably practicable, where essential not to interrupt business, and with the risks managed. CBK's guidance speaks only of CDD "prior to opening an account" (para 3.2), so agree your approach with CBK.

SACCOs: SASRA/GG/1/2024

SASRA's AML guideline, SASRA/GG/1/2024 (24 June 2024), §6.1.1 asks for an original national ID, passport or alien ID card for individuals; a certificate of incorporation and recent audited accounts, where applicable, for bodies corporate; and for unincorporated entities, a certificate of registration plus the identities of the officials or signatories. Identity is verified against a reliable, independent source such as IPRS or the KRA tax database. See our SACCO member onboarding guide.

Identity documents and the KRA PIN

  • Any one official record identifies an individual: a birth certificate, national ID card, passport, driver's licence or another prescribed document (POCAMLA s.45(1A)(a)). ID cards stay valid until the Cabinet Secretary declares otherwise in the Gazette (Registration of Persons Act s.17), so accept older cards as well as new ones.
  • Opening an account with a financial institution needs a KRA PIN (Tax Procedures Act, First Schedule item 11); non-residents have been exempt since the Finance Act 2026 (s.12(5B)). See our IPRS and KRA PIN guide.
  • Foreign customers present a valid passport, and CBK expects its authenticity to be checked (CDD para 3.4.1).
  • New accounts need a tax-residence self-certification, which may be part of the account-opening documents (CRS Regulations, LN 8 of 2023, regs 18 and 24).

Companies, beneficial owners and BRS

  • Regulation 16(1) lists what a legal person provides, including a certified board resolution naming the signatories and the particulars of the people who manage, control or own it. The business account opening documents checklist sets these out by entity type.
  • A beneficial owner holds at least 10% of the shares or votes, can appoint or remove a majority of the board, or exercises significant influence or control (Companies BO Regulations reg 3(2)). CBK's BO guidance asks institutions to collect the BO form filed with BRS and the BRS official search (often called CR12), match the names against both, and report a mismatch to the FRC (paras 4.6.1 and 4.8). See beneficial ownership at account opening.
  • Anyone acting for the customer needs documentary proof of authority and full CDD of their own (CDD para 3.4.2).
  • Since 25 September 2026, written trusts must be registered or incorporated with the Registrar of Trusts at BRS (Trust Administration Act 2026). A change like this tests how easily a vendor's forms can change.

Chamas, groups and joint accounts

We found no provision for unincorporated groups in the AML Regulations. Registered community groups hold a Form 2 certificate from the Directorate of Social Development, but on 10 September 2026 the High Court declared the Community Groups Registration Act unconstitutional, suspended until midnight on 10 February 2027. Banks commonly ask for the registration certificate, constitution, minutes naming the signatories and mandate, and each signatory's ID and KRA PIN; published checklists differ. See chama and group account opening. For joint accounts, the only specific provision we found is optional: written confirmation that one party has known the other for at least twelve months (reg 15(2)(j)).

PEPs, sanctions and records

  • CBK's PEP guidance (para 5.4) says to ask direct PEP questions at account opening and design forms to capture them, without relying on self-declaration alone.
  • Screen against the UN Consolidated List and Kenya's domestic list before onboarding (CDD para 3.6.3.2); see sanctions and PEP screening in Kenya.
  • If CDD cannot be completed, do not open the account, and file a suspicious transaction report (reg 25(2)).
  • Keep CDD records for at least seven years from the end of the transaction or relationship (POCAMLA s.46(4); reg 42). The wider framework is in our POCAMLA and POTA guide.

Data protection and hosting

The Data Protection Act requires a notice before you collect data (s.29), treats biometric data as sensitive (s.2), and requires an impact assessment for likely high-risk processing (s.31), such as selfies. Data may leave Kenya only with proof of appropriate safeguards or where necessary (s.48). Microsoft Azure has no region in Kenya; the nearest are in South Africa. For banks, CBK's outsourcing guideline (CBK/PG/16) gives data centres and KYC activities for AML compliance as examples of material outsourcing that needs CBK approval; whether a given product counts is for you and CBK to decide.

Evaluation checklist

AreaWhat to test
Account kindsIndividual, joint, chama and business applications in one system, each with its own form
Entity document packsDocuments per entity type (company, partnership, trust, society, NGO, group) and per director, signatory and owner
Signatories and mandatesSignatories tied to the resolution or minutes that appoint them; the operating mandate on the record
Who to screenEvery person to verify and screen (directors, owners, officials, holders, signatories) worked out and listed once each
Configurable formsYour team changes a field or document rule without a vendor release, under approval; old applications keep their form version
SwahiliApplicant-facing text in Swahili as well as English; which screens and messages stay English-only
SLA measurementTime per step from submission to account opened, on a dashboard; what happens when a target is missed
Audit recordWho did what, in which role and when; whether anyone can edit entries; keeping and exporting it for seven years
Deployment and data protectionWhere data is stored, processed and backed up; a data processing agreement; input for your DPIA and any CBK outsourcing application
IntegrationHow the system connects to your ID-verification provider and core banking: built in, by API, or by staff re-keying
Total costThree years of licence, per-check verification fees, hosting, implementation, form changes and support

Questions to ask vendors

  1. Show a chama with twelve members and three signatories, from application to decision.
  2. Show a limited company with a corporate shareholder. Who ends up on the screening list?
  3. Which checks does your product run itself, and which does it leave to another provider?
  4. Change a required document during the demo, and show who approves the change.
  5. Can an administrator edit or delete audit entries?
  6. Which features in your proposal are live today, and which are on the roadmap?

Red flags

  • "CBK requires selfie, liveness or video KYC" or "IPRS checks are mandatory for banks". CBK gives these as examples (Table 3).
  • "You must use a licensed IPRS aggregator." We found no such rule; the access route in law is an application to the Cabinet Secretary (LN 69 of 2016).
  • A 25% beneficial ownership threshold. Kenya uses at least 10%.
  • Instant BRS beneficial-ownership lookups. The Registrar may disclose BO data to financial institutions on Form BOF6; we found no published API for it.
  • "Kenyan data residency" on a cloud with no region in Kenya.
  • A chama form that is a relabelled business form, with no member register or officials.

Where BAOS fits

BAOS is the account-opening workflow that sits beside your identity-verification provider and your core banking system. It covers business and corporate, personal, group (chama) and joint accounts, each with its own form, and fifteen business entity types, from sole proprietorships to SACCOs, NGOs and trusts. Chama applications carry a member register, elected officials and the group meeting resolution; joint applications capture every holder in full, with the operating mandate and survivorship instruction.

Your team can change the form without a software release, and forms are published under four eyes. Forms can carry English and Swahili text. BAOS lists every person who needs screening (directors, beneficial owners, members, holders and signatories) once each, on the application. Reviewers claim an application, verify documents and approve or reject it, or email the applicant for more information, then record the account number once the core banking system opens the account. SLA timers run on the workflow steps, and every workflow action is recorded with who, what role, when and from which address.

What BAOS does not do: it does not check IDs against IPRS, BRS or KRA, run liveness or face match, screen against lists, rate risk, or hold approval until screening is done. Screening runs in your screening tool. There is no built-in connector to an ID-verification provider or a core banking system: staff run checks in your provider's tools and type the account number in. BAOS does not send SMS or provide e-signature, its audit record is not append-only, and the product interface is in English.

BAOS runs as an Azure Marketplace managed application in the Azure region you choose, and its plans are public: see the BAOS plans and pricing. For the Kenyan detail, see BAOS in Kenya.

Frequently asked questions

What is the difference between account opening software and a KYC provider?

A KYC provider's API checks a person, for example an ID against IPRS. Account opening software runs the whole application: form, documents, signatories, staff review and record. Business and chama accounts involve many people, so most institutions use both.

Does CBK require IPRS checks or selfies for digital account opening in Kenya?

We found no rule requiring them for banks. CBK's 2025 CDD guidance gives IPRS checks, KRA PIN name checks, selfies and video calls as examples (Table 3). Your written non-face-to-face policy (reg 9) should say which checks you use and why.

Is a KRA PIN required to open a bank account in Kenya?

Under Kenya's tax law, yes, unless you are a non-resident. The Tax Procedures Act lists opening accounts with financial institutions as a transaction that needs a PIN (First Schedule item 11). Since the Finance Act 2026, non-resident persons are exempt (s.12(5B)). For unregistered groups the text is not settled, so confirm with your adviser.

Can account-opening data be hosted outside Kenya?

It can, with conditions. The Data Protection Act allows transfers with proof of appropriate safeguards or where necessary (s.48), and sensitive data such as biometrics also needs the person's consent (s.49). Banks should also check whether the arrangement is material outsourcing that needs CBK approval under CBK/PG/16.

How long must account-opening records be kept in Kenya?

At least seven years from the end of the transaction or account relationship (POCAMLA s.46(4); reg 42). That covers the CDD file, ID copies and analysis results, so check the software can keep and retrieve the full record that long.

More guides for Kenya

See Bank Account Opening in action.