AML Compliance for Fintechs and Digital Credit Providers in Kenya: The Obligations and How to Automate Them

AML rules for Kenyan payment providers, digital lenders and virtual asset firms: who is covered, what CBK and POCAMLA require, and how to automate compliance.

CS
Creodata Solutions Team
September 17, 2026
AML Compliance for Fintechs and Digital Credit Providers in Kenya: The Obligations and How to Automate Them

Short answer: Kenyan payment service providers, e-money issuers, money remitters, digital lenders and, since November 2025, virtual asset service providers are reporting institutions under the Proceeds of Crime and Anti-Money Laundering Act (POCAMLA). They must register with the Financial Reporting Centre (FRC), identify customers and beneficial owners, screen against sanctions lists, monitor transactions, report suspicious activity within two days and keep records for at least seven years. At fintech volumes that means screening and monitoring software that works in real time through APIs, so compliance does not slow onboarding.

Fintechs move money and credit faster than any branch network, which is exactly why supervisors watch them. This guide sets out which fintech businesses are covered, what the Central Bank of Kenya (CBK) and POCAMLA require, where the money-laundering risk sits, and how to automate compliance. It is written for founders, compliance leads and engineering teams at payment companies, digital lenders and virtual asset businesses. It reflects the primary texts as they stood on 17 September 2026 and is a practical guide, not legal advice. Creodata sells AML compliance software built for Kenya, and we say where it fits near the end.

Which fintechs are reporting institutions

POCAMLA defines a reporting institution as a financial institution, a designated non-financial business or profession, or a virtual asset service provider, and it defines a financial institution by activity. Lending, including consumer credit; transferring funds or value by any means; and issuing and managing means of payment, including electronic money, all count. So most fintech business models are covered whether or not a schedule names them.

BusinessWhy it is coveredAML supervisorSector rules to know
Payment service providers, including mobile money and e-money issuersTransferring funds or value; issuing means of paymentCBKNational Payment System Act, section 17A; National Payment System Regulations, 2014
Digital credit providers, now called non-deposit-taking credit providersLending, including consumer creditCBKCentral Bank of Kenya (Digital Credit Providers) Regulations, 2022, Part VIII
Money remittance providersTransferring funds or valueCBKMoney Remittance Regulations, 2013
Virtual asset service providersAdded as reporting institutions by the Virtual Asset Service Providers Act, 2025CBK or the Capital Markets Authority, by activityVASP Act, 2025; VASP Regulations, 2026

The CBK's 2025 guidance notes on customer due diligence, politically exposed persons and beneficial ownership apply to payment service providers, money remittance providers and non-deposit-taking credit providers, alongside banks.

What the rules require

Under POCAMLA and the POCAML Regulations, 2023, every reporting institution must:

  • Register with the FRC (section 47A). The FRC registers institutions through goAML, and failing to register is an offence.
  • Appoint a money laundering reporting officer at management level, and notify the FRC and the supervisor of any appointment or removal within 14 days (regulation 12).
  • Assess its money-laundering, terrorism-financing and proliferation-financing risk, document it and update it at least every two years (regulation 7), and assess risk again before launching new products, practices or technologies (regulation 8(2)). For a fintech that ships often, the second duty is easy to miss.
  • Carry out customer due diligence, including identifying beneficial owners, and apply enhanced measures to every foreign politically exposed person and to domestic PEPs where the risk is higher (regulation 26).
  • Screen against sanctions lists. Kenya's 2026 terrorism-financing sanctions regulations require the funds of designated persons to be frozen within 24 hours of a designation at the latest, and the freeze reported within 24 hours.
  • Monitor transactions that are complex, unusual, suspicious or large on an ongoing basis (section 44(1)), and report suspicious activity to the FRC within two days after the suspicion arose (section 44(2)).
  • Report cash transactions of US$15,000 or more by the Friday of the week in which they occurred (section 44(6) and regulation 40). This matters most where agents or cash merchants handle cash.
  • Keep records for at least seven years (section 46(4)) and send the FRC an annual compliance report by 31 January (regulation 44).

Sector rules add to that:

  • Payment service providers must use systems capable of screening transactions for POCAMLA and Prevention of Terrorism Act purposes (National Payment System Regulations, 2014, regulation 31), must comply with both Acts and their regulations and guidelines (regulation 60), and must describe their AML internal controls when applying for authorisation (regulation 4(2)(g)(ii)). The CBK can suspend or revoke an authorisation for AML failures (regulation 10(1)(m)), and section 17B of the National Payment System Act sets penalties of up to KES 20 million for a legal person, up to KES 1 million for a natural person and up to KES 100,000 a day while a breach continues.
  • Digital credit providers must show that the funds invested in the business are not proceeds of crime (regulation 30 of the 2022 regulations), take reasonable measures to identify customers (regulation 31) and comply with POCAMLA, the Prevention of Terrorism Act and the related regulations and guidelines (regulation 32). A licence application must include AML/CFT policies and procedures and a description of the applicant's ICT system with an independent assurance on it, and the CBK can suspend or revoke a licence for AML violations. Draft regulations for non-deposit-taking credit providers were published in August 2025 but had not been gazetted by September 2026.
  • Virtual asset service providers fall under the VASP Act, 2025, which commenced on 4 November 2025 and gave existing providers one year from commencement to comply. The CBK licenses custodial wallet providers, virtual asset payment processors and stablecoin issuance; the Capital Markets Authority licenses exchanges, brokers, advisers, managers and token issuance. The VASP Regulations, 2026, gazetted on 22 July 2026, apply to anyone offering virtual asset services in or from Kenya, including providers without a physical presence that target Kenyan consumers, and require customer due diligence before onboarding and a compliance officer.

Where AML risk sits in a fintech

  • Speed and volume. Instant transfers leave little time to intervene, and alert volumes grow with the customer base.
  • Onboarding at scale. Remote sign-up invites borrowed or fraudulent identities and accounts opened to be used as mules.
  • Mule networks. Many small accounts that receive funds from unrelated senders and pass them on quickly.
  • Wallet-to-bank cycling. Value moving repeatedly between mobile wallets, bank accounts and cards to break the audit trail.
  • Cash at the edges. Agents and cash merchants where cash enters the system.
  • Credit as a laundering route. Loans repaid early with third-party funds, or disbursements that pass straight through to other accounts.
  • Cross-border corridors and virtual asset on-ramps and off-ramps.

Our guide to transaction monitoring software in Kenya lists the typologies behind these patterns, and mobile money AML reporting in Kenya covers the wallet channel.

Screening without slowing onboarding

  • Screen in real time at sign-up through an API, with matching tuned for Kenyan names, so most customers clear in seconds.
  • Step up only when the risk is higher, routing possible sanctions or PEP matches to an analyst instead of blocking everyone.
  • Rescreen the whole base when lists change, because the 24-hour freeze rule applies to existing customers as much as new ones.
  • Screen the people behind business accounts, such as merchants and corporate borrowers, not only the account holder.

The guide to sanctions and PEP screening in Kenya covers the lists, the freeze rule and the evidence to keep.

Monitoring at fintech volume

  • Stream where money moves instantly, and run pattern rules over longer windows in batch.
  • Use velocity and network rules: many counterparties, rapid in-and-out movement and sudden changes in behaviour.
  • Segment customers, so a merchant and a salaried individual are not judged by the same threshold.
  • Back-test rules on historical data before they go live, so alert volumes stay manageable.
  • Keep the path from alert to report short, with the two-day deadline visible from the moment an analyst forms a suspicion.

Building AML in-house or buying it

Many fintechs have strong engineering teams and consider building AML in-house. Building gives full control of the customer experience, but the hard parts are not the first version: they are keeping lists current within hours, maintaining monitoring rules as typologies change, producing goAML reports the FRC accepts, keeping an audit trail an examiner trusts and governing any machine-learning models. A common middle path is to keep onboarding in-house and call a specialist AML engine through APIs for screening, monitoring, cases and reporting.

Whichever you choose, the obligations above apply to the result, and the evidence an examiner asks for is the same.

Data protection, cloud and outsourcing

  • Personal data leaving Kenya. The Data Protection Act, 2019 allows transfers out of Kenya only with proof of appropriate safeguards or where the transfer is necessary, and sensitive personal data also needs the data subject's consent.
  • Outsourcing notice for payment service providers. A PSP must notify the CBK at least 30 days before implementing an outsourcing agreement, and the contract must allow the CBK to oversee the third party (National Payment System Regulations, 2014, regulation 23).
  • Evidence of your ICT system. Digital credit licence applications must describe the ICT system and include an independent assurance on it.

Ask every AML vendor where your data will be stored and processed, in writing, before you sign.

Questions to ask AML vendors as a fintech

QuestionA good answer looks like
What latency does real-time screening have, at our volumes?Published figures and a load test on representative traffic
How quickly do list changes reach existing customers?A rescreen path measured in hours, with logs
Can monitoring run on streaming data?Rules that run in real time and in batch from the same logic
How do we integrate?Documented APIs and connectors for event streams and files, with replay for failed loads
How are suspicious transaction reports produced?A case workflow ending in a goAML report the FRC accepts
Where is our data processed, and can it stay in Kenya?A specific location, a data processing agreement and a deployment option that meets your constraints
How are AI decisions governed?Explanations for every score, human decisions and model approval

Our free AML vendor RFP checklist turns these into scored requirements, and the buyer's guide to AML compliance software in Kenya covers the full evaluation.

Where Creodata fits

Creodata's AML software for fintechs and digital lenders covers screening, customer risk rating, transaction monitoring, case management and reporting in one workspace. Screening uses fuzzy, multi-script, locale-aware matching with a false-positive workflow; monitoring runs in batch and streaming, with back-testing and versioned rule promotion; and data arrives through REST, SFTP, Kafka, change data capture or ISO 20022 connectors with replay and a dead-letter queue. Suspicious and cash transaction reports hand off to the Creodata goAML Reporting Platform for the FRC filing, AI scores come with their reasons and a human decision, and every action is kept in an append-only audit log. It runs on Microsoft Azure or on-premises with the same features, and modules are licensed separately. Book a demo to see it on your own flows.

If you also operate as a SACCO or through a bank partner, see AML software for SACCOs in Kenya.

Frequently asked questions

Are digital credit providers in Kenya covered by AML law?

Yes. POCAMLA's definition of a financial institution includes lending, including consumer credit, so digital credit providers are reporting institutions. The CBK supervises them for AML, and Part VIII of the Central Bank of Kenya (Digital Credit Providers) Regulations, 2022 requires them to comply with POCAMLA and the Prevention of Terrorism Act, identify customers and show that the funds invested in the business are not proceeds of crime.

Do payment service providers in Kenya need AML software?

The law requires the capability rather than a product. Regulation 31 of the National Payment System Regulations, 2014 requires payment service providers to use systems capable of screening transactions for POCAMLA and Prevention of Terrorism Act purposes, and POCAMLA requires ongoing monitoring and reporting within two days of a suspicion. At payment volumes, meeting those duties without dedicated screening and monitoring software is rarely realistic.

When do virtual asset service providers have to comply with Kenya's AML rules?

The Virtual Asset Service Providers Act, 2025 commenced on 4 November 2025 and made VASPs reporting institutions under POCAMLA. It gave people already providing virtual asset services one year from commencement to comply. The VASP Regulations, 2026, gazetted on 22 July 2026, add customer due diligence before onboarding and a compliance officer, and they apply to providers that target Kenyan consumers even without a physical presence.

How quickly must a fintech report a suspicious transaction in Kenya?

Within two days after the suspicion arose, under section 44(2) of POCAMLA and regulation 38(1) of the POCAML Regulations, 2023. Reports go to the FRC through goAML. If the suspicion involves a designated person, the separate sanctions rules require a freeze and a report within 24 hours.

Do we need a new risk assessment before launching a product?

Yes. Regulation 8(2) of the POCAML Regulations, 2023 requires a money-laundering and terrorism-financing risk assessment before launching new products, practices or technologies, and the outcome has to be documented and available on request. The institution-wide risk assessment under regulation 7 must also be updated at least every two years.

Can a Kenyan fintech use cloud-based AML software?

Nothing in the rules reviewed here bans it, but conditions apply. Personal data can leave Kenya only with appropriate safeguards or where the transfer is necessary under the Data Protection Act, 2019, payment service providers must notify the CBK 30 days before implementing an outsourcing agreement, and banks need CBK approval for material outsourcing. Ask vendors where data is processed and whether an in-country or on-premises option exists.


See how Creodata's AML compliance software handles fintech volumes in a 30-minute demo, or score vendors with the free AML vendor RFP checklist.

See AML Compliance Software in action.