AML Compliance Software in Kenya: A Buyer's Guide for Banks, SACCOs and Fintechs (2026)
How to choose AML compliance software in Kenya: what it must do for FRC reporting, the types of vendor, evaluation criteria, what drives cost, and red flags.

Short answer: Good AML compliance software for a Kenyan institution does five jobs well: it screens customers against sanctions and PEP data, rates customer risk, monitors transactions across every channel you run, turns alerts into documented cases, and gets suspicious and cash transaction reports to the Financial Reporting Centre (FRC) through goAML. Choose on evidence from scripted demos on your own data, and compare three-year costs on the same basis.
This guide is for compliance officers, MLROs, heads of risk and procurement teams at Kenyan banks, microfinance banks, SACCOs, fintechs, insurers and other reporting institutions who are replacing spreadsheets or an older system. The stakes rose when the FATF placed Kenya under increased monitoring in February 2024. Kenya was still on that list after the FATF's June 2026 plenary, with risk-based supervision, suspicious transaction reporting and a targeted financial sanctions framework among the items still to complete.
Creodata sells AML compliance software built for Kenya, so we say plainly where we fit near the end. The criteria before that are the ones we would use to choose any vendor. This is a practical guide, not legal advice: confirm requirements against current law and your regulator's guidance.
What AML compliance software does
AML software turns your customer and transaction data into the decisions an AML programme has to make, and keeps the evidence of each one.
| Function | What it does | What matters in Kenya |
|---|---|---|
| Customer due diligence and risk rating | Scores each customer's money-laundering risk from factors such as geography, product, channel and PEP status | A model your compliance team can change, with every override approved and recorded |
| Sanctions and PEP screening | Checks names against sanctions lists, PEP data and adverse media, at onboarding and whenever lists change | Matching that copes with Kenyan and Swahili names, and proof of which list version was used |
| Transaction monitoring | Runs rules and models over transactions to raise alerts on suspicious patterns | Coverage of cash, mobile money and agent banking as well as bank transfers |
| Case management | Turns alerts into owned cases with deadlines, evidence and approvals | MLRO approval of reporting decisions and restricted access to suspicion-related cases |
| Regulatory reporting | Prepares suspicious and cash transaction reports | goAML XML that the FRC's portal accepts |
| Audit trail | Records every action and decision | An append-only log that holds up in an FRC or sector-regulator inspection |
The complete AML platform guide explains each function in depth.
Who needs AML software in Kenya
Under the Proceeds of Crime and Anti-Money Laundering Act (POCAMLA), a reporting institution is a financial institution, a designated non-financial business or profession (DNFBP), or, since November 2025, a virtual asset service provider. Financial institutions are defined by what they do, so the Act reaches banks and microfinance banks, SACCOs, lenders including digital credit providers, payment and e-money providers, money remitters, forex bureaus and life insurers. The DNFBPs are casinos, real estate agencies, dealers in precious metals and stones, accountants, trust and company service providers, and advocates, notaries and other independent legal professionals.
Every reporting institution must register with the Financial Reporting Centre (section 47A), which the FRC handles through goAML. Each also answers to a supervisory body listed in the Act: the Central Bank of Kenya, SASRA, the Insurance Regulatory Authority, the Capital Markets Authority, the Retirement Benefits Authority, the Gambling Regulatory Authority, the Estate Agents Registration Board, ICPAK or the Law Society of Kenya.
Not every institution needs the same system. A tier-1 bank needs real-time monitoring across many channels and a large analyst team's workflow. A SACCO or microfinance bank usually needs dependable screening, risk rating and reporting first, at a cost that fits its size; our guide to AML software for SACCOs covers that case. A fintech or digital lender needs screening and monitoring that keep pace with high-volume digital onboarding, covered in AML compliance for fintechs and digital credit providers.
Spreadsheets and manual review can carry a very small institution for a while. They stop working when volumes grow, when two people apply the same rule differently, or when an examiner asks why a customer was rated low risk and the answer is in someone's memory.
The Kenyan requirements that shape the choice
Most vendor demos look alike until you test them against the rules your institution actually works under. These are the ones that separate a Kenyan deployment from a generic one:
- Reporting through goAML. Suspicious transactions must be reported to the FRC within two days after the suspicion arose (POCAMLA section 44(2)), and cash transactions of US$15,000 or more by the Friday of the week in which they took place (section 44(6) and regulation 40 of the POCAML Regulations, 2023). goAML is the FRC's prescribed reporting channel, so the software has to produce files the portal accepts.
- Ongoing monitoring. Section 44(1) requires ongoing monitoring of complex, unusual, suspicious and large transactions. The law does not prescribe a technology, and the Central Bank of Kenya's 2025 guidance on customer due diligence accepts manual or automated systems. Some sector rules ask for systems outright: payment service providers must use systems capable of screening transactions (National Payment System Regulations, 2014, regulation 31), SASRA's 2024 guidelines ask regulated SACCOs for an integrated ICT systems module for AML, and the IRA's guidelines ask insurers for a management information system that can detect suspicious activity.
- Targeted financial sanctions. Kenya's 2026 terrorism-financing sanctions regulations require the funds of designated persons to be frozen without delay, defined as within 24 hours of a designation at the latest, and the freeze to be reported within 24 hours. Screening has to catch changes to the UN lists and Kenya's Domestic List fast enough to meet that.
- PEPs and beneficial owners. Regulation 26 of the POCAML Regulations, 2023 requires enhanced measures for every foreign politically exposed person, including senior management approval and establishing the source of wealth and funds, and for domestic PEPs where the relationship is higher risk. Legal-entity customers must be understood down to the natural persons who ultimately own or control them.
- Records. Transaction and identification records must be kept for at least seven years from the transaction or the end of the relationship (section 46(4)).
- Data protection and outsourcing. The Data Protection Act, 2019 allows personal data to leave Kenya only with proof of appropriate safeguards or where the transfer is necessary. Banks also need CBK approval for material outsourcing, which the CBK's outsourcing guideline says includes data centres and KYC activities for AML compliance.
The types of AML software provider in Kenya
A search for AML software in Kenya returns very different kinds of supplier. Knowing which kind you are talking to tells you what to test.
| Provider type | Typical strengths | Watch for |
|---|---|---|
| Global AML suites | Depth, large-bank references, mature analytics | Cost, long implementations, and whether goAML reporting and local channels are supported out of the box or through partners |
| AML modules from core banking vendors | Tight integration with the vendor's own core system | Depth of screening and monitoring compared with specialist tools, and lock-in to one core platform |
| Local compliance consultancies offering software | Advisory expertise, local presence, outsourced MLRO or reporting support | Whose software it is, who supports it, and whether the tool is a full system or a tracker for obligations and policies |
| Identity verification and KYC API providers | Fast digital onboarding, document and biometric checks | These usually cover onboarding checks, not transaction monitoring, case management or FRC reporting |
| Regional AML software vendors | goAML reporting and East African channels built in, local support | Scale of references, security assurance, and the roadmap behind each module |
| Spreadsheets and in-house builds | Low starting cost, full control | Key-person risk, no audit trail, and the cost of keeping pace with regulatory change |
Several of these can be combined. An institution might use an identity verification API at onboarding and a separate AML system for screening, monitoring and reporting. What matters is that the pieces share a record of the customer, so the evidence does not fragment.
Evaluation criteria
Score every vendor against the same requirements, weighted before the first demo. Our free AML vendor RFP checklist turns these areas into 47 requirements, vendor questions and a scoring spreadsheet.
| Area | What to test |
|---|---|
| Regulatory fit | A goAML XML file that validates; deadline tracking; how quickly new UN and domestic designations reach screening |
| Risk rating | Compliance can change the model without code; overrides need four eyes; ratings explain themselves |
| Screening | Matching quality on your own sample of Kenyan names; list coverage and cost; false-positive control |
| Transaction monitoring | Channel coverage including mobile money and agents; Kenyan typologies; back-testing before rules go live |
| Case management | SLAs and escalation; MLRO approval; tipping-off controls; append-only audit trail |
| Data and integration | Proven integration with your core banking or SACCO system; visible handling of failed feeds |
| Deployment and data protection | Where data is stored and processed; a data processing agreement under the Data Protection Act, 2019; security assurance |
| AI governance | Explanations for every score; a human makes the decision; model approval and rollback |
| Commercials | Three-year cost; implementation plan; local references; exit terms; regulatory updates included |
For monitoring and screening detail, see transaction monitoring software in Kenya and sanctions and PEP screening in Kenya.
How to run the evaluation
- Set priorities with compliance, risk, IT and procurement before meeting vendors.
- Long-list five to eight suppliers and remove those that fail your Must-have requirements.
- Issue an RFP with the questions and the evidence you expect.
- Run scripted demos on your own sample data: a domestic PEP at onboarding, a sanctions near-match, a structuring pattern across cash and mobile money, and an alert taken all the way to an STR.
- Call references of similar size and sector, and ask what went wrong as well as what went right.
- Score independently, then calibrate as a panel, and keep the completed scoring sheet with the decision papers.
What AML software costs in Kenya
Vendors price AML software in very different ways, which is why brochure prices rarely compare. Ask every shortlisted vendor to itemise the same cost lines over three years:
- Licence model: per module or tier, per customer or account, per transaction, or a flat enterprise fee.
- List data: sanctions, PEP and adverse-media data is often a separate subscription from a data provider.
- Implementation: data mapping, integration with your core system, rule configuration and training.
- Hosting: cloud subscription and consumption costs, or servers and operations for an on-premises deployment.
- Support and maintenance, including whether regulatory changes such as FRC schema updates are covered.
- Internal effort: the analyst and IT time your own team will spend during and after implementation.
A lower licence fee can hide higher data, integration or change-request costs, so compare the three-year total, not the first-year quote.
Red flags
- The vendor cannot show a goAML XML file that validates, or treats FRC reporting as a future feature.
- Screening is demonstrated only on the vendor's sample names, never on yours.
- The number of monitoring rules is offered as proof of quality, with no back-testing or tuning method.
- An administrator can edit or delete audit entries.
- Answers about where your data is stored are vague or change between meetings.
- Must-have requirements are answered with roadmap dates.
- No institution of similar size and sector will take a reference call.
Where Creodata fits
Creodata is a Nairobi software company, and our AML compliance software is a regional vendor's answer to the criteria above. It covers sanctions, PEP and adverse-media screening with multi-script matching and a false-positive workflow, a six-factor customer risk rating with four-eyes overrides, transaction monitoring in batch and streaming with back-testing before rules go live, case management with enhanced due diligence, and STR and CTR reporting that hands off to our goAML Reporting Platform for the filing. It runs on Microsoft Azure or on-premises with the same features, and each module is licensed separately, so a SACCO can start with screening and risk rating and a bank can run the full suite. The same software serves institutions in Uganda, Tanzania, Zambia and Rwanda. If you are shortlisting, book a demo and bring your own scenarios.
Frequently asked questions
What is the best AML software in Kenya?
There is no single best system; there is the best fit for your institution's size, channels and risks. A tier-1 bank, a SACCO and a digital lender need different depth and pricing. Shortlist two or three vendors that meet your Must-have requirements, run the same scripted demos on your own data, and score them with a weighted checklist such as our AML vendor RFP checklist.
How much does AML software cost in Kenya?
It varies widely because vendors price differently: by module or tier, by customer or account, by transaction volume, or as an enterprise licence, with list data, implementation and hosting often charged separately. Ask each shortlisted vendor to itemise licence, data, implementation, hosting and support costs over three years, and compare the totals rather than first-year prices.
Do SACCOs in Kenya need AML software?
Yes, in practice. SACCOs are reporting institutions under POCAMLA because they take deposits and lend, and SASRA's 2024 AML guidelines require regulated SACCOs to maintain an integrated ICT systems module that supports AML functions and to monitor member transactions continuously against their risk profile. The guidelines do not name a product, but a spreadsheet struggles to meet those requirements once membership grows. Our guide to AML software for SACCOs covers what to automate first.
Can AML software file reports directly with the FRC?
Reports reach the FRC through its goAML system, so what matters is whether the software produces goAML XML that the portal accepts and tracks each report to acknowledgement. Ask for a validated sample file and ask how the vendor handles FRC schema changes. Our goAML Kenya guide explains registration and filing.
Should AML software be hosted in the cloud or on-premises in Kenya?
Either can work. Cloud deployments are faster to start and easier to scale; on-premises deployments keep data in your own data centre. Your decision should reflect the Data Protection Act, 2019, your regulator's rules on outsourcing and cloud services, and your own risk appetite. Ask every vendor exactly where data is stored and processed, and whether both deployment options have the same features.
How long does it take to implement AML software?
It depends mostly on data and integration rather than on the software. Screening and risk rating need clean customer data; transaction monitoring also needs reliable transaction feeds from every channel. A phased plan that starts with screening and risk rating and adds monitoring once feeds are proven reduces risk. Ask vendors for a plan with named responsibilities on both sides.
See how Creodata's AML software meets these criteria in a 30-minute demo, or score every shortlisted vendor with the free AML vendor RFP checklist.




