AML Software for SACCOs in Kenya: What SASRA and POCAMLA Expect, and What to Automate First

What SASRA's 2024 AML guidelines and POCAMLA require of Kenyan SACCOs, the risks in SACCO channels, and a phased plan for choosing and rolling out AML software.

CS
Creodata Solutions Team
September 17, 2026
AML Software for SACCOs in Kenya: What SASRA and POCAMLA Expect, and What to Automate First

Short answer: Kenyan SACCOs are reporting institutions under the Proceeds of Crime and Anti-Money Laundering Act (POCAMLA), and SASRA is their AML supervisor. SASRA's 2024 guidelines ask regulated SACCOs for an integrated ICT systems module that supports AML functions, continuous monitoring of member transactions against their risk profile, sanctions-list checks, and suspicious-activity reports to the Financial Reporting Centre (FRC) within two days. Most SACCOs should automate member screening and risk rating first, then reporting, then transaction monitoring.

A SACCO carries much of the same AML obligation as a bank, usually with a compliance team of one or two people. This guide sets out what the rules require, where SACCO-specific risk sits, and how to phase AML software so a small team can cope. It is written for SACCO CEOs, MLROs, boards and ICT managers. It is a practical guide, not legal advice; confirm requirements against current law and SASRA's guidance. Creodata sells AML compliance software built for Kenya, and we say where it fits near the end.

Are SACCOs covered by POCAMLA?

Yes. POCAMLA defines a reporting institution as a financial institution, a designated non-financial business or profession, or a virtual asset service provider, and it defines a financial institution by what it does. Accepting deposits from the public and lending both count, so SACCOs are reporting institutions by activity even though no schedule names them. SASRA's own guidelines say the same, and note that SACCOs could register on the FRC's reporting portal from September 2023.

SASRA has been a supervisory body under POCAMLA's First Schedule since 17 January 2022. Since 20 June 2025, section 7A of the Sacco Societies Act has given it express powers to regulate, supervise and enforce AML/CFT/CPF compliance, and section 7B sets penalties of up to KES 5 million for a legal person, up to KES 1 million for a natural person, and up to KES 100,000 for each day a breach continues.

What SASRA's 2024 AML guidelines require

SASRA's Guidelines for Regulated SACCOs on Combating Money Laundering, Terrorism Financing and Countering Proliferation Financing, 2024 took effect on issue in June 2024. They apply to Sacco societies licensed or authorised under the Sacco Societies Act, which means licensed deposit-taking SACCOs and authorised non-withdrawable-deposit-taking SACCOs, and to their subsidiaries and agents. Under the Sacco Societies (Non-Deposit-Taking Business) Regulations, 2020, a non-deposit-taking SACCO needs SASRA authorisation if its non-withdrawable deposits reach KES 100 million, or if it mobilises membership or share capital through digital platforms or from people ordinarily resident outside Kenya.

The requirements that shape an AML system are:

Requirement in the SASRA guidelinesWhat it means for software
An integrated ICT systems module that supports AML/CFT/CPF functions (para 6.0(3)(b))Screening, risk rating, monitoring, cases and reporting should work together on one record of the member, not in separate spreadsheets
Continuous monitoring of all member and customer transactions against their risk profile (para 6.4(1))Monitoring rules that use each member's risk rating and expected activity
Systems to monitor activity on a risk basis, review large, complex or unusual transactions, and monitor sanctions and domestic lists (para 6.4(2))Rule-based monitoring plus list screening that re-runs when lists change
Checks of member and customer databases and transactions against terrorism- and proliferation-financing sanctions lists, including beneficial owners and connected persons (para 6.6.2)Screening that covers the people behind group, corporate and chama accounts, not only individual members
A management-level MLRO with access to all necessary systems and records; the CEO and internal auditor cannot hold the role; the FRC and SASRA are notified of the appointment within 14 days (paras 4.1(g) and 4.3.1)Role-based access that gives the MLRO a complete view, and an audit trail of decisions
Suspicious activity reported to the FRC within two days of forming a suspicion; registration with the FRC through goAML (paras 4.3.2(b) and 4.4)A case workflow with deadline tracking that ends in a goAML report
All foreign PEPs treated as high risk, domestic PEPs where the SACCO's assessment says so, with CEO or board approval, source of wealth or funds, and the expected purpose of the account (para 6.3.2)PEP screening at onboarding and an enhanced due diligence workflow with approvals

The guidelines say that where they conflict with POCAMLA, its regulations or FRC guidelines, those prevail. Three statutory figures sit behind these duties: POCAMLA section 44(2) requires a report to the FRC within two days after a suspicion arises; cash transactions of US$15,000 or more must be reported by the Friday of the week in which they occurred (section 44(6) and regulation 40 of the POCAML Regulations, 2023); and records must be kept for at least seven years (section 46(4)). The Kenya CTR threshold guide and the goAML Kenya guide cover the filing mechanics.

Where money-laundering risk sits in a SACCO

SACCO risk looks different from a bank's. The channels and products worth monitoring include:

  • Front office cash. Deposits at FOSA counters and through agents, including structuring just below the cash reporting threshold.
  • Mobile money. Deposits, loan repayments and withdrawals through mobile wallets, where value can move in and out within minutes.
  • Third-party deposits. Money paid into a member's account by people with no evident link to the member.
  • Loans secured on deposits, and early repayment. A loan repaid early with cash or third-party funds can make illicit money look like a legitimate loan cycle.
  • Group and chama accounts. Several signatories and members behind one account, which makes beneficial ownership and screening harder.
  • Members abroad. Contributions from members resident outside Kenya, which bring cross-border risk.
  • Dormant accounts that suddenly become active.

These are patterns to write monitoring rules for, sized to your own membership. The STR indicator library for Kenya lists the indicators behind many of them.

What to automate first: a phased plan

Few SACCOs can switch everything on at once. A phased plan puts the highest regulatory exposure first.

Phase 1: screening and member risk rating. Screen every existing and new member, and the people behind group and corporate accounts, against sanctions lists, domestic lists and PEP data, and re-screen when the lists change. Give every member a risk rating with a recorded basis, and route PEPs and high-risk members to enhanced due diligence with the approvals the guidelines require. Our guide to sanctions and PEP screening in Kenya covers the lists and the evidence to keep.

Phase 2: reporting. Register on goAML if you have not, detect cash transactions above the reporting threshold across branches, agents and channels, and move suspicious-activity cases through a workflow with the two-day deadline visible to the MLRO. Validate report files before submission; the free goAML XML validator checks a file against the schema.

Phase 3: transaction monitoring. Once transaction feeds from your core system and mobile channels are reliable, add rules for the patterns above, measured against each member's risk profile. Back-test each rule on historical data before it goes live, so the alert volume suits a small team. Transaction monitoring software in Kenya explains channels, typologies and tuning.

Throughout: evidence. Every rating, screening decision, closed alert and report decision should be recorded in a log that cannot be edited, because SASRA and the FRC will ask how the programme operated, not only what the policy says.

Choosing AML software as a SACCO

The general evaluation criteria in our buyer's guide to AML compliance software in Kenya apply. Five questions matter most for SACCOs:

  1. Does it integrate with our core SACCO system and mobile channels? Ask which SACCO systems the vendor has connected to and how mobile money transactions arrive.
  2. Can we start small? Look for modules you can license separately, so screening and risk rating can go live before monitoring.
  3. What will list data cost? Sanctions and PEP data is often a separate subscription, which matters more to a SACCO budget than to a bank's.
  4. Who supports us, and when? Support during East Africa Time matters when a reporting deadline is close.
  5. Where does our members' data sit? Kenya's Data Protection Act, 2019 allows transfers of personal data out of Kenya only with proof of appropriate safeguards or where a transfer is necessary, and sensitive personal data also needs the member's consent. Ask for the hosting location in writing.

Our free AML vendor RFP checklist turns these into scored requirements. Adjust the priorities for your SACCO's size rather than deleting rows.

Where Creodata fits

Creodata's AML software for SACCOs and banks is licensed by module, so a SACCO can begin with the Starter tier (sanctions, PEP and adverse-media screening, a six-factor member risk rating with four-eyes overrides, and case basics) and move to Growth when it is ready for transaction monitoring, STR and CTR reporting and ingestion connectors. Screening, risk rating, monitoring, cases and reporting share one record of the member, periodic reviews are scheduled by risk band, every decision is kept in an append-only audit log, and reports hand off to the Creodata goAML Reporting Platform for the FRC filing. It runs on Microsoft Azure or on-premises in your own data centre with the same features. To see it on your own member scenarios, book a demo.

Frequently asked questions

Do SACCOs in Kenya have to comply with POCAMLA?

Yes. POCAMLA treats any business that accepts deposits from the public or lends money as a financial institution, and financial institutions are reporting institutions. SASRA is the SACCO sector's supervisory body under POCAMLA's First Schedule, and its 2024 guidelines state that SACCOs are reporting institutions that register with the FRC through goAML.

Which SACCOs do SASRA's AML guidelines cover?

The 2024 guidelines cover Sacco societies licensed or authorised under the Sacco Societies Act: licensed deposit-taking SACCOs and authorised non-withdrawable-deposit-taking SACCOs, together with their subsidiaries and agents. A non-deposit-taking SACCO needs authorisation if its non-withdrawable deposits reach KES 100 million, or if it mobilises membership or share capital through digital platforms or from people ordinarily resident outside Kenya.

Does SASRA require SACCOs to use AML software?

The guidelines do not name a product, but they require a risk-based AML programme that includes an integrated ICT systems module supporting AML/CFT/CPF functions, continuous monitoring of member transactions against their risk profile, and systems to monitor sanctions and domestic lists. For most SACCOs, meeting those requirements in practice means dedicated AML software rather than spreadsheets.

How quickly must a SACCO report a suspicious transaction?

Within two days. POCAMLA section 44(2) requires a report to the FRC within two days after the suspicion arose, and SASRA's guidelines repeat that suspicious activity is reported to the FRC within two days of forming a suspicion. The clock runs from the suspicion, not from the end of an investigation, so the case workflow needs to show the deadline from the start.

What are the penalties for a SACCO that breaches AML requirements?

Section 7B of the Sacco Societies Act, in force since 20 June 2025, sets penalties of up to KES 5 million for a legal person and up to KES 1 million for a natural person, plus up to KES 100,000 for each day the breach continues. Penalties under POCAMLA itself can apply as well.

Can a small SACCO afford AML software?

Often, if it phases the rollout and compares full costs. Start with screening and risk rating, add reporting and monitoring as data feeds mature, and ask each vendor for a three-year cost that includes list data, integration, hosting and support. Software licensed by module lets a SACCO pay for what it uses now and add capability later.


See how Creodata's AML compliance software works on SACCO scenarios in a 30-minute demo, or score vendors with the free AML vendor RFP checklist.

See AML Compliance Software in action.