Choosing an AML Software Vendor in Kenya: The RFP Checklist and Free Scoring Template

A 47-point RFP checklist for choosing AML software in Kenya: vendor questions, evidence requests and a free scoring spreadsheet for banks, SACCOs and fintechs.

CS
Creodata Solutions Team
September 17, 2026
Choosing an AML Software Vendor in Kenya: The RFP Checklist and Free Scoring Template

Short answer: Score AML software vendors on evidence, not brochures. Our free checklist gives you 47 requirements in nine areas, the question to put to each vendor, the evidence to ask for, and a spreadsheet that weights and scores up to three shortlisted suppliers. Download it, adjust the priorities to your institution, and send the questions out with your RFP.

Download the AML vendor RFP checklist and scoring template (Excel, 24 KB)

Every AML software brochure promises end-to-end coverage. The differences only show up when you ask specific questions: can the system produce goAML XML that the Financial Reporting Centre (FRC) accepts, does its screening cope with Kenyan and Swahili names, does its monitoring see mobile money and agent transactions, and can it prove what happened to an alert that was closed eight months ago? A scored process also gives your board, your auditor and your regulator a record of why you chose the vendor you did.

A word on who wrote this. Creodata sells AML compliance software built for Kenya, so we have deliberately written criteria that any serious vendor, including us, should be able to evidence. Use it to score us alongside everyone else. This is a practical procurement guide, not legal advice: confirm current requirements against the law and your regulator's guidance before you issue an RFP.

What is in the checklist

The workbook has three tabs. Read me explains how to use it and lists the sources to check. Requirements holds the 47 requirements, each with why it matters in Kenya, the question to ask, the evidence to request, a priority and a score for up to three vendors. Scoring summary calculates the results.

AreaRequirementsWhat it tests
1. Regulatory fit (Kenya)8goAML reporting to the FRC, deadlines, targeted financial sanctions, PEPs, beneficial owners, record keeping, inspection evidence
2. Customer due diligence and risk rating5Configurable risk model, controlled overrides, periodic reviews, EDD
3. Sanctions and PEP screening6List coverage and cost, matching quality on local names, false-positive control, rescreening
4. Transaction monitoring6Channel coverage, Kenyan typologies, rule changes, back-testing, tuning
5. Case management and reporting5Case workflow, MLRO approval, tipping-off controls, audit trail, MI
6. Data and integration4Core banking or SACCO system integration, feed resilience, data quality
7. Deployment, security and data protection6Data location, Data Protection Act compliance, security assurance, resilience, support
8. AI and model governance2Explainability, human decisions, model approval
9. Commercials and vendor5Three-year cost, implementation plan, references, exit, regulatory updates

Each requirement carries a priority. By default a Must weighs 5, a Should 3 and a Could 1; you can change those defaults, or override the weight of any single requirement. Vendors are scored from 0 (not available) to 5 (exceeds the requirement, with evidence from production). The summary shows each vendor's weighted score, how many requirements you have scored, how many Must-haves scored below 3, and a score by area, so a vendor that is strong on screening but weak on reporting cannot hide behind one total.

The nine areas, and the requirements that decide most evaluations

1. Regulatory fit in Kenya

Start here, because a gap in this area is the one an examiner will find.

  • goAML reporting. Every reporting institution files with the FRC through goAML. Ask for a validated goAML XML file for a suspicious transaction report (STR) and a cash transaction report (CTR), and ask how the vendor ships FRC schema changes. Our goAML Kenya guide covers the filing mechanics, and the free goAML XML validator lets you check a sample file yourself.
  • Deadlines. Suspicious transaction reports are due within two days after the suspicion arose (POCAMLA section 44(2)), and cash transaction reports for transactions of US$15,000 or more by the Friday of that week (POCAML Regulations, 2023, regulation 40). The workflow should show time-to-deadline on every draft report and escalate before a breach.
  • Targeted financial sanctions. FATF Recommendations 6 and 7 require the funds of designated persons to be frozen without delay, which Kenya's 2026 terrorism-financing sanctions regulations define as within 24 hours of a designation at the latest. Ask how long it takes from a new UN or domestic designation to rescreening of your whole customer base, and ask to see the log.
  • PEPs and beneficial owners. Domestic politically exposed persons, their families and close associates, and the natural persons behind legal-entity customers, all need to be identified and screened.
  • Record keeping and inspection evidence. Records must be kept for at least seven years from the transaction or the end of the relationship (POCAMLA section 46(4)) and be retrievable quickly, for the FRC and for your sector regulator.

2. Customer due diligence and risk rating

A risk-based approach only works if compliance can change the model itself. Ask the vendor to change a factor weight during the demo, then show that the change was versioned and approved. Overrides should need a second approver and a recorded reason, reviews should be scheduled automatically by risk band, and every rating should show the factors that produced it. The customer risk assessment guide covers model design.

3. Sanctions and PEP screening

Two questions separate screening vendors quickly. First, which lists are included, which cost extra and who holds the data licence, because list data is often priced separately. Second, how well does matching work on your own names? Send a sample of known true and false matches, including Kenyan and Swahili names, reversed name order and transliterated spellings, and compare the results. Our guide to sanctions and PEP screening in Kenya explains what to screen and how to evidence it.

4. Transaction monitoring

Monitoring has to see the channels your customers actually use: cash, mobile money, agent banking, cards, RTGS and PesaLink transfers, and remittances. Ask for the rule catalogue and the typology each starter rule targets, watch a compliance analyst build a rule without vendor help, and ask for a back-test on historical data before any rule goes live. Transaction monitoring software in Kenya goes deeper on channels and tuning.

5. Case management and reporting

Alerts should become owned cases with SLAs and escalation. STR decisions should need MLRO approval with the rationale recorded, suspicion-related cases should be hidden from staff who deal with the customer, and the audit trail should be append-only. Ask directly whether any user, including an administrator, can alter or delete an audit entry. The audit trail and four-eyes guide explains why this matters in an inspection.

6. Data and integration

Integration is usually the largest implementation risk. Ask which core banking or SACCO systems the vendor has integrated with in Kenya, and what happens when a nightly file fails or arrives twice. A failed feed must be visible rather than a silent gap in monitoring.

7. Deployment, security and data protection

Ask exactly where your data will be stored and processed, whether it can stay in Kenya, and whether the vendor will sign your data processing agreement under the Data Protection Act, 2019. Ask for current security certifications, the latest penetration-test summary, and the uptime, recovery-point and recovery-time commitments in the contract. Support during East Africa Time matters when an issue lands close to a filing deadline.

8. AI and model governance

If a vendor uses machine learning, every score should come with its reasons and a human should make the decision. Ask who approves a model before it goes live and how it is rolled back. The explainable AI in AML guide sets out the controls to expect.

9. Commercials and vendor

Ask for licence, list data, implementation, hosting and support costs over three years, a plan with named client-side responsibilities, two references of similar size and sector, exit terms that return your records in a usable format, and confirmation that regulatory updates are covered by maintenance rather than billed as change requests.

How to run the evaluation

  1. Agree priorities first. Compliance, risk, IT and procurement should set the Must, Should and Could priorities before anyone speaks to a vendor.
  2. Long-list with the Must-haves only. A short request for information built from the Must requirements removes vendors that cannot meet the basics.
  3. Issue the RFP. Send the "Ask the vendor" and "Evidence to request" columns as your question set and require written answers.
  4. Run scripted demos on your own data. Give every vendor the same scenarios (see below) and the same sample data.
  5. Call references. Ask what went wrong during implementation, not only what went right.
  6. Score independently, then calibrate. Each panel member scores alone before the panel agrees final scores, which limits anchoring on the loudest voice.
  7. Check cost and exit terms. Compare three-year costs on the same basis and read the exit clause before you negotiate price.
  8. Record the decision. Keep the completed workbook with the evaluation papers. It shows your board and your examiner how the choice was made.

Five scripted demo scenarios to give every vendor

ScenarioWhat to watch
Onboard a new customer who is a domestic PEPWhether the match is found, why, and whether EDD is triggered and approved
Screen a near-match to a sanctioned name with a different spelling and name orderThe match explanation, and how the false positive is closed and re-checked later
Load a week of transactions showing cash structuring and rapid pass-through via mobile moneyWhich rules fire, how the alert reaches a case, and the time to close it
Take a case to an STRMLRO approval, the restricted-access controls, and a goAML XML file you can validate
Ask for the evidence on a case closed last quarterHow quickly the full history, the list version used and the audit trail appear

Red flags

  • The vendor cannot show a goAML XML file that validates, or says reporting is "on the roadmap".
  • Screening is only ever demonstrated on the vendor's own sample names.
  • Rule counts are offered as proof of quality, with no back-testing or tuning method.
  • List data costs are vague or missing from the price.
  • Audit entries can be edited by an administrator.
  • Must-have requirements are answered with roadmap dates.
  • No reference institution of similar size and sector is willing to take a call.
  • The answer to "where is our data?" changes between the sales call and the contract.

Where Creodata fits

Creodata's AML compliance software covers all nine areas in one workspace: sanctions, PEP and adverse-media screening with multi-script matching and a structured false-positive workflow, a six-factor customer risk rating with four-eyes overrides, transaction monitoring with back-testing and versioned rule promotion, case management with EDD, and STR and CTR reporting that hands off to our goAML Reporting Platform for the FRC filing. It runs on Microsoft Azure or on-premises with the same features, and each module is licensed separately. We would rather be scored against this checklist than chosen without it. Book a demo and bring your own scenarios.

For the wider picture before you shortlist, read the buyer's guide to AML compliance software in Kenya. If your institution is a SACCO or a fintech, see AML software for SACCOs in Kenya and AML compliance for fintechs and digital credit providers.

Frequently asked questions

What should an AML software RFP include?

It should state your priorities, the requirements with the question each vendor must answer, the evidence you expect, the demo scenarios every vendor will run on your data, and the commercial information you need for a three-year cost comparison. It should also ask about data location, data protection, implementation responsibilities and exit terms, because those are the points most often left vague until contract negotiation.

How should we weight requirements when comparing AML vendors?

Agree weights before you see any vendor, so the scoring reflects your risks rather than the best demo. The template's defaults weigh a Must-have 5, a Should-have 3 and a Could-have 1, and any single requirement can be overridden. Look at the Must-haves scored below 3 as well as the total: a high overall score can hide a failure on reporting or screening that no other strength makes up for.

Should a SACCO use the same checklist as a bank?

Yes, with different priorities. A SACCO still screens members, monitors transactions and files reports, but it may mark real-time screening or AI governance as Could-haves and give more weight to cost, integration with its core system and a phased start. Change the priorities on the Requirements tab rather than deleting rows, so the evaluation record shows what you considered.

How many AML vendors should we shortlist?

Most institutions get the best result from a long-list of five to eight suppliers, reduced to two or three for scripted demos and reference calls. Scoring more than three in depth takes time without improving the decision. The template's summary sheet is built for three shortlisted vendors.

Can we use this checklist in Uganda, Tanzania, Zambia or Rwanda?

Most of it applies unchanged. Replace the Kenya-specific references in the regulatory area with your own financial intelligence unit, law and sector supervisor, and check the local reporting rules. Our pages on AML software in Uganda, Tanzania, Zambia and Rwanda link to the relevant filing guides.

Is the checklist free to use and edit?

Yes. Download it, edit the requirements and priorities, add your own rows and share it inside your institution. If you insert new requirements, insert them inside the table so the summary formulas include them.


Download the AML vendor RFP checklist and scoring template, or see how Creodata's AML software scores against it in a 30-minute demo.

See AML Compliance Software in action.