CBK's Customer Due Diligence Guidance (2025): What It Changes for Account Opening in Kenya

What CBK's 2025 Customer Due Diligence Guidance means for KYC at account opening in Kenya: who it covers, ID checks, timing, risk, screening and records.

CS
Creodata Solutions Team
CBK's Customer Due Diligence Guidance (2025): What It Changes for Account Opening in Kenya

Short answer: CBK's Guidance on Customer Due Diligence, in effect since 1 September 2025, explains how banks, microfinance banks and other CBK-licensed institutions should apply POCAMLA and the 2023 Regulations when they open accounts. It restates the five CDD steps, gives IPRS, KRA PIN, selfie and video checks as examples, rates digital channels medium to high risk if not properly verified, and expects sanctions screening before onboarding.

This guide is for compliance officers, MLROs and the teams who design account opening at Kenyan commercial banks, microfinance banks (MFBs) and other CBK-licensed institutions. This is a practical guide, not legal advice; confirm requirements with your supervisor (CBK, SASRA) or adviser.

Creodata makes BAOS, account opening software for Kenyan banks, so we say plainly where it fits near the end. Checked against primary sources on 8 October 2026.

What is CBK's Guidance on Customer Due Diligence?

CBK issued it in August 2025 under POCAMLA s.36C(1)(d), effective 1 September 2025, alongside companion guidance on beneficial ownership and on politically exposed persons (PEPs). The duties themselves come from POCAMLA and the POCAML Regulations 2023 (LN 153 of 2023). For banks, the prudential AML guideline in force is still CBK/PG/08 of 2013; the August 2026 draft is not in force.

Who does the guidance apply to?

Para 1.2 covers commercial banks, mortgage finance companies, microfinance banks, money remittance providers, forex bureaus, payment service providers (PSPs) and non-deposit-taking credit providers.

SACCOs are not covered. They follow SASRA's AML guideline, SASRA/GG/1/2024 (24 June 2024), whose §6.1 sets out member due diligence. See our SACCO member onboarding guide and AML software for SACCOs.

What does it say about identifying and verifying a customer?

POCAMLA s.45(1) requires the customer "to produce an official record reasonably capable of establishing the true identity". For an individual, s.45(1A)(a) lists a certificate of birth, a national identity card, a passport, a driver's licence, "or" any other prescribed means of identification. Regulation 14(2)(a) requires verification "using reliable, independent source documents, data or information".

Watch the wording in para 3.3.1. The guidance says institutions "are required to obtain" the full name plus a birth certificate, national ID card, passport, driver's licence and any other prescribed means, joining the list with "and". The Act says "or", so any one official record satisfies s.45(1A)(a). If your forms copy the guidance's list, check them against the Act.

Para 3.3.1 then lists further details institutions can use, tracking reg 15(2): addresses, mobile number, occupation, source of income, the KRA PIN "where available", and references.

The KRA PIN also has a tax rule: opening an account with a financial institution is a transaction that needs a PIN (Tax Procedures Act, First Schedule item 11), and since the Finance Act 2026 non-residents are exempt (s.12(5B)). Our IPRS and KRA PIN guide explains how the two rules fit. For foreign customers, CBK expects a valid passport and a check of its authenticity (para 3.4.1).

Table 3: verification examples, not requirements

Table 3 is titled "Examples of Customer Verification":

MethodCBK's example (Table 3)
Government databasesNational ID: the ID number, serial number and name match IPRS. Passport: IPRS confirms the national ID number on the biodata page. KRA PIN: the name on the PIN matches on the KRA website
Cross-check against the IDFull names in the same order and spelling, date of birth, photograph likeness
Biometric authenticationA facial-recognition "selfie", described as particularly relevant for digital credit and mobile money providers
Video callConfirms physical presence and matches the face to the ID

Nothing in the table makes any method mandatory; the obligation is reg 14(2)(a). So "CBK requires IPRS checks" or "CBK requires video KYC" overstates the guidance. PSPs have a harder rule elsewhere: an e-money customer's ID card number or passport must be independently verified through IPRS "or through such other means as the Bank may approve" (National Payment System Regulations 2014, reg 12(2)).

How does CBK rate digital account opening?

Para 3.6.3.1(iv) weighs channel risk by factors including the level of identity verification and the degree of anonymity, and Table 4 rates the channels:

ChannelCBK's rating (Table 4)
Face-to-faceLower, because of strong verification
Digital/onlineMedium to high if not properly verified
Third-party introducersHigher if unregulated or offshore
AgentsVaries with oversight
Mobile/digital walletsHigher if unregulated

Reg 9, which the guidance does not mention, requires policies and procedures for non-face-to-face relationships, at onboarding and in ongoing due diligence. Reg 8(2) requires a risk assessment before introducing new technology or a "new delivery mechanism". No rule names a remote-verification method, so your reg 9 policy should say which checks you use and why.

Legal persons, and people acting for a customer

Para 3.3.2 restates reg 16(1): proof of incorporation or registration, the registered office, a certified board resolution naming the signatories, the particulars of the people who manage, control or own the entity, financial statements (new entities may be exempt) and the PIN. CBK's BO guidance also asks for a copy of the CR12 (para 4.6.1), today the BRS official search ordered on eCitizen.

Partnerships (reg 17) and trusts (reg 18) have their own lists. Cite the regulations in your policy, not the guidance's cross-references, which slip: para 3.3.3 cites reg 18(1) for the trust list, which is reg 18(2). Since 25 September 2026, written trusts must be registered or incorporated with the Registrar of Trusts at BRS (Trust Administration Act 2026).

For anyone acting for the customer (para 3.4.2; reg 23), CBK sets three steps:

  1. Proof of authority: a notarised or registered power of attorney, a board resolution, a letter of authorisation stating scope and duration, a partnership agreement or LLP deed, or a trust deed or trustee resolution.
  2. Full CDD on the authorised person.
  3. A check of their legal capacity and that they are not under a court injunction or regulatory ban.

The business account opening documents checklist sets out documents by entity type, and chama and group account opening covers groups, for which we found no specific rule in the 2023 Regulations.

Beneficial ownership

Para 3.4.3 quotes reg 22: institutions "shall identify and verify the natural persons behind a legal person and legal arrangement". CBK's beneficial ownership guidance adds the detail:

  • a three-step cascading test: ownership, then control by other means, then the senior managing official;
  • a 10% marker, which the Companies Beneficial Ownership Regulations put as "at least ten percent" of shares or voting rights (reg 3(2));
  • matching beneficial owners' names against the CR12 and the BO form filed with BRS (para 4.6.1), and reporting a mismatch to the FRC (para 4.8).

BRS may disclose BO information to financial institutions on Form BOF6 (reg 14(1)(c)). We found no evidence that it answers these requests online, so don't plan around instant lookups. See our beneficial ownership guide.

When must verification be complete?

The guidance and the Regulations read differently:

  • CBK para 3.2 applies CDD to new relationships and occasional transactions "regardless of the amounts", and its only timing statement is CDD "prior to opening an account".
  • Reg 25(3) requires verification "before or during the course of establishing a business relationship".
  • Reg 25(4) allows verification to finish afterwards, provided it happens as soon as reasonably practicable, is essential not to interrupt the normal conduct of business, and the risks are effectively managed. Reg 25(5) requires procedures for what the customer may do in the meantime.

The guidance does not mention reg 25(4). If your digital journey opens accounts before every check is back, base it on the regulation, write the reg 25(5) conditions into policy, record when verification completed, and agree the approach with CBK.

Risk rating and enhanced due diligence

Customer risk factors include ownership structure, nature of business, channel (Table 4), geography and source of funds and wealth (para 3.6.3.1), and ratings run low, medium and high.

  • Simplified due diligence (para 3.6.3.4; reg 21) is only for proven low risk, documented and justified, and never where there is suspicion.
  • Enhanced due diligence (para 3.6.3.5; reg 20) means more identity information, extra document checks, senior management approval before establishing or continuing the relationship, source-of-funds verification and ongoing monitoring.

For PEPs, CBK's PEP guidance applies the reg 26 measures to all foreign PEPs, and to domestic PEPs where risk is higher (para 3.2). It asks for direct PEP questions at account opening, without relying on self-declaration alone (para 5.4). See sanctions and PEP screening in Kenya.

Sanctions screening before onboarding

Para 3.6.3.2 asks institutions to screen before onboarding and on an ongoing basis, against the UN Security Council Consolidated List, the UNSCR 1267 list, the UNSCR 1373 domestic list on the FRC website, EU, OFAC and UK lists, PEP databases, and global adverse media. If a customer is UN-sanctioned, do not proceed, and file an STR. Kenya's targeted financial sanctions regulations require freezing "without delay", meaning within 24 hours of a designation at the latest, and reporting a freeze within 24 hours.

Whichever system screens, the onboarding record needs the result and the decision before the account opens. Creodata's AML software for Kenya covers the screening side.

When CDD cannot be completed: refuse and report

Para 5.1 restates reg 25(2): do not open the account, stop transactions, end any existing relationship and file a suspicious transaction report (STR), within two days after the suspicion arose (POCAMLA s.44(2)). If CDD would tip the customer off, stop and file an STR (reg 25(6)). Anonymous or fictitious accounts are banned (reg 13(1)). See our POCAMLA and POTA guide.

Records and ongoing CDD

Keep CDD records, account files, correspondence and "the results of any analysis undertaken" for at least seven years from the end of the transaction or account relationship (POCAMLA s.46(4); reg 42; guidance Part VI). Review customer information periodically, higher-risk customers first (regs 34 and 35). CBK says institutions "should use manual or automated systems" and gives examples of each; these are examples, not requirements.

What this means for a digital account-opening workflow

Whatever software you use, each CDD file should show:

StepWhat the record should show
IdentityOne official record per individual, with the ID type and number and the core personal details
VerificationWhich check ran (IPRS, KRA, document or video), by which provider or person, when, and the result
ChannelHow the customer was onboarded, as a risk factor, under a written non-face-to-face policy
Entities and agentsEntity documents, each signatory's own CDD, and their proof of authority
Beneficial ownersThe declaration, the comparison with BRS records, and measures exhausted where an owner could not be verified
PEPs and sanctionsThe PEP question, and the screening result and decision before opening
Risk and EDDThe rating, EDD steps, and senior management approval where required
TimingIf verification finished after opening, the reg 25(5) conditions and completion date

To compare systems against this list, see our account opening software buyer's guide for Kenya.

Where BAOS fits, and what it does not do

BAOS is the account-opening workflow that sits beside your identity-verification provider and your core banking system. Business, personal, group (chama) and joint accounts each have their own form, with Kenya corporate, personal and chama templates. KYC data, from ID document details to source of funds and wealth, is captured on your published form, and the KRA PIN and Kenyan ID number formats are validated as they are typed. Beneficial owners are recorded with their shareholding, PEP and FATCA declarations are made in the application, and BAOS lists every person who needs screening (directors, beneficial owners, members, holders and signatories) once each.

Reviewers claim an application, verify documents, approve or reject it, or email the applicant for more information, then record the account number once the core banking system opens the account. Every workflow action is recorded with who, what role, when and from which address, and your team can change the form without a software release.

What BAOS does not do: it does not check IDs against IPRS, BRS or KRA, run liveness or face match, screen against lists, rate risk, or hold approval until screening is done; screening runs in your screening tool. It has no multi-level account approval, so senior management approval for EDD stays in your existing process. It does not book accounts in core banking, has no retention tooling, and its audit record is not append-only. See BAOS in Kenya for how it maps to CBK and SASRA rules, or the BAOS product page for plans.

Frequently asked questions

Does CBK's Customer Due Diligence Guidance apply to SACCOs?

No. It covers banks, mortgage finance companies, microfinance banks, money remitters, forex bureaus, PSPs and non-deposit-taking credit providers (para 1.2). SACCOs follow SASRA/GG/1/2024, whose §6.1 covers member due diligence.

Does CBK require IPRS checks, selfies or video calls?

CBK gives them as examples, not requirements (Table 3). The duty is to verify against reliable, independent sources (reg 14(2)(a)). PSPs have a written IPRS requirement for e-money customer registers (NPS Regulations reg 12(2)).

Does a customer need a birth certificate, ID, passport and driving licence?

No. POCAMLA s.45(1A)(a) joins the list with "or", so any one official record satisfies it. The guidance's para 3.3.1 says "and"; follow the Act, and confirm your policy wording with CBK.

Can a bank open an account before verification is complete?

The Regulations allow it under the conditions in reg 25(4) and (5). CBK's guidance speaks only of CDD "prior to opening an account" (para 3.2), so agree your approach with CBK.

How long must CDD records be kept in Kenya?

At least seven years from the end of the transaction or account relationship (POCAMLA s.46(4); reg 42), including the results of any analysis.

More guides for Kenya

See Bank Account Opening in action.