CBK-Compliant Digital Lending in Kenya: What the Rules Require of Your Loan Origination System
Which Kenyan lenders CBK now regulates, the rules that touch loan origination software, and how to map each one to a system capability you can evidence.

Short answer: Since 27 December 2024 the Central Bank of Kenya's licensing mandate covers all non-deposit-taking credit providers, not only digital lenders, and the Digital Credit Providers Regulations 2022 remain in force while replacement regulations are still at draft stage. No regulator certifies software, so "CBK-compliant" really means that your loan origination system produces the records that let you show compliance: consents, disclosures, credit bureau checks, approvals and a complete audit trail.
This guide is for compliance officers, heads of credit and CIOs at Kenyan digital credit providers, other non-deposit-taking lenders, microfinance banks and banks choosing or reviewing a loan origination system. It covers which rules exist, what status each has, and what each means for the software.
It is not legal advice. Several of the instruments below are in draft or have been challenged in court, so confirm every point against current law and your regulator's guidance before you rely on it.
Who CBK regulates now
Step one: digital credit providers (2021–2022). The Central Bank of Kenya (Amendment) Act, 2021 came into force on 23 December 2021. It gave CBK power to license and supervise digital lenders, approve their channels, set pricing parameters and suspend or revoke licences, and it made unlicensed digital lending an offence. The Central Bank of Kenya (Digital Credit Providers) Regulations, 2022 (Legal Notice 46 of 2022) were gazetted on 18 March 2022, and existing digital credit providers (DCPs) had to apply for a licence by 17 September 2022. CBK publishes a Directory of Digital Credit Providers; the latest we found is dated April 2026.
Step two: all non-deposit-taking credit providers (2024). The Business Laws (Amendment) Act, 2024, which commenced on 27 December 2024, amended the CBK Act so that CBK regulation now covers all non-deposit-taking credit providers (NDTCPs). Buy-now-pay-later providers, peer-to-peer lenders, asset finance and logbook lenders and credit guarantee businesses all now need CBK licensing, not only app-based digital lenders.
What is still in draft. On 7 August 2025 CBK published the draft Central Bank of Kenya (Non-Deposit-Taking Credit Providers) Regulations, 2025 for comment, with comments due by 5 September 2025. The draft proposes registration for smaller providers and licensing for larger ones, a physical office in Kenya, and consumer-protection duties covering transparent information, complaints handling and fair marketing. Once final, it would repeal the DCP Regulations 2022. As of 23 September 2026 we found only the draft, not gazetted regulations, so check the current status with CBK before relying on either instrument. Until final regulations are gazetted, the DCP Regulations 2022 are the operative detailed rules for digital credit providers.
Everyone else. Banks and microfinance banks are licensed by CBK under the Banking Act and the Microfinance Act, 2006; deposit-taking SACCOs by SASRA under the Sacco Societies Act, 2008. The data protection obligations below apply to them too, and the credit reporting rules affect most of them (confirm which apply to your licence).
What "CBK-compliant software" can and cannot mean
CBK licenses lenders, not software vendors. No loan origination system is "CBK-approved". What software can do is make your compliance provable: when an examiner, the Office of the Data Protection Commissioner (ODPC) or a court asks what happened on a loan, the system answers from its records: who applied, what they were shown and consented to, which checks ran, and who approved when.
A loan origination system runs the journey to an approved, documented and disbursed loan. A loan management system or core banking system runs the loan after that: schedules, arrears, collections and the ledger. Some digital lending rules, notably on debt collection, apply to the second, but they rely on the consents and disclosures recorded in the first. Our guide to LOS vs loan management system vs core banking explains the split in detail.
The obligations that touch loan origination software
The table maps each area to the system capability that supports it; the notes after it explain each rule's status.
| Obligation area | What the rules say (status) | What the loan origination system should do |
|---|---|---|
| Disclosure of loan terms | The DCP Regulations 2022 contain disclosure requirements; the draft NDTCP Regulations add consumer-protection duties on transparent information (draft). Exact disclosure list not verified here: check the text | Generate the offer from the configured product (amount, interest, fees, repayment terms), record exactly what version the borrower saw and when, and block progression until acceptance is recorded |
| Consent and data protection | Data Protection Act 2019 in force, regulated by ODPC; lenders must register as data controllers regardless of turnover (in force) | Capture consent with a timestamp and version, restrict access by role, record who viewed or changed personal data, and support your ODPC registration and records |
| Credit bureau checks and listing notice | CRB Regulations 2020: 30 days' notice before negative listing, no listing below KES 1,000 (operative under a Court of Appeal stay, appeal pending); DCP Regulations: 30 days' notice before negative listing (in force) | Record the bureau check and result on the application; store the borrower contact details and notice consents that servicing will need later |
| Debt-collection conduct | DCP Regulations ban threats, abusive language, use of the borrower's contact list and harassing collection tactics (in force) | Mostly outside origination. Origination should record exactly what data was collected and on what basis, and must not collect phone-book or contact-list data |
| Complaints | The draft NDTCP Regulations include complaints handling (draft); complaint-handling timelines in the DCP Regulations not verified here | Keep an application history that answers a complaint quickly: every stage, decision, document and message |
| Identity, KYC and AML | IPRS is used by financial institutions to verify ID numbers; AML/CFT obligations are covered in a separate guide | Record identity, sanctions and PEP screening results against the application before approval, with who reviewed them |
| Audit evidence | Needed to demonstrate every item above | An append-only audit trail with actor, timestamp and correlation ID for every decision, assignment and document action |
Disclosure before the borrower commits
The DCP Regulations 2022 address disclosure of terms, and the draft NDTCP Regulations list transparent information among the proposed consumer-protection duties. We have not verified the exact items the DCP Regulations require, so check the text with your advocate and configure your offer templates to match.
For the software, the test is: can you prove what this borrower was shown? The offer should be built from configured product and fee rules rather than free text, with the version presented and the acceptance both stored.
Consent and data protection
The Data Protection Act, 2019 (No. 24 of 2019) is in force, and the Office of the Data Protection Commissioner is the regulator. Under the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 (Legal Notice 265 of 2021), controllers and processors with annual turnover below KES 5 million are exempt from registration, except where they process for purposes listed in the Third Schedule, which includes financial services. In practice every lender must register, whatever its size. ODPC has also published a Guidance Note for Digital Credit Providers.
The origination system should hold a consent record per borrower with wording version and timestamp, restrict personal data by role, log who viewed or changed each record, and say where data is stored. If any personal data will be stored or processed outside Kenya, ask your advocate what the Act requires before you sign with a cloud-only vendor.
Credit bureau checks and the 30-day notice
Kenya's credit reference bureaus operate under the Banking (Credit Reference Bureau) Regulations, 2020 (Legal Notice 55 of 2020), which replaced the earlier 2013 regulations and which CBK announced on 14 April 2020. Two rules matter most here: a customer must get 30 days' written notice before negative information goes to a bureau (or a shorter contractual period), and no negative information may be submitted where the amount is below KES 1,000.
The legal status of these Regulations is disputed. On 28 August 2023 the High Court declared them void because they were sent to Parliament late. The Court of Appeal then suspended that judgment pending CBK's appeal, which in effect reinstated them. As far as we could find, the appeal has not been finally decided, so the 2020 Regulations are operative following the Court of Appeal's stay, with the appeal pending.
For digital credit providers, the DCP Regulations also require at least 30 days' written or electronic notice before negative information is submitted to a bureau.
Notices and listing are servicing events; origination supplies the evidence behind them: the bureau check, verified contact details, and the consent and terms.
Debt-collection conduct
The DCP Regulations ban collection practices including threats, violence, and obscene or profane language; accessing the borrower's phone book or contact list; unauthorised calls or messages to the borrower's contacts; and any collection tactic that abuses, oppresses or harasses.
These rules sit with collections and servicing. Origination has two jobs: never collect contact-list or phone-book data, and keep a clean record of what personal data was collected and on what basis.
Complaints and audit evidence
Complaints handling is one of the consumer-protection duties in the draft NDTCP Regulations; we have not verified the complaint timelines in the DCP Regulations, so check them before setting internal service levels. Either way, a complaint is resolved faster when the full application history, with timestamps, is one search away. The same record answers auditors and examiners. See time-stamped application audits and audit trail, RBAC and security in a lending platform.
Identity, KYC and AML screening
Financial institutions use the Integrated Population Registration System (IPRS), operated by the National Registration Bureau under the Ministry of Interior, to verify ID numbers. We have not seen a CBK rule that mandates IPRS checks by name, so treat it as standard practice rather than a quoted legal requirement. Anti-money-laundering obligations for lenders, including sanctions and PEP screening, are covered in our guide to AML compliance for fintechs and digital credit providers.
For origination, identity, credit bureau, tax PIN and sanctions/PEP results should be attached to the application before approval, with the reviewer who relied on them recorded. The compliance checks in loan origination in Kenya guide shows how that works on a check-off loan.
What to ask your vendor
Ask for each answer to be shown on screen, not described.
- Offer evidence. Show the exact offer a past borrower saw, with version and acceptance timestamp.
- Consent records. Where is consent stored, which wording version applies, and can it be exported per borrower?
- Audit trail. Is the log append-only, with actor, time and correlation ID on every action? Can an administrator edit it?
- Access control. How are roles and least privilege enforced, and is access to personal data logged?
- Bureau and identity checks. Which checks run at which stage, and where are results and reviewer decisions stored?
- Data location. Where is data stored and processed? Is there an on-premises option with the same features?
- Change control. When fees or terms change, how do you prove which terms applied to last month's loans?
- Regulatory change. When the NDTCP Regulations are finalised, what changes in configuration, and what in code?
The full list, with weights, is in the loan origination RFP checklist for Kenya, and you can download the loan origination RFP checklist (Excel) to score vendors side by side. For wider selection criteria, see the loan origination software buyer's guide for Kenya.
Where Creodata fits
Creodata's loan origination software is a workflow layer for origination and credit decisions. It records every decision, assignment and document action with actor, timestamp and correlation ID. It routes approvals by amount through configurable committee levels and re-checks the amount at every decision point, with SLA timers on each stage. Document requirements are set per product in a configurable catalogue, access is role-based on Entra ID or LDAP, and it runs on Azure or on-premises with the same features. The on-premises edition keeps data in your own data centre. For check-off lending, the Workplace Banking Application adds IPRS, CRB, KRA and Comply Advantage checks, with results kept on the application for every reviewer.
We do not provide a mobile lending app, a credit scoring model, or collections and loan servicing; those stay in your core banking or loan management system. For how approval evidence is structured, see credit approval workflows in Kenyan banks. To see the audit trail and approval evidence on your own products, book a demo.
Frequently asked questions
Is there such a thing as CBK-approved lending software?
No. CBK licenses lenders; it does not certify software. A loan origination system supports compliance by producing evidence, and the licensed lender remains responsible.
Do non-deposit-taking credit providers in Kenya need a CBK licence?
Yes. The Business Laws (Amendment) Act, 2024, which commenced on 27 December 2024, extended CBK regulation to all non-deposit-taking credit providers, including buy-now-pay-later, peer-to-peer, asset finance and logbook lenders. The detailed NDTCP Regulations were published in draft on 7 August 2025, and we had not found them gazetted as of 23 September 2026, so check the current position with CBK.
Are the Digital Credit Providers Regulations 2022 still in force?
As far as we could find, yes. The draft NDTCP Regulations would repeal them, but only once the new regulations are gazetted. Until then, digital credit providers should treat the 2022 Regulations as current and confirm the position with CBK or their advocate.
How much notice must a lender give before listing a borrower with a CRB?
Under the CRB Regulations 2020, 30 days' written notice (or a shorter contractual period), with no negative listing below KES 1,000. Those Regulations were declared void by the High Court in 2023 but are operative under a Court of Appeal stay while CBK's appeal is pending. The DCP Regulations separately require 30 days' notice.
Do small digital lenders have to register with the Data Protection Commissioner?
Yes. The registration regulations exempt organisations with turnover below KES 5 million except those processing personal data for purposes in the Third Schedule, which includes financial services. Lenders therefore register whatever their size.
Does a loan origination system handle debt-collection compliance?
Not directly. Collection-conduct rules apply to your servicing or collections system and agents. The loan origination system supports them by recording the data collected, consents and accepted terms, and it should never collect contact-list data.
This guide summarises public sources as of 23 September 2026 and is not legal advice. Confirm every point against current law and your regulator's guidance. See how Creodata's loan origination system records approval evidence in a demo, or read the SACCO loan origination guide.




