Credit Approval Workflows in Kenyan Banks: Committee Routing, Maker-Checker and Turnaround Time
How Kenyan banks route credit approvals: the committee chain, amount-based limits, maker-checker at disbursement, turnaround SLAs and audit evidence to keep.

Short answer: A sound credit approval workflow sends each loan to the lowest level with authority to approve it, re-checks that authority at every decision, separates the person who books or releases funds from the person who approves it, and measures how long each stage takes. Most delay in Kenyan banks' loan turnaround sits in the handoffs between stages rather than in the credit decisions themselves, so the workflow has to make every queue owned and visible.
This guide is for heads of credit, credit administration managers, chief risk officers, internal auditors and operations leads at Kenyan banks and microfinance banks, and at larger SACCOs with committee approvals. It describes common practice, not a legal requirement: your board-approved credit policy sets the actual chain, and you should confirm it against current law and your regulator's guidance.
Creodata builds loan origination software around this kind of workflow, and we say where it fits near the end. The design principles before that apply whatever system you use, including a spreadsheet.
The typical credit approval chain in a Kenyan bank
Names and order vary between banks, but for a corporate or SME loan the chain usually looks something like this:
| Stage | Who | What they do |
|---|---|---|
| Proposal | Relationship manager | Prepares the credit proposal: purpose, amount, structure, security, the customer's financials |
| Document check | Branch credit administration | Confirms the file is complete and documents are valid before it goes further |
| Business credit committee (BCC) | Business or branch credit committee | First credit decision; approves within its limit or recommends upwards |
| Head of business | Head of corporate or retail banking | Business sign-off on the proposal and its fit with strategy |
| Credit analysis | Credit analyst (credit risk) | Independent review of repayment capacity, risk grading and conditions |
| Management credit committee (MCC) | Senior management | Decides loans above branch and business limits |
| Board credit committee | Board members | Decides the largest exposures and, commonly, insider-related loans |
| Risk gate | Chief risk officer or risk function | Concurrence on high-value or unusual exposures |
| Legal | Legal or security perfection team | Offer letter, security documents, charges registered |
| Finance | Finance or credit operations | Confirms conditions precedent, fees and funding |
| Disbursement | Credit operations under maker-checker | Books the loan in core banking and releases funds |
Smaller retail loans skip most of this: a branch officer and a manager may approve within their limits, and the file goes straight to booking. The chain above is the full path for loans that need it. An earlier post looks at one stage in depth: MCC review workflows.
Credit policy and delegated lending authority
Behind every approval chain is a board-approved credit policy, which in most banks sets out who may approve what: the delegated lending authority. It typically defines approval limits by role or committee, by product and by risk grade, and names the exceptions that must go higher regardless of amount, such as loans to insiders, restructures or policy exceptions.
On the regulatory side, banks licensed under the Banking Act work under the CBK Prudential Guidelines and Risk Management Guidelines that came into force on 1 January 2013. On 10 September 2026 CBK published draft revised Prudential Guidelines and Risk Management Guidelines for public comment; the 2013 versions stay in force until the revisions are final. We have not set out what either version says about credit committees or approval authority here. Read the current text, and the draft, with your compliance team before you design or change the workflow.
The practical point for software is simple: the delegated authority matrix must live in the system as configuration, owned by credit risk, so a policy change is a controlled configuration change rather than a vendor release.
Designing amount-based routing
Routing by amount is where most workflows are either too rigid or too loose. A design that holds up in audit has four features.
Tiers set by policy. Each tier names the highest level that must approve. Loans below a tier's upper limit skip the committees above it, so a small facility does not wait for a board slot.
A re-check at every decision. Amounts change during approval: a committee approves a lower figure, or a relationship manager adds a facility. The system should recompute the required route every time a decision is recorded, from the current total exposure, not from the amount on the original application.
Per-office limits. A large branch may have a higher BCC limit than a small one. Limits scoped per office let you reflect that without a separate workflow per branch.
Explicit exceptions. Insider loans, policy exceptions and certain products should route upward regardless of amount, and the reason should be recorded on the file.
An illustrative matrix, with limits your credit policy would fill in:
| Tier | Total exposure | Approval required | Also required |
|---|---|---|---|
| 1 | Up to limit A | Business credit committee (BCC) | Credit admin document check |
| 2 | Above A, up to B | BCC, then head of business | Credit analysis |
| 3 | Above B, up to C | BCC, head of business, MCC | Credit analysis |
| 4 | Above C | All of the above, then board credit committee | Risk concurrence |
| Exception | Any amount | Route set by policy (for example, insider loans to the board) | Reason recorded on the file |
Base tiers on total exposure to the customer and connected parties if your policy does, not only on the new facility. Our post on escalation workflows for high-value loans looks at the top tiers in more detail.
Maker-checker and segregation of duties at booking and disbursement
Approval says the bank is willing to lend. Booking and disbursement are where money actually moves, and they need a separate control. Under maker-checker (also called dual control or four eyes), one person captures the booking or disbursement and a second, different person verifies and releases it.
A workflow should enforce three separations:
- Approver and disburser are different people. Nobody who approved the credit should also release the funds.
- Maker and checker are different people. The system, not a procedures manual, should stop one login from doing both halves.
- Configuration and use are separate. People who change approval limits or routing rules should not also approve loans under them.
Conditions precedent (security perfected, insurance in place, fees collected) should be confirmed before the disbursement stage opens, not ticked off afterwards. Our guide to maker-checker in loan booking and disbursement walks through what the maker captures and what the checker confirms.
Loan turnaround time: where it goes
Ask a bank where its loan turnaround time goes and most people will name the credit committee. Stage-level data usually tells a different story. Our composite case study, 21 days to decision, drawn from typical East African deployments rather than a single client, describes a bank where decisions inside each stage were quick and most of the elapsed time was spent waiting between stages.
The usual culprits:
- Handoffs nobody owns. A file is approved but nobody tells legal; legal finishes but finance is not notified.
- Unassigned queues. An application arrives but waits until a manager notices an email and assigns it.
- Returns without reasons. A file is sent back with "incomplete", the RM guesses what is missing, and it bounces again.
- Every loan on the same path. Small loans queue behind large ones for the same committee slot.
- Committee packs built by hand. Someone assembles documents from email and shared drives before each sitting.
Measure per stage, with SLAs
Turnaround measured only from application to disbursement cannot tell you where to act. Record the time each file enters and leaves each stage, set a service-level target per stage, and separate working time from waiting time. Loan processing turnaround time and SLAs covers how to set and monitor stage SLAs.
What to report every week
- Applications received, approved, declined and returned, by product and branch
- Median and slowest-decile time per stage, against its SLA
- Files currently breaching SLA, with the owner and days overdue
- Returns by stage and by reason
- Waiting time between stages (the handoff gaps)
- Exceptions approved above normal authority
Keep the report short enough that the head of credit reads it, and name owners, not departments.
The audit evidence examiners and auditors ask for
When an internal auditor or examiner samples loans, they want to trace each one from application to disbursement without asking anyone to remember. For every file, the workflow should be able to produce:
- The approval route the file should have taken under the policy in force, and the route it did take
- Each decision with the approver's identity, role, timestamp and comments
- Proof that each approver acted within their limit on the amount at that moment
- Returns and declines, with reasons
- Exceptions and who authorised them
- The maker and checker on booking and disbursement
- Documents and conditions precedent, with who verified them and when
- A history of changes to approval limits and routing rules
An audit trail that an administrator can edit, or one kept in a separate spreadsheet, will not satisfy a careful auditor.
Designing the workflow in software
Whichever loan approval workflow software you choose, look for these capabilities:
- Configurable stages and roles. Adding a stage or changing who acts at it should be configuration, not code.
- Configurable routing. Amount tiers, per-office limits and exception routes owned by credit risk.
- Return and decline with reasons. Structured reasons, so returns can be reported and fixed at source.
- Escalation. A file that breaches its SLA moves up a queue and alerts a named person.
- Notifications at every handoff. The next stage learns about the file the moment it is ready.
- Role-based access. Staff see only the stages and offices they work in.
- A complete audit trail. Every decision, assignment and document action logged with who and when.
- Integration with core banking. An approved loan is booked without re-keying.
Our loan origination RFP checklist turns these into scored requirements, with a free scoring workbook.
Where Creodata fits
Creodata's loan origination system is built for this workflow. It runs 13 role-gated stages from application intake to final disbursement: intake, assignment, proposal preparation and document verification; BCC decision, head approval, credit analysis, MCC review and committee review; then legal processing, finance approval, risk approval for high-value loans, loan disbursement and final disbursement. Routing through the BCC, head, MCC, committee and risk gates is amount-based, the amount is re-checked server-side at every decision, smaller loans skip higher committees, and limits are configurable and scoped per office.
Every stage has an SLA timer, and overdue files surface with priority and escalation. Email notifications go out at every handoff, and every decision, assignment and document action is logged with actor, timestamp and correlation ID. For check-off lending, the Workplace Banking Application enforces maker-checker on booking and disbursement. Loan servicing stays in your core banking system. Pricing is quoted per institution. For how origination sits beside servicing and core banking, see LOS vs loan management system vs core banking; for the full evaluation, the loan origination software buyer's guide for Kenya.
Frequently asked questions
What is a credit approval workflow?
It is the defined path a loan application takes from proposal to disbursement: who reviews it, who can approve which amounts, what checks happen at each stage and what is recorded. In a bank it is set by the board-approved credit policy and delegated lending authority, and ideally enforced by software rather than by email and printed packs.
How does the credit committee approval process work in Kenyan banks?
Practice varies, but a common pattern is a branch or business credit committee for smaller loans, a management credit committee for larger ones and a board credit committee for the largest exposures and insider loans, with credit analysis and risk review in between. Each committee approves within its limit or recommends upwards. Your credit policy sets the actual limits and order.
What is a reasonable loan turnaround time in Kenya?
There is no single benchmark; it depends on the product, the amount and how many committees a loan must pass. A better approach is to set an SLA for each stage, measure against it weekly, and work on the stages and handoffs that breach most often. Waiting time between stages is usually the largest opportunity.
What is maker-checker in loan disbursement?
Maker-checker means one person captures the booking or disbursement and a second, different person verifies and releases it. It prevents a single person from moving money on their own. Good systems enforce it so the same login cannot perform both halves, and record both identities for audit.
How should approval limits be configured in loan approval workflow software?
Set tiers by total exposure, as your credit policy defines them, with the required approvers for each tier, per-office limits where branches differ, and exception routes that apply regardless of amount. Make sure the system recalculates the route whenever the amount changes during approval, and logs every change to limits.
What audit trail should a credit approval workflow keep?
Every decision with approver identity, role, timestamp and comments; the route required under policy against the route taken; returns, declines and exceptions with reasons; the maker and checker on booking and disbursement; document verification; and a history of changes to limits and routing rules. Nobody, including administrators, should be able to edit it.
See Creodata's loan origination software route a loan through BCC, MCC and risk in a demo, or score vendors with the free loan origination RFP checklist.




