Document Management Systems for Banks in Kenya: What to Look For
What Kenyan banks should require from an electronic document management system: records and retention, audit trails, access control, evidence for examiners and auditors, and integration with Microsoft 365.

Short answer: A bank's document management system should hold every record in one governed repository, classify it with metadata, keep every version, restrict access by role, apply retention and legal holds automatically, and log every action with who did it and when. That combination is what lets a bank produce evidence quickly for internal audit, external auditors and Central Bank of Kenya (CBK) examiners. If the bank already runs Microsoft 365, an EDMS built on SharePoint Online can deliver it inside the bank's own tenant.
This guide is for heads of operations, IT, risk, compliance and records at Kenyan commercial banks, microfinance banks and other financial institutions who are replacing file rooms, shared drives and email-based approvals. It covers what to require from any electronic document management system (EDMS), then where Creodata fits. It is not legal or regulatory advice: confirm requirements against current CBK guidance and with your compliance function.
Why banks in Kenya need an electronic document management system
Banks generate and receive documents at every step: account opening and KYC files, credit applications and security documents, board and committee papers, policies, supplier contracts, payment instructions, and correspondence with regulators and customers. The problems are familiar:
- Physical files are slow to retrieve, easy to misplace and hard to share across branches.
- Shared drives have no reliable metadata, so documents are found by memory, not by search.
- Approvals happen in email, and the approval is separated from the document it approved.
- Nobody is sure which records can be destroyed, so everything is kept, or the wrong things are deleted.
- When an examiner or auditor asks for evidence, staff spend days assembling it.
An EDMS addresses these by making the system, not individual habit, enforce how documents are stored, approved, accessed and retained.
What regulators and auditors expect to see
CBK's prudential guidelines expect banks to operate sound internal controls, segregation of duties and adequate records, and examiners and auditors test those controls by asking for evidence. The Data Protection Act, 2019 adds obligations for the personal data banks hold about customers and staff, including security safeguards and keeping data no longer than necessary. Anti-money-laundering rules require customer due diligence and transaction records to be kept for prescribed periods.
We will not quote section numbers here; the exact requirements change and your compliance team should map them. What matters for a document system is the common thread: the bank must be able to show what the record is, who created and changed it, who approved it, who can see it, and how long it will be kept.
What to look for in a document management system for banks
| Area | What good looks like | Why it matters to a bank |
|---|---|---|
| Central repository | One governed store for each document class, not personal drives and inboxes | A single source of truth for audit and operations |
| Classification and metadata | Documents tagged by type, customer or account, branch, department and date | Search, reporting and retention all depend on it |
| Version control | Every version kept and recoverable, with who changed what | Policies, contracts and credit papers can be reconstructed |
| Access control | Granular, role-based permissions tied to the bank's directory | Segregation of duties and customer confidentiality |
| Workflow | Review, approval and sign-off routed by rule, with each step recorded | Maker-checker evidence sits with the document |
| Audit trail | Every action logged with actor and timestamp, tamper-evident | Evidence examiners and auditors can rely on |
| Retention and legal hold | Schedules applied by category; holds stop deletion during disputes or investigations | Records kept as long as required and disposed of consistently |
| Search | Search by content and metadata within permissions | Evidence found in minutes, not days |
| Migration | Existing files moved with metadata intact | History is not lost when the system changes |
Records and retention
Retention is where banks carry the most hidden risk. Keep records too briefly and the bank cannot evidence a decision; keep everything forever and it holds personal data longer than the law allows and pays to store it. A workable approach:
- Build a retention schedule by document class (account opening, credit, payments, HR, contracts, board papers), agreed with compliance and legal.
- Apply it automatically in the document system, based on classification, so it does not depend on individuals.
- Use legal holds for matters under dispute, investigation or examiner query.
- Record disposal: what was destroyed, when and under which rule.
Audit trail and examiner evidence
An examiner or auditor typically picks a sample and asks for the evidence behind it: the policy in force at the time, the approval, the supporting documents and who had access. A good EDMS makes that a search, not a project. Test it in the demo by picking a real type of request, such as a board-approved policy change or a large supplier payment, and asking the vendor to produce the full history: versions, approvals, access and retention status.
The audit trail itself must be trustworthy. Ask whether any administrator can edit or delete log entries, how long logs are kept, and how they are exported.
Access control and segregation of duties
Banks need permissions that follow roles, not individuals: tellers, relationship managers, credit analysts, compliance, internal audit and senior management each see different things. Look for:
- Permissions driven by the bank's directory, so joiners, movers and leavers are handled once.
- Restricted libraries for sensitive material such as board papers, investigations and HR.
- Separation between those who prepare, review and approve a document.
- Read-only access for internal audit, so auditors can review without changing records.
Integration with Microsoft 365
Many Kenyan banks already license Microsoft 365. Building the EDMS on SharePoint Online in the bank's own tenant has practical advantages: staff work in tools they know, identity and access use the bank's existing directory, and documents stay within the bank's Microsoft 365 environment rather than in a separate vendor store. The trade-off is that SharePoint needs deliberate design (libraries, content types, metadata, permissions and retention) to behave as a governed EDMS rather than another shared drive. Ask any vendor who does that design and who maintains it.
Finance processes are a natural first use case. Payment requests, supplier invoices and petty cash all generate documents that need approval and must be kept as evidence; see payment approval workflows and audit-ready expense workflows.
Questions to ask EDMS vendors
- Show a document captured, classified and routed for approval, with each step logged.
- Restore an earlier version of a policy and show who changed it.
- Show that a teller cannot see a board paper, and that internal audit can read but not edit.
- Apply a retention rule and a legal hold, then show the disposal record.
- Produce the full evidence for one sample document in under five minutes.
- Explain where data is stored, who at the vendor can access it, and how you exit.
- Describe the migration plan for existing files and metadata.
Where Creodata fits
Creodata's EDMS solutions are built on SharePoint Online in the bank's own Microsoft 365 tenant. We configure a central, searchable repository; workflow automation that routes documents for review, approval and sign-off by rule; version control with every prior version recoverable; granular, role-based access; retention schedules and legal holds applied automatically by category; metadata and search; and a tamper-evident audit trail that logs every action with actor and timestamp.
We work in four steps: audit where documents live today and the obligations they carry; design libraries, content types, metadata and retention around how your teams work; configure SharePoint, automate workflows and migrate content with metadata intact; then train users and tune retention and permissions as obligations change.
For finance, our expense management system applies the same approach to payments: supplier invoice, petty cash and cashbook payment requests go through configurable multi-stage approval chains with SLA escalation and an audit entry for each step, every attachment is stored in SharePoint Online and linked to the request, and approved items post to Microsoft Dynamics 365 Business Central.
What we are not: a core banking system, a customer-facing document portal, or a licensed records-storage provider for physical files. We do not replace your compliance function's reading of the rules. To discuss your document estate, contact us or book a demo.
Frequently asked questions
What is an electronic document management system in Kenya?
An EDMS is software that stores, classifies, versions, secures and retains an organisation's documents, with workflows for approval and a full audit trail. In Kenya it is commonly used by banks, law firms, NGOs and public bodies to replace paper files and shared drives.
Does CBK require banks to use a document management system?
CBK does not, as far as we know, mandate a particular system. Its guidelines expect sound internal controls, audit trails and adequate records, and a document management system is a practical way to meet and evidence those expectations. Confirm specifics with your compliance team.
Can SharePoint be used as a bank's document management system?
Yes, when it is designed for it. SharePoint Online provides the platform; a bank-grade EDMS on it needs a deliberate information model, permissions, retention, workflows and audit reporting.
How long should banks in Kenya keep records?
It depends on the record type and the law or guideline that applies, including banking, tax, anti-money-laundering and data protection rules. Build a retention schedule by document class with your compliance and legal teams, and apply it in the system.
How does an EDMS help with audits and examinations?
It keeps each document with its versions, approvals, access history and retention status, so the evidence for a sampled item can be produced by search instead of assembled by hand.
Can an EDMS handle payment and expense approvals?
A general EDMS can route documents for approval. For payments specifically, a finance workflow such as an expense management system adds request types, amount-based approval chains, escalation, payment and ledger posting, with the documents kept alongside.

