SACCO Member Onboarding in Kenya: What SASRA's 2024 AML Guideline Requires
SACCO KYC requirements under SASRA/GG/1/2024: what to collect from individual, group and corporate members, IPRS and KRA checks, timing and penalties.

Short answer: SASRA's AML guideline, SASRA/GG/1/2024, requires a regulated SACCO to identify each new member before onboarding: an original ID card, passport or alien ID for individuals, a certificate of incorporation for companies, and for groups a certificate of registration plus the officials' and signatories' identities. The SACCO then verifies identity against a reliable, independent source such as IPRS or the KRA tax database.
This guide is for SACCO CEOs, compliance officers, MLROs and membership teams designing a SACCO membership form, a member onboarding process or a shortlist of SACCO software in Kenya. This is a practical guide, not legal advice; confirm requirements with your supervisor (CBK, SASRA) or adviser. Checked against primary sources on 8 October 2026.
A note on the text. SASRA's website carries two uploads of the guideline. We cite the signed copy, SASRA/GG/1/2024, with a foreword dated 24 June 2024. SASRA's site failed a security check on 8 October 2026, so the §6.1 wording summarised here was read in SASRA's earlier June 2024 upload, whose other section numbers match the signed copy. Re-check §6.1 against the signed copy before quoting it word for word.
Which SACCOs does SASRA's AML guideline cover?
SASRA has been an AML supervisory body under POCAMLA since 17 January 2022, and SACCOs are reporting institutions because they take deposits and lend. Since 20 June 2025, section 7A of the Sacco Societies Act has given SASRA express powers to supervise and enforce AML compliance.
The guideline applies to "regulated SACCOs": Sacco societies licensed or authorised under the Sacco Societies Act, and their subsidiaries, agents and other contracted parties. In practice that means:
- Licensed deposit-taking SACCOs (DT-SACCOs); and
- Authorised non-withdrawable deposit-taking SACCOs (NWDT-SACCOs). Under the Sacco Societies (Non-Deposit-Taking Business) Regulations, 2020 (reg 4(1)), a non-deposit-taking SACCO needs SASRA authorisation if its non-withdrawable deposits reach KES 100 million, if it mobilises membership or share capital through digital or electronic payment platforms, or if it mobilises it from people ordinarily resident outside Kenya.
If you plan to recruit members or collect share capital through a digital channel, check whether that brings your SACCO into scope. We could not confirm who supervises the AML compliance of SACCOs that are neither licensed nor authorised, so ask SASRA. Where the guideline conflicts with POCAMLA, its Regulations or FRC guidelines, those prevail (para 1.3). CBK's 2025 due diligence guidance covers banks and MFBs, not SACCOs (our guide to it).
When does member due diligence apply?
Under §6.1(4) to (5), due diligence applies when a person seeks to join, transacts, or exits membership; for unusual, occasional or one-off transactions; when there is a suspicion; and when the SACCO doubts information it already holds. If carrying out due diligence would tip off the member, the SACCO stops and files a report with the FRC.
What are the SACCO KYC requirements for a new member?
§6.1.1(1) sets out what the SACCO requires before onboarding a member or transacting with a customer.
| Member type | What §6.1.1(1) asks for |
|---|---|
| Individuals | An original national ID card, passport or alien identity card |
| Bodies corporate, such as companies | The certificate of incorporation, and the most recent audited financial statements where applicable |
| Unincorporated entities, such as groups and chamas | The certificate of registration, evidence of the registered address where applicable, and the identities of the officials or signatories |
Note the word "original". If you onboard members remotely, your written policy should say how the original is seen, for example at a branch or by an agent, and you should confirm the approach with SASRA. Under §6.1.1(3), the means of verification are documented in policy and applied on a risk basis.
Does SASRA require IPRS and KRA checks?
§6.1.1(2) requires the SACCO to verify identity using a reliable, independent source, and names the Integrated Population Registration Service (IPRS), the KRA tax database and other referrals as examples. Your policy decides which source you use for which member and when, so write it down and record each result on the member file.
The access route to IPRS data in law is a written application to the Cabinet Secretary, with a fee of KES 5 per record searched (Legal Notice 69 of 2016). Whether you apply directly or use a verification provider, the duty to verify stays with the SACCO. If your policy uses the KRA tax database, capture the member's KRA PIN on the form. Our guide to IPRS and KRA PIN checks explains how these checks fit into onboarding.
Who else must be identified?
People acting for a member (§6.1.2). A representative must be authorised in writing, and the SACCO identifies and verifies them as if they were the member. For a group or company, that covers each official or signatory who will operate the account.
Beneficial owners of non-natural members (§6.1.3). The SACCO understands the member's ownership and control structure, including changes, identifies the beneficial owners and takes reasonable steps to verify them. For a company member, Kenyan company law defines a beneficial owner as a natural person who holds at least 10% of the shares or voting rights, can appoint or remove a majority of the board, or exercises significant influence or control (Companies BO Regulations reg 3(2)). See beneficial ownership at account opening.
When must verification be complete?
§6.1.4 mirrors regulation 25 of the POCAML Regulations 2023. Verify before or during the relationship or occasional transaction. You may finish afterwards only if it is done as soon as reasonably practicable, is essential not to interrupt normal business, and the risks are managed. The procedures for what a member can do before verification is complete must be documented; for example, you might limit withdrawals until then.
If due diligence cannot be completed, §6.1.10 says do not open the account, end the relationship and file a suspicious transaction report. Under SASRA's para 4.3.2(b), suspicious activity goes to the FRC within two days of forming the suspicion.
What penalties can SASRA impose?
Section 7B of the Sacco Societies Act sets maximum penalties of KES 5 million for a legal person and KES 1 million for a natural person, plus up to KES 100,000 a day. POCAMLA carries its own offences and penalties (see our POCAMLA and POTA guide). Enforcement figures circulating online about SASRA sanctions could not be traced to a SASRA, FRC or Kenya Law source, so we do not repeat them.
Do chamas have to be registered to join a SACCO?
The guideline asks unincorporated entities for a certificate of registration, but the registration regime itself is in flux.
- Community groups. The Community Groups Registration Act (Cap. 108A) has been in force since 26 July 2022. The Director of Social Development, a national office, registers groups of at least ten adult members (five for a special interest group). The Community Groups Registration Regulations, 2026 (LN 154 of 2026) set the certificate as Form 2, "Certificate of Registration for Community Group". Registration is valid for two years and then renewed annually, and a change in a group's banking arrangements is a material change to be notified within fourteen days. Groups registered by the national government before the Act are deemed registered under it.
- The court ruling. On 10 September 2026 the High Court declared the Act unconstitutional for lack of public participation (Mathare Social Justice Centre & another v Bore, Cabinet Secretary for Labour & Social Protection & 8 others, [2026] KEHC 13419 (KLR)). The declaration is suspended and takes full effect at midnight on 10 February 2027 unless the defect is cured. We found no appeal or amending Bill as of 8 October 2026.
- Clubs and associations. The Societies Act covers clubs and other associations of ten or more people, which apply to the Registrar for a certificate of registration or exemption (ss.2, 9 and 10(3)).
We found no law that says an unregistered group cannot open an account. Treat an unregistered chama's application as a policy question and confirm your approach with SASRA. For comparison, banks commonly ask for the group's certificate, constitution, minutes naming the signatories, and each signatory's ID; see chama and group account opening.
How to turn §6.1 into a member-onboarding workflow
Individual members
- Show the privacy notice before collecting data (Data Protection Act s.29). SASRA's §6.1.11 says data on natural persons is handled under that Act.
- Capture identity details and the original ID, passport or alien ID, plus the KRA PIN if your policy uses KRA checks.
- Verify identity against your chosen source and record the result.
- Ask the PEP question. All foreign PEPs are high risk, and domestic PEPs are high risk where your own assessment says so; enhanced due diligence includes CEO or board approval and the source of wealth or funds (para 6.3.2).
- Screen against the sanctions lists (para 6.6.2), then decide and record the decision.
Group and chama members
- Capture the group's name, type, certificate type and number, registration date and renewal date.
- Collect the certificate of registration, evidence of the registered address where applicable, the constitution, and the minutes or resolution naming the officials, signatories and mandate.
- Identify and verify every official and signatory as you would an individual member, with written authority for anyone acting for the group.
- Keep the member register on the file if your policy needs it, and screen the officials and signatories.
Corporate members
- Collect the certificate of incorporation and the latest audited financial statements where applicable. The business account opening documents checklist lists documents by entity type.
- Collect written authority, such as a board resolution, for the people who will act for the company (§6.1.2), and verify each of them.
- Record the ownership and control structure and the beneficial owners, and take reasonable steps to verify them.
- Screen the company, its directors, beneficial owners and signatories.
For every member type, keep the file for at least seven years from the end of the relationship (POCAMLA s.46(4)), and keep it ready for review when events such as a change in ownership or PEP status trigger ongoing due diligence (§6.1.6). Our guide to AML software for SACCOs covers screening, monitoring and goAML reporting, and sanctions and PEP screening in Kenya covers the lists.
Where BAOS fits
BAOS is account opening software for Kenyan banks and SACCOs: the account-opening workflow that sits beside your identity-verification provider and your core banking system. Its personal, group (chama) and business forms map onto individual, group and corporate members; the personal and chama forms ship as drafts your team reviews and publishes. SACCO is also one of its fifteen business entity types, so a bank can onboard a SACCO itself as a business customer.
- Groups and chamas. A member register, elected officials and the group meeting resolution on the record.
- Swahili. Forms can carry English and Swahili text; your team adds the Swahili wording, and the product interface is in English.
- Who to screen. BAOS lists every person who needs screening (members, signatories, directors and beneficial owners) once each, on the application. Screening runs in your screening tool, such as Creodata's AML software.
- Documents and review. Staff verify documents one at a time or a whole application at once, and reviewers approve or reject, then record the account number once your core system opens the account.
- Changing forms. Your team can change the form without a software release, which matters while the community-groups regime is unsettled.
What BAOS does not do: it does not verify IDs against IPRS, BRS or KRA itself, run liveness or face match, screen against lists, rate risk, or hold approval until screening is done. It does not create the member in your core system, send SMS or provide e-signature, one person enters every party's details, and its audit record is not append-only. BAOS plans are public on Azure Marketplace; see BAOS plans and BAOS in Kenya. To compare it with other vendors, use the criteria in our account opening software buyer's guide.
Frequently asked questions
What documents does a SACCO need from a new member?
Under SASRA/GG/1/2024 §6.1.1, an individual presents an original national ID card, passport or alien identity card. A company provides its certificate of incorporation and recent audited accounts where applicable. A group provides its certificate of registration, evidence of its registered address where applicable, and the identities of its officials or signatories.
Does SASRA require IPRS verification for SACCO members?
SASRA requires verification against a reliable, independent source and names IPRS, the KRA tax database and other referrals as examples (§6.1.1(2)). Your written policy sets which source you use, applied on a risk basis (§6.1.1(3)).
Can an unregistered chama join a SACCO?
The guideline asks unincorporated entities for a certificate of registration, and we found no law that says an unregistered group cannot open an account. With the Community Groups Registration Act under a suspended declaration of invalidity until 10 February 2027, set a written policy for unregistered groups and confirm it with SASRA.
Can a SACCO admit a member before verification is complete?
Only within limits. §6.1.4 allows verification to finish after the relationship starts if it is done as soon as reasonably practicable, is essential not to interrupt business, and the risks are managed, with documented procedures for what the member can do meanwhile. If it cannot be completed, the SACCO ends the relationship and files a suspicious transaction report.
Which SACCOs must follow SASRA's AML guideline?
Regulated SACCOs: those licensed or authorised under the Sacco Societies Act, which means licensed deposit-taking SACCOs and authorised non-withdrawable deposit-taking SACCOs, plus their subsidiaries, agents and contracted parties.




