AML compliance software · Kenya & East Africa

AML compliance software for Kenya's banks, SACCOs and fintechs.

Find the risk. Prove the decision.

Sanctions and PEP screening, transaction monitoring, customer risk rating, case management and STR/CTR reporting to the Financial Reporting Centre, in one analyst workspace. A single codebase serves a tier-1 bank and a small intermediary alike — cloud or on-premise, at parity.

FRC Kenya reporting via goAMLCloud or on-premiseBanks, SACCOs, fintechs, DNFBPsKenya, Uganda, Tanzania, Zambia, Rwanda
app.creodata.aml · DashboardGCB Cell · MLRO
Dashboard
Last 24 hours · screening, cases, monitoring
en-GB
Open alerts
247
+12 since yesterday
Cases opened today
38
On track
SARs pending review
4
2 awaiting MLRO
SLA breaches
2
Escalated
Recent alertsOpen queue →
FA
Fatima Al-Mansouri
PEP match · 92% confidence
◕ Very high
JS
João da Silva
Sanctions · partial name
◑ High
AR
Alex Rivera
Adverse media · low
● Low
50+
Starter TM rules
Typology-aligned, back-tested rule pack out of the box
8
Sector packs
Banking to VASP, insurance to DNFBPs — one configuration each, not a fork
10
Locales + Arabic RTL
Every string via i18n, CLDR number and date formatting
2
List providers, plus your own
Dow Jones and World-Check sync, manual watchlist upload — versioned, with freshness dashboards
The problem

Not an AML problem so much as a fragmentation problem.

Risk scoring lives in one spreadsheet, sanctions screening in a separate tool, transaction alerts in a third system — and the evidence an examiner asks for is scattered across inboxes and shared drives. Point tools and manual process create more risk than they remove.

The cost is not only operational. An AML programme that cannot show its evidence on demand is hard to defend, regardless of how diligent the team actually is.

  • Decisions cannot be reconstructed

    When a regulator or auditor asks why a customer was rated low-risk, or why an alert was closed, the answer sits in someone's memory or a deleted email rather than an immutable log.

  • Work is duplicated and inconsistent

    The same customer is screened in one system, scored in another and investigated in a third, with no shared view of how those decisions connect.

  • Spreadsheets do not scale or survive scrutiny

    Manual scoring models and ad-hoc watchlists drift out of date, lack version history, and offer no four-eyes control over the overrides that matter most.

What changes

What changes when the programme runs on one record.

Screening, risk rating, monitoring, cases and reporting share one entity context — so the evidence is there when the question comes.

Every decision is defensible

The data, the rule, the score and the reasoning sit one click away, in an append-only audit log.

Analysts work real matches, not noise

Multi-script, locale-aware matching, a structured false-positive workflow and entity resolution take the look-alikes out of the queue.

One record from first screen to filed STR

Case, EDD and the SAR/STR lifecycle live in the same workspace, handing off to goAML for the filing itself.

Start with what you need

Modules are licensed by tier and switched on per tenant — screening and risk rating first, monitoring and AI when you are ready.

Kenya regulatory fit

Built for POCAMLA and the Financial Reporting Centre.

Kenya's Proceeds of Crime and Anti-Money Laundering Act (POCAMLA), its regulations and the FRC's guidance set out what a reporting institution has to do. Each duty below maps to a module, so the evidence sits where an examiner will look for it.

Identify customers and their beneficial owners, and rate their risk

Six-factor customer risk rating across country, industry, product, channel, behaviour and PEP/sanctions exposure, with four-eyes overrides, plus a beneficial-owner graph for legal-entity customers.

Customer risk ratingEntity resolution

Apply enhanced due diligence to foreign PEPs and higher-risk customers

An EDD workflow inside case management, with periodic reviews scheduled automatically by risk band so a high-risk file does not go stale.

Case management & EDDCustomer risk rating

Screen against UN and Kenyan sanctions lists, which require freezing within 24 hours of a designation

Multi-script, locale-aware matching against lists synced from providers such as Dow Jones and World-Check, plus manual upload for lists you maintain yourself, such as Kenya's Domestic List. Every list is versioned, and freshness dashboards show screening ran on current data.

ScreeningWatchlist management

Monitor complex, unusual and large transactions on an ongoing basis

A rule engine running in batch and streaming, with typology-aligned starter rules, a back-test harness and versioned promotion, fed by REST, SFTP, Kafka, CDC or ISO 20022 connectors.

Transaction monitoringData ingestion

Report STRs within two days, and cash transactions of US$15,000 or more by that week's Friday

A draft, review, approve and submit lifecycle with acknowledgement handling. The goAML XML is generated and validated by the Creodata goAML Reporting Platform, with a manual download if the portal is down.

SAR / STR reportinggoAML Reporting Platform

Keep records for at least seven years and show supervisors the evidence

An append-only audit log behind every decision, evidence packs for inspections, a read-only regulator portal, and an obligation registry that turns new FRC circulars and amendments into tracked tasks.

Regulator portalRegulatory intelligence

Sources: POCAMLA sections 44, 46 and 47A; the POCAML Regulations, 2023 (regulations 26 and 40); and the Prevention of Terrorism sanctions regulations, 2026. This maps software capability to Kenyan obligations; it is not legal advice. For registration and filing through goAML, see the goAML Kenya guide; for help designing the programme itself, see our AML/CFT advisory services.

The workspace

Every surface, one entity context.

From a customer's first screen to a filed report, every action lives in the same workspace — no swivel-chairing between tools. Click through the real surfaces an analyst and MLRO use every day.

app.creodata.aml/dashboard
Monitoring/Dashboard
Search…
Enterprise
Dashboard
Overview of the last 24 hours across screening, cases, and transaction monitoring.
Open onboarding wizard
Open alerts
247
+12 since yesterday
Cases opened today
38
On track
SARs pending review
4
2 awaiting MLRO
SLA breaches
2
Escalated
Recent alertsLast 5 open screening matches
Open queue →
MatchQueryConfidenceTop reason
a91f3c…Fatima Al-Mansouri0.924PEP list exposure
c20b7e…João da Silva0.871Sanctions partial
e4d109…Apex Holdings Ltd0.642Adverse media
7b8a52…Chen Xiaoming0.588Name-only match
1f60aa…Wei Logistics0.512High-risk geography
AI assistAI · fp-v2.3
3 candidate false positives ready for one-click close, each with SHAP top-3 reasons and a confidence score.
Name-only partial match94%
Stale sanctions entry91%

Eleven modules, license-gated by tier.

Turn on only what a tenant is licensed for — the rest stays hidden.
Watchlist management

Provider sync (Dow Jones, World-Check), manual upload, versioning and freshness dashboards — so screening always runs against current lists, and you can prove it.

Screening

Multi-script, locale-aware matching across sanctions, PEP and adverse media, with a false-positive workflow — so analysts spend their time on genuine matches, not look-alikes.

Customer risk rating

Six-factor CRA across country, industry, product, channel, behaviour and PEP/sanctions exposure, with four-eyes overrides — so every rating has a reviewable history.

Transaction monitoring

Rule DSL with batch and streaming, a back-test harness, tuning lab and versioned promotion — so a rule change is tested and traceable before it fires in production.

Case management & EDD

Queues, RFI cycle, SLA pause/resume, linked-case graph and enhanced due diligence — so no alert ages out unowned, and connected cases are seen together.

SAR / STR reporting

Draft-to-submit lifecycle with FRC Kenya direct, goAML universal and manual-download fallback — so a report can still go out when a portal is down.

Entity resolution

Resolved entities, links, clusters and a beneficial-owner graph wired into the case workbench — so an analyst sees who is really behind a customer without leaving the case.

Data ingestion

REST, SFTP, Kafka, CDC and ISO 20022 connectors with idempotency, replay and a dead-letter queue — so a failed overnight feed never becomes a silent monitoring gap.

AI inference

ONNX runtime and a first-party model registry, four-eyes activation, a kill switch and SHAP top-3 reasons — so every AI score can be explained to an examiner, and switched off in one click.

Regulator portal

A read-only, OIDC-federated build for supervisors with evidence packs and acknowledgements — so an examination runs on shared evidence rather than email attachments.

Regulatory intelligence

Obligation registry, change-notice ingest and per-tenant acknowledgement tracking — so a new circular becomes a tracked task, not a surprise at the next inspection.

Explainable AI

Every AI score comes with its reasons — and a human decides.

Models run in-process on an ONNX runtime with a first-party registry. Activation needs four eyes, a kill switch is one click away, and every inference is logged with model version and an inputs hash.

SHAP top-3 reasons on every score, with confidence stated in plain words and a percentage.
Every AI surface labelled AI · model · version, with a human Accept / Modify / Reject.
Four-eyes activation, one-click kill switch, and every inference logged for audit.
Risk contributionAI · risk · v2.3
High confidence (87%) — review before action
PEP exposure+0.34
High-risk geography+0.21
Transaction velocity+0.18
Account tenure−0.09
AcceptModifyReject
One codebase

Built once. Deployed anywhere, for any sector.

The same binary serves a global bank with a regulator on-premise and a small intermediary in the cloud. The difference is configuration and licence — not code.

Sector packs
Banking
Insurance
Betting & gaming
VASP / crypto
Payments / EMI
Real estate
DNFBPs
NPO / charity
Cloud and on-premise, at parity

Dual-backend abstractions mean every feature works identically on Azure and on your own Kubernetes — same code, validated to parity.

Azure Managed App
Azure Function Apps
Postgres Flexible Server
Service Bus + Blob
Entra ID identity
On-prem Kubernetes
Kubernetes (Helm)
Postgres 16 + RabbitMQ
MinIO + OpenSearch
Keycloak identity
Licence tiers

Modules switch on by tier. Endpoints check the licence; anything unlicensed is hidden.

Starter
Screening, CRA and case basics for a small intermediary in the cloud.
Growth
Adds transaction monitoring, SAR/STR reporting and ingestion connectors.
Enterprise
Full suite: AI inference, entity resolution, regulator portal and on-prem parity.
Who it's for

For every Kenyan institution that has to run an AML programme and stand behind it.

Built for reporting institutions under POCAMLA, which answer to the Financial Reporting Centre as well as their sector regulator, and for their peers under the FIA in Uganda, the FIU in Tanzania and the FIC in Zambia and Rwanda.

Banks, microfinance banks and SACCOs

Deposit-takers supervised by the Central Bank of Kenya and SASRA, carrying the full screening, monitoring and reporting obligation.

Fintechs, PSPs, mobile-money operators and digital lenders

CBK-licensed payment and credit businesses with high-volume, real-time flows that need streaming monitoring and fast, multi-script screening.

Insurers, forex bureaus and capital-markets firms

Firms supervised by the IRA, the CBK and the CMA. Smaller teams start with screening, risk rating and case basics and switch on more later.

DNFBPs

Casinos, real-estate agents, dealers in precious metals and stones, lawyers and accountants brought into the AML/CFT net by POCAMLA and its amendments.

FAQ

Frequently asked questions.

Is this AML software built for Kenya?

Yes. It is built for reporting institutions under Kenya's Proceeds of Crime and Anti-Money Laundering Act (POCAMLA): sanctions and PEP screening, customer risk rating, transaction monitoring, case management with enhanced due diligence, and STR/CTR reporting to the Financial Reporting Centre (FRC) through goAML. The same software serves institutions in Uganda, Tanzania, Zambia and Rwanda; the difference between countries is configuration, not code.

Does it file STRs and CTRs with the FRC?

Yes, through goAML. Suspicious and cash transaction reports move through a draft, review, approve and submit lifecycle in the AML software, with retry, reconciliation and acknowledgement handling. The goAML XML itself is generated and validated by the Creodata goAML Reporting Platform before it reaches the FRC's portal, and a manual download is available if the portal is down.

How much does AML software cost in Kenya?

There is no public price list. Each capability is licensed separately and grouped into Starter, Growth and Enterprise tiers, so a quote depends on the modules you switch on and whether you deploy on Azure or on-premises. A demo is the quickest route to a quote scoped to your institution.

Can a SACCO or microfinance institution start small?

Yes. The Starter tier covers screening, customer risk rating and case basics in the cloud. Growth adds transaction monitoring, STR/CTR reporting and ingestion connectors, which a deposit-taking SACCO or MFI will need to meet POCAMLA's monitoring and reporting duties. Modules switch on per tenant, so moving up a tier adds capability without starting again.

Where is our data hosted, and can we run it on-premises?

The cloud edition runs on Microsoft Azure as an Azure Managed Application. If data has to stay in your own data centre, the on-premises edition runs on Kubernetes with Postgres 16, RabbitMQ, MinIO, OpenSearch and Keycloak and has the same features: dual-backend abstractions keep the two editions identical, so an institution that must keep data in-country is not running a lesser product.

How long does implementation take?

It depends on how many modules you start with and how your data arrives. Screening and risk rating need customer data; transaction monitoring also needs transaction feeds, which connect over REST, SFTP, Kafka, change data capture or ISO 20022 with replay and a dead-letter queue, so a failed load is visible rather than silent. After scoping, we propose a phased path to your first production go-live.

Is this a full AML programme or only a reporting tool?

It is the full programme — customer risk assessment, screening, transaction monitoring, case management, entity resolution and more. STR/CTR reporting is one capability within it, and the actual goAML filing is handed off to the dedicated Creodata goAML Reporting Platform.

Do we have to adopt every capability at once?

No. Each capability is an independent, separately licensed service. Per-tenant module gating lets you start with what you need and switch on additional services over time.

How does the platform handle AI decisions for audit?

Every AI surface shows its model and version label, SHAP top-three explanations and a confidence percentage, and requires a human Accept, Modify or Reject. Decisions are logged with the model version, an inputs hash and the SHAP output, and models can only be activated under four-eyes approval, with a kill switch and rollback available.

From alert to filed SAR/STR, without leaving the workspace.

See the AML platform run on a realistic alert queue, tuned to your sector pack, in a live demo.