AML compliance software for Kenya's banks, SACCOs and fintechs.
Find the risk. Prove the decision.
Sanctions and PEP screening, transaction monitoring, customer risk rating, case management and STR/CTR reporting to the Financial Reporting Centre, in one analyst workspace. A single codebase serves a tier-1 bank and a small intermediary alike — cloud or on-premise, at parity.
Not an AML problem so much as a fragmentation problem.
Risk scoring lives in one spreadsheet, sanctions screening in a separate tool, transaction alerts in a third system — and the evidence an examiner asks for is scattered across inboxes and shared drives. Point tools and manual process create more risk than they remove.
The cost is not only operational. An AML programme that cannot show its evidence on demand is hard to defend, regardless of how diligent the team actually is.
- Decisions cannot be reconstructed
When a regulator or auditor asks why a customer was rated low-risk, or why an alert was closed, the answer sits in someone's memory or a deleted email rather than an immutable log.
- Work is duplicated and inconsistent
The same customer is screened in one system, scored in another and investigated in a third, with no shared view of how those decisions connect.
- Spreadsheets do not scale or survive scrutiny
Manual scoring models and ad-hoc watchlists drift out of date, lack version history, and offer no four-eyes control over the overrides that matter most.
What changes when the programme runs on one record.
Screening, risk rating, monitoring, cases and reporting share one entity context — so the evidence is there when the question comes.
The data, the rule, the score and the reasoning sit one click away, in an append-only audit log.
Multi-script, locale-aware matching, a structured false-positive workflow and entity resolution take the look-alikes out of the queue.
Case, EDD and the SAR/STR lifecycle live in the same workspace, handing off to goAML for the filing itself.
Modules are licensed by tier and switched on per tenant — screening and risk rating first, monitoring and AI when you are ready.
Built for POCAMLA and the Financial Reporting Centre.
Kenya's Proceeds of Crime and Anti-Money Laundering Act (POCAMLA), its regulations and the FRC's guidance set out what a reporting institution has to do. Each duty below maps to a module, so the evidence sits where an examiner will look for it.
Identify customers and their beneficial owners, and rate their risk
Six-factor customer risk rating across country, industry, product, channel, behaviour and PEP/sanctions exposure, with four-eyes overrides, plus a beneficial-owner graph for legal-entity customers.
Apply enhanced due diligence to foreign PEPs and higher-risk customers
An EDD workflow inside case management, with periodic reviews scheduled automatically by risk band so a high-risk file does not go stale.
Screen against UN and Kenyan sanctions lists, which require freezing within 24 hours of a designation
Multi-script, locale-aware matching against lists synced from providers such as Dow Jones and World-Check, plus manual upload for lists you maintain yourself, such as Kenya's Domestic List. Every list is versioned, and freshness dashboards show screening ran on current data.
Monitor complex, unusual and large transactions on an ongoing basis
A rule engine running in batch and streaming, with typology-aligned starter rules, a back-test harness and versioned promotion, fed by REST, SFTP, Kafka, CDC or ISO 20022 connectors.
Report STRs within two days, and cash transactions of US$15,000 or more by that week's Friday
A draft, review, approve and submit lifecycle with acknowledgement handling. The goAML XML is generated and validated by the Creodata goAML Reporting Platform, with a manual download if the portal is down.
Keep records for at least seven years and show supervisors the evidence
An append-only audit log behind every decision, evidence packs for inspections, a read-only regulator portal, and an obligation registry that turns new FRC circulars and amendments into tracked tasks.
Sources: POCAMLA sections 44, 46 and 47A; the POCAML Regulations, 2023 (regulations 26 and 40); and the Prevention of Terrorism sanctions regulations, 2026. This maps software capability to Kenyan obligations; it is not legal advice. For registration and filing through goAML, see the goAML Kenya guide; for help designing the programme itself, see our AML/CFT advisory services.
Every surface, one entity context.
From a customer's first screen to a filed report, every action lives in the same workspace — no swivel-chairing between tools. Click through the real surfaces an analyst and MLRO use every day.
| Match | Query | Confidence | Top reason |
|---|---|---|---|
| a91f3c… | Fatima Al-Mansouri | 0.924 | PEP list exposure |
| c20b7e… | João da Silva | 0.871 | Sanctions partial |
| e4d109… | Apex Holdings Ltd | 0.642 | Adverse media |
| 7b8a52… | Chen Xiaoming | 0.588 | Name-only match |
| 1f60aa… | Wei Logistics | 0.512 | High-risk geography |
Eleven modules, license-gated by tier.
Turn on only what a tenant is licensed for — the rest stays hidden.Provider sync (Dow Jones, World-Check), manual upload, versioning and freshness dashboards — so screening always runs against current lists, and you can prove it.
Multi-script, locale-aware matching across sanctions, PEP and adverse media, with a false-positive workflow — so analysts spend their time on genuine matches, not look-alikes.
Six-factor CRA across country, industry, product, channel, behaviour and PEP/sanctions exposure, with four-eyes overrides — so every rating has a reviewable history.
Rule DSL with batch and streaming, a back-test harness, tuning lab and versioned promotion — so a rule change is tested and traceable before it fires in production.
Queues, RFI cycle, SLA pause/resume, linked-case graph and enhanced due diligence — so no alert ages out unowned, and connected cases are seen together.
Draft-to-submit lifecycle with FRC Kenya direct, goAML universal and manual-download fallback — so a report can still go out when a portal is down.
Resolved entities, links, clusters and a beneficial-owner graph wired into the case workbench — so an analyst sees who is really behind a customer without leaving the case.
REST, SFTP, Kafka, CDC and ISO 20022 connectors with idempotency, replay and a dead-letter queue — so a failed overnight feed never becomes a silent monitoring gap.
ONNX runtime and a first-party model registry, four-eyes activation, a kill switch and SHAP top-3 reasons — so every AI score can be explained to an examiner, and switched off in one click.
A read-only, OIDC-federated build for supervisors with evidence packs and acknowledgements — so an examination runs on shared evidence rather than email attachments.
Obligation registry, change-notice ingest and per-tenant acknowledgement tracking — so a new circular becomes a tracked task, not a surprise at the next inspection.
Every AI score comes with its reasons — and a human decides.
Models run in-process on an ONNX runtime with a first-party registry. Activation needs four eyes, a kill switch is one click away, and every inference is logged with model version and an inputs hash.
Built once. Deployed anywhere, for any sector.
The same binary serves a global bank with a regulator on-premise and a small intermediary in the cloud. The difference is configuration and licence — not code.
Dual-backend abstractions mean every feature works identically on Azure and on your own Kubernetes — same code, validated to parity.
Modules switch on by tier. Endpoints check the licence; anything unlicensed is hidden.
For every Kenyan institution that has to run an AML programme and stand behind it.
Built for reporting institutions under POCAMLA, which answer to the Financial Reporting Centre as well as their sector regulator, and for their peers under the FIA in Uganda, the FIU in Tanzania and the FIC in Zambia and Rwanda.
Deposit-takers supervised by the Central Bank of Kenya and SASRA, carrying the full screening, monitoring and reporting obligation.
CBK-licensed payment and credit businesses with high-volume, real-time flows that need streaming monitoring and fast, multi-script screening.
Firms supervised by the IRA, the CBK and the CMA. Smaller teams start with screening, risk rating and case basics and switch on more later.
Casinos, real-estate agents, dealers in precious metals and stones, lawyers and accountants brought into the AML/CFT net by POCAMLA and its amendments.
AML compliance software beyond Kenya.
The same software serves reporting institutions in the markets below. The regulator and the reporting profile change; the code does not.
Frequently asked questions.
Is this AML software built for Kenya?
Yes. It is built for reporting institutions under Kenya's Proceeds of Crime and Anti-Money Laundering Act (POCAMLA): sanctions and PEP screening, customer risk rating, transaction monitoring, case management with enhanced due diligence, and STR/CTR reporting to the Financial Reporting Centre (FRC) through goAML. The same software serves institutions in Uganda, Tanzania, Zambia and Rwanda; the difference between countries is configuration, not code.
Does it file STRs and CTRs with the FRC?
Yes, through goAML. Suspicious and cash transaction reports move through a draft, review, approve and submit lifecycle in the AML software, with retry, reconciliation and acknowledgement handling. The goAML XML itself is generated and validated by the Creodata goAML Reporting Platform before it reaches the FRC's portal, and a manual download is available if the portal is down.
How much does AML software cost in Kenya?
There is no public price list. Each capability is licensed separately and grouped into Starter, Growth and Enterprise tiers, so a quote depends on the modules you switch on and whether you deploy on Azure or on-premises. A demo is the quickest route to a quote scoped to your institution.
Can a SACCO or microfinance institution start small?
Yes. The Starter tier covers screening, customer risk rating and case basics in the cloud. Growth adds transaction monitoring, STR/CTR reporting and ingestion connectors, which a deposit-taking SACCO or MFI will need to meet POCAMLA's monitoring and reporting duties. Modules switch on per tenant, so moving up a tier adds capability without starting again.
Where is our data hosted, and can we run it on-premises?
The cloud edition runs on Microsoft Azure as an Azure Managed Application. If data has to stay in your own data centre, the on-premises edition runs on Kubernetes with Postgres 16, RabbitMQ, MinIO, OpenSearch and Keycloak and has the same features: dual-backend abstractions keep the two editions identical, so an institution that must keep data in-country is not running a lesser product.
How long does implementation take?
It depends on how many modules you start with and how your data arrives. Screening and risk rating need customer data; transaction monitoring also needs transaction feeds, which connect over REST, SFTP, Kafka, change data capture or ISO 20022 with replay and a dead-letter queue, so a failed load is visible rather than silent. After scoping, we propose a phased path to your first production go-live.
Is this a full AML programme or only a reporting tool?
It is the full programme — customer risk assessment, screening, transaction monitoring, case management, entity resolution and more. STR/CTR reporting is one capability within it, and the actual goAML filing is handed off to the dedicated Creodata goAML Reporting Platform.
Do we have to adopt every capability at once?
No. Each capability is an independent, separately licensed service. Per-tenant module gating lets you start with what you need and switch on additional services over time.
How does the platform handle AI decisions for audit?
Every AI surface shows its model and version label, SHAP top-three explanations and a confidence percentage, and requires a human Accept, Modify or Reject. Decisions are logged with the model version, an inputs hash and the SHAP output, and models can only be activated under four-eyes approval, with a kill switch and rollback available.
From alert to filed SAR/STR, without leaving the workspace.
See the AML platform run on a realistic alert queue, tuned to your sector pack, in a live demo.
More on AML compliance software
AML Compliance for Insurers in Nigeria: NAICOM, the MLPPA 2022 and the 2025 Insurance Reform Act (2026)
What Nigerian insurance institutions must do on AML: MLPPA 2022 duties, section 202 of the Nigerian Insurance Industry Reform Act 2025, NAICOM supervision, customer and beneficiary checks, STRs within 24 hours, currency transaction reports, NFIU filing and records.
AML Compliance for Microfinance Banks and Payment Service Providers in Nigeria (2026)
What Nigerian microfinance banks, payment service providers and mobile money operators must do on AML under the MLPPA 2022: customer due diligence and PEPs, 24-hour STRs, ₦5m/₦10m currency transaction reports, US$10,000 foreign transfers, NFIU and RapidAML filing, records and agent-channel risk.
FICA Compliance for Crypto Asset Service Providers in South Africa: Registration, Directive 9 and the Travel Rule (2026)
What South African crypto asset service providers must do under FICA: register with the FIC under Schedule 1 item 22 (and item 12 if FSCA-licensed), apply the Directive 9 travel rule from 30 April 2025, screen counterparties, handle unhosted wallets, and report to the FIC.