Digital account opening and KYC
for Kenyan banks, SACCOs and MFIs.
Business, personal, chama and joint accounts opened online on the Kenya templates: the due diligence CBK and SASRA ask for, captured on your own forms and worked through a staff review — beside the IPRS and KRA checks your verification provider runs, in your own Azure subscription.
Paper account opening loses applicants and hides risk.
A form that emails a PDF to a branch is not a digital account-opening process. The applicant cannot see progress, the bank cannot see the applicant, and compliance happens on a photocopy after the fact.
Three years later, when the auditor asks what the applicant actually saw and declared, the answer has to be reconstructed.
- Half-finished applications nobody follows up
Applicants stop at a hard question or a missing document with no draft to come back to — and no one knows they left.
- Compliance captured after the fact
PEP and FATCA declarations and beneficial owners are collected on paper and typed in later, so screening starts after the account exists.
- Every circular is a release cycle
A new regulation, product or segment changes the form, and changing the form means an engineering ticket.
- The record does not match what the applicant saw
Forms change, but old applications are stored against whatever the current form happens to be.
What changes when the whole journey is one record.
Autosave, resume-anywhere drafts and a private progress link — for business, personal, group and joint applications alike.
PEP and FATCA declarations and the beneficial-owner register are part of the application, and every person involved is listed for screening on the same record.
A visual form builder with maker-checker publishing and version pinning — no code, no redeploy.
Each workflow action is recorded with who did it and when, reviewer decisions keep their comments, and applications re-open on the exact form version they were filled on.
Built around CBK, SASRA and Kenyan law on customer due diligence.
POCAMLA and its 2023 Regulations, CBK's 2025 Guidance on Customer Due Diligence (for banks, microfinance banks, payment service providers and other CBK-licensed institutions) and SASRA's 2024 AML guideline (for SACCOs) set what an institution must collect when it opens an account. Each duty below maps to what BAOS captures; identity lookups and screening stay with the tools you already use.
Identify and verify each customer with an official record: a national ID card, passport, birth certificate or driver's licence (POCAMLA s.45(1A)(a))
The Kenya personal and corporate templates capture the ID type and number, date of birth, address and occupation for every person, with the Kenyan ID and KRA PIN formats checked as they are typed. Checks against IPRS come from your identity-verification provider; staff record the review in BAOS.
Obtain a KRA PIN: the Tax Procedures Act lists opening an account with a financial institution as a transaction that needs one (non-residents are exempt since 2026)
The PIN is a field on the form for individuals and entities, checked for format. Matching the name against KRA records, which CBK's guidance gives as an example, stays with your provider.
For companies: the certificate of incorporation, memorandum and articles, a board resolution naming the signatories, and the people who manage, control or own it (POCAML Regulations reg 16)
The Kenya corporate standard template collects the entity profile, directors and beneficial owners, authorised signatories, the signing mandate and the board resolution, with a document slot for each item on your checklist.
Identify beneficial owners — anyone holding at least 10% of the shares or voting rights, or exercising control — and check them against the BRS register (Companies Beneficial Ownership Regulations reg 3(2))
Beneficial owners are recorded on the application with their ID and shareholding. Applying the 10% test and checking the BRS register are your team's steps; the declared owners stay on the same record as the review.
SACCO members: an original ID for individuals, the certificate of incorporation for bodies corporate, and for groups the certificate of registration plus the identities of officials and signatories (SASRA/GG/1/2024 §6.1.1)
A SACCO can run BAOS for member onboarding with individual, group and corporate journeys. The group journey records the member register, the elected officials and the group meeting resolution, so the officials and signatories SASRA names are on the application.
Screen every customer against the UN and Kenyan domestic sanctions lists before onboarding, and apply enhanced due diligence with senior-management approval to foreign PEPs and other higher-risk customers (CBK CDD 3.6.3; reg 26)
PEP declarations are made in the application, and BAOS lists every person who needs screening — directors, beneficial owners, members, holders and signatories — once each. The screening runs in your screening tool, such as Creodata's AML software. BAOS does not rate risk.
Keep customer due diligence records for at least seven years after the transaction or the relationship ends (POCAMLA s.46(4))
Each application stays on the form version it was filled on, with its documents and an audit record of every workflow action, in your own Azure subscription. Retention and deletion follow your own policy; BAOS has no automated retention schedule.
Tell applicants what you collect, why and on what lawful basis before you collect it (Data Protection Act ss.29–30)
Your privacy notice and consent wording go on the form as required declarations. BAOS runs in your Azure subscription in the region you choose; Azure has no region in Kenya, and the Act allows transfers abroad with appropriate safeguards (ss.48–49).
Statutory references were checked against primary texts (Kenya Law, CBK, SASRA and BRS documents) on 8 October 2026. This is a summary, not legal advice.
Digital onboarding and KYC, captured once and reviewed on a clock.
Digital onboarding is more than an online form. BAOS covers the journey banks are asked to digitise — the application, the KYC and due-diligence capture, the document checklist, the list of people to screen and the staff review — for business, personal, group and joint applicants alike.
Identification details, employment or business particulars, addresses, next of kin and contact data are captured on your published form, with the fields your KYC policy requires marked mandatory.
Declarations are part of the application itself, made by the applicant before an account exists rather than typed in later from paper.
Business applications record significant stakeholders; group and joint applications repeat a full section for every member or holder. Each person becomes a screening subject.
IDs, photos, registration certificates and resolutions are collected against the checklist for that kind of account, with per-holder slots so “complete” means complete for everyone.
Every person involved — directors, beneficial owners, group members, joint holders, signatories — becomes a screening subject, once per person even when they hold two roles, listed on the application for your compliance team. The screening itself runs in your screening tool.
Staff claim the application, verify its documents and approve or reject it, with SLA timers on the workflow steps. Once your core banking system opens the account, they record the account number in BAOS — and every workflow action is logged.
Evaluating digital onboarding solutions? Read build, buy or configure, the KYC onboarding process step by step, and the full account-opening guide library.
Business, personal, group, or joint — one platform.
The applicant's first step is choosing the kind of account. Your bank enables only the kinds it offers — each ships as a starter form you publish from the form builder — and every one of them runs through the same review workflow.
The full corporate journey, from entity profile to facilities.
Individual accounts, captured completely the first time.
Chamas and savings groups, with every member on the record.
Every holder captured as a person in their own right.
One review workflow for all of them. The applicant chooses the account kind, BAOS serves the right form, and every person involved — members, holders, signatories and stakeholders — is listed for screening.
Everything opening a bank account needs — in one flow.
Not a form that emails a PDF to a branch. A complete pipeline: the applicant applies, compliance data is captured in line, and your team reviews and decides against SLA timers.
The applicant picks the kind of account — business, personal, group, or joint — and gets the step-by-step form your bank published for it, with autosave and resume-anywhere drafts.
Applicants register and sign in — using your own customer identity service if you have one — keep a list of drafts they can resume or discard, and track progress by a private reference link that cannot be guessed.
Uploads are driven by your checklist, with their own slot for each signatory, beneficial owner, or group member. Staff verify them one at a time or a whole application at once.
PEP and FATCA declarations and the beneficial-owner register are captured inside the application. The applicant and every person involved — directors, beneficial owners, group members, joint holders, signatories — are listed for screening on the same record.
Board resolutions for companies, group meeting resolutions for chamas, operating mandates and survivorship for joint accounts — with authorized signatories and signing mandates captured and validated in the same flow.
Reviewers claim applications from an unassigned queue into their own, verify documents, and approve, reject or email the applicant for more information — with branch-scoped roles seeing only their own branch.
Every workflow step starts an SLA timer and a dashboard shows the average time each step takes; every workflow action is recorded with who did it and when.
Every question, section, and helper text can carry English and Swahili, edited in the form builder's translation editor — and applicants get a switcher wherever a translation exists.
Buy it on Azure Marketplace and run it in your own Azure subscription. If your data must stay on your own servers, we scope an on-premises deployment with your team.
Two sides, one application.
The customer picks the kind of account — business, personal, group, or joint — and fills in the guided form your bank published for it. The nine steps below are the Kenya corporate standard template, and every one of them is yours to change. Behind the glass, every kind of application runs through the same review pipeline: claimed by a reviewer, documents verified, approved or rejected, and the account number recorded once your core banking system opens the account.
Change the form without changing the software.
Account-opening forms move — a new regulation, a new product, a new segment. In BAOS that is an afternoon in an admin console, not a release cycle. Build the form visually, publish it under four eyes, and the next application picks it up.
Drag fields from the palette onto the canvas and set their properties on the right. Twenty-two field types, from declarations to repeating people lists — no code, no redeploy, no engineering ticket.
Every published version is immutable, and each application pins the version it was filled on — so an old submission always renders exactly as it was.
A form cannot be published by whoever last edited it. Separation of duties is enforced by the platform, not by policy.
Show or require a field based on earlier answers. The same rules are evaluated identically in the browser and on the server.
Per-field English and Swahili translations, edited in a dedicated translation editor, with a language switcher that appears only where translations have been provided.
Define a pick list once — industries, business types, currencies — and reuse it across every form and step.
Serve a different form by account kind and by channel — self-service or staff-assisted — with a tenant default sitting behind it.
Publishing is blocked on duplicate questions, empty steps, dropdowns with no options, and rules pointing at a field you removed — so a broken form never reaches an applicant.
Walk your draft form through the same screen the applicant will see, before anyone else does.
Configured questions map onto the proper fields of the underlying record — entity name, signatory, shareholding — so reporting and downstream systems keep working, however you rearrange the form.
Export a finished form and import it into another tenant or environment. A form proven at one institution becomes the starting point for the next.
Open drafts by step, measured against submissions — so you can find the question that is costing you applications.
Ten starter forms across all four account kinds ship with the platform, drawn from real account-opening forms in use across the region — including the Kenya corporate standard, the nine-step journey shown above.
Nearly forty prebuilt sections — beneficial owners, member registers, next of kin, signatories, FATCA, board resolutions, and the rest — to drop into any form, grouped across nine areas.
One application, every service it touches.
No re-keying between systems. The customer portal feeds a single application record that flows through compliance capture, documents, SLA timing and audit — and reaches approval complete and validated, ready for your team to open the account in your core banking system.
Self-service sign-up, draft autosave, and reference-token tracking — the only surface the applicant sees — so an applicant can stop, come back and finish without calling the branch.
The single source of truth: the entity or the person, members, holders, signatories, facilities, and mandate — all on one record, so nothing is re-keyed and nothing is lost between teams.
PEP and FATCA declarations and the beneficial-owner register, with the applicant and every person involved derived as a screening subject and a compliance summary on the application — so reviewers can see who still needs screening.
Checklist-driven upload, download, and verification — one document at a time or a whole application at once, including signatory photographs — so the reviewer works a complete file, not a trickle of attachments.
Per-step timers start automatically, and a dashboard shows the average time each step takes — so you can see where applications slow down before applicants give up.
Each workflow action is recorded with who did it, when and from which address, and applicants get an email at each key step — so everyone knows where the application stands, and the record shows it later.
Your brand, your products, your rules.
One codebase serves every institution as an isolated tenant. Configure it from an admin console — no engineering — and the customer portal and application screens wear your colours.
For applicants who would rather just talk.
An assistant that walks an applicant through the same application in conversation, and gives your reviewers an early read on the documents. It ships with the Enterprise plan, and it is deliberately built so that it can never make the decision.
Applicants who would rather talk than fill in a form are walked through it in chat, with interactive cards for choosing a product, completing a section, making the PEP and FATCA declarations, uploading documents, and confirming a final summary.
Those cards are generated from your own published form for the kind of account being opened — with prompts tuned per kind, so a personal applicant is never asked about board resolutions — and stay in step whenever you change the form.
Recognises seven common Kenyan document types, reads the key details, and deterministically cross-checks them against what the applicant typed. The reviewer sees an advisory flag — never an automatic decision.
There is deliberately no tool for submitting, verifying, or approving — those actions do not exist for the assistant. It is rate-limited, capped in how far it can go on its own, and treats document text as untrusted. A person still decides.
Built to survive an audit.
Onboarding is where a regulator starts asking questions. The platform is built so the answers are already recorded rather than reconstructed.
from staff data entry, reviewer and document verifier to compliance officer, branch manager and audit viewer — with fine-grained permissions checked on every request
who did what, in which role, when, and from which address and device — with reviewer decisions and their comments alongside
encrypted sessions, protection against cross-site request forgery, and every service checking who is calling — not just the front door
each institution's data lives in its own database schema, and branch-scoped staff only see their own branch's applications
automated tests that drive the full applicant and staff journeys in a real browser, plus checks that keep the screens and the services in step
the whole environment is defined as code and packaged for Azure Marketplace, so a rebuild is a rerun rather than a rediscovery
Two ways to deploy. One platform.
Buy it on Azure Marketplace and have it running in your own subscription. If your regulator or your own policy requires your own datacenter, we scope an on-premises deployment with your team.
Plans start at $1,500 per month — see the plans below. The plan price covers BAOS management and support; the Azure infrastructure it runs on is billed separately, on your own subscription.
Talk to us early: on-premises deployments are planned around your infrastructure, your network and the data-residency requirements set by your regulator.
The plan fee covers BAOS management and support; Azure infrastructure is billed separately on your subscription.
Prices as listed on Azure Marketplace. Azure infrastructure is billed separately — typically $40–80 per month for entry deployments, and $500–900 per month for a high-availability Enterprise configuration, plus model usage for the AI assistant.
| Capability | Microsoft Azure | On-premises design |
|---|---|---|
| Relational data | PostgreSQL Flexible Server | PostgreSQL |
| Messaging / events | Azure Service Bus | RabbitMQ |
| Document storage | Azure Blob Storage | MinIO |
| Identity | Microsoft Entra ID (staff) · Azure AD B2C (customers) | Keycloak |
The customer portal runs on App Service, as a static site, or in containers. The Standard and Professional plans install the App Service option; the Enterprise plan runs on Container Apps with autoscaling — the mode that hosts the AI assistant.
Guides for Kenya
- CBK's Customer Due Diligence Guidance (2025): What It Changes for Account Opening in Kenya
- IPRS and KRA PIN Checks in Account Opening: Where They Fit in Your Onboarding Workflow (Kenya)
- SACCO Member Onboarding in Kenya: What SASRA's 2024 AML Guideline Requires
- Account Opening Software in Kenya: A Buyer's Guide for Banks, SACCOs and MFIs (2026)
Account opening in Kenya: questions banks and SACCOs ask.
No. CBK's 2025 guidance gives IPRS checks of the ID number, serial number and name, a KRA PIN name check, selfies and video calls as examples of verification (Table 3). BAOS does not run those lookups itself: it checks the Kenyan ID and KRA PIN formats as they are typed, holds the documents and records the staff review. The IPRS and KRA checks come from your identity-verification provider or your own process.
The Kenya corporate standard (a nine-step corporate journey), Kenya personal and Kenya group / chama templates, plus joint, trustee, Islamic-banking, FATCA / CRS and additional-signatory templates. Your team changes any of them in the no-code form builder — for example, to ask for the trust registration certificate that the Trust Administration Act 2026 introduces.
Yes. SASRA's 2024 AML guideline (SASRA/GG/1/2024, §6.1.1) asks for an original ID for individual members, the certificate of incorporation for bodies corporate, and, for unincorporated groups, the certificate of registration and the identities of officials and signatories. BAOS runs individual, group and corporate journeys, and the group journey records the member register, the officials and the meeting resolution. Verification against IPRS and the KRA database, which the guideline names, stays with your provider.
We found no Kenyan law that bars an unregistered group from banking, and banks' requirements differ. Groups registered under the Community Groups Registration Act receive a certificate from the Director of Social Development, but on 10 September 2026 the High Court declared that Act unconstitutional, suspending the declaration until 10 February 2027. In BAOS each bank sets the chama document list it accepts in the form builder.
Not on Azure: Azure has no region in Kenya, and BAOS runs in your own Azure subscription in the region you choose (the nearest are South Africa North and South Africa West). The Data Protection Act allows transfers abroad with appropriate safeguards (ss.48–49). If your policy requires in-country hosting, Creodata scopes an on-premises deployment with your team.
The same public plans as everywhere: Standard at $1,500, Professional at $3,500 and Enterprise at $6,000 per month on Azure Marketplace, plus the Azure infrastructure on your own subscription. Kenya is one of BAOS's Azure Marketplace markets.
Yes, where you provide the text: every question, section and help line can carry English and Swahili, and applicants get a language switcher wherever a translation exists. The staff interface is in English.
See any account opened end to end.
We'll walk you through the applicant journey, the form builder, and the review pipeline — across business, personal, group, and joint accounts, in your institution's colours. Or deploy it yourself from Azure Marketplace.
More on account opening
Account Opening Software in Kenya: A Buyer's Guide for Banks, SACCOs and MFIs (2026)
How to choose account opening software in Kenya: workflow vs KYC providers vs core banking, what CBK and SASRA rules mean, a checklist and red flags.
CBK's Customer Due Diligence Guidance (2025): What It Changes for Account Opening in Kenya
What CBK's 2025 Customer Due Diligence Guidance means for KYC at account opening in Kenya: who it covers, ID checks, timing, risk, screening and records.
IPRS and KRA PIN Checks in Account Opening: Where They Fit in Your Onboarding Workflow (Kenya)
Where IPRS ID verification and KRA PIN checks fit in Kenyan account opening: IPRS access, CBK's examples, the PIN rule, the new ID card and your record.