Account opening software · Kenya

Digital account opening and KYC
for Kenyan banks, SACCOs and MFIs.

Business, personal, chama and joint accounts opened online on the Kenya templates: the due diligence CBK and SASRA ask for, captured on your own forms and worked through a staff review — beside the IPRS and KRA checks your verification provider runs, in your own Azure subscription.

Business · personal · chama · jointCustomer portalCBK & SASRA KYC captureSLA timersAudit trailKenya templatesRuns in your Azure
apply · BlueHarbor Bank
Account typeBusinessPersonalGroup / chamaJoint
9 steps
Business info
Account selection
Facilities
Compliance
5Signatories
6Signing mandate
7Collections
8Board resolution
9Documents
Compliance
PEP declaration, FATCA, stakeholders
Saved
Is any director or owner a politically exposed person (PEP)?
NoYes — declare
FATCA classification
Active NFFE
Significant stakeholders2 added
ANAmani NjorogeDirector · 40% holding◐ PEP
BackContinue
The problem

Paper account opening loses applicants and hides risk.

A form that emails a PDF to a branch is not a digital account-opening process. The applicant cannot see progress, the bank cannot see the applicant, and compliance happens on a photocopy after the fact.

Three years later, when the auditor asks what the applicant actually saw and declared, the answer has to be reconstructed.

  • Half-finished applications nobody follows up

    Applicants stop at a hard question or a missing document with no draft to come back to — and no one knows they left.

  • Compliance captured after the fact

    PEP and FATCA declarations and beneficial owners are collected on paper and typed in later, so screening starts after the account exists.

  • Every circular is a release cycle

    A new regulation, product or segment changes the form, and changing the form means an engineering ticket.

  • The record does not match what the applicant saw

    Forms change, but old applications are stored against whatever the current form happens to be.

What changes

What changes when the whole journey is one record.

Applicants finish what they start

Autosave, resume-anywhere drafts and a private progress link — for business, personal, group and joint applications alike.

Compliance captured at the source

PEP and FATCA declarations and the beneficial-owner register are part of the application, and every person involved is listed for screening on the same record.

Change the form in an afternoon

A visual form builder with maker-checker publishing and version pinning — no code, no redeploy.

Every decision reconstructable

Each workflow action is recorded with who did it and when, reviewer decisions keep their comments, and applications re-open on the exact form version they were filled on.

Kenya onboarding rules

Built around CBK, SASRA and Kenyan law on customer due diligence.

POCAMLA and its 2023 Regulations, CBK's 2025 Guidance on Customer Due Diligence (for banks, microfinance banks, payment service providers and other CBK-licensed institutions) and SASRA's 2024 AML guideline (for SACCOs) set what an institution must collect when it opens an account. Each duty below maps to what BAOS captures; identity lookups and screening stay with the tools you already use.

Identify and verify each customer with an official record: a national ID card, passport, birth certificate or driver's licence (POCAMLA s.45(1A)(a))

The Kenya personal and corporate templates capture the ID type and number, date of birth, address and occupation for every person, with the Kenyan ID and KRA PIN formats checked as they are typed. Checks against IPRS come from your identity-verification provider; staff record the review in BAOS.

Kenya templatesDocument checklist

Obtain a KRA PIN: the Tax Procedures Act lists opening an account with a financial institution as a transaction that needs one (non-residents are exempt since 2026)

The PIN is a field on the form for individuals and entities, checked for format. Matching the name against KRA records, which CBK's guidance gives as an example, stays with your provider.

ValidatorsForm builder

For companies: the certificate of incorporation, memorandum and articles, a board resolution naming the signatories, and the people who manage, control or own it (POCAML Regulations reg 16)

The Kenya corporate standard template collects the entity profile, directors and beneficial owners, authorised signatories, the signing mandate and the board resolution, with a document slot for each item on your checklist.

Kenya corporate templateSignatories & mandates

Identify beneficial owners — anyone holding at least 10% of the shares or voting rights, or exercising control — and check them against the BRS register (Companies Beneficial Ownership Regulations reg 3(2))

Beneficial owners are recorded on the application with their ID and shareholding. Applying the 10% test and checking the BRS register are your team's steps; the declared owners stay on the same record as the review.

Beneficial owners

SACCO members: an original ID for individuals, the certificate of incorporation for bodies corporate, and for groups the certificate of registration plus the identities of officials and signatories (SASRA/GG/1/2024 §6.1.1)

A SACCO can run BAOS for member onboarding with individual, group and corporate journeys. The group journey records the member register, the elected officials and the group meeting resolution, so the officials and signatories SASRA names are on the application.

Group & chama accountsKenya chama template

Screen every customer against the UN and Kenyan domestic sanctions lists before onboarding, and apply enhanced due diligence with senior-management approval to foreign PEPs and other higher-risk customers (CBK CDD 3.6.3; reg 26)

PEP declarations are made in the application, and BAOS lists every person who needs screening — directors, beneficial owners, members, holders and signatories — once each. The screening runs in your screening tool, such as Creodata's AML software. BAOS does not rate risk.

Screening listPEP & FATCA declarations

Keep customer due diligence records for at least seven years after the transaction or the relationship ends (POCAMLA s.46(4))

Each application stays on the form version it was filled on, with its documents and an audit record of every workflow action, in your own Azure subscription. Retention and deletion follow your own policy; BAOS has no automated retention schedule.

Version pinningAudit record

Tell applicants what you collect, why and on what lawful basis before you collect it (Data Protection Act ss.29–30)

Your privacy notice and consent wording go on the form as required declarations. BAOS runs in your Azure subscription in the region you choose; Azure has no region in Kenya, and the Act allows transfers abroad with appropriate safeguards (ss.48–49).

DeclarationsYour Azure subscription

Statutory references were checked against primary texts (Kenya Law, CBK, SASRA and BRS documents) on 8 October 2026. This is a summary, not legal advice.

Digital onboarding for banks

Digital onboarding and KYC, captured once and reviewed on a clock.

Digital onboarding is more than an online form. BAOS covers the journey banks are asked to digitise — the application, the KYC and due-diligence capture, the document checklist, the list of people to screen and the staff review — for business, personal, group and joint applicants alike.

Applicant identity and KYC data

Identification details, employment or business particulars, addresses, next of kin and contact data are captured on your published form, with the fields your KYC policy requires marked mandatory.

PEP and FATCA/CRS declarations

Declarations are part of the application itself, made by the applicant before an account exists rather than typed in later from paper.

Directors, beneficial owners, members and holders

Business applications record significant stakeholders; group and joint applications repeat a full section for every member or holder. Each person becomes a screening subject.

A document checklist per account kind

IDs, photos, registration certificates and resolutions are collected against the checklist for that kind of account, with per-holder slots so “complete” means complete for everyone.

Who needs screening, worked out for you

Every person involved — directors, beneficial owners, group members, joint holders, signatories — becomes a screening subject, once per person even when they hold two roles, listed on the application for your compliance team. The screening itself runs in your screening tool.

Staff review, SLA timers and an audit trail

Staff claim the application, verify its documents and approve or reject it, with SLA timers on the workflow steps. Once your core banking system opens the account, they record the account number in BAOS — and every workflow action is logged.

Evaluating digital onboarding solutions? Read build, buy or configure, the KYC onboarding process step by step, and the full account-opening guide library.

Every kind of applicant

Business, personal, group, or joint — one platform.

The applicant's first step is choosing the kind of account. Your bank enables only the kinds it offers — each ships as a starter form you publish from the form builder — and every one of them runs through the same review workflow.

Business & corporate

The full corporate journey, from entity profile to facilities.

Entity profile & contacts
Directors & beneficial owners
Board resolutions
Account facilities
Personal

Individual accounts, captured completely the first time.

Identity & documents
Employment & income
Residential & postal addresses
Next of kin
Group (chama)

Chamas and savings groups, with every member on the record.

Group entity
Member register
Elected officials
Group meeting resolution
Joint

Every holder captured as a person in their own right.

Each holder in full
Operating mandate
Survivorship instruction
Per-holder documents

One review workflow for all of them. The applicant chooses the account kind, BAOS serves the right form, and every person involved — members, holders, signatories and stakeholders — is listed for screening.

Capabilities

Everything opening a bank account needs — in one flow.

Not a form that emails a PDF to a branch. A complete pipeline: the applicant applies, compliance data is captured in line, and your team reviews and decides against SLA timers.

Guided application, on your own form

The applicant picks the kind of account — business, personal, group, or joint — and gets the step-by-step form your bank published for it, with autosave and resume-anywhere drafts.

Customer self-service portal

Applicants register and sign in — using your own customer identity service if you have one — keep a list of drafts they can resume or discard, and track progress by a private reference link that cannot be guessed.

Documents, checked off

Uploads are driven by your checklist, with their own slot for each signatory, beneficial owner, or group member. Staff verify them one at a time or a whole application at once.

Compliance at the source

PEP and FATCA declarations and the beneficial-owner register are captured inside the application. The applicant and every person involved — directors, beneficial owners, group members, joint holders, signatories — are listed for screening on the same record.

Governance and mandates built in

Board resolutions for companies, group meeting resolutions for chamas, operating mandates and survivorship for joint accounts — with authorized signatories and signing mandates captured and validated in the same flow.

Staff review & approval

Reviewers claim applications from an unassigned queue into their own, verify documents, and approve, reject or email the applicant for more information — with branch-scoped roles seeing only their own branch.

SLA timers & audit trail

Every workflow step starts an SLA timer and a dashboard shows the average time each step takes; every workflow action is recorded with who did it and when.

Works in two languages

Every question, section, and helper text can carry English and Swahili, edited in the form builder's translation editor — and applicants get a switcher wherever a translation exists.

Deploy it your way

Buy it on Azure Marketplace and run it in your own Azure subscription. If your data must stay on your own servers, we scope an on-premises deployment with your team.

How it works

Two sides, one application.

The customer picks the kind of account — business, personal, group, or joint — and fills in the guided form your bank published for it. The nine steps below are the Kenya corporate standard template, and every one of them is yours to change. Behind the glass, every kind of application runs through the same review pipeline: claimed by a reviewer, documents verified, approved or rejected, and the account number recorded once your core banking system opens the account.

For the applicant — the Kenya corporate standard template
Autosaved drafts · resume anywhere · track by reference token
1
Business information
Entity details, addresses, and contacts.
2
Account selection
Product, currency, segment, and home branch.
3
Account facilities
Debit card, cheque, mobile and internet banking.
4
Compliance
PEP declaration, FATCA, and stakeholders.
5
Authorized signatories
Up to four signatories with identification.
6
Signing mandate
Operating instructions and terms.
7
Collections setup
Pay-in short code, portal users, alerts.
8
Board resolution
Resolution items and admin configuration.
9
Documents & review
Upload documents and final review.
For your bank — the review pipeline
Role-based queues · SLA timers · audit trail
Application #4821 · progressUpdated 12s ago
Application submittedDone
Completed 2h ago
Claimed by reviewerDone
41m ago · A. Njoroge
Documents verifiedIn review
Started 38m ago · A. Njoroge
Approve or reject
Pending
Account number recorded
Pending
Submitted
24
Under review
11
Completed
63
Avg. hours per step
6.5
Pending reviewsCompliance queue
MK
Mwangi & Kariuki LLP
Business · App #4821 · 38m in stage
In review
AO
Amina Otieno
Personal · App #4818 · awaiting docs
Pending
UC
Umoja Investment Chama
Group · App #4815 · officials added
Unassigned
Queues that know who you are
A personal queue and an unassigned queue to claim from, with branch-scoped roles seeing only their own branch's applications — so nobody picks through everyone's work.
Claim it
A reviewer claims an unassigned application into their own queue, so every application has a named owner instead of being nobody's job.
Decisions carry a reason
Approve or reject — or email the applicant to ask for more information — with the reviewer's comments recorded against the application.
Office-use sections
Staff-only fields — relationship manager and sales codes, exception notes — sit on the same record as the applicant's answers, hidden from the applicant.
The whole application, one view
The entity or the people, facilities, mandate, compliance, and documents on a single screen, with a timeline of who did what and when.
Exactly as it was submitted
Re-open any application on the form version it was filled on. What an auditor sees three years from now is what the applicant actually saw.
Form builder

Change the form without changing the software.

Account-opening forms move — a new regulation, a new product, a new segment. In BAOS that is an afternoon in an admin console, not a release cycle. Build the form visually, publish it under four eyes, and the next application picks it up.

Visual three-pane builder

Drag fields from the palette onto the canvas and set their properties on the right. Twenty-two field types, from declarations to repeating people lists — no code, no redeploy, no engineering ticket.

Versioned and restorable

Every published version is immutable, and each application pins the version it was filled on — so an old submission always renders exactly as it was.

Maker-checker publishing

A form cannot be published by whoever last edited it. Separation of duties is enforced by the platform, not by policy.

Conditional logic

Show or require a field based on earlier answers. The same rules are evaluated identically in the browser and on the server.

Bilingual forms

Per-field English and Swahili translations, edited in a dedicated translation editor, with a language switcher that appears only where translations have been provided.

Reusable option sets

Define a pick list once — industries, business types, currencies — and reuse it across every form and step.

Routing by applicant

Serve a different form by account kind and by channel — self-service or staff-assisted — with a tenant default sitting behind it.

Checked before it goes live

Publishing is blocked on duplicate questions, empty steps, dropdowns with no options, and rules pointing at a field you removed — so a broken form never reaches an applicant.

Preview before you publish

Walk your draft form through the same screen the applicant will see, before anyone else does.

Still structured data

Configured questions map onto the proper fields of the underlying record — entity name, signatory, shareholding — so reporting and downstream systems keep working, however you rearrange the form.

Portable between institutions

Export a finished form and import it into another tenant or environment. A form proven at one institution becomes the starting point for the next.

Funnel analytics

Open drafts by step, measured against submissions — so you can find the question that is costing you applications.

You don't start from a blank canvas

Ten starter forms across all four account kinds ship with the platform, drawn from real account-opening forms in use across the region — including the Kenya corporate standard, the nine-step journey shown above.

Kenya corporate standardKenya personal accountTanzania personal accountKenya group / chama accountJoint accountIslamic banking variantTanzania enterpriseTrustee accountFATCA / CRS self-certificationAdditional signatories mandate
And a library of ready-made sections

Nearly forty prebuilt sections — beneficial owners, member registers, next of kin, signatories, FATCA, board resolutions, and the rest — to drop into any form, grouped across nine areas.

BusinessIndividualGroupJointPeopleComplianceBankingLegalStaff
Connected platform

One application, every service it touches.

No re-keying between systems. The customer portal feeds a single application record that flows through compliance capture, documents, SLA timing and audit — and reaches approval complete and validated, ready for your team to open the account in your core banking system.

Customer portal

Self-service sign-up, draft autosave, and reference-token tracking — the only surface the applicant sees — so an applicant can stop, come back and finish without calling the branch.

Application service

The single source of truth: the entity or the person, members, holders, signatories, facilities, and mandate — all on one record, so nothing is re-keyed and nothing is lost between teams.

Compliance service

PEP and FATCA declarations and the beneficial-owner register, with the applicant and every person involved derived as a screening subject and a compliance summary on the application — so reviewers can see who still needs screening.

Document service

Checklist-driven upload, download, and verification — one document at a time or a whole application at once, including signatory photographs — so the reviewer works a complete file, not a trickle of attachments.

SLA monitoring

Per-step timers start automatically, and a dashboard shows the average time each step takes — so you can see where applications slow down before applicants give up.

Audit & notifications

Each workflow action is recorded with who did it, when and from which address, and applicants get an email at each key step — so everyone knows where the application stands, and the record shows it later.

On approval, a complete, validated record is ready for account creation in your core systemAccount opened
Built multi-tenant

Your brand, your products, your rules.

One codebase serves every institution as an isolated tenant. Configure it from an admin console — no engineering — and the customer portal and application screens wear your colours.

Account kinds — enable business, personal, group, and joint — each with its own form
Branding — primary colours and browser title per tenant
Account products — define the products and currencies on offer
Segments & branches — set up the segments and branches your staff are scoped to
Form & checklist config — tune required fields and documents
Roles & permissions — reviewer, compliance officer, branch manager
Schema isolation — each tenant’s data fully separated
Tenant configurationtenant_blueharbor
BH
BlueHarbor Bank
Primary colours · browser title
Account kinds4 live
Account products7
Segments5
Branches18
Document checklist12 items
AI assistantEnterprise plan · Container Apps hosting

For applicants who would rather just talk.

An assistant that walks an applicant through the same application in conversation, and gives your reviewers an early read on the documents. It ships with the Enterprise plan, and it is deliberately built so that it can never make the decision.

A guided conversation

Applicants who would rather talk than fill in a form are walked through it in chat, with interactive cards for choosing a product, completing a section, making the PEP and FATCA declarations, uploading documents, and confirming a final summary.

Built from your form

Those cards are generated from your own published form for the kind of account being opened — with prompts tuned per kind, so a personal applicant is never asked about board resolutions — and stay in step whenever you change the form.

Document pre-check

Recognises seven common Kenyan document types, reads the key details, and deterministically cross-checks them against what the applicant typed. The reviewer sees an advisory flag — never an automatic decision.

It cannot approve anything

There is deliberately no tool for submitting, verifying, or approving — those actions do not exist for the assistant. It is rate-limited, capped in how far it can go on its own, and treats document text as untrusted. A person still decides.

Your model, your choice. The assistant runs on Claude through Azure AI Foundry or on Azure OpenAI, inside your own subscription — you pick the model in the deployment wizard. It is included in the Enterprise plan, which deploys the Container Apps hosting it needs.
Platform

Built to survive an audit.

Onboarding is where a regulator starts asking questions. The platform is built so the answers are already recorded rather than reconstructed.

Eight roles out of the box

from staff data entry, reviewer and document verifier to compliance officer, branch manager and audit viewer — with fine-grained permissions checked on every request

Every workflow action on the record

who did what, in which role, when, and from which address and device — with reviewer decisions and their comments alongside

Hardened by default

encrypted sessions, protection against cross-site request forgery, and every service checking who is calling — not just the front door

Tenants genuinely separated

each institution's data lives in its own database schema, and branch-scoped staff only see their own branch's applications

Tested end to end

automated tests that drive the full applicant and staff journeys in a real browser, plus checks that keep the screens and the services in step

Reproducible deployments

the whole environment is defined as code and packaged for Azure Marketplace, so a rebuild is a rerun rather than a rediscovery

Deployment

Two ways to deploy. One platform.

Buy it on Azure Marketplace and have it running in your own subscription. If your regulator or your own policy requires your own datacenter, we scope an on-premises deployment with your team.

Azure Marketplace
Managed application · transact with Microsoft
Your subscription — deploys into your own Azure tenancy, in the region you choose
Managed by Creodata — updates and support through Azure managed-application publisher access, with no VPNs and no shared credentials
Seven fields to deploy — app name, environment, database settings, and a staff admin password
Provisioned for you — App Service, Function Apps, PostgreSQL Flexible Server, Service Bus, Blob Storage, and Application Insights
Get it on Azure Marketplace

Plans start at $1,500 per month — see the plans below. The plan price covers BAOS management and support; the Azure infrastructure it runs on is billed separately, on your own subscription.

Your own datacenter
On-premises · scoped per engagement
Your infrastructure — for institutions whose regulator or policy requires data to stay on their own servers
The on-premises design — PostgreSQL, RabbitMQ, MinIO and Keycloak take the place of the Azure services
Scoped first — sized and planned with your infrastructure team before any commitment — not a download
Delivered with you — installed, configured, and supported by Creodata as an implementation engagement
Talk to us about an on-premises deployment

Talk to us early: on-premises deployments are planned around your infrastructure, your network and the data-residency requirements set by your regulator.

Three plans on Azure Marketplace

The plan fee covers BAOS management and support; Azure infrastructure is billed separately on your subscription.

Standard
$1,500/month
Single brand, the full platform
All four account kinds and the form builder
Review workflow, SLA timers, and audit trail
Bilingual English and Swahili forms
Publisher-managed updates and support
View on Azure Marketplace
Professional
$3,500/month
Multi-brand with enterprise identity
Up to three brands on one deployment
Staff single sign-on with Microsoft Entra ID
Customer identity via Azure AD B2C
24x5 priority support and two onboarding workshops
View on Azure Marketplace
Enterprise
AI assistant
$6,000/month
AI-assisted, high-availability operation
Unlimited brands and subsidiaries
AI assistant and AI document pre-check
Container Apps autoscaling and HA PostgreSQL
24/7 P1 support with a named account manager
View on Azure Marketplace

Prices as listed on Azure Marketplace. Azure infrastructure is billed separately — typically $40–80 per month for entry deployments, and $500–900 per month for a high-availability Enterprise configuration, plus model usage for the AI assistant.

The on-premises design, service by service
CapabilityMicrosoft AzureOn-premises design
Relational dataPostgreSQL Flexible ServerPostgreSQL
Messaging / eventsAzure Service BusRabbitMQ
Document storageAzure Blob StorageMinIO
IdentityMicrosoft Entra ID (staff) · Azure AD B2C (customers)Keycloak
Three hosting modes on Azure

The customer portal runs on App Service, as a static site, or in containers. The Standard and Professional plans install the App Service option; the Enterprise plan runs on Container Apps with autoscaling — the mode that hosts the AI assistant.

FAQ

Account opening in Kenya: questions banks and SACCOs ask.

Does BAOS check IDs against IPRS or KRA?

No. CBK's 2025 guidance gives IPRS checks of the ID number, serial number and name, a KRA PIN name check, selfies and video calls as examples of verification (Table 3). BAOS does not run those lookups itself: it checks the Kenyan ID and KRA PIN formats as they are typed, holds the documents and records the staff review. The IPRS and KRA checks come from your identity-verification provider or your own process.

Which Kenyan templates ship with BAOS?

The Kenya corporate standard (a nine-step corporate journey), Kenya personal and Kenya group / chama templates, plus joint, trustee, Islamic-banking, FATCA / CRS and additional-signatory templates. Your team changes any of them in the no-code form builder — for example, to ask for the trust registration certificate that the Trust Administration Act 2026 introduces.

Can a SACCO use BAOS for member onboarding?

Yes. SASRA's 2024 AML guideline (SASRA/GG/1/2024, §6.1.1) asks for an original ID for individual members, the certificate of incorporation for bodies corporate, and, for unincorporated groups, the certificate of registration and the identities of officials and signatories. BAOS runs individual, group and corporate journeys, and the group journey records the member register, the officials and the meeting resolution. Verification against IPRS and the KRA database, which the guideline names, stays with your provider.

Does a chama have to be registered before it can open an account?

We found no Kenyan law that bars an unregistered group from banking, and banks' requirements differ. Groups registered under the Community Groups Registration Act receive a certificate from the Director of Social Development, but on 10 September 2026 the High Court declared that Act unconstitutional, suspending the declaration until 10 February 2027. In BAOS each bank sets the chama document list it accepts in the form builder.

Is our data hosted in Kenya?

Not on Azure: Azure has no region in Kenya, and BAOS runs in your own Azure subscription in the region you choose (the nearest are South Africa North and South Africa West). The Data Protection Act allows transfers abroad with appropriate safeguards (ss.48–49). If your policy requires in-country hosting, Creodata scopes an on-premises deployment with your team.

How much does BAOS cost in Kenya?

The same public plans as everywhere: Standard at $1,500, Professional at $3,500 and Enterprise at $6,000 per month on Azure Marketplace, plus the Azure infrastructure on your own subscription. Kenya is one of BAOS's Azure Marketplace markets.

Can applicants fill in the form in Swahili?

Yes, where you provide the text: every question, section and help line can carry English and Swahili, and applicants get a language switcher wherever a translation exists. The staff interface is in English.

See any account opened end to end.

We'll walk you through the applicant journey, the form builder, and the review pipeline — across business, personal, group, and joint accounts, in your institution's colours. Or deploy it yourself from Azure Marketplace.