From the journal

Kenya's Digital Asset Licensing and Client Protection Rules

Kenya licenses businesses that hold, exchange, transfer, manage or issue virtual assets and prescribes how they protect customers. The question is how the Virtual Asset Service Providers Act, 2025, No. 20 of 2025 (Act), and the Virtual Asset Service Providers Regulations, 2026, Legal Notice 134 of 2026 (Regulations), govern market entry and continuing operations.

Illia ProkopievCo-Founder and CEO33 min read

Summary

Each service requires classification under the Act's First Schedule. The Central Bank of Kenya (CBK) regulates wallets, payment processing and stablecoin issuance; the Capital Markets Authority (CMA) regulates the other listed activities. Offshore income from Kenya can trigger the territorial rule without a Kenyan office. (Act, ss. 3–9 and First Schedule; Regulations, r. 4.)

The incumbent transition runs from the Act's commencement on 4 November 2025. Its one-year anniversary is 4 November 2026, not one year after the Regulations' publication. A pending application does not expressly extend that period. Annual licence expiry and the separate post-licensing commencement deadline require their own controls. (Act, p. 489 and ss. 13 and 47; Regulations, rr. 8 and 11.)

Capital is activity-specific and must remain available throughout operations. Multiple activities require the highest applicable paid-up amount plus 50% for each additional activity. Liquidity, insurance, customer assets and stablecoin reserves require separate assessments. Fee bases also differ between turnover, revenue, transaction value and assets under management. (Regulations, rr. 75–77 and 85–88; First and Fifth Schedules.)

A share transaction of 10% or less cannot safely proceed on notification alone. Regulation 29's notification tier does not remove the broader approval requirement in section 27 of the Act. A qualifying exchange-traded licensee may obtain the statutory exemption, subject to its conditions. (Act, ss. 27 and 49(4); Regulations, r. 29.)

Wallet providers may pool customer assets with explicit consent, but must keep them separate from proprietary assets. Consent to pooling does not authorize lending or pledging assets entrusted for safekeeping. Customer entitlements must remain traceable through operational failure and lawful asset freezes. (Act, s. 31; Regulations, rr. 66, 104, 107 and 140.)

Stablecoin issuers must maintain full eligible reserves, Kenyan reserve arrangements and a par-redemption mechanism. The ordinary redemption period is two working days, subject to the specified CBK-approved exceptions and intervention powers. Holding-period benefits count as prohibited interest, including when another licensee provides the stablecoin service. (Regulations, rr. 68(4)(e), 71–72, 75–77, 80 and 83.)

Provider licensing, offering approval, promoter approval and platform approval are distinct requirements. Tokenization requires evidence of underlying legal rights; creating a token does not establish the rights described in its white paper. Stablecoin listing also requires the specified CBK approval and a duly licensed issuer. (Act, s. 34; Regulations, rr. 49–65.)

Cyber incidents, financial returns, complaints and advertisements create separate reporting and retention obligations. Administrative sanctions, criminal convictions and customer claims have different prerequisites and limits. The published text supports the substantive answers, but final parliamentary disposition and complete later judicial or legislative treatment remain unverified. (Act, ss. 25, 39–44; Regulations, rr. 26, 92–99, 110, 133 and 142–151.)

Publication, statutory authority and transition

The National Treasury made the Regulations under section 49 of the Act. Legal Notice 134 appears in Kenya Gazette Supplement No. 185, Legislative Supplement No. 103, dated 22 July 2026. The instrument was made on 3 July 2026. Those dates distinguish signature from publication. Kenya Law records commencement on 22 July 2026; the gazetted text contains no separate delayed commencement clause. (Act, s. 49; Regulations, preamble, r. 1 and signature page, pp. 4259 and 4368; Kenya Law, Legal Notice 134 of 2026, commencement record.)

The Act had already commenced on 4 November 2025. Section 47 gives persons providing virtual asset services at commencement one year to comply. Adding one calendar year produces the anniversary of 4 November 2026. Publication of the Regulations does not restart that statutory period. A company incorporated earlier, but not providing the relevant services at commencement, cannot establish eligibility through its incorporation date alone. (Act, p. 489 and s. 47.)

An incumbent can rely on section 47 when addressing the time allowed for compliance. Its strongest argument is that the legislature expressly anticipated adjustment by existing operators. The provision does not expressly extend the period for an undecided application or exempt conduct from other applicable laws. A provider relying on transition needs dated evidence of its services at commencement and a route to compliance within the statutory period. New entrants remain subject to the ordinary licensing prohibition. (Act, ss. 8 and 47.)

Publication establishes the text issued by the Treasury; it does not establish every later procedural event. The Regulations and supporting documents were tabled in the National Assembly on 13 August 2026. The Committee on Delegated Legislation's tracker, with a status timestamp of 24 August 2026, records receipt on 5 August 2026 and the instrument as pending before the Committee. These records establish receipt and tabling, not final parliamentary disposition or compliance with every applicable scrutiny requirement. Later parliamentary disposition and any subsequent judicial restriction remain unverified. An unconditional opinion that the instrument has survived all statutory scrutiny is therefore unavailable on this record. The substantive answers apply to the published instrument unless an operative amendment, annulment or court order changes the relevant provision. The Act independently controls where delegated wording exceeds the authority conferred by section 49. (Act, s. 49(1), (3)–(4); Regulations, preamble; National Assembly, Votes and Proceedings, 13 August 2026, item 6(a), p. 920; Committee on Delegated Legislation, Statutory Instruments Tracker, status as at 24 August 2026, entry 94, p. 11.)

Covered services, exclusions and offshore operations

Classification turns on what the business does and what rights the asset carries. The Act's definition covers a digital representation of value that can be digitally traded or transferred and used for payment or investment. It excludes digital representations of fiat currencies, securities and other financial assets. A product does not enter the virtual-asset category merely because its operator records it on a distributed ledger. A securities characterization therefore requires assessment before selecting the virtual-asset licensing route. (Act, s. 2, definitions of "virtual asset" and "virtual asset service provider".)

Section 4 contains narrower exclusions. A closed-system product must satisfy the statutory restrictions on external transfer, exchange and use. A non-fungible token falls outside the Act only when it is not used for payment, investment or a financial purpose. The exclusion for a virtual service token depends on its non-transferability and sole service-access function. These conditions prevent an operator from establishing an exemption through a product name alone. A transferable investment token cannot claim the service-token exception merely because it also provides access to software. (Act, ss. 2 and 4(2)–(3).)

Regulation 4 reaches a provider that actively solicits or targets Kenyan consumers, or derives economic benefit or income from Kenya. The alternatives matter: absence of Kenyan advertising does not dispose of the income limb. An offshore provider receiving revenue from Kenyan users must examine that connection even without premises in Kenya. The rule does not justify treating every globally accessible webpage as a Kenyan business without examining the statutory activity and territorial facts. (Act, ss. 3–4 and 8; Regulations, r. 4.)

A claim that software is non-custodial addresses only part of the classification exercise. The Act defines a custodial wallet through third-party management of private keys, but separately regulates exchanges, brokerage and other listed services. A developer supplying software without carrying on a listed service presents a different case from an operator arranging trades or controlling customer transactions. Neither the label "decentralized" nor the absence of one custody function supplies a general exemption from the Act. (Act, s. 2 and First Schedule.)

Regulator allocation and corporate presence

The CBK licenses virtual asset wallet providers, payment processors and stablecoin issuers. The CMA licenses exchanges, brokers, investment advisers, managers, initial coin offering providers, tokenization providers and token issuance platforms. A combined exchange, wallet and stablecoin business must map each function to the relevant regulator. Regulation 6 permits consideration of multiple activities, but does not transfer one regulator's statutory functions to the other. (Act, ss. 5–9 and First Schedule; Regulations, r. 6(5).)

The applicant must be a company limited by shares incorporated in Kenya, or a foreign company limited by shares registered under the Companies Act. Section 8 does not invariably require a Kenyan subsidiary. Section 19 nevertheless requires a physical office in Kenya, and regulation 44 requires a Kenyan-domiciled chief executive officer. Foreign incorporation therefore does not establish an exemption from local operating presence. (Act, ss. 8(1) and 19; Regulations, r. 44.)

The Coordination Forum supports cooperation and information exchange across the agencies in the Sixth Schedule. The CBK and CMA may undertake joint supervisory and licensing activities. These provisions do not create an alternative licensing body or convert participation by the Kenya Revenue Authority or Data Commissioner into tax or data-protection clearance. Each relevant permission must be obtained under the power that authorizes it. (Act, ss. 5–6; Regulations, rr. 145–148 and Sixth Schedule.)

Applications, annual expiry and additional authorizations

Regulation 6 requires the prescribed form, business plan, ownership and funding information, fit-and-proper material, financial evidence and the specified control policies. Independent systems assurance and vulnerability testing form part of that package. The Second Schedule supplies the application form; the Third specifies the business plan; the Fourth addresses fit-and-proper assessment. An applicant must complete the applicable parts and provide additional information requested by the regulator. (Regulations, r. 6 and Second–Fourth Schedules.)

The general determination period is thirty days after receipt of all required documents and information and completion of due diligence. It is not an unconditional thirty-day period beginning with an initial submission. The Regulations contain no deemed approval for silence. A launch date dependent on automatic approval after filing would therefore lack textual support. Applicants must also report material changes within two days under regulation 9; the Act's fourteen-day information-update period does not excuse failure to meet that shorter requirement. Once licensed, a provider must obtain prior written regulatory no-objection before effecting or permitting a material change within section 26(2); a later notification does not replace that requirement. (Act, ss. 10(8) and 26(1)–(2); Regulations, rr. 6(4), 7 and 9.)

A licence expires on 31 December of its year of issue, while renewal must be sought at least two months before expiry. Subtracting two calendar months gives a planning date of 31 October. A licence issued late in the year raises an unresolved application-timing question; neither provision grants an automatic twelve-month first term. A newly licensed provider must also commence business within twelve months of grant. That commencement allowance does not displace annual renewal or extend the incumbent transition. (Act, ss. 13 and 47; Regulations, rr. 8 and 11.)

For a specific provider, the licensed legal entity, service categories, conditions and expiry must be verified. Section 10(7) requires Gazette notice within thirty days of a licence grant; section 17 requires an updated public register. Incorporation or an application receipt does not establish authorization. A business already regulated under another law must also provide the required no-objection from that regulator. (Act, ss. 10(7), 11(k), 12(2), 13 and 17.)

Currency conversion requires separate attention. A licensee intending to undertake conversion of virtual assets to or from foreign currency must obtain prior CBK authorization under regulation 14. That authorization also expires on 31 December and has a separate renewal process. The ten-day notice period follows the CBK's determination; it is not a promise that the application will be decided within ten days. Before suspension or revocation under regulation 16, the CBK must give at least fourteen days' notice and an opportunity for representations. (Regulations, rr. 14–16.)

Capital, liquidity and funding quality

The Fifth Schedule prescribes different paid-up and liquid-capital requirements. Regulation 2 defines liquid capital as the amount by which liquid assets exceed liabilities. Wallet providers require KES 150 million paid up; liquid capital is the higher of KES 30 million or 100% of current liabilities for at least thirty days. Exchanges require KES 100 million paid up and liquid capital equal to the higher of KES 20 million or 8% of total liabilities. A payment processor requires KES 10 million paid up and liquid capital covering 100% of current liabilities for at least thirty days. The current-liability and total-liability tests must not be substituted for one another. (Regulations, rr. 2 and 85; Fifth Schedule, rows 1–3.)

Brokers and tokenization providers each require KES 10 million paid up and the higher of KES 2 million or 8% of total liabilities in liquid capital. Managers, initial coin offering providers and token issuance platforms each require KES 20 million paid up and the higher of KES 4 million or 8% of total liabilities in liquid capital. Investment advisers have NIL scheduled paid-up and liquid-capital amounts, but still require at least KES 1 million of professional indemnity cover. NIL does not remove licensing or operating duties. (Regulations, rr. 85 and 88(6); Fifth Schedule, rows 4–9.)

Stablecoin issuers require KES 300 million paid up. Their liquid-capital requirement is the higher of KES 60 million or 100% of current liabilities for at least thirty days. Full backing of outstanding coins remains separately required. A reserve held for holders cannot be treated as freely available shareholder capital merely because it is liquid. Its segregation and restrictions on use must remain effective. (Regulations, rr. 75–77 and 85; Fifth Schedule, row 10.)

For multiple activities, regulation 85(6) requires the highest-category paid-up amount plus 50% of each additional activity's amount. A permitted wallet-and-exchange combination therefore gives KES 150 million + 50% × KES 100 million = KES 200 million. Adding stablecoin issuance produces KES 300 million + 50% × KES 150 million + 50% × KES 100 million = KES 425 million. These are derived illustrations, not approvals for either combination. The wording does not prescribe the same aggregation formula for liquid capital. (Regulations, rr. 6(5) and 85(6); Fifth Schedule, rows 1, 2 and 10.)

Shareholder loans, borrowed capital, unpaid commitments, revaluation reserves and internally generated intangibles do not qualify as paid-up capital. Non-cash consideration requires regulatory approval, objective valuation and immediate realization. Core capital must remain unencumbered, and the regulator may require a higher amount for the provider's risk profile. A fall, or likely fall, below the minimum triggers immediate written notification and a restoration plan. Temporary inflation of capital is a separate offence. (Regulations, rr. 85(3)–(14) and 86.)

Licence fees and the cost of additional approvals

Application and initial licence fees are separate. The wallet amounts are KES 100,000 and KES 500,000; exchange amounts are KES 100,000 and KES 1 million. Payment processors pay KES 100,000 and KES 200,000; brokers pay KES 100,000 for each. Advisers pay KES 10,000 and KES 50,000, while managers pay KES 50,000 and KES 200,000. Each initial coin offering, tokenization and token issuance platform category carries KES 100,000 and KES 500,000. Stablecoin issuance carries KES 100,000 and KES 2 million. These amounts exclude renewal and transaction-specific approval fees. (Regulations, First Schedule, para. 1.)

Annual renewal uses different charging bases. Wallet, initial coin offering, tokenization and token issuance platform providers pay the higher of KES 500,000 or 0.15% of gross turnover. Stablecoin issuers pay the higher of KES 2 million or 0.15% of gross turnover. Exchanges pay the higher of KES 500,000 or 0.5% of the previous year's gross revenue. Brokers pay KES 100,000 and advisers KES 50,000. Managers pay 0.05% of assets under management, subject to a KES 200,000 minimum and KES 5 million maximum. (Regulations, First Schedule, para. 2.)

Payment processor renewal depends on annual gross transaction value. The scheduled fee is KES 20,000 for zero through KES 1 billion; KES 100,000 for KES 1,000,000,001 through KES 10 billion; and KES 500,000 for KES 10,000,000,001 through KES 50 billion. It rises to KES 1 million for KES 50,000,000,001 through KES 100 billion, KES 5 million for KES 100,000,000,001 through KES 500 billion, and KES 10 million for KES 500,000,000,001 through KES 1 trillion. Above KES 1 trillion, the fee is KES 15 million. These are transaction-value bands, rather than revenue bands. (Regulations, First Schedule, para. 2, payment processor entry.)

Initial coin offering and tokenization approvals each cost 0.25% of the successful offer's value, with a KES 200,000 floor and KES 30 million ceiling. Approval of a share acquisition, transfer or disposal costs the higher of 0.25% of transaction value or KES 50,000. Licence assignment carries the category's licence fee. No common percentage or common cap applies across these charges. (Regulations, First Schedule, paras. 3–4.)

A provider must therefore identify which amounts are its revenue, which are customer throughput and which are assets under management. The schedule's different terms do not authorize a single accounting proxy for every category. Where a model makes "gross turnover" uncertain, written clarification is needed before fixing its fee provision. None of these licence charges determines the separate tax treatment of the provider or its customers. (Regulations, First Schedule, paras. 1–4.)

Ownership, board composition and outsourcing

Section 27(1) requires approval before shares in a licensee are issued or issued shares are voluntarily transferred or disposed of. Regulation 29(1)(a) requires advance notification for an acquisition, transfer or disposal of no more than 10%; paragraph (b) requires approval above 10%. A purchaser can argue that the notification tier was intended to permit smaller transactions without approval. That reading encounters the Act's express prohibition and the limits on delegated authority. Notification alone is therefore an unsafe basis for completing a transaction within section 27(1). (Act, ss. 27(1) and 49(4); Regulations, r. 29.)

A regulator may exempt a licensee with shares or interests publicly traded on a qualifying Kenyan or recognized overseas exchange. The exemption carries control-change notification, information and any additional conditions. Section 27 also covers legal and beneficial interests and treats involuntary vesting separately. Parties should obtain the applicable approval or establish an actual exemption, rather than infer one from deal size or group ownership. (Act, s. 27(2)–(4); Regulations, r. 29(3)–(5).)

Assignment of the licence is a different transaction. Regulation 13 requires approval and requires the licence to have been held for at least thirty-six months from the date of commencement of business, alongside compliance and transferee requirements. It does not impose that same condition on every share sale. A business acquisition must identify whether the licensed company remains the operator or the licence itself is being transferred. The latter cannot be completed through an unapproved contractual assignment. (Act, s. 14; Regulations, r. 13.)

The board must contain at least three directors, with at least three natural persons. Regulation 42 requires one-third independent directors and restricts related directors; it also prevents a chairperson or director from being appointed chief executive officer. The Act limits a director to service on two virtual asset service provider boards. Independence and fit-and-proper requirements must be tested against the actual appointments and relationships, rather than satisfied through nominal job titles. (Act, ss. 18 and 20; Regulations, rr. 42–44.)

A licensee needs an independent compliance function with resources and access to its board. Its board remains responsible despite delegation, and the virtual-asset business must be kept in a separate unit with separate management and records from other business. Outsourcing approval must be obtained at least thirty days before the agreement is implemented. The approval rule applies to the operational functions described in regulation 113(1)–(2); additional protections attach to material functions under paragraph (4). A materiality argument therefore does not remove the preceding approval requirement. (Act, s. 26; Regulations, rr. 39, 41, 43 and 113.)

Customer ownership, custody and pooled accounts

The Act requires sufficient assets of each type to meet custody obligations, separation from proprietary holdings and protection against the licensee's creditors. Regulation 66 makes those requirements operational through separate on-chain addresses and internal accounts, reconciliations and records of customer claims. A platform cannot satisfy a shortfall in one asset solely by pointing to the value of another. A claim based on aggregate solvency would not answer the type-specific custody requirement. (Act, s. 31; Regulations, r. 66(1)(a)–(d), (i) and (l).)

Omnibus custody is permitted with explicit customer consent. The pooled arrangement must still preserve customer entitlements and remain separate from the provider's own assets. Regulation 66(1)(g) prohibits lending, use, hypothecation, pledging or encumbrance of assets entrusted for safekeeping. The permission to pool assets does not create an exception to that prohibition. A custody-based yield product therefore needs a different legal analysis; customer consent to an omnibus account cannot establish permission to deploy the assets. (Regulations, r. 66(1)(e)–(g); r. 104(8).)

Regulation 106 permits a clearing or settlement security interest, lien or setoff for an obligation owed directly by the affected customer. The licensee must retain the specified records. That exception does not permit collateral for the provider's general borrowing. It also does not expressly override the wallet-specific safekeeping prohibition in regulation 66(1)(g). A proposed settlement lien over wallet custody assets therefore requires resolution of that interaction before implementation. (Regulations, rr. 66(1)(g) and 106.)

Wallet agreements must address the customer's beneficial and equitable interests, and providers must support return of assets or access on demand. Wallet statements are required at least every three months and on request. Monthly on-chain reconciliations must be available to the CBK by the tenth day of the following month. Managers face separate monthly customer statements under regulation 107. The customer statement and regulatory reconciliation duties have different recipients and frequencies. (Regulations, rr. 66(1)(d), (j), (m), 66(2) and 107.)

Client and proprietary bank accounts must be maintained with a bank licensed in Kenya, with customer money segregated. Customer funds must be deposited by the end of the business day following receipt. Pooled accounts require records identifying individual entitlements, and customer assets cannot be used for the licensee's own account or another person's account. Contractual terms must preserve the statutory duties of care and responsibility; broad liability exclusions cannot remove them. (Regulations, rr. 24, 103–104.)

Asset segregation reduces exposure to the provider's estate only when the legal arrangements and operational records maintain it. A customer must still establish the relevant entitlement if ownership or a shortfall is disputed. Neither a licence nor an insurance requirement promises repayment of every loss. Contract terms, custody records, policy limits and the applicable insolvency process remain material to recovery. (Act, s. 31; Regulations, rr. 66, 88, 102–107 and 149–150.)

Stablecoin authorization, reserves and redemption

Stablecoin issuance requires CBK licensing and approval of the white paper. Regulation 70 separately conditions a public offer or admission to trading on issuer status, licensing, white-paper approval and publication. The issuer must seek the white-paper approval at least ninety days before publication. The thirty-day complete-application determination period does not eliminate that separate lead time. Material model or white-paper changes require the prescribed approval before implementation. (Regulations, rr. 67–70 and 73.)

Outstanding coins must be fully backed at all times by eligible reserves. Permitted categories include cash and bank deposits, government securities with residual maturity no longer than ninety days, and repurchase agreements no longer than seven days backed by the specified cash deposits. Other assets require CBK approval. The text therefore does not support an unbacked algorithmic model merely because the issuer calls its token stable. Reserve eligibility and sufficiency must each be demonstrated. (Regulations, r. 75(1)(a)–(b).)

At least 30% of funds received must be held in segregated trust accounts at commercial banks in Kenya. The remainder must be invested in Kenya in accordance with regulation 75. For a fiat-referenced coin, reserve assets must be denominated in the referenced official currency. The issuer bears the investment gains or losses and counterparty or operational risks. An overseas group reserve pool does not satisfy these requirements without arrangements meeting the Kenyan rules. (Regulations, r. 77.)

Each coin requires a separate reserve pool insulated from the issuer's estate. Reserves must remain unencumbered and held through a CBK-approved custodian, with protection against that custodian's creditors. Quarterly stress tests and independent reserve audits must reach the CBK by the tenth day of the following calendar month. Public disclosures cover circulation, reserve composition and the audit summary. General financial accounts cannot replace these reserve-specific tests. (Regulations, rr. 75–76, 78 and 82.)

A holder has a claim against the issuer and may redeem at any time. The ordinary requirement is monetary payment at par within two working days. Regulation 68 permits disclosed extensions under stressed conditions with prior CBK approval; regulation 83 permits specified intervention, including suspension of redemption. These provisions qualify an assertion that every redemption must invariably settle within two days, but they do not permit an issuer to invent its own suspension right. (Regulations, rr. 68(4)(e), 71 and 83.)

Redemption terms and fees require CBK approval. An issuer that accepts Kenyan shillings when selling its stablecoin must always offer a Kenyan-shilling redemption option. The rules should not be described as guaranteeing cost-free redemption because approved fees are expressly contemplated. The contract must explain the approved process without displacing the holder's statutory claim. (Regulations, rr. 71 and 80.)

Interest is prohibited for issuers and for licensees providing stablecoin-related services. Any benefit tied to the duration of holding counts as interest. Renaming a time-linked return as a reward or loyalty benefit therefore does not resolve the prohibition. A benefit unconnected with holding duration still requires assessment under the other conduct and advertising rules; the interest definition alone does not approve it. (Regulations, r. 72; rr. 109 and 123–130.)

A Kenyan exchange cannot list a stablecoin without the specified CBK approval and a duly licensed issuer. The CBK may also direct Kenyan intermediaries to restrict or delist an offshore-issued coin. Overseas authorization therefore does not itself establish permission for local listing or distribution. The relevant issuer and product approvals must be identified before a listing decision. (Regulations, rr. 60(6) and 83.)

Misleading stablecoin white papers can create civil liability for the issuer, directors, senior officers and external auditors. The holder must produce evidence of the misleading information and its effect on the purchase, sale or exchange decision, alongside the loss required by regulation 74(1). Contractual exclusion of that liability is ineffective. The qualified rule for reliance on a summary prevents treating every disappointed investment as an automatic damages claim. (Regulations, r. 74.)

Offerings, tokenization and exchange admission

An initial coin offering requires CMA approval and use of an approved trading platform or system. Promoter approval and platform approval have their own requirements. The approval for an offering lasts no longer than twelve months. An extension application must precede expiry by at least three months; an extension may run no more than six calendar months after approval. These offer periods do not change the provider's annual licence expiry. (Act, ss. 13 and 34; Regulations, rr. 49–53 and 57.)

The white paper must meet regulation 54, and material changes require approval under regulation 55. Offering advertisements require the CMA's prior no-objection to the proposed issuance or promotion and must follow the approved white paper and offering period. A natural person is not eligible to promote or issue an offering under section 34(2). An issuer cannot treat approval of its company as permission for an individual promoter or an unapproved campaign. (Act, s. 34(2)–(3); Regulations, rr. 52 and 54–58.)

A tokenization provider needs a licence under regulation 61 and approval of the particular offer under regulation 62. The application must establish the asset's ownership, valuation and absence of encumbrances, together with custody and title arrangements. Regulation 62(3) requires clear legal rights and independently verifiable valuation, existence and condition. The white paper must explain whether holders obtain direct ownership, a fractional interest or another right. (Regulations, rr. 61–63.)

Those requirements make the legal mechanism for transferring rights indispensable. A token can describe a contractual claim without conveying ownership of the underlying asset. Whether the holder receives title depends on the documented arrangement and the law governing that asset; the act of minting cannot prove compliance with those conditions. Securities excluded by section 2 require separate classification. Neither tokenization approval nor computer code resolves that threshold by itself. (Act, s. 2; Regulations, rr. 62(2)(e)–(j), 62(3), 63(2)(c)–(d) and 65.)

Exchanges and token issuance platforms must maintain approved listings and perform the prescribed asset due diligence. A listing requires attainment of the approved white paper's minimum subscription where applicable. New listings and delistings must be notified monthly by the tenth day of the following month. The CMA retains power to direct delisting for the specified financial-stability or consumer-protection risk. Admission to trading therefore does not eliminate continuing scrutiny of the asset or issuer. (Regulations, rr. 33 and 60.)

Financial-crime controls, records and privacy

Virtual asset service providers (VASPs) must implement anti-money-laundering, counter-terrorism-financing and counter-proliferation-financing measures, including targeted financial sanctions. The Act's consequential amendments bring VASPs within the reporting-institution definition under the Proceeds of Crime and Anti-Money Laundering Act. Regulation 32 requires customer due diligence before onboarding. Section 21 expressly prohibits mixer, tumbler and anonymity-enhancing services. An operator cannot avoid those conduct restrictions merely by describing its service as non-custodial. (Act, ss. 21, 24(e), 32–33 and Second Schedule; Regulations, r. 32.)

The licensee must also identify and report market abuse and prevent use of its systems to conceal financial crime. The Regulations do not state a standalone numeric transfer threshold for a VASP "Travel Rule". That absence does not establish an exemption from obligations imposed under the anti-money-laundering legislation or a binding direction. A transfer-data specification must identify its domestic legal source before adopting a foreign threshold or treating an international standard as directly enforceable Kenyan law. (Act, ss. 6, 24(e) and 32; Regulations, rr. 32 and 112.)

Section 44 permits the regulator to require online or automated real-time, read-only access to records of customer and proprietary transactions. It also requires transaction records for at least seven years at the principal place of business. Read-only supervisory access does not itself authorize transaction execution or delivery of private keys. Production of keys or control under a lawful seizure order engages a different power. (Act, s. 44; Regulations, rr. 22, 26 and 137.)

Section 46 preserves data-protection duties. The Data Protection Act, 2019 permits retention required by law and requires purpose limitation and appropriate security. Seven-year retention of prescribed financial records therefore does not justify keeping every customer data field indefinitely. Outsourced processing and overseas transfers require their own legal basis and safeguards. Client consent to a service or to pooled custody does not automatically meet the conditions for processing sensitive information abroad. The application of these additional provisions remains subject to confirmation of their operative version. (Act, s. 46; Data Protection Act, 2019, ss. 25, 39, 41–42 and 48–49.)

Cybersecurity and overlapping reporting periods

A licensee must assign cybersecurity responsibility to a chief information security officer or equivalent and maintain recovery, monitoring and staff-training arrangements. Systems controls must address confidentiality, authorized access, integrity, updates and forks. Vulnerability assessment and penetration testing are required on a bi-annual basis during the first licensing year and at least annually thereafter. A vendor's assurance does not discharge the licensee's own systems obligations. (Regulations, rr. 96–98 and 113.)

Discovery of a cybersecurity incident triggers notification to the relevant regulator within twenty-four hours. Regulation 99 also requires a detailed report within five working days and separately addresses material incidents, key loss and unauthorized transactions. Section 25 requires a written report within seven working days after the initial statutory notification. An incident plan must satisfy the shorter cyber-reporting requirement and include the content required by the Act; waiting seven working days is not sufficient for the regulatory report. (Act, s. 25; Regulations, r. 99.)

A personal-data breach may create a separate notification duty. Under section 43 of the Data Protection Act, unauthorized access or acquisition plus a real risk of harm triggers the controller's notice to the Data Commissioner without delay and within seventy-two hours of awareness. A processor must notify its controller without delay and, where reasonably practicable, within forty-eight hours. Those triggers and recipients differ from the VASP regulator's twenty-four-hour duty. Compliance with one notice does not establish compliance with the others; the operative data-protection version must be confirmed for an actual incident. (Data Protection Act, 2019, s. 43; Regulations, r. 99.)

Financial returns, insurance and customer complaints

The reporting calendar contains overlapping general and activity-specific returns. Regulation 26 requires monthly operational reports by the tenth day of the following month. Regulation 92 requires quarterly financial returns by the tenth day of the calendar month following the end of the quarter. It also requires monthly capital-adequacy or liquidity reports and annual audited accounts within three months of year-end. Regulation 95 fixes the financial year at twelve months ending on 31 December. A single annual accounts submission cannot satisfy the monthly and quarterly duties. (Regulations, rr. 26 and 92–95.)

Wallet reconciliation returns, exchange reports and stablecoin returns add separate requirements. Stablecoin issuers submit monthly information by the tenth day of the following month and daily reconciliation reports. Managers submit quarterly and half-yearly assets-under-management returns within fifteen days, and annual audited assets-under-management statements within three months. The licensee needs a recipient, trigger and deadline for each return, rather than one undifferentiated compliance date. (Regulations, rr. 66(1)(d), 84 and 93–94.)

The external auditor requires regulatory approval and must belong in good standing to the Institute of Certified Public Accountants of Kenya. Appointment is annual, with a maximum of four consecutive financial years. A qualification caused by uncertainty over the completeness or accuracy of accounting records triggers a separate reporting duty. The auditor must notify the regulator and licensee as soon as practicable, and within seven days. That specific trigger cannot be replaced with the ordinary annual filing timetable. (Regulations, rr. 90–91.)

Insurance must match the risks and scale of the service and address cybersecurity, theft, key loss and operational failure. A provider that cannot obtain the required cover must demonstrate that it exhausted the available means and seek approval for an alternative. A group policy must expressly identify the licensee and its coverage. Foreign insurance requires the specified regulatory approval in consultation with the Insurance Regulatory Authority. Neither group membership nor an unsuccessful insurance enquiry is itself an exemption. (Regulations, r. 88.)

Complaints procedures must specify responsibility, remedies and appeal arrangements. They must set a timeframe no longer than twenty-one days for informing the complainant of progress. The twenty-one-day provision concerns informing the complainant of progress; it is not a universal deadline for final resolution. Records of complaints and action taken must be retained for at least seven years. Although the consumer care system must be established within six months after service commencement, an interim complaint mechanism is required from the outset. (Regulations, rr. 110–111.)

Trading conduct, advice and promotional responsibility

A licensee must deal fairly, assess suitability where required and give customers the prescribed information before providing services. Customer orders receive priority over proprietary trading in the same virtual asset, and transaction confirmations must be issued by the prescribed next-trading-day deadline. Managers must use a custodian licensed in Kenya and obtain approval to exceed the 10% related-company investment limit. These duties constrain vertically integrated business models even where multiple activities are licensed. (Regulations, rr. 24–25, 30, 34–37 and 87.)

The market-conduct offences address insider dealing, manipulation, false trading, misleading inducements, fraudulent devices, front-running and churning. Each offence requires the conduct and mental element specified in its provision. An unusual price movement alone does not establish every element of manipulation. Cold calling also carries identification, timing and do-not-call restrictions. Automated execution or an overseas marketing contractor does not remove responsibility for conduct within the applicable provision. (Regulations, rr. 114–122.)

A licensee cannot promise investment returns and must present advertisements fairly with the prescribed risk, fee and identity information. Historical performance and projections face separate requirements. Paid promoters must disclose the commercial relationship and compensation, while the licensee remains responsible for advertisements made on its behalf. A contractual indemnity from an influencer does not remove that public-law responsibility. (Regulations, rr. 109 and 123–130.)

Online advertisements must preserve accessible risk information, usable copies and the prescribed dating. Regulation 132 prohibits practices that obscure warnings through placement, font, scrolling or linked pages. Advertisement records must identify who approved the material and when, and remain available for at least seven years after it ceases to be available to customers. The retention clock therefore differs from the date-of-transaction clock for financial records. (Regulations, rr. 131–133.)

Freezing orders, enforcement and exit

The Regulations apply the procedures and evidentiary requirements of the relevant proceeds-of-crime or other recovery law to freezing and seizure. They do not make every regulatory request an asset-confiscation order. A served freezing order requires immediate restraint of the specified assets and preservation of records. A seizure order can require transfer of control and access to relevant wallets and devices. Conversion of seized assets to fiat to preserve value requires approval of the competent court. (Regulations, rr. 134–139.)

Orders must target specified customer accounts or assets and permit clarification or variation where uninvolved customers would be affected. An omnibus arrangement makes that protection operationally demanding, but does not eliminate it. The licensee should use its entitlement records to identify the affected holdings and seek the available clarification without disregarding the order. Failure to comply is an offence under regulation 141. (Regulations, rr. 66, 107 and 140–141.)

The applicable sanction depends on the breached provision. Regulation 142 imposes administrative maxima of KES 3 million for an individual and KES 5 million for a company for the listed contraventions. It also permits suspension, revocation and remedial directions. Section 39(2)(f) of the Act separately prescribes maxima of KES 3 million and KES 10 million for its specified breaches. The lower regulatory company maximum cannot be presented as a universal ceiling for enforcement under the Act. (Act, s. 39; Regulations, rr. 142 and 144.)

Regulation 143's listed offences carry, on conviction, a maximum individual fine of KES 5 million, imprisonment up to five years, or both; the corporate maximum is KES 8 million. Unlicensed business and the other offences assigned to section 40(3) instead carry maximum individual exposure of KES 10 million, five years, or both, and KES 25 million for a company. Section 40(1) separately addresses prohibited ownership changes. Corporate-officer liability under section 41 requires knowing authorization, permission or assistance in the commission of the offence. These provisions do not make every director automatically criminally liable for every company breach. (Act, ss. 8(3), 27(5), 40–41; Regulations, r. 143.)

The Act requires written reasons in specified decisions and provides an appeal to a competent body established by written law. Regulation 151 refers back to that route. Neither provision creates one universal VASP appellate tribunal or states a common appeal period. The forum, deadline, exhaustion requirement and any interim relief must be established for the actual decision. The appeal provision alone does not state that enforcement is automatically stayed. (Act, ss. 10(4), 12(4), 15, 26(6) and 43; Regulations, r. 151.)

Regulation 46 permits intervention on its specified grounds. Following licence suspension or revocation, regulation 47 permits appointment of a statutory manager by Gazette notice. The initial term cannot exceed twelve months; a court-approved extension cannot exceed twelve months. A licensee seeking voluntary surrender must meet section 16, including the required customer-asset and liability arrangements. Insolvent voluntary liquidation requires regulatory approval under regulation 149, subject to the Insolvency Act. A private liquidation applicant must serve the regulator, which may participate in the proceedings. Customer recovery therefore depends on identifying protected assets, actual shortfalls and the applicable process before distributing the estate. (Act, s. 16; Regulations, rr. 46–48 and 149–150.)

Illia Prokopiev

Written by

Illia Prokopiev

Co-Founder and CEO

Illia is the Managing Partner and founder of Licentium. With over 11 years of practice, he has guided innovators through cross-border M&A deals and the disputes that follow, combining transactional skill with courtroom resolve. Admitted to the bar in 2017, he pivoted early to Web3, serving as legal advisor to prominent crypto projects and carrying AML/MLRO duties that anchored complex token, DAO, and compliance questions on solid regulatory ground. Certified in money laundering prevention and an active crypto investor, Illia blends market intuition with a global network of specialists, enabling Licentium to untangle licensing knots for crypto and AI ventures anywhere in the world.