Banking & Finance8 min read

Banking Regulation in Kenya: What the CBK Expects From Licensed Institutions

CBK enforcement has shifted from capital to governance and AML. Institutions still resourcing for the old priorities are exposed.

Gracen Law Advocates

Corporate & commercial counsel, Westlands, Nairobi

The short answer

Central Bank of Kenya enforcement has shifted from capital adequacy toward governance and anti-money-laundering compliance. Institutions still resourcing primarily for prudential ratios are exposed. The failures regulators cite most are not policy gaps but the distance between documented policy and what staff actually do day to day.

A bank can be comfortably capitalised and still be the subject of enforcement. The Central Bank's supervisory attention has moved, and institutions that built their compliance function around capital ratios are defending yesterday's examination.

This article covers what CBK actually supervises, where enforcement concentrates, and what a defensible compliance programme looks like in practice.

Who regulates what

The Central Bank of Kenya licenses and supervises banks, mortgage finance companies, microfinance banks, forex bureaux, payment service providers and, since the framework was extended, digital credit providers.

The Capital Markets Authority regulates securities, fund managers, investment banks and collective investment schemes. The Insurance Regulatory Authority covers insurers and intermediaries. SASRA supervises deposit-taking SACCOs. The Financial Reporting Centre receives suspicious transaction reports under the anti-money-laundering framework.

Overlap is common. A fintech offering payments, credit and an investment product may sit under three regulators simultaneously, each with its own licence, capital requirement and reporting cycle. Mapping the perimeter before launch is materially cheaper than retro-fitting authorisations.

Licensing and what it requires

A banking licence requires minimum core capital, fit and proper assessment of significant shareholders, directors and senior management, a business plan with financial projections, governance and risk management frameworks, and demonstrated systems capability.

The fit and proper assessment extends beyond the applicant institution to ultimate beneficial owners. Structures designed to obscure who ultimately controls an institution do not clear this stage, and attempting it damages the application.

Changes after licensing also require approval: significant shareholding changes, appointments of directors and senior officers, and material changes to the business model. A change of control completed before approval is a regulatory breach regardless of its commercial merits.

Where enforcement actually concentrates

Governance

Board composition and independence, the functioning of board committees, the quality of board oversight, and whether directors are genuinely exercising judgement or ratifying management decisions. Examiners read minutes, and minutes that record only resolutions without reasoning evidence nothing.

Anti-money-laundering

Customer due diligence, enhanced due diligence for higher-risk relationships, beneficial ownership identification, transaction monitoring, sanctions screening, and suspicious transaction reporting to the Financial Reporting Centre.

This is where most enforcement now sits. And the finding is rarely that the policy is inadequate — it is that the policy is not being followed. Files without the documentation the policy requires, alerts closed without investigation, screening not run at the frequency prescribed.

Consumer protection

Disclosure of terms, presentation of interest and charges, complaints handling, and debt collection practices. Digital lending drew significant attention here, and the conduct expectations now extend across the sector.

Data protection

Financial institutions hold sensitive personal data at scale, bringing the Office of the Data Protection Commissioner into scope alongside the financial regulator. Our regulatory compliance practice treats these as a single programme rather than two, because the underlying controls overlap substantially.

Directors' exposure

Directors of financial institutions carry obligations beyond the Companies Act duties.

They must satisfy fit and proper requirements on an ongoing basis, not only at appointment. They can be removed by the regulator, disqualified from holding office in a licensed institution, and held personally responsible for regulatory breaches.

The practical protection is the same as it is elsewhere but matters more here: contemporaneous minutes recording the factors considered, declared interests, independent advice on significant transactions, and a board that receives positive assurance on compliance rather than inferring it from silence.

Anti-money-laundering: building something that survives inspection

Five elements, and the gap between them and daily practice is what examiners look for.

Risk assessment. A documented assessment of the institution's exposure by customer type, product, channel and geography, reviewed periodically and actually used to allocate resource.

Customer due diligence. Identification and verification at onboarding, with enhanced measures for politically exposed persons, complex ownership structures and higher-risk jurisdictions. Beneficial ownership traced to natural persons rather than stopped at the first corporate layer.

Ongoing monitoring. Transaction monitoring calibrated to the risk assessment, with alerts investigated and the investigation documented. An alert closed with no recorded rationale is a finding.

Reporting. Suspicious transaction reports filed with the FRC within the required timeframe. Tipping off the customer is an offence.

Training and record-keeping. Staff trained at appropriate intervals with attendance recorded, and records retained for the statutory period.

Lending: the documentation that decides recovery

Regulatory compliance and commercial protection meet in the security package.

Facility documentation should be complete before drawdown, with conditions precedent satisfied rather than waived on the expectation they will follow. Security must be registered within the statutory period — an unregistered charge is void against a liquidator, leaving the institution unsecured while the debt survives.

Enforcement of a charge over land requires the statutory notices under the Land Act, strictly observed. Sales conducted without valid notice are set aside, and the institution bears that cost. Our banking, finance and fintech practice treats registration as a named completion item with a diarised deadline, because it is the failure with the largest consequence.

Digital lending and fintech

Bringing digital credit providers within CBK licensing changed the market substantially. Providers now require authorisation, and the conditions address pricing disclosure, debt collection conduct, and the use of customer data.

Payment service providers require licensing under the National Payment System framework, with customer funds held in trust and segregated from the operator's own balance sheet. That segregation requirement shapes the entire business model and is not negotiable.

Virtual asset service providers now fall within a defined regime as well. Firms that launched before these frameworks and continued unchanged are operating without required authorisation, which is a materially different position from operating in an unregulated space.

Capital, liquidity and the prudential baseline

Supervisory attention has shifted toward conduct and governance, but the prudential requirements have not gone away and remain the licence condition.

Institutions must maintain minimum core capital and prescribed capital adequacy ratios against risk-weighted assets, together with liquidity ratios. Breaches are reportable and attract supervisory action.

Asset classification and provisioning is a recurring area of disagreement between institutions and examiners. Loans must be classified according to prescribed criteria and provisioned accordingly, and examiners frequently reclassify facilities the institution had treated as performing. Where classification is disputed, the institution should be able to evidence the borrower's actual payment behaviour rather than argue from expectation.

Related party exposures carry limits, and lending to directors, significant shareholders and their associates is closely examined. These exposures must be on arm's length terms and within prescribed limits, and breaches here are treated as governance failures rather than technical ones.

Preparing for an examination

Examiners request policies, board and committee minutes, risk assessments, sample customer files, transaction monitoring output, training records, and evidence of prior findings being remediated.

The single most useful preparation is a self-assessment conducted honestly in advance. Institutions that identify their own gaps and can show a remediation plan in progress are treated very differently from those where the examiner finds the gap first.

The second is closing out prior findings. A repeat finding is treated as a governance failure rather than a control failure, and it escalates.

Outsourcing, agents and third-party risk

Financial institutions increasingly deliver services through agents and technology partners, and the regulatory responsibility does not transfer with the function.

Agency banking arrangements make the institution responsible for the agent's conduct in dealing with customers. Agent selection, training, monitoring and the terms of the agency agreement are all supervisory concerns, and failures by agents are treated as failures by the institution.

Technology outsourcing — core banking, cloud hosting, payment processing — requires the institution to retain effective oversight. Contracts should provide audit rights, service levels, data location and return provisions, and a viable exit. An institution that cannot access its own data without the vendor's cooperation has a resilience problem the regulator will identify.

Where personal data is processed by a third party, the Data Protection Act requires a written arrangement governing the processing. This is a statutory requirement rather than good practice.

Recovery and resolution

Institutions are expected to plan for their own stress, not only to avoid it.

Recovery planning identifies the actions available if capital or liquidity deteriorates — capital raising, asset disposals, business line exits — with triggers defined in advance rather than improvised under pressure.

Where an institution fails, CBK has powers including the appointment of a statutory manager, and the Kenya Deposit Insurance Corporation administers depositor protection. Directors should understand that the regulator's powers on intervention are broad and that their own conduct in the period before intervention will be examined.

When enforcement comes

Regulatory action ranges from a letter requiring remediation, through directions and monetary penalties, to restrictions on business, removal of officers, and ultimately licence revocation or statutory management.

The response to an early letter shapes everything that follows. An institution that responds promptly, accepts what is accurate, and presents a credible remediation plan with owners and deadlines is in a materially better position than one that contests findings reflexively.

Where the position is genuinely contestable, contest it — but do so on the specific finding rather than as a posture. If your institution has received regulatory correspondence, take advice before responding rather than after.

Frequently asked questions

What does the Central Bank of Kenya actually supervise?

Banks, mortgage finance companies, microfinance banks, forex bureaux, payment service providers and digital credit providers. Supervisory attention has shifted from capital adequacy toward governance and anti-money-laundering compliance.

What do AML examiners most commonly find in Kenya?

Not inadequate policy, but the distance between policy and practice — customer files missing documentation the policy requires, alerts closed without recorded investigation, and screening not run at the prescribed frequency.

Do digital lenders need a licence in Kenya?

Yes. Digital credit providers now require Central Bank authorisation, with conditions addressing pricing disclosure, debt collection conduct and use of customer data. Firms that launched before the framework and continued unchanged are operating without required authorisation.

Can a director be personally liable for a bank's regulatory breach?

Yes. Directors of financial institutions must satisfy fit and proper requirements on an ongoing basis, can be removed or disqualified by the regulator, and may be held personally responsible for breaches. Contemporaneous board minutes are the principal protection.

What happens if a bank's charge is not registered in time?

It is void against a liquidator and other creditors. The institution becomes an unsecured creditor while the debt survives, which is functionally the same as having taken no security at all. Registration should be a diarised completion item.

Facing this issue now?

A 30-minute consultation with a senior advocate will tell you where you stand and what it will cost to resolve. There is no charge for the first conversation.

This article is general information on Kenyan law and is not legal advice for your situation. Law and practice change; the position stated is as at the date of publication. Speak to an advocate before acting.