About
Corporate & Business Law
Real Estate & Conveyancing
Technology, Fintech & Digital Assets
Private Client & Estate Planning
Insights Legal Templates Capabilities & Approach Our People Contact Book a Consultation
Fintech, Crypto & Technology Law

The Legal & Regulatory Framework for Capital Raising via Digital Assets in Kenya: A Founder's Guide

Once a tokenisation structure is sound, the next question is how to raise capital on it lawfully. Here is the regulatory map, from CMA and CBK jurisdiction to sandbox testing, SAFTs, SPVs and AML compliance.

Njau & Associates Advocates/Published 6 August 2026/Reviewed 6 August 2026/10 min read

Our companion piece, Real-World Asset Tokenisation in Kenya: Legal Questions Founders Should Resolve, set out the questions founders must answer before a token can represent a sound legal right. This piece picks up where that one leaves off: once the structure is right, how do you lawfully raise capital on it? Digital asset regulation in Kenya is still developing, but that does not mean a founder can proceed without a compliance plan. It means the plan has to be built with more care, not less.

Why legal foundations come before the raise

Raising capital through digital assets, whether a security token offering, a SAFT-based pre-sale, or a tokenised real estate fund, is still, in law, an offer to investors. The label "token sale" does not change that. Kenyan regulators assess substance over form: what the instrument does, who it is offered to, and what promises are made, not what it is called in a whitepaper. Founders who treat fintech fundraising compliance as an afterthought risk rescission claims, regulatory enforcement, or a raise that cannot be closed at all once counsel or investors flag the gaps. Getting the legal structure right before the first dollar is accepted is materially cheaper than fixing it afterward.

The regulatory landscape and jurisdiction

Three Kenyan regulators have overlapping and distinct interests in a digital asset capital raise. Understanding which one is engaged, and often more than one will be, is the starting point for any compliance plan.

Capital Markets Authority (CMA)

The CMA administers the Capital Markets Act and has direct jurisdiction wherever a token or arrangement functions as a security. This includes public offers of securities, collective investment schemes, and any arrangement where investors contribute money to a common enterprise with an expectation of profit derived from the efforts of others. The CMA has also been the most active Kenyan regulator in engaging with digital assets, including through its regulatory sandbox, and its public statements and policy work are the most direct source of guidance on digital asset regulation in Kenya for anything with investment characteristics.

Central Bank of Kenya (CBK)

The CBK's jurisdiction centres on payments, foreign exchange and the banking system rather than on securities as such. A digital asset raise engages the CBK where it touches virtual asset service provision, where proceeds move cross-border, or where the token or platform functions as a payment instrument or facilitates remittances. Founders accepting foreign currency from international investors, or building any settlement rail alongside the raise, should map their flows against CBK's foreign exchange and payment system rules before launch, not after funds have moved.

Office of the Data Protection Commissioner (ODPC)

Any capital raise that collects investor identity information, and KYC obligations mean it will, processes personal data under the Data Protection Act, 2019. Where identity or KYC records are anchored on a blockchain, founders face a structural tension: distributed ledgers are typically immutable, while the Act contemplates correction and, in some circumstances, deletion of personal data. Well-designed platforms keep personal data off-chain, storing only hashes or references on-chain, and register with the ODPC as a data controller and, where applicable, processor before onboarding a single investor.

Security tokens vs. utility tokens under Kenyan law

Kenyan law has no bespoke statute naming "security tokens" or "utility tokens," so the analysis proceeds by applying existing tests to the token's actual features. The Capital Markets Act's definition of a security is broad and substance-driven: instruments creating or acknowledging indebtedness, shares, and interests in collective investment schemes are all captured, and Kenyan courts and regulators generally look past form to economic substance, in a manner consistent with the reasoning of the well-known Howey investment-contract test used in other common-law and US jurisprudence.

The practical triggers that push a token sale toward regulated territory include:

  • Profit expectation from others' efforts. If buyers are told, or reasonably understand, that the token's value will rise because the founding team will build, manage or promote something, that is the hallmark of an investment contract.
  • Revenue or profit-sharing rights. A token entitling holders to a share of protocol fees, rental income, or company profits looks like a share or debenture in substance.
  • Governance rights tied to an enterprise. Voting or control rights over a common enterprise strengthen the case that the token is a security-like interest.
  • Marketing as an investment. Whitepapers, pitch decks and social media that emphasise price appreciation, "returns," or comparisons to shares are strong evidence of investment character, whatever the token is called internally.

By contrast, a token that only grants access to a working product or service, is priced and used at consumption value rather than speculated on, and carries no profit-sharing or governance rights over an enterprise, is a stronger case for utility classification. Founders should not rely on a self-serving label; the safer approach is to have counsel test the token's actual rights and marketing against the public-offer and collective-investment-scheme definitions before launch.

Navigating the CMA Regulatory Sandbox

For founders building a genuinely novel fundraising mechanism, one that does not map cleanly onto an existing licence category, the CMA Regulatory Sandbox is the most practical route to test the model with regulatory visibility rather than in the dark.

A practical roadmap

  1. Pre-application scoping. Confirm the innovation is genuinely novel and would otherwise fall outside, or ambiguously within, existing CMA licensing categories. The sandbox is for testing genuine innovation, not for avoiding licensing that clearly applies.
  2. Application and documentation. Submit a detailed application setting out the product, target investors, technology architecture, risk controls, and an explicit test plan with defined success and exit criteria.
  3. Suitability and risk assessment. The CMA assesses the applicant's governance, financial soundness, technical capability and consumer-protection safeguards before admission.
  4. Live testing under restricted parameters. Approved participants test with defined limits on investor numbers, transaction values and testing duration, under close CMA supervision.
  5. Exit and transition. At the end of the testing period, the founder must transition to full licensing if the model is to continue, wind down the test, or seek an extension; there is no indefinite sandbox status.

Common pitfalls

  • Treating sandbox admission as a substitute for a licence rather than a time-boxed test.
  • Under-specifying investor protection and exit safeguards in the test plan.
  • Failing to plan the post-sandbox compliance pathway before the testing window closes.
  • Exceeding the approved investor or transaction limits during live testing.

Legal instruments and structuring for founder capital raises

Once the regulatory posture is clear, founders need contractual instruments that both work commercially and hold up to regulatory scrutiny.

SAFTs vs. SAFEs with token warrants

A SAFT agreement in Kenya law functions as a contract under which an investor pays now for a right to receive tokens once a network is functional. It is a familiar structure from other markets, but founders should note that if the token to be delivered is itself a security, the SAFT may be characterised as an offer of that security at signing, not merely at delivery, which brings CMA rules forward in time. An alternative structure pairs a standard SAFE (Simple Agreement for Future Equity) with a separate token warrant, giving the investor equity in the issuing company plus a contractual right to tokens if and when they are issued. This can be cleaner where the founder wants the primary instrument tested against well-understood equity law, with the token right layered on as a secondary benefit rather than the main promise.

Special Purpose Vehicles under the Companies Act, 2015

Most tokenised raises are best run through a dedicated SPV incorporated under the Companies Act, 2015, rather than directly through an operating company. The SPV isolates the fundraising vehicle and its liabilities from the founders' operating business, gives investors a single, defined legal counterparty, and simplifies the cap table if tokens or equity later need to be restructured. Directors of the SPV owe standard fiduciary and statutory duties, and the SPV's constitutional documents should expressly address token-related rights, since the Companies Act itself does not.

Enforceable off-chain governance and investor rights

Smart contracts can automate a token's technical behaviour, but they cannot, by themselves, create legally enforceable rights in Kenya. Investor protections, information rights, anti-dilution, liquidation preference, dispute resolution and governing law, need to sit in a conventional off-chain agreement (a shareholders' or token holders' agreement) that a Kenyan court can actually enforce. Treat the smart contract as the mechanism and the written agreement as the source of the legal right.

AML/CFT and cross-border compliance

The Proceeds of Crime and Anti-Money Laundering Act (POCAMLA) applies to reporting institutions handling investor funds, and a digital asset issuer accepting investment should assume it needs a KYC/AML programme even absent a bespoke virtual-asset licensing regime. In practice this means:

  • Customer due diligence. Verified identity for every investor, with enhanced due diligence for politically exposed persons and higher-risk jurisdictions.
  • Source-of-funds checks proportionate to investment size, documented and retained.
  • Suspicious transaction reporting to the Financial Reporting Centre where red flags arise.
  • Record-keeping sufficient to reconstruct the transaction history of each investor relationship.

Cross-border participation adds two further layers. First, foreign exchange: inbound investment in foreign currency should be routed and reported consistently with CBK foreign exchange rules, and founders should confirm banking or payment partners can lawfully receive and convert those funds. Second, extraterritorial exposure: an investor based in the United States, the European Union or another jurisdiction with its own securities laws may bring that jurisdiction's rules into the transaction regardless of where the issuer is incorporated. A Kenya-compliant raise is not automatically compliant elsewhere; founders soliciting non-Kenyan investors should confirm the offer is structured to fit an applicable exemption in the investor's home jurisdiction too.

Practical founder checklist

Before accepting a single investor's funds, founders should be able to answer yes to each of the following:

  • Characterisation. Counsel has tested the token against the security/utility distinction, based on actual rights and marketing, not internal labelling.
  • Regulatory pathway. The raise proceeds either under a valid exemption, full CMA authorisation, or approved sandbox testing, and the choice is documented.
  • Structure. An SPV is incorporated, its constitutional documents address token rights, and the instrument (SAFT, or SAFE plus token warrant) is drafted and reviewed.
  • Governance documentation. Off-chain investor rights and governance agreements are in place and enforceable, independent of the smart contract.
  • AML/KYC programme. Customer due diligence, source-of-funds checks and suspicious transaction reporting procedures are operational before onboarding begins.
  • Cross-border check. Foreign exchange handling is confirmed with banking partners, and non-Kenyan investors are screened against their home jurisdiction's securities rules.

Conclusion

Kenya's regulatory treatment of digital assets will keep evolving, and founders who wait for a finished rulebook will be waiting some time. The more reliable approach is to build on the regulatory principles that already exist, capital markets law, banking and payments law, data protection and AML law, and to structure the raise so it can adapt as specific digital asset rules mature. A capital raise built on sound legal foundations from the outset is far easier to defend, to close, and to scale than one retrofitted for compliance after investors are already in. We advise founders, fund managers and developers on structuring digital asset capital raises in Kenya, from initial characterisation through sandbox applications and closing documentation. Contact Njau & Associates Advocates to discuss your fundraising structure.

Frequently asked questions

Is a Security Token Offering (STO) legal in Kenya?

There is no bespoke STO licence in Kenya, but that does not place STOs outside the law. If a token carries investment characteristics, such as profit-sharing, equity-like rights or a claim on an enterprise, it can fall within the definition of a security under the Capital Markets Act, triggering the same public-offer, disclosure and licensing obligations that apply to conventional securities.

Do I need CMA approval before selling tokens to Kenyan investors?

If the token is structured as a security or investment, a public offer generally requires either CMA authorisation and an approved information memorandum, or a valid private-placement exemption with a limited, defined investor pool. Testing the product first inside the CMA Regulatory Sandbox is the more common route for genuinely novel structures.

Is a SAFT enforceable under Kenyan law?

A SAFT is a contract, and Kenyan contract law will generally enforce its terms. The harder question is regulatory characterisation: if the future token is itself a security, the SAFT that promises to deliver it may be treated as an offer of that security, bringing CMA rules into play at the SAFT stage rather than only at token delivery.

Sources and further reading

  • Kenya Law, the official source of Kenyan legislation and case law (kenyalaw.org), including the Capital Markets Act, the Companies Act, 2015, the Data Protection Act, 2019, and POCAMLA.
  • Capital Markets Authority guidance and public statements on the CMA Regulatory Sandbox, which should be reviewed in their current form.
  • Central Bank of Kenya guidance on foreign exchange and payment system oversight relevant to cross-border investor flows.

The information on this website is general in nature, is not legal advice, and does not create an advocate-client relationship. It should not be relied upon for any specific matter. Requirements may change and should be confirmed against the current law, regulations and regulator guidance before action is taken. Please contact Njau & Associates Advocates for advice on your circumstances.