Kenya VASP Licensing & Compliance Resource Centre
Licence categories, CBK/CMA jurisdiction, costs, AML and the transition deadline for virtual asset businesses.
Read insight →Once a tokenisation structure is sound, the next question is how to raise capital on it lawfully. Here is the regulatory map, from CMA and CBK jurisdiction to sandbox testing, SAFTs, SPVs and AML compliance.
Our companion piece, Real-World Asset Tokenisation in Kenya: Legal Questions Founders Should Resolve, set out the questions founders must answer before a token can represent a sound legal right. This piece picks up where that one leaves off: once the structure is right, how do you lawfully raise capital on it? Digital asset regulation in Kenya is still developing, but that does not mean a founder can proceed without a compliance plan. It means the plan has to be built with more care, not less.
Raising capital through digital assets, whether a security token offering, a SAFT-based pre-sale, or a tokenised real estate fund, is still, in law, an offer to investors. The label "token sale" does not change that. Kenyan regulators assess substance over form: what the instrument does, who it is offered to, and what promises are made, not what it is called in a whitepaper. Founders who treat fintech fundraising compliance as an afterthought risk rescission claims, regulatory enforcement, or a raise that cannot be closed at all once counsel or investors flag the gaps. Getting the legal structure right before the first dollar is accepted is materially cheaper than fixing it afterward.
Three Kenyan regulators have overlapping and distinct interests in a digital asset capital raise. Understanding which one is engaged, and often more than one will be, is the starting point for any compliance plan.
The CMA administers the Capital Markets Act and has direct jurisdiction wherever a token or arrangement functions as a security. This includes public offers of securities, collective investment schemes, and any arrangement where investors contribute money to a common enterprise with an expectation of profit derived from the efforts of others. The CMA has also been the most active Kenyan regulator in engaging with digital assets, including through its regulatory sandbox, and its public statements and policy work are the most direct source of guidance on digital asset regulation in Kenya for anything with investment characteristics.
The CBK's jurisdiction centres on payments, foreign exchange and the banking system rather than on securities as such. A digital asset raise engages the CBK where it touches virtual asset service provision, where proceeds move cross-border, or where the token or platform functions as a payment instrument or facilitates remittances. Founders accepting foreign currency from international investors, or building any settlement rail alongside the raise, should map their flows against CBK's foreign exchange and payment system rules before launch, not after funds have moved.
Any capital raise that collects investor identity information, and KYC obligations mean it will, processes personal data under the Data Protection Act, 2019. Where identity or KYC records are anchored on a blockchain, founders face a structural tension: distributed ledgers are typically immutable, while the Act contemplates correction and, in some circumstances, deletion of personal data. Well-designed platforms keep personal data off-chain, storing only hashes or references on-chain, and register with the ODPC as a data controller and, where applicable, processor before onboarding a single investor.
Kenyan law has no bespoke statute naming "security tokens" or "utility tokens," so the analysis proceeds by applying existing tests to the token's actual features. The Capital Markets Act's definition of a security is broad and substance-driven: instruments creating or acknowledging indebtedness, shares, and interests in collective investment schemes are all captured, and Kenyan courts and regulators generally look past form to economic substance, in a manner consistent with the reasoning of the well-known Howey investment-contract test used in other common-law and US jurisprudence.
The practical triggers that push a token sale toward regulated territory include:
By contrast, a token that only grants access to a working product or service, is priced and used at consumption value rather than speculated on, and carries no profit-sharing or governance rights over an enterprise, is a stronger case for utility classification. Founders should not rely on a self-serving label; the safer approach is to have counsel test the token's actual rights and marketing against the public-offer and collective-investment-scheme definitions before launch.
For founders building a genuinely novel fundraising mechanism, one that does not map cleanly onto an existing licence category, the CMA Regulatory Sandbox is the most practical route to test the model with regulatory visibility rather than in the dark.
Once the regulatory posture is clear, founders need contractual instruments that both work commercially and hold up to regulatory scrutiny.
A SAFT agreement in Kenya law functions as a contract under which an investor pays now for a right to receive tokens once a network is functional. It is a familiar structure from other markets, but founders should note that if the token to be delivered is itself a security, the SAFT may be characterised as an offer of that security at signing, not merely at delivery, which brings CMA rules forward in time. An alternative structure pairs a standard SAFE (Simple Agreement for Future Equity) with a separate token warrant, giving the investor equity in the issuing company plus a contractual right to tokens if and when they are issued. This can be cleaner where the founder wants the primary instrument tested against well-understood equity law, with the token right layered on as a secondary benefit rather than the main promise.
Most tokenised raises are best run through a dedicated SPV incorporated under the Companies Act, 2015, rather than directly through an operating company. The SPV isolates the fundraising vehicle and its liabilities from the founders' operating business, gives investors a single, defined legal counterparty, and simplifies the cap table if tokens or equity later need to be restructured. Directors of the SPV owe standard fiduciary and statutory duties, and the SPV's constitutional documents should expressly address token-related rights, since the Companies Act itself does not.
Smart contracts can automate a token's technical behaviour, but they cannot, by themselves, create legally enforceable rights in Kenya. Investor protections, information rights, anti-dilution, liquidation preference, dispute resolution and governing law, need to sit in a conventional off-chain agreement (a shareholders' or token holders' agreement) that a Kenyan court can actually enforce. Treat the smart contract as the mechanism and the written agreement as the source of the legal right.
The Proceeds of Crime and Anti-Money Laundering Act (POCAMLA) applies to reporting institutions handling investor funds, and a digital asset issuer accepting investment should assume it needs a KYC/AML programme even absent a bespoke virtual-asset licensing regime. In practice this means:
Cross-border participation adds two further layers. First, foreign exchange: inbound investment in foreign currency should be routed and reported consistently with CBK foreign exchange rules, and founders should confirm banking or payment partners can lawfully receive and convert those funds. Second, extraterritorial exposure: an investor based in the United States, the European Union or another jurisdiction with its own securities laws may bring that jurisdiction's rules into the transaction regardless of where the issuer is incorporated. A Kenya-compliant raise is not automatically compliant elsewhere; founders soliciting non-Kenyan investors should confirm the offer is structured to fit an applicable exemption in the investor's home jurisdiction too.
Before accepting a single investor's funds, founders should be able to answer yes to each of the following:
Kenya's regulatory treatment of digital assets will keep evolving, and founders who wait for a finished rulebook will be waiting some time. The more reliable approach is to build on the regulatory principles that already exist, capital markets law, banking and payments law, data protection and AML law, and to structure the raise so it can adapt as specific digital asset rules mature. A capital raise built on sound legal foundations from the outset is far easier to defend, to close, and to scale than one retrofitted for compliance after investors are already in. We advise founders, fund managers and developers on structuring digital asset capital raises in Kenya, from initial characterisation through sandbox applications and closing documentation. Contact Njau & Associates Advocates to discuss your fundraising structure.
There is no bespoke STO licence in Kenya, but that does not place STOs outside the law. If a token carries investment characteristics, such as profit-sharing, equity-like rights or a claim on an enterprise, it can fall within the definition of a security under the Capital Markets Act, triggering the same public-offer, disclosure and licensing obligations that apply to conventional securities.
If the token is structured as a security or investment, a public offer generally requires either CMA authorisation and an approved information memorandum, or a valid private-placement exemption with a limited, defined investor pool. Testing the product first inside the CMA Regulatory Sandbox is the more common route for genuinely novel structures.
A SAFT is a contract, and Kenyan contract law will generally enforce its terms. The harder question is regulatory characterisation: if the future token is itself a security, the SAFT that promises to deliver it may be treated as an offer of that security, bringing CMA rules into play at the SAFT stage rather than only at token delivery.
The information on this website is general in nature, is not legal advice, and does not create an advocate-client relationship. It should not be relied upon for any specific matter. Requirements may change and should be confirmed against the current law, regulations and regulator guidance before action is taken. Please contact Njau & Associates Advocates for advice on your circumstances.
Licence categories, CBK/CMA jurisdiction, costs, AML and the transition deadline for virtual asset businesses.
Read insight →Before tokenising property or other assets, founders should resolve a set of foundational legal questions. Here is a practical map.
Read insight →A step-by-step approach to data protection compliance for early-stage Kenyan companies, from registration to day-to-day practice.
Read insight →