About
Corporate & Business Law
Real Estate & Conveyancing
Technology, Fintech & Digital Assets
Private Client & Estate Planning
Insights Legal Templates Capabilities & Approach Our People Contact Book a Consultation
Fintech, Crypto & Technology Law

Kenya VASP AML/CFT/CPF Compliance Checklist

AML/CFT/CPF compliance sits at the centre of VASP licensing and ongoing supervision. Here is a practical checklist of what a programme should cover.

Njau & Associates Advocates/Published 2026-08-17/Reviewed 2026-08-17/8 min read

Virtual asset businesses are treated as reporting institutions under Kenya's anti-money laundering framework, and the VASP Regulations layer sector-specific expectations on top of the Proceeds of Crime and Anti-Money Laundering Act (POCAMLA). A credible AML/CFT/CPF programme is both a licensing precondition and an ongoing supervisory expectation.

Enterprise-wide risk assessment

A programme should start with a documented assessment of the money laundering, terrorism financing and proliferation financing risks specific to the business, its customer base, geographic exposure, product features and transaction types, rather than a generic template borrowed from an unrelated sector.

Customer due diligence and beneficial ownership

  • Identity verification proportionate to risk, at onboarding and on an ongoing basis
  • Enhanced due diligence for politically exposed persons and higher-risk jurisdictions
  • Beneficial ownership identification where customers are corporate entities or structures

Sanctions screening

Customers and, where relevant, counterparties and wallet addresses should be screened against applicable sanctions lists, with a documented process for handling and escalating potential matches.

Transaction monitoring

Monitoring should be calibrated to the specific transaction patterns of a virtual asset business, unusually structured transactions, rapid movement between multiple wallets, or patterns consistent with layering, rather than relying solely on monitoring tools designed for traditional banking transactions.

Suspicious transaction reporting

Where red flags are identified, businesses should have a clear internal escalation path leading to timely reporting to the Financial Reporting Centre, supported by staff training on what constitutes a reportable transaction.

The Travel Rule

Where applicable under the Kenyan framework, originator and beneficiary information should travel with virtual asset transfers between institutions, consistent with international standards on this point. The specific mechanics and thresholds should be confirmed against current CBK and CMA guidance, since implementation approaches continue to be refined internationally.

Governance of the compliance function

  • A designated compliance officer with appropriate seniority and independence
  • Board-level oversight of the AML/CFT/CPF programme, not delegation without review
  • Regular staff training tailored to virtual asset red flags
  • Periodic independent review or audit of the programme's effectiveness

Record-keeping

Records should be sufficient to reconstruct the full transaction history and due diligence trail of any customer relationship, retained for the period required under POCAMLA and the VASP Regulations.

Distinguishing statutory requirements from good practice

Not every item on this checklist is spelled out as a rigid statutory minimum for every licence category; some reflect recommended implementation practice consistent with the statutory risk-based approach. Confirm the specific mandatory requirements applicable to your licence category against the current POCAMLA framework and VASP Regulations, and treat the rest as the standard a well-run compliance function should meet regardless.

Need to test your AML/CFT/CPF framework against VASP requirements?

We review or build your risk assessment, KYC/CDD and monitoring programme against current expectations.

Request a Compliance Readiness Review

Key legal & regulatory sources

  • Kenya Law — Virtual Asset Service Providers Act, 2025 (Act No. 20 of 2025)
  • Kenya Law — Virtual Asset Service Providers Regulations, 2026 (Legal Notice No. 134 of 2026)
  • Central Bank of Kenya and Capital Markets Authority public guidance on VASP licensing

Frequently asked questions

Does a small VASP startup need a full-time compliance officer?

Requirements scale with the size and risk profile of the business, but every licensee should have a clearly designated person accountable for AML/CFT/CPF compliance, with board oversight, even where that role is combined with other responsibilities at an early stage.

Is the Travel Rule mandatory for Kenyan VASPs?

Kenya's framework is expected to reflect international standards on this point, but the specific mechanics and thresholds should be confirmed against current CBK and CMA guidance rather than assumed from international practice alone.

What triggers enhanced due diligence?

Common triggers include politically exposed person status, customers or transactions connected to higher-risk jurisdictions, unusually large or complex transactions, and patterns inconsistent with a customer's stated profile or activity.

Related insights

The information on this website is general in nature, is not legal advice, and does not create an advocate-client relationship. Figures, fees, capital thresholds and procedural requirements under the Virtual Asset Service Providers Act, 2025 and the Virtual Asset Service Providers Regulations, 2026 should be confirmed against the current Gazette text and regulator guidance before action is taken. Please contact Njau & Associates Advocates for advice on your specific circumstances.