About
Corporate & Business Law
Real Estate & Conveyancing
Technology, Fintech & Digital Assets
Private Client & Estate Planning
Insights Legal Templates Capabilities & Approach Our People Contact Book a Consultation
Fintech, Crypto & Technology Law

Customer Asset Segregation & Custody Rules for VASPs in Kenya

Custody is where a VASP's governance either proves itself or fails. Here is what segregation, records and incident planning should look like in practice.

Njau & Associates Advocates/Published 2026-08-17/Reviewed 2026-08-17/8 min read

Any business holding customer virtual assets, an exchange, a custodial wallet provider, or an asset manager with client custody, sits at the centre of the framework's consumer-protection concerns. Segregation and custody practice is one of the areas regulators are likely to scrutinise most closely, because failures here directly harm customers.

The core principle: legal ownership stays with the customer

Customer virtual assets held by a licensee should be legally and operationally distinct from the licensee's own assets. This means the licensee's own creditors should have no claim on customer assets if the licensee becomes insolvent, and customer holdings should be clearly identifiable and reconstructable at any point in time.

Segregation in practice

  • Separate wallets or accounts for customer assets versus the licensee's operating assets, with documented wallet architecture.
  • Individual vs omnibus arrangements. Whether customer assets are held in individually attributed wallets or a pooled ("omnibus") wallet with internal ledger records, the internal records must reliably attribute each customer's entitlement.
  • Independent custodians. Using a third-party custodian independent of the licensee's own operations can strengthen protection, though the licensee remains responsible for oversight of that custodian.

Records and reconciliation

Licensees should maintain records sufficient to show, at any time, exactly which customer owns which assets, and should reconcile internal records against actual on-chain holdings on a regular, documented basis. Discrepancies should trigger a defined investigation and escalation process, not be carried forward unresolved.

Customer statements and transparency

Customers should receive regular, accurate statements of their holdings, and should be able to request an up-to-date position on demand. Ambiguity about what a customer actually holds, particularly during periods of market stress, undermines trust and invites regulatory scrutiny.

Custody agreements and outsourcing

Where custody is outsourced to a third party, whether a specialist custodian or an affiliate, the arrangement should be documented in a custody agreement addressing liability, sub-custody restrictions, audit rights and termination arrangements, consistent with the outsourcing expectations under the Regulations generally.

Insolvency and incident planning

A licensee should be able to answer clearly: what happens to customer assets if the business fails? Robust segregation, independent custody, and a documented wind-down plan all improve the answer. Licensees should also have a documented incident response plan addressing loss or theft of customer assets, including customer notification obligations and any regulatory reporting triggers.

Common custody mistakes

  • Commingling customer and operating funds in the same wallet without clear internal attribution
  • No regular reconciliation between internal records and actual on-chain balances
  • Outsourcing custody without a documented agreement addressing liability and audit rights
  • No tested incident response plan for asset loss or theft

Mid-article CTA

Building or reviewing your custody architecture? We help structure segregation, custody agreements and asset-protection arrangements that hold up to regulatory review.

Discuss your custody structure

Frequently asked questions

Is an omnibus wallet arrangement acceptable for customer assets?

Pooled wallet arrangements can be acceptable provided internal records reliably and verifiably attribute each customer's entitlement at all times; the key requirement is accurate attribution and reconciliation, not the specific wallet architecture chosen.

Who is responsible if a third-party custodian loses customer assets?

This depends on the terms of the custody agreement between the licensee and the custodian, but the licensee generally remains responsible to its own customers regardless of what recourse it separately has against the custodian, making custodian selection and contract terms important.

Must customer assets be held in Kenya?

Location requirements for customer assets should be confirmed against the current Regulations for the specific licence category; this should not be assumed either way without checking the applicable rules.

Key legal sources

  • Kenya Law — Virtual Asset Service Providers Act, 2025 (Act No. 20 of 2025)
  • Kenya Law — Virtual Asset Service Providers Regulations, 2026 (Legal Notice No. 134 of 2026)
  • Central Bank of Kenya and Capital Markets Authority public guidance on VASP licensing

Related insights

The information on this website is general in nature, is not legal advice, and does not create an advocate-client relationship. Figures, fees, capital thresholds and procedural requirements under the Virtual Asset Service Providers Act, 2025 and the Virtual Asset Service Providers Regulations, 2026 should be confirmed against the current Gazette text and regulator guidance before action is taken. Regulatory requirements may also be supplemented by subsequent guidance, notices or licensing requirements issued by the CBK or CMA. Please contact Njau & Associates Advocates for advice on your specific circumstances.