Kenya VASP Licensing & Compliance Resource Centre
The central hub for licence categories, CBK/CMA jurisdiction, costs, AML and the transition deadline.
Read insight →Virtual asset businesses are technology businesses first. Regulators assess technology governance as closely as financial governance, because a systems failure is a customer-harm event.
Because virtual assets are bearer instruments at the protocol level, a security failure, a compromised key, an exploited smart contract, a breached admin account, can be irreversible in a way traditional banking incidents often are not. This is why cybersecurity and technology governance sit prominently in the VASP Regulations rather than as an afterthought.
Regulators are likely to expect clear board and senior management accountability for technology risk, not delegation to a technical team without oversight. A documented ICT governance framework should set out who is accountable for systems decisions, security posture and incident response authority.
Applicants and licensees should expect to demonstrate periodic security testing, including penetration testing of externally facing systems, and, where the business relies on smart contracts, independent smart-contract audits before deployment and after material changes. The frequency and scope of testing that regulators expect should be confirmed against the current Regulations and any supplementary guidance for your licence category.
Not every specific control described in this article is necessarily a rigid mandatory minimum spelled out for every licence category; some reflect the standard of implementation that a well-run compliance and technology function should meet under the Regulations' more general risk-based cybersecurity expectations. Confirm the specific mandatory requirements applicable to your licence category directly against the current Regulations.
Where infrastructure, cloud hosting, or key technology functions are outsourced, licensees remain accountable for the security of those functions. Vendor risk assessments, contractual security obligations, and the right to audit critical vendors should be built into outsourcing arrangements from the start.
Licensees should maintain documented business continuity and disaster recovery plans covering system outages, data loss and cyber incidents, tested periodically rather than left as an unexercised document.
A documented incident response plan should address containment, customer communication, and any regulatory notification obligations that arise from a security incident. Where regulatory notification is required, timelines and thresholds should be confirmed against the current Regulations, since prompt, transparent handling of incidents is generally viewed far more favourably by regulators than delayed disclosure.
Preparing your technology and cybersecurity documentation for a licence application? We help structure and review the technology-control evidence regulators expect to see.
Discuss your systems readinessTesting expectations should be confirmed against the current Regulations for your specific licence category; as a matter of good practice, periodic testing of externally facing systems is expected across custodial and exchange-type businesses regardless of the precise statutory minimum.
Where a business relies on smart contracts for customer-facing functions, independent audit before deployment is a strong risk-management practice and is likely to be expected as part of a credible technology governance framework, even where not spelled out as a specific numbered requirement for every category.
A licensee should follow its documented incident response plan, covering containment, customer communication and any applicable regulatory notification. Prompt, transparent handling is generally viewed far more favourably by regulators than delayed disclosure.
The central hub for licence categories, CBK/CMA jurisdiction, costs, AML and the transition deadline.
Read insight →How segregation, records and incident planning protect customer assets.
Read insight →Systems resilience and market integrity obligations for trading venues.
Read insight →The information on this website is general in nature, is not legal advice, and does not create an advocate-client relationship. Figures, fees, capital thresholds and procedural requirements under the Virtual Asset Service Providers Act, 2025 and the Virtual Asset Service Providers Regulations, 2026 should be confirmed against the current Gazette text and regulator guidance before action is taken. Regulatory requirements may also be supplemented by subsequent guidance, notices or licensing requirements issued by the CBK or CMA. Please contact Njau & Associates Advocates for advice on your specific circumstances.