About
Corporate & Business Law
Real Estate & Conveyancing
Technology, Fintech & Digital Assets
Private Client & Estate Planning
Insights Legal Templates Capabilities & Approach Our People Contact Book a Consultation
Fintech, Crypto & Technology Law

VASP Licence Application Documents in Kenya: Complete Readiness Checklist

A VASP application is a substantial document set, not a form. Here is what to assemble before you submit, organised the way a regulator will actually review it.

Njau & Associates Advocates/Published 2026-08-17/Reviewed 2026-08-17/8 min read

The Virtual Asset Service Providers Regulations, 2026 require a structured application file covering ownership, governance, financial standing, and operational and risk controls. Assembling this file well before submission, rather than reactively during a regulator query cycle, is the single biggest determinant of a smooth process. The categories below are organisational; the precise documents required for your business depend on your licence category and should be confirmed against the current Regulations.

Corporate and ownership documents

  • Certificate of incorporation and constitutional documents
  • Shareholding structure and beneficial ownership records
  • Group structure chart, where the applicant sits within a wider corporate group

Directors and senior officers

  • Fit-and-proper documentation for directors and senior management
  • CVs and evidence of relevant experience
  • Declarations addressing character, competence and any prior regulatory or criminal history matters

Business plan and financial information

  • A business plan describing the product, target market and operating model
  • Financial statements or opening financial position statements
  • Evidence of source of funds and of paid-up and liquid capital

Governance and risk framework

  • Governance framework and board committee structure, where applicable
  • Enterprise risk-management policy
  • AML/CFT/CPF policy, including customer due diligence and enhanced due diligence procedures

Technology and operational controls

  • Cybersecurity and IT governance policies
  • Business continuity and disaster recovery arrangements
  • Details of material outsourcing arrangements and third-party vendors

Customer-facing documentation

  • Complaints handling policy
  • Customer terms, disclosures and risk warnings
  • Custody and asset-segregation arrangements, where the business holds customer assets

Category-specific documentation

Depending on licence category, additional documents may be required, for example platform or business rules for an exchange, or offering documentation and a white paper for a token issuance or stablecoin business. This list is a practical starting point rather than an exhaustive statement of what the current Regulations require for every category; the precise document set should be confirmed for your specific licence category before finalising an application.

How to sequence the work

Most delays we see come from businesses drafting the AML/CFT and governance documents only once the regulator asks for them. Building this document set alongside the core product, rather than after launch, means the application can move at the pace of the regulator's review rather than the pace of your own document drafting.

The regulation 6(2) document list, in full

Regulation 6(2) of the Virtual Asset Service Providers Regulations, 2026 lists the specific items an application must be accompanied by. Reproduced and organised here, this is the authoritative baseline the categorised checklist above is built from:

  • Personal details, qualifications, experience, business interests and occupation of the applicant's directors, senior officers, significant shareholders and beneficial owners
  • A business plan prepared in accordance with the Third Schedule
  • A duly completed fit-and-proper assessment form under the Fourth Schedule
  • Proof of source of funds
  • A description of the systems and controls of the proposed virtual asset business
  • The operational policies: risk management, AML/CFT/CPF, data protection and privacy, cybersecurity and information technology, complaints management, market conduct, consumer protection, conflict of interest, and a business continuity and disaster recovery plan
  • Copies of contracts and any arrangements for oversight of activities
  • Evidence of paid-up capital and liquid capital at the amount specified in the Fifth Schedule
  • Audited financial statements for the three years prior to the application (or auditor-verified opening financial statements for a newly incorporated applicant)
  • Where the applicant is a subsidiary of a foreign parent, the parent's audited consolidated financial statements for three years
  • Evidence of the human and technology resources required under Regulation 18
  • An independent information systems audit report, including a vulnerability assessment and penetration test
  • Full disclosure of cross-border operations, affiliates, and regulatory status in other jurisdictions
  • For exchanges, token issuance platforms, virtual asset offerings and wallet providers: business rules prepared under Regulation 20
  • Evidence of systems and controls to maintain market integrity, including avoidance of market abuse
  • The class of virtual assets intended to be traded or available for subscription
  • Details of the applicant's principal business address and website
  • A certified copy of the certificate of incorporation
  • Up-to-date director and shareholder details issued by the Registrar of Companies, and a copy of the register of beneficial owners issued by the Registrar of Companies
  • Proof of payment of the application fee specified in the First Schedule

Category-specific additions

Where the licence sought is for virtual asset tokenisation specifically, Regulation 61 requires the application to additionally include the rules of ownership, transferability, compliance and profit distribution (where the tokenisation uses distributed ledger technology), and an independent audit of the systems used in the tokenisation. Where the application also involves an offering of the tokenised asset, Regulation 62 requires a white paper meeting the Regulation 63 disclosure standard, the issuer's governance structure, an independent valuation of the real-world asset's fair market value, disclosure of the underlying technology, evidence of clear title, and the proposed custody arrangements for the underlying asset.

Sequencing the document set

Because Regulation 6(4)'s thirty-day determination clock only starts once all required documents and information are filed and due diligence is complete, treat the independent information systems audit, the auditor-verified financial statements, and the full operational policy suite as long-lead items to commission first, not documents to assemble in the final week before filing.

Assembling your application dossier?

We review draft governance, AML/CFT and risk documentation against what your licence category actually requires.

Request a Document Review

Key legal & regulatory sources

  • Kenya Law — Virtual Asset Service Providers Act, 2025 (Act No. 20 of 2025)
  • Kenya Law — Virtual Asset Service Providers Regulations, 2026 (Legal Notice No. 134 of 2026)
  • Central Bank of Kenya and Capital Markets Authority public guidance on VASP licensing

Frequently asked questions

Is this checklist the exhaustive list of documents the CBK or CMA will require?

No. It reflects the categories of information the Regulations generally require across licence types. The precise document set depends on your specific licence category and should be confirmed against the current Regulations before submission.

Do I need audited financial statements to apply?

Financial information requirements vary by licence category and by whether the applicant is a new or existing business. Confirm the specific financial evidence required for your category before assembling this part of the file.

Can Njau & Associates review documents we have already drafted?

Yes. We regularly review governance, AML/CFT and risk-management documentation prepared internally and align it with regulatory expectations before submission.

Related insights

The information on this website is general in nature, is not legal advice, and does not create an advocate-client relationship. Figures, fees, capital thresholds and procedural requirements under the Virtual Asset Service Providers Act, 2025 and the Virtual Asset Service Providers Regulations, 2026 should be confirmed against the current Gazette text and regulator guidance before action is taken. Please contact Njau & Associates Advocates for advice on your specific circumstances.