← ServicesKenya · Financial crime compliance

AML/CFT Compliance Programmes for Fintechs

An AML/CFT programme must reflect the institution’s customers, products, delivery channels, geographies, merchants, counterparties and transaction behaviour. A policy copied from another business will rarely explain how risk decisions are made in the actual system.

Discuss your route
Who this is for

Built around the proposed activity.

Typical work sequence

From legal perimeter to operating evidence.

01

Obligations and risk assessment

Confirm reporting-institution and supervisory status, then assess enterprise, product, customer, geographic, channel and transaction risk.

02

Control design

Develop CDD, EDD, PEP, sanctions, beneficial-ownership, monitoring, escalation, reporting, recordkeeping and training arrangements.

03

Operational integration

Map controls to onboarding screens, data fields, rules, case management, approval authorities, vendors and evidence.

04

Assurance and improvement

Test files and controls, document findings, train accountable teams and establish periodic review and management reporting.

Core readiness areas

What the work normally needs.

  • Documented institutional and customer-risk assessments
  • Governance, MLRO responsibility and independent oversight
  • CDD, EDD, beneficial-ownership, PEP and sanctions procedures
  • Ongoing monitoring, unusual-activity escalation and statutory reporting workflows
  • Recordkeeping, training, compliance testing and management information
  • Technology and vendor controls consistent with the written programme
Common pressure points

Problems to resolve before they become delays.

  1. 01

    Using a generic risk assessment that does not drive onboarding, monitoring or approval decisions

  2. 02

    Collecting documents without verifying ownership, source, purpose and expected activity

  3. 03

    Treating sanctions, PEP and adverse-information screening as a one-time onboarding event

  4. 04

    Writing escalation and reporting procedures that are not reflected in systems, cases, roles and evidence

How the firm assists

A defined mandate, not a generic package.

We provide reporting-institution analysis, AML/CFT and customer-risk assessments, policy suites, onboarding and escalation design, vendor and rule review, board and staff training, compliance testing and remediation support.

Send a non-confidential enquiry
Frequently asked questions

Useful starting answers.

Does every fintech have the same AML/CFT obligations?+

No. The business model, regulatory status, products, customers and statutory category determine the applicable obligations and supervisory position.

Can KYC be completely outsourced to a vendor?+

A vendor can support verification and screening, but the regulated business remains responsible for its risk decisions, oversight, escalation, records and compliance.

How often should an AML/CFT programme be reviewed?+

Review should be risk-based and triggered by legal, product, customer, geographic, system, vendor or risk changes, as well as periodic assurance requirements.

Have a matter in mind?

Choose the right first step.

Send a non-confidential enquiry or request a focused 20–30 minute introductory consultation. We ordinarily respond within one business day.

info@snnyagaadvocates.co.ke+254 728 852 448Westpark Towers, 11th Floor, Mpesi Lane, Westlands, Nairobi