← All publications

AML Compliance in Kenya: A Practical Guide for Businesses

Establish which AML obligations apply, then connect customer checks, monitoring, reporting and recordkeeping to daily operations.

Discuss your legal needs

Discuss an AML programme review?

Send a short description of your business, the support needed and any relevant deadline. Scope and fees are agreed before work begins.

Discuss an AML programme review

Start with the business, then build the controls

An AML policy should help a business decide whom to onboard, what information to request, which transactions need attention and when to escalate concerns. The policy must guide daily decisions.

Kenya’s framework covers anti-money laundering, counter-terrorism financing and counter-proliferation financing. Start by identifying which requirements apply to your business.

1. Establish whether you are a reporting institution

POCAMLA defines reporting institutions to include financial institutions, designated non-financial businesses and professions, and virtual-asset service providers. The financial-institution definition looks at activities, including lending, money or value transfers and portfolio management. Designated businesses include real-estate agencies, casinos, certain professional services and dealers in precious metals or stones. POCAMLA, section 2.

A business should therefore assess its activities rather than assume that being outside banking places it outside AML regulation. Equally, it is inaccurate to say every Kenyan business has the same FRC reporting duties merely because it accepts payments. Professional firms also need to consider the relevant activity rules and applicable privilege provisions.

Revisit the assessment when introducing new services.

2. Put registration and ownership of the programme in place

Reporting institutions must register with the FRC. The Centre’s live electronic reporting platform is goAML. Establish the institution’s registration and authorised users early, and keep evidence that access works. Registration is part of the compliance infrastructure; it does not certify the entire business as compliant. FRC compliance guidance.

The Regulations require a management-level Money Laundering Reporting Officer with competence, authority and independence. They also address training, internal controls and independent testing. POCAML Regulations, regulations 11–12.

Give recurring tasks an owner and deputy: user access, alert review, customer-file remediation, training and returns. Provide cover for key staff absences.

3. Make the risk assessment specific

The Regulations require a documented institutional assessment covering relevant customer, geographical, product, transaction and delivery-channel risks. New products and technologies must also be assessed. POCAML Regulations, regulations 7–8.

Start with concrete scenarios. Could an account receive funds from unrelated third parties? Could a merchant process payments for undisclosed businesses? Could an apparently local customer operate across several jurisdictions?

For each scenario, record the control, its owner and the evidence that shows it works. Distinguish a control that exists on paper from one that is configured in the system and tested. Use the findings when deciding whether to launch products or accept customer segments.

4. Build a customer file that explains the relationship

Customer due diligence includes identifying and verifying customers, checking a representative’s authority and identifying the beneficial owner. A company certificate alone does not establish the identity of every relevant person behind the relationship. POCAMLA, section 45.

As a practical file structure, record:

  • The customer’s identity and business activity.
  • The ownership and control structure, with supporting evidence.
  • The persons authorised to give instructions.
  • The reason for the account or service and expected activity.
  • The risk decision, supporting rationale and next review trigger.

Make missing information visible. A checklist should distinguish “received”, “verified”, “inconsistent” and “awaiting clarification”. Received documents still need assessment.

Higher-risk cases require enhanced measures. The Regulations contain specific politically exposed person requirements, including distinctions between foreign PEPs and higher-risk domestic or international-organisation PEP relationships. POCAML Regulations, regulation 26.

5. Monitor behaviour and record the reasoning

Useful monitoring compares what the customer actually does with what the business understands about the relationship. Illustrative review triggers include unexplained third-party funding, rapid movement through an account, abrupt changes in volume or settlement requests that do not match the documented business.

These examples are prompts for examination, not automatic findings of wrongdoing. Record what triggered the review, which facts were checked, what explanation was obtained and why the case was escalated or closed. Avoid conclusions such as “customer known to us” without supporting analysis.

Test whether another reviewer can follow a sample of closed-alert decisions from the records alone.

6. Escalate and report within the correct timeframe

The FRC’s published guidance states that suspicious transaction or activity reports must be submitted within two days after the suspicion arose. The legal obligation also covers attempted suspicious transactions. Teams should escalate promptly and avoid internal approval arrangements that consume the reporting window. FRC compliance guidance, POCAMLA, section 44.

As a working method, maintain a restricted case record containing the chronology, relevant parties, transaction details, reasons for suspicion and submission evidence. Distinguish a technical submission problem from a decision that no report is required, and raise reporting-access failures immediately through the appropriate FRC channel.

Do not tell a customer that an STR is being prepared or has been filed. POCAMLA prohibits tipping off. Customer communications require careful handling while the matter is assessed. POCAMLA, section 8.

Cash reporting is a separate obligation: the Regulations set a US$15,000-equivalent threshold, regardless of suspicion. A suspicious transaction need not reach that amount to be reportable. POCAML Regulations, regulations 38 and 40.

7. Treat sanctions and records as separate controls

Targeted financial sanctions need their own procedures. FRC guidance explains that these obligations extend beyond reporting institutions to natural and legal persons generally. Confirmed matches require action under the applicable Kenyan sanctions framework; screening alone is insufficient. FRC public guidance on targeted financial sanctions.

Keep an identifiable record of the list screened, the potential match, the assessment and the action taken. Separate a false-positive decision from a confirmed match so staff know which process applies.

The Regulations prescribe a minimum seven-year record-retention period, with the applicable starting event tied to the transaction or relationship. Apply any longer required retention or lawful preservation hold. POCAML Regulations, regulation 42.

Frequently asked questions

Is buying screening software enough?
Software supports decisions. The business still needs appropriate data, review procedures, trained staff, escalation and evidence of action.

Does a PEP match mean the person committed an offence?
No. It identifies a category requiring assessment and the applicable due-diligence measures; it is not proof of criminal conduct.

What is the most useful first review?
Test the complete journey of several customer files, from onboarding through monitoring to escalation. This reveals whether the policy is being implemented.

Review your AML programme

S.N. Nyaga & Company Advocates assists with AML scope assessments, policy and procedure development, customer-onboarding reviews, training and compliance remediation. Email info@snnyagaadvocates.co.ke with the subject “Kenya AML Compliance Review” and a short description of your business and the area requiring support.

General information, current to the review date. Sector-specific requirements and the facts of each matter may require additional analysis.

Continue your preparation

Explore all six Kenya business guides, our related legal service, and the Legal Toolkit. For continuing updates, read the Commercial and Regulatory Briefing.

How we can assist

Discuss an AML programme review?

Explore how the firm can assist with the next step for your business.

Explore legal support Use the Legal Toolkit
Have a matter in mind?

Choose the right first step.

Send a non-confidential enquiry or request a focused 20–30 minute introductory consultation. We ordinarily respond within one business day.

info@snnyagaadvocates.co.ke+254 728 852 448WhatsApp the firm ↗Westpark Towers, 11th Floor, Mpesi Lane, Westlands, Nairobi