Start with what your business actually does
Which licence does a fintech need in Kenya? A payment processor, lender and investment manager may all describe themselves as fintechs, but they face different regulatory questions.
There is no single permission that covers every fintech business model. The practical starting point is a written map of your product, customers, contracts, movement of funds and responsibilities. That map helps identify the relevant approval before expensive technology development or commercial commitments are made.
Match the activity to the regulatory framework
Begin with this activity map.
| Proposed activity | Main regulatory starting point | First question to resolve |
|---|---|---|
| Payment processing, merchant collections or electronic money | Central Bank of Kenya (CBK); National Payment System framework | What payment function does your entity perform, and which authorisation covers it? |
| Non-deposit-taking credit, including app-based lending | CBK; Central Bank of Kenya Act | Does the business fall within CBK’s credit-provider framework or another applicable law? |
| Investment advice, fund management, securities platforms or brokerage | Capital Markets Authority (CMA); relevant capital-markets rules | Which intermediary, platform or product approval matches the service? |
| Virtual-asset exchanges, brokerage, investment advice or management | CMA under the Virtual Asset Service Providers framework | Which scheduled activity or combination of activities is being undertaken? |
| Custodial virtual-asset wallets, virtual-asset payment processing or stablecoin issuance | CBK under the Virtual Asset Service Providers framework | Does the service involve custody, processing or issuance as legally defined? |
| Handling customer, employee or merchant personal information | Office of the Data Protection Commissioner (ODPC) | What are the entity’s controller and processor responsibilities? |
| Activities falling within the reporting-institution definition | Financial Reporting Centre (FRC), alongside the sector supervisor | Which AML, counter-terrorism and proliferation-financing controls apply? |
This map draws on the National Payment System Regulations, CBK Act, CMA licensing checklists, VASP Act, First Schedule, Data Protection Act framework and POCAMLA.
Draw the complete transaction before choosing a licence
Consider a platform that collects customer payments for merchants and later settles the merchants. The key questions include whose account receives the money, who owes the merchant, who can delay settlement, and which entity resolves a failed payment.
Now add a wallet balance, instalment credit or an investment feature. Each addition changes the analysis. A useful product description therefore records:
- The customer and the entity with which the customer contracts.
- Every entity that receives, controls, transfers or safeguards funds.
- When ownership or entitlement to funds changes.
- The payment instructions, settlement timetable and refund process.
- The countries involved and the role of each outsourced provider.
This exposes gaps between the sales promise, technical design and contracts before disputes arise.
Be precise about lending and investment products
Kenya’s credit-provider framework should not be described as applying only to businesses with lending apps. The current CBK Act addresses non-deposit-taking credit business, including licensing and supervision under sections 33R and 33S. A lender should assess the statutory scope and the applicable implementation requirements for its particular model. Central Bank of Kenya Act.
For investment products, distinguish the platform operator from the adviser, fund manager, custodian and issuer. One customer journey may involve several regulated roles. CMA publishes separate licensing and approval materials and expressly notes that its checklists are summaries; the legislation remains controlling. CMA licensing checklists.
Before describing a product as “savings”, “investment”, “guaranteed” or “regulated”, ensure the wording matches the actual structure and permissions. Product labels should follow the legal analysis.
Build the application around an operating business
Organise the preparation into five connected files:
- Business model: product description, customer journey, transaction flow and revenue model.
- Ownership and governance: group structure, beneficial owners, management responsibilities and funding evidence.
- Operations: reconciliation, safeguarding where applicable, complaints, outsourcing and business continuity.
- Compliance: AML procedures, data protection, risk assessment and reporting responsibilities.
- Contracts: customer terms, merchant agreements, banking arrangements and technology-provider agreements.
Requirements and financial thresholds depend on the authorisation sought. The practical test is whether the application, financial model, contracts and live product tell the same story.
Treat partnerships as a regulatory design question
A partnership with a licensed institution can form part of a lawful operating model. It should be clear which entity provides each regulated service and whether the proposed arrangement is permitted within the partner’s authorisation and applicable rules.
Review the agreements for onboarding responsibility, settlement, withheld funds, refunds, chargebacks, complaints, audit access, data use and termination. Include an exit plan: how will customers receive their funds or records if the relationship ends?
The conduct of the parties must support descriptions such as “technology partner”.
Build AML and privacy into the customer journey
FRC registration and reporting duties attach to reporting institutions as defined by law; they are not an identical checklist for every software company. Establish the applicable scope, then design controls around the institution’s actual risks. POCAMLA, section 2.
For privacy, document the information collected, the purpose and lawful basis, who receives it, retention and applicable transfer safeguards. ODPC registration, where required, is one part of compliance. A certificate does not replace lawful processing or appropriate security. ODPC data-protection legislation.
A dated note on virtual assets
The VASP Act commenced on 4 November 2025, and the 2026 Regulations commenced on 22 July 2026. Section 47 gives persons providing virtual-asset services at commencement one year to comply, pointing to 4 November 2026. Assess whether the transitional provision applies to the particular business; it is not a general permission for every new entrant to launch. VASP Act, VASP Regulations, 2026.
Frequently asked questions
Does incorporating a company authorise a fintech to operate?
Incorporation creates the legal entity. Any applicable financial-services authorisation is a separate matter, as the licensing frameworks above demonstrate.
Can a foreign licence cover Kenyan operations?
Do not assume it does. Assess the Kenyan activities, customers, entities and local requirements before relying on an overseas permission.
What should founders prepare for a first regulatory discussion?
A clear product summary, ownership chart, transaction-flow diagram, target customers and a list of the permissions already held by relevant partners.
Discuss your Kenya launch
S.N. Nyaga & Company Advocates assists businesses with regulatory scoping, application preparation, commercial contracts and compliance frameworks. Email info@snnyagaadvocates.co.ke with the subject “Kenya Fintech Regulatory Scoping” and a short description of your product and intended launch stage.
General information, current to the review date. Application to a particular business requires an assessment of its facts.
Continue your preparation
Explore all six Kenya business guides, our related legal service, and the Legal Toolkit. For continuing updates, read the Commercial and Regulatory Briefing.
