Kenya's payments market continues to attract payment gateways, merchant aggregators, digital-wallet providers, remittance businesses and international fintech groups. For a business whose model falls within Kenya's definition of a payment service provider, however, incorporation and a banking partnership are not enough. The business must obtain the appropriate authorisation from the Central Bank of Kenya (CBK) before commencing regulated payment-service activities.
The application is not simply a form-filling exercise. CBK reviews the proposed payment flow, ownership and source of capital, governance, financial viability, safeguarding arrangements, technology, cybersecurity, AML/CFT controls, outsourcing, customer contracts and operational readiness as one connected operating model.
This guide explains the principal authorisation categories, the application sequence, the documents CBK expects and the issues that commonly delay an application under the National Payment System Act, 2011 and the National Payment System Regulations, 2014.
Terminology: The legislation generally uses the term authorisation. Searches and industry discussions often refer to a PSP licence. This article uses both terms to describe the same CBK approval process, except where a separate regulatory approval may apply.
1. First determine whether the business requires PSP authorisation
The National Payment System Act defines a payment service provider broadly. The definition includes a person, company or organisation that provides services relating to the sending, receiving, storing or processing of payments through an electronic system. It also extends to certain network, processing and data-storage functions connected with payment services.
A licensing question may therefore arise where a business:
- receives or transmits payment instructions;
- processes electronic retail transfers;
- collects money from customers for onward settlement to merchants;
- controls the routing, timing or execution of payments;
- issues or manages stored value or digital wallets;
- provides cash-in or cash-out services;
- determines refunds, reversals, reserves or chargebacks; or
- holds itself out to customers or merchants as responsible for moving money.
The analysis is functional. Calling the product a gateway, aggregator, marketplace, software platform or technical integration does not determine the result. Equally, saying that the company “does not hold customer funds” is relevant but does not answer every licensing question: processing payment instructions can itself fall within the statutory definition.
A fintech may instead operate as a technology supplier to an authorised bank or PSP where the regulated institution genuinely contracts for and performs the regulated service, controls the payment instruction and settlement, bears regulatory responsibility, and remains the customer-facing payment provider. That conclusion should be tested against the actual funds flow, contracts, user interface, account structure and division of liability.
Where the model involves cross-border remittance, foreign exchange, digital credit, virtual assets or stablecoins, the National Payment System framework may not be the only applicable regime. A separate regulatory-perimeter analysis may be required before selecting an application route.
2. Select the correct authorisation category
The application category must follow the proposed service. It should not be selected solely by reference to the lowest capital threshold.
The First Schedule to the National Payment System Regulations presently sets out the following fees and core-capital requirements:
| Category | Application fee | Authorisation fee | Minimum core capital |
|---|---|---|---|
| Electronic retail payment service provider | KES 5,000 | KES 100,000 | KES 5,000,000 |
| E-money issuer | KES 5,000 | KES 1,000,000 | KES 20,000,000 |
| Small e-money issuer | KES 5,000 | KES 100,000 | KES 1,000,000 |
| Designated payment instrument issuer | Not stated in Table A | KES 5,000,000 | KES 50,000,000 |
These are statutory minimums. They do not include the cost of establishing the company, appointing personnel and trustees, developing the technology, securing bank and vendor arrangements, conducting systems and security audits, or preparing the application and compliance framework. The figures should also be verified immediately before filing because CBK may amend prescribed capital requirements and its payment instructions or administrative practice may change.
Electronic retail payment service provider
This is the category most commonly considered by gateways, aggregators, payment processors and other providers of electronic retail-transfer services. Whether it is correct for a particular platform depends on what the platform actually does in the transaction chain.
E-money issuer
An e-money model involves monetary value that is electronically or magnetically stored, issued against receipt of currency, and accepted as payment by persons other than the issuer. Wallet and stored-value products require particular attention to safeguarding, liquidity, redemption, trust arrangements, customer accounts and restrictions on the issuer's activities.
Small e-money issuer
This is a limited-scale registration category, not a general lower-capital route for an ordinary wallet. Under the Regulations, a small e-money issuer must be a Kenyan company; must keep individual transaction limits within the prescribed threshold; must keep total e-money liabilities within the prescribed ceiling; and may issue e-money accepted only by specified companies within its group. The proposed commercial model must genuinely fit these restrictions.
Designated payment instrument or payment system
A product that constitutes a payment instrument, or an arrangement that operates a payment system, may require designation rather than—or in addition to—the ordinary electronic-retail-transfer authorisation route. CBK should be engaged early where the proposed infrastructure, instrument or system has wider market or systemic characteristics.
3. Prepare a regulatory-perimeter and application-readiness assessment
Before requesting name approval or compiling policies, the applicant should document the complete operating model. A useful readiness package normally includes:
- a product and service description;
- an end-to-end transaction-flow and funds-flow diagram;
- identification of every bank account, trust account and settlement account;
- the role of each bank, mobile network operator, card network, processor, technology provider, agent and merchant;
- the customer and merchant contracting structure;
- responsibility for onboarding, KYC, transaction monitoring, refunds, reversals, chargebacks and complaints;
- custody and control of customer or merchant funds at each stage;
- settlement timing and reconciliation processes;
- countries, currencies and customer types involved; and
- the division of liability where a payment fails, is delayed, reversed, fraudulent or unauthorised.
This work identifies the correct authorisation category and prevents a common application problem: policies, agreements, financial projections and technical diagrams that describe different versions of the business.
4. Engage CBK before submitting the full application
CBK's Payment Service Providers Authorisation Checklist recommends that an applicant first determine the applicable PSP category and, where necessary, seek clarification from CBK. The applicant may request a preliminary meeting to discuss its concept note and application requirements through CBK's National Payment System contact channel.
The concept note should be concise but sufficiently detailed to allow CBK to understand:
- the proposed payment service and target users;
- the payment and settlement flow;
- the proposed authorisation category;
- the ownership and group structure;
- the source and availability of capital;
- the proposed banks and major partners;
- the technology architecture and material outsourcing; and
- the compliance, risk and governance structure.
The preliminary engagement is not an authorisation and should not be treated as permission to launch, market the product as licensed, onboard customers or begin regulated transactions.
5. Obtain company-name and product-name approval
An applicant must first apply to CBK for approval of its proposed company name. Three names should be submitted in order of preference. CBK may invite the applicant to a preliminary meeting to understand the intended business and explain the application requirements.
Once CBK accepts a proposed name, the applicant reserves it with the Registrar of Companies. The approved name should not be used to conduct the payment-service business until CBK grants authorisation. A proposed product name also requires CBK approval, subject to any existing intellectual-property rights.
The CBK checklist indicates that the name-approval submission should be accompanied by preliminary information including:
- the business model, proposed activities and marketing strategy;
- the proposed company objects;
- the ownership and governance structure;
- evidence of the source and availability of capital;
- three-year financial projections;
- the proposed legal and regulatory compliance function;
- a high-level infrastructure and internal-control outline; and
- high-level risk-management policies and procedures.
The sequence matters. Incorporating an entity under a payments-related name before obtaining CBK's approval may create avoidable restructuring and branding work.
6. Establish the applicant, ownership and capital structure
The application must present a transparent legal and beneficial-ownership structure. The corporate documents normally include:
- a certified certificate of incorporation;
- the constitution or memorandum and articles of association;
- current company-registry records showing directors and shareholders;
- the applicant's tax-compliance certificate;
- the applicant's credit-reference report;
- the registered, physical and postal addresses of the head office;
- audited financial statements for the preceding three years, where the applicant has been operating; and
- corporate documents for any corporate significant shareholder.
For purposes of the Regulations, a significant shareholder generally includes a person holding directly or indirectly at least 5% of the share capital of an unlisted PSP. CBK will look through corporate shareholders to the ultimate beneficial owners and may require shareholder agreements, group-structure information and evidence supporting the ownership chain.
Evidence and source of capital
The applicant must demonstrate that it holds the applicable minimum core capital. CBK's checklist contemplates evidence such as isolated funds shown in a statement from a licensed bank or deposit-taking microfinance institution, or unencumbered Government of Kenya Treasury bills or bonds. CBK may verify the evidence directly with the financial institution.
The filing should explain:
- how much each promoter or shareholder has contributed;
- the allocation, percentage and ultimate beneficiary of the capital;
- the citizenship and identity of the contributors;
- the documentary source of each significant contribution; and
- why the funds are lawful and unencumbered.
Significant shareholders are also expected to provide a sworn declaration that the proposed capital is not derived from proceeds of crime. Capital evidence should be consistent with the applicant's registry records, financial statements, bank evidence and business plan.
Foreign groups
Where the applicant is a subsidiary of a foreign company, additional documents may include a no-objection letter from the home regulator, board approval to establish the Kenyan payments business, a description of the foreign group's operations and regulators, an undertaking to maintain the required assigned capital in Kenya, and confirmation that the home regulator can exchange supervisory information with CBK.
7. Prepare the formal application and sworn affidavit
The formal application is made using Form 1 in the First Schedule to the National Payment System Regulations, 2014. It should be accompanied by a covering letter summarising the applicant and the authorisation sought, a sworn affidavit in the prescribed form, a detailed business plan, the supporting application documents and the applicable non-refundable application fee.
The form and affidavit should be checked carefully against every attachment. Inconsistencies in names, shareholding percentages, dates, capital figures, job titles or product descriptions can undermine confidence in the application and trigger clarification requests.
8. Build a business plan and programme of operations that can withstand regulatory review
The business plan is the core narrative of the application. It must do more than describe market opportunity. It should demonstrate that the proposed service can operate safely, efficiently and sustainably.
A strong business plan should cover:
- the business concept and services to be offered;
- the target market, public interest and customer need;
- the proposed products and delivery channels;
- the programme of operations;
- the transaction and settlement flows;
- the revenue model and pricing;
- a market and competitor assessment;
- activities performed in-house and those outsourced;
- the bank, mobile network, card, technology and settlement relationships;
- the staffing and governance plan;
- the risk, compliance and internal-control functions;
- an implementation and launch plan; and
- three-year financial projections with clear assumptions.
The projections should reconcile to the proposed capital, staffing, transaction volumes, technology costs, audit costs, safeguarding structure and expected revenues. A rapid-growth forecast unsupported by operational capacity or liquidity planning is unlikely to assist the application.
9. Prepare the governance and fit-and-proper file
CBK assesses the history, character, integrity and suitability of significant shareholders, directors, trustees and senior management. The application should identify the board, chief executive, senior managers, control functions and persons responsible for the proposed payment service.
The fit-and-proper package commonly includes:
- the prescribed fit-and-proper form;
- a current and detailed curriculum vitae;
- identification documents;
- tax PIN and current tax-compliance certificate;
- a recent credit-reference report;
- a certificate of good conduct;
- contact details for independent referees; and
- information about other business interests, regulatory history, insolvency, litigation or previous rejected applications.
The organisational chart should distinguish the board from management and show meaningful responsibility for finance, risk, compliance, AML/CFT, technology, security, operations, customer protection and internal audit. Titles alone are not enough; job descriptions, reporting lines, independence, competence and resourcing should support the structure.
10. Develop the operational and compliance framework
CBK's review tests whether the applicant is ready to operate, not merely whether it has collected policies. The documents should be tailored to the actual product and should allocate responsibilities, approval thresholds, escalation routes, records and reporting obligations.
The application file will usually require policies, procedures or manuals addressing:
- enterprise and operational risk management;
- accounting, finance and reconciliations;
- settlement and settlement-risk management;
- AML/CFT, sanctions and transaction monitoring;
- customer and merchant onboarding and due diligence;
- fraud prevention, detection and response;
- information security and cybersecurity;
- data protection, retention and access control;
- complaints and dispute resolution;
- business continuity and disaster recovery;
- incident and breach management;
- outsourcing and third-party risk;
- agents and cash merchants, where applicable;
- human resources and competence;
- internal audit and compliance monitoring; and
- recordkeeping and regulatory reporting.
These frameworks should match the terms of service, merchant agreements, system capabilities and staffing model. A policy should not promise daily monitoring, maker-checker controls, screening, audit logging or business-continuity capabilities that the proposed system and team cannot deliver.
11. Evidence technology, cybersecurity and data readiness
The applicant should be prepared to describe the full technology architecture and demonstrate that sensitive payment data, customer information and transaction records are appropriately protected.
CBK's checklist calls for, among other items:
- an information-systems and security policy;
- an independent IT systems audit report;
- a vulnerability assessment report;
- an internal-audit readiness report;
- a business-continuity and disaster-recovery plan;
- security-incident procedures;
- fraud-prevention measures;
- transaction and cash-holding limits;
- data classification and access-right controls;
- encryption, firewall and related technical safeguards;
- identification of persons with access to sensitive payment data; and
- an explanation of how breaches will be detected and addressed.
The applicant must also demonstrate compliance with Kenya's data-protection framework. Depending on the processing model, this may require controller or processor registration, privacy notices, lawful-basis mapping, processor contracts, cross-border transfer safeguards, retention rules, data-subject procedures and a data protection impact assessment for high-risk processing. Product design, cloud hosting, KYC vendors and offshore group access should all be addressed consistently.
12. Document settlement, safeguarding and customer-fund arrangements
CBK will expect a clear explanation of how payment obligations are settled. The funds-flow diagram should show every stage from payment initiation to final settlement, identify the legal owner and controller of each account, state the settlement timing, and explain reconciliations, failed payments, refunds, reversals and chargebacks.
Where the model involves e-money or holding customer funds, safeguarding becomes central. The application may require:
- a trust deed and trustee structure;
- the proposed local bank or banks in which trust funds will be held;
- diversification and protection arrangements;
- daily reconciliation and liquidity controls;
- the permitted treatment of income on trust funds;
- procedures for dormant and deceased-customer accounts; and
- arrangements for termination, insolvency or discontinuation of the service.
Customer and operational funds should not be mixed. The legal documents, accounting treatment, banking arrangements and system ledgers must all reflect the intended segregation.
13. Prepare customer, merchant, bank and outsourcing agreements
The application should include the material agreements on which the service depends. Depending on the model, these may include:
- customer terms and conditions;
- merchant or aggregator agreements;
- agent and cash-merchant agreements;
- bank, settlement and trust-account agreements;
- trustee or trust-management documents;
- technology-platform, cloud and connectivity contracts;
- KYC, screening and fraud-vendor agreements;
- payment-network or mobile-network agreements; and
- material outsourcing contracts.
The customer service agreement must accurately describe the service and address matters such as onboarding, account use, loading and withdrawing funds, fees, privacy, suspension, termination, freezing, complaints, liability, unauthorised transactions, dispute resolution, data retention, dormant accounts and deceased-person accounts.
Outsourcing does not transfer the applicant's regulatory responsibility. The applicant should provide a due-diligence assessment for material third parties, define service levels and security obligations, preserve audit and access rights, regulate subcontracting and cross-border data access, and demonstrate operational resilience if a provider fails.
14. Submit the application and manage CBK's review
The application should be submitted in the form and through the channel directed by CBK at the time of filing. Payment instructions, contacts and administrative requirements should be reconfirmed immediately before submission rather than copied from an old checklist or third-party article.
Under the Regulations, CBK may request additional information within 30 days after receiving an application where the filing is incomplete or further information is considered necessary. This is not a statutory promise that the entire authorisation will be completed within 30 days.
CBK's substantive assessment includes:
- whether the applicant can provide the service safely and efficiently;
- the applicant's financial condition and capital;
- the integrity and suitability of shareholders, directors, trustees and senior officers;
- the adequacy of governance and internal controls;
- the effect of the applicant's other commercial activities on safety and supervision; and
- the convenience, needs and public interest served by the proposed service.
The applicant should maintain a formal query tracker during review. Responses should be complete, consistent and supported by updated documents. If a clarification changes the business model, the corresponding policies, agreements, diagrams and projections should be updated together.
There is no reliable one-size-fits-all end-to-end licensing period. The Regulations prescribe certain procedural periods—for example, issuance of the certificate within seven days after receipt of the authorisation fee once CBK has approved the applicant—but the time needed to reach that stage depends on the completeness of the file, regulatory queries, ownership and source-of-funds review, technology readiness, partner documentation, inspections and remediation.
15. Complete operational-readiness testing before launch
An applicant should expect to demonstrate that the proposed controls work in practice. Readiness work may include:
- end-to-end transaction and reconciliation testing;
- user-acceptance and failure-scenario testing;
- penetration and vulnerability testing;
- incident-response and disaster-recovery exercises;
- testing of onboarding, screening and monitoring rules;
- complaints and refund workflow testing;
- access-control and privileged-user reviews;
- review of vendor and bank integration evidence; and
- remediation of internal, systems and security-audit findings.
The product shown to CBK should be materially consistent with the product described in the application. Material changes to channels, partners, functions or documents may require notification or approval.
16. Pay the authorisation fee and receive the certificate
Once CBK has received a complete application, completed its assessment and is satisfied that the requirements are met, it advises the applicant to pay the applicable authorisation fee. The Regulations provide for CBK to issue the authorisation certificate within seven days after receiving that fee.
The applicant should review the certificate and any attached conditions carefully. Authorisation is not a blanket permission to offer every payment product. The business must operate within the approved category, product description and conditions, and obtain or provide any required approval or notice before making material changes.
17. Plan for post-authorisation compliance from the beginning
PSP authorisation creates continuing obligations. These should be built into staffing, systems and budgets during the application rather than addressed after launch.
Ongoing requirements may include:
- maintaining the required core capital;
- safeguarding and reconciling customer funds;
- retaining transaction records and complete audit trails;
- submitting monthly regulatory returns;
- filing annual audited financial statements and systems-security audit reports;
- maintaining AML/CFT screening and reporting controls;
- managing complaints within prescribed periods;
- giving required notices for material product or partner changes;
- supervising agents, cash merchants and outsourced providers;
- maintaining data-protection and cybersecurity compliance; and
- applying for renewal within the prescribed period.
Under the National Payment System Act, an authorisation is generally valid for 12 months and a renewal application should be lodged at least two months before expiry. A provider that fails to commence business in Kenya within six months after authorisation may be required to apply afresh.
Common reasons PSP applications are delayed
The recurring causes of delay are usually substantive rather than clerical:
- The authorisation category has not been settled. The product description, payment flow and requested category do not match.
- The funds flow is incomplete. Accounts, settlement timing, custody, reversals or liability are unclear.
- The business plan and financial model do not reconcile. Transaction volumes, costs, capital, liquidity and staffing tell different stories.
- Source of funds is inadequately documented. Capital is shown, but the lawful origin and beneficial contributors are not demonstrated.
- Governance is nominal. Key functions appear on an organisation chart without suitable personnel, independence, job descriptions or resources.
- Policies are generic. Controls are copied from templates and do not reflect the product, channels, risks or system capabilities.
- Critical contracts are missing. Bank, trustee, platform, outsourcing or settlement arrangements remain unsigned or materially incomplete.
- Technology is not ready for review. Required audits, testing, access controls, logs, resilience measures or remediation are outstanding.
- The applicant changes the product during review. New partners, countries, currencies or functions are introduced without updating the complete application file.
- Regulatory queries are answered in isolation. A response changes one document but leaves contradictions elsewhere.
Frequently asked questions
Can a fintech apply before its product is fully built?
An applicant does not necessarily need to have launched, but it must be able to demonstrate a sufficiently developed and testable operating model. The architecture, controls, contracts, financial plan, staffing and audit evidence must be mature enough for CBK to assess whether the service can operate safely and efficiently.
Does partnering with a licensed bank or PSP remove the need for authorisation?
Not automatically. The result depends on the division of functions. If the fintech itself receives or processes payment instructions, controls settlement or funds, contracts as the payment provider, or bears core payment-service responsibility, it may still have its own authorisation exposure.
Is KES 5 million the capital requirement for every PSP?
No. KES 5 million is the statutory core-capital figure for an electronic retail payment service provider. Other categories have different thresholds, including KES 20 million for an e-money issuer and KES 50 million for a designated payment instrument issuer under the present First Schedule.
Is the authorisation fee always KES 100,000?
No. The fee depends on the category. The current First Schedule specifies KES 100,000 for an electronic retail payment service provider and a small e-money issuer, KES 1 million for an e-money issuer, and KES 5 million for a designated payment instrument issuer.
How long does the PSP application take?
There is no dependable universal period. A complete, internally consistent and operationally ready filing is easier to review, while unresolved ownership, capital, technology, safeguarding, contracts or regulatory-perimeter issues can extend the process. The 30-day provision in the Regulations concerns CBK's ability to request additional information; it is not an overall approval deadline.
Can the applicant begin operating while the application is pending?
No. A person proposing to conduct PSP business must apply before commencing, and an application does not itself authorise the business to operate. Section 12 of the National Payment System Act prohibits conducting PSP business in Kenya without authorisation and provides criminal penalties for contravention.
Conclusion
A credible PSP application is a regulatory, operational and technology-readiness project. The most effective sequence is to settle the licensing perimeter, map the end-to-end payment flow, confirm the correct authorisation category, align ownership and capital, obtain name approval, and then build one coherent application across the business plan, financial model, governance, policies, systems, safeguarding arrangements and contracts.
Planning a payment product or preparing a CBK application? We can review the transaction flow, confirm the likely authorisation route, identify readiness gaps and support the preparation and management of the application through the regulatory review process.

