Kenya’s non-deposit-taking lenders now need to review how they obtain authorisation, price loans, handle customer information and oversee their operations. The Central Bank of Kenya (Non-Deposit Taking Credit Providers) Regulations, 2026 were published as Legal Notice No. 191 in the Kenya Gazette on 29 September 2026. They replace the 2022 Digital Credit Providers Regulations. [1]
The instrument contains no separate commencement date. Section 23(1) of the Statutory Instruments Act provides for commencement on publication where no other date is specified, subject to the statutory qualifications. On that basis, the Regulations took effect on 29 September 2026. Businesses should use the gazetted 2026 text when assessing their obligations. [1] [2]
The immediate response depends on the lender’s position. Existing licensed digital credit providers retain their authorisation under the transition provisions. Other qualifying existing lenders must assess the licensing or registration route and prepare an application. Both groups need to examine the conduct of their lending business.
Which businesses are affected
The framework covers non-deposit-taking credit business that is not regulated under another written law. It reaches lending through physical premises as well as digital channels. Asset finance, buy-now-pay-later, stock-now-pay-later and pay-as-you-go models are among the activities requiring careful assessment, subject to the Regulations’ exclusions and any applicable CBK determination or approval. [1, regulations 2, 3 and 17]
A company’s description as a fintech, credit company or microfinance business does not determine its position. The assessment should identify the contracting lender, who funds the loan, who makes the credit decision, how repayments are collected and which entity bears the credit risk.
The exclusions matter. They include institutions licensed under the Banking Act or Microfinance Act, registered co-operative societies, licensed SACCOs, specified credit guarantee providers and businesses regulated under other written laws. Certain regulated lease-finance and hire-purchase arrangements are also excluded. Credit merely incidental to a seller’s primary business of supplying goods or services has a separate exclusion. A third-party financing arrangement should not be assumed to qualify merely because it supports a sale. [1, regulation 3]
What existing and prospective lenders should do
For an existing DCP licensee, regulations 96(3) and 96(4) preserve continuity and deem the provider licensed under the new framework. The immediate work is a compliance review against the 2026 requirements. A fresh application is not required solely because the 2022 Regulations have been revoked. [1]
For a person already conducting qualifying non-deposit-taking credit business at commencement, regulation 96(1) requires an application for a licence or registration within six months of publication. The clock runs from 29 September 2026. An applicant within this provision may continue operating while CBK determines the application, subject to the Act, the Regulations and CBK conditions. The continuation provision is tied to qualifying applicants; it should not be treated as an unrestricted grace period for every unlicensed lender. [1]
For a pending applicant, regulation 96(6) requires processing under Part II or Part III of the new Regulations, as appropriate. The application file should therefore be checked for additional information and updated policies. New entrants must establish the applicable authorisation route before commencing business or holding themselves out as authorised lenders. [1, regulations 5 and 96]
Existing operators should set a filing timetable well ahead of the end of the six-month window in March 2027. Evidence of the operating history, corporate structure and funding arrangements should be assembled at the start of that process.
Licensing and registration need separate assessments
Regulation 6(1) directs a person seeking to establish the business with initial capital of at least KES 20 million to apply for a licence. Part III provides a registration route, subject to CBK’s assessment. Registration remains a regulated status with continuing duties. [1]
A registered provider must apply for a licence if its capital, borrowings or loan book exceeds KES 20 million. CBK may also require conversion following rapid expansion or incorrect disclosure of those amounts. A smaller provider should therefore monitor funding and portfolio growth, as well as its original capital. [1, regulation 11]
The KES 20 million figure should not be presented as a blanket exemption for smaller lenders. The registration provision cross-refers to the licensing assessment conditions in regulation 7(1), so the appropriate route should be confirmed against the full application requirements and the business’s facts.
Fees should be included in the compliance budget
The Third Schedule provides the following fees. These are regulatory charges, separate from legal and other professional fees. [1]
| Regulatory fee | Licensed provider | Registered provider |
|---|---|---|
| Application | KES 100,000 | KES 100,000 |
| Grant of authorisation | KES 500,000 | KES 250,000 |
| Annual fee | KES 500,000 | KES 250,000 |
The annual payment date is 31 December. The Third Schedule also lists KES 1 million in late penalty fees. Regulations 7(5) and 10(5) separately prescribe double the annual fee for payment within three months after the due date. The relationship between these provisions, particularly for registered providers, warrants CBK clarification. Lenders should arrange timely payment rather than assume a particular late-payment calculation. [1]
The operational changes that deserve priority
Loan documents and pricing
The Regulations address repayment capacity, key information documents and disclosure of the annual percentage rate. Product and pricing changes require the relevant CBK approval and customer notices. Repayments must settle due principal first, then outstanding fees and charges, then interest. The rules also protect early repayment without a penalty or interest for the remaining period where the loan is repaid in full. [1, regulations 26, 28, 48 and 54–59]
A useful implementation exercise is to follow one loan from advertisement to settlement. The contract, app screens, repayment schedule and accounting system should apply the same charges and repayment rules. Legal review should involve the credit, finance and product teams so that revised wording is reflected in actual transactions.
Collections and recovery
The rules restrict recoverable interest on non-performing loans and prohibit abusive collections, contact-list shaming and undisclosed recovery charges. They also address security enforcement, guarantor consent and notice, and outsourced collectors. [1, regulations 29, 30 and 42–44]
Lenders should review their recovery notices and collection instructions against these requirements. A borrower’s reference contact should not be treated as a guarantor without the required consent. Recovery budgets and portfolio valuations should reflect what can lawfully be recovered.
Customer data and automated lending
Regulation 58 requires express, specific and verifiable customer consent obtained separately from the loan offer or accepted terms. A general privacy notice alone does not satisfy that requirement. Regulation 60 addresses AI used for lending decisions, including explanations, human oversight, bias assessment and data security. [1]
The practical task is to inspect how consent is captured and retained, how automated decisions are explained and how a customer reaches a human reviewer. Vendor contracts should support those processes. A policy that cannot be demonstrated in the customer journey will be difficult to implement consistently.
Governance and outsourced services
The local board remains responsible for governance, including where the lender belongs to a group. Material outsourcing is subject to advance notification and contractual access for CBK. Reserved functions include the final lending decision, board decision-making, management and control, determination of legal compliance and management of the loan portfolio. [1, regulations 15 and 31]
Lenders should map responsibilities across their own staff, group teams, technology vendors and collection partners. External legal support can assist with advice and implementation, while the lender retains responsibility for the functions the Regulations reserve to it.
Returns and incident reporting
Specified monthly, quarterly and annual returns are due within ten days after the relevant reporting period. An annual compliance return is due by 31 December, and audited financial statements within three months after the financial year ends. Qualifying fraud and cybersecurity incidents must be notified within 24 hours. [1, regulations 66 and 67]
Each return should have an owner, a reliable source of information and a review date. Incident procedures should allow legal, compliance and technology teams to assess reporting obligations promptly.
A practical starting point for management
Management should commission a documented assessment of the business’s regulatory status and a review of one representative lending journey. The resulting action plan should identify the requirement, the operational gap, the person responsible and the evidence needed to show completion.
For a lender without confirmed authorisation, the first deliverable should be a reasoned licensing, registration or exclusion assessment and an application timetable. For an existing licensee, the first deliverable should be a prioritised implementation plan covering customer documents, systems, approvals and reporting. These are different assignments and should be scoped accordingly.
How we can assist
We assist lenders with legal work that supports both authorisation and the continuing operation of their business. The appropriate engagement will depend on the lender’s current status and the products it offers.
For lenders assessing authorisation, we can review the business model and applicable exclusions, advise on the licensing or registration route, prepare the corporate and application documents, develop policies for board approval, and assist with CBK queries and submission follow-up.
For licensed providers, we can conduct a gap review against the 2026 Regulations and update loan agreements, key information documents, consent forms, guarantees, collection notices and material outsourcing agreements. We can also assist with product-change submissions, board reporting and staff training.
For lenders requiring ongoing support, we can agree a legal and regulatory retainer covering contract reviews, regulatory correspondence, implementation advice, complaints and recovery matters, and periodic reviews of compliance evidence. Management and statutory responsibilities remain with the lender.
To discuss a Credit Provider Regulatory Review, contact info@snnyagaadvocates.co.ke with your company name, a short description of the lending model and your current CBK licensing or application status. We can use an initial 20-minute scoping call to identify the work required and provide a defined proposal.
Sources
- Central Bank of Kenya (Non-Deposit Taking Credit Providers) Regulations, 2026 — Legal Notice No. 191 of 2026.
- Statutory Instruments Act, section 23.
This article provides general information as at 4 October 2026. Advice on a particular lender requires consideration of its activities, authorisations and circumstances.
