Kenya VASP Licence: Complete Requirements, Costs, Capital and Application Process

In Part 1, we established that a Kenya VASP licence is determined by the substance of the proposed business.

Before applying, a founder must identify:

  • the services the company will provide;
  • whether the business falls under CBK, CMA or both;
  • which virtual asset activities require authorisation;
  • whether more than one licence category applies; and
  • whether an offshore business is targeting or deriving income from Kenya.

Once the correct licensing route has been identified, the next challenge begins.

The applicant must prove that it is capable of operating a regulated virtual asset business safely, honestly and sustainably.

This is where many founders underestimate the licensing process.

A Kenya VASP licence application is not simply a form supported by a business plan and incorporation certificate. It is an institutional readiness assessment.

The relevant regulator will examine whether the applicant has:

  • transparent ownership;
  • competent management;
  • sufficient capital;
  • lawful funding;
  • appropriate governance;
  • operationally relevant policies;
  • effective AML controls;
  • secure technology;
  • tested cybersecurity systems;
  • adequate customer-asset safeguards;
  • reliable business continuity arrangements; and
  • enough financial and human resources to operate after approval.

This Part 2 explains the complete Kenya VASP licence requirements and how a serious applicant should prepare for regulatory scrutiny.

1. The Kenya VASP Licence Application Package

An application to conduct one or more permissible virtual asset activities must be made in the prescribed form and submitted to the appropriate regulatory authority.

The final Regulations require a substantial body of information and supporting evidence, including:

  • personal and professional details of directors, senior officers, significant shareholders and beneficial owners;
  • a regulatory business plan;
  • completed fit-and-proper assessment forms;
  • proof of source of funds;
  • descriptions of systems and controls;
  • operational policies;
  • material contracts and oversight arrangements;
  • evidence of paid-up and liquid capital;
  • audited or opening financial statements;
  • evidence of adequate human and technology resources;
  • an independent information systems audit;
  • vulnerability-assessment and penetration-test reports;
  • information concerning cross-border operations and foreign regulatory status;
  • activity-specific business rules;
  • market-integrity controls;
  • details of the virtual assets to be offered;
  • incorporation and ownership records;
  • beneficial ownership records;
  • principal office and website information; and
  • proof of payment of the application fee.

The list is extensive because the regulator is not assessing an abstract business idea.

It is assessing a company that proposes to become part of Kenya’s regulated financial and digital-asset ecosystem.

2. Corporate Eligibility and Legal Structure

An applicant must ordinarily be:

  • a company limited by shares incorporated under Kenya’s Companies Act; or
  • a foreign company limited by shares that has been duly registered in Kenya.

The legal entity applying for the licence should be the entity that will genuinely conduct the regulated business.

That entity should normally:

  • contract with customers;
  • employ or formally engage key personnel;
  • own or lawfully use the technology;
  • receive the relevant revenue;
  • maintain the required capital;
  • enter into material outsourcing agreements;
  • bear the regulatory obligations; and
  • exercise operational control over the licensed activity.

A common structuring mistake occurs where one entity applies for the licence but another group company performs most of the actual business.

For example:

  • the Kenyan applicant signs the customer agreement;
  • an offshore affiliate controls the platform;
  • another entity holds customer assets;
  • a third company earns the fees; and
  • The local board has little influence over any of them.

Such a structure may raise questions about whether the proposed licensee has genuine substance, operational control and financial independence.

What the regulator will want to understand

The ownership and group structure should clearly show:

  • the immediate shareholders;
  • significant shareholders;
  • ultimate beneficial owners;
  • parent companies;
  • sister companies;
  • subsidiaries;
  • voting rights;
  • economic interests;
  • nominee arrangements;
  • shareholder loans;
  • intellectual-property ownership;
  • intra-group services; and
  • control over material decisions.

A significant shareholder includes a person holding, directly or indirectly, more than 10% of the applicant’s share capital.

However, persons holding less than 10% may still need to be disclosed where they exercise influence or control through voting arrangements, contractual rights or other means.

3. Beneficial Ownership Transparency

The regulator must be able to identify the real individuals who ultimately own or control the applicant.

A corporate chart that ends with another company, trust, partnership or nominee is not a complete beneficial ownership disclosure.

The application should trace ownership through every layer until it reaches the relevant natural persons.

The applicant may be required to provide:

  • certified corporate records;
  • registers of members;
  • registers of beneficial owners;
  • shareholder agreements;
  • trust documents;
  • nominee declarations;
  • identity documents;
  • residential-address evidence;
  • tax information;
  • organisational charts; and
  • explanations of voting and control arrangements.

Why complicated structures attract more scrutiny

A complex structure is not automatically unacceptable.

International groups often use holding companies, intellectual-property entities, operating subsidiaries and investment vehicles for legitimate commercial reasons.

The difficulty arises where the structure:

  • lacks a clear business rationale;
  • obscures beneficial ownership;
  • separates control from regulatory responsibility;
  • uses opaque jurisdictions;
  • contains dormant or shell entities;
  • creates circular ownership;
  • relies on undisclosed nominees; or
  • makes the source of invested funds difficult to verify.

The applicant should be prepared to explain not merely who owns each entity, but why the structure exists.

4. Fit-and-Proper Requirements

The fit-and-proper assessment is central to the Kenya VASP licensing process.

The regulator will assess the suitability of key persons connected to the applicant, including:

  • directors;
  • the chief executive officer;
  • senior officers;
  • significant shareholders; and
  • beneficial owners.

The assessment is designed to determine whether those persons have the integrity, competence and financial standing required to own, manage or control a regulated virtual asset business.

The Act establishes continuing fit-and-proper obligations, while the final Regulations prescribe detailed assessment forms and supporting information.

Areas considered during the assessment

The regulator may consider:

  • honesty and integrity;
  • professional reputation;
  • academic qualifications;
  • relevant industry experience;
  • management competence;
  • regulatory history;
  • criminal history;
  • civil litigation;
  • insolvency or bankruptcy;
  • financial soundness;
  • conflicts of interest;
  • prior directorships;
  • disciplinary proceedings;
  • tax compliance;
  • the person’s role in failed or sanctioned businesses; and
  • the time and capacity available to perform the proposed function.

The fit-and-proper requirement is not satisfied merely because a person has not been convicted of an offence.

The regulator may also assess whether the person:

  • has sufficient experience for the role;
  • understands the business model;
  • can challenge management effectively;
  • can oversee crypto-specific risks;
  • has demonstrated poor judgement in previous businesses; or
  • has been connected to regulatory misconduct elsewhere.

Management interviews

The regulator may require the applicant and key personnel to attend an interview.

During that interview, senior officers may be expected to explain:

  • the company’s products;
  • the customer journey;
  • custody arrangements;
  • AML controls;
  • transaction monitoring;
  • cybersecurity;
  • outsourcing;
  • complaints management;
  • capital maintenance;
  • liquidity;
  • governance; and
  • business continuity.

A director who cannot explain how the platform works may be viewed as a nominal appointment rather than a genuine decision-maker.

5. Source of Funds and Source of Wealth

The applicant must provide proof of the source of funds used to capitalise and finance the business.

This is different from merely showing that money arrived in the company’s bank account.

The regulator may want to understand:

  1. who provided the funds;
  2. how that person acquired the funds;
  3. how the funds moved through the financial system;
  4. whether the transaction is commercially genuine; and
  5. whether any part of the capital is linked to unlawful, opaque or high-risk activity.

Typical source-of-funds evidence

Depending on the origin of the money, evidence may include:

  • bank statements;
  • audited company accounts;
  • salary records;
  • dividend statements;
  • investment statements;
  • share-sale agreements;
  • property-sale agreements;
  • tax returns;
  • loan agreements;
  • inheritance documents;
  • business-income records; and
  • virtual asset wallet histories.

Where the capital originated from crypto, the applicant may also need to provide:

  • wallet addresses;
  • transaction hashes;
  • exchange statements;
  • blockchain-analytics reports;
  • evidence of the original purchase;
  • proof of wallet ownership; and
  • records linking the disposal proceeds to the applicant.

Shareholder loans

A shareholder loan may be commercially valid, but it should be properly documented.

The regulator may consider:

  • the identity of the lender;
  • the lender’s source of funds;
  • the repayment terms;
  • whether interest is payable;
  • whether repayment could weaken regulatory capital;
  • whether the loan creates hidden control rights; and
  • whether the business is excessively leveraged.

Paid-up capital should not be disguised debt.

Where the Regulations require fully paid ordinary share capital, the applicant must satisfy that requirement through genuine equity rather than relying entirely on loans.

6. The Regulatory Business Plan

The business plan is one of the most important documents in the Kenya VASP licence application.

It should explain how the company will operate as a regulated institution.

The Third Schedule requires the business plan to cover areas including:

  • executive summary;
  • corporate governance;
  • operational plan;
  • services to be offered;
  • technology and security infrastructure;
  • risk management;
  • compliance and internal controls;
  • financial projections;
  • market analysis;
  • fees and charges;
  • safeguarding of customer assets; and
  • implementation milestones.

A regulatory business plan is not an investor pitch

An investor presentation highlights:

  • market opportunity;
  • growth;
  • product differentiation;
  • customer acquisition; and
  • financial upside.

A regulatory business plan must also address:

  • risk;
  • governance;
  • control;
  • consumer protection;
  • capital adequacy;
  • financial sustainability;
  • system resilience;
  • compliance;
  • outsourcing; and
  • orderly wind-down.

A pitch deck may say:

“We will become East Africa’s leading crypto platform.”

A regulatory business plan must explain:

  • which services will be offered;
  • how customers will be onboarded;
  • how fiat and crypto will move;
  • who holds private keys;
  • how transactions will be monitored;
  • how customer assets will be reconciled;
  • what happens during a cyber incident;
  • how revenue is generated;
  • how the business remains capitalised; and
  • what happens if the company ceases operations.

Core components of the business plan

Business and market rationale

The applicant should explain:

  • why it is entering Kenya;
  • the customer problem being addressed;
  • its target market;
  • expected demand;
  • competitors;
  • distribution channels; and
  • expected market share.

Product description

Each proposed product should be described separately.

For every service, the application should explain:

  • the customer journey;
  • the parties involved;
  • the contractual structure;
  • the movement of fiat;
  • the movement of virtual assets;
  • custody;
  • settlement;
  • fees;
  • risks; and
  • controls.

Three-to-five-year projections

The financial model should normally include:

  • income statements;
  • statements of financial position;
  • cash-flow forecasts;
  • customer numbers;
  • transaction volumes;
  • transaction values;
  • revenue assumptions;
  • staffing costs;
  • technology costs;
  • compliance expenses;
  • capital plans; and
  • liquidity assumptions.

The assumptions should be internally consistent and commercially credible.

7. Governance Requirements

A licensed VASP must establish governance arrangements proportionate to its size, complexity and risk profile.

The final Regulations contain specific requirements concerning:

  • governance structures;
  • the board of directors;
  • the board’s responsibilities;
  • the chief executive officer;
  • finance officers;
  • internal auditors;
  • compliance;
  • risk management; and
  • conflicts of interest.

The board’s role

The board should not exist only to approve documents prepared by consultants.

It should be able to oversee:

  • business strategy;
  • regulatory compliance;
  • capital and liquidity;
  • risk appetite;
  • AML/CFT/CPF;
  • cybersecurity;
  • consumer protection;
  • outsourcing;
  • internal controls;
  • financial reporting;
  • complaints;
  • business continuity; and
  • senior management performance.

The board should receive regular management information and be able to challenge the executive team.

Board composition

The appropriate composition will depend on the activity.

A simple investment-advisory firm may require a different governance structure from:

  • a crypto exchange;
  • a custodial wallet provider;
  • a token issuance platform; or
  • a stablecoin issuer.

The applicant should consider whether the board collectively possesses experience in:

  • financial services;
  • virtual assets;
  • compliance;
  • risk;
  • technology;
  • cybersecurity;
  • finance;
  • audit; and
  • consumer protection.

Chief executive officer

The CEO must have genuine authority and responsibility for the business.

The role should not be performed by a person who:

  • rarely engages with the company;
  • lacks knowledge of the platform;
  • is appointed only to satisfy local substance expectations; or
  • is unable to make meaningful operational decisions.

8. Human Resources and Key Control Functions

The applicant must demonstrate that it has sufficient qualified personnel to conduct the proposed business.

The final Regulations expressly require evidence of adequate human and technology resources.

Depending on the licence category, the team may include:

  • chief executive officer;
  • compliance officer;
  • money laundering reporting officer;
  • finance officer;
  • risk manager;
  • internal auditor;
  • cybersecurity officer;
  • technology lead;
  • operations manager;
  • customer-service personnel;
  • legal personnel; and
  • market-surveillance specialists.

Proportionality does not mean minimalism

A startup may have a leaner structure than a large exchange.

However, the proposed staffing must be credible when measured against:

  • expected customer numbers;
  • transaction volumes;
  • supported virtual assets;
  • geographic exposure;
  • operating hours;
  • outsourcing arrangements;
  • technology complexity; and
  • financial-crime risk.

One person should not be assigned multiple incompatible roles merely to reduce cost.

For example, combining business development, compliance, internal audit and transaction approval in one individual may undermine independence and create conflicts of interest.

9. Required Operational Policies

The final Regulations require an applicant to submit a comprehensive set of operational policies.

These include:

  • risk management policy;
  • AML/CFT/CPF policy;
  • data protection and privacy policy;
  • cybersecurity and information technology policy;
  • complaints management policy;
  • market conduct policy;
  • consumer protection policy;
  • conflicts of interest policy; and
  • business continuity and disaster recovery plan.

The applicant may also require activity-specific policies, such as:

  • token listing and delisting policy;
  • custody policy;
  • wallet-management policy;
  • stablecoin reserve policy;
  • redemption policy;
  • order-execution policy;
  • market-surveillance policy;
  • outsourcing policy;
  • personal-account dealing policy;
  • sanctions policy;
  • transaction-monitoring procedure;
  • incident-reporting procedure; and
  • wind-down plan.

Policies must reflect the actual business

A generic policy is not useful merely because it contains regulatory language.

Each policy should correspond with:

  • the business plan;
  • system architecture;
  • customer agreement;
  • operational procedures;
  • organisational structure;
  • service-provider contracts;
  • risk assessment; and
  • financial model.

For example, an AML policy should not state that all customer transactions occur through individual wallets if the platform actually uses an omnibus wallet.

Similarly, a custody policy should not claim that assets are held in cold storage where most assets are operationally maintained in hot wallets.

10. AML/CFT/CPF Requirements

A VASP must establish effective controls for anti-money laundering, counter-terrorist financing and counter-proliferation financing.

The framework should operate throughout the customer lifecycle.

Customer onboarding

Before onboarding a customer, the VASP should perform appropriate customer due diligence.

The process may involve:

  • identification;
  • identity verification;
  • address verification;
  • beneficial ownership;
  • sanctions screening;
  • politically exposed person screening;
  • customer risk classification;
  • source-of-funds assessment; and
  • enhanced due diligence for higher-risk customers.

Corporate customers may require additional review of:

  • incorporation records;
  • directors;
  • shareholders;
  • beneficial owners;
  • business activities;
  • licences;
  • expected transaction patterns; and
  • source of wealth.

Transaction monitoring

The applicant should explain how it will identify suspicious activity across:

  • fiat transactions;
  • virtual asset transfers;
  • deposits;
  • withdrawals;
  • exchange activity;
  • linked accounts;
  • merchant transactions;
  • blockchain addresses; and
  • cross-border flows.

Crypto-specific red flags may include:

  • exposure to mixers;
  • sanctioned wallets;
  • stolen funds;
  • darknet marketplaces;
  • rapid chain hopping;
  • high-risk peer-to-peer activity;
  • structuring of deposits;
  • use of multiple accounts;
  • transactions inconsistent with the customer profile; and
  • movement through unregulated exchanges.

Travel Rule

The business should establish a process for exchanging required originator and beneficiary information when transferring virtual assets to or from other VASPs.

The framework should address:

  • counterparty identification;
  • Travel Rule data transmission;
  • data security;
  • unhosted wallets;
  • failed data transmission;
  • high-risk counterparties;
  • record keeping; and
  • transaction rejection or escalation.

11. Technology and Cybersecurity Requirements

Technology is a substantive part of the application.

The applicant must submit an independent information systems audit report that includes:

  • a vulnerability assessment; and
  • a penetration test.

The assessment must be prepared by a person with appropriate qualifications and competence.

The final Regulations also impose dedicated obligations relating to:

  • cybersecurity strategy;
  • systems and controls;
  • cybersecurity audits;
  • cybersecurity-risk reporting; and
  • audit reports.

Areas likely to be assessed

The cybersecurity review may cover:

  • network architecture;
  • cloud infrastructure;
  • wallet architecture;
  • private-key management;
  • access controls;
  • multi-factor authentication;
  • encryption;
  • transaction authorisation;
  • privileged access;
  • system logging;
  • data retention;
  • incident monitoring;
  • patch management;
  • secure software development;
  • third-party integrations;
  • backup;
  • disaster recovery; and
  • system availability.

Wallet security

For businesses holding customer assets, particular attention should be given to:

  • hot and cold wallet allocation;
  • private-key generation;
  • key storage;
  • multi-signature arrangements;
  • withdrawal approvals;
  • whitelisting;
  • key rotation;
  • wallet reconciliation;
  • recovery procedures;
  • access segregation; and
  • emergency controls.

Remediation before filing

A penetration-test report containing unresolved critical vulnerabilities can materially weaken an application.

The applicant should:

  1. identify vulnerabilities;
  2. classify them by severity;
  3. implement remediation;
  4. retest the system;
  5. document closure; and
  6. explain any accepted residual risks.

The regulator should not be expected to accept promises that major security weaknesses will be fixed after licensing.

12. Business Continuity and Disaster Recovery

A VASP must prepare for disruption.

Its business continuity and disaster recovery framework should address scenarios such as:

  • cyberattacks;
  • cloud-service failure;
  • wallet compromise;
  • loss of key personnel;
  • liquidity disruption;
  • payment-partner failure;
  • custodian failure;
  • blockchain congestion;
  • market disruption;
  • data loss;
  • office closure; and
  • telecommunications outages.

The plan should identify:

  • critical systems;
  • critical functions;
  • recovery priorities;
  • recovery-time objectives;
  • recovery-point objectives;
  • alternate service providers;
  • communication procedures;
  • escalation responsibilities;
  • customer-notification processes; and
  • regulatory-reporting procedures.

A policy that merely states that the company will restore services “as soon as possible” is unlikely to demonstrate adequate operational preparedness.

13. Consumer Protection Requirements

Consumer protection is a central feature of Kenya’s VASP framework.

The final Regulations include detailed rules on:

  • consumer-protection strategy;
  • consumer service agreements;
  • management and safekeeping of customer assets;
  • systems and controls;
  • protection from third-party claims;
  • records and accounts;
  • risk understanding;
  • complaints; and
  • customer-care systems.

Customer service agreement

The agreement should clearly explain:

  • the services provided;
  • the legal entity providing them;
  • customer eligibility;
  • supported virtual assets;
  • fees and charges;
  • execution arrangements;
  • custody;
  • settlement;
  • withdrawal procedures;
  • customer responsibilities;
  • risks;
  • complaints;
  • termination;
  • suspension;
  • liability; and
  • dispute resolution.

The agreement should be consistent with the actual technology and operational model.

Risk disclosures

Customers should understand material risks, including:

  • market volatility;
  • loss of value;
  • blockchain failure;
  • forks;
  • cyberattacks;
  • private-key risks;
  • smart-contract vulnerabilities;
  • liquidity risk;
  • counterparty failure;
  • regulatory change;
  • irreversible transactions; and
  • service disruption.

Risk warnings should be prominent and understandable, not buried in legal terms.

14. Safeguarding Customer Assets

Where the applicant holds customer fiat or virtual assets, it must establish robust safeguarding arrangements.

The framework should cover:

  • segregation of customer and company assets;
  • reconciliation;
  • wallet records;
  • bank-account arrangements;
  • access controls;
  • custody providers;
  • withdrawal approvals;
  • third-party claims;
  • insolvency treatment;
  • proof of ownership;
  • incident response; and
  • record keeping.

Segregation

The VASP should be able to demonstrate that customer assets are not treated as the company’s own assets.

The firm should not use customer assets to:

  • finance operations;
  • meet corporate liabilities;
  • make unauthorised investments;
  • provide loans;
  • support proprietary trading; or
  • satisfy claims against the business.

Reconciliation

The company should be able to reconcile:

  • individual customer balances;
  • omnibus wallet balances;
  • bank balances;
  • blockchain records;
  • internal ledgers; and
  • custodian records.

Reconciliation procedures should identify shortages promptly and require investigation and escalation.

Third-party custody

Outsourcing custody does not remove the licensee’s responsibility.

The applicant should assess:

  • the custodian’s regulatory status;
  • security controls;
  • financial standing;
  • jurisdiction;
  • insurance;
  • asset segregation;
  • insolvency arrangements;
  • audit rights;
  • incident reporting; and
  • termination support.

15. Market Integrity and Conflicts of Interest

The application must demonstrate that the business can prevent or manage market abuse.

This is particularly important for exchanges, brokers, token issuance platforms and businesses dealing with virtual asset offerings.

Relevant controls may include:

  • market surveillance;
  • insider lists;
  • employee-dealing rules;
  • trade monitoring;
  • order-book monitoring;
  • manipulation alerts;
  • listing controls;
  • issuer due diligence;
  • restricted lists;
  • conflict disclosures;
  • escalation procedures; and
  • disciplinary measures.

The final Regulations address misconduct including:

  • insider dealing;
  • market manipulation;
  • false trading;
  • market rigging;
  • fraudulent inducement;
  • manipulative devices;
  • misleading statements;
  • front-running;
  • churning; and
  • cold calling.

Typical conflicts in a crypto business

Conflicts may arise where the VASP:

  • trades against its customers;
  • lists its own token;
  • receives listing fees from issuers;
  • provides custody and proprietary trading;
  • operates an exchange and acts as market maker;
  • provides investment advice on assets it holds;
  • earns higher fees from certain products;
  • gives preferential access to affiliates; or
  • allows employees to trade before customers.

These conflicts should be identified before launch and supported by appropriate restrictions, disclosures and controls.

16. Outsourcing and Third-Party Service Providers

Most crypto businesses rely heavily on third parties.

These may include:

  • cloud providers;
  • custodians;
  • liquidity providers;
  • banks;
  • payment processors;
  • KYC vendors;
  • blockchain-analytics firms;
  • Travel Rule providers;
  • software developers;
  • cybersecurity firms;
  • customer-support providers; and
  • data-hosting providers.

The applicant must disclose relevant contracts and arrangements for oversight of outsourced activities.

The outsourcing framework should consider:

  • due diligence;
  • regulatory status;
  • financial stability;
  • data access;
  • cybersecurity;
  • service levels;
  • audit rights;
  • subcontracting;
  • business continuity;
  • incident notification;
  • termination;
  • data return;
  • migration support; and
  • concentration risk.

Outsourcing a critical function does not outsource regulatory accountability.

The licensed VASP remains responsible for ensuring that the outsourced service is performed properly.

17. Application Consistency: The Hidden Licensing Requirement

The Regulations prescribe many individual documents, but one of the most important practical requirements is consistency.

Every document should describe the same business.

The following should align:

  • application form;
  • business plan;
  • financial model;
  • corporate structure;
  • customer terms;
  • AML policy;
  • custody policy;
  • system architecture;
  • outsourcing agreements;
  • website;
  • marketing materials; and
  • management interview responses.

Examples of damaging inconsistencies

Custody contradiction

The business plan says the company does not hold customer assets, but the system diagram shows all customer deposits entering a wallet controlled by the applicant.

Revenue contradiction

The application describes a technology-subscription model, but the financial forecast shows income from trading spreads.

Outsourcing contradiction

The customer agreement says assets are held by a third-party custodian, but no executed custody agreement exists.

Capital contradiction

The application states that shareholder funds are equity, while the financial statements record them as repayable loans.

Product contradiction

The application seeks an exchange licence, but the website also advertises wallet custody, crypto payments and managed portfolios.

These inconsistencies may suggest that the applicant has not fully understood or finalised its own business model.

18. A Practical Kenya VASP Licensing-Readiness Checklist

Before submitting the application, the applicant should be able to answer “yes” to the following questions.

Corporate structure

  • Is the applicant eligible?
  • Are all beneficial owners identified?
  • Is the group structure transparent?
  • Does the applicant genuinely control the licensed business?
  • Are intra-group arrangements documented?

Management

  • Are directors and senior officers fit and proper?
  • Do they understand the business?
  • Are key control functions adequately staffed?
  • Are reporting lines clear?
  • Are conflicts properly managed?

Finance

  • Is the required paid-up capital available?
  • Is any liquid-capital requirement satisfied?
  • Is the source of funds documented?
  • Is there sufficient operating runway?
  • Are the projections realistic?

Compliance

  • Is the AML framework tailored to the business?
  • Are KYC and sanctions-screening systems operational?
  • Is blockchain monitoring in place?
  • Is the Travel Rule addressed?
  • Are suspicious transaction procedures established?

Technology

  • Is the platform sufficiently developed?
  • Has an independent systems audit been completed?
  • Has penetration testing been completed?
  • Have critical vulnerabilities been remediated?
  • Are incident-response and disaster-recovery plans tested?

Consumer protection

  • Are customer assets segregated?
  • Are reconciliations reliable?
  • Are customer terms accurate?
  • Are risks clearly disclosed?
  • Is a complaints process operational?

Documentation

  • Are all required policies complete?
  • Are material contracts executed?
  • Does the business plan match the actual model?
  • Are all documents internally consistent?
  • Can management defend the application during an interview?

Where the answer to several of these questions is “no”, the applicant is not ready to submit.

Conclusion to Part 2: The Regulator Is Licensing an Institution, Not a Document Pack

A company does not become ready for a VASP licence in Kenya simply because it has drafted the required policies.

The regulator is assessing whether the applicant has built a real institution capable of managing virtual asset risks.

That requires alignment between:

  • ownership;
  • management;
  • funding;
  • capital;
  • governance;
  • technology;
  • compliance;
  • contracts;
  • customer protection; and
  • day-to-day operations.

A polished application will not compensate for:

  • opaque shareholders;
  • weak source-of-funds evidence;
  • nominal directors;
  • underdeveloped technology;
  • generic compliance policies;
  • unresolved cyber vulnerabilities;
  • inadequate working capital; or
  • contradictions in the business model.

The strongest applicants approach licensing as a business-building project.

They establish the controls before filing, test their systems before regulatory review and ensure that key officers can explain the business without relying on advisers.

In Part 3, we will complete this guide by examining:

  • Kenya VASP capital and liquidity requirements;
  • application, initial licence and renewal fees;
  • the true cost of obtaining a Kenya crypto licence;
  • the step-by-step application process;
  • the regulatory timeline;
  • grounds for rejection;
  • common licensing mistakes;
  • post-licensing obligations;
  • practical market-entry strategy;
  • frequently asked questions; and
  • how CRYPTOVERSE can support the complete licensing process.

FAQs

1. How much capital is required for a Kenya VASP licence?

The requirement depends on the activity. It ranges from no prescribed fixed minimum for a virtual asset investment adviser to KSh 300 million for a stablecoin issuer. Exchanges require KSh 100 million, wallet providers KSh 150 million, and brokers and payment processors KSh 10 million.

2. How much does a Kenya crypto licence cost?

The regulatory application and licence fees vary by category. The complete cost also includes capital, staffing, legal support, compliance systems, technology, cybersecurity testing, audit, insurance and operating expenses.

3. Can one company apply for several VASP activities?

Potentially, yes. The regulator must be satisfied that the company has suitable capital, infrastructure, controls, staffing and risk separation for the combined activities.

4. How long does the Kenya VASP application process take?

The regulator’s determination period applies after all required documents and information have been received and due diligence has been completed. The full project can take several months because structuring, capitalisation, policy drafting, systems testing and regulatory review must occur first.

5. Does the licence need to be renewed?

Yes. A Kenya VASP licence is renewed annually, and the renewal application must be submitted at least two months before expiry.