What Exchanges, Wallet Providers, Brokers, Payment Platforms and Crypto Startups Must Have Before Applying
A crypto founder can have an impressive product and still be unprepared for licensing.
The application may look polished. The platform may process transactions quickly. The founders may have raised capital, signed a liquidity provider and recruited a technical team.
Yet the regulator may still ask questions the company cannot answer:
- Who controls the customer’s private keys?
- Where are customer assets held?
- How is regulatory capital protected?
- Who is responsible for suspicious transaction reporting?
- What happens if the platform is hacked?
- Can the board explain the business model?
- Are the shareholders’ funds traceable?
- Does the company have enough money to operate after paying its licensing costs?
- Do the business plan, customer agreement and technical architecture describe the same service?
These are not secondary questions.
They sit at the centre of the Kenya crypto licence requirements.
Kenya regulates virtual asset businesses under the Virtual Asset Service Providers Act, 2025, which commenced on 4 November 2025, and the Virtual Asset Service Providers Regulations, 2026. Together, these instruments establish the licensing, governance, financial, operational, technological and conduct requirements applicable to virtual asset service providers operating in or targeting Kenya.
This guide provides a practical Kenya VASP compliance checklist for 2026. It is designed for:
- crypto exchanges;
- custodial wallet providers;
- virtual asset brokers;
- crypto payment processors;
- investment advisers and managers;
- tokenisation businesses;
- token issuance platforms;
- initial coin offering providers;
- stablecoin issuers; and
- foreign VASPs seeking access to the Kenyan market.
The central lesson is simple:
A Kenya VASP licence application is not merely a collection of documents. It is evidence that the applicant has built a regulated institution capable of protecting customers, assets and the integrity of the market.
1. Regulatory Perimeter Checklist
Before preparing a licence application, the company must establish exactly what it intends to do.
This is the first and most important compliance exercise.
The Virtual Asset Service Providers Act regulates commercial activities involving virtual asset exchange, transfer, custody, payments, investment services, token issuance and related services. The correct licence is determined by the substance of the activity rather than the label used by the business.
Confirm every customer-facing service
The applicant should prepare a complete list of products and identify whether it will:
- exchange fiat currency for virtual assets;
- exchange one virtual asset for another;
- operate an order book;
- match buyers and sellers;
- arrange OTC transactions;
- quote prices or earn trading spreads;
- hold customer private keys;
- provide wallet recovery;
- receive or transmit virtual assets;
- process merchant payments;
- convert crypto into Kenyan shillings;
- advise customers on virtual asset investments;
- manage virtual asset portfolios;
- issue tokens;
- operate a token launchpad;
- tokenise real-world assets; or
- issue or redeem a stablecoin.
Map the full transaction flow
For each product, identify:
- the contracting entity;
- the customer;
- the bank or payment partner;
- the liquidity provider;
- the wallet or custodian;
- the fiat flow;
- the virtual asset flow;
- the party controlling private keys;
- the party executing the transaction;
- the settlement mechanism;
- the fee recipient; and
- the party responsible for complaints and refunds.
Check whether more than one licence applies
A platform may perform several regulated activities.
For example, an application that allows customers to deposit Kenyan shillings, buy USDT, hold it in a hosted wallet and exchange it for Bitcoin may combine:
- virtual asset payment processing;
- custodial wallet services; and
- virtual asset exchange services.
The company should not assume that one permission automatically covers every feature on the platform.
Compliance checkpoint
Before proceeding, the applicant should be able to answer:
- What exact regulated services will we provide?
- Which features will be provided by third parties?
- Which features will the applicant control?
- Which services will be available at launch?
- Which services may be added later?
- Does the proposed licence cover every customer journey?
2. Regulator and Licence-Category Checklist
Kenya uses a dual-regulator framework involving the Central Bank of Kenya and the Capital Markets Authority.
The allocation depends on the regulated activity.
Central Bank of Kenya activities
CBK is responsible for activities including:
- virtual asset wallet services;
- virtual asset payment processing; and
- stablecoin issuance.
Capital Markets Authority activities
CMA is responsible for activities including:
- virtual asset exchanges;
- virtual asset brokerage;
- virtual asset investment advice;
- virtual asset management;
- initial coin offerings;
- virtual asset tokenisation; and
- token issuance platforms.
These allocations arise from the statutory licensing framework established under the Act and implemented through the 2026 Regulations.
Correct classification questions
An exchange applicant should ask:
- Do we match customer orders?
- Do we operate an order book or request-for-quotation system?
- Do we determine or display prices?
- Do we purchase assets from sellers and resell them to buyers?
- Do we control customer assets during trading?
A broker applicant should ask:
- Do we receive customer trade instructions?
- Do we source assets from liquidity providers?
- Do we arrange or execute transactions?
- Do we earn a commission, markup or spread?
- Do we take principal risk?
A wallet applicant should ask:
- Do we hold or manage private keys?
- Can we freeze, recover or authorise transactions?
- Do we maintain omnibus wallets?
- Can we move customer assets without a separate customer signature?
A payment processor should ask:
- Do we receive payment instructions?
- Do we facilitate on-ramp or off-ramp transactions?
- Do we route virtual assets between customers and merchants?
- Do we arrange merchant settlements?
- Who is responsible if settlement fails?
Compliance checkpoint
The applicant should have:
- a written regulatory-perimeter assessment;
- confirmation of the correct regulator;
- confirmation of each required licence category;
- an analysis of overlapping activities;
- an outsourcing map; and
- a phased plan for any services that will not be included at launch.
3. Territorial Scope and Foreign-Company Checklist
An overseas business should not assume that it falls outside the Kenyan regime because it has no local office.
The 2026 Regulations extend to persons offering virtual asset services in or from Kenya, including businesses that target Kenyan consumers or derive income or economic benefit from Kenya, regardless of whether they have a physical presence in the country.
A foreign VASP may therefore enter the Kenyan regulatory perimeter where it:
- accepts Kenyan residents;
- supports Kenyan shilling payments;
- connects to local mobile-money services;
- advertises specifically to Kenya;
- engages Kenyan affiliates or influencers;
- maintains Kenya-specific customer support;
- works with Kenyan merchants;
- operates a Kenya-specific website or social-media page; or
- earns transaction income from Kenyan customers.
A foreign crypto licence does not automatically authorise Kenyan operations.
Foreign applicant checklist
A foreign applicant should confirm:
- whether it will incorporate a Kenyan company or register a foreign company;
- which entity will hold the licence;
- which entity will contract with Kenyan customers;
- where management decisions will be made;
- where technology and intellectual property are held;
- where customer assets will be custodied;
- whether cross-border data transfers are involved;
- whether offshore affiliates will provide critical services; and
- how the Kenyan licensee will retain genuine operational control.
4. Corporate Structure Checklist
A Kenya VASP applicant must use an eligible corporate vehicle and demonstrate that the proposed licensee is not merely an empty shell.
The applicant will generally need to be a company limited by shares incorporated in Kenya or an eligible foreign company registered under Kenyan company law. The licensing entity should be the company that genuinely conducts and controls the regulated business.
The applicant should ordinarily:
- enter into customer agreements;
- receive regulated revenue;
- maintain regulatory capital;
- employ or engage key personnel;
- own or lawfully use the platform;
- contract with banks, custodians and liquidity providers;
- oversee outsourced functions;
- maintain compliance systems;
- receive regulatory correspondence; and
- remain accountable for the licensed activities.
Corporate documents checklist
Prepare:
- certificate of incorporation or registration;
- constitutional documents;
- tax registration records;
- register of shareholders;
- register of directors;
- register of beneficial owners;
- board and shareholder resolutions;
- group structure chart;
- organisation chart;
- shareholder agreement;
- intra-group agreements;
- intellectual-property licences;
- local office details;
- principal website details; and
- details of trade names used by the business.
Avoid structural inconsistencies
The application may be weakened where:
- the Kenyan entity is described as the operator but an offshore affiliate earns the fees;
- the applicant claims to control the platform but has no enforceable technology licence;
- customer assets are held by an undisclosed group company;
- senior management sits outside the applicant and has no formal reporting line;
- the licensee has no employees, systems or independent decision-making authority.
Compliance checkpoint
Ask:
- Is the licence applicant the true operating entity?
- Does it control the regulated services?
- Does it have contractual rights to the technology?
- Can the board direct outsourced providers?
- Does it have enough substance to discharge its legal duties?
5. Ownership and Beneficial Ownership Checklist
The regulator must be able to identify every person who owns, controls or materially influences the applicant.
The application should disclose:
- direct shareholders;
- indirect shareholders;
- significant shareholders;
- ultimate beneficial owners;
- directors;
- senior officers;
- parent companies;
- affiliates;
- nominee arrangements;
- trust interests;
- voting agreements; and
- other control rights.
Supporting evidence
The applicant may need:
- certified identity documents;
- residential-address evidence;
- corporate registry extracts;
- shareholder registers;
- beneficial ownership registers;
- trust deeds;
- nominee declarations;
- shareholder agreements;
- voting agreements;
- tax records;
- ownership charts; and
- explanations of each intermediate entity.
Risk factors
Expect more scrutiny where the structure includes:
- several offshore holding companies;
- nominees;
- trusts;
- opaque jurisdictions;
- dormant entities;
- circular ownership;
- unexplained minority control rights;
- bearer-like arrangements;
- politically exposed persons; or
- investors whose source of wealth is difficult to verify.
Complexity is not automatically prohibited. It must, however, have a credible commercial rationale and remain fully transparent.
Compliance checkpoint
The ownership chart should end with natural persons, not another company.
6. Fit-and-Proper Checklist
Directors, senior officers, significant shareholders and beneficial owners must be suitable to own, control or manage a regulated virtual asset business.
The assessment may consider:
- honesty and integrity;
- professional reputation;
- competence;
- academic and technical qualifications;
- relevant industry experience;
- financial soundness;
- criminal records;
- civil litigation;
- insolvency or bankruptcy;
- regulatory investigations;
- licence refusals or cancellations;
- disciplinary proceedings;
- tax compliance;
- conflicts of interest; and
- involvement in failed or sanctioned businesses.
The final Regulations require fit-and-proper information and supporting records as part of the licence application, and the regulator may require relevant persons to attend interviews.
Individual file checklist
For each key person, prepare:
- completed fit-and-proper form;
- curriculum vitae;
- passport or identification document;
- residential-address evidence;
- academic certificates;
- professional qualifications;
- employment references;
- police-clearance or criminal-record documents where required;
- financial standing evidence;
- regulatory declarations;
- litigation and insolvency disclosures;
- directorship history;
- conflict-of-interest declaration; and
- explanation of the person’s proposed responsibilities.
Management readiness
A fit-and-proper person must also understand the business.
The CEO, directors and compliance personnel should be able to explain:
- the customer journey;
- transaction flows;
- custody;
- AML controls;
- supported assets;
- cyber risk;
- capital requirements;
- complaints;
- outsourcing; and
- business continuity.
Nominal appointments are a major risk. A director who has lent their name to the application but cannot explain the business may undermine regulatory confidence.
7. Governance Checklist
A licensed VASP requires governance arrangements proportionate to its size, activities and risk profile.
The governance framework should establish clear accountability between:
- shareholders;
- the board;
- the chief executive officer;
- compliance;
- risk;
- finance;
- technology;
- operations;
- cybersecurity; and
- internal audit.
Board checklist
The board should:
- approve business strategy;
- approve the risk appetite;
- oversee regulatory compliance;
- monitor capital and liquidity;
- supervise AML/CFT/CPF controls;
- oversee cybersecurity;
- review customer-asset safeguarding;
- approve material outsourcing;
- monitor complaints and consumer outcomes;
- review management information;
- address conflicts of interest; and
- supervise senior management.
Governance documents
Prepare:
- board charter;
- committee terms of reference;
- governance policy;
- delegation of authority matrix;
- reserved-matters schedule;
- reporting lines;
- management committee structure;
- conflicts register;
- board calendar;
- meeting templates;
- management-information reports; and
- succession arrangements.
Independence and segregation
The business should avoid incompatible combinations of roles.
For example, the same person should not ordinarily:
- lead sales;
- approve high-risk customers;
- conduct compliance monitoring;
- investigate their own decisions; and
- perform an internal audit.
A startup may operate with a lean structure, but proportionality does not justify ineffective independence.
8. Staffing and Human-Resources Checklist
The regulator will expect the applicant to have enough competent personnel to operate safely.
Depending on the licence, required functions may include:
- chief executive officer;
- compliance officer;
- money laundering reporting officer;
- finance officer;
- risk manager;
- technology lead;
- cybersecurity officer;
- operations manager;
- customer-support team;
- market-surveillance personnel; and
- internal auditor.
Staffing plan
The applicant should document:
- job descriptions;
- reporting lines;
- qualifications;
- recruitment status;
- employment or consultancy terms;
- time commitment;
- residency and location;
- succession plans;
- performance indicators;
- training requirements; and
- conflicts of interest.
Capacity analysis
Staffing should be assessed against:
- expected customer numbers;
- transaction volumes;
- supported jurisdictions;
- number of virtual assets;
- operating hours;
- custody structure;
- outsourcing;
- customer-risk profile;
- technology complexity; and
- regulatory-reporting burden.
A business projecting hundreds of thousands of customers but employing one compliance officer and no transaction-monitoring team may not present a credible operating model.
9. Capital and Financial-Resources Checklist
The 2026 Regulations prescribe minimum paid-up capital requirements according to the licence category.
| Licence category | Minimum paid-up capital |
| Virtual Asset Investment Adviser | No prescribed fixed minimum |
| Virtual Asset Broker | KSh 10 million |
| Virtual Asset Payment Processor | KSh 10 million |
| Virtual Asset Tokenisation Provider | KSh 10 million |
| Virtual Asset Manager | KSh 20 million |
| Initial Coin Offering Provider | KSh 20 million |
| Token Issuance Platform | KSh 20 million |
| Virtual Asset Exchange | KSh 100 million |
| Virtual Asset Wallet Provider | KSh 150 million |
| Stablecoin Issuer | KSh 300 million |
These are regulatory minima rather than complete startup budgets. Certain categories are also subject to liquid-capital requirements.
Capital evidence checklist
Prepare:
- bank statements;
- share allotment documents;
- shareholder resolutions;
- updated shareholder register;
- audited or opening financial statements;
- accountant or auditor confirmations;
- source-of-funds documents;
- evidence that shares are fully paid;
- capital-maintenance calculations; and
- liquidity calculations where applicable.
Operational runway
The applicant should separately budget for:
- staff salaries;
- premises;
- legal and compliance support;
- technology;
- KYC and sanctions systems;
- blockchain analytics;
- cybersecurity;
- systems audit;
- penetration testing;
- insurance;
- banking and custody costs;
- audit;
- regulatory fees; and
- contingency funding.
Meeting the paid-up capital threshold on the filing date is not enough. The company must remain adequately capitalised after incurring launch and operating costs.
10. Source of Funds and Source of Wealth Checklist
The regulator will examine how the company was funded.
The applicant should identify:
- the investor;
- the amount contributed;
- whether the contribution is equity or debt;
- how the investor acquired the money;
- how the money moved into the applicant;
- whether any third party was involved; and
- whether the transaction is consistent with the investor’s known financial profile.
Evidence may include:
- bank statements;
- audited accounts;
- payslips;
- employment records;
- dividend statements;
- investment statements;
- property-sale agreements;
- share-sale agreements;
- tax returns;
- inheritance records;
- loan agreements; and
- business-income documentation.
Crypto-derived funds
Where investment capital originated from virtual assets, prepare:
- wallet addresses;
- transaction hashes;
- exchange account statements;
- evidence of wallet ownership;
- blockchain tracing reports;
- original acquisition evidence;
- conversion records;
- bank deposit records; and
- a complete narrative linking acquisition, disposal and investment.
Unexplained deposits, temporary transfers and undocumented third-party funding can materially delay the application.
11. Regulatory Business Plan Checklist
The regulatory business plan is one of the most important application documents.
It must explain the proposed institution, not merely promote the commercial opportunity.
The Regulations require applicants to submit a business plan alongside information concerning governance, systems, controls, resources, financial position and the proposed virtual asset services.
Required content
The business plan should cover:
- executive summary;
- regulatory activities;
- products and services;
- target customers;
- market analysis;
- corporate structure;
- governance;
- management team;
- customer onboarding;
- transaction flows;
- custody;
- settlement;
- outsourcing;
- technology architecture;
- AML/CFT/CPF;
- cybersecurity;
- consumer protection;
- risk management;
- safeguarding;
- fees and revenue;
- financial projections;
- capital and liquidity;
- implementation plan;
- business continuity; and
- orderly wind-down.
Product-by-product analysis
For each product, explain:
- who the customer is;
- what the customer requests;
- what the applicant does;
- which third parties participate;
- where fiat moves;
- where crypto moves;
- who holds private keys;
- how fees are charged;
- which risks arise;
- how those risks are controlled.
Financial projections
Prepare credible projections for at least the relevant planning period, covering:
- customers;
- transaction volumes;
- revenue;
- staff costs;
- compliance costs;
- technology expenditure;
- audit expenses;
- cash flow;
- capital;
- liquidity;
- profitability; and
- downside scenarios.
12. AML/CFT/CPF Checklist
Virtual asset businesses face distinctive financial-crime risks.
The applicant’s AML/CFT/CPF framework should be tailored to its products, customers, jurisdictions, assets and delivery channels.
The Act forms part of Kenya’s broader anti-money laundering framework, while the Regulations require VASPs to implement detailed compliance systems and controls.
Governance
The company should have:
- board-approved AML policy;
- appointed money laundering reporting officer;
- enterprise-wide risk assessment;
- customer-risk methodology;
- escalation procedures;
- independent compliance monitoring;
- employee training;
- suspicious transaction procedures; and
- record-retention standards.
Customer due diligence
The onboarding process should cover:
- identity;
- identity verification;
- residential address;
- beneficial ownership;
- purpose of the relationship;
- expected transaction activity;
- sanctions screening;
- politically exposed person screening;
- source of funds;
- source of wealth where appropriate;
- customer-risk rating; and
- enhanced due diligence.
Transaction monitoring
Monitoring should address both fiat and blockchain activity, including:
- unusual deposit patterns;
- structuring;
- rapid movement of assets;
- multiple linked accounts;
- sanctions exposure;
- mixers;
- darknet markets;
- stolen assets;
- high-risk exchanges;
- chain hopping;
- unusual peer-to-peer activity;
- inconsistent transaction behaviour; and
- transactions without a clear economic purpose.
Travel Rule
The VASP should establish procedures for:
- identifying originators and beneficiaries;
- transmitting required information;
- assessing counterparty VASPs;
- dealing with incomplete information;
- handling unhosted wallets;
- protecting Travel Rule data;
- rejecting or escalating high-risk transfers; and
- retaining records.
13. Technology and Cybersecurity Checklist
Technology readiness is a substantive licensing requirement.
The 2026 Regulations require applicants to provide an independent information systems audit, including vulnerability assessment and penetration testing, alongside cybersecurity and information-technology policies and controls.
Technology documentation
Prepare:
- system architecture diagram;
- data-flow diagram;
- wallet architecture;
- network architecture;
- cloud-services map;
- API inventory;
- user-access matrix;
- privileged-access controls;
- change-management process;
- software-development lifecycle;
- logging framework;
- monitoring arrangements;
- backup architecture; and
- disaster-recovery design.
Cybersecurity controls
The applicant should demonstrate:
- multi-factor authentication;
- encryption;
- role-based access;
- privileged-access management;
- secure coding;
- vulnerability management;
- patch management;
- malware protection;
- intrusion detection;
- security monitoring;
- incident response;
- data-loss prevention;
- third-party risk controls;
- penetration testing; and
- cyber-risk reporting.
Wallet security
A wallet or exchange should document:
- private-key generation;
- key storage;
- multi-signature arrangements;
- hot and cold wallet allocation;
- withdrawal approval;
- wallet whitelisting;
- key rotation;
- recovery procedures;
- emergency access;
- employee access;
- reconciliation; and
- incident containment.
Critical and high-risk findings should be remediated before filing. A report containing major unresolved weaknesses may demonstrate that the applicant is not ready to operate.
14. Consumer Protection and Customer Agreements Checklist
The customer must clearly understand:
- who provides the service;
- what service is being provided;
- the fees;
- custody arrangements;
- transaction execution;
- withdrawal rules;
- the risks;
- complaint procedures; and
- what happens if the relationship ends.
The final Regulations impose requirements concerning consumer agreements, risk understanding, complaints, customer care, asset safeguarding and protection from third-party claims.
Customer agreement checklist
Include:
- identity of the licensee;
- scope of services;
- customer eligibility;
- onboarding requirements;
- supported assets;
- fees and spreads;
- order-execution terms;
- settlement;
- custody;
- deposits and withdrawals;
- service suspension;
- transaction reversibility;
- customer responsibilities;
- risk disclosures;
- complaints;
- liability;
- data protection;
- termination; and
- dispute resolution.
Risk disclosures
Disclose material risks including:
- price volatility;
- total loss;
- liquidity shortages;
- blockchain failure;
- forks;
- cyberattacks;
- wallet compromise;
- smart-contract vulnerabilities;
- irreversible transactions;
- counterparty failure;
- regulatory change;
- stablecoin de-pegging; and
- service interruption.
Risk warnings should be visible and understandable rather than buried in lengthy legal wording.
15. Customer-Asset Safeguarding Checklist
Where the applicant holds customer fiat or virtual assets, it must establish strong safeguarding arrangements.
Required controls
The framework should address:
- segregation of customer and company assets;
- separate bank accounts where applicable;
- wallet segregation or reliable internal sub-ledgers;
- daily or periodic reconciliation;
- ownership records;
- withdrawal approvals;
- access controls;
- custodian due diligence;
- shortage identification;
- breach escalation;
- protection from creditor claims;
- insolvency treatment; and
- return of assets during wind-down.
Prohibited or high-risk practices
Customer assets should not be used to:
- finance the company’s operations;
- pay corporate creditors;
- fund proprietary trading;
- make unauthorised loans;
- collateralise company borrowing; or
- satisfy obligations unrelated to the customer.
Reconciliation
The VASP should be able to reconcile:
- individual customer balances;
- omnibus wallets;
- on-chain balances;
- bank balances;
- internal ledgers;
- pending transactions; and
- custodian statements.
16. Outsourcing Checklist
Crypto businesses rely heavily on third parties, but regulatory accountability remains with the licensee.
Typical outsourced providers include:
- cloud providers;
- custodians;
- liquidity providers;
- banks;
- payment processors;
- KYC vendors;
- sanctions-screening providers;
- blockchain-analytics firms;
- Travel Rule providers;
- software developers;
- customer-support providers; and
- cybersecurity firms.
Outsourcing file
For each material provider, prepare:
- due-diligence report;
- service agreement;
- service-level standards;
- data-protection assessment;
- cybersecurity assessment;
- regulatory-status verification;
- financial-standing review;
- business continuity assessment;
- audit rights;
- incident-notification terms;
- subcontracting restrictions;
- termination rights;
- migration plan; and
- oversight responsibility.
The applicant should also assess concentration risk where several critical services depend on one provider or jurisdiction.
17. Market Conduct and Conflicts Checklist
Exchanges, brokers, investment businesses and token platforms require controls against market abuse and conflicts of interest.
Market-integrity controls
These may include:
- trade surveillance;
- order-book monitoring;
- manipulation alerts;
- wash-trading detection;
- insider lists;
- restricted lists;
- personal-account dealing rules;
- employee pre-clearance;
- listing controls;
- issuer due diligence;
- escalation procedures; and
- investigation records.
Conflicts to assess
Consider whether the company:
- trades against customers;
- operates an exchange and market maker;
- lists its own token;
- receives issuer listing fees;
- advises on assets it owns;
- manages portfolios and provides custody;
- favours affiliated liquidity providers;
- gives preferential information to selected users; or
- permits employees to trade before customers.
Every material conflict should be avoided, controlled or transparently disclosed.
18. Business Continuity and Wind-Down Checklist
The company must be prepared for operational failure, cyber incidents and commercial distress.
Business continuity scenarios
Plan for:
- cyberattack;
- loss of wallet keys;
- cloud outage;
- payment-partner failure;
- banking disruption;
- custodian failure;
- blockchain congestion;
- loss of key staff;
- data corruption;
- office closure;
- liquidity pressure; and
- telecommunications failure.
Plan components
Include:
- critical functions;
- critical providers;
- recovery-time objectives;
- recovery-point objectives;
- backup arrangements;
- alternate providers;
- emergency responsibilities;
- customer communication;
- regulatory notification;
- testing schedule; and
- post-incident review.
Orderly wind-down
The wind-down plan should explain:
- how customers will be notified;
- how open positions will be handled;
- how assets will be returned;
- how records will be preserved;
- how creditors will be managed;
- how critical staff and vendors will be funded;
- how regulatory obligations will continue; and
- how the licence will be surrendered.
19. Application-Document Checklist
Before filing, confirm that the application package includes the required forms and supporting materials.
Core application documents
- prescribed application form;
- regulatory business plan;
- corporate records;
- ownership structure;
- beneficial ownership records;
- fit-and-proper forms;
- source-of-funds evidence;
- capital evidence;
- financial statements;
- financial projections;
- governance framework;
- AML/CFT/CPF policy;
- risk-management policy;
- cybersecurity policy;
- technology documentation;
- systems audit;
- vulnerability assessment;
- penetration-test report;
- data-protection policy;
- consumer-protection policy;
- complaints policy;
- conflicts policy;
- market-conduct policy;
- business continuity plan;
- outsourcing arrangements;
- customer agreements;
- activity-specific procedures;
- details of supported virtual assets;
- key-personnel records; and
- proof of payment of the application fee.
The exact package depends on the licence category and proposed activities.
20. Application Consistency Checklist
A hidden but critical licensing requirement is consistency.
Every document must describe the same business.
Cross-check:
- application form;
- business plan;
- financial projections;
- customer terms;
- website;
- product descriptions;
- technical diagrams;
- outsourcing contracts;
- custody policy;
- AML policy;
- organisation chart; and
- management interview answers.
Common contradictions
- The business plan says the wallet is non-custodial, but the company can recover customer keys.
- The application describes brokerage, but the platform matches customer orders.
- The customer agreement names a custodian that has not signed a contract.
- The financial model shows trading-spread revenue, while the application claims the company earns only software fees.
- The company says it does not hold customer assets, but funds pass through its wallets.
- The licence application covers exchange services, while the website also advertises payments and portfolio management.
Resolve contradictions before filing.
21. Post-Licensing Compliance Checklist
Licensing does not end compliance.
The licensed VASP must continue to maintain:
- required capital and liquidity;
- fit-and-proper management;
- effective governance;
- AML/CFT/CPF systems;
- sanctions controls;
- cybersecurity;
- safeguarding;
- consumer protection;
- complaints handling;
- market conduct;
- record keeping;
- audit;
- regulatory reporting;
- outsourcing oversight; and
- business continuity.
The licence must be renewed annually under the final regulatory framework, and the licensee must observe the prescribed renewal and ongoing supervisory requirements.
Compliance calendar
Maintain deadlines for:
- licence renewal;
- regulatory returns;
- audited financial statements;
- capital reporting;
- AML reports;
- cybersecurity audits;
- penetration testing;
- policy reviews;
- staff training;
- board meetings;
- vendor reviews;
- business continuity testing;
- complaints reporting; and
- beneficial ownership updates.
Material changes
The company should assess whether prior approval or notification is required before changing:
- shareholders;
- beneficial owners;
- directors;
- senior officers;
- business activities;
- custody arrangements;
- critical service providers;
- principal office;
- technology;
- capital structure; or
- customer terms.
Final Kenya Crypto Licence Readiness Scorecard
An applicant should not file until it can confidently answer “yes” to the following.
| Area | Key question |
| Regulatory perimeter | Have all regulated services been correctly identified? |
| Regulator | Is the correct CBK or CMA licensing route confirmed? |
| Applicant entity | Does the applicant genuinely control the business? |
| Ownership | Are all beneficial owners transparent? |
| Management | Are directors and officers fit, proper and competent? |
| Governance | Are responsibilities and reporting lines clear? |
| Capital | Is the minimum paid-up capital fully available? |
| Funding | Is source of funds and wealth documented? |
| Runway | Can the company fund at least its expected launch period? |
| Business plan | Does it accurately describe the complete model? |
| AML | Are customer and transaction controls operational? |
| Technology | Is the platform ready for independent review? |
| Cybersecurity | Have material vulnerabilities been remediated? |
| Safeguarding | Are customer fiat and virtual assets protected? |
| Consumer protection | Are terms, risks and complaints procedures clear? |
| Outsourcing | Are critical providers properly contracted and supervised? |
| Market conduct | Are conflicts and market-abuse risks controlled? |
| Continuity | Can the business recover or wind down safely? |
| Documentation | Is the complete application package available? |
| Consistency | Do all documents describe the same business? |
Several “no” answers indicate that the company requires remediation before submission.
How CRYPTOVERSE Can Help
CRYPTOVERSE Legal Consultancy can support exchanges, wallet providers, brokers, payment platforms, token businesses and international VASPs through the complete Kenya licensing process.
Our support may include:
- regulatory-perimeter assessments;
- CBK and CMA licence mapping;
- applicant and group structuring;
- beneficial ownership review;
- capital and liquidity planning;
- source-of-funds preparation;
- licensing-readiness assessments;
- regulatory business plans;
- financial projections;
- fit-and-proper applications;
- governance frameworks;
- AML/CFT/CPF policies;
- Travel Rule procedures;
- consumer-protection frameworks;
- custody and safeguarding documentation;
- customer agreements;
- outsourcing agreements;
- exchange and wallet operating rules;
- cybersecurity and systems-audit coordination;
- application preparation;
- regulatory responses;
- management interview preparation;
- approval-condition closure; and
- ongoing compliance support.
The objective is not merely to assemble documents.
It is to build an application in which the company’s legal structure, management, technology, capital, customer journey and compliance framework operate as one coherent regulated model.
Conclusion: Compliance Must Be Operational Before It Is Documented
The most common mistake in crypto licensing is treating compliance as a writing exercise.
A company hires advisers to prepare policies, places the documents in a virtual data room and assumes that the regulatory requirements have been satisfied.
But a policy cannot compensate for a missing control.
An AML policy is not effective if the transaction-monitoring system is not configured.
A custody policy is not credible if the company cannot identify who controls the keys.
A cybersecurity policy is not sufficient if penetration testing reveals unresolved critical vulnerabilities.
A governance framework is not meaningful if the directors do not understand the business.
A capital statement is not reliable if the funds were temporarily borrowed for the application.
Kenya’s crypto licensing framework requires applicants to demonstrate institutional readiness across:
- legal structure;
- ownership;
- management;
- capital;
- compliance;
- technology;
- custody;
- consumer protection;
- market conduct; and
- operational resilience.
The strongest applicant will be the one that can show not only that every required document exists, but that every policy has been translated into a functioning process, assigned to a responsible person, supported by appropriate technology and tested before regulatory submission.
That is the real meaning of compliance readiness in 2026..
FAQs
1. What are the main Kenya crypto licence requirements?
The principal requirements include an eligible corporate structure, transparent beneficial ownership, fit-and-proper directors and officers, regulatory capital, documented source of funds, a regulatory business plan, AML controls, secure technology, cybersecurity testing, consumer protection, customer-asset safeguarding and adequate operational resources.
2. Does every Kenya crypto licence require the same capital?
No. Minimum paid-up capital depends on the activity. An exchange, wallet provider and stablecoin issuer face substantially higher thresholds than a broker, payment processor or tokenisation provider.
3. Must the platform be operational before applying?
It does not necessarily need to be commercially live. However, it should generally be sufficiently developed to support independent systems auditing, vulnerability assessment, penetration testing, transaction-flow analysis and regulatory demonstration.
4. Can compliance functions be outsourced?
Certain functions may be supported by third parties, but the licensed company remains accountable. It must conduct due diligence, maintain oversight, establish audit and incident-reporting rights and ensure that outsourcing does not create an empty-shell licensee.
5. What is the biggest cause of licensing delays?
Common causes include incorrect licence classification, opaque ownership, weak source-of-funds evidence, nominal management, insufficient capital, incomplete technology, generic policies, unresolved cyber risks and inconsistencies between the business plan, contracts, systems and website.