A Founder-Focused Guide to Kenya’s Core Crypto Law, Licensing Perimeter, Regulators, Compliance Duties and Enforcement Risks
Imagine spending eighteen months building a crypto platform.
You incorporate the company, raise capital, engage developers, integrate a liquidity provider and begin negotiating with banks. The website describes the product as a “blockchain marketplace”. The founders believe this wording keeps the company outside financial regulation.
Then the legal analysis begins.
The platform allows customers to deposit money, buy virtual assets, exchange one token for another, and retain those assets in hosted wallets. Although the company calls itself a technology business, its actual functions include trading, custody and settlement.
The regulatory issue is no longer whether the company uses blockchain technology.
The issue is whether it is providing a regulated virtual asset service in or from Kenya.
That is the central purpose of Kenya’s Virtual Asset Service Providers Act, 2025.
The Act creates the primary legal framework for licensing and regulating virtual asset service providers, commonly referred to as VASPs. It was assented to on 15 October 2025, published on 21 October 2025 and commenced on 4 November 2025. Its stated objective is to establish a legislative framework for licensing and regulating VASPs operating in and from Kenya. (Kenya Law)
For founders, the Act changes the commercial question from:
“Can we launch this crypto product in Kenya?”
to:
“Which regulated activities does the product contain, which authority supervises them, and what must the company build before it can lawfully launch?”
This guide explains the Act from that practical perspective.
1. What the Virtual Asset Service Providers Act Does
The Act is Kenya’s primary legislation for virtual asset service providers.
It performs several core functions.
It:
- establishes the regulatory perimeter for virtual asset services;
- prohibits unlicensed VASP activity;
- designates the responsible regulators;
- creates the legal basis for licence applications;
- establishes broad licensing criteria;
- imposes financial crime obligations;
- regulates virtual asset offerings;
- gives regulators supervisory and enforcement powers; and
- authorises more detailed subsidiary regulations.
The detailed operational requirements are contained in the Virtual Asset Service Providers Regulations, 2026. Those Regulations address matters such as application documents, fees, capital, liquidity, governance, cybersecurity, customer protection and ongoing reporting.
The distinction is important.
The Act establishes the legal framework
It answers questions such as:
- Who is regulated?
- Which activities require a licence?
- Who are the regulators?
- What powers do they have?
- What general obligations apply?
- What happens if a business operates unlawfully?
The Regulations establish the detailed rulebook
They answer questions such as:
- What application form must be filed?
- What capital must be maintained?
- Which policies are required?
- What systems testing must be completed?
- What fees must be paid?
- How will the licence be renewed or changed?
A founder should therefore read the Act and Regulations together. The Act defines the legal obligation to become regulated; the Regulations show how the business must satisfy that obligation.
2. Who Does the Act Apply To?
The Act applies to virtual asset service providers offering virtual asset services in Kenya. Its object also expressly refers to VASPs operating in and from Kenya. (Kenya Law)
This means the framework is not limited to companies physically incorporated in Nairobi.
A business may potentially fall within scope where it:
- is incorporated in Kenya;
- operates from Kenya;
- markets services to Kenyan customers;
- onboards Kenyan residents;
- processes transactions involving Kenyan users;
- maintains local agents or representatives;
- provides Kenyan shilling on-ramp or off-ramp services; or
- otherwise offers regulated virtual asset services into the Kenyan market.
An offshore company should not assume that foreign incorporation automatically places it outside the Act.
The regulatory analysis is functional
The authorities will look at what the company actually does.
They are unlikely to be persuaded solely by descriptions such as:
- blockchain infrastructure company;
- digital technology provider;
- decentralised ecosystem;
- Web3 marketplace;
- liquidity solution;
- software-as-a-service provider; or
- financial technology platform.
The key questions are more practical:
- Who contracts with the customer?
- Who receives the customer’s instructions?
- Who receives fiat or virtual assets?
- Who controls the wallet?
- Who can move the assets?
- Who matches or executes transactions?
- Who determines or communicates the price?
- Who settles the transaction?
- Who earns the transaction fee or spread?
- Who is responsible when something goes wrong?
A genuine technology vendor may remain outside the perimeter where it merely supplies software to another regulated operator and does not conduct the regulated service itself.
However, using third-party software does not make a VASP into a mere technology company.
3. What Is a Virtual Asset?
The Act uses a broad, functional concept of a virtual asset.
In practical terms, a virtual asset is a digital representation of value that may be transferred, traded or stored electronically and used for payment, investment or another financial purpose.
Depending on their features, virtual assets may include:
- cryptocurrencies;
- exchange tokens;
- payment tokens;
- stablecoins;
- investment tokens;
- asset-backed tokens;
- tokenised securities;
- tokenised real estate interests;
- governance tokens with financial functionality; and
- other transferable blockchain-based units of value.
The legal character of a token depends on its functionality, not its marketing name.
A founder may call a token:
- a utility token;
- community point;
- membership credit;
- game asset;
- reward token; or
- digital certificate.
That label is not conclusive.
The more important questions include:
- Can the token be transferred between users?
- Can it be sold?
- Can it be exchanged for fiat currency?
- Can it be exchanged for another virtual asset?
- Is it marketed as an investment?
- Does it represent rights over an asset or business?
- Does the issuer promise redemption?
- Is it traded on a secondary market?
- Can it be used to pay third parties?
Where a token operates like money, an investment or a transferable store of value, the regulatory analysis becomes more significant.
4. Which Activities Require a Licence?
The Act establishes the principle that a person may not carry on, purport to carry on or hold itself out as carrying on virtual asset services without the required licence.
This prohibition is broader than simply processing transactions.
A company may create risk even before launching if it publicly represents that it provides a regulated virtual asset service without having the relevant authorisation.
That means founders should review:
- websites;
- social media;
- pitch decks;
- sales presentations;
- terms and conditions;
- partnership announcements;
- waitlists;
- advertisements; and
- public statements.
A disclaimer saying “licence pending” does not necessarily authorise the business to begin conducting the regulated activity.
Main categories of regulated activity
Under the framework established by the Act and operationalised by the 2026 Regulations, regulated business models include:
| Activity | Typical example |
| Virtual asset exchange | Operating an order book or trading venue |
| Virtual asset broker | Arranging or executing trades for customers |
| Wallet services | Holding or controlling customer private keys |
| Payment processing | Accepting or settling payments involving virtual assets |
| Investment advice | Recommending virtual asset investments |
| Virtual asset management | Managing portfolios on a discretionary basis |
| ICO services | Conducting or supporting token fundraising |
| Tokenisation | Converting assets or rights into blockchain-based tokens |
| Token issuance platforms | Operating infrastructure for token offerings |
| Stablecoin issuance | Issuing redeemable stable-value virtual assets |
One platform may contain several regulated activities.
A retail exchange, for example, may provide:
- fiat-to-crypto conversion;
- crypto-to-crypto trading;
- hosted wallets;
- customer transfers;
- merchant payment functions; and
- investment products.
The founder should not ask which single label best describes the platform.
The correct question is which regulated functions are present throughout the complete customer journey.
5. What Activities May Fall Outside the Act?
The Act contains exclusions intended to prevent every digital token or blockchain project from automatically becoming a regulated VASP business.
The exclusions must be interpreted carefully.
Closed-ecosystem instruments
A digital unit used only within a genuinely restricted ecosystem may fall outside the Act.
Examples may include:
- loyalty points usable only with one retailer;
- internal game credits that cannot be externally traded;
- prepaid service units redeemable only for the issuer’s services; or
- non-transferable internal platform points.
The exclusion becomes less reliable where the unit can:
- be transferred to other users;
- be traded externally;
- be redeemed for cash;
- be exchanged for cryptocurrency;
- be used to pay unrelated merchants; or
- appreciate and be marketed as an investment.
Certain non-fungible tokens
An NFT may fall outside the core VASP regime where it is genuinely unique and is not used for payment, investment or another financial purpose.
A digital artwork may therefore be treated differently from:
- a fractionalised property NFT;
- an NFT representing revenue rights;
- an NFT marketed for guaranteed appreciation;
- an NFT used as collateral;
- or an NFT representing an interest in a fund.
Calling an instrument an NFT does not decide its legal status.
Central-bank-issued digital money
A digital representation of fiat currency issued by a central bank is treated separately from private virtual assets.
Qualifying virtual service tokens
The Act also excludes certain virtual service tokens and persons dealing only with such instruments.
However, founders should obtain a written perimeter analysis before relying on an exclusion. A business model may begin as a closed service ecosystem and later enter the regulated perimeter once transferability, redemption or external trading is introduced.
6. Kenya Has Two Principal VASP Regulators
The Act designates both the Central Bank of Kenya and the Capital Markets Authority as the authorities responsible for licensing, regulating and supervising VASPs according to the services allocated to them. CBK and CMA confirmed this dual-regulator structure when the Act commenced.
The allocation broadly follows the existing competence of each regulator.
Central Bank of Kenya
CBK supervises activities that are closely connected to:
- payments;
- custody;
- settlement;
- liquidity;
- monetary stability; and
- stable-value instruments.
Its principal VASP categories include:
- virtual asset wallet providers;
- virtual asset payment processors; and
- stablecoin issuers.
Capital Markets Authority
CMA supervises activities connected to:
- investment markets;
- trading;
- brokerage;
- investment advice;
- portfolio management;
- token offerings;
- capital raising; and
- tokenisation.
Its principal VASP categories include:
- virtual asset exchanges;
- virtual asset brokers;
- investment advisers;
- virtual asset managers;
- ICO providers;
- tokenisation providers; and
- token issuance platforms.
A business may involve both regulators
Consider a platform that allows users to:
- deposit Kenyan shillings;
- purchase virtual assets;
- trade those assets with other users;
- store them in hosted wallets; and
- spend them with merchants.
That model may contain:
- exchange activity supervised by CMA;
- wallet or custody activity supervised by CBK; and
- payment processing supervised by CBK.
A founder should therefore avoid treating “CBK or CMA” as an either-or question until every product function has been mapped.
7. Licensing Is About the Entire Institution
The Act gives the regulators authority to assess more than the company’s product.
They are also concerned with whether the applicant itself is suitable to become a regulated financial institution.
The licensing assessment may consider:
- ownership;
- beneficial ownership;
- governance;
- competence;
- financial condition;
- capital;
- source of funds;
- technology;
- internal controls;
- AML arrangements;
- risk management;
- consumer protection; and
- the suitability of directors and senior officers.
A licence application is therefore not simply evidence that the software works.
The applicant must demonstrate that it has the people, money, systems and accountability needed to operate safely.
The applicant entity must have real substance
The licensed company should ordinarily:
- contract with customers;
- receive regulated revenue;
- maintain regulatory capital;
- employ or control key personnel;
- own or validly license the technology;
- enter into critical provider contracts;
- supervise outsourced functions;
- maintain records; and
- be accountable to the regulator.
A shell company that relies entirely on an offshore affiliate for decisions, personnel, technology and funding may struggle to demonstrate genuine control.
8. Ownership and Beneficial Ownership Matter
Crypto founders frequently focus on the product and underestimate the importance of the ownership structure.
CBK or CMA will need to understand:
- who directly owns the applicant;
- who indirectly owns it;
- who ultimately benefits economically;
- who has voting power;
- who can appoint directors;
- who has veto or reserved-matter rights;
- whether trusts or nominees are involved; and
- whether any person can exercise control without holding a large shareholding.
The regulators’ financial crime and suitability mandates include vetting significant shareholders, beneficial owners, directors and senior officers. The Act also strengthens the integration of VASPs into Kenya’s AML supervisory framework. (Central Bank of Kenya)
What founders should prepare
The ownership file should include:
- shareholder registers;
- beneficial ownership registers;
- incorporation records;
- constitutional documents;
- shareholder agreements;
- trust documents;
- nominee declarations;
- voting arrangements;
- identity documents; and
- a complete group structure chart.
The chart should continue through every corporate layer until the relevant natural persons are identified.
Complicated ownership is not necessarily prohibited.
Unexplained ownership is the problem.
9. Directors, Officers and Owners Must Be Fit and Proper
The regulatory authorities are entitled to assess the persons responsible for the applicant.
Relevant individuals may include:
- directors;
- the chief executive officer;
- senior management;
- compliance officers;
- significant shareholders;
- beneficial owners; and
- persons responsible for critical control functions.
The assessment may cover:
- honesty;
- integrity;
- competence;
- professional experience;
- qualifications;
- reputation;
- financial soundness;
- criminal history;
- insolvency;
- disciplinary action;
- civil proceedings;
- past regulatory breaches; and
- conflicts of interest.
Nominal appointments are dangerous
A founder should not appoint a local director merely to satisfy a perceived residency or substance expectation while all decisions remain offshore.
A regulator may interview directors and senior officers.
They should be able to explain:
- the business model;
- why the selected licence applies;
- how customer assets move;
- who holds private keys;
- how transactions are monitored;
- how capital is maintained;
- how cyber incidents are handled;
- how complaints are escalated; and
- how the business will be wound down.
External lawyers and consultants can prepare the application, but the board and management must understand it.
10. The Act Makes AML/CFT/CPF a Core Obligation
The Act expressly addresses the prevention of:
- money laundering;
- terrorism financing; and
- proliferation financing.
CBK and CMA’s public notice on commencement of the Act highlighted these obligations as a central part of the framework.
The Act also links VASPs to Kenya’s wider anti-money laundering legislation, including the Proceeds of Crime and Anti-Money Laundering Act. That legislation was amended when the VASP Act commenced. (Kenya Law)
A licensed VASP must therefore operate as a financial crime gatekeeper.
The compliance framework should include
- enterprise-wide risk assessment;
- customer identification and verification;
- beneficial ownership checks;
- customer risk classification;
- sanctions screening;
- politically exposed person screening;
- enhanced due diligence;
- source-of-funds enquiries;
- ongoing customer monitoring;
- fiat transaction monitoring;
- blockchain analytics;
- suspicious transaction escalation;
- record keeping;
- regulatory reporting;
- staff training; and
- Travel Rule processes.
Blockchain monitoring is essential
A VASP should be capable of identifying exposure to:
- sanctioned wallet addresses;
- scams;
- stolen virtual assets;
- ransomware;
- darknet marketplaces;
- mixers;
- high-risk services;
- fraudulent investment schemes; and
- suspicious chain-hopping.
A generic bank-style AML policy that ignores blockchain transactions will not adequately address the risks of a crypto business.
11. The Act Regulates Virtual Asset Offerings
The Act does not regulate only exchanges and wallets.
It also addresses virtual asset offerings and admission of virtual assets to trading.
This is highly relevant to founders planning:
- ICOs;
- token launches;
- fundraising tokens;
- tokenised real estate;
- asset-backed tokens;
- investment tokens;
- token launchpads; or
- secondary market admission.
A token project should not assume that deploying a smart contract and publishing a white paper is sufficient.
A regulated offering may require scrutiny of
- the issuer;
- founders and promoters;
- token rights;
- token supply;
- distribution;
- use of proceeds;
- underlying assets;
- token economics;
- smart contracts;
- custody of fundraising proceeds;
- marketing;
- risk disclosures;
- conflicts;
- redemption rights;
- secondary trading;
- lock-up arrangements; and
- failure or wind-down scenarios.
The Act provides the statutory basis for regulatory oversight of virtual asset offerings and admission to trading. Its broader objective is to ensure that token fundraising and trading do not operate outside investor protection and market integrity standards. (Kenya Law)
A white paper is not merely marketing
For a regulated token project, the white paper may become a disclosure document on which investors and regulators rely.
Misstatements, omissions or exaggerated claims may therefore create legal and regulatory consequences.
Claims such as the following require particular care:
- guaranteed returns;
- risk-free investment;
- fully backed token;
- legally secured ownership;
- immediate liquidity;
- protected capital; or
- guaranteed listing.
The legal rights represented by the token must match the marketing.
12. Tokenisation Does Not Replace Traditional Law
One of the most significant opportunities under Kenya’s framework is the tokenisation of real-world assets.
A project may seek to tokenise:
- land;
- buildings;
- commodities;
- receivables;
- shares;
- debt;
- investment funds;
- intellectual property;
- infrastructure; or
- revenue streams.
But creating a blockchain token does not automatically transfer legal ownership of an asset.
The project must still answer:
- Who legally owns the underlying asset?
- What exactly does the token holder acquire?
- Is the token equity, debt, a fund unit or a contractual right?
- Is a special-purpose vehicle required?
- Is a trustee or custodian involved?
- How are distributions paid?
- What happens if the issuer becomes insolvent?
- Can the token be transferred freely?
- Which other laws apply?
Depending on the structure, a tokenisation project may also involve:
- company law;
- securities law;
- land law;
- trust law;
- insolvency law;
- tax;
- data protection; and
- consumer protection.
The VASP Act regulates the virtual asset service. It does not make the underlying legal structure unnecessary.
13. Stablecoins Receive Heightened Regulatory Attention
Stablecoins sit at the intersection of virtual assets, payments, liquidity and monetary stability.
Their risks include:
- insufficient reserves;
- inability to honour redemption;
- reserve mismatches;
- de-pegging;
- runs;
- misleading backing claims;
- custody failure;
- liquidity concentration; and
- operational disruption.
For that reason, stablecoin issuance falls within CBK’s mandate and is subject to detailed requirements under the Regulations.
A founder should distinguish three separate financial concepts:
| Financial resource | Purpose |
| Regulatory capital | Absorbs losses of the issuer |
| Liquid capital | Covers short-term corporate obligations |
| Reserve assets | Support redemption of issued stablecoins |
The same pool of money should not be counted simultaneously as corporate capital, reserve backing, and operating cash.
A stablecoin structure must also explain:
- what supports the token;
- how reserves are held;
- who has legal title to them;
- how they are valued;
- how frequently they are verified;
- whether they are segregated;
- how redemption works;
- how stress is managed; and
- what happens during insolvency or wind-down.
14. Outsourcing Does Not Outsource Accountability
Crypto businesses commonly rely on third parties for:
- technology;
- hosted exchange infrastructure;
- wallets;
- custody;
- cloud services;
- KYC;
- blockchain analytics;
- liquidity;
- banking;
- payment processing;
- cybersecurity; and
- customer support.
These arrangements may make the business more efficient.
They do not remove the VASP’s responsibility.
The applicant should remain able to demonstrate that it:
- selected the provider carefully;
- understands the outsourced function;
- supervises performance;
- receives adequate reporting;
- can investigate incidents;
- has audit rights;
- can provide regulatory access;
- manages subcontracting;
- has continuity arrangements; and
- can terminate or replace the provider.
White-label does not mean licence-free
A company may purchase a fully built exchange platform and still require an exchange licence where it:
- contracts with customers;
- controls onboarding;
- sets commercial terms;
- selects assets;
- receives fees;
- controls the service; and
- bears responsibility for customer outcomes.
The technology provider may operate the software, but the customer-facing business may remain the regulated VASP.
15. Customer Assets Must Be Protected
Where a VASP receives, holds or controls customer money or virtual assets, the business must address safeguarding.
The regulator will want to understand:
- where customer fiat is held;
- where virtual assets are held;
- whether assets are segregated;
- who controls private keys;
- how customer balances are recorded;
- how reconciliations occur;
- whether the company can use customer assets;
- what happens if a custodian fails;
- what customers can recover during insolvency; and
- how assets are returned during closure.
Customer assets are not the company’s operating capital.
A VASP should not use them to fund:
- payroll;
- technology;
- liquidity shortfalls;
- trading;
- lending;
- marketing; or
- general company expenses.
Customer agreements must also match operational reality. A term stating that assets are segregated is not enough where the actual wallet architecture mixes customer and corporate assets without reliable internal records.
16. The Act Gives Regulators Broad Supervisory Powers
The Act does not create a one-time licensing exercise.
It creates an ongoing supervisory relationship.
CBK and CMA may exercise powers relating to:
- licensing;
- inspections;
- information requests;
- offsite monitoring;
- onsite examination;
- AML supervision;
- group supervision;
- investigation;
- regulatory directions;
- enforcement;
- financial penalties; and
- restrictions on regulated businesses or responsible persons.
The Act’s framework enables the authorities to impose monetary, civil or administrative consequences and to enforce compliance with Kenya’s financial crime laws. (Kenya Law)
A licensed company should therefore be capable of providing evidence—not merely assurances.
The regulator may request:
- customer records;
- transaction histories;
- wallet data;
- board minutes;
- risk assessments;
- financial statements;
- capital calculations;
- audit reports;
- provider contracts;
- complaints;
- incident records;
- suspicious transaction controls; and
- cybersecurity testing.
Records should allow the regulator to reconstruct how a transaction was approved, processed, monitored and settled.
17. Operating Without a Licence Is a Strategic Risk
A startup may be tempted to launch first and apply later.
This creates several layers of risk.
Regulatory risk
The company may be directed to cease activities, investigated or subjected to enforcement.
Banking risk
Banks and payment providers may terminate relationships once they identify unlicensed regulated activity.
Investor risk
Professional investors may refuse to fund a business with unresolved licensing exposure.
Contract risk
Customers or commercial partners may challenge agreements entered into while the company lacked the necessary authorisation.
Reputational risk
Public regulatory action can undermine customer trust and future licensing applications.
Founder and management risk
Directors and senior officers may face scrutiny regarding their knowledge of and involvement in the unlicensed activity.
A founder should not rely on the assumption that the regulators will overlook a startup because it is small, offshore or innovative.
The Act is activity-based.
A small unlicensed exchange may still be an unlicensed exchange.
18. Existing Businesses Must Review Their Entire Model
A business that operated before the Act should not assume that its historic model can continue unchanged.
The company should conduct a comprehensive review of:
- products;
- entities;
- customers;
- jurisdictions;
- transaction flows;
- custody;
- banking;
- outsourcing;
- marketing;
- capital;
- governance;
- AML;
- technology; and
- contracts.
The key objective is to determine:
- which activities now require licensing;
- which regulator is responsible;
- whether more than one licence category applies;
- whether the current entity is suitable;
- whether services must be suspended or modified;
- what remediation is needed before filing; and
- whether the group structure should be changed.
A business should also review public statements. Marketing a regulated service before authorisation may create unnecessary regulatory exposure.
19. A Founder’s Practical Implementation Roadmap
The following sequence provides a practical starting point.
Step 1: Map the customer journey
Document what happens from onboarding to final settlement.
Include:
- money flows;
- virtual asset flows;
- private-key control;
- contracting entities;
- third-party providers;
- pricing;
- revenue; and
- customer communications.
Step 2: Complete a regulatory perimeter assessment
Identify every regulated function and any exclusion on which the business intends to rely.
Step 3: Determine the regulator and licence combination
Confirm whether the business falls under:
- CBK;
- CMA; or
- both.
Step 4: Select the correct applicant entity
Ensure that the licence holder genuinely controls the regulated operation.
Step 5: Review ownership and funding
Identify all beneficial owners and prepare source-of-funds evidence.
Step 6: Appoint credible management
Choose directors and senior officers who understand the product and regulatory risks.
Step 7: Build the compliance framework
Implement AML/CFT/CPF, sanctions, transaction monitoring, Travel Rule and reporting controls.
Step 8: Review technology and safeguarding
Complete architecture analysis, cybersecurity testing, custody design and reconciliation procedures.
Step 9: Finalise contracts and disclosures
Prepare customer terms, provider agreements, risk warnings and offering documents.
Step 10: Conduct a readiness review
Do not file until the documents, systems, people and financial model describe the same business.
Founder Readiness Checklist
| Area | Question founders should answer |
| Regulatory perimeter | Which functions constitute regulated virtual asset services? |
| Licence categories | Does the business require one or several licences? |
| Regulator | Is CBK, CMA or both responsible? |
| Applicant | Which entity contracts with customers and controls the business? |
| Ownership | Can every beneficial owner be identified? |
| Management | Can directors explain the complete operating model? |
| Capital | Is regulatory capital separate from operating funds? |
| AML | Can the business monitor both fiat and blockchain activity? |
| Custody | Who controls customer private keys? |
| Safeguarding | Are customer assets segregated and reconciled? |
| Technology | Has the actual platform been independently tested? |
| Outsourcing | Can critical providers be supervised and replaced? |
| Token rights | Do legal rights match the token’s marketing? |
| Marketing | Is the business holding itself out as licensed before approval? |
| Records | Can every transaction and compliance decision be reconstructed? |
A material number of unanswered questions usually indicates that the business is not ready for licensing or launch.
How CRYPTOVERSE Can Help
CRYPTOVERSE Legal Consultancy assists crypto founders, investors and established virtual asset businesses with the implementation of Kenya’s VASP framework.
Our support may include:
- regulatory perimeter assessments;
- business-model and customer-journey mapping;
- CBK and CMA licence analysis;
- multi-licence planning;
- applicant and group structuring;
- beneficial ownership reviews;
- source-of-funds preparation;
- capital and liquidity planning;
- regulatory business plans;
- fit-and-proper documentation;
- governance frameworks;
- AML/CFT/CPF policies;
- Travel Rule procedures;
- blockchain-monitoring frameworks;
- customer asset safeguarding;
- custody and wallet documentation;
- exchange and brokerage rules;
- stablecoin structuring;
- ICO and token issuance support;
- real-world asset tokenisation;
- white-paper and disclosure review;
- outsourcing agreements;
- licence application preparation;
- regulatory responses;
- management interview preparation; and
- ongoing compliance support.
The objective is to translate the Act from a legal obligation into a practical licensing and operating plan.
Conclusion: The Act Regulates the Business, Not the Buzzwords
The Virtual Asset Service Providers Act, 2025 represents a fundamental change in how crypto businesses must approach the Kenyan market.
A founder can no longer rely on:
- regulatory uncertainty;
- offshore incorporation;
- technology branding;
- outsourced infrastructure;
- token terminology; or
- the absence of a physical office.
The Act focuses on substance.
It asks what the business actually does, who controls it, who owns it, how it is funded, how customer assets are protected and whether the people responsible are suitable to operate a regulated institution.
For serious founders, the Act creates both responsibility and opportunity.
It requires greater investment in:
- governance;
- capital;
- compliance;
- technology;
- customer protection; and
- regulatory readiness.
But it also creates a pathway for properly structured businesses to operate within a recognised legal framework.
The central lesson is straightforward:
Do not design the product first and add regulation at the end.
The regulatory perimeter affects the product itself.
It determines:
- which services can be offered;
- which regulator must be approached;
- how much capital is required;
- whether custody should be internal or outsourced;
- how tokens should be structured;
- what management team is needed;
- which contracts must be signed; and
- how long the business may take to launch.
A founder who understands the Act early can design a licensable institution.
A founder who ignores it may later discover that the regulator must redesign the company, product and funding model before the business can lawfully operate.
FAQs
1. What is the Virtual Asset Service Providers Act, 2025 in Kenya?
The Virtual Asset Service Providers Act, 2025 is Kenya’s primary law for regulating virtual asset businesses. It establishes licensing, supervision, compliance and enforcement requirements for VASPs operating in or from Kenya.
2. Who needs a VASP licence in Kenya?
Businesses providing regulated virtual asset services, such as exchanges, brokers, wallet providers, payment processors, investment advisers and certain token-related services, may need a VASP licence depending on their activities.
3. Which regulators oversee virtual asset businesses in Kenya?
The Central Bank of Kenya (CBK) and Capital Markets Authority (CMA) are responsible for regulating VASPs. The applicable regulator depends on the specific services and activities offered by the business.
4. What compliance requirements apply to Kenyan VASPs?
VASPs may need to meet requirements covering AML/CFT/CPF, customer due diligence, transaction monitoring, governance, capital, cybersecurity, customer asset safeguarding, reporting and ongoing regulatory supervision.
5. Can an offshore crypto company operate in Kenya without a VASP licence?
Not necessarily. Foreign incorporation does not automatically remove a business from Kenya’s regulatory framework. An offshore company offering virtual asset services to the Kenyan market should assess its activities and licensing obligations before operating.