A Step-by-Step Guide to Building a Licensed Cryptocurrency Exchange Under Kenya’s VASP Framework
Building a crypto exchange is no longer just a technology project.
Many founders begin by choosing a matching engine, integrating liquidity providers and designing a mobile application. Only later do they ask the legal question:
“What licence do we need?”
By that stage, the answer may require redesigning the entire business.
The choice of licence affects almost everything:
- the corporate structure;
- the amount of capital required;
- the technology architecture;
- whether customer assets can be held;
- governance arrangements;
- AML systems;
- cybersecurity controls;
- banking relationships;
- customer agreements; and
- the launch timeline.
Kenya’s Virtual Asset Service Providers Act, 2025 and the Virtual Asset Service Providers Regulations, 2026 now provide a comprehensive legal framework for licensing and operating crypto exchanges. Rather than treating exchanges as unregulated technology businesses, the framework recognises them as regulated financial market operators subject to prudential, governance, consumer protection and financial crime requirements.
This guide explains how founders can establish a compliant crypto exchange in Kenya and avoid the mistakes that delay or derail many licensing projects.
Step 1: Understand What a “Crypto Exchange” Really Is
Many founders describe their business simply as a “crypto exchange.”
Legally, that description may be incomplete.
Regulators examine what the platform actually does.
A typical exchange allows customers to:
- create an account;
- complete KYC;
- deposit fiat currency;
- deposit cryptocurrency;
- buy and sell virtual assets;
- exchange one token for another;
- withdraw fiat;
- withdraw crypto; and
- sometimes store assets in hosted wallets.
Each of those activities may carry separate regulatory consequences.
Spot exchange
A conventional spot exchange enables customers to buy and sell virtual assets for immediate settlement.
Examples include:
- BTC/KES;
- ETH/KES;
- BTC/USDT;
- ETH/BTC.
This core exchange activity is regulated by the Capital Markets Authority (CMA).
When your exchange becomes more than an exchange
Many platforms also introduce:
- custodial wallets;
- merchant payments;
- OTC brokerage;
- staking;
- lending;
- token launchpads;
- tokenisation;
- portfolio management; or
- stablecoins.
Adding these services may require additional licences or engagement with the Central Bank of Kenya (CBK).
The most successful founders identify every regulated activity before development begins—not after launch.
Step 2: Determine Whether You Need One Licence or Several
One of the biggest misconceptions is that a “crypto exchange licence” authorises every crypto-related activity.
It does not.
Your platform should first be mapped into individual regulated functions.
For example:
| Platform feature | Possible regulated activity | Likely regulator |
| Order matching | Virtual Asset Exchange | CMA |
| Hosted wallets | Virtual Asset Wallet Provider | CBK |
| Merchant payments | Virtual Asset Payment Processor | CBK |
| OTC desk | Virtual Asset Broker | CMA |
| Token launchpad | Token Issuance Platform | CMA |
| Asset tokenisation | Tokenisation Provider | CMA |
A single mobile application may therefore involve multiple regulated businesses.
The licensing strategy should always begin with a regulatory perimeter assessment.
Step 3: Choose the Right Corporate Structure
The applicant must be more than a registered company.
It must be capable of operating as a regulated financial institution.
The exchange operator should ordinarily:
- contract directly with customers;
- own or validly license the exchange technology;
- hold the required regulatory capital;
- employ key management personnel;
- maintain compliance systems;
- supervise outsourced providers;
- receive exchange revenue; and
- remain accountable to the regulator.
Local versus international group structures
Many founders use international holding companies.
That is not necessarily problematic.
However, the Kenyan applicant should have genuine operational substance.
The regulator may expect clarity regarding:
- group ownership;
- intellectual property ownership;
- service agreements;
- technology licensing;
- funding arrangements;
- governance;
- decision-making authority; and
- operational control.
A shell company with no personnel, no authority and no resources is unlikely to inspire regulatory confidence.
Step 4: Raise the Required Capital
Capital planning should occur before preparing the licence application.
The Regulations prescribe a minimum paid-up capital of KSh 100 million for a Virtual Asset Exchange.
In addition, the exchange must maintain liquid capital of at least KSh 20 million or 8% of total liabilities, whichever is higher.
Paid-up capital is not the launch budget
Many founders assume:
“We have KSh 100 million. We are ready.”
Not necessarily.
That amount represents regulatory capital.
The exchange must also fund:
- licensing costs;
- legal advisers;
- compliance implementation;
- technology;
- staffing;
- cybersecurity testing;
- banking;
- insurance;
- liquidity arrangements;
- marketing;
- operating expenses; and
- contingency reserves.
The real funding requirement is therefore significantly higher than the statutory minimum.
Step 5: Develop a Regulatory Business Plan
A pitch deck prepared for investors is not a regulatory business plan.
The regulator expects a detailed explanation of how the exchange will operate.
A high-quality business plan should explain:
- the products offered;
- target customers;
- customer journey;
- exchange architecture;
- supported virtual assets;
- custody arrangements;
- fiat settlement;
- pricing methodology;
- liquidity providers;
- governance;
- compliance;
- technology;
- outsourcing;
- risk management;
- financial projections;
- complaints handling;
- business continuity; and
- orderly wind-down.
Every statement should be consistent with:
- customer agreements;
- technical architecture;
- AML policies;
- financial projections; and
- operational procedures.
Contradictions between documents are a common cause of regulatory questions.
Step 6: Appoint the Right Management Team
A licensed exchange is expected to have competent leadership.
Key positions may include:
- Chief Executive Officer;
- Chief Compliance Officer;
- Money Laundering Reporting Officer;
- Chief Technology Officer;
- Chief Information Security Officer;
- Finance Manager;
- Risk Manager;
- Operations Manager;
- Customer Support Lead.
The precise structure depends on the scale of the business.
Fit and Proper assessment
Directors, beneficial owners and senior officers may be assessed for:
- integrity;
- competence;
- qualifications;
- financial soundness;
- regulatory history;
- criminal history;
- conflicts of interest; and
- relevant experience.
Nominal appointments should be avoided.
The board should genuinely understand:
- crypto markets;
- exchange operations;
- custody;
- AML;
- cybersecurity;
- governance;
- regulatory obligations.
Step 7: Build AML and Financial Crime Controls
Every crypto exchange must establish an effective AML/CFT/CPF framework.
Traditional banking controls alone are insufficient.
Crypto exchanges face additional blockchain-specific risks.
Customer Due Diligence
The exchange should implement:
- customer identification;
- identity verification;
- beneficial ownership verification;
- sanctions screening;
- politically exposed person screening;
- customer risk classification;
- enhanced due diligence;
- ongoing monitoring.
Blockchain monitoring
The compliance framework should also identify exposure to:
- sanctioned wallets;
- ransomware;
- darknet marketplaces;
- mixers;
- scams;
- stolen assets;
- fraud;
- suspicious transaction chains;
- high-risk jurisdictions.
Dedicated blockchain analytics tools are generally expected for larger exchanges.
Step 8: Design Secure Custody Arrangements
A major regulatory question is:
Who controls customer assets?
There are generally two approaches.
Non-custodial model
Customers control their own private keys.
The exchange merely facilitates trading.
This model may reduce regulatory complexity, depending on the actual structure.
Custodial model
The exchange controls customer private keys.
This creates additional safeguarding obligations and may also require separate wallet-provider licensing under the Kenyan framework.
Founders should analyse custody carefully before selecting their business model.
Step 9: Build the Technology Stack
Technology should be selected according to the licensing strategy.
A regulated exchange typically requires:
- matching engine;
- order management system;
- trading interface;
- customer portal;
- mobile application;
- KYC integration;
- blockchain monitoring;
- wallet infrastructure;
- reconciliation engine;
- market surveillance;
- reporting tools;
- audit logs;
- administration dashboard.
Build versus buy
Some founders build proprietary exchanges.
Others use:
- white-label platforms;
- licensed exchange software;
- SaaS infrastructure.
Buying software does not remove regulatory responsibility.
The exchange operator remains accountable for:
- security;
- governance;
- compliance;
- customer protection.
Step 10: Implement Cybersecurity Controls
Cybersecurity is one of the most heavily scrutinised aspects of an exchange application.
The Regulations require an independent information systems audit, including vulnerability assessment and penetration testing.
Security controls should include:
- encryption;
- multi-factor authentication;
- privileged access management;
- key management;
- network monitoring;
- incident response;
- backup;
- disaster recovery;
- change management;
- security logging.
Penetration testing
Testing should occur before the licence application is submitted.
Material findings should be:
- documented;
- remediated;
- retested.
Ignoring critical vulnerabilities can delay approval.
Step 11: Establish Customer Asset Safeguards
Customer assets should never be treated as company assets.
The exchange should establish:
- segregation of assets;
- reconciliation procedures;
- wallet governance;
- withdrawal controls;
- multi-signature approval;
- insolvency planning;
- incident response.
The regulator will want to understand:
- where customer assets are held;
- who controls access;
- how balances are reconciled;
- what happens if systems fail.
Step 12: Build Market Conduct Controls
An exchange is not simply a marketplace.
It must also maintain fair and orderly markets.
The compliance framework should address:
- wash trading;
- spoofing;
- market manipulation;
- insider dealing;
- conflicts of interest;
- proprietary trading;
- market surveillance;
- suspicious trading alerts.
Listing standards should also be documented.
The exchange should define:
- admission criteria;
- due diligence;
- delisting procedures;
- disclosure obligations.
Step 13: Select Banking and Liquidity Partners
A crypto exchange depends heavily on third-party infrastructure.
Key relationships may include:
- commercial banks;
- payment processors;
- custodians;
- liquidity providers;
- market makers;
- blockchain analytics providers;
- cloud providers.
Founders should begin these discussions early.
Banking relationships often take longer than expected.
Step 14: Prepare Customer Documentation
Customer documentation should accurately reflect how the exchange operates.
Core documents usually include:
- Terms of Service;
- Privacy Policy;
- Risk Disclosure Statement;
- AML Notice;
- Complaints Procedure;
- Listing Policy;
- Market Conduct Rules.
The documents should explain:
- fees;
- execution;
- custody;
- supported assets;
- withdrawal procedures;
- settlement;
- complaints;
- termination rights.
Generic internet templates should be avoided.
Step 15: Complete the Licence Application
A complete application typically includes:
- application forms;
- business plan;
- ownership information;
- beneficial ownership;
- fit and proper documentation;
- financial projections;
- capital evidence;
- source of funds;
- governance documents;
- AML policies;
- cybersecurity reports;
- systems audit;
- technology documentation;
- customer agreements;
- outsourcing arrangements.
The quality of the submission often determines how smoothly the review progresses.
Common Mistakes Made by Exchange Founders
Building first, licensing later
The platform is complete before anyone considers regulation.
Underestimating capital
The founders raise only KSh 100 million and have no operating runway.
Poor regulatory perimeter analysis
Additional regulated activities are discovered late in the application.
Weak governance
The directors cannot explain how the exchange operates.
Generic AML policies
The policies address banks rather than blockchain transactions.
No cybersecurity testing
The application lacks independent security assurance.
Inadequate customer documentation
Customer agreements do not match the platform’s actual functionality.
Weak ownership transparency
Beneficial ownership documentation is incomplete.
Ignoring outsourcing risk
The exchange cannot adequately supervise critical service providers.
Treating compliance as a legal exercise
Compliance must be embedded into daily operations—not simply documented.
Indicative Launch Timeline
A realistic exchange project often follows this sequence:
| Phase | Typical activities |
| Phase 1 | Regulatory perimeter assessment and structuring |
| Phase 2 | Incorporation and capital planning |
| Phase 3 | Technology selection and development |
| Phase 4 | Governance and recruitment |
| Phase 5 | AML and compliance implementation |
| Phase 6 | Cybersecurity testing |
| Phase 7 | Documentation preparation |
| Phase 8 | Licence application |
| Phase 9 | Regulatory review and responses |
| Phase 10 | Operational launch after approval |
Attempting to compress these phases frequently results in delays.
Exchange Readiness Checklist
Before applying, confirm that:
- the correct licence category has been identified;
- the exchange business model has been fully mapped;
- required capital has been secured;
- beneficial ownership is transparent;
- governance is established;
- key personnel have been appointed;
- AML systems are operational;
- blockchain monitoring has been implemented;
- cybersecurity testing has been completed;
- customer asset safeguarding has been designed;
- customer documentation is complete;
- technology has been independently reviewed;
- outsourcing arrangements are documented;
- banking relationships are progressing;
- financial projections are realistic.
A “No” to several of these questions usually indicates that the business is not yet licensing-ready.
How CRYPTOVERSE Can Help
CRYPTOVERSE Legal Consultancy provides end-to-end support for crypto exchange licensing in Kenya, including:
- regulatory perimeter assessments;
- exchange licensing strategy;
- CBK and CMA regulatory analysis;
- corporate structuring;
- capital planning;
- ownership and beneficial ownership reviews;
- regulatory business plans;
- governance frameworks;
- AML/CFT/CPF programmes;
- Travel Rule implementation;
- customer asset safeguarding;
- cybersecurity workstream coordination;
- technology and custody reviews;
- exchange rulebooks;
- listing policies;
- customer documentation;
- licence application preparation;
- regulatory engagement;
- post-licensing compliance support.
Our objective is not simply to obtain a licence, but to help founders build an exchange that can operate safely, attract institutional partners and scale sustainably within Kenya’s regulatory framework.
Conclusion: A Crypto Exchange Is a Regulated Financial Institution
Launching a crypto exchange in Kenya is no longer primarily a software project.
It is the creation of a regulated financial institution.
The strongest applications are built on:
- clear regulatory strategy;
- adequate capital;
- competent leadership;
- secure technology;
- effective AML controls;
- transparent governance;
- strong customer protection; and
- operational resilience.
Founders who integrate these requirements from the beginning typically experience a smoother licensing process than those who treat regulation as something to address after development.
The most successful exchanges are not necessarily those with the most sophisticated matching engine.
They are the ones that combine innovative technology with strong governance, prudent risk management and regulatory credibility.
That combination creates a platform capable of attracting customers, banking partners, institutional investors and long-term confidence within Kenya’s rapidly evolving digital asset ecosystem.
FAQs
1. Which regulator licenses a crypto exchange in Kenya?
A Virtual Asset Exchange is generally licensed and supervised by the Capital Markets Authority (CMA) under Kenya’s VASP framework.
2. How much capital is required to start a crypto exchange?
The Regulations prescribe minimum paid-up capital of KSh 100 million, together with minimum liquid capital of KSh 20 million or 8% of total liabilities, whichever is higher. Additional funding is required for technology, staffing and operations.
3. Can a crypto exchange also offer hosted wallets?
Yes, but hosted or custodial wallet services may trigger additional licensing requirements under the Central Bank of Kenya. The exchange model should be assessed before launch.
4. Can I use a white-label exchange platform?
Yes. However, purchasing or licensing technology does not transfer regulatory responsibility. The licensed operator remains responsible for compliance, governance and customer protection.
5. How long does it take to launch a licensed exchange?
The timeframe depends on the readiness of the applicant, the complexity of the business model, the quality of the application, regulatory review and the implementation of governance, technology and compliance systems. A well-prepared project generally progresses more efficiently than one that addresses regulatory issues late in the process.