A Practical Guide to Preparing, Submitting and Defending a Kenya VASP Licence Application

A crypto founder may believe the application process begins when the prescribed form is submitted to the regulator.

In reality, the process begins much earlier.

It begins when the founders decide:

  • which services the business will provide;
  • which company will hold the licence;
  • who will own and control that company;
  • how customer money and virtual assets will move;
  • who will safeguard private keys;
  • how much capital the company will maintain; and
  • whether the platform is technically ready for regulatory review.

By the time an application reaches the Central Bank of Kenya or the Capital Markets Authority, the applicant should already resemble a regulated financial institution.

Kenya’s virtual asset licensing framework is established under the Virtual Asset Service Providers Act, 2025, which commenced on 4 November 2025, and the Virtual Asset Service Providers Regulations, 2026. The legislation requires regulated virtual asset services to be conducted under the appropriate licence and gives CBK and CMA supervisory responsibility for different categories of virtual asset service providers.

This article explains the Kenya crypto licence application process, the documents applicants should prepare and what CBK and CMA are likely to examine before granting a licence.

1. Start With the Correct Licence Classification

The first question is not:

“What documents must we submit?”

It is:

“What regulated activities will the applicant actually perform?”

A business may present itself as a crypto platform, blockchain company, Web3 application or technology provider. Those labels do not determine the licensing outcome.

The regulator will examine what the company does in practice.

The business should map whether it will:

  • exchange fiat currency for virtual assets;
  • exchange one virtual asset for another;
  • operate a trading platform;
  • arrange or execute OTC transactions;
  • hold or manage private keys;
  • process crypto payments;
  • convert crypto into fiat;
  • advise customers on virtual asset investments;
  • manage portfolios;
  • issue tokens;
  • operate a token launchpad;
  • tokenise assets; or
  • issue a stablecoin.

Under the Act, Kenya’s framework applies to virtual asset service providers operating in and from Kenya. It establishes regulated categories covering exchange, brokerage, custody, payments, investment services and token-related activities. 

Why classification matters

An incorrect classification can affect:

  • the responsible regulator;
  • the application forms;
  • minimum capital;
  • required personnel;
  • technology expectations;
  • safeguarding arrangements;
  • market-conduct controls; and
  • the overall cost of licensing.

For example, a company may apply as a virtual asset broker but operate a platform that automatically matches customer orders. Another applicant may describe itself as non-custodial while retaining the ability to recover or move customer assets.

These contradictions are likely to attract regulatory scrutiny.

2. Determine Whether CBK or CMA Is Responsible

Kenya applies a dual-regulator model.

Central Bank of Kenya

CBK is responsible for categories associated primarily with:

  • virtual asset wallet services;
  • virtual asset payment processing; and
  • stablecoin issuance.

A business involving customer custody, merchant settlement, on-ramp or off-ramp services, or the issuance of a stable-value virtual asset may therefore fall within CBK’s mandate.

Capital Markets Authority

CMA is responsible for categories including:

  • virtual asset exchanges;
  • virtual asset brokers;
  • virtual asset investment advisers;
  • virtual asset managers;
  • initial coin offering providers;
  • tokenisation providers; and
  • token issuance platforms.

A trading venue, OTC dealing business, crypto investment firm, token launchpad or real-world asset tokenisation platform is therefore more likely to engage CMA supervision.

Applications involving both regulators

Some platforms combine activities.

An exchange may also provide custodial wallets. A payment platform may convert fiat into stablecoins, hold the assets and facilitate merchant settlement. A token issuance platform may also operate a secondary trading market.

In such cases, the applicant should determine whether:

  • separate permissions are required;
  • both regulators must be engaged;
  • activities should be separated between entities;
  • one service should be postponed; or
  • a phased licensing strategy would be more practical.

The licence structure should be settled before the regulatory business plan, policies and financial forecasts are finalised.

3. Establish the Applicant Entity

A licence application should be made by the entity that will genuinely conduct and control the regulated business.

The applicant should ordinarily:

  • contract with customers;
  • receive regulated revenue;
  • maintain the required capital;
  • employ or engage key officers;
  • own or lawfully use the technology;
  • contract with banks, custodians and liquidity providers;
  • supervise outsourced functions; and
  • remain accountable for regulatory compliance.

A Kenyan company limited by shares or an appropriately registered foreign company may be eligible, subject to the applicable legal and regulatory requirements.

What CBK and CMA will want to understand

The regulators are likely to examine:

  • where the applicant is incorporated;
  • where its principal office is located;
  • who makes operational decisions;
  • which group entity owns the platform;
  • which entity holds customer assets;
  • where revenue is booked;
  • which entity employs the management team; and
  • whether the applicant has genuine operational substance.

A Kenyan entity that exists only to hold the licence while all material functions remain with an offshore affiliate may face questions about control and accountability.

4. Make Ownership Fully Transparent

The application must clearly identify the persons who ultimately own, control or materially influence the applicant.

The ownership file should cover:

  • direct shareholders;
  • indirect shareholders;
  • significant shareholders;
  • ultimate beneficial owners;
  • parent entities;
  • trusts;
  • nominee arrangements;
  • voting rights;
  • economic interests; and
  • contractual control rights.

The ownership chart should continue through every corporate layer until it reaches the relevant natural persons.

Supporting documents

Applicants should expect to prepare:

  • incorporation documents;
  • shareholder registers;
  • beneficial ownership registers;
  • constitutional documents;
  • corporate registry extracts;
  • shareholder agreements;
  • trust records;
  • nominee declarations;
  • identity documents;
  • residential-address evidence; and
  • an explanatory group structure chart.

Complex structures are not automatically disqualifying. However, unexplained offshore entities, circular ownership, undisclosed nominees or unclear control rights may delay due diligence.

The regulator will want to understand not only who owns the company, but why the structure has been designed in that manner.

5. Prepare Fit-and-Proper Applications

CBK and CMA will assess the suitability of individuals who own, direct or manage the proposed VASP.

Relevant persons may include:

  • directors;
  • the chief executive officer;
  • senior officers;
  • significant shareholders;
  • beneficial owners; and
  • persons responsible for key control functions.

The assessment may consider:

  • honesty and integrity;
  • professional reputation;
  • academic qualifications;
  • relevant experience;
  • financial soundness;
  • criminal history;
  • civil litigation;
  • insolvency;
  • previous regulatory action;
  • disciplinary proceedings;
  • conflicts of interest; and
  • involvement in failed or sanctioned businesses.

Evidence for each key person

The applicant should prepare a structured file containing:

  • completed fit-and-proper forms;
  • curriculum vitae;
  • identification documents;
  • address evidence;
  • academic and professional certificates;
  • employment history;
  • references;
  • directorship history;
  • financial standing information;
  • criminal and regulatory declarations;
  • conflict-of-interest declarations; and
  • explanations of any adverse matters.

Full disclosure is critical.

An adverse matter does not always result in automatic rejection. However, failing to disclose it may create a separate concern about honesty and integrity.

6. Capitalise the Applicant Properly

The applicant must satisfy the paid-up capital requirement applicable to its licence category.

The 2026 Regulations prescribe different minimum capital thresholds based on the risks associated with each activity. These range from lower requirements for brokerage, payment processing and tokenisation to substantially higher thresholds for exchanges, custodial wallet providers and stablecoin issuers.

The company should be able to prove that:

  • the shares were validly issued;
  • the shareholders paid for them;
  • the funds were received by the applicant;
  • the capital is correctly reflected in its records;
  • the funds are not temporary or circular; and
  • the source of the investment is lawful and verifiable.

Capital is not the same as operating funding

An applicant should not inject the exact minimum and then use most of it to pay licensing and launch expenses.

The financial plan should separately cover:

  • regulatory capital;
  • any liquid-capital requirement;
  • staff salaries;
  • platform development;
  • compliance systems;
  • cybersecurity;
  • audit;
  • insurance;
  • professional fees;
  • premises; and
  • contingency funding.

CBK and CMA will be interested in whether the applicant can remain financially viable after authorisation, not merely whether it meets the threshold on the filing date.

7. Prove Source of Funds and Source of Wealth

The regulators will want to understand where the applicant’s capital originated.

A bank statement showing the final deposit may not be sufficient.

The applicant should establish:

  1. who contributed the funds;
  2. how the contributor accumulated them;
  3. how they moved through the financial system;
  4. whether they are equity or debt; and
  5. whether any third party funded the contribution.

Supporting evidence may include:

  • bank statements;
  • audited accounts;
  • salary records;
  • dividend statements;
  • investment statements;
  • tax returns;
  • property or share sale agreements;
  • inheritance documents;
  • business-income evidence; and
  • properly executed loan agreements.

Where funds originated from virtual assets, applicants may also need:

  • wallet addresses;
  • transaction hashes;
  • exchange records;
  • proof of wallet ownership;
  • blockchain-analytics reports;
  • acquisition records; and
  • evidence connecting the crypto disposal proceeds to the investment.

An unexplained crypto-derived capital contribution is likely to attract detailed questions.

8. Prepare a Regulatory Business Plan

The regulatory business plan is not an investor pitch.

It must explain how the applicant will operate as a regulated institution.

The plan should cover:

  • the proposed regulated activities;
  • products and services;
  • target customers;
  • market analysis;
  • ownership and group structure;
  • governance;
  • management;
  • staffing;
  • customer onboarding;
  • fiat and crypto flows;
  • custody;
  • settlement;
  • technology;
  • outsourcing;
  • AML controls;
  • cybersecurity;
  • risk management;
  • consumer protection;
  • revenue;
  • capital and liquidity;
  • financial projections;
  • implementation milestones;
  • business continuity; and
  • orderly wind-down.

What regulators expect from an exchange

An exchange applicant should explain:

  • its trading model;
  • order types;
  • matching engine;
  • supported assets;
  • listing and delisting;
  • liquidity arrangements;
  • market surveillance;
  • settlement;
  • custody;
  • conflicts of interest; and
  • whether proprietary trading or market making will occur.

What regulators expect from a wallet provider

A wallet applicant should address:

  • wallet architecture;
  • hot and cold storage;
  • private-key generation;
  • multi-signature arrangements;
  • withdrawal approval;
  • wallet recovery;
  • reconciliation;
  • segregation;
  • cyber incident response; and
  • third-party custody.

The application should allow the regulator to follow a transaction from customer onboarding to final settlement.

9. Build the AML/CFT/CPF Framework

The applicant must demonstrate effective controls against money laundering, terrorist financing and proliferation financing.

The framework should include:

  • enterprise-wide risk assessment;
  • customer identification and verification;
  • beneficial ownership;
  • sanctions screening;
  • politically exposed person screening;
  • customer-risk classification;
  • source-of-funds checks;
  • enhanced due diligence;
  • fiat transaction monitoring;
  • blockchain monitoring;
  • suspicious transaction escalation;
  • Travel Rule procedures;
  • record keeping; and
  • staff training.

Kenya’s VASP framework operates alongside the country’s anti-money laundering legislation, including the Proceeds of Crime and Anti-Money Laundering Act.

Policies must match systems

A written AML policy is not enough.

CBK or CMA may examine whether:

  • the KYC vendor has been selected;
  • screening rules are configured;
  • blockchain analytics are operational;
  • transaction-monitoring scenarios reflect the business;
  • alert escalation is documented;
  • the reporting officer has authority; and
  • higher-risk customers receive enhanced review.

The applicant should be able to demonstrate how the controls work in practice.

10. Complete the Technology and Cybersecurity Review

Technology is a core part of the application.

The 2026 Regulations require an independent information systems audit, including vulnerability assessment and penetration testing. Applicants must also establish cybersecurity and information-technology policies, systems and controls.

The technology file should include:

  • system architecture;
  • network architecture;
  • data-flow diagrams;
  • wallet architecture;
  • cloud infrastructure;
  • access-control matrix;
  • encryption;
  • API inventory;
  • logging and monitoring;
  • backup arrangements;
  • incident response;
  • disaster recovery;
  • change management; and
  • third-party integrations.

Remediate before submission

The applicant should not expect the regulator to accept unresolved critical vulnerabilities on the basis that they will be fixed after licensing.

A credible process should involve:

  1. independent testing;
  2. classification of findings;
  3. remediation;
  4. retesting;
  5. documented closure; and
  6. formal acceptance of any remaining low-level risks.

The platform should also be sufficiently developed to support a demonstration.

11. Prepare Policies, Contracts and Customer Protections

The application should be supported by policies covering areas such as:

  • risk management;
  • AML/CFT/CPF;
  • cybersecurity;
  • data protection;
  • consumer protection;
  • complaints;
  • conflicts of interest;
  • market conduct;
  • outsourcing;
  • business continuity; and
  • disaster recovery.

Activity-specific documents may also be necessary, including:

  • custody policy;
  • wallet-management procedures;
  • exchange rules;
  • token listing and delisting policy;
  • order-execution policy;
  • market-surveillance framework;
  • stablecoin reserve policy;
  • redemption policy;
  • token-admission standards; and
  • orderly wind-down plan.

Material contracts

Applicants should prepare or finalise agreements with:

  • banks;
  • payment providers;
  • custodians;
  • liquidity providers;
  • cloud-service providers;
  • KYC vendors;
  • blockchain-analytics providers;
  • cybersecurity firms;
  • technology suppliers; and
  • intra-group service providers.

The regulator will want to know whether critical third-party relationships are real, documented and subject to adequate oversight.

12. Submit a Complete and Consistent Application

The application package will ordinarily include:

  • the prescribed application form;
  • corporate documents;
  • ownership and beneficial ownership records;
  • regulatory business plan;
  • fit-and-proper forms;
  • source-of-funds evidence;
  • capital evidence;
  • financial statements;
  • financial projections;
  • governance documents;
  • compliance policies;
  • customer agreements;
  • outsourcing contracts;
  • technology documentation;
  • systems audit;
  • vulnerability assessment;
  • penetration-test report;
  • details of supported virtual assets;
  • activity-specific operating rules; and
  • proof of payment of the application fee.

The precise documents will depend on the activity and regulator. The Regulations establish the detailed licensing and supporting-information framework for VASP applicants.

Consistency is essential

The following documents must describe the same business:

  • application form;
  • business plan;
  • financial projections;
  • customer terms;
  • custody policy;
  • system diagrams;
  • website;
  • outsourcing agreements; and
  • management interview answers.

A contradiction can raise wider doubts about the applicant’s readiness.

13. Respond to Regulatory Questions and Interviews

Submission is not the end of the application process.

CBK or CMA may request:

  • additional ownership records;
  • source-of-funds clarification;
  • revised projections;
  • further capital evidence;
  • changes to policies;
  • copies of provider contracts;
  • platform demonstrations;
  • cybersecurity remediation;
  • explanations of customer-asset flows; or
  • interviews with directors and senior management.

Responses should be:

  • complete;
  • accurate;
  • internally consistent;
  • delivered within the required period; and
  • approved by the appropriate officers.

A response matrix is useful for tracking:

  • each regulatory question;
  • the responsible person;
  • the supporting document;
  • the response deadline;
  • internal approvals; and
  • the final submission date.

Management interviews

Senior officers should be prepared to explain:

  • the licensing rationale;
  • customer journeys;
  • custody;
  • transaction monitoring;
  • capital;
  • liquidity;
  • outsourcing;
  • cybersecurity;
  • complaints;
  • business continuity; and
  • the company’s revenue model.

A director who repeatedly refers every question to external advisers may appear to lack genuine oversight.

14. Understand the 30-Day Determination Period

The 2026 Regulations provide for regulatory determination after the authority has received the required information and completed its due diligence.

This should not be interpreted as an automatic 30-day licence from the date of first submission.

The determination stage may not be reached while:

  • documents remain outstanding;
  • ownership due diligence is incomplete;
  • management interviews have not occurred;
  • capital evidence is insufficient;
  • cyber vulnerabilities remain unresolved; or
  • regulatory questions are unanswered.

The full project may therefore take several months.

A well-prepared applicant may progress more efficiently, but no credible adviser should guarantee approval within a fixed period.

15. What CBK and CMA Ultimately Expect

Although the exact emphasis differs by licence category, both regulators will expect the applicant to demonstrate five core qualities.

1. Clarity

The business model, licence category and transaction flows must be clear.

2. Transparency

Ownership, control, funding and group relationships must be fully disclosed.

3. Competence

Directors and senior officers must understand the business and its risks.

4. Operational readiness

The platform, policies, staffing, contracts and controls must be capable of functioning in practice.

5. Financial resilience

The company must have enough capital and operating resources to launch and remain compliant.

The regulator is not only deciding whether the documents satisfy a checklist.

It is deciding whether the applicant can be trusted to:

  • serve customers;
  • safeguard assets;
  • manage financial crime;
  • protect data;
  • operate reliable systems; and
  • respond responsibly when something goes wrong.

Common Causes of Delay

Applications commonly encounter difficulty because of:

  • incorrect licence classification;
  • incomplete ownership disclosure;
  • weak source-of-funds evidence;
  • nominal management;
  • insufficient capital;
  • unrealistic financial projections;
  • incomplete technology;
  • unresolved penetration-test findings;
  • generic policies;
  • unsigned provider contracts;
  • unclear custody arrangements;
  • conflicting application documents; and
  • delayed responses to regulatory enquiries.

The most effective solution is not faster drafting. It is a licensing-readiness review before filing.

How CRYPTOVERSE Can Help

CRYPTOVERSE Legal Consultancy can support applicants through the complete Kenya VASP licensing process, including:

  • regulatory perimeter assessments;
  • CBK and CMA activity mapping;
  • applicant and group structuring;
  • ownership and beneficial ownership review;
  • capital and liquidity planning;
  • source-of-funds preparation;
  • regulatory business plans;
  • financial projections;
  • fit-and-proper files;
  • governance frameworks;
  • AML/CFT/CPF policies;
  • Travel Rule procedures;
  • custody and safeguarding frameworks;
  • customer agreements;
  • exchange, wallet and token operating rules;
  • outsourcing arrangements;
  • systems-audit coordination;
  • application preparation;
  • regulatory information requests;
  • management interview preparation;
  • approval-condition closure; and
  • post-licensing compliance.

The objective is to submit an application that presents one clear and defensible story across the company’s legal structure, ownership, finances, technology, operations and compliance controls.

Conclusion: Apply Only When the Business Is Ready to Be Examined

A Kenya crypto licence application is not the stage at which the founders begin deciding how the business will operate.

Those decisions should already have been made.

Before approaching CBK or CMA, the applicant should know:

  • what it is applying to do;
  • why the selected regulator is responsible;
  • who owns and controls the business;
  • where the capital came from;
  • who manages the company;
  • how customer assets are protected;
  • how financial crime is detected;
  • how the platform withstands cyber threats;
  • which third parties perform critical functions; and
  • how the company will remain compliant after launch.

The strongest application is not necessarily the longest.

It is the one in which every document, system, contract and management response describes the same well-designed business.

That is what CBK and CMA ultimately expect from a serious applicant.

FAQs

1. Should a Kenya VASP applicant approach CBK or CMA first?

The correct regulator depends on the activity. CBK generally supervises wallet providers, virtual asset payment processors and stablecoin issuers, while CMA supervises exchanges, brokers, investment businesses and token-related platforms.

2. Must the platform be complete before applying?

It does not necessarily need to be commercially live. However, it should be sufficiently developed for systems auditing, penetration testing, transaction-flow analysis and regulatory demonstration.

3. Can a foreign company apply for a Kenya crypto licence?

An appropriately structured and registered foreign company may potentially apply, but it must satisfy the applicable corporate, ownership, governance, capital, technology and compliance requirements.

4. How long does CBK or CMA take to approve an application?

The regulatory determination period applies after the required information has been received and due diligence has been completed. The total licensing project may take several months.

5. What is the most important application document?

No single document guarantees approval. The business plan is central, but it must be consistent with the application form, financial forecasts, policies, contracts, technology, and actual operating model.