A Complete Guide to Licensing, Capital, Custody, Cybersecurity and Compliance Under Kenya’s VASP Framework

One of the biggest misconceptions in the crypto industry is that wallet providers are simply software companies.

Many founders believe that because they have developed a mobile application that allows users to store cryptocurrency, they are operating a technology platform rather than a regulated financial service.

That assumption can be costly.

The moment a business controls a customer’s private keys—or can authorise the movement of a customer’s virtual assets—it moves beyond software development into one of the most heavily regulated areas of the digital asset ecosystem.

Unlike an exchange that primarily facilitates trading, a custodial wallet provider safeguards customer assets. Customers trust the business to protect their Bitcoin, Ethereum, stablecoins, and other digital assets against theft, cyberattacks, operational failures, and internal fraud.

From a regulator’s perspective, that responsibility resembles the safeguarding obligations traditionally imposed on banks, custodians and payment institutions.

For this reason, Kenya’s Virtual Asset Service Providers Act, 2025 and the Virtual Asset Service Providers Regulations, 2026 require custodial wallet providers to obtain a licence before carrying on regulated wallet services. The licensing responsibility falls primarily under the Central Bank of Kenya (CBK) because custodial wallets involve the safeguarding and control of customer assets.

This guide explains what constitutes a custodial wallet, when a licence is required and how founders can build a compliant wallet business in Kenya.

What Is a Custodial Crypto Wallet?

Before discussing licensing, it is important to distinguish between different wallet models.

Not every wallet is regulated in the same way.

Non-custodial wallets

A non-custodial wallet allows users to control their own private keys.

The provider does not have the ability to move customer assets.

Examples include wallets where:

  • users generate and retain their own seed phrase;
  • the provider cannot reset or recover private keys;
  • transactions require only the user’s cryptographic authorisation; and
  • the provider cannot access customer funds.

The wallet developer supplies software rather than custody.

Whether such a model falls within the VASP framework depends on its actual functionality and should be assessed carefully.

Custodial wallets

A custodial wallet provider holds or controls customers’ private keys or otherwise has the ability to initiate or authorise transactions on behalf of customers.

Examples include:

  • exchange wallets;
  • hosted crypto wallets;
  • institutional custody platforms;
  • enterprise treasury custody;
  • digital asset custody providers;
  • white-label custody solutions.

The defining question is simple:

Who controls the private keys?

If the provider controls them, the business is likely operating a regulated custodial wallet service.

Why Custodial Wallet Providers Are Regulated

Virtual assets differ from traditional bank balances.

If private keys are lost, compromised or stolen, customer assets may become permanently unrecoverable.

Unlike many banking transactions, blockchain transfers are generally irreversible.

This means custodians face unique risks including:

  • cyberattacks;
  • insider theft;
  • compromised administrators;
  • private key loss;
  • ransomware;
  • operational failures;
  • smart contract vulnerabilities;
  • third-party provider failures.

Because wallet providers safeguard customer property, regulators require higher prudential and operational standards.

The objective is not merely to protect the business.

It is to protect customers whose assets may represent life savings or institutional investments.

Which Regulator Licenses Wallet Providers?

Under Kenya’s VASP framework, custodial wallet providers are supervised primarily by the Central Bank of Kenya (CBK).

This reflects the role wallets play in:

  • safeguarding customer assets;
  • settlement infrastructure;
  • payment systems;
  • financial stability.

Where a wallet provider also offers:

  • exchange services;
  • brokerage;
  • tokenisation;
  • merchant payments;
  • stablecoin issuance;

additional licensing considerations may arise.

Many businesses therefore require a regulatory perimeter assessment before launching.

Activities That May Require a Wallet Licence

The label used by a business is less important than the services it performs.

Examples of regulated wallet activities may include:

  • hosted cryptocurrency wallets;
  • institutional custody;
  • exchange custody;
  • managed wallets;
  • enterprise treasury wallets;
  • digital asset safekeeping;
  • multi-client custody platforms;
  • custodial mobile wallets.

The regulator will typically analyse:

  • customer journey;
  • wallet architecture;
  • transaction authorisation;
  • private key management;
  • operational controls;
  • revenue model.

Capital Requirements

Custodial wallet providers are subject to one of the highest prudential thresholds under Kenya’s framework.

The Regulations prescribe:

  • Minimum paid-up capital: KSh 150 million
  • Minimum liquid capital: KSh 30 million or 8% of total liabilities, whichever is higher.

These requirements reflect the significant responsibility associated with safeguarding customer assets.

Paid-up capital is not operating cash

Many startups misunderstand regulatory capital.

Paid-up capital represents shareholder funds committed to supporting the licensed institution.

It should not be confused with:

  • customer assets;
  • liquidity reserves;
  • operating cash;
  • security deposits.

A realistic funding plan should include:

  • regulatory capital;
  • liquid capital;
  • technology costs;
  • staffing;
  • cybersecurity;
  • insurance;
  • legal expenses;
  • operational runway.

The total amount required to launch is therefore usually much higher than the statutory minimum.

Choosing the Right Business Model

Before applying for a licence, founders should decide what type of custody business they intend to build.

Examples include:

Retail custody

Services aimed at individual customers.

Typical features include:

  • mobile wallet;
  • cryptocurrency deposits;
  • withdrawals;
  • portfolio dashboard.

Institutional custody

Designed for:

  • family offices;
  • investment funds;
  • exchanges;
  • corporates;
  • professional investors.

Institutional clients typically expect enhanced governance and reporting.

Exchange custody

Many exchanges operate hosted wallets for their users.

This creates additional regulatory obligations beyond operating the exchange itself.

Enterprise treasury custody

Businesses may provide custody solutions for:

  • listed companies;
  • payment firms;
  • fintechs;
  • institutional treasury operations.

Each model presents different operational and regulatory risks.

Corporate Structure

The licensed applicant should have genuine operational substance.

The company should ordinarily:

  • contract with customers;
  • receive custody fees;
  • employ key personnel;
  • control wallet operations;
  • maintain regulatory capital;
  • supervise service providers;
  • manage compliance.

The regulator will expect transparency regarding:

  • ownership;
  • beneficial ownership;
  • governance;
  • group structure;
  • decision-making.

Governance Requirements

A licensed custodian should have appropriate governance arrangements.

Typical key functions include:

  • Chief Executive Officer;
  • Chief Compliance Officer;
  • Money Laundering Reporting Officer;
  • Chief Information Security Officer;
  • Chief Technology Officer;
  • Operations Manager;
  • Finance Manager;
  • Risk Officer.

Directors should understand:

  • custody;
  • blockchain;
  • operational risk;
  • cybersecurity;
  • AML;
  • governance.

Nominal appointments should be avoided.

Private Key Management

Private keys are the foundation of every custodial wallet.

Regulators will closely examine how keys are:

  • generated;
  • stored;
  • backed up;
  • accessed;
  • rotated;
  • destroyed.

Questions commonly include:

Who generates the keys?

Who has access?

Can a single employee transfer assets?

What happens if an administrator leaves?

How are emergency recoveries handled?

How are compromised keys replaced?

Private key governance is often the most critical aspect of the application.

Hot Wallets vs Cold Wallets

Most custodians use a combination of storage methods.

Hot wallets

Connected to the internet.

Advantages:

  • faster withdrawals;
  • customer convenience.

Risks:

  • greater cyber exposure.

Cold wallets

Offline storage.

Advantages:

  • stronger security.

Disadvantages:

  • slower operational access.

Many institutions maintain:

  • operational balances in hot wallets;
  • long-term holdings in cold storage.

The balance depends on customer needs and risk appetite.

Multi-Signature Controls

Strong custodians rarely rely on a single approval.

Instead, they implement:

  • multi-signature wallets;
  • approval workflows;
  • segregation of duties;
  • transaction limits.

Examples include:

  • two-of-three signatures;
  • three-of-five signatures.

These controls reduce insider risk.

Cybersecurity Requirements

Custody businesses are prime targets for attackers.

The Regulations require an independent information systems audit, including vulnerability assessment and penetration testing.

A comprehensive cybersecurity framework should include:

  • encryption;
  • multi-factor authentication;
  • privileged access management;
  • endpoint protection;
  • network monitoring;
  • intrusion detection;
  • backup;
  • disaster recovery;
  • incident response.

Testing should be completed before licence submission.

Customer Asset Safeguarding

Customer assets should always be protected from company assets.

A safeguarding framework should address:

  • segregation;
  • reconciliation;
  • wallet governance;
  • transaction approvals;
  • record keeping;
  • recovery procedures.

The regulator may ask:

Where are customer assets held?

Who controls withdrawals?

Can company creditors access customer assets?

How are balances reconciled?

How frequently?

What happens if the custodian becomes insolvent?

AML and Blockchain Monitoring

Custodial wallets remain subject to AML/CFT/CPF obligations.

The compliance framework should include:

  • customer due diligence;
  • beneficial ownership;
  • sanctions screening;
  • politically exposed persons;
  • source-of-funds verification;
  • enhanced due diligence;
  • suspicious transaction reporting.

Crypto-specific monitoring should detect:

  • sanctioned addresses;
  • ransomware wallets;
  • darknet exposure;
  • mixers;
  • scams;
  • stolen assets;
  • high-risk jurisdictions.

Blockchain analytics solutions are increasingly becoming standard for institutional custodians.

Insurance Considerations

Although insurance is not a substitute for strong governance, many institutional customers expect custodians to maintain appropriate cover.

Policies may include:

  • cyber insurance;
  • crime insurance;
  • professional indemnity;
  • directors’ liability.

Insurance should complement—not replace—operational controls.

Outsourcing

Wallet providers frequently outsource:

  • cloud infrastructure;
  • blockchain nodes;
  • cybersecurity;
  • KYC;
  • analytics;
  • technology support.

Outsourcing does not transfer regulatory responsibility.

The licensed wallet provider remains accountable for:

  • oversight;
  • monitoring;
  • audit rights;
  • service quality;
  • incident management.

Technology Architecture

A licensed custodian should document:

  • wallet infrastructure;
  • network architecture;
  • APIs;
  • encryption;
  • authentication;
  • audit logging;
  • backup;
  • disaster recovery;
  • reconciliation systems.

The architecture should support regulatory supervision and operational resilience.

Customer Documentation

Customers should receive clear information regarding:

  • custody arrangements;
  • fees;
  • withdrawal procedures;
  • risks;
  • transaction finality;
  • complaints;
  • liability;
  • supported assets.

Terms should accurately reflect operational reality.

Common Mistakes Made by Wallet Providers

Calling custody “technology”

Controlling private keys generally creates regulatory obligations.

Weak private key governance

Single-person control creates significant operational risk.

Mixing customer and company assets

Customer assets should remain segregated.

No independent cybersecurity testing

Applications should include robust technical assurance.

Generic AML programme

Wallet providers require blockchain-specific monitoring.

Poor governance

Directors should understand custody operations.

Underestimating capital

Regulatory capital is not the same as startup funding.

Ignoring outsourcing risk

Third-party providers remain subject to regulatory oversight.

Wallet Licensing Readiness Checklist

Before applying, confirm that:

  • the custody model has been clearly defined;
  • wallet architecture is documented;
  • required capital has been secured;
  • governance has been established;
  • key personnel are appointed;
  • private key management is documented;
  • cybersecurity testing has been completed;
  • customer asset safeguarding is implemented;
  • AML programme is operational;
  • blockchain monitoring is implemented;
  • outsourcing arrangements are documented;
  • customer agreements are complete.

Multiple negative responses usually indicate that the business is not yet licensing-ready.

How CRYPTOVERSE Can Help

CRYPTOVERSE Legal Consultancy advises digital asset custodians and wallet providers throughout the licensing lifecycle, including:

  • regulatory perimeter assessments;
  • CBK wallet licence strategy;
  • corporate structuring;
  • capital planning;
  • governance frameworks;
  • custody model reviews;
  • wallet architecture assessments;
  • private key governance frameworks;
  • customer asset safeguarding policies;
  • AML/CFT/CPF programmes;
  • Travel Rule implementation;
  • blockchain analytics integration support;
  • cybersecurity workstream coordination;
  • outsourcing documentation;
  • customer agreements;
  • licence application preparation;
  • regulatory engagement;
  • ongoing compliance support.

Our goal is to help clients build custody businesses that meet regulatory expectations while maintaining the operational resilience required to protect customer assets.

Conclusion: Custody Is Built on Trust

A crypto wallet provider does far more than store digital assets.

It safeguards the cryptographic credentials that give customers control over their wealth.

That responsibility explains why Kenya’s VASP framework imposes rigorous requirements on custodial wallet providers.

A successful wallet business combines:

  • strong governance;
  • adequate capital;
  • secure technology;
  • disciplined private key management;
  • effective AML controls;
  • resilient cybersecurity;
  • transparent customer protection.

Founders who treat custody as a regulated financial service—not merely a software feature—are far better positioned to obtain a licence, build institutional credibility and earn long-term customer trust.

In digital asset custody, technology creates access.

Governance and compliance create confidence.

And confidence is the foundation on which every successful custodial wallet business is built.

FAQs

1. Does a custodial crypto wallet require a licence in Kenya?

Yes. A custodial wallet provider that holds or controls customers’ private keys or safeguards their virtual assets may be required to obtain a licence under Kenya’s VASP framework. The exact requirement depends on the wallet’s functionality and business model.

2. Which authority regulates custodial crypto wallet providers in Kenya?

The Central Bank of Kenya (CBK) is the primary regulator for custodial wallet providers under Kenya’s Virtual Asset Service Providers framework, particularly where the service involves safeguarding or controlling customer virtual assets.

3. What is the minimum capital required for a crypto wallet licence in Kenya?

Under the requirements outlined in the blog, custodial wallet providers need a minimum paid-up capital of KSh 150 million and a minimum liquid capital of KSh 30 million or 8% of total liabilities, whichever is higher.

4. What cybersecurity measures should a Kenyan crypto wallet provider have?

A custodial wallet provider should implement strong cybersecurity controls, including multi-factor authentication, encryption, privileged access management, transaction monitoring, secure backups, disaster recovery, and independent vulnerability assessment and penetration testing.

5. Can a crypto wallet provider outsource its technology in Kenya?

Yes. A wallet provider may outsource services such as cloud infrastructure, KYC, cybersecurity, or blockchain analytics. However, outsourcing does not remove the provider’s regulatory responsibility for customer protection, cybersecurity, compliance, and oversight.