TK Global OS — Regulatory notesCryptoasset licensing: United Kingdom, Kenya, Brazil

Legal Notice 134 asks for a chief information security officer. The draft did not.

Kenya Published 2026-08-30

A post that appears in the law but not in the draft

The gazetted Kenyan VASP Regulations require a chief information security officer. The National Treasury draft that circulated in March 2026 did not. We hold the gazette text and the requirement appears at page 56 of the notice.

That single difference is a useful test of whichever secondary guide you are working from. Kenya Law's record page for Legal Notice 134 has no HTML body — it is a PDF-only record — which is why so much of the market is quoting summaries of the draft rather than the law. If the guide in front of you does not mention a security officer, it is describing March, not July. The instrument to cite is Legal Notice No. 134, made 3 July 2026 by the Cabinet Secretary to the National Treasury and published on 22 July 2026 in Kenya Gazette Supplement No. 185, Legislative Supplement No. 103. Quote both supplement numbers; Kenyan supplements carry both and sources quote one or the other.

The cyber policy is one of nine, not one of four

Regulation 6(2)(f) requires written operational policies, and the gazetted list has nine heads: risk management; AML/CFT/CPF; data protection and privacy; cybersecurity and information technology; complaints management; market conduct; consumer protection; conflict of interest; and business continuity and disaster recovery. The four-item list still circulating in commentary is the March draft.

Two further points from the text. The word used is "including", so the list is a floor rather than a closed set. And the Second Schedule application form separately asks for written policies on data protection, outsourcing, operational controls and AML/CFT/CPF — which makes outsourcing an effective tenth policy even though it is not one of the nine.

What the security officer inherits on day one

The security build is not a policy document. It is a set of retention and access obligations that have to be engineered:

The last of these is the one that changes architecture. Seven-year retention can be satisfied with cold storage and a restore procedure. A standing read-only channel for the regulator cannot. A retention schedule that stops at the seven-year figure is under-drafted, and the gap will not show up until someone asks for the access to be demonstrated.

The seven-year rule appears in more places than the four cited above — we have counted at least two further provisions, including one in the trading platform sequence and a ledger provision, whose regulation numbers we have not yet confirmed against the gazette pagination. We are not citing numbers we have not verified. If your policy cites only one source for the retention period, it is incomplete regardless.

Insurance reaches into the security build

Insurance for Kenyan VASPs is regulation 88, not the Fifth Schedule, and reg. 88(5) requires cover that includes cyber, theft, loss of keys and operational failure. Regulation 88(1) sets no prescribed sum — cover must be commensurate with risk and scale — so the underwriting conversation is driven by the controls you can evidence. The only hard figure in the regulation is 88(6): professional indemnity of at least KSh 1,000,000 for an investment adviser. Key management is therefore both a security control and an insurance variable, and the security officer will be the person asked to describe it.

The statutes the policy has to be written against

A generic international information security policy reads as generic to a Kenyan reviewer. The instruments a Kenyan cyber and data policy should be visibly written against are:

The Third Schedule business plan asks for a named risk register identifying key risks. It is an application deliverable, not an annex to be promised later, and the most common failure we see is a group-level risk framework with no Kenya-specific register and no named Kenyan risk owner.

Why the timing is tighter than it looks

The statutory deadline is 4 November 2026 under s.47 of the VASP Act 2025, and there is no transitional provision, no savings clause and no deemed-licensing regulation anywhere in the 151 regulations. As at publication the application window had not opened. Hiring a security officer, standing up a real-time read-only access channel and getting a cyber policy through a board are not things that compress into the weeks after a window opens.

The checklist behind this article

Our Kenya VASP readiness checklist maps the application file to the gazetted text — the nine policies under reg. 6(2)(f) and the Second Schedule additions, the Fifth Schedule capital columns, the First Schedule fees, the record-keeping and access duties — with each item cited to its regulation, each figure marked as gazette text or as reporting of it, and open questions left open. USD 79, with the updated edition free as the position develops.

If you are applying in a single category with a straightforward structure, the checklist is the whole of what you need from us. If your structure is less obvious — two activities under reg. 85(6), a group security function shared with an offshore parent, or custody arranged through a third party — the 48-hour gap check takes your specific facts against the text.

Get the note when something actually changes

The UK gateway, Kenya's VASP Act and Brazil's BCB regime. Only when a rule, date or figure moves — and primary sources are always marked separately from press reporting.

More on Kenya