Kenya VASP governance: the people your application file has to name
Most Kenyan VASP preparation is discussed as a document exercise: nine policies, a business plan, a set of schedules. That framing understates the problem. Legal Notice No. 134 of 2026 and the anti-money-laundering statutes behind it do not only ask what your policies say. They ask who, by name, is responsible — and several of those roles carry statutory independence tests that a group cannot satisfy by pointing at a head office.
The deadline is 4 November 2026, under section 47 of the Virtual Asset Service Providers Act, 2025 (Act No. 20 of 2025). There is no transitional provision, no savings clause and no deemed-licensing regulation anywhere in the 151 regulations.
The money laundering reporting officer, and why the role is constrained
This is the most tightly specified role in the Kenyan stack, and it is specified outside LN 134. The Proceeds of Crime and Anti-Money Laundering Regulations, 2023 (Legal Notice No. 153 of 2023) provide, at r.12, that the MLRO must be at management level and independent, and cannot be the internal auditor or the chief executive officer — the sole exception being a sole proprietorship. Appointment or removal must be notified to the Financial Reporting Centre and to the supervisory body within 14 days, and the MLRO reports “forthwith”.
Read that against r.11, which requires an MLRO at management level, screening on hire, ongoing training, an independent audit function and a compliance manual. Between them, r.11 and r.12 rule out three arrangements that groups routinely propose: the CEO doubling as MLRO; the internal auditor doubling as MLRO; and an MLRO who sits in another jurisdiction with no management standing in the Kenyan entity.
The role also owns the clocks. Suspicious transaction reports go to the Financial Reporting Centre within two days after the suspicion arose (POCAMLA s.44(2)), and s.44(3) extends this to attempted transactions. Follow-up requests from the FRC must be answered not later than 30 days (s.44(9)). Cash transaction reports are triggered above USD 15,000 or equivalent (s.44(6) and the Fourth Schedule). The annual compliance report is due 31 January (POCAML Regulations r.44), and s.45A requires an annual list of customers from higher-risk countries. Separately, the institution registers with the FRC and notifies changes in particulars within 90 days (s.47A).
Note the statutory route by which all of this reaches virtual asset firms: the Schedule to the VASP Act 2025 inserted “or a virtual asset service provider” into the s.2 definition of reporting institution, with effect from 4 November 2025. These obligations did not wait for LN 134.
The chief information security officer
LN 134 requires a chief information security officer. This is worth flagging for one specific reason: it is in the gazetted text and it was not in the National Treasury draft of March 2026, which is still downloadable and still being quoted. A firm that built its org chart from the draft does not have this role. (Sourcing note: I hold this from the gazette at page 56 of the supplement; I have not confirmed the regulation number, so I do not quote one. Check it against the gazette before citing it in a filing.)
The risk owner the reviewer looks for first
The Third Schedule business-plan content requires a named risk register identifying key risks. That is an application deliverable, not an annex to be promised later, and in practice the reviewer reads the register before the prose around it. Second Schedule item 27 separately asks for written audit, internal controls and risk management policies.
The most common failure in a Kenyan file is a group-level enterprise risk framework with no Kenya-specific risk register and no named Kenyan risk owner. It reads as a document produced elsewhere and posted in, which is exactly what it is.
The same logic runs through reg. 6(2)(f), which requires nine operational policies — risk management; AML/CFT/CPF; data protection and privacy; cybersecurity and information technology; complaints management; market conduct; consumer protection; conflict of interest; and a business continuity and disaster recovery plan. The word the regulation uses is “including”, so the list is not exhaustive, and the Second Schedule application form separately asks about outsourcing. If you have seen a four-item version of this list, that is the March 2026 draft, not the law.
Two houses of style, one set of names
Which regulator reads your file is set by the “Responsible Relevant Regulatory Authority” column of the First Schedule to the VASP Act 2025. The Central Bank of Kenya takes wallet providers, virtual asset payment processors and stablecoin issuers. The Capital Markets Authority takes exchanges, brokers, investment advisers, virtual asset managers, ICO providers, tokenisation providers and token issuance platforms.
The nine headings are the same either way, but the rulebooks the reviewer has in mind are not. A CMA reviewer reads against the Capital Markets Act (Cap. 485A) and the CMA Corporate Governance (Market Intermediaries) Regulations 2011 (LN 144/2011). A CBK reviewer reads against the CBK Risk Management Guidelines of January 2013, whose §7.15 on business continuity and §7.16 on outsourcing are the template in their head. A group doing custody and an exchange is read by both. Underneath both sit the Companies Act 2015 duties on directors, conflicts and the beneficial ownership register.
One piece of context that changes how these files are read: Kenya remains on the FATF list of jurisdictions under increased monitoring, retained as at 19 June 2026, with an outstanding action plan that includes risk-based supervision and the targeted financial sanctions framework. Reviewers are measured on exactly those items. Name the people, give them standing in the Kenyan entity, and the file reads as an operating company rather than a submission.
The checklist behind this article
The Kenya VASP Licensing Readiness Checklist maps each requirement to its regulation or section, marks every figure as instrument text or as reporting of it, and leaves the genuinely open points — including the LN 134 regulation numbers I would not quote above — marked as open rather than guessed. USD 79, with the updated edition free as the position develops.
If you know your category, your regulator and who your MLRO will be, the checklist is enough and you do not need anything more from me. If the constraint is harder — an MLRO candidate who might fail the r.12 independence test, or a group structure that leaves no one with management standing in Kenya — the 48-hour gap check is meant for that.