TK Global OS — Regulatory notesCryptoasset licensing: United Kingdom, Kenya, Brazil

It is nine written policies, not four: Kenya VASP reg. 6(2)(f)

Kenya Published 2026-08-13

The four-policy list is the draft, not the law

If you have been told that a Kenyan VASP application needs four written policies — risk management, AML/CFT/CPF, cybersecurity and complaints — you are working from the National Treasury draft circulated in March 2026. That draft is still downloadable and still being quoted. It is not the instrument.

The instrument is Legal Notice No. 134 of 2026, made on 3 July 2026 by the Cabinet Secretary to the National Treasury and published in Kenya Gazette Supplement No. 185 (Legislative Supplement No. 103) on 22 July 2026 — 116 pages, 151 regulations, six schedules. Cite both supplement numbers; Kenyan supplements carry both and sources quote one or the other. Regulation 6(2)(f) of that notice lists nine operational policies.

The nine, as gazetted

Five of those nine — data protection, market conduct, consumer protection, conflicts and business continuity — are absent from the four-item list. A firm that has budgeted a policy drafting exercise on the draft has under-scoped it by more than half.

"Including" means nine is a floor

The operative word in reg. 6(2)(f) is including. The list is not exhaustive and the regulator may ask for more. It already does: the Second Schedule application form separately asks for written policies on data protection, outsourcing, operational controls and AML/CFT/CPF. Outsourcing is not in the reg. 6(2)(f) list, so in practice it is a tenth policy — required by the form rather than by the regulation.

One list, two houses of style

The nine headings are the same for everyone. What goes inside them is not. The VASP Act 2025 First Schedule carries a "Responsible Relevant Regulatory Authority" column: the Central Bank of Kenya supervises wallet providers, virtual asset payment processors and stablecoin issuers; the Capital Markets Authority supervises exchanges, brokers, investment advisers, virtual asset managers, ICO providers, tokenisation providers and token issuance platforms. Published law-firm summaries disagree on where exchanges and wallets sit — the First Schedule controls, not the summary.

A CMA applicant should be writing market conduct and conflicts against the Capital Markets Act (Cap. 485A) and the CMA Corporate Governance (Market Intermediaries) and Conduct of Business Regulations 2011. A CBK applicant should be writing business continuity and outsourcing against the CBK Risk Management Guidelines of January 2013 — sections 7.15 and 7.16, the latter cross-referring to CBK/PG/16. That is the document in a CBK reviewer's head. A group running both custody and an exchange is read by both regulators, against both rulebooks, from one set of nine headings.

The AML policy is where the hard numbers live

The VASP Act 2025 inserted virtual asset service providers into the definition of reporting institution in POCAMLA (Cap 59A) with effect from 4 November 2025. Your AML policy therefore has to reproduce statutory timings, not describe them loosely:

Under the POCAML Regulations 2023 (LN 153/2023): the money laundering reporting officer must be at management level and independent, and cannot be the internal auditor or the chief executive; appointment or removal is notified to both the FRC and the supervisory body within 14 days (r.12). Regulation 8 requires a risk assessment before launching any new product, delivery mechanism or technology — a product-approval gate belongs inside the risk policy, not in a separate memo. Regulation 32 is Kenya's travel-rule hook: full originator and beneficiary data on domestic and cross-border transfers. The annual compliance report is due 31 January (r.44).

Two things in the gazette that were not in the draft

LN 134 requires a chief information security officer — in the gazetted text, absent from the March draft. And the Third Schedule business-plan content requires a named risk register identifying key risks. That is an application deliverable, not an annex you promise to build later, and reviewers read the register before the prose. The most common failure in a Kenyan risk policy is a group-level enterprise risk framework with no Kenya-specific register and no named Kenyan risk owner.

Why this is graded harder than you expect

Kenya remained on the FATF list of jurisdictions under increased monitoring at the June 2026 plenary, with risk-based supervision and the targeted financial sanctions framework still on its action plan. CBK and CMA reviewers are measured on precisely those items. The deadline is 4 November 2026 (VASP Act 2025, s.47) and there is no transitional provision, no savings clause and no deemed-licensing regulation anywhere in the 151 regulations. The application window had not opened when this was written.

The checklist behind this article

The Kenya VASP Readiness Checklist maps the application to the gazetted text — the nine policies under reg. 6(2)(f) plus the Second Schedule's outsourcing item, the Third Schedule risk register, the Fifth Schedule capital columns and the First Schedule fees — with every item cited to a regulation, every figure marked as gazette text or as reporting of it, and open points such as the application form and the window opening date left marked open. USD 79, updated edition free as the position develops.

If you are applying for one licence category under one regulator, the checklist is the whole job. If you are applying across categories, or your group sits under both CBK and CMA, a 48-hour gap check will tell you which of the nine headings you have to write twice.

Get the note when something actually changes

The UK gateway, Kenya's VASP Act and Brazil's BCB regime. Only when a rule, date or figure moves — and primary sources are always marked separately from press reporting.

More on Kenya