Every crypto business operating in or from Kenya is already a money-laundering reporting institution, with full anti-money-laundering and know-your-customer duties, even though no VASP licence has yet been issued. The Virtual Asset Service Providers Act, 2025 amended the Proceeds of Crime and Anti-Money Laundering Act (Cap. 59A) so that every virtual asset service provider became a “reporting institution” from 4 November 2025. That single amendment switched on the entire POCAMLA compliance stack: customer due diligence, ongoing monitoring, suspicious transaction reports within two days, cash transaction reports above USD 15,000, a seven-year records duty, a Money Laundering Reporting Officer, internal controls, and separate registration with the Financial Reporting Centre through the goAML portal. None of this waits for the draft VASP Regulations to be gazetted. It is live now, and skipping the Financial Reporting Centre registration is itself a criminal offence. This guide sets out exactly what an AML and KYC programme must contain, how the FATF Travel Rule fits in, and the practical order in which to build it.

Short answer

Are crypto businesses in Kenya subject to AML and KYC rules yet?

Yes, and the trigger date is fixed. The Second Schedule to the VASP Act 2025 amended POCAMLA (Cap. 59A) so that the core definition of “reporting institution” now reads “a financial institution, designated non-financial business and profession or a virtual asset service provider”. Adding those last six words pulled every Kenyan VASP inside the full POCAMLA regime from the Act’s commencement on 4 November 2025.

This matters because it does not depend on the licensing channel being open. The Central Bank of Kenya and the Capital Markets Authority confirmed jointly on 18 November 2025 that no VASP has been licensed and that licensing will only begin once the Cabinet Secretary’s Regulations are gazetted. Those Regulations are still in draft. So you cannot get a VASP licence in Kenya today. But the AML and KYC duties are not gated by the licence. A crypto business that meets the definition of a virtual asset service provider is already a reporting institution with live obligations, licensed or not.

For the full picture of who counts as a VASP, the dual CBK and CMA regulator model, and what is still waiting on the Regulations, see the pillar on VASP licensing in Kenya. This guide stays on the AML and KYC build.

What is customer due diligence and how do you do it?

Customer due diligence is the legal heart of KYC. POCAMLA section 45(1) requires a reporting institution to “identify and verify any applicant seeking to enter into a business relationship with it or to carry out a transaction or series of transactions with it” by “requiring the applicant or customer to produce an official record reasonably capable of establishing the true identity of the applicant or customer”. Anonymous onboarding is over for any business inside the definition.

In practice, a compliant CDD programme for a Kenyan VASP captures and verifies, at minimum:

CDD is risk-based, not one-size-fits-all. The ongoing-monitoring duty (POCAMLA section 44(1)) and the CDD regulations carry the obligation through the life of the relationship, so you cannot simply onboard once and forget. Higher-risk customers (large flows, high-risk jurisdictions, politically exposed persons, structuring patterns) attract enhanced due diligence: deeper source-of-funds checks, senior sign-off and tighter monitoring. Lower-risk relationships can run on simplified measures, documented as such.

The VASP Act reinforces this from the conduct-of-business side. Every VASP must comply with the full range of AML, CFT and CPF preventive measures, including targeted financial sanctions, as a continuing condition of licence. So your CDD framework is not just a POCAMLA duty, it is also part of the prudential file the regulator will assess.

What is ongoing monitoring?

Onboarding checks are the front door. Ongoing monitoring is the rest of the house. POCAMLA section 44(1) requires a reporting institution to monitor “all complex, unusual, suspicious, large or such other transactions” whether completed or not. For a crypto business this means transaction-monitoring rules tuned to virtual-asset typologies: rapid movement through multiple wallets, transactions just under reporting thresholds (structuring), interaction with high-risk or sanctioned addresses, mixer or tumbler exposure, and behaviour that does not match the customer’s stated profile.

On-chain analytics tooling is now effectively expected. A monitoring stack that scores counterparty wallet risk, flags exposure to illicit-fund clusters and surfaces structuring patterns is the difference between a programme that finds the suspicious transaction and one that explains, after the fact, why it did not. The output of monitoring feeds straight into the reporting duties below.

When must a Kenyan VASP file a suspicious transaction report?

As soon as suspicion arises, and the clock is short. POCAMLA section 44(2) requires the suspicious transaction report to be filed with the Financial Reporting Centre within two days. The threshold is suspicion, not proof. If a transaction or a customer’s behaviour gives reasonable grounds to suspect money laundering, terrorism financing or proceeds of crime, the report is due, whether or not the transaction completed.

Two practical points. First, two days is tight, so the path from a monitoring alert to a filed STR has to be designed, with a named decision-maker (the MLRO) and a documented internal escalation route. Second, “tipping off” the customer that a report has been or may be made is a separate offence under POCAMLA. Frontline staff must be trained never to alert a customer that a suspicious transaction report is in play.

When must a VASP file a cash transaction report?

For any cash transaction above USD 15,000, suspicious or not. The Fourth Schedule to POCAMLA, read with section 44, fixes the trigger: a reporting institution must file reports on all cash transactions exceeding USD 15,000 or its equivalent in any other currency. Section 44 closes the loop by applying the duty “whether they appear to be suspicious or not”.

The distinction matters. A cash transaction report (CTR) is a threshold report, filed automatically once the value is crossed, with no judgment call about suspicion. A suspicious transaction report (STR) is a judgment-based report, filed whenever suspicion arises at any value. A crypto on-ramp or off-ramp that handles cash, or cash-equivalent settlement, needs an automated CTR trigger at the USD 15,000 line and a separate STR pathway running alongside it.

How do you register with the Financial Reporting Centre on goAML?

Separately from the VASP licence, and it is not optional. POCAMLA section 47A requires every reporting institution to register with the Financial Reporting Centre. For VASPs this is done through the Centre’s goAML portal using Form FRC RF 1-1. Failing to register is itself a criminal offence under section 47A, so this is one of the first compliance steps a crypto business should complete, not one to defer until the licence comes through.

goAML is the United Nations Office on Drugs and Crime reporting platform the Financial Reporting Centre uses for registration and for receiving STRs and CTRs. Once registered, the reporting institution files its suspicious and cash transaction reports through the same portal. So goAML registration is both the legal precondition to being recognised as a reporting institution and the operational channel through which the two-day STR and the USD 15,000 CTR get filed.

Who is the MLRO and what records must you keep?

POCAMLA section 47 requires every reporting institution to put in place internal controls and internal reporting procedures, including identifying the internal reporting officer (the role the industry calls the Money Laundering Reporting Officer, or MLRO). The MLRO is the named individual responsible for receiving internal suspicion reports, deciding whether to escalate them to the Financial Reporting Centre, and maintaining the institution’s AML programme. The role needs seniority and independence: the MLRO must be able to file a report even when a transaction is commercially attractive.

On records, POCAMLA section 46 requires a reporting institution to keep customer and transaction records for at least seven years. Read together with the VASP Act’s own records duty, which requires client and house transaction records to be kept at the principal place of business for not less than seven years and to be available to the regulator on a real-time read-only basis, the practical standard is clear: seven-year retention, structured, retrievable, and capable of being produced to the regulator and the Financial Reporting Centre on demand.

What is the FATF Travel Rule and does it apply in Kenya?

The Travel Rule is the Financial Action Task Force standard (FATF Recommendation 16) that requires the originating VASP in a virtual-asset transfer to obtain, hold and pass on originator and beneficiary information to the receiving VASP, so that virtual-asset transfers carry the same identifying data as a traditional wire. In a crypto transfer that means the sending platform must transmit the sender’s name and account or wallet reference, and the beneficiary’s name and account or wallet reference, to the platform receiving the transfer.

Kenya’s direction of travel makes this a build priority rather than a future nicety. Kenya was grey-listed by FATF in February 2024 and remains on the grey list as of the FATF June 2026 plenary. Grey-list exit turns on demonstrating an effective AML regime across the financial system, and the FATF virtual-asset standards, including the Travel Rule, are part of that picture. The VASP Act’s requirement that every VASP comply with the full range of AML, CFT and CPF preventive measures is the domestic hook through which Travel Rule expectations land on Kenyan crypto businesses.

The practical build: a VASP needs the capacity to collect Travel Rule data at the point of transfer, to transmit it securely to counterparty VASPs (typically through one of the interoperable Travel Rule messaging protocols the industry uses), and to receive and screen inbound Travel Rule data. The exact domestic threshold and the technical standard for Kenya are matters likely to be detailed in the VASP Regulations or in regulator guidance, which are not yet gazetted, so the messaging architecture should be built to the FATF standard and tuned once the Kenyan specifics are published.

A practical AML and KYC build for a Kenyan crypto business

The duties above translate into a programme. In build order:

  1. Register with the Financial Reporting Centre. Complete goAML registration using Form FRC RF 1-1 under POCAMLA section 47A. This is a criminal offence to skip, so it goes first.
  2. Appoint the MLRO and write the AML policy. Name a senior, independent MLRO (the internal reporting officer POCAMLA section 47 requires you to identify) and document the internal controls and internal reporting procedures section 47 requires: the suspicion-escalation route, the decision record, the training plan.
  3. Stand up CDD and onboarding. Build identity collection and verification to POCAMLA section 45, with risk tiering, sanctions and PEP screening, beneficial-ownership capture for corporates, and enhanced due diligence triggers.
  4. Deploy transaction monitoring. Implement rules and, for any meaningful volume, on-chain analytics tuned to virtual-asset typologies, feeding alerts to the MLRO under POCAMLA section 44(1).
  5. Wire the reporting pipelines. Build the two-day STR path (section 44(2)) and the automated USD 15,000 CTR trigger (Fourth Schedule), both filing through goAML.
  6. Build Travel Rule capability. Add origination, transmission, receipt and screening of Travel Rule data to the FATF Recommendation 16 standard, ready to tune to the Kenyan threshold once gazetted.
  7. Set seven-year retention. Configure records retention and real-time read-only regulator access to meet POCAMLA section 46 and the VASP Act records duty.
  8. Train and test. Train frontline and compliance staff (including on the no-tipping-off rule), and run independent testing of the programme.

Two registrations sit alongside this AML build and should be sequenced with it. The VASP licence itself, with CBK or CMA, will open once the Regulations are gazetted. And, because a VASP holds national IDs, passports, addresses and transaction histories, registration with the Office of the Data Protection Commissioner is a separate precondition for processing that personal data: the overlap between AML records and data-protection duties is covered in crypto and data protection in Kenya.

How do AML duties interact with VASP licensing and tax?

They run in parallel, on different statutes. The AML and KYC duties bite from 4 November 2025 under POCAMLA, before any licence exists. The licence itself sits under the VASP Act and is not yet available because the Regulations are still draft: see the VASP compliance deadline in Kenya for the transitional one-year window that closes on 4 November 2026.

On the draft figures that the proposed VASP Regulations 2026 attach to licensing (minimum core capital, licensing fees, stablecoin reserves): those are DRAFT, published for comment on 17 March 2026 and not yet gazetted, so they may change and should not be relied on as final. The AML duties in this guide, by contrast, are already in force.

Frequently asked questions

Do AML and KYC rules apply before I get a VASP licence? Yes. The POCAMLA amendment made every VASP a reporting institution from 4 November 2025. The duties do not wait for the licence. CBK and CMA have confirmed no VASP is licensed yet because the Regulations are still draft, but that does not pause the AML obligations.

How fast must I file a suspicious transaction report? Within two days of suspicion arising, under POCAMLA section 44(2). The threshold is suspicion, not proof, and the report is due whether or not the transaction completed.

What is the cash transaction reporting threshold? USD 15,000, or its equivalent in any currency, under the Fourth Schedule to POCAMLA. Cash transactions above that line must be reported whether or not they look suspicious.

How long must I keep records? At least seven years, under POCAMLA section 46, with the VASP Act adding a parallel seven-year duty and a real-time read-only access requirement for the regulator.

Do I have to register with the Financial Reporting Centre even though I have not been licensed? Yes. Registration with the Financial Reporting Centre via the goAML portal, using Form FRC RF 1-1, is required under POCAMLA section 47A and is a criminal offence to skip. It is one of the first steps, not one to defer.

Does the FATF Travel Rule apply to Kenyan crypto businesses? The Travel Rule is part of the FATF standards Kenya is working to meet, and Kenya is grey-listed (since February 2024 and still listed as of the FATF June 2026 plenary). The VASP Act’s requirement to comply with the full range of AML, CFT and CPF measures is the domestic hook. Build to the FATF Recommendation 16 standard now; the precise Kenyan threshold and data standard are expected in Regulations or guidance not yet gazetted.

Who can be the MLRO? A senior, independent person inside the business who can receive internal suspicion reports, decide on escalation, and file with the Financial Reporting Centre even when a transaction is commercially attractive. POCAMLA section 47 requires you to identify this internal reporting officer as part of mandatory internal controls and reporting procedures; ‘MLRO’ is the conventional name for the role.

Is anonymous or no-KYC onboarding still possible? No. POCAMLA section 45 requires identification and verification of every customer before the relationship goes live. Anonymous onboarding is not lawful for any business inside the VASP definition. Separately, mixer, tumbler and anonymity-enhancing services are prohibited outright under the VASP Act: see unlicensed VASP penalties in Kenya.


If you are building a crypto exchange, a custodial wallet, a payment gateway or any virtual-asset business aimed at Kenyan users, the AML and KYC obligations are live today and the penalties for getting them wrong are real. We help founders and treasury teams stand up a compliant programme: the goAML registration, the MLRO appointment, the CDD and monitoring framework, the STR and CTR pipelines, the Travel Rule build, and the records architecture, sequenced alongside the VASP licensing strategy and the data-protection registration. Book a consultation and we will scope your compliance file.

Related reading: VASP licensing in Kenya, the VASP compliance deadline in Kenya, crypto and data protection in Kenya, unlicensed VASP penalties in Kenya, and is cryptocurrency legal in Kenya.