Insights / Financial Services

Building an AML Risk Assessment for a Kenyan Fintech or DCP: Where Do You Even Start?

By Clay & Associates Advocates · 3 min read ·

Two people using smartphones for a mobile payment and QR code scan

Most digital lenders discover their AML obligations backwards: they build the product, start onboarding customers, and only then realise the Central Bank of Kenya (Digital Credit Providers) Regulations, 2022 actually require an anti-money laundering policy to be in place before you apply for a licence, not after. The risk assessment is meant to come first. Here is what it actually needs to cover for a fintech or DCP specifically, rather than a generic AML policy copied from a bank template that does not match how your product actually works.

Start with how your product is actually used, not a generic template

A risk-based approach means the assessment has to reflect your specific business, not a bank’s. The questions that matter for a Kenyan fintech are different from the ones that matter for a branch-based lender: How much of your onboarding happens with no human ever seeing the customer? Do you lend through agents or purely through an app? Are loan sizes small and high-volume, which changes how suspicious patterns actually look, or larger and less frequent? Do you touch cross-border transfers or remittance corridors at all? The answers should shape which controls you actually build, rather than defaulting to the heaviest possible checks on every single customer.

Non-face-to-face onboarding is where regulators expect more, not less

Digital-only identity verification is treated as a higher-risk channel precisely because nobody is physically checking the ID against the person holding it. A defensible risk assessment for a DCP typically needs to document how identity is verified (ID plus a liveness-checked selfie is now standard practice among licensed DCPs), how the system flags mismatches, and what happens when verification fails rather than simply being waved through. This is also where enhanced due diligence needs to be triggered automatically, not left to a staff member’s judgement, for politically exposed persons, unusually large loans relative to a customer’s profile, and cross-border activity.

The compliance calendar most founders miss

Beyond the policy itself, a DCP is expected to register as a reporting institution with the Financial Reporting Centre through the goAML platform, file suspicious transaction reports where genuine grounds for suspicion arise, and submit an annual compliance report, with 31 January as the recurring deadline that catches people out most often. None of this is optional once you are licensed, and CBK’s supervision has been active enough that “we are still building it” is not treated as an acceptable answer at inspection.

Putting it together

A workable risk assessment for a Kenyan fintech or DCP realistically covers four things: a written description of how your specific product and customer base create money laundering risk, the identity verification and due diligence controls mapped to that risk, clear rules for when a transaction gets escalated for review, and the ongoing reporting obligations that follow once you are operating. Building it around your actual product, rather than adapting someone else’s bank policy, is usually the difference between something that survives a CBK inspection and something that looks good in a folder but was never actually followed.

Sources

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more