The regulatory sandbox Kenya programme allows fintech companies to test innovative financial products under relaxed regulatory conditions supervised by the CBK or CMA. A regulatory sandbox is a supervised environment in which innovators can test new products, services, and business models under relaxed regulatory requirements for a defined period, with appropriate consumer protections. Kenya has been a pioneer in regulatory sandbox development in Sub-Saharan Africa, with active sandboxes operated by the Central Bank of Kenya (CBK), the Capital Markets Authority (CMA), and the Communications Authority (CA). The sandbox frameworks allow Kenya to remain at the forefront of financial technology innovation while managing regulatory risk.
The CBK Regulatory Sandbox in Kenya
The Central Bank of Kenya launched its Regulatory Sandbox Framework in September 2019 under the National Payment System Act and its amendments. The CBK sandbox allows fintech companies to test innovative payment and financial products with real customers under supervisory oversight for a period of up to 12 months, which may be extended. The sandbox has been used by mobile lending platforms, digital bank account providers, cross-border remittance innovators, and open banking API providers.
CBK Sandbox Application Requirements
To be admitted to the CBK sandbox, an applicant must: be a company incorporated in Kenya; have a genuinely innovative product that cannot be adequately tested under existing licensing frameworks; demonstrate a credible consumer protection plan; have the technical and financial capacity to deliver the proposed product; and show that there is a realistic pathway to full regulatory compliance post-sandbox. Applications are assessed by a dedicated CBK Fintech team, and admission decisions are typically made within eight to twelve weeks of a complete application.
Sandbox Operating Conditions
Sandbox participants operate under a Sandbox Agreement with the CBK specifying the permitted activities, customer limits, geographic boundaries, monitoring requirements, and exit criteria. Participants must submit monthly progress reports to the CBK and must immediately report any consumer harm, security incident, or material deviation from the agreed test parameters. At the conclusion of the sandbox period, the participant either graduates to full licensing or exits the market.
The CMA Regulatory Sandbox
The Capital Markets Authority operates a Regulatory Sandbox under its Regulatory Sandbox Policy Guidance Note (PGN), 2019, effective 26 March 2019, a policy instrument rather than a formal statutory regulation, which governs how the sandbox is administered. The CMA sandbox targets innovations in capital markets including: digital securities issuance and trading platforms; robo-advisory and AI-driven investment platforms; real-time settlement systems; tokenised investment products; and crowdfunding platforms. The CMA sandbox period is 12 months, extendable by the CMA at its discretion.
CMA sandbox graduates that successfully complete the testing phase may apply for the appropriate CMA licence (dealer, investment adviser, fund manager, or a new licence category created specifically for their business model). The CMA sandbox has attracted significant interest from regional fintech companies seeking a CMA-regulated pathway for capital markets innovations.
The Communications Authority Sandbox
The Communications Authority of Kenya operates a regulatory sandbox for telecoms and digital services innovations that require testing in the CA’s licensed spectrum environment. The CA sandbox is particularly relevant for IoT innovators, spectrum-sharing technologies, 5G use case developers, and over-the-top (OTT) service providers testing models that interface with licensed telecoms infrastructure.
Benefits of Regulatory Sandbox Participation
Participation in a regulatory sandbox provides innovators with several significant advantages over operating outside the sandbox. Sandbox participants receive regulatory certainty for the period of the sandbox agreement, protection from enforcement action for activities covered by the sandbox agreement, direct access to the regulator’s technical and legal teams, and guidance on the regulatory pathway post-sandbox. For investors and potential partners, sandbox admission is a signal of regulatory credibility that significantly de-risks the investment decision.
Common Reasons for Sandbox Rejection
Regulatory sandboxes receive more applications than they admit. Common reasons for rejection include: the product is not genuinely innovative and could be delivered under an existing licence; the applicant does not have adequate consumer protection mechanisms; the proposed scale of testing is too large or presents systemic risk; the applicant does not have the technical capacity to execute the proposed test; or the applicant’s business model is inconsistent with the regulator’s policy objectives. A well-prepared sandbox application addresses each of these potential grounds for rejection explicitly.
Our regulatory compliance practice advises fintech companies and innovators on sandbox applications to the CBK, CMA, and CA. For businesses in the technology and startups sector, the regulatory sandbox is often the most efficient route to market for genuinely novel products. For related financial services regulatory advisory, our team provides end-to-end support from application to graduation.
Post-Sandbox Regulatory Compliance Challenges
Graduating from a regulatory sandbox to full compliance is a significant challenge for many fintech companies. During the sandbox period, companies operate under relaxed requirements and close regulator supervision. On graduation, all relaxations end and full compliance with the applicable licensing framework, capital adequacy requirements, AML/CFT obligations, and reporting requirements becomes mandatory. Companies that have not built their compliance infrastructure in parallel with their product development during the sandbox period often find themselves facing a compliance gap at graduation that delays or prevents them from obtaining a full licence. The most successful sandbox graduates begin building their full compliance programme from the first day of sandbox operation, treating the sandbox period as a compliance incubation phase.
Comparing Kenya’s Sandbox with Regional Peers
Kenya’s regulatory sandboxes compare favourably with peers in the region. Rwanda’s NBR Sandbox, Ghana’s Bank of Ghana Sandbox, and Nigeria’s CBN Regulatory Sandbox have all attracted significant fintech activity. Kenya differentiates itself through the maturity of its financial infrastructure (M-Pesa, mobile banking penetration), the depth of its startup ecosystem, and the sophistication of the CBK’s fintech supervision team. However, Kenya’s sandbox capacity is limited by the volume of applications received, and not all qualified applicants are admitted in a given cycle. Early engagement with the relevant regulator before the formal application is submitted significantly improves the likelihood of admission. Our technology and startups practice advises on sandbox pre-application engagement strategy and application preparation.
Regulatory Sandbox and AML Obligations
Even during the sandbox period, participants are not exempt from AML/CFT obligations under POCAMLA 2009. The CBK and CMA sandbox agreements expressly require participants to implement AML/CFT controls proportionate to their business model and customer base, even if the full AML programme required for a licensed entity is not yet in place. Participants must file suspicious transaction reports with the FRC where applicable and must maintain customer due diligence records. The FRC has taken the position that sandbox participants that handle customer funds are Reporting Institutions subject to POCAMLA regardless of their sandbox status. Regulatory sandbox participants should take specific AML compliance advice at the outset of sandbox operations to avoid inadvertent POCAMLA breaches during the testing period.
Sandbox Application Tips for Kenyan Fintechs
Fintech companies applying for the CBK or CMA regulatory sandbox should ensure their applications address the following common failure points: inadequate consumer protection planning (the regulator requires specific consumer redress mechanisms and limits on the scale of consumer exposure during testing); insufficient technological infrastructure (the regulator needs confidence that the platform can be monitored and that consumer data is secure); unclear pathway to full licensing (applications that cannot articulate how the product will be licensed after the sandbox period are less likely to succeed); and insufficient Kenya-specific market analysis (international sandbox graduates applying to Kenya’s regulatory sandbox must demonstrate understanding of the Kenya-specific regulatory and market context). Pre-application meetings with the relevant regulator’s fintech team are strongly recommended and are generally welcomed. Contact our regulatory team for sandbox application preparation support.
Regulatory Sandbox Application Resources
The Central Bank of Kenya’s Regulatory Sandbox Framework and application guidelines are available at centralbank.go.ke. The Capital Markets Authority’s Regulatory Sandbox Regulations 2019 and application procedures are published at cma.or.ke. Our CMA licensing guide covers the pathway from sandbox graduation to full CMA licence.






