Virtual Asset Custody Obligations Kenya is a question we field often from clients, and this article sets out the practical answer.
Custody is where a wallet provider’s licence becomes real. Everything else in Kenya’s Virtual Asset Service Providers Regulations, 2026 is about how a business is run; regulation 66 is about what happens to a consumer’s actual holdings once the provider has them. For product and compliance teams building or buying custody infrastructure, this is the regulation that dictates system design, not just paperwork.
Virtual Asset Custody Obligations Kenya: The Practical Requirements
The sections below walk through what this involves in practice. The primary legal texts and regulator guidance sit at www.centralbank.go.ke, and the rest of this article works through the detail.
What a wallet provider must actually do with client assets
Regulation 66 sets out a detailed list of obligations for any licensee providing virtual asset wallet services. Three requirements sit at the centre of it. First, a provider must segregate its consumers’ virtual assets from its own holdings and from any other non-consumer assets it handles. Second, on the relevant distributed ledger itself, consumer assets must sit on separate addresses from the provider’s own assets. Third, where the provider maintains internal ledger accounts rather than on-chain segregation for every consumer, it must still keep those accounts separately for consumer assets versus its own.
This is a three-layer test: legal segregation, on-chain segregation, and internal bookkeeping segregation. A provider that gets the accounting right but pools consumer assets in a single on-chain address has not met the requirement. A provider that separates addresses but blends the internal ledger has not met it either.
Reconciliation: a monthly, reportable obligation
Regulation 66(1)(d) requires a wallet provider to reconcile its on-chain holdings against its internal records and consumer entitlements every month, and to make those reconciliation records available to the Central Bank of Kenya by the tenth day of the following calendar month. This is not a self-certification exercise. It is a recurring compliance deliverable with a fixed deadline, and it needs to be built into the provider’s operational calendar from day one rather than treated as an annual audit item.
For a provider using a third-party custody vendor rather than holding keys itself, this obligation does not disappear. The licensee remains the party responsible for producing the reconciliation and meeting the CBK deadline, which means the vendor contract needs to guarantee the data access and timing the licensee needs to comply.
Consent, disclosure, and what a provider cannot do with client assets
Where a provider holds consumer assets in an omnibus account, or under any arrangement that does not segregate assets under each consumer’s own name, regulation 66(1)(e) requires explicit consumer consent before that happens. Standard disclosures and the standard consumer agreement must also be readily accessible on the provider’s website, in plain, non-technical language, under regulation 66(1)(h).
Regulation 66(1)(g) is the provision compliance teams should read most carefully: a wallet provider may not lend, use, hypothecate, pledge, or otherwise encumber consumer assets entrusted to it for safekeeping. This closes off a range of business models that have been common in less regulated markets, including using client deposits as working capital or as collateral for the provider’s own borrowing. A provider also has to hold, at all times, a sufficient amount of each type of virtual asset to meet its obligations to consumers, and have procedures in place to return those assets on request.
Outsourcing custody to a third party
Many providers do not run their own custody infrastructure; they rely on a specialist vendor. Regulation 113 governs this directly. A licensee may outsource its operational functions, including custody, but must obtain the approval of the relevant regulatory authority at least thirty days before the outsourcing agreement is implemented. Approval is not a formality to be sought after the contract is signed.
The regulation also limits what outsourcing can achieve. A licensee cannot outsource in a way that impairs the quality of its own internal controls, or that limits the regulator’s ability to monitor the licensee’s compliance with the Act and the Regulations. Where a material function is outsourced, the licensee must ensure the arrangement does not amount to its senior officers delegating away their responsibilities, and that the licensee’s relationship and obligations to its own consumers are unchanged by the fact that a vendor is doing the underlying work. In practical terms, the custody vendor is a technology and operations provider; the licensed entity carries the regulatory responsibility regardless of who is actually holding the keys.
Insulation and return of assets
Regulation 66(1)(f) requires a provider to maintain procedures ensuring that virtual assets held in custody remain separate from, and insulated from, the provider’s own business at all times, not just on the day of an audit. This insulation requirement is what is meant to keep consumer assets out of reach if the provider itself runs into financial difficulty. Regulation 66(1)(j) then requires the provider to have procedures in place to return consumer assets, or the value of them, on request, which in practice means the segregation and reconciliation obligations above have to produce a clean, current, asset-by-asset record at all times, not just a monthly snapshot.
None of this is optional documentation. A regulator reviewing a custody model will expect to see the segregation architecture, the reconciliation process, and the return procedure operating together as one system, since a gap in any one of them defeats the purpose of the other two.
Building this into a licence application
Because custody arrangements sit inside the licence application itself under regulation 6(2), a provider that intends to use third-party custody needs to have that arrangement, and the outsourcing approval process under regulation 113, mapped out before it applies rather than treated as a later implementation detail. Providers issuing a stablecoin face closely related obligations on reserve assets, covered in our guide to stablecoin issuance in Kenya.
How We Can Help
Clay & Associates Advocates advises virtual asset businesses on the full scope of Kenya’s licensing regime, from structuring the licence application to negotiating and vetting third-party custody and outsourcing agreements against regulation 113’s approval requirements. Our guide to Kenya’s virtual asset licensing regime covers the wider application process. Contact our Regulatory & Compliance practice to discuss a custody model before you build or contract for it.
Sources: Virtual Asset Service Providers Regulations, 2026 (Legal Notice 134 of 2026), regulations 6(2), 66, 113.
Frequently asked questions
Does using a third-party custody vendor remove my obligations under regulation 66?
No. The licensee remains responsible for segregation, reconciliation, and reporting regardless of who technically holds the assets. The vendor relationship has to be structured to let the licensee meet those obligations itself.
How often does reconciliation have to happen, and who sees it?
Monthly, with records made available to the Central Bank of Kenya by the tenth day of the following calendar month.
Can a wallet provider ever lend out consumer assets to generate a return?
No. Regulation 66(1)(g) prohibits lending, using, hypothecating, pledging, or otherwise encumbering assets held for safekeeping, regardless of consumer consent.
How far in advance do I need regulatory approval to outsource custody?
At least thirty days before the outsourcing agreement is implemented, under regulation 113(2).



