Insights / Corporate & Commercial

Does Your Business Need to Vet Its Own Suppliers? KYC Beyond Your AML Obligations

By Clay & Associates Advocates · 3 min read ·

A businessman on the phone taking notes at his desk

Customer due diligence gets most of the attention in Kenyan AML compliance, because it is the specific, documented obligation that falls on banks, DNFBPs, and other reporting institutions. What gets overlooked is that the underlying money laundering offence in Kenyan law does not only reach reporting institutions. It reaches anyone, including an ordinary business that never registered with the FRC and never thought of itself as having AML obligations at all.

The offence that catches everyone, not just reporting institutions

Under the Proceeds of Crime and Anti-Money Laundering Act, a person who knows, or who ought reasonably to have known, that property is or forms part of the proceeds of crime, and enters into an agreement or transaction involving that property, commits an offence. This is not a duty limited to banks or designated professions. It applies to any business paying a supplier, and the “ought reasonably to have known” standard means willful blindness is not a defence. A company that never asks basic questions about who it is actually paying is not automatically protected simply because nobody told it to check.

Why this is a real risk, not a theoretical one

Shell companies, invoice fraud, and payments routed through intermediaries are not rare in Kenyan commercial practice, and a business that pays a supplier without confirming who actually owns and controls it has no way of knowing whether it has just become part of that chain. Beyond the criminal exposure, there is a simpler commercial risk: a supplier that turns out not to be who it claimed to be can leave a business with no real recourse when a contract goes wrong, since there is no genuine, traceable counterparty behind the invoice.

What proportionate vendor due diligence actually looks like

This does not need to match the full customer due diligence process a bank runs. For most businesses, a workable baseline covers four things: confirming the supplier is a genuinely registered entity, checking who its directors and, where practical, its beneficial owners actually are, confirming payment details match the registered entity rather than a third party, and applying closer scrutiny where a new supplier is unusually eager to be paid through an intermediary account or an unfamiliar payment route. None of this requires specialist software for a typical SME. It requires a checklist that someone actually follows before a new supplier gets onboarded, not after a payment has already gone out.

Where to apply more scrutiny

Higher-value contracts, suppliers introduced through a personal connection rather than a normal procurement process, and suppliers in cash-intensive or historically higher-risk sectors all warrant a closer look before the relationship starts, not a lighter one. The same logic that makes a bank apply enhanced due diligence to a higher-risk customer applies just as sensibly to a business choosing which suppliers to actually pay.

The practical takeaway

Vendor vetting is not a compliance obligation invented by lawyers to create work. It is a direct response to a genuine legal exposure that already exists under Kenyan law for any business, combined with an obvious commercial interest in knowing who you are actually doing business with. A short onboarding checklist, applied consistently, closes most of this gap at very little cost.

Sources

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more