Fintech and digital lending regulation in Kenya

Dignified financial institution building illustrating fintech regulation in Kenya

No Comments

Legal Articles

Kenya’s fintech sector is among the most dynamic in Africa. M-Pesa — the mobile money service launched by Safaricom in 2007 — demonstrated that transformative financial infrastructure could emerge from Kenya and be replicated globally. That legacy has made Nairobi a magnet for fintech investment and a testing ground for mobile lending, digital insurance, blockchain-based remittances and buy-now-pay-later services. The regulatory framework has had to evolve at pace: the Central Bank of Kenya (CBK) has brought digital credit providers within its perimeter, the Capital Markets Authority (CMA) has opened a regulatory sandbox, and the government has invested in an inter-agency regulatory co-ordination architecture. Understanding where your fintech business sits in this landscape — and which licences it needs — is the starting point for any regulatory engagement in this sector.

At a glance
  • Digital credit providers (DCPs) — lenders who extend credit via digital platforms — must now be licensed by the CBK under the Central Bank of Kenya (Amendment) Act 2021; hundreds of unlicensed apps were removed from app stores following the introduction of this requirement.
  • Mobile money operators require a Payment Service Provider (PSP) licence from the CBK under the National Payment System Act 2011; M-Pesa, Airtel Money and T-Kash are the major licensed operators.
  • The CMA’s Regulatory Sandbox allows fintech companies to test innovative capital markets products and services in a controlled environment before seeking a full licence.
  • All licensed fintech businesses that deal with customer funds are reporting institutions under the Proceeds of Crime and Anti-Money Laundering Act 2009 (POCAMLA) and must implement full AML/CFT programmes.
  • The Data Protection Act 2019 applies in full to fintech businesses — including mobile lenders’ access to smartphone data — and the ODPC has specifically scrutinised lending apps’ data collection practices.

The regulatory architecture

Kenya’s fintech regulation is distributed across three principal regulators and several sectoral authorities. The Central Bank of Kenya (CBK) supervises banks, microfinance banks, mortgage finance companies, payment service providers and digital credit providers. The Capital Markets Authority (CMA) supervises investment platforms, crowdfunding portals, digital asset intermediaries and collective investment scheme managers. The Insurance Regulatory Authority (IRA) supervises digital insurance distributors and InsurTech businesses. The Sacco Societies Regulatory Authority (SASRA) supervises digital savings and credit cooperative organisations.

In 2021 the government established the Financial Sector Regulatory Authorities (FSRA) co-ordination mechanism to address regulatory overlaps and gaps. A company whose business model spans two or more of these regulatory perimeters — a “super app” offering payments, lending and insurance in one platform — must navigate multiple licence requirements simultaneously and maintain ongoing dialogue with all relevant regulators.

Digital credit providers

The Central Bank of Kenya (Amendment) Act 2021 brought digital credit providers within the CBK’s licensing framework for the first time. A “digital credit provider” is a person who provides credit facilities or credit services by electronic means. The CBK issued the Digital Credit Providers Regulations 2022, which set out the eligibility criteria for a DCP licence: minimum core capital (KES 3 million for a Tier 2 DCP and KES 10 million for a Tier 1 DCP), a fit-and-proper assessment of directors and shareholders, an approved business plan, and compliance with interest rate disclosure, data privacy and debt-collection conduct requirements.

The DCP Regulations impose conduct obligations that directly address the abusive practices that proliferated before licensing: DCPs may not access a borrower’s phone contacts list for debt collection purposes; loan terms and the Annual Percentage Rate (APR) must be disclosed clearly before disbursement; debt collection agents must be licensed and must not use threatening or abusive tactics. A DCP that does not comply with the conduct rules risks licence suspension or revocation.

Payment service providers and mobile money

The National Payment System Act 2011 (NPS Act) and the National Payment System Regulations 2014 are the primary instruments for payment regulation. A PSP licence from the CBK is required to operate a payment system or provide payment services. The CBK categorises PSPs by the nature of their activities: mobile network operators providing mobile money services (Safaricom/M-Pesa, Airtel, Telkom), banks providing internet and mobile banking, payment aggregators, payment facilitators, and card networks. Each category has its own capital, operational and technical requirements.

The CBK has also implemented a regulatory framework for fast payment systems through the Kenya Fast Payment System (KFPS) and has driven interoperability between mobile money platforms — a Kenyan user can now send money between M-Pesa, Airtel Money and T-Kash accounts without a bilateral arrangement. Interoperability has been achieved through a combination of CBK mandate and commercial negotiation.

The CMA regulatory sandbox

The CMA’s Regulatory Sandbox Policy Guidance Note (2019) allows fintech companies to test innovative products and services that fall within the CMA’s regulatory perimeter — such as robo-advisory platforms, digital securities exchanges, tokenised securities and investment platforms — in a controlled environment with a time-limited “sandbox licence.” A sandbox participant is subject to agreed testing parameters, reporting obligations and conditions designed to protect consumers during the testing period. Successful sandbox exits have led to full CMA licensing for several Kenyan fintechs. Companies considering sandbox applications should engage the CMA Innovation Office at an early stage.

AML/CFT obligations

All CBK-licensed fintech businesses and all CMA-licensed fintech platforms are reporting institutions under POCAMLA. They must implement customer due diligence (know-your-customer/KYC) programmes, maintain transaction records for seven years, appoint a dedicated AML compliance officer, and file Suspicious Transaction Reports (STRs) and Cash Transaction Reports (CTRs) with the Financial Reporting Centre (FRC). The AML Act 2023 strengthened FRC’s investigation powers and introduced risk-based supervision for reporting institutions. Mobile money platforms face particular AML scrutiny given the high transaction volumes and the need to balance financial inclusion with AML controls.

What you should do now

For digital lenders

Apply for a DCP licence from the CBK if you have not done so. The CBK has taken enforcement action against unlicensed DCPs, including directing app stores to remove unlicensed lending applications. Review your data practices against the DCP Regulations and the Data Protection Act 2019: accessing a borrower’s contacts, location data or media without explicit consent is both a DPA violation and a DCP Regulations breach. Obtain a data protection impact assessment for your scoring model if it processes sensitive personal data.

For payment businesses

Map your business model against the NPS Act’s PSP licence categories before launch. A payment aggregator that collects customer funds, even briefly, is likely to require a PSP licence; the CBK takes a substance-over-form approach. Implement a float management policy: customer funds held in a PSP’s float account must be held in a trust or designated account with a licensed bank and must not be commingled with the PSP’s own funds.

For investment platforms and CMA-regulated fintechs

Consider the CMA sandbox for genuinely innovative products that do not fit cleanly within an existing licence category. Prepare a detailed regulatory analysis before the sandbox application: the CMA will want to understand which aspects of your model require a dispensation and why a standard licence is not adequate. Budget for ongoing compliance costs — a sandbox licence is not a licence exemption; it is a licence with monitoring obligations.

Frequently asked questions

Q1. Does a buy-now-pay-later (BNPL) product require a DCP licence?

Yes, in most configurations. A BNPL product that allows a consumer to receive goods or services now and pay in instalments — where the provider is bearing the credit risk — is offering credit facilities by electronic means and falls within the definition of a digital credit provider. The CBK’s DCP licensing requirement applies regardless of whether the product is described as “credit” or framed differently.

Q2. Can a foreign fintech company operate in Kenya without a local entity?

Generally, no. The CBK requires DCP licensees to be incorporated in Kenya; PSP licences are similarly restricted to Kenyan-incorporated entities. The CMA sandbox and full CMA licences are available to foreign companies but require a local establishment. Cross-border fintech services targeted at Kenyan consumers will typically trigger Kenyan licensing requirements regardless of where the platform is hosted or incorporated.

Q3. Is cryptocurrency regulated in Kenya?

As of 2026, Kenya does not have a primary licensing regime for cryptocurrency exchanges or for the issuance of crypto-assets. The CBK has issued caution notices about the risks of virtual currencies, and the CMA has considered crypto-assets that exhibit security-like characteristics within its existing perimeter. A formal regulatory framework for virtual assets is under development. Businesses operating in this space should seek specific legal advice and monitor CBK and CMA developments closely; operating without a licence in a space the regulator later determines was licensed carries significant retrospective risk.

Q4. What consumer protection obligations apply to mobile lenders?

The DCP Regulations 2022 impose mandatory disclosure of loan terms including the APR before disbursement; a prohibition on accessing the borrower’s phone contacts for any purpose including debt collection; a requirement to provide a 24-hour cooling-off period for loans above KES 10,000; and restrictions on the conduct of third-party debt collectors. Separately, the Consumer Protection Act 2012 prohibits unfair contract terms and misleading commercial practices — relevant to the terms and marketing of digital credit products. The CBK has the power to direct a DCP to refund charges imposed in breach of its regulations.

Q5. How is mobile money float regulated?

Mobile money operators are required under the MAC Act and CBK regulations to hold customer float — the aggregate balance held in customers’ mobile wallets — in a dedicated trust account with a CBK-licensed bank. The float may not be used by the operator for its own purposes. The CBK conducts regular audits of float accounts to ensure customer funds are fully segregated and available for redemption on demand. This regime protects mobile money customers in the event of the operator’s insolvency.

How OLM Law can help

OLM Law advises fintech companies — digital lenders, payment businesses, investment platforms, InsurTech companies and blockchain ventures — on CBK and CMA licensing, regulatory compliance, product structuring, data protection, AML programme design, and regulatory engagement. We represent clients before the CBK, CMA, ODPC and FRC, and advise on the structuring of fintech investments and joint ventures. To discuss your fintech regulatory question, contact us at [email protected].

Key fintech regulatory licences in Kenya
Licence / approvalRegulatorGoverning instrumentTypical applicant
Payment Service Provider (PSP) licenceCentral Bank of KenyaNational Payment System Act 2011Mobile money operators, payment gateways
Digital Credit Provider (DCP) licenceCentral Bank of KenyaCentral Bank of Kenya (Amendment) Act 2021; CBK DCP Regulations 2022App-based digital lenders
Non-Deposit-Taking Microfinance (MFI) licenceCentral Bank of KenyaMicrofinance Act 2006Fintech lenders outside DCP regime
Insurance intermediary approvalInsurance Regulatory Authority (IRA)Insurance Act (Cap. 487)Insurtech distribution platforms
Capital markets intermediary licenceCapital Markets Authority (CMA)Capital Markets Act (Cap. 485A)Investment platforms, robo-advisers

In our view, the multi-regulator landscape creates material compliance complexity for operators whose products straddle two or more regulated activities. A platform that both disburses credit and facilitates payments will require both a DCP licence from the CBK and a PSP registration, each with distinct capital, reporting, and consumer disclosure requirements. We advise fintech operators to map their full product set against each regulatory perimeter at the outset, rather than seeking licences incrementally as regulators identify gaps.

Sources and authorities

Central Bank of Kenya Act (Cap. 491), as amended by the Central Bank of Kenya (Amfndment) Act 2021. | National Payment System Act 2011. | National Payment System Regulations 2014. | Digital Credit Providers Regulations 2022. | Capital Markets Act (Cap. 485A). | CMA Regulatory Sandbox Policy Guidance Note 2019. | Proceeds of Crime and Anti-Money Laundering Act 2009 (POCAMLA), as amended by the AML Act 2023. | Data Protection Act 2019. | Consumer Protection Act 2012. | Central Bank of Kenya: centralbank.go.ke. | Financial Reporting Centre: frc.go.ke. | Capital Markets Authority: cma.or.ke. | All statutes available via kenyalaw.org.

Disclaimer: This article is general commentary on Kenyan law as at September 2026 and does not constitute legal advice. Specific situations require specific advice. No solicitor-client relationship is created by reading this article. OLM Law Advocates LLP accepts no liability for bction taken in reliance on it.