Remote VASP serving residents in Kenya
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Kenya with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD: Verify customer identities and maintain beneficial ownership (UBO) records (ke.licensing.customer-due-diligence-cdd-verify)
- EDD: Apply enhanced due diligence for high-risk cross-border VA activities (ke.licensing.customer-due-diligence-cdd-verify)
- STR: Report suspicious transactions involving virtual assets to the Financial Reporting Centre (FRC) promptly (ke.licensing.suspicious-transaction-reporting-str-report)
- Record-keeping: Retain transaction records, customer data, and verification documents for at least 7 years per POCAMLA standards (ke.licensing.record-keeping-obligations-retain-transaction-records)
- AML/CFT compliance program required under the VASP Act 2025 and Draft VASP Regulations 2026 (ke.licensing.draft-virtual-asset-service-providers)
- Asset segregation: 30% of customer funds must be held in Kenyan banks for stablecoin-related services (ke.licensing.draft-virtual-asset-service-providers)
Key Restrictions
- Must be licensed under the Virtual Asset Service Providers Act, 2025 (presidential assent Nov 15, 2025) (ke.licensing.virtual-asset-service-providers-act)
- Must maintain a physical office in Kenya (ke.licensing.draft-virtual-asset-service-providers)
- Remote cross-border service without a local entity is not permitted — the VASP Act requires local licensing, incorporation, and physical presence (ke.licensing.draft-virtual-asset-service-providers)
- Stablecoin-related services require 30% of customer funds deposited in Kenyan banks (ke.licensing.draft-virtual-asset-service-providers)
- Oversight shared between CMA (securities-like crypto assets), CBK (payment systems, stablecoins, fiat interfaces), and FRC (AML/CFT) — possible multi-regulator compliance burden (ke.licensing.capital-markets-authority-cma-regulates, ke.licensing.central-bank-of-kenya-cbk, ke.licensing.financial-reporting-centre-frc-primary)
- Tax obligations to Kenya Revenue Authority (KRA) on crypto income (ke.licensing.kenya-revenue-authority-kra-handles)
Key Risks
- Enforcement precedent: DCI Crypto Fraud Unit handled 500+ cases and dozens of arrests in 2024; unlicensed operators face criminal investigation and arrest (ke.enforcement.directorate-of-criminal-investigations-dci)
- Worldcoin enforcement: operators collecting data without proper registration had activities banned and registrations revoked by ODPC and High Court (ke.enforcement.entity-targeted-tools-for-humanity)
- Bitpesa precedent: CBK and courts cut off payment rails (M-PESA) to stop unauthorized crypto remittance — unlicensed remote operators risk payment channel disruption (ke.enforcement.entity-targeted-bitpesa-operating-through)
- Regulatory framework still being finalized (Draft Regulations 2026 under review) — some ambiguity in operational requirements (ke.licensing.draft-virtual-asset-service-providers)
- Cross-border VA activities are explicitly flagged as high-risk under CDD/EDD rules, increasing scrutiny on remote operators (ke.licensing.customer-due-diligence-cdd-verify)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Kenya's Virtual Asset Service Providers Act, 2025 is Act No. 20 of 2025; it received presidential assent on 15 October 2025, was published in Kenya Gazette Supplement No. 173 (Acts No. 20) on 21 October 2025 and commenced on 4 November 2025, and its implementing regulations were gazetted as Legal Notice No. 134 of 2026 on 22 July 2026.
The Virtual Asset Service Providers Regulations, 2026 stopped being a draft on 22 July 2026, when they were gazetted as Legal Notice No. 134 of 2026 in Kenya Gazette Supplement No. 185; they run to 151 regulations in fifteen parts and six schedules and impose licensing, capital, AML/CFT/CPF, cybersecurity, custody, market-conduct and stablecoin reserve duties that are now in force.
Virtual asset service providers licensed in Kenya must perform customer due diligence before onboarding a client under regulation 32 of the Virtual Asset Service Providers Regulations, 2026, carried out in accordance with the Proceeds of Crime and Anti-Money Laundering Act, and the Second Schedule to the Virtual Asset Service Providers Act, 2025 makes every virtual asset service provider a reporting institution under that Act.
The Second Schedule to Kenya's Virtual Asset Service Providers Act, 2025 amends the Proceeds of Crime and Anti-Money Laundering Act so that the definition of reporting institution expressly includes a virtual asset service provider, which places Kenyan virtual asset service providers under the suspicious transaction reporting duty owed to the Financial Reporting Centre with effect from the Act's commencement on 4 November 2025.
Kenyan virtual asset service providers must keep a record of both client and own transactions for not less than seven years from the date of the transaction under section 44(2) of the Virtual Asset Service Providers Act, 2025, repeated at regulations 22(1)(b) and 26(3) of Legal Notice No. 134 of 2026, and must give the regulator online read-only real-time access to those records under section 44(1).
Kenya's financial intelligence unit is the Financial Reporting Centre, established under the Proceeds of Crime and Anti-Money Laundering Act, which receives and analyses suspicious transaction reports; AML/CFT/CPF supervision and enforcement for virtual asset service providers is carried out by the Central Bank of Kenya and the Capital Markets Authority under section 32 of the Virtual Asset Service Providers Act, 2025.
The Capital Markets Authority licenses and supervises virtual asset exchanges, virtual asset brokers, virtual asset investment advisers, virtual asset managers, virtual asset offering providers conducting initial coin offerings, tokenisation providers and token issuance platforms under the First Schedule to the Virtual Asset Service Providers Act, 2025, and section 11(3)(fb) of the Capital Markets Act now requires it to regulate virtual asset service providers.
The Central Bank of Kenya licenses virtual asset wallet providers, virtual asset payment processors and stablecoin issuance under the First Schedule to the Virtual Asset Service Providers Act, 2025, and section 4A(1)(dc) of the Central Bank of Kenya Act now empowers it to license and supervise virtual asset service providers; virtual asset exchanges are licensed by the Capital Markets Authority and fall outside the Central Bank's perimeter.
Kenya's 3 per cent digital asset tax under section 12F of the Income Tax Act, introduced by section 10 of the Finance Act 2023 from 1 September 2023, was repealed and replaced from 1 July 2025 by excise duty at 10 per cent of the excisable value of fees charged on virtual asset transactions, which the provider collects and remits to the Commissioner on or before the twentieth day of the following month; the Virtual Asset Service Providers Act, 2025 made no tax amendment.
Directorate of Criminal Investigations (DCI) Crypto Fraud Unit: Handled over 500 crypto-related cases in past three years; dozens of arrests in 2024. High-profile busts in Nairobi and Nakuru targeted scams worth $119,000, $100,000, and $30,000 (no named entities or penalties detailed). Losses totaled $43.3 million in 2024 scams.
The Office of the Data Protection Commissioner issued suo motu determination ODPC/COMP/1394/2023 on 6 September 2023 against Worldcoin Foundation, Tools for Humanity and Tools for Humanity GmbH over biometric iris data collected in Kenya; the general penalty in section 73 of the Data Protection Act, No. 24 of 2019 is a fine not exceeding three million shillings or imprisonment not exceeding ten years or both, while the Data Commissioner's administrative penalty notice under sections 62 and 63 is capped at five million shillings or one per cent of an undertaking's preceding annual turnover, whichever is lower.
Entity targeted: Bitpesa (operating through Lipsha Consortium Limited). Violation type: Operating money remittance business via Bitcoin without CBK authorization; AML/KYC non-compliance due to cryptocurrency anonymity. Penalty amount: None specified (service termination, not direct fine).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Kenyan residents must establish a local entity, obtain a license under the VASP Act 2025, maintain a physical office in Kenya, comply with AML/CFT obligations (CDD, EDD, STR, 7-year record retention) under FRC supervision, and face significant enforcement risk (DCI crypto fraud unit, payment-rail shutdown precedent) if operating without authorization.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?