← Regulations / Kenya / Operating Models / DeFi frontend

DeFi protocol frontend in Kenya

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Kenya with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Customer Due Diligence (CDD): Verify customer identities, maintain beneficial ownership (UBO) records, and apply enhanced due diligence for high-risk relationships (e.g., cross-border VA activities) — per ke.licensing.customer-due-diligence-cdd-verify
  • Suspicious Transaction Reporting (STR): Report suspicious activities, including those involving virtual assets, to the Financial Reporting Centre (FRC) promptly — per ke.licensing.suspicious-transaction-reporting-str-report
  • Record-Keeping Obligations: Retain transaction records, customer data, and verification documents for at least 7 years (per POCAMLA standards applied to VASPs) — per ke.licensing.record-keeping-obligations-retain-transaction-records
  • AML/CFT compliance program required as part of VASP licensing under the VASP Act 2025 and draft Regulations 2026 — per ke.licensing.draft-virtual-asset-service-providers
  • Asset segregation: e.g., 30% of customer funds in Kenyan banks for stablecoin-related activities — per ke.licensing.draft-virtual-asset-service-providers

Key Restrictions

  • DeFi frontend operators are likely captured as VASPs under the Virtual Asset Service Providers Act 2025 if they facilitate exchanges, transfers, or custody of virtual assets for Kenyan residents — requiring a VASP license
  • Physical office requirement in Kenya under draft VASP Regulations 2026 — per ke.licensing.draft-virtual-asset-service-providers
  • Geofencing/KYC screening of Kenyan residents is necessary; operating without a license and without customer screening risks CBK enforcement (Bitpesa precedent — services terminated for facilitating crypto without authorization) — per ke.enforcement.entity-targeted-bitpesa-operating-through
  • Fee-taking (e.g., frontend fees, swap fees) strengthens the case that the operator is a VASP providing financial services for reward, making licensing unavoidable
  • Coordination with multiple regulators (CMA, CBK, FRC, KRA) required — single-window licensing not yet fully implemented

Key Risks

  • CBK enforcement precedent: Bitpesa's crypto-to-fiat service was terminated and upheld by courts for operating without authorization — similar logic could apply to a fee-collecting DeFi frontend targeting Kenyan users — per ke.enforcement.entity-targeted-bitpesa-operating-through
  • DCI Crypto Fraud Unit has handled 500+ crypto-related cases; aggressive enforcement against unlicensed crypto operators — per ke.enforcement.directorate-of-criminal-investigations-dci
  • Regulatory framework is in flux (VASP Act just enacted Nov 2025, draft regulations still being finalized 2026) — high ambiguity on how DeFi-specific models will be classified
  • Worldcoin enforcement (biometric data collection banned, operations halted) shows regulators take a strict approach to novel crypto-adjacent models that lack compliance frameworks — per ke.enforcement.entity-targeted-tools-for-humanity
  • Tax obligations through KRA: crypto income is taxable, and failure to register/report could trigger KRA and DCI action — per ke.licensing.kenya-revenue-authority-kra-handles

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 20% confidence

Virtual Asset Service Providers Act, 2025: Enacted November 15, 2025 (presidential assent); establishes legal framework for VASPs. Draft regulations operationalize it.

licensing 20% confidence

Draft Virtual Asset Service Providers Regulations, 2026: Public participation completed (deadline ~April 10-15, 2026); next steps include review for finalization. Requires licensing, AML/CFT compliance, asset segregation (e.g., 30% customer funds in Kenyan banks for stablecoins), physical offices, fees, and bans on anonymous transactions.

licensing 60% confidence

Virtual Asset Service Providers Bill 2025: https://www.afriwise.com/blog/kenya-now-has-a-crypto-law-virtual-asset-service-providers-vasp-bill-2025

licensing 60% confidence

Customer Due Diligence (CDD): Verify customer identities, maintain beneficial ownership (UBO) records, and apply enhanced due diligence for high-risk relationships (e.g., cross-border VA activities).

licensing 60% confidence

Suspicious Transaction Reporting (STR): Report suspicious activities, including those involving virtual assets, to the Financial Reporting Centre (FRC) promptly.

licensing 60% confidence

Record-Keeping Obligations: Retain transaction records, customer data, and verification documents for at least 7 years (per POCAMLA standards applied to VASPs).

licensing 60% confidence

Financial Reporting Centre (FRC): Primary AML/CFT authority; receives/analyzes STRs. Website: frc.go.ke.

licensing 90% confidence

Capital Markets Authority (CMA): Regulates securities-like crypto assets, token offerings, and develops VASP policy. Website: cma.or.ke.

licensing 60% confidence

Central Bank of Kenya (CBK): Oversees payment systems, wallets, exchanges, and stablecoins interfacing with fiat. Website: centralbank.go.ke.

licensing 20% confidence

Capital Markets Authority (CMA): Oversees exchanges, brokers, tokenization platforms, and securities-like crypto assets; leading draft regulations.

licensing 20% confidence

Kenya Revenue Authority (KRA): Handles taxation on crypto income and participates in framework development.

enforcement 100% confidence

Entity targeted: Bitpesa (operating through Lipsha Consortium Limited). Violation type: Operating money remittance business via Bitcoin without CBK authorization; AML/KYC non-compliance due to cryptocurrency anonymity. Penalty amount: None specified (service termination, not direct fine).

enforcement 90% confidence

Directorate of Criminal Investigations (DCI) Crypto Fraud Unit: Handled over 500 crypto-related cases in past three years; dozens of arrests in 2024. High-profile busts in Nairobi and Nakuru targeted scams worth $119,000, $100,000, and $30,000 (no named entities or penalties detailed). Losses totaled $43.3 million in 2024 scams.

enforcement 100% confidence

Entity targeted: Tools for Humanity (parent company), Worldcoin Foundation, World Assets Limited, Platinum De Plus Limited. Violation type: Unauthorized collection, processing, and transfer of biometric data (iris scans) without proper registration as data controllers/processors; misrepresentation in registration; potential public safety risks. Penalty amount: No monetary fine specified; potential fines up to KES 3 million (~USD 20,000) or 10 years imprisonment for registration violations; possible equipment forfeiture.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a DeFi protocol frontend serving Kenyan residents is likely to be classified as a VASP under the VASP Act 2025, requiring a high-burden license, local entity incorporation, physical office, full AML/CFT compliance (CDD, STR, 7-year record-keeping), geofencing/KYC of users, and asset segregation; fee-taking virtually guarantees regulated status, and enforcement risks are significant given the Bitpesa and DCI precedents.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?