DeFi protocol frontend in Kenya
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Kenya with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD): Verify customer identities, maintain beneficial ownership (UBO) records, and apply enhanced due diligence for high-risk relationships (e.g., cross-border VA activities) — per ke.licensing.customer-due-diligence-cdd-verify
- Suspicious Transaction Reporting (STR): Report suspicious activities, including those involving virtual assets, to the Financial Reporting Centre (FRC) promptly — per ke.licensing.suspicious-transaction-reporting-str-report
- Record-Keeping Obligations: Retain transaction records, customer data, and verification documents for at least 7 years (per POCAMLA standards applied to VASPs) — per ke.licensing.record-keeping-obligations-retain-transaction-records
- AML/CFT compliance program required as part of VASP licensing under the VASP Act 2025 and draft Regulations 2026 — per ke.licensing.draft-virtual-asset-service-providers
- Asset segregation: e.g., 30% of customer funds in Kenyan banks for stablecoin-related activities — per ke.licensing.draft-virtual-asset-service-providers
Key Restrictions
- DeFi frontend operators are likely captured as VASPs under the Virtual Asset Service Providers Act 2025 if they facilitate exchanges, transfers, or custody of virtual assets for Kenyan residents — requiring a VASP license
- Physical office requirement in Kenya under draft VASP Regulations 2026 — per ke.licensing.draft-virtual-asset-service-providers
- Geofencing/KYC screening of Kenyan residents is necessary; operating without a license and without customer screening risks CBK enforcement (Bitpesa precedent — services terminated for facilitating crypto without authorization) — per ke.enforcement.entity-targeted-bitpesa-operating-through
- Fee-taking (e.g., frontend fees, swap fees) strengthens the case that the operator is a VASP providing financial services for reward, making licensing unavoidable
- Coordination with multiple regulators (CMA, CBK, FRC, KRA) required — single-window licensing not yet fully implemented
Key Risks
- CBK enforcement precedent: Bitpesa's crypto-to-fiat service was terminated and upheld by courts for operating without authorization — similar logic could apply to a fee-collecting DeFi frontend targeting Kenyan users — per ke.enforcement.entity-targeted-bitpesa-operating-through
- DCI Crypto Fraud Unit has handled 500+ crypto-related cases; aggressive enforcement against unlicensed crypto operators — per ke.enforcement.directorate-of-criminal-investigations-dci
- Regulatory framework is in flux (VASP Act just enacted Nov 2025, draft regulations still being finalized 2026) — high ambiguity on how DeFi-specific models will be classified
- Worldcoin enforcement (biometric data collection banned, operations halted) shows regulators take a strict approach to novel crypto-adjacent models that lack compliance frameworks — per ke.enforcement.entity-targeted-tools-for-humanity
- Tax obligations through KRA: crypto income is taxable, and failure to register/report could trigger KRA and DCI action — per ke.licensing.kenya-revenue-authority-kra-handles
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Virtual Asset Service Providers Act, 2025: Enacted November 15, 2025 (presidential assent); establishes legal framework for VASPs. Draft regulations operationalize it.
Draft Virtual Asset Service Providers Regulations, 2026: Public participation completed (deadline ~April 10-15, 2026); next steps include review for finalization. Requires licensing, AML/CFT compliance, asset segregation (e.g., 30% customer funds in Kenyan banks for stablecoins), physical offices, fees, and bans on anonymous transactions.
Virtual Asset Service Providers Bill 2025: https://www.afriwise.com/blog/kenya-now-has-a-crypto-law-virtual-asset-service-providers-vasp-bill-2025
Customer Due Diligence (CDD): Verify customer identities, maintain beneficial ownership (UBO) records, and apply enhanced due diligence for high-risk relationships (e.g., cross-border VA activities).
Suspicious Transaction Reporting (STR): Report suspicious activities, including those involving virtual assets, to the Financial Reporting Centre (FRC) promptly.
Record-Keeping Obligations: Retain transaction records, customer data, and verification documents for at least 7 years (per POCAMLA standards applied to VASPs).
Financial Reporting Centre (FRC): Primary AML/CFT authority; receives/analyzes STRs. Website: frc.go.ke.
Capital Markets Authority (CMA): Regulates securities-like crypto assets, token offerings, and develops VASP policy. Website: cma.or.ke.
Central Bank of Kenya (CBK): Oversees payment systems, wallets, exchanges, and stablecoins interfacing with fiat. Website: centralbank.go.ke.
Capital Markets Authority (CMA): Oversees exchanges, brokers, tokenization platforms, and securities-like crypto assets; leading draft regulations.
Kenya Revenue Authority (KRA): Handles taxation on crypto income and participates in framework development.
Entity targeted: Bitpesa (operating through Lipsha Consortium Limited). Violation type: Operating money remittance business via Bitcoin without CBK authorization; AML/KYC non-compliance due to cryptocurrency anonymity. Penalty amount: None specified (service termination, not direct fine).
Directorate of Criminal Investigations (DCI) Crypto Fraud Unit: Handled over 500 crypto-related cases in past three years; dozens of arrests in 2024. High-profile busts in Nairobi and Nakuru targeted scams worth $119,000, $100,000, and $30,000 (no named entities or penalties detailed). Losses totaled $43.3 million in 2024 scams.
Entity targeted: Tools for Humanity (parent company), Worldcoin Foundation, World Assets Limited, Platinum De Plus Limited. Violation type: Unauthorized collection, processing, and transfer of biometric data (iris scans) without proper registration as data controllers/processors; misrepresentation in registration; potential public safety risks. Penalty amount: No monetary fine specified; potential fines up to KES 3 million (~USD 20,000) or 10 years imprisonment for registration violations; possible equipment forfeiture.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend serving Kenyan residents is likely to be classified as a VASP under the VASP Act 2025, requiring a high-burden license, local entity incorporation, physical office, full AML/CFT compliance (CDD, STR, 7-year record-keeping), geofencing/KYC of users, and asset segregation; fee-taking virtually guarantees regulated status, and enforcement risks are significant given the Bitpesa and DCI precedents.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?