Remote VASP serving residents in Kenya
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Kenya with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD: Verify customer identities and maintain beneficial ownership (UBO) records (ke.licensing.customer-due-diligence-cdd-verify)
- EDD: Apply enhanced due diligence for high-risk cross-border VA activities (ke.licensing.customer-due-diligence-cdd-verify)
- STR: Report suspicious transactions involving virtual assets to the Financial Reporting Centre (FRC) promptly (ke.licensing.suspicious-transaction-reporting-str-report)
- Record-keeping: Retain transaction records, customer data, and verification documents for at least 7 years per POCAMLA standards (ke.licensing.record-keeping-obligations-retain-transaction-records)
- AML/CFT compliance program required under the VASP Act 2025 and Draft VASP Regulations 2026 (ke.licensing.draft-virtual-asset-service-providers)
- Asset segregation: 30% of customer funds must be held in Kenyan banks for stablecoin-related services (ke.licensing.draft-virtual-asset-service-providers)
Key Restrictions
- Must be licensed under the Virtual Asset Service Providers Act, 2025 (presidential assent Nov 15, 2025) (ke.licensing.virtual-asset-service-providers-act)
- Must maintain a physical office in Kenya (ke.licensing.draft-virtual-asset-service-providers)
- Remote cross-border service without a local entity is not permitted — the VASP Act requires local licensing, incorporation, and physical presence (ke.licensing.draft-virtual-asset-service-providers)
- Stablecoin-related services require 30% of customer funds deposited in Kenyan banks (ke.licensing.draft-virtual-asset-service-providers)
- Oversight shared between CMA (securities-like crypto assets), CBK (payment systems, stablecoins, fiat interfaces), and FRC (AML/CFT) — possible multi-regulator compliance burden (ke.licensing.capital-markets-authority-cma-regulates, ke.licensing.central-bank-of-kenya-cbk, ke.licensing.financial-reporting-centre-frc-primary)
- Tax obligations to Kenya Revenue Authority (KRA) on crypto income (ke.licensing.kenya-revenue-authority-kra-handles)
Key Risks
- Enforcement precedent: DCI Crypto Fraud Unit handled 500+ cases and dozens of arrests in 2024; unlicensed operators face criminal investigation and arrest (ke.enforcement.directorate-of-criminal-investigations-dci)
- Worldcoin enforcement: operators collecting data without proper registration had activities banned and registrations revoked by ODPC and High Court (ke.enforcement.entity-targeted-tools-for-humanity)
- Bitpesa precedent: CBK and courts cut off payment rails (M-PESA) to stop unauthorized crypto remittance — unlicensed remote operators risk payment channel disruption (ke.enforcement.entity-targeted-bitpesa-operating-through)
- Regulatory framework still being finalized (Draft Regulations 2026 under review) — some ambiguity in operational requirements (ke.licensing.draft-virtual-asset-service-providers)
- Cross-border VA activities are explicitly flagged as high-risk under CDD/EDD rules, increasing scrutiny on remote operators (ke.licensing.customer-due-diligence-cdd-verify)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Virtual Asset Service Providers Act, 2025: Enacted November 15, 2025 (presidential assent); establishes legal framework for VASPs. Draft regulations operationalize it.
Draft Virtual Asset Service Providers Regulations, 2026: Public participation completed (deadline ~April 10-15, 2026); next steps include review for finalization. Requires licensing, AML/CFT compliance, asset segregation (e.g., 30% customer funds in Kenyan banks for stablecoins), physical offices, fees, and bans on anonymous transactions.
Customer Due Diligence (CDD): Verify customer identities, maintain beneficial ownership (UBO) records, and apply enhanced due diligence for high-risk relationships (e.g., cross-border VA activities).
Suspicious Transaction Reporting (STR): Report suspicious activities, including those involving virtual assets, to the Financial Reporting Centre (FRC) promptly.
Record-Keeping Obligations: Retain transaction records, customer data, and verification documents for at least 7 years (per POCAMLA standards applied to VASPs).
Financial Reporting Centre (FRC): Primary AML/CFT authority; receives/analyzes STRs. Website: frc.go.ke.
Capital Markets Authority (CMA): Regulates securities-like crypto assets, token offerings, and develops VASP policy. Website: cma.or.ke.
Central Bank of Kenya (CBK): Oversees payment systems, wallets, exchanges, and stablecoins interfacing with fiat. Website: centralbank.go.ke.
Kenya Revenue Authority (KRA): Handles taxation on crypto income and participates in framework development.
Directorate of Criminal Investigations (DCI) Crypto Fraud Unit: Handled over 500 crypto-related cases in past three years; dozens of arrests in 2024. High-profile busts in Nairobi and Nakuru targeted scams worth $119,000, $100,000, and $30,000 (no named entities or penalties detailed). Losses totaled $43.3 million in 2024 scams.
Entity targeted: Tools for Humanity (parent company), Worldcoin Foundation, World Assets Limited, Platinum De Plus Limited. Violation type: Unauthorized collection, processing, and transfer of biometric data (iris scans) without proper registration as data controllers/processors; misrepresentation in registration; potential public safety risks. Penalty amount: No monetary fine specified; potential fines up to KES 3 million (~USD 20,000) or 10 years imprisonment for registration violations; possible equipment forfeiture.
Entity targeted: Bitpesa (operating through Lipsha Consortium Limited). Violation type: Operating money remittance business via Bitcoin without CBK authorization; AML/KYC non-compliance due to cryptocurrency anonymity. Penalty amount: None specified (service termination, not direct fine).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Kenyan residents must establish a local entity, obtain a license under the VASP Act 2025, maintain a physical office in Kenya, comply with AML/CFT obligations (CDD, EDD, STR, 7-year record retention) under FRC supervision, and face significant enforcement risk (DCI crypto fraud unit, payment-rail shutdown precedent) if operating without authorization.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?