Our Expert in Kenya
No results available
Kenya’s draft payment system reforms would reshape the country’s financial infrastructure by moving toward a model in which banks, electronic money issuers and mobile money operators such as M-Pesa may be required to share customer payment-account data with licensed third parties on customer instruction. Such reforms form part of the broader national payment system modernisation agenda led by the Central Bank of Kenya (CBK) and the National Treasury. For banks, payment service providers (PSPs), fintechs, compliance teams and foreign payment groups seeking entry to the East African market, understanding the direction of travel and engaging early in any public participation process is commercially important.
This article maps the likely licence architecture, explains the open-finance concepts under discussion, sets out capital-sizing considerations and provides a practical checklist for preparing comments on any published draft.
Kenya’s draft payment system reforms point toward an open-finance regime, a more disaggregated set of licence categories and new consent-based data-sharing duties. Who should pay attention now: banks, electronic money issuers, wallet providers, merchant acquirers, aggregators and prospective payment initiation and account information service providers. Where a draft is published for public participation, affected institutions should confirm the exact comment deadline directly from the CBK and Treasury. Three immediate takeaways: (1) map your current and planned activities to the likely licence categories; (2) model the capital impact across multiple licences; and (3) prepare a written comment addressing consent standards, transition timelines and technical rule-making before any published deadline.
Reform of Kenya’s national payment system, building on the National Payment System Act and its regulations, is among the most significant developments in the country’s payments regulation in over a decade. At the centre of the open-finance debate is a framework in which, on a customer’s consent, incumbent holders of payment-account data, including banks and mobile money operators, would make that data available to licensed competitors. The intended effect is to lower barriers for new entrants, stimulate competition and give consumers greater control over their financial information.
Three immediate actions should be prioritised by every affected institution. First, map every service you currently offer, and intend to offer, against the likely licence categories, because many providers will span more than one. Second, model the capital consequences of holding multiple licences, since aggregation rules can materially increase the total minimum capital you must carry. Third, convene legal, compliance, product and technology teams to prepare a written submission for any comment process. Early engagement is the most effective way to shape transitional provisions, consent standards and the technical rules the CBK may later issue.
Any draft legislation or policy on the national payment system should be released for public participation by the relevant authority, typically the CBK, the National Treasury, or Parliament once a Bill is formally introduced. Affected institutions should confirm the exact submission address, format and deadline on the official CBK, Treasury and Parliament portals, and should download the official text directly from those primary sources rather than relying on secondary summaries. Public participation is a constitutional requirement under Article 118 and related provisions of the Constitution of Kenya, 2010, for legislation proceeding through Parliament.
The stated purpose of payment system reform is generally to modernise the legal framework governing payment systems in Kenya, promote competition and innovation, protect consumers and strengthen the oversight of an increasingly interconnected payments ecosystem. Kenya’s payment system reforms would plausibly move away from a single, broad authorisation for payment service providers toward more granular, activity-specific authorisations, and could embed open-finance principles that provide for data portability between licensed participants. The policy intent across comparable markets is to move toward a consent-driven, interoperable payments market.
A central feature of payments reform is the role of the Central Bank of Kenya, which already supervises payment systems and PSPs under the National Payment System Act. Reform proposals typically empower the CBK to set the mechanisms by which payment-account data is shared, to prescribe technical and security standards for interoperability, and to supervise the operation of shared, clearing and settlement systems. In practice, this means the regulator, rather than individual market participants, would determine the architecture through which open-finance requests are routed, authenticated and settled.
In an open-finance model, a data-sharing request is, in essence, an instruction by a customer authorising a licensed third party to access their payment-account data or to initiate a transaction on their behalf. Three categories of request illustrate the scope of open finance that Kenya may move toward:
The common thread across all three is that incumbents, including banks and mobile money operators, would respond to a valid, consented request from a licensed counterparty. The practical consequence is that data held by the largest incumbents could become a shared competitive resource rather than a proprietary advantage.
Consent is the cornerstone of any open-finance regime, and it must interact cleanly with the Data Protection Act, 2019. Kenya’s data-protection framework already requires that personal data be processed lawfully, with the data subject’s consent being a key lawful basis. In practical terms, institutions should expect any open-finance framework and subordinate technical rules to address the following:
Because the Office of the Data Protection Commissioner (ODPC) enforces Kenya’s data-protection regime, institutions should design consent flows that satisfy both the CBK and the ODPC. Recordkeeping, proving that valid consent was obtained, used within scope and respected on revocation, will be a practical compliance burden and a litigation risk if neglected.
Payment system reform typically disaggregates a broad payment service provider authorisation into a set of activity-specific licences. This is a decisive shift: a provider that today operates under one broad authorisation may, under a new regime, need several. Among the likely additions are a payment initiation service provider category and an account information service provider category, dedicated open-finance authorisations that would sit at the lower end of any capital scale but carry significant data-handling obligations.
Mapping begins with an honest inventory of every revenue-generating and customer-facing activity. For each activity, ask: does this involve issuing e-money, holding customer float, operating wallets, acquiring merchant payments, initiating payments on behalf of a customer, reading account data with consent, or operating a clearing and settlement system? Each affirmative answer points to a licence category, and many providers will trigger several.
Consider a bank that offers a consumer wallet, acquires merchant payments and plans to launch an aggregation service reading customer data. That institution may need to hold an electronic money or wallet authorisation, a merchant acquirer authorisation and an account information service provider authorisation, three categories under one roof. A pure-play fintech adding a payment initiation feature to an existing wallet product would, similarly, need to layer a payment initiation authorisation onto its wallet licence. The decision is rarely binary; it is a matrix that drives directly into the capital-sizing exercise discussed below.
| Possible licence category | Purpose / activity | Minimum capital | Practical notes |
|---|---|---|---|
| Electronic Money Issuer | Issue e-money; hold customer float | As prescribed by the CBK | Historically the highest tier, e.g. a full-scale mobile money operator |
| Electronic Wallet Provider | Consumer wallets, basic peer-to-peer transfers | As prescribed by the CBK | Relevant to many fintech wallet players |
| Merchant Acquirer | Accepting and processing merchant payments | As prescribed by the CBK | Often combined with a wallet licence |
| Payment Initiation Service Provider (PISP) | Initiate payments on behalf of customers | As prescribed by the CBK | Potential new open-finance licence |
| Account Information Service Provider (AISP) | Read account payment data with consent | As prescribed by the CBK | Potential new open-finance licence |
| Payment System Operator | Operate clearing and settlement systems | As prescribed by the CBK | Depends on system scale |
| Card Issuer / Processor | Card issuance and processing | As prescribed by the CBK | Confirm exact tier from official text |
| Payment Service Provider (other) | Other payment services not otherwise categorised | As prescribed by the CBK | Residual category |
| Intermediary / Aggregator | Third-party aggregator services | As prescribed by the CBK | Relevant to platform and gateway businesses |
| Other specialist licences | As defined by the CBK | As prescribed by the CBK | Reserved for future or niche activities |
The current minimum capital and net-worth requirements for payment service providers and e-money issuers are set out in the National Payment System Regulations and related CBK guidelines. Because any reform may revise these figures, institutions should confirm the exact amounts against the published official text before making decisions, rather than relying on indicative numbers.
A key commercial question raised by a disaggregated licence model is how much capital a multi-licence provider must hold. Some proposals contemplate an aggregation rule, for example, total required capital equalling the capital of the highest category held plus a percentage of the capital requirement of each additional category. Any such rule would penalise breadth and reward focus, and would force many diversified players to reassess which activities genuinely justify a separate authorisation. The exact formula, if any, must be confirmed against the enacted text and any explanatory notes.
To illustrate the mechanics in general terms: if a provider holds a high-capital category and adds a low-capital open-finance category under an aggregation rule, its total minimum capital would exceed the higher figure by a proportion of the additional category’s requirement. These illustrations show how an aggregation rule compounds as activities multiply, and why a mobile money operator that also acquires merchants and reads account data could face a materially higher capital floor than today. Because the precise figures and formula are not settled, institutions should model scenarios rather than treat any single number as fixed.
Finance and compliance leaders should build a licence-by-licence capital model using the current prescribed requirements as a baseline and testing alternative aggregation assumptions. Stress-test against your most ambitious product roadmap, identify activities that could be housed in a separate legal entity to manage capital, and factor in any transitional grace period that reform may allow. Early modelling also strengthens any comment submission: a credible, numbers-backed case for a phased capital transition is far more persuasive to the regulator than a general objection.
Consent documentation must be specific, legible and auditable. Draft consent language that identifies the requesting licensed party, the exact data categories involved, the purpose, the duration and the method of revocation. Retain a reliable record of each consent event, each use of data within scope, and each revocation. These records are your primary defence if a customer or the ODPC later challenges a transfer, so build recordkeeping into the consent flow rather than bolting it on afterwards.
Because the CBK would be expected to set the data-sharing mechanism, institutions should anticipate standardised API requirements. Prudent preparation includes strong customer and counterparty authentication, data minimisation so that only the data necessary for the consented purpose is shared, encryption in transit and at rest, and comprehensive audit trails that log every request and response. Interoperability would demand that incumbents expose reliable, well-documented interfaces capable of handling consented requests at scale. Firms that begin building toward likely open-finance standards now will face a shorter and less costly compliance runway once any final technical rules are issued.
Knowing how to respond to public participation on payments reform is a practical skill, and comment windows are often short, so coordination is essential. Use the following checklist to assemble a submission:
Effective submissions are specific and constructive. Recommend a defined capital transition period, phased implementation of any open-finance obligations, clear allocation of liability for unauthorised transfers, and an explicit commitment that the CBK will issue detailed technical standards before the data-sharing duties take effect. Two short illustrative paragraphs:
From a bank: “We support the policy objective of consent-driven data portability but request a transitional period of not less than eighteen months from publication of the final technical standards, to allow safe build-out of compliant APIs and consent-management systems. We further request that liability for losses arising from an unauthorised request rest with the licensed requesting party where our systems have correctly authenticated a valid consent.”
From a fintech: “We welcome dedicated PISP and AISP categories and proportionate capital thresholds. We ask that any aggregation rule for multiple licences be clarified in the final text, and that the Central Bank confirm standardised, openly documented API specifications to ensure a level playing field between new entrants and incumbents.”
Payments legislation in Kenya already carries supervisory and penalty provisions enforced by the CBK under the National Payment System Act, including powers to refuse, suspend or revoke authorisations and to impose sanctions for non-compliance. Reform would likely extend these to any new data-sharing and capital obligations. Institutions should confirm the specific enforcement clauses and any transitional grace periods against the published text. A phased commencement is common, with open-finance obligations likely to follow, rather than coincide with, the issuance of detailed technical standards, though the final sequencing will depend on the enacted provisions.
The likely practical effect of mandatory data portability is intensified competition. Lower-capital open-finance categories would reduce the barrier for fintechs and foreign PSPs eyeing the Kenyan market, while incumbents would lose the exclusive advantage of proprietary data. For a dominant mobile money operator, strategic options include embracing open finance as a platform play, monetising high-quality APIs and partnerships, rather than resisting data sharing. Providers who treat any new regime as an opportunity to build superior services on shared data, rather than merely a compliance cost, are likely to be best positioned.
Kenya’s direction of travel sits within a wider regional trend toward open banking and open finance. Several of Kenya’s neighbours are at earlier stages of exploring data portability and interoperable payments, and regulatory approaches vary in scope, consent architecture and capital treatment. For cross-border PSPs, the practical significance is that regional alignment, or divergence, will shape how easily a licence and compliance build in one market can be reused in another. Firms operating across East Africa should track these parallel reforms closely, because convergence on common technical standards would lower the cost of multi-market expansion, while fragmentation would require jurisdiction-by-jurisdiction compliance. Comparative statements should be treated as directional; each neighbouring framework must be assessed against its own enacted law.
Payment system reform in Kenya would alter the competitive balance of the payments market by moving toward treating customer data as a shared, consent-governed resource and by replacing broad authorisations with a more granular, activity-specific architecture. For banks, PSPs, fintechs and foreign entrants, the combination of potential open-finance obligations, capital aggregation considerations and new consent duties interacting with the Data Protection Act makes early, coordinated preparation worthwhile. Institutions that map their licences, model their capital and submit substantive comments on any published draft will be better placed to shape a workable final framework and to compete in an open-finance market.
Verify every date, figure and clause against the official text published by the Central Bank of Kenya, the National Treasury or Parliament before committing to any course of action.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Wangai Muhiu Maina at Mahida & Maina Company Advocates, a member of the Global Law Experts network.
posted 17 minutes ago
posted 38 minutes ago
posted 41 minutes ago
posted 58 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message