Biometric
KYC & AMLUpdated September 24, 20265 min

KYC in Kenya: Updated Procedures and Required Evidence

An operational Kenya KYC workflow under POCAMLA rules and the CBK 2025 CDD guidance: identity, beneficial ownership, risk, monitoring and evidence.

A KYC file can contain a national ID, a selfie and a sanctions result and still fail to show why an account was opened. Documents are inputs. To defend the customer decision, you also need source verification, beneficial-owner analysis where relevant, a risk rationale, resolved discrepancies and a record of who applied which rule.

Kenya's Proceeds of Crime and Anti-Money Laundering Regulations, 2023 require reporting institutions to identify customers and verify identity using reliable, independent source documents, data or information. The Central Bank of Kenya's Guidance on Customer Due Diligence, effective 1 September 2025 for the institutions within its scope, connects that requirement to a risk-based process, ongoing monitoring and enhanced measures for higher risk.

In brief

  • Separate identification—collecting the claim—from verification against reliable, independent evidence.

  • A document type is not a verification method; record the issuing source, validation performed and result.

  • For legal persons, trace ownership and control to natural persons and resolve inconsistent evidence.

  • Preserve a decision package: evidence, risk factors, policy version, exceptions, approver and review trigger.

KYC is a sequence of claims and tests

Kenya KYC evidence chain
Editorial evidence model based on the POCAMLA Regulations and CBK's CDD guidance.new.kenyalaw.org

Stage

Claim to establish

Evidence expected

Failure to avoid

Customer identity

Who is applying?

Official identity evidence plus independent verification

Storing an image without validating it

Authority

Is the person acting for themselves or another party?

Mandate, signatory authority and represented-person data

Verifying the agent but not the principal

Beneficial ownership

Which natural persons ultimately own or control the entity?

Registry, ownership chain, control evidence and corroboration

Stopping at the first corporate shareholder

Purpose

Why is the relationship being opened?

Product, expected activity, source and destination context

Generic “personal use” accepted for every case

Risk

What level and controls apply?

Customer, geography, product, channel and screening factors

Letting the vendor score become the institution's rating

Monitoring

Does later activity remain consistent?

Transactions, profile changes and review events

Treating onboarding as permanent clearance

What “required KYC documents” should mean

Section 45 of POCAMLA and the CBK guidance identify primary official identity evidence for individuals, including a birth certificate, national identity card, passport or driving licence. The POCAMLA Regulations add corroborating measures such as a KRA personal identification number, physical-address verification and utility evidence where applicable. For legal persons, the framework requires incorporation evidence, authority to act and information on the people managing, controlling or owning the entity. Treat them as evidence categories within a broader CDD decision. One cannot simply stand in for another.

No one-page checklist fits every customer. The right package depends on customer type, product, risk and whether a person acts for somebody else. Build your procedure around evidence classes and verification rules instead of hard-coding one document for everyone.

For each item, store:

  • the field or proposition it supports;

  • issuer and source;

  • verification method and timestamp;

  • result and discrepancy;

  • expiry or refresh trigger;

  • reviewer or automated policy version.

A seven-step Kenya CDD workflow

1. Classify the relationship

Determine customer type, product, channel, jurisdiction, whether the relationship is ongoing and whether another person is represented. The answers decide which evidence and risk rules apply.

2. Collect the identity claim

Capture names, date of birth or incorporation, identifiers, address and authority information needed for the case. Keep customer-submitted values distinct from values returned by an independent source.

3. Verify using reliable, independent evidence

Check that the document is authentic and the source valid; a readable image proves neither. In remote onboarding, document inspection, face comparison and liveness can support the process, but the institution remains responsible for deciding that the evidence is reliable for its regulatory context.

4. Establish representatives and beneficial owners

For legal persons, map the ownership chain and control rights until the relevant natural persons are identified. Record why a person qualifies and how conflicts between declarations, registry data and corporate documents were resolved.

5. Understand purpose and expected activity

Expected transaction size, frequency, counterparties and geographies create a baseline for monitoring. If nobody looks at the stated purpose again, collecting it only adds paperwork.

6. Screen and risk-rate

PEP, sanctions and adverse-information screening returns candidates. A person still has to reach the legal conclusion. Resolve identity, list context and applicable restriction. Record risk factors and the rationale for standard, simplified where permitted, or enhanced measures.

7. Decide, monitor and refresh

Link approval, conditions or rejection to the evidence and policy version. Define event-driven review triggers: material profile changes, document expiry, ownership change, unusual activity or new list exposure.

Treat exceptions as designed states

Event

Wrong interpretation

Better state

Registry or source unavailable

Customer is fraudulent

Verification pending / source unavailable

Face comparison below threshold

Identity theft proved

Biometric mismatch requiring controlled resolution

Name-screening candidate

Sanctioned person confirmed

Potential match awaiting adjudication

Ownership data conflict

Ignore and approve

Unresolved discrepancy; escalate before decision

Existing customer profile becomes stale

Repeat the whole journey blindly

Trigger a scoped refresh based on changed risk

The minimum reproducible decision package

A reviewer should be able to answer: what was claimed, what independent source was used, what did not match, who ultimately owned or controlled the customer, which screening candidates were resolved, why the risk rating was assigned, and who authorised the relationship.

Biometric.Vision's identity modules can connect document, liveness and face checks, while AML Screening can return sanctions and PEP candidates and monitoring results. The tools generate evidence. Your institution decides whether a source is legally sufficient, who qualifies as a beneficial owner and whether residual risk is acceptable under its own policy.

A strong KYC file is the smallest set of evidence that lets a reviewer reproduce the decision and see that higher-risk customers got stronger scrutiny.

Starter pack · free

Ready to strengthen your customer checks?

500 checks free every month · no card · no contract · no sales call.

Or message us onTelegramWhatsApp— we reply within 5 minutes

Read also