KYC in Kenya: Updated Procedures and Required Evidence
An operational Kenya KYC workflow under POCAMLA rules and the CBK 2025 CDD guidance: identity, beneficial ownership, risk, monitoring and evidence.
A KYC file can contain a national ID, a selfie and a sanctions result and still fail to show why an account was opened. Documents are inputs. To defend the customer decision, you also need source verification, beneficial-owner analysis where relevant, a risk rationale, resolved discrepancies and a record of who applied which rule.
Kenya's Proceeds of Crime and Anti-Money Laundering Regulations, 2023 require reporting institutions to identify customers and verify identity using reliable, independent source documents, data or information. The Central Bank of Kenya's Guidance on Customer Due Diligence, effective 1 September 2025 for the institutions within its scope, connects that requirement to a risk-based process, ongoing monitoring and enhanced measures for higher risk.
In brief
Separate identification—collecting the claim—from verification against reliable, independent evidence.
A document type is not a verification method; record the issuing source, validation performed and result.
For legal persons, trace ownership and control to natural persons and resolve inconsistent evidence.
Preserve a decision package: evidence, risk factors, policy version, exceptions, approver and review trigger.
KYC is a sequence of claims and tests

Stage | Claim to establish | Evidence expected | Failure to avoid |
|---|---|---|---|
Customer identity | Who is applying? | Official identity evidence plus independent verification | Storing an image without validating it |
Authority | Is the person acting for themselves or another party? | Mandate, signatory authority and represented-person data | Verifying the agent but not the principal |
Beneficial ownership | Which natural persons ultimately own or control the entity? | Registry, ownership chain, control evidence and corroboration | Stopping at the first corporate shareholder |
Purpose | Why is the relationship being opened? | Product, expected activity, source and destination context | Generic “personal use” accepted for every case |
Risk | What level and controls apply? | Customer, geography, product, channel and screening factors | Letting the vendor score become the institution's rating |
Monitoring | Does later activity remain consistent? | Transactions, profile changes and review events | Treating onboarding as permanent clearance |
What “required KYC documents” should mean
Section 45 of POCAMLA and the CBK guidance identify primary official identity evidence for individuals, including a birth certificate, national identity card, passport or driving licence. The POCAMLA Regulations add corroborating measures such as a KRA personal identification number, physical-address verification and utility evidence where applicable. For legal persons, the framework requires incorporation evidence, authority to act and information on the people managing, controlling or owning the entity. Treat them as evidence categories within a broader CDD decision. One cannot simply stand in for another.
No one-page checklist fits every customer. The right package depends on customer type, product, risk and whether a person acts for somebody else. Build your procedure around evidence classes and verification rules instead of hard-coding one document for everyone.
For each item, store:
the field or proposition it supports;
issuer and source;
verification method and timestamp;
result and discrepancy;
expiry or refresh trigger;
reviewer or automated policy version.
A seven-step Kenya CDD workflow
1. Classify the relationship
Determine customer type, product, channel, jurisdiction, whether the relationship is ongoing and whether another person is represented. The answers decide which evidence and risk rules apply.
2. Collect the identity claim
Capture names, date of birth or incorporation, identifiers, address and authority information needed for the case. Keep customer-submitted values distinct from values returned by an independent source.
3. Verify using reliable, independent evidence
Check that the document is authentic and the source valid; a readable image proves neither. In remote onboarding, document inspection, face comparison and liveness can support the process, but the institution remains responsible for deciding that the evidence is reliable for its regulatory context.
4. Establish representatives and beneficial owners
For legal persons, map the ownership chain and control rights until the relevant natural persons are identified. Record why a person qualifies and how conflicts between declarations, registry data and corporate documents were resolved.
5. Understand purpose and expected activity
Expected transaction size, frequency, counterparties and geographies create a baseline for monitoring. If nobody looks at the stated purpose again, collecting it only adds paperwork.
6. Screen and risk-rate
PEP, sanctions and adverse-information screening returns candidates. A person still has to reach the legal conclusion. Resolve identity, list context and applicable restriction. Record risk factors and the rationale for standard, simplified where permitted, or enhanced measures.
7. Decide, monitor and refresh
Link approval, conditions or rejection to the evidence and policy version. Define event-driven review triggers: material profile changes, document expiry, ownership change, unusual activity or new list exposure.
Treat exceptions as designed states
Event | Wrong interpretation | Better state |
|---|---|---|
Registry or source unavailable | Customer is fraudulent | Verification pending / source unavailable |
Face comparison below threshold | Identity theft proved | Biometric mismatch requiring controlled resolution |
Name-screening candidate | Sanctioned person confirmed | Potential match awaiting adjudication |
Ownership data conflict | Ignore and approve | Unresolved discrepancy; escalate before decision |
Existing customer profile becomes stale | Repeat the whole journey blindly | Trigger a scoped refresh based on changed risk |
The minimum reproducible decision package
A reviewer should be able to answer: what was claimed, what independent source was used, what did not match, who ultimately owned or controlled the customer, which screening candidates were resolved, why the risk rating was assigned, and who authorised the relationship.
Biometric.Vision's identity modules can connect document, liveness and face checks, while AML Screening can return sanctions and PEP candidates and monitoring results. The tools generate evidence. Your institution decides whether a source is legally sufficient, who qualifies as a beneficial owner and whether residual risk is acceptable under its own policy.
A strong KYC file is the smallest set of evidence that lets a reviewer reproduce the decision and see that higher-risk customers got stronger scrutiny.
Ready to strengthen your customer checks?
500 checks free every month · no card · no contract · no sales call.



