Four different bodies regulate somebody in Kenyan credit, and which one regulates you turns almost entirely on what you take in — deposits, savings, member shares — rather than on what you lend out. This is a map, not legal advice: it is written to help you work out which questions to take to a lawyer, and which returns you are probably already late on.
The question that decides everything
Ask it in this order:
- Do you take deposits from the public? If yes, you are in banking or deposit-taking microfinance, and the Central Bank of Kenya licenses you.
- Are you a co-operative society whose members save with you? If yes, you are a SACCO, and the question becomes whether SASRA regulates you as well as the Commissioner for Co-operative Development.
- Do you lend your own money, and reach customers through an app, USSD or an online channel? If yes, the CBK's Digital Credit Provider regime is very likely yours.
- Do you lend your own money, offline, to people you meet? Then you are a credit-only lender, which is the least directly supervised category — and the one people most often assume means "unregulated". It does not.
The Central Bank of Kenya
The CBK licenses and supervises microfinance banks — the deposit-taking kind — under the Microfinance Act, 2006. This is a full prudential regime: minimum capital, liquidity ratios, fit-and-proper testing of directors, periodic returns, on-site inspection. If you are a microfinance bank you already know it, because getting the licence dominated a year of somebody's life.
Since the Central Bank of Kenya (Digital Credit Providers) Regulations came into force in 2022, the CBK also licenses digital credit providers. This was the change that surprised the most people, because a large number of businesses that thought of themselves as tech companies discovered they were regulated lenders. The regime covers licensing, fit-and-proper requirements for significant shareholders and management, pricing disclosure, and — the part that changed behaviour most — rules on debt collection conduct and on how customer data may be used.
If you originate loans through an app, a USSD shortcode or a web form and you are not a bank, a microfinance bank or a SACCO, assume the DCP regime applies to you until somebody qualified tells you otherwise.
SASRA and the SACCO question
Two distinct things regulate SACCOs, and conflating them is the most common mistake in this whole area.
Every SACCO is a co-operative society registered under the Co-operative Societies Act and supervised by the Commissioner for Co-operative Development. That is what makes it a SACCO at all.
Some SACCOs are additionally licensed and supervised by the SACCO Societies Regulatory Authority (SASRA) under the SACCO Societies Act, 2008. Historically that meant deposit-taking SACCOs — the ones running a front-office service activity (FOSA), where members can withdraw. The perimeter was then extended by regulations to bring in specified non-withdrawable deposit-taking SACCOs above a size threshold, so a back-office-only SACCO that has grown past it is now in scope where it once was not.
The practical consequence for a system: SASRA-regulated SACCOs file periodic returns in a prescribed format, and those returns are built from the loan book and the general ledger together. If those two do not agree, the return is guesswork. This is one of the places where having a real double-entry ledger under the loan module stops being an accounting preference and starts being a filing requirement.
Credit-only lenders: the "unregulated" category that is not
A credit-only microfinance institution — lending its own capital, taking no deposits, not operating digitally — is not licensed by the CBK and not supervised by SASRA. People routinely read that as "no rules apply". Several do:
- Data protection. The Data Protection Act, 2019 applies to anyone processing personal data, and a lender holding ID numbers, payslips and next-of-kin details is squarely inside it. See the Act, for lenders.
- Credit reference reporting. If you submit borrower data to a credit reference bureau, the Credit Reference Bureau Regulations govern what you may submit, the accuracy you owe, and the customer's right to dispute it.
- Anti-money-laundering. The Proceeds of Crime and Anti-Money Laundering Act reaches reporting institutions broadly, and "we are small" has never been a defence in it.
- Consumer protection and general law. Contract terms, collection conduct, and the Consumer Protection Act do not switch off because nobody issued you a licence.
The Office of the Data Protection Commissioner
The ODPC is the fourth regulator, and the one most lenders have not registered with. It supervises data controllers and data processors under the Data Protection Act, 2019, and registration is mandatory for organisations above thresholds set by regulation — thresholds a lender with a handful of staff can easily cross.
Unlike the others, this one applies regardless of which of the boxes above you are in. A digital credit provider, a SASRA-regulated SACCO and a two-branch credit-only lender all hold the same kind of personal data and owe the same duties over it.
Credit reference bureaus
Kenya has three licensed credit reference bureaus. Submitting to them is valuable — it is most of what makes a credit decision better than a guess — and it comes with obligations: the data must be accurate, the customer has the right to see and dispute it, and adverse listings have prescribed rules around notification.
From a systems point of view the requirement is boring and load-bearing: you need to be able to produce, for any borrower and any month, exactly what their balance and arrears state was — and to be able to explain why. A loan book that is recalculated rather than recorded cannot do that.
What all of this means for the system you run
Regardless of which regulator you have, the same four capabilities keep coming up:
- An audit trail that is append-only. Financial records get reversed, not deleted. Somebody will one day ask who changed a loan's interest rate and when.
- A ledger that agrees with the loan book. Every prudential return and every SASRA filing is built from both.
- Role separation with teeth. Maker-checker on disbursement, approval and write-off. "The manager knows not to" is not a control.
- Data you can produce on demand and delete on schedule. Both directions matter: the Act obliges you to be able to give a customer their data, and not to keep it forever.
Those are also, not coincidentally, the four things worth checking hardest when you are choosing software. We have written that up as a buyer's guide.