Made under the Virtual Asset Service Providers Act, No. 20 of 2025. In exercise of the powers conferred by section 49 of the Virtual Asset Service Providers Act, 2025, the Cabinet Secretary to the National Treasury, on the advice of the relevant regulatory authorities, makes the following Regulations.
| REGULATION NO. | CONTENT OF THE REGULATION | OUR COMMENTS |
|---|---|---|
| PART I – PRELIMINARY | ||
| Regulation 2 | In these Regulations, unless the context otherwise requires— | |
| Interpretation | ||
| “Act” means the Virtual Asset Service Providers Act, 2025; | ||
| “advertisement” means to make a representation for the purposes of directly or indirectly promoting virtual assets and services through any medium and in any form, including— (a) magazines and newspapers; | This definition fills a genuine gap, since the Act itself does not define "advertisement" but requires under section 24(j) that advertising material be fair and not misleading, and empowers the Cabinet Secretary under section 49(2)(h) to prescribe the contents of advertisements. | |
| (b) radio and television; | ||
| (c) outdoor advertising, including billboards, window displays and signs at public venues; | ||
| (d) the internet, including web pages, banner advertisements, online messaging services and social media and networking platforms; | ||
| (e) product brochures and promotional fact sheets; | ||
| (f) direct mail, including post, facsimile or email; | ||
| (g) white papers or prospectus; | ||
| (h) telemarketing activities; and | ||
| (i) seminars and presentations to individuals or such other groups of individuals, whether held in person or online, conducted in live format or recorded and made available for public access thereafter, which are distributed through any medium; | ||
| “AML/CFT/CPF” has the meaning assigned to it under section 2 of the Act; | This definition correctly cross-references section 2 of the Act rather than restating it, avoiding any risk of future inconsistency. | |
| “consumer assets” means any virtual assets owned by a consumer, including stablecoins; | This definition fills a gap left by the Act. | |
| “cyber security” means an approach or series of steps to prevent or manage the risk of damage to, unauthorized use of, exploitation of and, as needed, to restore electronic information and communications systems, and the information they contain, in order to strengthen the confidentiality, integrity, and availability of these systems; | This definition elaborates on the cyber security measures contemplated under section 28 of the Act. | |
| “cyber security event” means any act or attempt, successful or unsuccessful, to gain unauthorized access to disrupt, or misuse the electronic systems or information stored on such systems; | This definition describes acts or attempts to gain unauthorized access to or disrupt electronic systems, supporting the cyber security obligations under section 28 of the Act. | |
| “cyber security risk” means the risk of financial loss, operational disruption or damage from the failure of the digital technologies employed for informational or operational functions introduced to an information system via electronic means from the unauthorized access, use, disclosure, disruption, modification, or destruction of the information system; | This definition describes the risk of loss or disruption arising from failures in digital technologies, supporting the cyber security framework under section 28 of the Act. | |
| “consumer” means a person who uses, has used, or is or may be contemplating using directly or indirectly any of the products or services provided by a virtual asset service provider or is intended to receive an advertisement; | This definition describes the class of persons protected under the consumer protection obligations imposed on licensees by the Act, including sections 21 and 24. | |
| “core capital” means issued and fully paid-up ordinary share capital and disclosed reserves; | This definition gives effect to the capital requirements contemplated under section 22 and section 49(2)(i)(vi) of the Act. | |
| “fiat-referenced stablecoin” means a type of stablecoin that maintains a stable value by being pegged to the value of a fiat currency; | This definition provides a sub-category of the Act's "stablecoin" definition under section 2, specific to fiat-currency-pegged instruments. | |
| “forks” means changes to the software on which a distributed ledger technology protocol operates; | This definition describes changes to distributed ledger technology protocols, a concept defined under section 2 of the Act. | |
| “liquid capital” in relation to a licensee, means the amount which the liquid assets of a licensee exceed its liabilities; “paid-up capital” means issued and fully paid-up ordinary shares paid by shareholders of the company; | This definition gives effect to the capital and solvency requirements contemplated under section 22 and section 49(2)(i)(vi) of the Act. | |
| “reserve asset” means an asset that is held by a licensee to back the value of its virtual assets issued and held strictly for discharging liabilities arising from the issuance of virtual assets; | This definition elaborates on the concept of reserve assets referenced in the Act's section 2 definition of "stablecoin." | |
| “shareholders funds” means the net worth of a company, calculated as total assets minus total liabilities | This definition provides a prudential measure consistent with the capital and solvency framework under section 22 of the Act. | |
| “tokenization” or “tokenize” means the process of converting real-world assets into digital tokens on a blockchain; and | This definition reflects the description of Virtual Asset Tokenization set out in the First Schedule to the Act | |
| “white paper” means a disclosure document published by or on behalf of a virtual asset offering provider prior to the offer, issue, or admission to trading of a virtual asset, containing such information as specified in these Regulations. | This definition gives effect to the disclosure requirements associated with a virtual asset offering under section 34 of the Act. | |
| Regulation 3 | (1) These Regulations shall apply to persons offering virtual asset services in or from Kenya. | Sub regulation (2) is a significant policy assertion in that any person deriving economic benefit from Kenya even without physical presence falls under these Regulations. This aligns with FATF Recommendation 15 and the EU MiCA Regulation's approach to platform jurisdiction. |
| Application of the Regulations | ||
| (2) A person is deemed to be operating "in or from Kenya" where that person derives an economic benefit or income from Kenya regardless of whether the person has physical presence in Kenya. | This provision is a critical tool for preventing offshore regulatory trade which is a common tactic among some crypto platforms. Without this a foreign incorporated exchange could generate substantial Kenyan retail revenues entirely beyond regulatory oversight. | |
| (3) These Regulations shall be read in conjunction with the Act, the Proceeds of Crime and Anti-Money Laundering Act, the Prevention of Terrorism Act, the Computer Misuse and Cyber Crimes Act and any other relevant written law. | ||
| Regulation 4 | (1) The fees payable under these Regulations shall be as set out in the First Schedule. | This regulation conforms with the constitutional dictates of article 210 which provides for the imposition on taxes and or licensing fees through legislation which includes regulations. |
| Fees Payable | ||
| (2) The withdrawal of any application shall result in the forfeiture of the application fee. | ||
| PART II – LICENSING AND AUTHORISATION REQUIREMENTS | ||
| Regulation 5 | (1) An application for a licence to offer one or more of the permissible activities pursuant to section 10(1) of the Act shall be made in the form set out in the Second Schedule. | The application requirements are comprehensive and reflect international best practice for VASP licensing. The requirement for AML/CFT/CPF policies, fit and proper assessments, and source-of-funds disclosure are essential preventative measures that prevent the licensing of entities who pose financial crime risks. |
| Application for and Issuance of Licence | (2) An application for a licence under sub regulation (1) shall be accompanied by— | |
| (a) the personal details, qualifications, experience, business interests and occupation of the applicant’s— | The requirement for three years of audited financial statements can potentially discriminate against newly incorporated entities. We propose that the Regulations provide a clear tiered evidence standard based on the applicant's operational history. | |
| (i) directors; | ||
| (ii) senior officers; | ||
| (iii) significant shareholders; | ||
| (iv) beneficial owner; | ||
| (b) a business plan prepared in accordance with the Third Schedule to these Regulations; | ||
| (c) a dully filled fit and proper assessment form as provided for in the Fourth Schedule to these Regulations; | ||
| (d) proof of source of funds; | ||
| (e) a description of the systems and controls of the proposed virtual asset business; | ||
| (f) the operational policies that shall guide the applicant’s activities, including— | ||
| (i) the risk management policies; | ||
| (ii) the AML/CFT/CPF policies; | ||
| (iii) the cybersecurity and information technology policy; | ||
| (iv) the complaints managements policy; | ||
| (g) copies of contracts and any arrangements for oversight of activities as the relevant regulatory authority may require, where applicable; | ||
| (h) evidence of the paid-up capital and liquid capital at the amount specified in the Fifth Schedule; the audited financial statements for three years prior to the submission of the application or the opening financial statements verified by an auditor, as applicable; | ||
| (i) the audited financial statements for three years prior to the submission of the application or the opening financial statements verified by an auditor, as applicable; | ||
| (j) evidence of human and technology resources sufficient to efficiently operate and manage the virtual asset business as required in regulation; | ||
| (k) in the case of virtual asset exchange, token issuance platforms, virtual asset offerings and virtual asset wallet providers, the business rules of the applicant prepared in accordance with regulation 19; | ||
| (l) evidence of adequate systems and controls to maintain market integrity prepared in accordance with these Regulations, including avoidance of market abuse; | ||
| (m) the class of virtual assets intended to be traded or available for subscription; | ||
| (n) the details of the applicant’s principal business address and website; | ||
| (o) a certified copy of the certificate of incorporation of the applicant; | ||
| (p) up to date the details of the directors and shareholders of the applicant issued by the Registrar of Companies (CR12); | ||
| (q) a copy of the register of beneficial owners prepared and issued by the Registrar of Companies; | ||
| (r) Issuance of licence. proof of payment of the application fee specified in the First Schedule; and | ||
| (s) any additional requirements that may be required under the Act. | ||
| (3) An applicant shall, upon the request of the relevant regulatory authority, participate in an interview, to obtain further information concerning its application or supporting information and records. | ||
| Regulation 6 | (1) Where the relevant regulatory authority is satisfied that the applicant meets the requirements of section 11 of the Act, the relevant regulatory authority may issue the applicant with a virtual asset service providers licence upon payment of licence fee prescribed under the First Schedule. | We note that the regulations do not prescribe any statutory timeline within which the relevant regulatory authority must determine an application. We propose that a statutory timeline. |
| Issuance of licence. | (2) A licence issued under this regulation may contain such conditions as the relevant regulatory authority may determine. | |
| Regulation 7 Commencement of virtual asset business | Upon grant of a licence under the Act, a licensee shall commence its virtual asset business immediately on the date of grant of the licence, but where that commencement is not practicable, the licensee shall seek an extension from the relevant regulatory authority which extension shall not be more than twelve months from the date the licence was granted. | This is a good proposal that will prevents licence hoarding and ensure that licences are used productively. However, It is objectively unreasonable to expect service providers to commence business activities “immediately”, essentially on day 1 of obtaining the license. Some ample time should be given before an entity is expected to commence activities. |
| Regulation 8 | (1) An applicant for a licence under regulation 5 shall give written notice to the relevant regulatory authority of— | This proposal is essential in that it ensures that the regulator has real time information about changes affecting the licensee. This prevents misinformation between the regulator and the regulated entity. |
| Alteration of facts disclosed in application. | (a) any proposed alteration to the information in the original application; | |
| (b) the occurrence of any material event that affects or may affect information provided to the relevant regulatory authority, in the application. | ||
| (2) For purposes of sub regulation (1) (b), “material event” includes— | ||
| (a) failure or material degradation of a proposed critical third-party service provider; | ||
| (b) any litigation or dispute resolution activity undertaken or affecting the applicant; | ||
| (c) insolvency, a material liquidity shortfall or credible threat to solvency; | ||
| (d) an enforcement action, criminal investigation or sanction that affects the applicant; | ||
| (e) a cybersecurity incident; | ||
| (f) any intended change in ownership and actual change or control that is material to the applicant; | ||
| (g) such other action or incident that directly or indirectly affects the general business operations of the applicant. | ||
| Regulation 9 | The relevant regulatory authority may reject an application for a licence where— | The rejection grounds in this regulation, particularly the public interest and public policy grounds, are broad and may risk inconsistency. We propose that the relevant regulatory authority be required to publish written reasons for any rejection, as required by section 47(2) of the Fair Administrative Action Act, 2015, and that an express right of appeal to an administrative review body be provided within the Regulations. It would also be prudent to add a timeline for when applicants can expect a response in relation to their applications. |
| Grounds for rejection of an application. | (a) the applicant fails to respond to requests for clarification or further information from the relevant regulatory authority concerning its application or of the supporting any information or records; | |
| (b) the applicant fails to comply with a request to participate in an interview made under regulation 5(3); | ||
| (c) the applicant, in the opinion of the relevant regulatory authority, does not have the requisite capability to comply with the AML/CFT/CPF requirements; | ||
| (d) the applicant’s directors, or such other senior officers fail to meet the fit and proper criteria set out in section 18 of the Act; | ||
| (e) the granting of the licence is against public interest or public policy; | ||
| (f) False and misleading statements. the applicant has a record of history of regulatory breaches or non-compliance with prudential, AML/CFT/CPF or any other regulatory requirements, either in Kenya or any other jurisdiction in which the applicant is or has been licensed as a virtual asset service provider; or | ||
| (g) in the opinion of the relevant regulatory authority, the approval of the application may pose a risk to the integrity, security and stability of the financial system. | ||
| Regulation 10 | (1) A person shall not, in connection with an application submitted to the relevant regulatory authority for grant of a licence under these Regulations— | This regulation ensures only serious, well capitalised, and compliant entities enter the market. Comprehensive upfront disclosure reduces post licensing compliance risks. AML/CFT policy requirements align with FATF standards and prevent illicit use of VASPs. The criminal penalties are appropriate. The Kshs. twenty million (20,000,000) cap for companies is adequate relative to the potential gains from improperly obtained licences for larger corporate VASPs. |
| False and misleading statements. | (a) make a statement to the relevant regulatory authority which he or she knows or ought reasonably to know is false or misleading; or | |
| (b) omit to state any matter to the relevant regulatory authority where he or she knows or ought reasonably to know that, because of the omission, the application is misleading. | ||
| (2) Any person who contravenes sub regulation (1) commits an offence and is liable, upon conviction— | ||
| (a) in the case of an individual, to a fine not exceeding seven million shillings (7,000,000) or to imprisonment for a term not exceeding three (3) years, or to both; | ||
| (b) in the case of a company, to a fine not exceeding twenty million shillings (20,000,000). | ||
| Regulation 11 | (1) A licensee who wishes to assign or transfer a licence issued under these Regulations shall, on payment of the fee set out in the First Schedule, make an application to the relevant regulatory authority for the assignment or transfer of the licence. | The thirty-six (36) month minimum holding period for licence transfer is designed to prevent speculative licensing. |
| Assignment, Transfer, Authorisation for Currency Conversion, Renewal, Revocation | (2) An assignment or transfer made by a licensee in contravention of subsection (1) shall be null and void and constitute sufficient grounds for the relevant regulatory authority to revoke the license. | |
| (3) An application made under sub-regulation (1) shall only be considered if the licensee | ||
| (a) commenced operations in accordance with the conditions of the licence; | ||
| (b) held the licence for a minimum period of thirty-six (36) months from the date of commencement of business; and | ||
| (c) has fully complied with provisions of these Regulations. | ||
| (4) In determining an application for transfer or assignment of a license under this regulation, the relevant regulatory authority shall consider the following— | ||
| (a) that the transferee meets all requirements for licensing under the Act, these Regulations and other relevant Act; | ||
| (b) the applicant has paid all outstanding fees and penalties, if any, relating to the license; | ||
| (c) the applicant has no outstanding noncompliance matters; | ||
| (d) that the transfer is necessary in the interest of the business, its consumers or financial stability. | ||
| Regulations 12 | (1) A person seeking to transact the business of conversion of virtual assets to or from foreign currency shall, before commencing such conversion business, apply to the relevant regulatory authority for authorisation. | This specific regulation provides specific regulatory oversight over the fiat conversion function, which is the highest AML/CFT risk activity in the VASP lifecycle. Further, this aligns with the Central Bank of Kenya's mandate over foreign exchange regulation. |
| Authorisation for conversion of virtual assets. | (2) An application under sub regulation (1) shall be made in the form and manner specified by the relevant regulatory authority. | |
| (3) In considering an application under sub regulation (1), the relevant regulatory authority shall take into consideration the financial condition and history of the applicant | ||
| 4) The relevant regulatory authority may grant an authorization subject to such conditions as it may consider necessary. | ||
| (5) An authorisation issued under this regulation shall, unless earlier revoked, be valid from the date it is issued and shall expire on 31st December of the year it is issued. | ||
| Regulations 13 | (1) An authorisation granted under regulation 12 may, on expiry, be renewed on an annual basis. | This is a good proposal that ensures continuous regulatory oversight over the fiat conversion function. This is also beneficial in that the annual renewal could act as a regular checkpoint for AML/CFT compliance review. |
| Renewal of authorisation. | (2) An application for the renewal of an authorization shall be lodged with the relevant regulatory authority at least two months prior to the expiry of the authorisation. Revocation of authorisation. | |
| Regulations 14 | (1) The relevant regulatory authority may, by notice in writing, revoke or suspend an authorisation granted under these Regulations for such period as it may specify, if the authorised person— | The minimum fourteen (14) day notice period and the right to make representations respects natural justice. Further to this the grounds for revocation are specific and objective, limiting arbitrary use. |
| Revocation of authorisation. | (a) ceases to carry on business in Kenya or goes into liquidation or is wound up or is otherwise dissolved. | |
| (b) fails to comply with the provisions of these Regulations or any condition attached to an authorisation; or | ||
| (c) conducts business in a manner detrimental to the best interests of the public. | ||
| (2) Before revoking or suspending an authorization under this regulation, the relevant regulatory authority shall give an authorized person, at least fourteen (14) days’ notice and shall consider any representations made to it in writing by the authorised person. | ||
| PART III – PROVISIONS ON ONGOING REQUIREMENTS | ||
| Regulations 15 | (1) A licensee shall ensure that notifications and reports required to be submitted under section 25 of the Act are submitted in the form and manner specified by the relevant regulatory authority. | The requirement of the CEO’s accountability for regulatory compliance strengthens personal liability and ensures senior management engagement in compliance. Further, this regulation aligns the form of notification to regulatory specifications, ensuring data consistency. |
| Ongoing notifications. | ||
| (2) The chief executive officer of the licensee shall provide a notification or report in accordance with section 25 of the Act. | ||
| Regulation 16 | (1) Every licensee shall ensure that its virtual asset services are conducted in a fair, transparent and efficient manner for the purpose of reducing any systemic or any other type of risk that may adversely affect fair and orderly provision of virtual asset services. | This regulation’s obligation to conduct virtual asset services in a fair, transparent and efficient manner' gives the regulator wide discretion in enforcement. This might be beneficial allowing the regulator to address novel situations not specifically contemplated by rules. The reporting requirement also creates a regular supervisory communication channel |
| Ongoing obligations. | (2) A licensee shall, in writing and at such times as the relevant regulatory authority may direct, submit to the relevant regulatory authority a report addressing matters affecting the virtual assets business. | |
| (3) The report referred to in sub regulation (2) may include— | ||
| (a) ongoing compliance by the licensee with the terms of the licence; | ||
| (b) complaints received and resolutions reached; (c) disciplinary matters arising and dealt with; | ||
| (d) the adequacy and performance of systems and controls; | ||
| (e) the financial matters concerning the operation of the virtual asset business; and | ||
| (f) Human and technology resources. any other information as may be required by the relevant regulatory authority. | ||
| Regulation 17 | (1) A licensee shall, to the satisfaction of the relevant regulatory authority, have sufficient human and technology resources to operate a virtual asset business. | This regulation ensures that there is operational competence is a condition of licensing and continued compliance. The technology security requirements protect consumers from data breaches and system failures, this approach is flexible and accommodative of different business models. |
| Human and technology resources. | (2) For purposes of sub regulation (1), a licensee shall satisfy the relevant regulatory authority with respect to— | |
| (a) employing fit and proper staff, appropriately trained for the duties to be performed and trained to the standards required; | ||
| (b) appointing a management team with adequate levels of experience and expertise to supervise and monitor the operations of the virtual asset business; | ||
| (c) technology resources that are established and maintained in such a way as to ensure that they are secure and maintain confidentiality of the data they contain; and the | ||
| (d) details of systems and associated technologies to be adopted by the applicant. | ||
| Regulation 18 Virtual asset business to establish proper markets. | A virtual asset service provider shall, to the satisfaction of the relevant regulatory authority, establish and operate proper markets that are conducive to the economic good of the country and that do not cause or promote instability. | This regulation articulates a macro prudential dimension to VASP regulation, ensuring the whole system’s stability is considered. |
| Regulation 19 | (1) A licensee shall, to the satisfaction of the relevant regulatory authority, have clear and fair business rules which are— | The comprehensive list of required business rules aligns with standards for regulated financial market infrastructures. Further the pre-approval of business rules by the regulator ensures that consumer protection standards are embedded at the operational level. This proposal is sound in that the default rules could prevent failures in the event of consumer default. |
| Business and default rules. | (a) legally enforceable by consumers; and | |
| (b) published and made freely available. | ||
| (2) A licensee shall have compliance procedures in place to ensure that— | ||
| (a) the business rules in sub regulation (1) are enforced; | ||
| (b) the complaints regarding its virtual asset services and appeal procedures are in place; | ||
| (c) where appropriate, a disciplinary action resulting in financial and other types of penalties is available; and | ||
| (d) the procedure for detecting, preventing and reporting any form of market abuse is available. | ||
| (3) The business rules under sub regulation (1) shall be approved by the relevant regulatory authority. | ||
| (4) The business rules in sub regulation (1) shall specify the class of virtual assets traded on or available for subscription, and requirements with respect to— | ||
| (a) a licensee’s financial reporting including how regular reports are made, the applicable international accounting standards or any other accounting standard accepted by the relevant regulatory authority to which they comply; | ||
| (b) the auditing standards; | ||
| (c) the licensee’s track record in terms of profit or operating history; and | ||
| (d) any restrictions that may exist on transferability for a virtual asset. | ||
| (5) A virtual asset service provider shall have default rules in place which in the event of a purchaser or consumer being or appearing to be unable to fulfil its obligations in respect of one or more contracts, enables action to be taken with respect to unsettled virtual asset transactions to which the consumer is a party. | ||
| (6) A virtual asset exchange or token issuance platform shall have in place and submit to the relevant regulatory authority, rules containing provisions relating to— | ||
| (a) methods of access to its platform; | ||
| (b) hours of operation, exchange availability and interruptions; | ||
| (c) admission, suspension or delisting of virtual assets from trading on the exchange or platform; | ||
| (d) the conditions governing dealings in virtual assets and investor protection measures; | ||
| (e) asset custody arrangements; | ||
| (f) prompt and real-time disclosure to all investors of material information; | ||
| (g) order submission procedures, order minimums and order types; | ||
| (h) market data, pre and post trade transparency; (i) prevention of market abuse and other prohibited conduct; investigation into trading in virtual asset transactions and for conducting inspections; | ||
| (j) investigation into trading in virtual asset transactions and for conducting inspections; | ||
| (k) suspension of trading for the protection of investors or for the conduct of orderly and fair trading; | ||
| (l) the conduct of virtual assets trading and the form in which information relating to transactions is to be maintained and reported to the virtual asset exchange; | ||
| (m) dispute resolution mechanisms; | ||
| (n) trading fees chargeable; | ||
| (o) requirements on funding of accounts; | ||
| (p) order matching and order matching priorities; (q) trade settlement and confirmation; and | ||
| (r) Business continuity plan. deposit and withdrawal procedures. | ||
| Regulation 20 | (1) A licensee shall have in place a formalized business continuity plan, as approved by its board of directors, and address its strategy for maintaining continuity of its operations, its plans for communicating and regularly testing the adequacy and effectiveness of this plan. | This regulation’s requirement for a formalised business continuity plan, approved by the board, with biennial testing and availability to the regulator is a great addition to allow for operational flexibility. The administrative penalty of Kshs. three million (3,000,000) for non-compliance is fair and proportionate as a disincentive for noncompliance. We propose that the regulator should consider mandating that the BCP should include a description of the client asset segregation measures considered by the entity. |
| Business continuity plan. | (2) The business continuity plan shall outline arrangements to reduce the impact of short, medium or long-term disruption, including— | |
| (a) resource requirements such as people, systems and other assets, and arrangements for obtaining these resources; | ||
| (b) the recovery priorities for the licensee' operations; and | ||
| (c) communication arrangements for internal and external concerned parties. | ||
| (3) A licensee shall review and test its business continuity plan at least every two years to ensure that it is up to date. | ||
| (4) A licensee shall make available its business continuity plan or its report depicting the results of its business continuity testing to the relevant regulatory authority, upon request, and within such time as may be indicated. | ||
| (5) Where a person acts in contravention of this regulation, the relevant regulatory authority shall take 21 such enforcement action as it deems necessary under the Act and may impose an administrative penalty of three million shillings. | ||
| Regulation 21 | 1) Pursuant to section 44 of the Act, a licensee shall— | The transaction metadata requirements in this regulation are well tailored and demonstrate an advanced understanding of blockchain forensics. The inclusion of cross chain bridge pathway identifiers is a globally pioneering provision that directly addresses the emerging money laundering risk posed by cross-chain bridging. |
| Transaction information. | (a) record the activity and transactions effected on or through its distributed ledger technology platform; | |
| (b) maintain the activity and transaction records for at least seven years; and | ||
| (c) provide the relevant regulatory authority or any competent authority with such records in a timely manner as the relevant regulatory authority or competent authority may require. | ||
| (2) The information referred to under sub regulation (1) shall include technical and contextual metadata on transactions such as wallet addresses, transaction hashes, network or chain identifiers, high-precision timestamps, order-book and application programming interface (API) interaction logs and identifiers of cross-chain or bridge pathways. | ||
| Regulation 22 Disclosure of information by employees | A licensee shall have appropriate procedures and protection measures for allowing employees to disclose any information to the relevant regulatory authority, competent authorities or comparable bodies involved in the prevention of market abuse, financial crime, money laundering, terrorism financing or proliferation financing. | This regulation creates an internal channel for reporting market abuse and financial crime. It is a critical warning mechanism for regulators. Further this regulation aligns with FATF Recommendation 40 on information sharing. |
| Regulation 23 | (1) A licensee shall make the following disclosures to its consumers prior to engaging in any transaction or providing any service— | The regulation mandates extensive pre-transaction disclosures covering 11 categories of information. Sub regulation (2) critically prohibits exclusion clauses that limit licensee liability in ways that would undermine consumer rights which is a strong consumer protection provision. Further, the prohibition on charging consumers for disclosure fulfilment is consumer friendly. The requirement to disclose conflicts of interest and security protocols is comprehensive and aligns with EU MiCA standards. |
| Disclosure of information to consumers. | (a) full details of the current licence status, including the specific categories of virtual asset services for which it is licenced by the relevant regulatory authority; | |
| (b) the full legal name, physical address of the principal office in Kenya and their contact information; | ||
| (c) a clear and up-to-date disclosure of any actual conflicts of interest from the licensee’s activities including a description of the mechanisms employed to identify, manage, or mitigate such conflicts; | ||
| (d) a publicly accessible policy outlining the procedure for handling consumer complaints, including the maximum response time and the escalation path to the relevant regulatory authority; | ||
| (e) an accurate description of the nature of virtual asset services offered, features, characteristics and limitations; | ||
| (f) a comprehensive statement of the risks associated with virtual asset and the services provided, including the market volatility, technology and cybersecurity risks; | ||
| (g) any applicable fees, commissions or other charges in the provision of their services and the timing of payment for the fees; | ||
| (h) the procedures for withdrawals, suspension and cancellation of transactions; | ||
| (i) the security transaction protocols execution, employed for consumer authentication, and data protection; | ||
| (j) the measures in place to ensure business continuity and recovery in the event of a system failure or cyber incident; and | ||
| (k) any material change in business operations, ownership, management, terms of service or rates and charges. | ||
| (2) In furtherance to sub regulation (1), a licensee shall not, in any written communication or agreement, exclude or restrict— | ||
| (a) any duty or liability to a consumer which it has under any law or under any regulations made by the relevant regulatory authority; | ||
| (b) any liability owed to a consumer for failure to exercise the degree of skill, care and diligence that may reasonably be expected of it in the provision of the service of a regulated activity; | ||
| (c) any other duty to act with skill, care and diligence that is owed to a consumer in connection with the provision to him of her of the service of a regulated activity. | ||
| (3) A licensee may not charge the consumer for fulfilment of its disclosure and information obligations under these Regulations. | ||
| Regulation 24 | (1) A licensee shall seek sufficient information about the consumer and the consumer’s circumstances to ensure that the services provided are consistent with those circumstances. | This regulation’s suitability assessment requirement aims to ensure that recommendations are appropriate for the consumer mirrors the MiFID II suitability standard and represents best practice in investor protection. |
| Consumer information. | (2) Notwithstanding the generality of sub regulation (1), a licensee shall — | |
| (a) when recommending investments to a consumer or where it has discretion to act on behalf of a consumer, take and document reasonable steps to satisfy itself that the recommendation or discretionary action is suitable for the consumer, taking account of all the available alternatives; | ||
| (b) not recommend, or where the licensee has discretion to act on behalf of a consumer, execute any sale or purchase that is unsuitable for the consumer. | ||
| (3) A licensee shall take all reasonable steps to ensure that it does not give advice or effect a transaction, on behalf of a consumer, unless the advice or transaction is suitable for the consumer considering the facts disclosed by the consumer and any other relevant facts about the consumer that the licensee is or ought to reasonably be aware of. | ||
| Regulation 25 | (1) A licensee shall use systems which are able to provide an accurate and fully accessible audit trail of all transactions. | This regulation proposes comprehensive reporting requirements which creates a robust supervisory data infrastructure. The fraud and security breach reporting enables rapid regulatory response and the geographic distribution data supports financial inclusion monitoring. |
| Record keeping and submission of reports | (2) A licensee shall, within ten days of the end of every calendar month, submit daily reports to the relevant regulatory authority, in the manner specified by the relevant regulatory authority, information regarding— | |
| (a) the volumes, values and geographic distribution of each virtual asset transfer or payment offered by it; | ||
| (b) incidents of fraud, theft or robbery; | ||
| (c) material service interruptions and major security breaches; | ||
| (d) complaints reported, including remedial measures taken, those resolved and those outstanding. | ||
| Regulation 26 | The relevant regulatory authority may— | The regulation confers wide investigative powers on the regulator, including on site inspection. The power to enter premises where the regulator reasonably suspects unlicensed business is quite broad. This power should be exercised judiciously to avoid discouraging legitimate business activity. |
| Provision of Information. | (a) require an officer of the licensee to produce or furnish to the relevant regulatory authority or officer making an examination, within a reasonable time— | |
| (i) such books of accounts and any other documents in the custody or power of the licensee; | ||
| (ii) statements or information relating to the affairs of licensee as may be required by the examining officer; | ||
| (b) by notice, require a licensee to provide information to the relevant regulatory authority, in such manner and form as the relevant regulatory authority may specify for the purposes of assessing compliance with these Regulations; | ||
| (c) at any time, enter any premises where a licensee is carrying on business, or any premises where the relevant regulatory authority reasonably suspects that any business is carried out in contravention of these Regulations. | ||
| Regulation 27 | (1) A licensee shall maintain a register of interests disclosing any holdings, directorships, or beneficial interests of directors, senior officers, or associated parties in any virtual asset issuer. | This regulation’s requirement for a register of directors' and senior officers' interests in virtual asset issuers is a reasonable provision which is designed to identify and manage conflicts of interest. This provision aligns with the Companies Act, 2015 requirements for declaration of interests. |
| Register of interests. | (2) The register shall be reviewed at least annually and made available to the relevant regulatory authority upon request. | |
| Regulation 28 | (1) In relation to a virtual asset exchange, stablecoin issuance or virtual asset wallet provider, a person shall not— | The thirty-three and a third percent (33.3%) maximum shareholding limit for virtual asset exchanges, stablecoin issuers, and wallet providers is designed to prevent single entity control and complete risk concentration. The exception for diverse corporate shareholders is a welcome incentive for institutional investors. |
| Shareholding of virtual asset exchange, stable coin issuer and wallet provider. | (a) control or be beneficially entitled, directly or indirectly, to more than thirty-three and a third percent of the issued share capital or voting rights, directorship appointments, dividends or interest on shareholder loans in a licensee; or | |
| (b) appoint more than one-third of the members of the board of a licensee. | ||
| (2) Notwithstanding sub regulation (1), a person may be allowed to own more than thirty-three and a third percent or control more than one-third of appointments in a licensee, if the person is— | ||
| (a) a corporate entity with a diverse shareholding; and | ||
| (b) the ultimate beneficial owners of the corporate entity do not hold more that 33.3 percent of the shareholding in that entity. | ||
| Regulation 29 | (1) Pursuant to section 27 of the Act, where a person desires to directly or indirectly acquire shares or an interest in a licensee or where a licensee wishes to voluntarily transfer or dispose of its shares, it shall make an application to the relevant regulatory authority upon payment of a fee set out in the First Schedule. | This regulation provides a comprehensive framework for regulatory approval of ownership changes, including scrutiny of the acquirer's character, financial soundness, source of funds, and AML/CFT risk. The consultation with competition authorities and AML bodies is a best practice provision. |
| Ownership changes. | (2) An application made in terms of sub regulation one (1) shall include sufficient information to enable the relevant regulatory authority to consider the proposed acquisition, transfer or disposal in relation to— | |
| (a) the nature of the proposed acquisition, disposal or transfer; | ||
| (b) the identity of the proposed acquirer or acquiree and any person who has control or management of the proposed acquirer; | ||
| (c) how the proposed acquisition, transfer or disposal is to be financed. | ||
| (3) In assessing a proposed acquisition, transfer or disposal, the relevant regulatory authority shall have regard to— | ||
| (a) the suitability and character of the proposed acquirer; | ||
| (b) the ability of the proposed acquirer to conduct the business of the licensee in the long term; | ||
| (c) the reputation, knowledge, skills and experience of any person who will direct the business of the licensee as a result of the proposed acquisition, transfer or disposal; | ||
| (d) the fitness and probity of any new directors, significant shareholders and senior officers appointed as a result of the proposed acquisition, transfer or disposal; | ||
| (e) the financial soundness of the proposed acquisition, transfer or disposal; | ||
| (f) the source of funds of the acquirer; | ||
| (g) whether the licensee will be able to comply and continue to comply with the provisions of the Act and these Regulations; and | ||
| (h) whether there are reasonable grounds to suspect that, in connection with the proposed acquisition, disposal or transfer, financial crime, money laundering, terrorism financing or proliferation financing is being or has been committed or attempted or could increase the risk thereof. | ||
| (4) The relevant regulatory authority may, where it grants or refuses to grant approval on the proposal to acquire, dispose or transfer shares or interest in a licensee, inform the licensee, in writing, and shall give reasons for the grant or refusal of the approval. Conflict of interest. | ||
| (5) For the purposes of this regulation, the relevant regulatory authority may consult the competent authorities responsible for mergers and acquisitions and anti-money laundering, counterterrorism and proliferation financing in granting or declining its approval. | ||
| Regulation 30 | (1) A licensee shall— | This regulation is a detailed conflict of interest management provision, the requirements for information barriers, physical segregation, employee undertakings, and training represent best practice conflict management standards. The prohibition on using consumer information for the benefit of employees or other consumers is particularly important for custodians and wallet providers who hold sensitive data. |
| Conflict of interest. | (a) identify and document the conflicts of interest that are likely to occur in the course of its regulated activity; | |
| (b) adopt and document appropriate policies to minimize those conflicts by identifying the instances where it would refuse to act and, where this is not necessary, making arrangements to minimize the risk of any loss to the consumer; and | ||
| (c) avoid any conflict of interest between itself and a consumer and where such a conflict exists, decline to act, or if it considers that the conflict can be managed, disclose it to the consumer and follow the policies developed to minimize damage to the consumer and to 28 put the consumer’s interests ahead of its own. | ||
| (2) A licensee shall not take advantage of information it obtained from providing services to a consumer for its own benefit or the benefit of its employees or the benefit of another consumer, and where such an eventuality is likely to occur, the licensee shall— | ||
| (a) adopt and document procedures, including the erection of information barriers, barriers between information technology systems, physical barriers or even separate office locations, to minimize the possibility of information from one consumer being used for the benefit of another consumer, its employees or the licensee; | ||
| (b) train employees in matters relating to the conflict of interest and the procedures developed to avoid them; and | ||
| (c) obtain undertakings from employees that they will not use information gained from the consumers for their personal benefit. | ||
| (3) Where a licensee has a material interest in a transaction to be entered into with or for a consumer, or a relationship which gives rise to a conflict of interest, the licensee shall not, knowingly, advise, or exercise discretion, in relation to that transaction unless it has— | ||
| (a) disclosed the material interest or relationship that may give rise to a conflict, as the case may be, to the consumer; or | ||
| (b) taken reasonable steps to ensure that neither the material interest nor relationship would adversely affect the interests of the consumer. | ||
| (4) A licensee shall take reasonable steps to ensure that neither it nor any of its employees or agents offers or gives, or solicits or accepts, any inducement that is likely to conflict with any of the duties owed to consumers. | ||
| Regulation 31 | (1) A licensee shall, at the point of service, provide— | This regulation requires licensees to display key information at all points of service which is applicable both to physical and digital service points. The requirement to display information at all service points is appropriate for consumer protection. |
| Information at point of service. | (a) a clear and understandable description of the services which it offers and the rates, terms, conditions and charges for such services; | |
| (b) clear terms of service to its consumers and agents; | ||
| (c) the name of the licensee; | ||
| (d) a telephone number or such other contact medium which provides access to its consumer care system. | ||
| (2) The information referred to under sub regulation (1) shall be published and displayed conspicuously at all points of service. | ||
| Regulation 32 | (1) A licensee shall perform customer due diligence prior to onboarding a consumer by identifying and verifying the identity details of the consumer for purposes of these Regulations. | This regulation incorporates POCAMLA CDD requirements, this is a good cross-referencing approach that avoids duplicating anti money laundering legislation. |
| Performance of customer due diligence prior to onboarding. | (2) The performance of customer due diligence under sub regulation (1), shall be done in accordance with the obligations imposed under the Proceeds of Crime and Anti-Money Laundering Act. | |
| Regulation 33 | (1) A virtual asset exchange or token issuance platform provider shall perform due diligence on all virtual assets before including them for trading on the exchange or platform. | The requirement for smart contract audits by independent assessors before listing is a sound provision. |
| Performance of due diligence before admission for trading. | (2) In the performance due diligence under sub regulation (1), the virtual asset exchange or token issuance platform provider shall take into consideration— | |
| (a) the regulatory status of the virtual asset and whether its regulatory status would also affect the regulatory obligations of the virtual asset exchange and token issuance platform provider; (b) the supply, demand, maturity and liquidity of 30 a virtual asset; | ||
| (c) the complexity and development of the virtual asset; | ||
| (d) the risks associated with the virtual asset and its issuer; | ||
| (e) the enforceability of any consumer rights relating to the virtual asset. | ||
| (3) Where a virtual asset for trading is based on a smart-contract, a virtual asset exchange or token issuance platform provider shall cause the smart-contract to be audited by an independent assessor before admitting the virtual asset for trading. Transaction confirmation. Fair allocation. | ||
| (4) A virtual asset exchange or token issuance platform provider shall continuously monitor each virtual asset admitted for trading on the exchange or the platform to determine the viability of that virtual asset to continue or cease trading. | ||
| Regulation 34 Transaction confirmation. | A licensee shall, in respect of every contract for the exchange, purchase or sale of a virtual asset it has entered into, not later than the end of the trading day after the contract was entered into, make out and send to the consumer, a confirmation with respect to the transaction. | This regulation’s requirement to send transaction confirmations by end of trading day following execution is an appropriate consumer protection measure. |
| Regulation 35 | Where a licensee has aggregated an order for a consumer’s transaction with an order for its own account transaction, or with an order for another consumer’s transaction, a licensee shall in the subsequent allocation— | These provisions address order aggregation and allocation fairness which are critical in preventing front running and self dealing. The priority rule that consumer orders take precedence over proprietary orders is an investor protection measure. |
| Fair allocation. | (a) not give unfair preference to itself or to any of the consumers; and | |
| (b) give priority to satisfying orders for consumer transactions, if all orders cannot be satisfied. | ||
| Regulation 36 Timely allocation. | A licensee shall ensure that any transaction it executes are allocated to the consumers who gave the orders in a timely and equitable manner. | This provision prevents front running and self dealing by requiring consumer priority in order allocation. |
| Regulation 37 Off-market transactions. | A licensee shall report all trades in virtual assets dealt with otherwise than at a licensed virtual asset exchange or token issuance platform provider in such manner as may be specified by the relevant regulatory authority. | This regulation’s requirement to report off market transactions to the regulator supports market transparency. |
| Regulation 38 | (1) Pursuant to section 35(1) of the Act, the relevant regulatory authority may conduct routine onsite and offsite inspections to assess compliance with the Act and these Regulations. | The provision for both routine and unannounced on site and off-site inspections is appropriate for an active supervisory regime. |
| Inspections. | (2) Where the relevant regulatory authority exercises the powers under sub regulation one (1), the licensee shall— | |
| (a) grant full access to premises, systems, and records; | ||
| (b) provide explanations, clarifications or data as requested; and | ||
| (c) implement remedial measures within such period as the relevant regulatory authority may specify. | ||
| (3) In furtherance of its powers under this regulation, the relevant regulatory authority shall maintain continuous surveillance of market conduct, transactional activity and systemic risk using data analytics and reporting tools. | ||
| Regulation 39 | The board of directors of a licensee shall appoint a compliance officer who shall— | The mandatory compliance officer provision is comprehensive and well structured, requiring the compliance officer to have sufficient authority, unfettered access to information, direct board access, and no involvement in the functions being monitored. |
| Compliance officer. | (a) monitor compliance with the regulatory requirements specified by the relevant regulatory authority, and shall not be involved with any function that is the subject of compliance; | |
| (b) have sufficient authority to carry out such function; | ||
| (c) have unfettered access to information; | ||
| (d) have direct access to the board of directors; | ||
| (e) take necessary action to rectify any non- 32 compliance; | ||
| (f) report any non-compliance issues that cannot be rectified to the board of directors; | ||
| (g) report to the board of directors any material breaches of the regulatory requirements; | ||
| (h) submit an annual corporate governance report to the board of directors; and | ||
| (i) Risk management. ensure that conflict of interest is avoided where compliance staff perform non compliance tasks. | ||
| Regulation 40 | For the purposes of risk management, a licensee shall comply with Governance arrangements. | This provision is essentially a reference to technical standards and international guidelines to be issued by the regulator. |
| Risk management. | (a) any technical standards that may be issued by the relevant regulatory authority from time to time; and | |
| (b) any other international standards and risk management guidelines which may be required by the relevant regulatory authority from time to time. | ||
| PART IV – CORPORATE GOVERNANCE REQUIREMENTS | ||
| Regulation 41 | (1) A licensee shall establish effective, transparent and adequate governance arrangements to ensure continued integrity of its services. | The requirement to separate the virtual asset business into a distinct business unit with separate management and accounts is a reasonable measure that can help to prevent risk and conflicts of interest with any other business lines the parent company may have. |
| Governance arrangements. | (2) The governance arrangements established under sub regulation (1) shall include— | |
| (a) a board of directors consisting of persons who meet the fit and proper criteria as set out in the Fourth Schedule; | ||
| (b) clearly defined and documented organisational structure including ownership, oversight and management structure; | ||
| (c) segregation of duties and internal control arrangements; and | ||
| (d) the separation of virtual asset business by the licensee in a separate business unit from its other business units, including maintaining a separate management structure and keeping separate books of account. | ||
| (3) A licensee offering payment services shall establish adequate operational arrangements for its services. | ||
| (4) The operational arrangements established under sub regulation (3) shall include— | ||
| (a) rules and procedures setting out the rights and liabilities of the licensee and the consumer; | ||
| (b) the risks the consumer may incur; | ||
| (c) measures to ensure prudent management of the funds collected from consumers, including measures to ensure that such funds are available at all times for repayment to consumers; | ||
| (d) measures to ensure safety, security and operational reliability of the service, including contingency arrangements; and | ||
| (e) the maintenance of separate records and accounts for virtual asset payment processing services from other business activities. | ||
| Regulation 42 | (1) The board of directors of a licensee shall consist of— | The definition of an independent director is comprehensive, borrowing from best practices in corporate governance. The requirement for a minimum of three directors and the separation of the roles of Chairperson and CEO is sound. |
| Board of directors. | (a) at least three members of whom one-third shall be independent directors; and | |
| (b) not more than one third of the directors shall be related to any director. (2) The chairperson of the board shall not be appointed as the chief executive officer of the licensee. | ||
| (3) For purposes of this regulation an “independent director” means a person who— | ||
| (a) has not been employed by the licensee in an executive capacity within the last five years; | ||
| (b) is not associated to an adviser or consultant to the licensee or a member of the licensee’s senior management or a person employed by the licensee in an executive capacity within the last five years; | ||
| (c) is not associated to a significant consumer or supplier of the licensee or has not had any business relationship with the licensee within the last five years; Role of the board of directors. | ||
| (d) does not have a contract of service with the virtual asset service provider, or a member of the licensee senior management; | ||
| (e) is not a close relation of an adviser or consultant to the licensee or a member of the licensee senior management; | ||
| (f) has not had any of the relationships described in paragraphs (a), (b), (c), (d) and (e) with any affiliate of the licensee. | ||
| Regulation 43 | (1) The board of directors of a licensee shall be collectively responsible for the conduct and governance of its virtual asset business and in particular shall— | This regulation establishes the principle of ultimate board accountability. The stipulation in sub regulation (3) reinforces the non-delegable nature of the board's duties, which is a vital safeguard. |
| Role of the board of directors. | (a) give strategic direction and provide effective oversight to a licensee; | |
| (b) ensure the integrity of the licensee’s accounting and financial reporting systems; | ||
| (c) manage risks affecting the regulated activity and shall regularly review the effectiveness of the risk management process; and 35 | ||
| (d) ensure that the licensee complies with the Act and other relevant laws. | ||
| (2) The board of directors of a licensee may establish such committees, including an audit committee, as it may consider necessary to assist it in the performance of its functions. | ||
| (3) The board of directors of a licensee shall not be discharged from its duties and responsibilities for matters or authority delegated to committees of the board or to the management of a licensee. | ||
| Regulation 44 | A person shall qualify for appointment or designation as the chief executive officer of a licensee under section 30(1) of the Act, if that person— | The requirement for professional competence is sound. |
| Chief executive officer. | (a) meets the fit and proper requirements under section 18 of the Act; and | |
| (b) possesses professional competence in virtual assets or other fields relevant to the operations of virtual asset business. | ||
| Regulation 45 Finance officers and internal auditors. | The persons responsible for the management of finance function and the internal audit function in a licensee shall be members of the Institute of Certified Public Accountants of Kenya. | This is a clear and objective requirement that leverages existing professional standards. It ensures that key financial roles are held by qualified and regulated professionals, this adds a layer of credibility and accountability to a licensee's financial operations. |
| PART V – INTERVENTION AND STATUTORY MANAGEMENT | ||
| Regulation 46 | (1) The relevant regulatory authority may intervene in the management of a licensee where— | This regulation provides a comprehensive suite of early intervention tools, which is critical for a such a high-risk sector. |
| (a) the licensee fails to meet its obligations to its customers; | ||
| (b) the licensee fails to meet its financial obligations to other licensees; | ||
| (c) the licensee fails to comply with a directive issued by the relevant regulatory authority; | ||
| (d) the licensee fails to comply with the provisions of the Act. | ||
| (2) The relevant regulatory authority may, where necessary, intervene in the management of a licensee during a crisis to safeguard financial stability, protect customers, and preserve public confidence in the financial system. | ||
| (3) In any case to which this regulation applies, the relevant regulatory authority may— | ||
| (a) appoint a statutory manager in accordance with regulation Appointment of statutory manager. | ||
| (b) remove any officer or employee of a licensee who, in the opinion of the relevant regulatory authority, has caused or contributed to any contravention of any provision of the Act or these Regulations or to any deterioration in the financial stability of the licensee; | ||
| (c) restrict the licensee from engaging in new virtual asset services; | ||
| (d) prohibit the licensee from engaging any new agents or direct the licensee to terminate any agency arrangement. | ||
| Regulation 47 | (1) Where the relevant regulatory authority exercises its power under section 15 of the Act, the relevant regulatory authority shall, by notice in the Gazette, appoint a statutory manager to manage consumer assets for a period not exceeding twelve months. | The fixed term of the statutory manager with the possibility of a court approved extension strikes a reasonable balance between providing the manager with sufficient time to stabilize the entity and preventing indefinite government control without judicial oversight. |
| (2) The term of the statutory manager may be extended for a further term not exceeding twelve months with the approval of the competent court. | ||
| Regulations 48 | (1) The functions of a statutory manager shall include— | The powers granted are standard for statutory management and are necessary for effective administration. This also aligns with the procedures stipulated under the Insolvency Act for financially distressed companies. |
| Intervention in Management, Appointment of Statutory Manager, Functions and Powers of Statutory Manager | (a) taking control of the assets of the licensee for purposes of safeguarding monies and virtual assets belonging to consumers; and | |
| (b) overseeing and administering the settlement of monies and virtual assets belonging to consumers. | ||
| (2) In the performance of his or her functions under sub regulation (1), a statutory manager shall have powers necessary for the performance of his or her functions and in particular shall have the power to declare a moratorium for purposes of safeguarding monies and virtual assets belonging to consumers. | ||
| (3) The moratorium referred to in sub regulation (2) shall be applied equally and without discrimination to all classes of creditors: Provided that the statutory manager may offset the liabilities owed by the licensed person to any creditor against any debts owed by that creditor to the licensed person. | ||
| (4) Where the statutory manager has assumed control of a licensee, that statutory manager shall have the power— | ||
| (a) to enter into any premises of licensee and take possession and control of the assets and require any person in the premises to account for and deliver up to the statutory manager possession and control of the assets; | ||
| (b) to sell or otherwise dispose of any asset that is subject to an agreement creating a security interest to any person who agrees to assume the obligation secured by the security interest; | ||
| (c) subject to paragraph (b), to sell or otherwise dispose of the assets and business undertaking of the licensee by private treaty or public sale or in such other manner and on such terms and conditions as the statutory manager deems appropriate; | ||
| (d) to arrange for the assumption of all or any part of the liabilities of a licensee by a person; | ||
| (e) to carry on the business of a licensee to the extent that the statutory manager deems necessary or beneficial; | ||
| (f) to sue for, defend, compromise and settle, in the name of the licensee, any claim made by or against it; | ||
| (g) in the name of the licensee, to do all acts and execute all receipts and other documents; and | ||
| (h) to recover out of the assets of the licensee all the costs, charges and expenses, including remuneration, properly incurred by the statutory manager in the exercise of powers, in priority to all other claims. Application for licence to issue or promote initial coin offering. | ||
| (5) Where the statutory manager exercises one or more powers under this regulation, the statutory manager shall not, by reason of the exercise of such powers, be held to have assumed or incurred any obligation or liability of the licensee for its own account. | ||
| PART VI – REQUIREMENTS FOR OFFER OF INITIAL COIN OFFERINGS AND LISTINGS FOR VIRTUAL ASSET EXCHANGES | ||
| Regulation 49 | (1) Pursuant to section 34 of the Act, a person seeking to issue or promote an initial coin offering shall make an application to the relevant regulatory authority for approval. | This regulation creates a customized licensing regime for initial coin offering’s, which is a significant improvement over a regulatory gap. The requirement for a white paper and governance structure could promote investor protection. |
| (2) In addition to the requirements under regulation 5, an application made under sub regulation (1) shall be accompanied by— | ||
| (a) a white paper with the information provided for under regulation 53; | ||
| (b) governance structure of the issuer, including the board and senior management; | ||
| (c) the policies and procedures for the monitoring the cycle of the issuing and offering of an initial coin offering; | ||
| (d) the information where the proceeds raised will be transferred or deposited; | ||
| (e) the location where the information as required by these Regulations will be retained and will be accessible in Kenya; | ||
| (f) the details and confirmation of the promoter; and (g) the application fee specified in the First Schedule. | ||
| (2) The relevant regulatory authority may require an applicant to furnish such other information, document or report in connection with the application, as it may deem necessary, for the purpose of assessing the application. | ||
| (3) An applicant may withdraw an application by giving written notice, including the reasons thereof, to the relevant regulatory authority, at any time before the determination of the application. | ||
| Regulation 50 | (1) The relevant regulatory authority may object to an application where it is satisfied that — | The requirement in sub regulation (3) that an initial coin offering must be conducted through an approved trading platform is a key structural control. It ensures that the offering takes place within a regulated environment, making it easier to monitor market conduct and enforce rules against market abuse. |
| (a) the application does not comply with the Act or these Regulations; | ||
| (b) the criteria set out in section 34(4) of the Act is not met; | ||
| (c) a white paper does not meet the requirements in regulation 53; | ||
| (d) the promoter is not an eligible person under section 34(2) of the Act; | ||
| (e) the policies and procedures for monitoring the cycle of the issuing and offering of an initial coin are insufficient for mitigating possible market abuse, mis-selling or fraud risks. | ||
| (2) Upon approval of an application under regulation 49(1), the relevant regulatory authority shall register the applicant’s details in accordance with regulation 53. (3) An initial coin offering approved under this Part shall be conducted through trading platforms approved under regulation 51. | ||
| Regulation 51 | (1) A trading system or platform to be deployed by a virtual asset exchange or token issuance platform provider shall be approved by the relevant regulatory authority prior to its use. | This regulation sets a high standard for technological integrity and transparency. The requirement for a complete and tamper-proof audit trail and the mandatory seven (7) year record retention is important for forensic analysis and regulatory oversight. |
| (2) The trading system or platform referred to under sub regulation (1) shall— | ||
| (a) enable real-time public access to trading information; | ||
| (b) incorporate mechanisms for transparent and efficient price discovery. | ||
| (c) maintain a complete and tamper-proof audit trail of all transactions. | ||
| (d) implement adequate cybersecurity, resilience and access control measures; and | ||
| (e) retain and securely store all trading and transaction records for a period of not less than seven years beginning from the date the transaction occurred. | ||
| Regulation 52 | An approval of an offer of an initial coin offering shall be valid for a period not exceeding twelve months. | This clause sets a maximum twelve-month validity period for the approval of an initial coin offering, giving effect to the relevant regulatory authority's approval function over virtual asset offerings under section 34 of the Act and the Cabinet Secretary's power under section 49(2)(m) to prescribe requirements for the offer of initial coin offerings. |
| Regulation 53 | (1) An applicant shall publish its white paper upon receipt of notice from the relevant regulatory authority that it has no objection to the proposed issuance and promotion. | This regulation is the cornerstone of investor protection for initial coin offering. The extensive disclosure list eliminates historical information asymmetry. Further, holding the board directly responsible is a critical accountability mechanism. |
| (2) The white paper referred to under sub regulation (1) shall provide full and accurate disclosure of information that will enable an investor to make an informed assessment before subscribing or investing and such information shall include — | ||
| (a) brief description of the directors, senior officers and advisers of the issuer including their name, designation, nationality, address, professional qualifications, related experience and any involvement or participation in a previous similar offering; | ||
| (b) the objective or purpose of initial coin offering including information on the project to be managed and operated by the issuer; | ||
| (c) the key characteristics of the initial coin offering; | ||
| (d) identification as to whether a virtual asset offering will have different classes of holders in relation to any benefits, rights or liabilities linked to the offering; | ||
| (e) a detailed description of the sustainability of the project; the business plan of the issuer; | ||
| (f) the business plan of the issuer; | ||
| (g) the targeted amount to be raised through the project and subsequent use and application of the proceeds thereafter illustrated in a scheduled timeline for drawdown and utilization of proceeds; | ||
| (h) any rights, conditions or functions attached to the offering, including any specific rights; | ||
| (i) the details on the determination of the accounting and the valuation treatments for the offering, including all valuation methodology and reasonable presumptions adopted in such calculation; | ||
| (j) the details on the determination of the accounting and the valuation treatments for the offering, including all valuation methodology and reasonable presumptions adopted in such calculation; the associated challenges and risks, as well as mitigating measures thereof; | ||
| (k) the information in respect to the distribution of the initial coin offering and, where 42 applicable, the distribution policy of the issuer of initial coin offering; | ||
| (l) policies on monitoring the cycle of the initial coin offering; | ||
| (m) information about the person, if any, underwriting or guaranteeing the project; | ||
| (n) any restrictions on the transferability of the investment made; | ||
| (o) methods of payment to invest or subscribe; | ||
| (p) details of refund mechanism or withdrawal rights; | ||
| (q) details of the authorized status of the promoter or issuer in Kenya; and intellectual property rights associated with the offerings and protection thereof. | ||
| (r) intellectual property rights associated with the offerings and protection thereof. | ||
| (3) The initial coin white paper shall contain a clear notice that the initial coin offering is not covered by the Investor Compensation Fund. | ||
| (4) The board of directors of an issuer shall be responsible for the information provided in the white paper. | ||
| (5) A person who fails to comply with the requirements of this regulation is liable to an administrative penalty of three million shillings. | ||
| Regulation 54 | (1) An applicant may only commence advertising of an issuance or promotion following the date on which it receives notice from the relevant regulatory authority that it has no objection to the proposed issuance or promotion. | This regulation is straightforward, it ensures that marketing does not precede regulatory approval, preventing exposure to unvetted promotional material. |
| (2) The applicant may only advertise the issuance or promotion for the duration specified in the application. | ||
| (3) A person who fails to comply with the 43 requirements of this regulation is liable to an administrative penalty of three million shillings. | ||
| Regulation 55 | (1) Where an applicant wishes to extend the promotion or issuance of an initial coin offering beyond the end date stated in its application, the applicant shall submit to the relevant regulatory authority an application for extension of issuance or promotions and reasons thereof of extension. (2) A notice of an extension under sub regulation (1) shall be submitted not later than three months before the expiry date of the end date stated in its application. | This regulation provides limitations on extension over the provided timelines. The new white paper requirement for subsequent offers is a compliance measure. |
| (3) The relevant regulatory authority may object to the extension where— | ||
| (a) prejudice would be caused or would ensue to the financial services industry or any part thereof; | ||
| (b) the continued promotion or issuance is against public policy; or | ||
| (c) the continued promotion or issuance is unlikely to meet the financial objectives stated in the original application. | ||
| (4) An extension shall take effect where the relevant regulatory authority has no objection to the proposed change within a period of thirty working days following receipt of notice under sub regulation (1). | ||
| (5) An extension may only occur for a period of no more than six calendar months after approval under sub regulation (4). | ||
| (6) Any subsequent offer to the public of the virtual assets shall be deemed to constitute a separate offer to the public to which the requirements of this Part shall apply. | ||
| (7) An additional virtual asset white paper shall be required for any subsequent offer to the public of the virtual asset. | ||
| Regulation 56 | (1) Where an applicant wishes to change the promoter named in its application, it shall submit a written notice to the relevant regulatory authority and provide reasons for the change. | This regulation allows operational flexibility while maintaining the necessary oversight. Further its approval mechanism ensures changes cannot happen without regulatory visibility. |
| (2) A notice provided under sub regulation (1) shall be submitted to the relevant regulatory authority not less than 15 working days before the applicant proposes to effect the change. | ||
| (3) The relevant regulatory authority may object to the change where— | ||
| (a) the promoter is not an eligible person under section 34(2) of the Act; | ||
| (b) prejudice would be caused or would ensue to the financial services industry or any part thereof. (4) A change of a promoter shall be effected where the relevant regulatory authority has no objection to the proposed change within a period of 15 working days following receipt of notice under subregulation (1). | ||
| (5) A person who fails to comply with the requirements of this regulation is liable to an administrative penalty of three million shillings. | ||
| Regulation 57 | The relevant regulatory authority shall maintain a register with the following information — | This regulation establishes a public record of approved initial coin offering’s, enhancing transparency and allowing verification of offering status and history. |
| (a) the name and address of the issuer or promoter of initial coin offerings; | ||
| (b) the date upon which the promotion or issuance is to start and to end; | ||
| (c) any measures imposed by the relevant regulatory authority under the Act; | ||
| (d) any other relevant information that the relevant regulatory authority deems necessary. | ||
| Regulation 58 | (1) A virtual asset exchange or a token issuance exchanges and token issuance platforms. platform provider shall maintain an official list in respect of all virtual assets listed on the exchange or platform. | The requirement to meet a minimum subscription before listing is a consumer protection measure that helps filter out projects with insufficient market interest or support. The retained power of the regulator to order a delisting is a safety valve, allowing it to act decisively in the event of fraud, market disruption, or a material risk to consumers. |
| (2) The virtual asset exchange or a token issuance platform provider shall enter in the official list the particulars of all virtual assets that have been approved for listing. | ||
| (3) A virtual asset exchange or a token issuance platform provider shall only include a virtual asset in the official list where the virtual asset has attained the minimum total subscription disclosed in the white paper approved by the relevant regulatory authority in respect of the initial virtual asset offering and listing of the virtual asset. | ||
| (4) The official list shall, where applicable, include the following particulars in respect of each listed virtual asset— | ||
| (a) the name of the virtual asset; | ||
| (b) the name of the issuer, where applicable; | ||
| (c) the total number of virtual assets listed; | ||
| (d) the listing date; | ||
| (e) the trading commencement date; and | ||
| (f) the redemption date. | ||
| (5) A virtual asset exchange or a token issuance platform provider shall promptly notify the relevant regulatory authority of each new listing or delisting decision and where a listing of stablecoins is undertaken, comply with all applicable reserve, redemption and disclosure requirements. | ||
| (6) The relevant regulatory authority shall retain the power to direct the delisting of a virtual asset where a material risk to market integrity, financial stability or consumer protection is identified. | ||
| PART VII – PROVISION RELATING TO TOKENIZATION OF REAL-WORLD ASSETS | ||
| Regulation 59 | (1) A person seeking to undertake the activity of virtual asset tokenization shall make an application to the relevant regulatory authority for licence. | This regulation requires evidence of ownership, an independent valuation, and proof of no encumbrances which is essential to ensure the tokenized asset is legitimate and not fraudulently created. The requirement for a custody agreement is a safeguard to link the digital token to a verifiable, secure, and controlled physical or traditional asset. |
| (2) In addition to the requirements under regulation 5, an application for a licence to undertake the activity of virtual asset tokenization shall be accompanied by— | ||
| (a) evidence that the real-world asset can be tokenized and ownership can be established; | ||
| (b) an agreement of the proposed custodian who shall hold the title and custody of the real-world asset; | ||
| (c) a report by an independent valuer showing the real-world asset’s fair market value; | ||
| (d) evidence that the real-world asset is clear of any encumbrances; | ||
| (e) rules of ownership, transferability, compliance, and profit distribution where the tokenization is based on distributed ledger technology-based smart contracts; | ||
| (f) the application fee set out in the First Schedule | ||
| (3) The relevant regulatory authority may require an applicant to furnish such other information, document or report in connection with the application, as it may deem necessary, for the purpose of assessing the application. | ||
| Regulation 60 | (1) A person seeking to undertake a virtual asset offering of a tokenised real-world asset shall make an application to the relevant regulatory authority for approval. | This regulation creates a distinct approval pathway for tokenized real-world asset offerings. The requirement to specify where proceeds will be deposited is a useful measure. |
| (2) An application under sub regulation (1) shall be accompanied by— | ||
| (a) a white paper with the information provided for under regulation. | ||
| (b) governance structure of the issuer, including the board and senior management; | ||
| (c) the policies and procedures for the monitoring the cycle of issuance and offering of tokenised real-world assets; | ||
| (d) the information where the proceeds raised will be transferred or deposited; | ||
| (e) the details and confirmation of the promoter; and | ||
| (f) Contents of white paper for offering of tokenized real-world asset. the application fee specified in the First Schedule. | ||
| Regulation 61 | (1) The white paper a virtual asset offering of a tokenised real-world asset shall provide full and accurate disclosure of information that will enable an investor to make an informed assessment before subscribing or investing. | The mandate to clearly state whether the token represents a direct ownership right is crucial, as it defines the legal nature of the instrument and the investor's recourse. The requirement to detail risk assessments related to the underlying asset such as credit risk of a real estate borrower ensures investors are not just focused on the token technology but also on the fundamentals of the real-world asset. |
| (2) The information under sub regulation (1) shall include— | ||
| (a) brief description of the directors, senior management, key personnel and advisers of the issuer including their name, designation, nationality, address, professional qualifications, related experience and any involvement or participation in a previous similar offering; | ||
| (b) the key information about the tokenized assets including their location; | ||
| (c) a clear and accurate description of the rights or value that the token grants, or purports to grant, owners and/or holders of the token; | ||
| (d) whether the token represents, or purports to represent, a direct right of ownership of the tokenized assets, or a fractional proportion thereof, and if so, a detailed description of how | ||
| the right of ownership is established or such fractionalisation is structured; | ||
| (e) if transactions in the tokenized assets are subject to legal or regulatory requirements; | ||
| (f) a clear and detailed policy on the procedure for the creation and destruction of the tokens in public circulation and the consequence of such creation or destruction; | ||
| (g) the custody arrangement of the tokenized assets including the custodians involved; | ||
| (h) detailed assessments of risks relevant to the management, custody, investment or liquidation of the referenced real-world asset including credit risk, market risk, counterparty risk and liquidity risk; | ||
| (i) details on the determination of the accounting and the valuation treatments for the offering, including all valuation methodology and reasonable assumptions adopted in such calculation; | ||
| (j) associated challenges and risks, as well as mitigating measures thereof; | ||
| (k) information in respect to the distribution of the token offering; | ||
| (l) policies on monitoring the cycle of the token offering; | ||
| (m) details of how tokens will be traded or transferred; | ||
| (n) any restrictions on the transferability of the tokens; | ||
| (o) methods of payment to invest or subscribe; | ||
| (p) details of refund mechanism or withdrawal rights; | ||
| (q) details of the status of the promoter or issuer in Kenya; | ||
| (r) experience and track record of third-party vendors or service providers; | ||
| (s) information on the adequacy of systems and controls in place to safeguard the operation of tokenised assets against cyber security related risks; | ||
| (t) Listing of tokenized assets. the interoperability between the distributed ledger technology networks and systems of issuers and other parties; | ||
| (u) the information where proceeds raised will be transferred or deposited. | ||
| Regulation 62 | A person undertaking a virtual asset offering of a tokenised real-world asset shall— | This regulation creates a complete lifecycle framework from creation to secondary market trading. Requiring listing on a licensed platform ensures ongoing regulatory oversight after the initial offering. |
| Application for Tokenization Licence, Issuance of Tokenised Real-World Assets, White Paper Contents, Listing of Tokenised Assets | (a) create the tokens on a distributed ledger technology platform, representing fractional ownership or rights to the real-world asset; | |
| (b) code the rules of ownership, transferability, compliance, and profit distribution into distributed ledger technology platform based smart contracts; | ||
| (c) distribute the tokens via a primary offering; | ||
| (d) list the tokens on a licensed token issuance platform to enable liquidity and investor exit options. | ||
| PART VIII – PROVISIONS RELATING TO VIRTUAL ASSET WALLET PROVIDERS AND ISSUERS OF STABLECOIN | ||
| Regulation 63 | (1) A licensee providing virtual asset wallet provider services shall— | This regulation is very detailed and promotes consumer protection. The explicit consumer consent requirement for omnibus accounts, and the ongoing reconciliation obligations, provide structural protections against the asset commingling that has preceded every major VASP insolvency. |
| Responsibilities of a Virtual Asset Wallet Provider | (a) segregate holdings of virtual assets on behalf of their consumers from their own holdings or property, and from any other non-consumer virtual assets; | |
| (b) ensure that on the relevant distributed ledger, their consumers’ virtual assets are held on separate addresses from those on which their own virtual assets or any other non-consumer virtual assets are held; | ||
| (c) with respect to any internal ledger accounts, maintain separate accounts consumers’ virtual assets and their own virtual assets or any other non-consumer virtual assets; for their | ||
| (d) conduct regular internal and independent reconciliations of on-chain holdings against internal records and consumer entitlements, and make such records available to the relevant regulatory authority upon request; | ||
| (e) obtain explicit consumer consent prior to holding virtual assets on behalf of such consumers in one or more omnibus accounts, or under any other arrangement where consumer assets are not held in separate accounts for each individual consumer under that consumer’s name; | ||
| (f) maintain appropriate procedures to ensure that the virtual assets held in custody shall at all times be separate and insulated from the virtual asset service business’ estate; | ||
| (g) not lend, use, hypothecate, pledge or otherwise use or encumber consumer assets that have been entrusted to it for safekeeping; | ||
| (h) make its standard disclosures and standard consumer agreement readily accessible to consumers on such virtual asset service business’ website and such disclosures shall be made in clear, concise and non-technical language; | ||
| (i) maintain in its custody, a sufficient amount of each type of virtual asset to meet its obligations to consumers; ensure that necessary procedures are in place to return virtual assets held on behalf of their consumers or the means of access on demand to those consumers; | ||
| (j) ensure that necessary procedures are in place to return virtual assets held on behalf of their consumers or the means of access on demand to those consumers; | ||
| (k) establish, maintain, enforce, and regularly test reasonably designed written policies, procedures, and arrangements in order to— | ||
| (i) identify, in advance, the steps it intends to take in the wake of events that could affect the virtual asset business’ custody of the virtual assets; | ||
| (ii) enable the virtual asset business seize or freeze virtual assets, when required; | ||
| (iii) enable the transfer of virtual assets held by the virtual asset business to another appropriate person; | ||
| (iv) remedy mistaken, fraudulent or otherwise unauthorised transactions; | ||
| (v) ensure the continued safekeeping and accessibility of virtual assets in the event of unexpected disruptions to the virtual asset business’ control over its consumers’ virtual assets, the rights related to those virtual assets or the means of access to the virtual assets; | ||
| (l) maintain an up-to-date register of positions which records each consumer’s rights to the virtual assets in the control of the virtual asset business; | ||
| (m) provide their consumers, at least once every three months and at each request of the consumer concerned, with a statement of 52 holdings of the virtual assets recorded in the name of those consumers; | ||
| (n) if it outsources the custody of virtual assets— (i) only make use of other virtual asset businesses which are licensed under the Act; | ||
| (ii) notify the relevant regulatory authority of the use of other entities for the custody of virtual assets as a material change under section 26(f) of the Act; and | ||
| (iii) disclose to their consumers the terms and conditions associated with such outsourcing arrangement. | ||
| (2) The agreement referred to in subregulation (1)(h), shall include — | ||
| (a) the general terms and conditions regarding custody of the consumer’s virtual assets; | ||
| (b) how the virtual asset business segregates and accounts for the consumer’s virtual assets under subregulation (1)(a) to (g); | ||
| (c) the beneficial and equitable interests the consumer retains in their virtual assets; | ||
| (d) the limitations on the use of custodied virtual assets by the virtual asset business. | ||
| (3) For the purposes of subregulation (1)(l), the statement of position shall state at the minimum the virtual assets concerned, their balance, their value and the transfer of virtual assets made during the period concerned. | ||
| (4) Where a licensee providing virtual asset wallet provider services holds virtual assets— | ||
| (a) in one or more omnibus accounts; or | ||
| (b) under any other arrangement where consumer assets are not held in separate accounts for each individual consumer under that consumer’s name, it shall maintain appropriate procedures and up-to-date records in order to identify, at all times, the virtual assets belonging to each consumer and to account for all consumer transactions. | ||
| Regulation 64 | (1) A person seeking to undertake a virtual asset offering of a stablecoin shall make an application to the relevant regulatory authority for licence. | This regulation creates a dedicated licensing regime for stablecoin issuers, recognizing their unique risks. Further to this the requirement of investment policies and redemption policies allows for preapproved scrutiny of key risk areas. |
| (2) In addition to the requirements under regulation 5, an application for licence under sub regulation (1) shall be accompanied by — | ||
| (a) the investment policies of the reserve assets and an assessment of how such investment policy can affect the value of reserve assets; | ||
| (b) the issuer’s redemption policies; | ||
| (c) a white paper containing the information specified under regulation 65; | ||
| Regulation 65 | (1) A virtual asset white paper for stablecoin shall contain all of the following information— | This regulation is comprehensive in disclosure requirements. The inclusion of environmental impact of the consensus mechanism is forward looking. Further, the warning about lack of deposit insurance promotes consumer protection. |
| (a) information about the issuer of the stablecoin; | ||
| (b) information about the stablecoin; | ||
| (c) information about the offer to the public of the stablecoin or its admission to trading; | ||
| (d) information on the rights and obligations attached to the stablecoin; | ||
| (e) information on the underlying technology; | ||
| (f) information on the risks of the stablecoin; | ||
| (g) information on the principal adverse impacts on the climate and other environment-related adverse impacts of the consensus mechanism used to issue the stablecoin; | ||
| (h) the method and all factors used to calculate the value of reserve assets; | ||
| (i) the initial value and composition of the reserve assets; the conditions and the procedure to purchase stablecoins and redeem such stablecoins against reserve assets; | ||
| (j) the conditions and the procedure to purchase stablecoins and redeem such stablecoins against reserve assets; | ||
| (k) details of the stabilisation mechanism; | ||
| (l) a summary of the investment policies referred to in regulation 64(2)(a) and an explanation of how such investment policy can affect the value of reserve assets; | ||
| (m) details of the arrangements for custody and management of the reserve assets; | ||
| (n) the rights provided to holders of the stablecoin; | ||
| (o) the date of its approval. | ||
| (2) The virtual asset white paper shall also include the identity of the person other than the issuer that offers the stablecoin to the public or seeks its admission to trading, and the reason why that particular person offers that stablecoin or seeks its admission to trading. | ||
| (3) All the information listed in sub regulation (1) shall be fair, clear and not misleading. | ||
| (4) The virtual asset white paper shall not contain material omissions and shall be presented in a concise and comprehensible form. | ||
| (5) The virtual asset white paper shall contain a clear warning that— | ||
| (a) the stablecoin is not covered by investor compensation schemes; | ||
| (b) the stablecoin is not covered by deposit insurance; | ||
| (c) the issuer of the stablecoin is solely responsible for the contents of the virtual asset white paper. | ||
| (6) The virtual asset white paper shall contain a summary, which shall in brief and non-technical language provide— | ||
| (a) key information about the offer to the public of the stablecoin or the intended admission to trading of such stablecoin; | ||
| (b) appropriate information about the characteristics of the virtual assets concerned in order to help prospective holders of the virtual assets to make an informed decision; | ||
| (c) a warning that— | ||
| (i) it should be read as an introduction to the virtual asset white paper; | ||
| (ii) the prospective holder should base any decision to purchase the stablecoin on the content of the virtual asset white paper as a whole and not on the summary alone; | ||
| (d) state that holders of the stablecoin have a right of redemption at any time and at par value as well as the conditions for redemption. | ||
| (7) Issuers of stablecoins shall notify the relevant regulatory authority of the virtual asset white paper at least 30 days before the date of their publication. | ||
| (8) Any significant new factor, any material mistake or any material inaccuracy that is capable of affecting the assessment of the stablecoin shall be described in a modified virtual asset white paper drawn up by the issuers, notified to the relevant regulatory authority and published on the issuers’ websites upon approval by the relevant regulatory authority. | ||
| Regulation 66 | (1) Upon approval by the relevant regulatory authority, a stablecoin issuer shall publish on its website the approved virtual asset white paper and, where applicable, the modified virtual asset white paper. | This regulation ensures ongoing transparency throughout the life of the stablecoin. The requirement to publish changes and significant events is critical for informed holding decisions. |
| (2) The issuer of a stablecoin shall— | ||
| (a) for the purposes of the issuer’s duty to publish the white paper from the starting date of the offer to the public of the stablecoin or the admission to trading of that stablecoin; | ||
| (b) ensure that the approved white paper and modified white paper remain accessible for the duration that the relevant stablecoin is held by the public; | ||
| (c) publish as soon as possible on its website— | ||
| (i) any changes to the information referred to in the white paper; | ||
| (ii) any event that has or is likely to have a significant impact on the value of the stablecoin or on the reserve assets. | ||
| Regulation 67 | (1) A person shall not make an offer to the public or seek the admission to trading of a stablecoin, unless that person— | The ninety (90) day notification period gives the relevant regulatory authority adequate time for review and any necessary interventions. |
| Stablecoin Provisions: Licence, White Paper, Publication, Requirements for Offer, Issuance and Redeemability, Prohibition of Interest, Reserve Assets, Custody, Investment, Ongoing Disclosures, Conflicts, Redemption, Marketing, Audits, Delisting, Reporting | (a) is the issuer of such stablecoin | |
| (b) obtained approval from the relevant regulatory authority to publish the virtual asset white paper; and | ||
| (c) has published that virtual asset white paper in accordance with regulation 65. | ||
| (2) Notwithstanding sub regulation (1), upon the 57 written consent of the issuer, other persons may offer to the public or seek the admission to trading of the stablecoin. | ||
| (3) Issuers of stablecoins shall, at least 90 days before the date on which they intend to offer to the public those stablecoins or seek their admission to trading, notify the relevant regulatory authority of that intention. | ||
| Regulation 68 | (1) A holder of a stablecoin shall have a claim against the issuers of the stablecoin. | This regulation enshrines the core principle of a well-regulated stablecoin which is a direct, one on one claim on the issuer with a permanent, fee-free redemption right. This is a foundational consumer protection action that distinguishes a compliant stablecoin from a riskier, unregulated token. |
| (2) Issuers of stablecoins shall issue stablecoins at par value and on the receipt of funds. | ||
| (3) Upon request by a holder of a stablecoin, the issuer of that stablecoin shall redeem it, at any time and at par value, by paying the monetary value of the stablecoin held to the holder of the stablecoin. | ||
| (4) Issuers of stablecoins shall prominently state the conditions for redemption in the virtual asset white paper. | ||
| (5) The redemption of stablecoins shall not be subject to a fee. | ||
| Regulation 69 | (1) Issuers of stablecoins shall not grant interest in relation to stablecoins. | This regulation is a strict prohibition that prevents stablecoins from functioning as unlicensed deposit taking vehicles. |
| (2) A licensee shall not grant interest when providing virtual asset services related to stablecoins. | ||
| (3) Any remuneration or any other benefit related to the length of time during which a holder of a stablecoin holds such stablecoin shall be treated as interest and that includes net compensation or discounts, with an effect equivalent to that of interest received by the holder of the stablecoin, directly from the issuer or from third parties, and directly associated to the stablecoin or from the remuneration or pricing of other products. | ||
| Regulation 70 | (1) An issuer of stablecoins shall seek the approval of the relevant regulatory authority on any intended change of their business model likely to have a significant influence on the purchase decision of any holders or prospective holders of stablecoins, which occurs after licensing or after the approval of the virtual asset white paper. | This regulation prevents issuers from unilaterally changing the terms on which holders relied on. Further, the requirement for approval before changes take effect is a consumer protection measure. |
| (2) The changes envisaged under sub regulation (1) include any material modifications to— | ||
| (a) the governance arrangements, including reporting lines to the management body and risk management framework; | ||
| (b) the reserve assets and the custody of the reserve assets; | ||
| (c) the rights granted to the holders stablecoins; | ||
| (d) the mechanism through which a stablecoin is issued and redeemed; | ||
| (e) the protocols for validating the transactions in stablecoins; | ||
| (f) functioning of issuers’ proprietary distributed ledger technology, where the stablecoins are issued, transferred and stored using such a distributed ledger technology; | ||
| (g) the mechanisms to ensure the liquidity of stablecoins; | ||
| (h) the arrangements with third-party entities, including for managing the reserve assets and the investment of the reserve, the custody of reserve assets, and, where applicable, the distribution of the stablecoins to the public; | ||
| (i) the complaints-handling procedures. | ||
| (3) A request for approval under sub regulation (1) shall be accompanied by a draft modified virtual asset white paper and ensure that the order of the information appearing therein is consistent with that of the original virtual asset white paper. | ||
| (4) An issuer of stablecoins shall seek the approval of the relevant regulatory authority before the intended changes take effect. | ||
| (5) Where the relevant regulatory authority approves the modified virtual asset white paper, it shall require the issuer of the stablecoin— | ||
| (a) to put in place mechanisms to ensure the protection of holders of the stablecoins, when a potential modification of the issuer’s operations can have a material effect on the value, stability, or risks of the stablecoin or the reserve assets; | ||
| (b) to take any appropriate corrective measures to address concerns related to market integrity and financial stability. | ||
| Regulation 71 | (1) Where an issuer of a stablecoin has provided in its virtual asset white paper or in a modified virtual asset white paper, information that is not complete, fair or clear, or that is misleading, that issuer and its directors, significant shareholders, senior officers, and external auditors shall be liable to a holder of such stablecoin for any loss incurred due to that infringement. | This regulation creates personal liability for key individuals, not just the corporate entity. This significantly raises the stakes for accuracy and completeness. Making contractual exclusions void ensures accountability cannot be contracted away. |
| (2) Any contractual exclusion or limitation of civil liability as referred to in sub regulation (1) shall be deprived of legal effect. | ||
| (3) It shall be the responsibility of the holder of the stablecoin to present evidence indicating that the issuer of that stablecoin has infringed these Regulations by providing in its virtual asset white paper or in a modified virtual asset white paper information that is not complete, fair or clear, or that is misleading and that reliance on such information had an impact on the holder’s decision to purchase, sell or exchange that stablecoin. | ||
| (4) The issuer and its senior officers, directors, significant shareholders shall not be liable for loss suffered as a result of reliance on the information provided in a summary, except where the summary— | ||
| (a) is misleading, inaccurate or inconsistent when read with the other parts of the virtual asset white paper; or | ||
| (b) does not provide, when read with the other parts of the virtual asset white paper, key information in order to aid prospective holders when considering whether to purchase such stablecoins. | ||
| Regulation 72 | (1) The issuer of a stablecoin shall— | This is a very conservative and prudent approach to reserve management. By limiting reserve assets to high-quality, highly liquid, and short-term instruments, the regulation minimizes credit, market, and liquidity risk, ensuring that the stablecoin can withstand periods of stress and always meet redemption requests. |
| (a) fully back such stablecoins with reserve assets, such that the value of the reserve assets shall at all times be at least equal to the nominal value of all outstanding units of the stablecoin; | ||
| (b) only issue stablecoins whose reserve assets consist of one or a combination of the following— cash including central bank reserve deposits and bank deposits; | ||
| (i) government securities with residual maturity of not more than ninety days; | ||
| (ii) repurchase agreements with a maturity of not more than seven days backed by cash including central bank reserve deposits and bank deposits; | ||
| (c) ensure that reserve assets of each stablecoin are segregated from the operating assets of the issuer and the reserve assets of any other stablecoins; | ||
| (d) make reserve assets available for examination and for verification of the issuer’s disclosures as upon request of relevant regulatory authority or otherwise specified by relevant regulatory authority; | ||
| (e) ensure that the reserve assets are sufficiently liquid to enable the issuer to fund redemption requests; | ||
| (f) for the purposes of complying with its obligations under this sub-regulation, employ methods of calculating the valuation of reserve assets which are in accordance with generally accepted international standards on auditing or such standards as the relevant regulatory authority may recognise; | ||
| (g) maintain appropriate procedures to ensure that the reserve assets shall at all times be separate and insulated from issuer’s estate such that creditors of the issuer have no recourse on the reserve assets held in custody, in particular in the event of insolvency; | ||
| (h) ensure that the reserve of assets is composed and managed in such a way that— | ||
| (i) the risks associated to the assets referenced by the stablecoins are covered | ||
| (ii) the liquidity risks associated to the permanent rights of redemption of the holders are addressed; | ||
| (iii) ensure that the reserve of assets is legally segregated from the issuers’ estate, as well as from the reserve of assets of other stablecoins, in the interests of the holders of stablecoins, so that creditors of the issuers have no recourse to the reserve of assets, in the event of insolvency. (2) Stablecoin issuers that offer two or more stablecoins to the public shall operate and maintain segregated pools of reserves of assets for each stablecoin and each of those pools of reserves of assets shall be managed separately. | ||
| (3) A stablecoin issuer shall ensure that the issuance and redemption of stablecoins is always matched by a corresponding increase or decrease in the value of the reserve assets. | ||
| Regulation 73 | (1) Stablecoin issuers shall establish, maintain and implement custody policies, procedures and contractual arrangements that ensure at all times that— | This regulation’s requirement of CBK-approved custodians places reserve custody under the central bank's supervisory umbrella. |
| (a) the reserve assets are not encumbered nor pledged as a financial collateral arrangement; | ||
| (b) the reserve assets are held in custody in accordance with these Regulations; | ||
| (c) they have prompt access to the reserve assets to meet any requests for redemption from the holders of stablecoins; | ||
| (d) concentrations of the custodians of reserve assets are avoided; | ||
| (e) risk of concentration of reserve assets is avoided. | ||
| (2) The reserve assets shall be held in custody by a custodian approved by the Central Bank of Kenya. | ||
| (3) Issuers of stablecoins shall ensure that the reserve assets held in custody are protected against claims of the custodians’ creditors. | ||
| Regulation 74 | (1) Stablecoin issuers shall ensure that funds received by in exchange for stablecoins shall comply with the following— | The requirement for a significant portion of reserves to be held in local commercial banks promotes the local financial sector development ensuring that the backing is within the jurisdiction of the relevant regulatory authorities. The requirement to match the reserve currency to the reference currency is a critical to eliminate currency mismatch risk, which has been a source of instability in past crypto-asset collapses. |
| (a) at least 30 percent of the funds received is held in accounts in commercial banks in Kenya segregated for processing funds related to the issuance and redemption of stablecoin; | ||
| (b) the remaining funds received are invested in secure, low-risk assets in Kenya that qualify as high-quality liquid assets with minimal market risk, credit risk and concentration risk; and | ||
| (c) for fiat-referenced stablecoin, the reserve assets should be denominated in the same 63 official currency as the one referenced by the fiat-referenced stablecoin. | ||
| (2) The financial instruments in which the reserve of assets is invested shall be held in custody. | ||
| (3) All profits or losses, including fluctuations in the value of the financial instruments referred to in sub regulations (1), and any counterparty or operational risks that result from the investment of the reserve of assets shall be borne by the stablecoin issuer. | ||
| Regulation 75 | (1) Stablecoin issuers shall in a clear, accurate and transparent manner disclose, in a publicly and easily accessible place on their website, the amount of stablecoins in circulation, and the value and composition of the reserve of assets and such information shall be updated at least monthly. | This regulation requires monthly reserve disclosure which is a good transparency requirement. The requirement for prompt disclosure of significant events ensures holders are not trading on outdated information. |
| (2) Stablecoin issuers shall publish as soon as possible in a publicly and easily accessible place on their website a brief, clear, accurate and transparent summary of the audit report, as well as the full and unredacted audit report, in relation to the reserve of assets. | ||
| (3) Stablecoin issuers shall as soon as possible and in a clear, accurate and transparent manner disclose, in a publicly and easily accessible place, on their website any event that has or is likely to have a significant effect on the value of the stablecoins or on the reserve of assets. | ||
| Regulation 76 | (1) Stablecoin issuers shall implement and maintain effective policies and procedures to identify, prevent, manage and disclose conflicts of interest between themselves and— | This regulation contains a comprehensive conflict management framework. The proposal for website disclosure will enable holders to assess potential biases before investing. |
| (a) their shareholders or members; | ||
| (b) any shareholder or member, whether direct or indirect, that has a qualifying holding in the issuers; | ||
| (c) the members of their management body; | ||
| (d) their employees; | ||
| (e) the holders of stablecoin; | ||
| (f) any third-party providing services to the stablecoin issuer. | ||
| (2) Stablecoin issuers shall take all appropriate steps to identify, prevent, manage and disclose conflicts of interest arising from the management and investment of the reserve of assets referred. | ||
| (3) Stablecoin issuers shall, in a prominent place on their website, disclose to the holders of their stablecoins the general nature and sources of conflicts of interest referred to in sub-regulation (1) and the steps taken to mitigate them. Redemption of stablecoins | ||
| (4) The disclosure referred to in sub regulation (3) shall be sufficiently precise to enable the prospective holders of their stablecoin to make an informed purchasing decision about the stablecoin. | ||
| Regulation 77 | (1) Redemption of stablecoins shall be subject to the stablecoin issuer’s terms and conditions as approved by relevant regulatory authority. | This regulation’s provision mandating a Kenya Shilling redemption option where payment was accepted in Kenya Shillings is a consumer protection policy. This will help prevent currency conversion costs being passed to redeemers. The redemption of stablecoins not being subjected to a fee is arguably unfair given that conventional PSPs providing wallets such as M Pesa and Airtel Money are permitted to charge withdrawal fees. |
| (2) Stablecoin issuers shall establish a policy on consumers’ right of redemption setting out— | ||
| (a) the conditions, including thresholds, periods and timeframes, for holders of stablecoins to exercise such right of redemption; | ||
| (b) the mechanisms and procedures to ensure the redemption of the stablecoin; | ||
| (c) the valuation, or the principles of valuation, of the stablecoin and of the reserve assets when the right of redemption is exercised by the holder of stablecoin; | ||
| (d) the conditions for settlement of the redemption; | ||
| (e) measures that the stablecoin issuer takes to adequately manage increases or decreases in the reserve of assets in order to avoid any adverse impacts on the market of the reserve assets. | ||
| (3) Where a stablecoin issuer, when selling a stablecoin, accepts payment in the Kenya Shilling, they shall always provide an option to redeem the stablecoin in the Kenya Shilling. | ||
| (4) The redemption policies referred to in sub regulation (2) shall — | ||
| (a) be clear and conspicuous; | ||
| (b) confer on any holder of a stablecoin, a right to redeem units of the stablecoin from the issuer on demand at par value of the underlying unit of the currency; | ||
| (c) clearly disclose the meaning, timing and conditions of redemption. | ||
| (5) Upon request by a holder of a stablecoin, a stablecoin issuer shall redeem by paying an amount in fiat, equivalent to the market value of the stablecoin. | ||
| (6) The redemption of stablecoins shall not be subject to a fee. | ||
| (7) The business continuity plan of a stablecoin issuer shall include measures by the stablecoin issuer to restore compliance with the requirements applicable to the reserve of assets in cases where the issuer fails to comply with those requirements. | ||
| Regulation 78 | (1) Marketing communications relating to an offer to the public of a stablecoin, or to the admission to trading of such stablecoin, shall comply with all the following requirements— | This regulation aligns with marketing rules with traditional financial services standards. The prohibition on pre-white paper marketing prevents unsubstantiated promotion. We propose that for purposes of clarity marketing sounding to be differentiated from advertising and marketing under sub regulation 5. |
| (a) the marketing communications are clearly identifiable as such; | ||
| (b) the information in the marketing communications is fair, clear and not misleading; | ||
| (c) the information in the marketing communications is consistent with the information in the virtual asset white paper; | ||
| (d) the marketing communications clearly state that a virtual asset white paper has been published and clearly indicate the address of the website of the issuer of the stablecoin, a telephone number, and an email address to contact the issuer. | ||
| (2) Marketing communications shall contain a clear and unambiguous statement that the holders of the stablecoin have a right of redemption against the issuer at any time and at par value. Audits, review and reports. | ||
| (3) Marketing communications and any modifications thereto shall be published on the issuer’s website. | ||
| (4) Marketing communications shall be notified to the relevant regulatory authority upon request. | ||
| (5) No marketing communications shall be disseminated prior to the publication of the virtual asset white paper, but such restriction does not affect the ability of the issuer of the stablecoin to conduct market soundings. | ||
| Regulation 79 | (1) The issuer of a stablecoin shall appoint an approved auditor to— | The monthly reserve examinations with a ten (10) day reporting window provide near real-time assurance of reserve adequacy. This is exceptionally rigorous and appropriate given the systemic importance of stablecoins. |
| (a) conduct an annual review of its systems, process and procedures and other internal controls with respect to its compliance with the requirements of these Regulations; | ||
| (b) on a monthly basis, conduct an examination of the issuer’s reserve assets with respect to its compliance with these Regulations and provide a proof of reserve report by an independent approved auditor to the relevant regulatory authority within ten days of the start of the following month; (c) conduct, on an annual basis, a review of the issuer's— | ||
| (i) redemption policies to determine whether the policies meet the requirements of these Regulations; and | ||
| (ii) compliance with its redemption policies. | ||
| Regulation 80 | (1) The relevant regulatory authority may, prohibit or otherwise limit the issuance or use of a stablecoin before or after an issuer which has been approved in accordance with regulation 5, and may require that any such issuer delist, halt, or otherwise limit or curtail activity with respect to such stablecoin. | This regulation is a necessary safety valve allowing the regulator to act decisively where a stablecoin poses risks to consumers or financial stability. |
| Regulation 81 | (1) Issuers of stablecoins shall report on a monthly basis to the relevant regulatory authority the following information— | This regulation provides for a daily transaction reporting which is a very high frequency requirement that will provide the relevant regulatory authority with exceptional visibility into stablecoin activity. |
| (a) the number of holders; | ||
| (b) the value, circulation and peak values of the stablecoins; | ||
| (c) the average number and average aggregate value of transactions per day during the relevant quarter; | ||
| (d) the number of consumers and new account holders; | ||
| (e) the composition of reserve assets in respect of the stablecoin; and | ||
| (f) instances of de-pegging of the stablecoin. | ||
| (2) In addition to the reports under sub regulation (1), a licensee shall, on daily basis, report average number and average aggregate value of transactions per day. | ||
| PART IX – CAPITAL AND FINANCIAL REQUIREMENTS | ||
| Regulation 82 | (1) A licensee shall, at all times, have capital and other financial requirements of such nature and amount that is commensurate to the scale, risk and the complexity of the licensee based on its authorised activities. | This regulation links capital requirements to the risk profile of the business. The requirement in sub regulation (11) to maintain shareholder funds above the paid-up capital minimum acts as a buffer, requiring the licensee to maintain a financial cushion before it hits the regulatory minimum, thereby providing an early warning of financial distress. |
| (2) In determining whether a licensee has adequate capital and other financial requirements under sub regulation (1), the relevant regulatory authority, where applicable, shall establish the ability of the licensee to have— | ||
| (a) and maintain the paid-up capital and liquid capital at the amount specified in the Fifth Schedule; | ||
| (b) a proper accounting record framework established, documented and maintained; | ||
| (c) adequate financial reporting mechanisms; | ||
| (d) and maintain the required insurance coverage. | ||
| (3) A licensee shall, at the time of licensing and at all times thereafter, maintain core capital of not less than the paid-up capital prescribed in the Fifth Schedule to these Regulations. | ||
| (4) The issued share capital shall be regarded as paid up only where— | ||
| (a) the consideration has been received in cash; or | ||
| (b) the consideration has been received in other acceptable consideration approved by the relevant regulatory authority, which shall be capable of objective valuation and immediate realization. | ||
| (5) The following shall not constitute paid-up capital for the purposes of this regulation— | ||
| (a) unpaid, partly paid or contingent capital 70 commitments; (b) shareholder loans or advances; | ||
| (c) capital raised through borrowed funds, whether directly or indirectly; or | ||
| (d) revaluation reserves or internally generated intangible assets. | ||
| (6) Where a licensee intends to or has been authorised to carry out more than one virtual asset service, the licensee shall hold the amount of paid-up capital under this regulation for each licensed activity. | ||
| (7) The relevant regulatory authority may require a licensee to increase the paid-up capital under this regulation, as it may deem necessary, depending on the risk profile of the virtual asset service. | ||
| (8) The core capital maintained under these Regulations shall be unencumbered and shall not be— | ||
| (a) pledged, charged, or otherwise subjected to any form of security; | ||
| (b) subject to any contractual or legal restriction that impairs its availability to absorb loss; or | ||
| (c) repayable, redeemable or callable at the initiative of any shareholder or third party. | ||
| (9) The relevant regulatory authority may require a licensee to furnish evidence that its core capital is free from any encumbrance or obligation. | ||
| (10) A licensee shall ensure that its core capital does not fall below the prescribed minimum at any time. | ||
| (11) A licensee shall ensure that its shareholder funds does not fall below the prescribed minimum paid-up capital at all times. | ||
| (12) A licensee shall at all times ensure that it maintains adequate liquid capital as prescribed in the Fifth Schedule. | ||
| (13) Where the core capital of a licensee falls, or is likely to fall, below the prescribed minimum, the licensee shall— | ||
| (a) immediately notify the relevant regulatory authority, in writing; and | ||
| (b) submit a remedial capital restoration plan for approval by the relevant regulatory authority. | ||
| (14) The relevant regulatory authority may impose such enforcement actions as it considers appropriate where a licensee fails to comply with the capital adequacy requirements under these Regulations. | ||
| Regulation 83 | A licensee shall not engage in any arrangement or transaction the effect of which is to temporarily inflate or misrepresent its capital position for purposes of meeting the requirements of this Act. | This regulation promotes integrity safeguards that prevents cosmetic compliance. |
| Regulation 84 | (1) A virtual asset manager shall maintain, at all times, sufficient risk-based capital to cover operational and technology-related risks, in accordance with the guidelines issued by the relevant regulatory authority. | The ten percent (10%) limit on related party investments is a prudent concentration risk control. The requirement of a licensed Kenyan custodian for consumer funds ensures local regulatory oversight. |
| (2) A virtual asset manager managing consumer funds shall appoint a custodian licenced in Kenya to safeguard the funds. | ||
| (3) Where a virtual asset manager invests in or through a related company, that investment shall not exceed ten percent of the value of the total virtual assets under management, unless otherwise approved by the relevant regulatory authority. | ||
| (4) For purposes of this sub regulation (3), a “related company” means a holding company, subsidiary, or any entity under common control or substantially of the same shareholders. | ||
| Regulation 85 | (1) A licensee shall hold and maintain an insurance coverage allowing for the necessary protection and coverage of consumers’ virtual assets, that is commensurate with the level of risks and the scale of the proposed virtual asset service. | Mandating insurance is a consumer protection measure, especially for custody and exchange services where the risk of loss due to theft, hacking, or operational failure is high. The provision allowing for an alternative means of coverage is pragmatic, recognizing that the insurance market for virtual assets is still evolving. The requirement that group-level insurance explicitly covers the Kenyan licensee is necessary to ensure the protection is direct and enforceable. |
| (2) Where the licensee has demonstrated that it has exhausted all means in obtaining the insurance coverage under sub regulation (1), the licensee shall submit, for approval to the relevant regulatory authority, a proposal in respect of an alternative means of insurance coverage to address the level of risks and the scale of the proposed business. | ||
| (3) All insurance policies shall be held and maintained with an insurer licensed in Kenya or an insurer in a jurisdiction outside of Kenya which has been approved by the relevant regulatory authority. | ||
| (4) The insurance policies may be held in the name of Accounting records. another entity within the licensee’s group provided that the relevant insurance policy— | ||
| (a) explicitly states that the licensee is an insured party; and (b) states the nature and the level of cover applicable to the licensee. | ||
| (5) A licensee shall maintain appropriate insurance cover against cyber security risks including theft, loss of keys, or operational failure. | ||
| Regulation 86 | (1) A licensee shall keep accurate accounting records which are able to show and explain its transactions, whether are effected on its own behalf or on behalf of the consumers and that— | This regulation proposes comprehensive record-keeping. The distinction between records for the licensee's own account and those for others is essential for segregation and auditability. |
| (a) disclose with reasonable accuracy, at any time, the financial position of the licensee at that time; and | ||
| (b) enable the licensee to prepare a statement of comprehensive income and statement of the financial position as at any time and which comply with the requirements of these Regulations; | ||
| (2) The accounting records shall, in particular, contain— | ||
| (a) entries from day to day of all sums of monies and virtual assets, including initial coin offerings, received, exchanged, sold, transferred and held in custody; | ||
| (b) details on administrative expenditures, receipts of commissions and charges imposed for transactions by the licensee; | ||
| (c) a record of all assets and liabilities of the licensee including any commitments or contingent liabilities; | ||
| (d) entries from day-to-day transactions of all virtual assets, including initial coin offerings, distinguishing those which are made by the licensee on its own account and those which are made by and on behalf of others; | ||
| (e) entries from day-to-day of all consumers' monies, virtual assets, initial coin offerings which is paid into or out of a consumer's bank account or consumer's virtual asset, initial coin offerings and initial coin offerings account or any wallet; | ||
| (f) record of balances on consumer's account. | ||
| (3) The accounting records that a licensee are required to keep shall conform to the requirements of international accounting standards. | ||
| (4) A licensee shall preserve, in original digital form, the accounting records that is required to be kept under this regulation for at least seven years from the date of completion of the transactions or operations to which they each relate. | ||
| (5) The accounting records which are required to be kept under this regulation shall, at any time during the period in which they are required to be preserved, be produced for inspection to the relevant regulatory authority, or any person authorised by the relevant regulatory authority to receive the records, on demand at a reasonable time and place as may be specified by the relevant regulatory authority or the authorised person. | ||
| Regulation 87 | (1) A licensee shall, with the approval of the relevant regulatory authority, appoint an external auditor who shall be a member of good standing of the Institute of Certified Public Accountants of Kenya to carry out an audit of the transactions in its business. | The regulation establishes a framework for the appointment, approval, and oversight of external auditors for virtual asset service providers. The structure is logical, progressing from appointment requirements through regulatory powers to tenure limitations and removal provisions. |
| (2) The relevant regulatory authority may require an auditor appointed under sub regulation (1) to— | ||
| (a) submit to the relevant regulatory authority such information or report as the relevant regulatory authority may require in relation to the audit carried out by the auditor; | ||
| (b) extend the scope of an audit of the business and affairs of the business of the virtual asset service provider and to submit a report to the relevant regulatory authority; and | ||
| (c) carry out any examination or establish any procedure in any particular case. | ||
| (3) A person appointed as an auditor under this regulation shall be appointed annually and may serve for a maximum period of four consecutive financial years. | ||
| (4) The relevant regulatory authority may decline to approve, or revoke the appointment of an external auditor, if the external auditor has contravened the provisions of the Act and guidelines or circulars issued by the relevant regulatory authority. | ||
| Regulation 88 | Where the auditor's report is qualified on the grounds of the auditor's uncertainty as to the completeness or accuracy of the accounting records under regulation 86, the auditor shall, as soon as is practicable and in any event within seven days, report it in writing to the relevant regulatory authority and the licensee. | A short, mandatory reporting window for qualifications ensures the regulator is promptly alerted to potential record-keeping failures. |
| Regulation 89 | Every licensee shall submit to the relevant 74 regulatory authority— | The standard financial reporting requirements is aligned with traditional financial services. The twenty-one (21) day window for semi annual reports is appropriate. |
| (a) semi-annual financial statements within one month after the end of the half year period; | ||
| (b) monthly financial statements within fifteen days from the end of the month; | ||
| (c) monthly and annual periodic capital adequacy or liquidity statements; | ||
| (d) audited annual financial statements within three months after the end of the financial year; Reports by virtual asset exchange and token issuance platform provider. | ||
| (e) promptly disclose any event that could materially affect solvency, valuation of virtual assets or consumer protection. | ||
| Regulation 90 | Each virtual asset exchange or token issuance platform provider shall submit a monthly report to the relevant regulatory authority which shall include— | The requirement to report on market surveillance activities is unique and valuable, it forces licensees to proactively monitor misconduct and report on their efforts, not just raw data. |
| (a) a summary of all virtual assets listed, suspended, or delisted during the financial year; | ||
| (b) aggregate trading volumes and values; | ||
| (c) fiat and virtual assets; | ||
| (d) daily electronic trading reports, including transaction volumes and price movements; | ||
| (e) quarterly reports of all transactions, including off-platform trades and transfers; | ||
| (f) Reports by virtual asset managers. an annual audited financial statement prepared in accordance with applicable accounting standards. | ||
| Regulation 91 | Every licensee undertaking virtual asset management shall submit the relevant regulatory authority— | This regulation distinguishes between the manager's own financial statements and statements of assets under management. |
| (a) quarterly reports of assets under management by virtual asset managers within 21 days from the end of the quarter; | ||
| (b) semi-annual financial statements of assets under management; | ||
| (c) audited financial statements of assets under management. | ||
| Regulations 92 | The financial year of every licensed person shall be the period of twelve months ending on the 31st December in each year. | This clause standardises the financial year for all licensees to a twelve-month period ending 31st December. |
| Capital Requirements, Misrepresentation, Virtual Asset Manager Capital, Insurance, Accounting Records, External Auditor, Reports, Financial Year | ||
| PART X – CYBER SECURITY MEASURES, SYSTEMS AND CONTROL | ||
| Regulations 93 | (1) Pursuant to section 28(1) of the Act, a licensee shall have in place cyber security measures for the establishment and maintenance of appropriate systems and controls for managing cyber security and operational risks that may arise from inadequacies or failures in its processes and systems. | This regulation mandates a formal, top-down approach to cybersecurity, which is essential in this sector. The requirement for senior officers oversight with clearly defined roles ensures accountability at the management level. The requirement for periodic review and training helps ensure that security measures evolve with the threat landscape. |
| Cybersecurity Strategy, Systems and Control, Cyber Security Audit, Reporting of Cyber Security Risk, Audit Report | (2) In giving effect to the provisions in subregulation (1), a licensee shall— | |
| (a) have in place organisational, human and technological resources to prevent system and process failures or in the event of such a failure, to identify them and undertake the necessary steps for prompt rectification; | ||
| (b) ensure that it has in place arrangements for the continuity of operations in the event that a significant process or system becomes unavailable or is destroyed; and | ||
| (c) ensure adequate monitoring mechanisms are in place to quickly detect and prevent cyber incidents and periodically evaluate the effectiveness of systems and controls. | ||
| (3) Furtherance to the requirements provided for under sub regulation (2), a licensee shall— | ||
| (a) ensure that there is adequate senior officers oversight over its cyber security systems with clearly defined roles, responsibilities and accountability for staff implementing, managing and overseeing the effectiveness of the licensee's cyber security strategy and policy; | ||
| (b) ensure that the documentation of its internal processes and systems is maintained and distributed in managing operational and cyber security risk; and | ||
| (c) ensure that all staff receive appropriate training in relation to cyber security on a periodic basis. | ||
| (4) A licensee shall review its cyber security strategy and policy regularly, and at least annually, in response to changes in cyber security risks, as well as in response to a cyber security incident or to any issues or weaknesses identified specific to the licensee operation. | ||
| (5) Further to sub regulation (4), the licensee shall submit the results of its review of the cyber security strategy and policy, and any remedial actions needed, to its board of directors as soon as practicable and, in any event, no later than one month after the date of the review. | ||
| (6) Where a person acts in contravention of this regulation, the relevant regulatory authority shall take such enforcement action as it deems necessary under the Act, and may impose an administrative penalty of three million shillings. | ||
| Regulation 94 | (1) A licensee shall at all times ensure that its systems and controls are adequate and suitable for the performance of a virtual asset business and appropriate to the size and nature of its operations. | The specific requirement for regular vulnerability assessments and penetration testing is a critical technical control. The increased frequency in the first year is a sensible approach, reflecting the higher risk profile of newly licensed entities. Further, the requirement for audit trail systems to track and maintain information to allow for complete and accurate reconstruction of all financial transactions is a cornerstone of effective oversight and forensic investigation. |
| (2) The systems and controls in sub regulation (1) shall be in relation to the— | ||
| (a) transmission of information to purchasers and consumers using its distributed ledger technology platform; | ||
| (b) assessment and management of risks; | ||
| (c) safeguarding and administration of assets which belong to purchasers or its consumers; and | ||
| (d) the fitness and propriety of its employees and the adequacy of the technology resources. | ||
| (3) In maintaining appropriate systems and controls under sub regulation (1) and (2), a licensee shall have regard to— | ||
| (a) confidentiality, including the safe storage of information and transmission of data in accordance with clear protocols, which may require firewalls within a system, as well as entry restrictions and compliance with relevant data protection laws; | ||
| (b) accessibility of the system to authorized persons, employees of the licensee and as the case maybe, to authorized employees of the relevant regulatory authority; | ||
| (c) integrity, including safeguarding the accuracy and completeness of information and data through its system and control; | ||
| (d) maintenance of systems and infrastructure, including proper code version control, implementation of updates and resolution; | ||
| (e) procedures to address updates to technological infrastructure, including forks. | ||
| (4) The systems and control of a licensee shall include the following audit functions — | ||
| (a) vulnerability assessment, risk assessment and penetration testing of those systems conducted on a bi-annual basis during the first year of 78 licensing and at least once a year for subsequent years; | ||
| (b) audit trail systems that — | ||
| (i) track and maintain information and data that allows for the complete and accurate reconstruction of all financial transactions and accounting; | ||
| (ii) protect the integrity of data stored and maintained as a part of the audit trail from alteration or tampering; | ||
| (iii)protect the integrity of hardware from alteration or tampering, including by limiting electronic and physical access permissions to hardware and maintaining logs of physical access to hardware that allows for event reconstruction; | ||
| (iv) log system events, including but not limited to access and alterations made to the audit trail systems and cyber security events; | ||
| (v) maintain records produced as part of the audit trail; | ||
| (vi) the effectiveness of the safe keeping, storage and accessibility of the virtual assets being kept by the licensee. | ||
| (5) Subject to the approval of the relevant regulatory authority, a licensee shall appoint a qualified independent party to audit its systems and control, as and when may be required by the relevant regulatory authority, and provide a written opinion to the relevant regulatory authority that the licensee's program and controls are suitably designed and operating effectively to meet the licensee's obligations under these Regulations. | ||
| (6) Further to sub regulation (5), in making an appointment, a licensee shall consider and state in the resolution making the appointment whether the independent party conducting the audit, as the case may be— | ||
| (a) holds the required qualifications and competence, has proven experience and adequate resources to perform the appointee’s functions; and | ||
| (b) is independent of the licensee in that the appointee or, in the case of a firm, any of its partners has no relationship with, or interest in, the licensee, any of its group of companies, nor has any connection with any director or substantial shareholder of the licensee that could reasonably be perceived as materially affecting the exercise by the appointee of an independent mind and judgement in the performance of the appointee's duties. | ||
| (7) A licensee shall carry out regular reviews of its systems and control. | ||
| (8) Where a person acts in contravention of sub regulations (2) and (3), the relevant regulatory authority may impose an administrative penalty — | ||
| (a) in the case of an individual, a fine not exceeding three million shillings; or | ||
| (b) in the case of a company, a fine not exceeding ten million shillings. | ||
| Regulation 95 | (1) The relevant regulatory authority may at any time— | This regulation grants the relevant regulatory authority broad powers to commission audits, call for investigations, and conduct inspections related to cybersecurity and general compliance. The structure is straightforward, with sub regulation (1) addressing the power to initiate audits or investigations, and sub regulation (2) addressing specific inspection powers. |
| (a) commission an audit of a licensee; or | ||
| (b) call for an investigation of the licensee. | ||
| (2) The relevant regulatory authority may— | ||
| (a) require an officer of the licensee to produce or furnish to the relevant regulatory authority officer making an examination, within a reasonable time— | ||
| (i) such books of accounts and any other documents in the custody or power of the licensee; or | ||
| (ii) statements or information relating to the affairs of the licensee as may be required by the examining officer; | ||
| (b) at any time, enter any premises where a licensee is carrying on virtual asset business, or any premises where the relevant regulatory authority reasonably suspects that any virtual asset business is carried out in contravention of these Regulations. | ||
| Regulation 96 | (1) Where the licensee discovers a cyber security risk as a result of a cyber security event, it shall notify the relevant regulatory authority of any attempt within twenty-four hours. | The proposal for the twenty-four ( 24) hour notification for attempts is rapid, enabling near real-time threat awareness across the sector. Further, the distinction between attempts and successful events is practical. |
| (2) Further to subsection (1), for any successful attempt, the licensee shall provide a report within five working days on whether the cyber security incident — | ||
| (a) affects or has affected the services or network and information systems that support critical or important functions of the licensee; | ||
| (b) affects or has affected services for which the licensee has been authorized to provide; | ||
| (c) constitutes or has constituted a malicious and unauthorized access to the network and information systems of the licensee. | ||
| (3) The report under subsection (2) shall include the remedial actions to mitigate cyber security incident and prevent future cyber security event. | ||
| (4) A virtual asset wallet provider shall report any material cybersecurity incident, loss of keys, or unauthorised transaction within 24 hours and shall maintain appropriate insurance cover against theft, loss of keys, or operational failure. | ||
| Regulation 97 | (1) A cyber security audit report shall be duly prepared by the fit and proper person responsible for information security, containing— | This regulation requires not just identification of issues but also proposed corrective steps, ensuring the audit drives improvement. |
| (a) the functionality and integrity of the licensee's electronic systems; | ||
| (b) any identified cyber security risk arising from any virtual asset service carried on or to be carried on, by the licensee; and | ||
| (c) the cyber security program implemented and proposals for steps for the redress of any inadequacies identified. | ||
| (2) Where a person acts in contravention of this regulation, the relevant regulatory authority shall take such enforcement action as it deems necessary under the Act and may impose an administrative penalty of three million shillings. | ||
| PART XI – SAFEKEEPING AND MANAGEMENT OF CONSUMER'S ASSETS | ||
| Regulation 98 | Where a distributed ledger technology platform provides for the safeguarding and administration of assets which belong to purchasers and consumers, and in pursuant to section 31 of the Act, a licensee shall ensure that— | This regulation cross-references section 31 of the Act, establishing the foundational requirement for asset safeguarding arrangements. |
| (a) satisfactory arrangements are made for that purpose; and | ||
| (b) clear terms of agreement exist between the consumers and the licensee in relation to the virtual asset. | ||
| Regulation 99 | (1) A licensee shall at all times provide safeguards to ensure consumer protection to such standard as the relevant regulatory authority may determine. | This regulation has a comprehensive consumer protection framework. We propose that the regulation differentiate between retail and professional investors so that commensurate levels of consumer protection safeguards are implemented. |
| (2) Without derogating from the generality of sub regulation (1), a licensee shall have business rules, procedures and an effective surveillance programme that ensure that a virtual asset business conducted on or through its distributed ledger technology platform or trading systems is conducted in an orderly manner to provide proper protection to consumers, including monitoring for conduct which may amount to market abuse, financial crime, money laundering, terrorism financing or proliferation financing. | ||
| (3) In furtherance of the duty to protect the consumers assets under sub regulation (1), a licensee shall— | ||
| (a) establish policies, systems and controls for the safekeeping and management of consumer assets; | ||
| (b) make adequate arrangements to safeguard consumers' ownership rights, mitigate the risk of loss or diminution on the value of consumers’ assets; | ||
| (c) and establish and maintain adequate organizational arrangements for transfer of consumer assets. | ||
| (4) A licensee shall, as part of its policies, procedures and controls for the safekeeping and management of consumer assets, including the reconciliation of consumer assets, specify how consumer assets are protected against loss or misuse and how consumer assets are segregated so that they are not subject to the claims of the licensee's creditors as envisaged under section 31(d) of the Act. | ||
| (5) A licensee shall make the policies referred to in sub regulation (3)(a) available in summarized form to its consumers in electronic format, upon request, no later than 2 working days from the date of receipt of the request. | ||
| (6) A licensee who contravenes this regulation shall be subjected to enforcement action as it deems necessary under the Act, and the relevant regulatory authority may impose an administrative penalty not exceeding three million shillings. | ||
| Regulations 100 | (1) A licensee shall— | This regulation mandates a formal, written agreement with extensive required terms. This professionalizes customer relationships and ensures consumers understand their rights and obligations |
| Safeguarding Strategy, Consumer Protection, Consumer Service Agreement, Management of Consumer Funds, Systems and Controls, Protection from Third Party Claims, Records and Accounts | (a) enter into a consumer service agreement with every consumer to which it renders services; | |
| (b) submit to the relevant regulatory authority a copy of the standard consumer service agreement applicable to each service offered to the public; | ||
| (c) in the event of handling a dormant account comply with the provisions of Unclaimed Financial Assets Act; and | ||
| (d) in the case of a deceased persons' account, comply with the Law of Succession Act. | ||
| (2) A consumer service agreement under sub regulation (1)(a) shall, at minimum include— | ||
| (a) a detailed description of the virtual asset services offered; | ||
| (b) the registration requirements for account opening; | ||
| (c) the procedures for maintaining a consumer account; | ||
| (d) the privacy policy of the licensee; | ||
| (e) the consumer account use and access responsibility; | ||
| (f) the suspension, termination and freezing of accounts; | ||
| (g) the dispute resolution and the governing law; | ||
| (h) the warranties and liability; | ||
| (i) the indemnity; the exclusions or limitations of the virtual asset service; | ||
| (k) disclosure and data retention; | ||
| (l) force majeure; | ||
| (m) details on how dormant accounts are handled; and | ||
| (n) details on how accounts of deceased persons are handled. | ||
| Regulation 101 | (1) Pursuant to section 24(h) of the Act, a licensee shall open and operate all client account and licensees own accounts in a bank licensed in Kenya. | The requirement to hold client accounts in a bank licensed in Kenya ensures that a core part of the business is under the direct oversight of the Central Bank of Kenya. The absolute prohibition on using consumer assets for the licensee's own account is a reasonable safeguard. The requirement to deposit consumer funds by the end of the business day on which they are received is a best practice operational standard. |
| (2) A licensee shall ensure that the total amount and type of consumer assets held for consumers matches the amounts it has agreed to hold. | ||
| (3) Any transfer undertaken of consumer assets shall be authorised or expressly permitted by the consumer. | ||
| (4) A licensee shall, following the day on which consumers' funds, other than consumer assets, are received, place those funds by the end of the business day, with a bank or financial institution in accordance with these Regulations. | ||
| (5) A licensee shall take all necessary measures to ensure that consumers’ funds, other than consumer assets, held in accordance with sub regulation (4), are held in an account separate to that which is used to hold funds belonging to the licensee. | ||
| (6) Where a licensee holds virtual assets — | ||
| (a) in one or more omnibus accounts; or; | ||
| (b) under any other arrangement where consumer assets are not held in separate accounts for each individual consumer’s name, consumer under that the licensee shall maintain appropriate procedures and up to-date records in order to identify, at all times, the virtual assets belonging to each consumer and to account for all consumer transactions. | ||
| (7) A licensee shall have adequate arrangements in place to safeguard the ownership rights of consumers over their consumer assets and prevent the use of those assets for their own account. | ||
| (8) A licensee shall not use consumer assets for its own account or the account of any other person or consumer of the licensee. | ||
| (9) A licensee shall take appropriate measures to prevent the unauthorized use of consumer assets for its own account or the account of any other person. | ||
| (10) A licensee shall have procedures in place to ensure that consumers have a means by which to access their consumer assets. Systems and controls to safe- keep consumer assets. | ||
| (11) Where a person acts in contravention with this regulation, the relevant regulatory authority shall take such enforcement action as it deems necessary under the Act and may impose an administrative penalty of not more than three million shillings | ||
| Regulation 102 | (1) A licensee shall ensure that technology used for the purpose of holding consumer assets is reliable, resilient and compatible with the consumer assets being held, where applicable. | This regulation recognizes that technology itself is a critical control point. Requiring consideration of wallet architecture and key security addresses the technical risks of virtual asset custody. |
| (2) A licensee, in complying with sub regulation (1) shall have regard to— | ||
| (a) the impact of the software architecture of the wallets used to hold consumer assets and the interoperability of systems used to hold them; and | ||
| (b) the systems’ ability to ensure that security measures for access and use of private and public keys, hot and cold wallets storage, password protection and encryption, are reliable and effective. | ||
| (3) Where a person acts in contravention with this regulation, the relevant regulatory authority shall take such enforcement action as it deems necessary under the Act and may impose an administrative penalty of three million shillings. | ||
| Regulation 103 | (1) A licensee shall not grant any security interest, lien or right of set-off to another person over any consumer assets unless it applies directly to the clearing or settlement of such obligations as owed directly by the consumer to whom such security interest, lien or right of set-off claim is against. | This regulation protects consumer assets from being used to satisfy claims against other consumers or the licensee itself. |
| (2) A licensee shall maintain records of any security interest, lien or right of set-off which it applies under sub regulation (1), including any court order, legal proceeding or similar records served upon the licensee, the amount and nature of the consumer assets and the date upon which the obligation was applied. | ||
| (3) Where a person acts in contravention with this regulation, the relevant regulatory authority shall take such enforcement action as it deems necessary under the Act and may impose an administrative penalty of three million shillings. | ||
| Regulation 104 | (1) In fulfilling its obligations under these Part, a licensee shall ensure that it maintains accurate and up to date records that are easily accessible by the consumer. | The consumer-by-consumer reconciliation using both on-chain and off-chain records is a standard that ensures alignment between internal records and distributed ledger reality. |
| (2) A licensee shall make accessible at its office a register and enter in it the following information as appropriate to the relevant consumer— | ||
| (a) the name of the consumer; | ||
| (b) the consumers’ rights to its assets; | ||
| (c) the any movement of consumer asset with reference to instructions received from the consumer. | ||
| (3) A licensee shall use the register referred to in sub regulation (2) to track, record transactions and ownership of consumer's assets and reconcile the consumer assets on 87 a consumer-by-consumer basis to resolve any discrepancies with consideration to be had to relevant off chain and on-chain records. | ||
| PART XII – MARKET CONDUCT AND RELATED OFFENCES | ||
| Regulations 105 | (1) A licensee shall, when conducting a licensed activity— | This regulation establishes conduct standards for licensees, setting the tone for expected behaviour in the virtual asset sector. The structure is logical, moving from general principles in sub regulation (1) to reporting obligations in sub regulation (2) and specific requirements in sub regulation (3). |
| Standards of Conduct, Designation, Consumer Risk Understanding, Complaints, Consumer Care System, Deterrence of Market Abuse, Outsourcing, Custodial Outsourcing, Agent Arrangements | (a) observe a high standard of integrity and fair dealing; | |
| (b) act with due skill, care and diligence; and | ||
| (c) observe high standards of market conduct. | ||
| (2) A licensee shall, from time to time, provide to the relevant regulatory authority details of how it promotes and maintains professional conduct as required under sections 20 and 21 of the Act. | ||
| (3) For purposes of sub regulation (2), a licensee shall— | ||
| (a) take all the necessary steps to promote and maintain high standards of integrity and fair dealing in the carrying on of a virtual asset business on or through its distributed ledger technology platform or trading systems; and | ||
| (b) cooperate with the relevant regulatory authority with regard to regulatory matters as the relevant determine. | ||
| Regulation 106 | (1) The relevant regulatory authority may, by notice, designate a virtual asset service for the purposes of the Act, if in its assessment— | This regulation seeks to identify market players that can have a significant impact on the market in case of downtime or any other systemic failure. This is comparable to “Designation of a Payment System” for PSPs pursuant to section 3 of the PSP Act. |
| (a) the virtual asset service poses systemic risk; | ||
| (b) the designation is necessary to protect the interests of the public; or | ||
| (c) such designation is in the interest of the integrity of the payment system. | ||
| (2) The notice issued under subsection (1) shall indicate the conditions to be met by the licensee. | ||
| (3) The relevant regulatory authority may, by notice, withdraw the designation or vary the conditions attached to the designation. | ||
| (4) Any person who fails to comply with a notice issued under this section shall be guilty of an offence under the Act. | ||
| Regulation 107 | (1) A licensee shall not— | This regulation codifies suitability obligations. The requirement to document explanations whether written or oral with written note, this creates an audit trail and protects both consumer and licensee. |
| (a) recommend a transaction to a consumer, or effect a transaction with or for him, unless it has taken all reasonable steps to enable the consumer to understand the risks involved; | ||
| (b) knowingly mislead a consumer on any advantages or disadvantages of a contemplated transaction; | ||
| (c) promise a return on any investment. | ||
| (2) A licensee shall give sufficient information to the consumer to ensure that the consumer’s decisions are informed. | ||
| (3) A licensee shall, when making recommendations to a consumer, take all reasonable steps to ensure that the consumer has a proper understanding of— | ||
| (a) the nature of the investment; | ||
| (b) the fees and charges associated with the investment; | ||
| (c) the risks of the investment; | ||
| (d) risks related to AML/CFT/CPF; | ||
| (e) the factors that are likely to affect the performance of the investment; | ||
| (f) the terms and conditions of the investment; | ||
| (g) the consequences of departing from the terms and conditions of the investment. | ||
| (4) Where a licensee— | ||
| (a) after giving a consumer an explanation, in writing, is satisfied that the consumer understands the information required to be given under sub regulation (3), the licensee shall retain a copy of such explanation in its records; | ||
| (b) gives an explanation orally, it shall send a written note of the advice to the consumer and retain a copy of the explanation in the consumer’s file; | ||
| (c) is of the opinion that an explanation is not required, because of the consumer’s existing knowledge, it shall document that opinion in its records. | ||
| Regulation 108 | (1) A licensee shall, to the satisfaction of the relevant regulatory authority, have in place procedures to address complaints by consumers of its distributed ledger technology platform. | This regulation provides for a seven (7) year complaint record retention which is a robust standard. Further, this regulation requires a register and consumer care system professionalizes complaint handling. |
| (2) The procedures referred to in sub regulation (1) shall include— | ||
| (a) effective arrangements for the investigation and resolution of complaints made against the licensee’s virtual asset services; | ||
| (b) establishing and maintaining a register of complaints made against the licensee’s virtual asset services and resolutions reached with the purchaser, consumer or consumer. | ||
| (c) establishing and maintaining a consumer care system in accordance with regulation; | ||
| (d) setting out the process for dealing with complaints, including– | ||
| (i) the apportionment of responsibility for the actions that led to the complaint including to persons not specifically named in the complaint; | ||
| (ii) the timeframe for dealing with a complaint; | ||
| (iii) the timeframe within which to inform the complainant of progress in dealing with the complaint, which shall not be more than three months; | ||
| (iv) the available remedial actions in respect of any complaints by the consumer; (v) the procedure for an appeal where the complaint cannot resolved. otherwise be (3) When addressing a complaint from a consumer, a licensee shall — | ||
| (a) disclose to a consumer its procedures for handling of complaints. | ||
| (b) address a complaint from a consumer in a fair, appropriate and timely manner; | ||
| (c) inform the consumer of the outcome of their complaint; (d) provide appropriate restitution and address the weaknesses in its internal systems that led to the action causing the complaint. | ||
| (4) A licensee shall keep and maintain the records of the complaints and action taken under this regulation for a minimum of seven years. | ||
| Regulation 109 | (1) Within six months after commencing the provision of virtual asset services, a licensee shall establish a consumer care system within which its consumers can make inquiries and complaints concerning its services. | This regulation provides for a six (6) month implementation window which recognizes that new licensees may need time to build out systems. The requirement for clear, accessible complaint information at all points of service is practical. |
| (2) Prior to establishing a consumer care system under sub regulation (1), the licensee shall— | ||
| (a) put in place a clear mechanism to address consumer complaints; | ||
| (b) provide adequate means for consumers to file complaints; | ||
| (c) address such complaints within a reasonable period from the time receipt of the complaint; and | ||
| (d) provide, at all points of service, easily understood information about their complaint handling procedure. | ||
| Regulation 110 | (1) A licensee shall have appropriate measures to identify, deter and prevent market abuse, financial crime and money laundering, terrorism financing or proliferation financing on and through its distributed ledger technology platform or systems and report to the relevant regulatory authority any market abuse. | This regulation provides for proactive deterrence obligations, not just reactive detection. Further, this regulation requires licensees to build market integrity into their systems from the outset. |
| (2) Pursuant to sub regulation (1), a licensee shall have rules and procedures to prohibit or prevent any— | ||
| (a) transaction intended to create a false appearance of a trading activity or transaction; | ||
| (b) improper execution of virtual asset transfer or exchange, stablecoin issuance, token issuance, or initial coin offering; | ||
| (c) transaction intended to assist or conceal any potentially identifiable market abuse or financial crime. | ||
| Regulation 111 | (1) A licensee may enter into an agreement to outsource its operational functions of provision of virtual asset services. | This regulation gives a thirty (30) day pre-approval requirement for outsourcing arrangements which may aid in preventing reactive approvals. |
| (2) A licensee who intends to outsource its functions under sub regulation (1) shall obtain the approval of the relevant regulatory authority at least thirty days before such outsourcing agreement is implemented. | ||
| (3) For the purposes of this regulation, a licensee shall not outsource its material operational function in such a way as to impair— | ||
| (a) the quality of internal control of the licensee; and | ||
| (b) the ability of the relevant regulatory authority to monitor compliance of the licensee with the Act and these Regulations. | ||
| (4) Where a licensee outsources a material operational function under this regulation, the licensee shall ensure that— | ||
| (a) the outsourcing does not result in the delegation by responsibilities; senior officers of its | ||
| (b) the relationship and obligations of the licensee to its consumers under this regulation is not altered; | ||
| (c) the outsourcing contract provides that the relevant regulatory authority can exercise its oversight and supervisory powers under this regulation in respect of the third parties to who functions are outsourced; and | ||
| (d) the requirements which the licensee is required to comply in order to be licensed and remain so, including any conditions imposed by the relevant regulatory authority are not undermined. | ||
| (5) For the purpose of sub regulation (3), an operational function shall be regarded as material if a defect or failure in its performance would materially impair— | ||
| (a) the continuing compliance of the licensee with the requirements of its licence under these Regulations; | ||
| (b) its financial performance; or | ||
| (c) the soundness or the continuity of its virtual asset services. | ||
| Regulation 112 | Where a virtual asset exchange outsources custodial services, it shall— | This regulation creates a closed loop for custody outsourcing to only licensed providers, this prevents regulatory arbitrage through outsourcing. |
| (a) only make use of licensed virtual asset wallet providers licensed under the Act; | ||
| (b) notify the regulatory authority of the use of other entities for the custody of virtual assets as a material change under section of the Act; | ||
| (c) disclose to their consumers the terms and conditions associated with such outsourcing arrangements. | ||
| Regulation 113 | (1) A licensee may appoint an agent to provide any of its services on its behalf by entering into an agency agreement: Provided that such services are approved by the relevant regulatory authority. | This regulation establishes principal agent liability which may prevent licensees from disclaiming responsibility for misconduct by agents. |
| (2) A licensee shall be liable to its consumers for the acts and omissions of its agent. | ||
| Regulations 114 | (1) A person who possesses material non-public information in relation to a virtual asset shall not use that information to acquire or dispose of that virtual asset, or attempt to do so, or encourage or cause another person to deal in that virtual asset. | The penalty of Kshs. ten million (10, 000, 000) or a fine of five (5) years imprisonment signals the seriousness with which such misconduct will be treated. |
| Market Conduct Offences: Insider Trading, Market Manipulation, False Trading and Market Rigging, Fraudulent Inducement, Manipulative Devices, False Statements, Front-Running, Churning, Cold Calling | (2) A person who contravenes the provisions of sub regulation (1) commits an offence and shall be liable, on conviction, to a fine not exceeding ten million or imprisonment for a term not exceeding five years, or to both. | |
| Regulation 115 | (1) No person shall enter into or carry out, directly or indirectly, two or more transactions in virtual assets, which by themselves or in conjunction with any other transaction— | This regulation prohibits market manipulation through transactions that artificially increase, reduce, or stabilize prices with the intent to induce others to trade. The structure is clear, with sub regulation (1) setting out the prohibited conduct and sub regulation (2) establishing the penalty. |
| (a) increase, or are likely to increase the price with the intention of inducing another person to purchase, or subscribe for, or to refrain from selling virtual assets issued by the same company or a related company, or such other listed virtual assets; | ||
| (b) reduce, or are likely to reduce, the price with the intention of inducing another person to sell, or to refrain from purchasing, virtual assets issued by the same company or a related company, or such other listed virtual assets; or | ||
| (c) stabilize, or are likely to stabilize, the price with the intention of inducing another person to sell, purchase, or subscribe for, or to refrain from selling, purchasing or subscribing for, virtual assets issued by the same company or by a related company, or such other listed virtual assets. | ||
| (2) A person who contravenes the provisions of sub regulation (1) commits an offence and shall be liable, on conviction, to a fine not exceeding ten million or imprisonment for a term not exceeding five years, or to both. | ||
| Regulation 116 | (1) A person shall not create or do anything which is intended or likely to create a false or misleading impression— | This regulation addresses wash trading and matched orders, common manipulation techniques in virtual asset markets. Further it provides consistent penalties for the same. |
| (a) of active trading in virtual assets on a virtual asset exchange or token issuance platform; or | ||
| (b) with respect to the market for, or the price for dealings in, virtual assets traded on the virtual assets exchange or token issuance platform. | ||
| (2) Without prejudice to the generality of sub regulation (1), a false or misleading impression of active trading in virtual assets is created if a person— | ||
| (a) enters into or carries out, directly or indirectly, any transaction for the sale or purchase of a virtual asset which does not involve a change in the beneficial ownership of the virtual asset, or offers to do so; or | ||
| (b) offers to sell a virtual asset at a price which is substantially the same as the price at which he has made or proposes to make, or knows that an associate of his has made or proposes to make an offer to buy the same or substantially the same number of virtual assets. | ||
| (3) A person who contravenes the provisions of sub regulation (1) commits an offence and shall be liable, on conviction, to a fine not exceeding ten million or imprisonment for a term not exceeding five years, or to both. | ||
| Regulation 117 | (1) A person shall not induce or attempts to induce another person to subscribe for, sell or purchase virtual assets by— (a) making or publishing any statement, promise or forecast that is false, misleading or deceptive; | This regulation captures fraudulent promotion and information manipulation. The inclusion of recording false information addresses technological means of deception. |
| (b) concealing any material facts; | ||
| (c) making or publishing any statement, promise or forecast which is misleading, false or deceptive; or | ||
| (d) recording or storing in, or by means of, any mechanical, electrical or other device, information that is false or misleading. | ||
| (2) A person who contravenes the provisions of sub regulation (1) commits an offence and shall be liable, on conviction, to a fine not exceeding ten million or imprisonment for a term not exceeding five years, or to both. | ||
| Regulation 118 | (1) A person shall not, directly or indirectly, in connection with any transaction with any other person involving the subscription, purchase or sale of virtual assets— | This regulation serves as a blanket clause capturing any fraudulent conduct not specifically enumerated elsewhere. |
| (a) uses any device, scheme or artifice to defraud the other person; | ||
| (b) engages in any act, practice or course of business which is fraudulent, deceptive or likely to defraud or deceive that other person | ||
| (c) makes any false statement in relation to a matter or omits to state a material fact that is necessary in order to make the statements made in the light of the circumstances under which they were made, not misleading. | ||
| (2) A person who contravenes the provisions of sub regulation (1) commits an offence and shall be liable, on conviction, to a fine not exceeding ten million or imprisonment for a term not exceeding five years, or to both. | ||
| Regulation 119 | No person shall, directly or indirectly, for the purpose of inducing the subscription for, sale or purchase of virtual assets by another person of any company, or of any other virtual assets, or to maintain, increase, reduce or stabilize the price of such virtual assets, makes with respect to the virtual assets— | This regulation is similar to Regulation 117 but focuses specifically on statements. The overlap between the two regulations provides multiple enforcement avenues. |
| (a) any statement which is, at the time and in light of the circumstances in which it is made, false or misleading with respect to any material fact and which that person knows or reasonably ought to know is false or misleading; or | ||
| (b) any statement which is, by reason of the omission of a material fact, rendered false or misleading and which that person knows or ought to know is rendered false or misleading by reason of omission of that fact. | ||
| (2) A person who contravenes the provisions of 97 sub regulation (1) commits an offence and shall be liable, on conviction, to a fine not exceeding ten million or imprisonment for a term not exceeding five years, or to both. | ||
| Regulation 120 | (1) No person who has insider information on consumer orders with a price differential, or is aware of such orders, shall effect an own account transaction in the virtual assets concerned or in any related investments directly or through any other person, to take advantage of the price differential before the consumer order is executed. | This regulation directly addresses front running which is a specific abuse of position by those with advance knowledge of customer orders. |
| (2) A person who contravenes or facilitates the contravention of the provisions of sub regulation (1) commits an offence and shall be liable, on conviction, to a fine not exceeding ten million or imprisonment for a term not exceeding five years, or to both. | ||
| Regulation 121 | A licensee shall not – | This regulation prohibits excessive trading to generate commissions. The reference to consumer's trading activities, investment objectives, size and operations" provides a contextual standard. |
| (a) deal or arrange a deal in the exercise of discretion for any consumer; or (b) advise a consumer to deal, if the dealing could in the circumstances be reasonably considered as too frequent or too large having regard to the trading activities, investment objectives, size and operations of such consumer. | ||
| (2) A person who contravenes or facilitates the contravention of the provisions of sub regulation (1) commits an offence and shall be liable, on conviction, to a fine not exceeding ten million or imprisonment for a term not exceeding five years, or to both. | ||
| Regulation 122 | A licensee shall not, for the purposes of soliciting business relating to a regulated activity, make unsolicited telephone calls or attend at any property, unless it has established and monitors the implementation of operational procedures to— (a) maintain a Do-Not-Call list of prospects that is updated whenever any contacted person requests not to be called again; | This regulation brings virtual asset sales practices under telemarketing regulations. The recording requirement is a strong accountability measure. |
| (b) train staff on the use of the Do-Not-Call list; | ||
| (c) limit the making calls to between 8 a.m. and 5 p.m.; | ||
| (d) oblige the callers to state their first and last names at the commencement of the call; | ||
| (e) oblige the callers to state the firm’s name and address and the fact that it is licensed by the relevant regulatory authority at the commencement of the call; | ||
| (f) oblige the caller to provide a detailed over view of any product being marketed by the licensee prior to soliciting any off; | ||
| (g) record and avail copies of all recordings to the relevant regulatory authority for inspection. | ||
| (2) A person who contravenes or facilitates the contravention of the provisions of sub regulation (1) commits an offence and shall be liable, on conviction, to a fine not exceeding ten million or imprisonment for a term not exceeding five years, or to both. | ||
| PART XIII – ADVERTISEMENTS AND PROMOTIONS OF VIRTUAL ASSETS AND PRODUCTS | ||
| Regulation 123 | (1) A person shall not carry on, or purport to carry on, the advertisement of— | This regulation ensures that all promotional activity is subject to the same standards, regardless of who carries it out. The principle of holding the licensee or promoter liable for agents prevents them from using third parties to circumvent the rules. |
| (a) virtual asset services; or | ||
| (b) the issue or the promotion of virtual assets, including initial coin offerings and non fungible tokens, in or from Kenya, unless that person complies with the requirements of these Regulations. | ||
| (2) These Regulations shall not apply to the following persons and activities — | ||
| (a) advertisement by ministry, department, authorities or agencies of the Government; | ||
| (b) persons engaged in the business of printing commercial and promotional materials for licensees or promoters; and (c) persons responsible for securing the placement of an advertisement: Provided they are not responsible for the contents thereof. | ||
| (3) Any person acting on behalf of a licensee or promoter shall comply with these Regulations, and the licensee or promoter shall be liable and responsible for such persons as if the licensee or promoter had undertaken the relevant advertising itself. | ||
| (4) A person who acts in contravention with this regulation commits an offence and is liable on conviction to a fine not exceeding three million shillings or one year imprisonment, or to both. | ||
| Regulation 124 | (1) Advertisements shall— | This regulation sets a high standard of integrity for marketing materials. The prohibition on using advertisements to lure or induce consumers into malicious virtual asset services and offerings is a necessary and important principle to combat scams and predatory schemes that have been prevalent in the industry. |
| (a) be fair, clear, complete, concise, unambiguous and unbiased, and shall not be false, misleading nor deceptive; (b) contain information that is timely and consistent with any relevant virtual assets, including initial coin offerings or virtual asset services; | ||
| (c) convey an equitable message in respect of the returns, benefits and risks associated with the relevant virtual asset, including initial coin offerings or virtual asset services; | ||
| (d) be clearly identifiable and the media chosen for an advertisement shall be suitable for that advertisement with due consideration as to the target market and or class of consumers; | ||
| (e) not lure or induce consumers into malicious virtual asset services and offerings; | ||
| (f) not facilitate illicit actors or high-risk virtual asset service providers in the offering of virtual assets, including initial coin offerings or virtual asset services; | ||
| (g) be in plain language as to be capable of being clearly understood by prospective consumers or consumers that might reasonably be expected to see it; and | ||
| (h) not state or imply that relevant virtual assets, including initial coin offerings and non fungible tokens, or virtual asset services are suitable for a particular class of consumers or consumers unless designated as being a product advertisable to a particular class of individuals or persons. | ||
| (2) Before selling any relevant virtual asset, including initial coin offerings or virtual asset services because of an advertisement, any licensee or promoter shall ensure that consumers have received sufficient information, regarding such products or services, inclusive of the benefit and potential failings, so as to allow a consumer to make an informed decision. | ||
| (3) Advertisements relating to the virtual asset services rendered by a licensee, shall include such relevant information as to the type of service offered, inclusive of terms and timeframes for consumer deposits and withdrawals, associated fees payable and such other relevant terms under which the service is provided to consumers. | ||
| (4) Where a person acts in contravention of this regulation, the relevant regulatory authority shall take such enforcement action as it deems necessary under the Act and may impose an administrative penalty of five million shillings. | ||
| Regulation 125 | (1) A licensee or promoter shall avoid extensive use of technical, legal terminology or complex language in an advertisement which may not convey a clear message to the consumers or may be such as to cause confusion if the likely audience is unfamiliar with the concepts. | This regulation’s specific content requirements enhance transparency. Further, the prohibiting implication of regulatory approval beyond licensing prevents misleading consumers about the level of oversight. |
| (2) All advertisements shall— | ||
| (a) include details of the licensee or promoter, including its full name and tradename (if applicable), licence number and registered office; | ||
| (b) include, if a known third party is issuing or cause the advertisement to be issued on behalf of the licensee or promoter of the virtual asset, the relevant details of the third party; | ||
| (c) be accurate and up-to-date; | ||
| (d) not omit any material relevant facts, and shall not make definitive statements that cannot be sustained; | ||
| (e) use a design and presentation that shall be easily and clearly understood; | ||
| (f) include, if relevant, any approved trademark, tradename, slogan or associated marker to the licensee or promoter; | ||
| (g) always give a fair, balanced and clear indication of any relevant risks when referencing potential benefits; | ||
| (h) include the contact details where consumers can make enquiries; | ||
| (i) ensure that changes to original information about the virtual asset or virtual asset service are promptly notified and described, with the advertisement indicating the date the information contained therein was updated. | ||
| (3) Where information is sourced externally, the licensee or promoter shall disclose it as being such, and shall ensure that the information is accurate, complete and up-to-date and include the original source. | ||
| (4) An advertisement shall only make a comparison, reference to past performance or future performance where this can be provided clearly, accurate, fair, balanced and not misleading, and does not take unfair advantage of the recipient of the communication. | ||
| (5) Any reference to the involvement of the relevant regulatory authority in the advertisement shall not be construed or imply that the relevant regulatory authority has approved the advertisement or taken the responsibility for the soundness of the virtual asset, including an initial coin offerings or virtual asset service, and shall be limited to reference as to licensing. | ||
| (6) A licensee shall not make reference to the name of any regulator, including the relevant regulatory authority or government in a way that is misleading and shall not use the name of any regulator, including the relevant regulatory authority, without seeking prior approval with the concerning regulator or the relevant regulatory authority. Performance information. | ||
| (7) Where a person contravenes this regulation, the relevant regulatory authority shall take such enforcement action as it deems necessary under the Act and may impose an administrative penalty of five million shillings. | ||
| Regulation 126 | (1) An advertisement shall — | This regulation provides comprehensive rules on performance claims. The requirement to present both negative and positive scenarios prevents cherry picking whilst the consumer research advisory is a useful nudge toward due diligence. |
| (a) not contain any projection of performance returns based on borrowing plans where it cannot be evidenced and substantiated; | ||
| (b) when referring to a comparison, ensure that— | ||
| (i) the comparison is meaningful and presented in a fair and balanced way; | ||
| (ii) the sources of the information used for the comparison are specified; and | ||
| (iii) the key facts and assumptions used to make the comparison are included, with clear provision as to its being an assumption and not a guarantee; | ||
| (c) when referring to past performance— | ||
| (i) contain a clear and prominent statement that past performance is not an indicator of future performance; | ||
| (ii) clearly state the reference period and the source of the information provided; and | ||
| (iii) is based on objective, up-to-date and accurate information. | ||
| (2) An advertisement that refer to future performance shall ensure that — | ||
| (a) the information gives a balanced impression, covering both negative and positive scenarios; | ||
| (b) it is clear as to the basis on which future performance is predicted; and | ||
| (c) there is a clear and prominent statement that such forecasts are not a reliable indicator of future performance. | ||
| (3) An advertisement shall not contain information on future performance if it is not able to obtain objective data to substantiate the advertisement. | ||
| (4) Future performance shall not be based on nor refer to simulated past performance. | ||
| (5) An advertisement shall advise that a consumer should undertake their own research and not rely solely on the information provided within the advertisement or other materials prepared. | ||
| (6) Where a person acts in contravention with this regulation, the relevant regulatory authority shall take such enforcement action as it deems necessary under the Act and may impose an administrative penalty of five million shillings. | ||
| Regulation 127 | Where a fee or cost is referred to in an advertisement, it shall give a realistic impression of the overall level of fees and costs a consumer is likely to pay with clear indication as to the fee or cost being an estimate, if applicable. | This regulation prevents fraud where headline offers obscure actual costs. The provision for full fee disclosure is essential for informed decision-making. |
| Regulation 128 | (1) An advertisement shall adequately display and explain any risks associated with relevant virtual asset, including initial coin offerings or virtual asset service. | The foreign currency warning is particularly important in Kenya where many virtual assets are priced in USD or other foreign currencies. |
| (2) Where the price of a relevant virtual asset, including initial coin offerings and non-fungible tokens, or virtual asset service, is denominated in a currency other than Kenya shillings, the consumer shall be warned that changes to the rates of exchange may have an effect on the value, price or income obtained from relevant advertisement. | ||
| (3) Where a person acts in contravention with this regulation, the relevant regulatory authority shall take such enforcement action as it deems necessary under the Act and may impose an administrative penalty not exceeding five million shillings. | ||
| Regulation 129 | (1) Any person making an advertisement shall, at all times— | This regulation establishes a personal duty of care for anyone making advertisements. The criminal penalty for breach signals the seriousness of responsible advertising. |
| (a) act responsibly, with honesty, fairness, integrity and professionalism; | ||
| (b) avoid aggressive or offensive sale practices; | ||
| (c) avoid indecent images or phrases; | ||
| (d) deal respectfully with the consumers and ensure sufficient disclosure is made for them to make informed decisions; its | ||
| (e) be transparent regarding the nature of his, her or relationship with the licensee or promoter; | ||
| (f) avoid any inaccurate, false, misleading or deceptive information; | ||
| (g) preserve confidentiality of the consumer's information, and not take advantage of such information for personal or another person's gain in conformity with the data protection law. | ||
| (2) A person who acts in contravention with this regulation commits an offence and is liable on conviction to a fine not exceeding three million shillings or 2 years imprisonment, or to both. | ||
| Regulation 130 | (1) Any person acting on behalf of a licensee or promoter, where appropriate, shall— | This regulation addresses influencer and affiliate marketing by requiring disclosure of paid promotions is essential for consumer trust. |
| (a) always disclose his full and accurate identity, at the time of introduction with consumers; | ||
| (b) always disclose to consumers before entering into any contract for relevant virtual asset, including initial coin offering and non fungible tokens, or virtual asset service, all benefits that will be paid to him or her, whether by way of fees, commissions, dividends (directly or indirectly) or otherwise under such contract, based on his relationship and interest that he or she may share with other parties which are associated with the relevant products or services; | ||
| (c) always disclose if they are being paid to promote or feature such a promotion on personal, business or other web pages controlled by the person itself. | ||
| (2) A person who acts in contravention with this regulation commits an offence and is liable on conviction to a fine not exceeding three million shillings or two years imprisonment, or to both. | ||
| Regulation 131 | An advertisement on the internet shall adhere to the following principles and standards — | This regulation adapts traditional advertising standards to digital formats, further, the date stamp on downloads is a practical audit trail feature. |
| (a) electronic advertisements shall be identical to the most upto-date paper versions; | ||
| (b) there shall be a prominent statement on the relevant web pages, which is capable of being seen and read with reasonable ease by the consumer accessing the electronic copies of such advertisements, to the effect that printed copies of the advertisements are also available, as well as where and how they can be obtained; | ||
| (c) any advertisements on the relevant web pages shall remain available for as long as it is necessary for the consumers to have a reasonable opportunity to read or access them, or for such duration of validity period as may be relevant from time to time; Prohibited internet advertising and marketing practices. | ||
| (d) consumers shall also be given the opportunity to retain the information through printing and downloading; and | ||
| (e) downloadable advertisements should contain the date by print or watermark or through a time stamp in the downloadable version of the triggered date that the download has occurred. | ||
| Regulation 132 | A licensee or promoter shall, inter alia, abstain from the following internet-based advertisement practices when making an advertisement over the internet— | The prohibited internet advertising practices in this regulation directly address dark pattern advertising techniques widely used by unscrupulous crypto platforms. |
| (a) hiding essential information by the close proximity of promotional images or additional text; | ||
| (b) reducing risk warnings in importance due to their location outside advertisement border; of the main | ||
| (c) diminishing some statements through the use of small font sizes, hard-to-read coloring, being placed at non prominent positioning and unclear type styles so as to render difficult or ineligible to read; | ||
| (d) hiding important information within, or in some cases absent from, the respective 107 internet landing page and only accessed through significant scrolling down or multiple page links; | ||
| (e) due to positioning, making risk warnings easy to overlook, resulting in consumers being taken directly to an application form by clicking onto a banner advertisement; | ||
| (f) publishing risk statements within a “pop-up” box that only appears on the consumer's initial visit to the relevant website; | ||
| (g) providing minimal information on the risks associated to promoted; | ||
| (h) obscuring key information or warnings, such as fees or exclusions, within the internet website or placed under a separate section or heading; incentives such as bonuses and inducements published on the main web page, but which are subject to conditions within pages noted in paragraph (h), that are not explained at the outset of account opening, transfer of funds or virtual asset; | ||
| (i) specific products being | ||
| (j) not taking into account the different-sized browsers of consumers when positioning risk information whereby it is necessary to scroll down to access the information; and | ||
| (k) superimposing important information, statements or warnings across colored or patterned backgrounds which lessen their visual impact. | ||
| Regulations 133 | A licensee or promoter shall maintain adequate records of its advertisements, including details of who signed off each advertisement and when it was signed off, for at least 7 years after the advertisement ceases to be available to consumers, or such other period which the relevant regulatory authority may request. | The seven (7) year record-keeping requirement in Regulation 133 is appropriate. |
| Prohibition, General Requirements, Content, Performance Information, Fees and Costs, Risks and Warnings, Duty of Advertiser, Third Party Duties, Internet Advertisements, Prohibited Internet Practices, Record Keeping | ||
| PART XIV – FREEZING AND SEIZURE ORDERS | ||
| Regulations 134 | In this Part— “authorised officer" means— | This Part defines "authorised officer," "freezing order," and "seizure order," giving effect to the Cabinet Secretary's power under section 49(2)(l) of the Act to prescribe conditions for freezing and seizure orders, and connecting to the Act's investigation and enforcement framework under sections 35 to 38. |
| (a) a police officer; | ||
| (b) officer of an investigating authority; | ||
| (c) any other officer, employee, or agent of a competent authority who is appointed to perform any specific function, duty, or exercise any power conferred upon an authorised officer under these Regulations or any written law; “freezing order” means an order issued by a competent court or other lawful authority directing a virtual asset service provider to prohibit any dealing, transfer, conversion, withdrawal or disposal of a specified virtual asset; and “seizure order” means an order issued by a competent court or other lawful authority directing the taking of possession or control of specified virtual assets for purposes of preservation or forfeiture. | ||
| Regulations 135 | (1) A freezing order or seizure order under these Regulations shall be obtained in accordance with the procedures and evidentiary requirements set out under the Proceeds of Crime and Anti-Money Laundering Act and the Anti-Corruption and Economic Crimes Act, or any other written law relating to the identification, tracing, seizure, or forfeiture of proceeds of crime. | This regulation does not create new substantive powers but rather extends existing legal frameworks to virtual assets. By incorporating the procedural and evidentiary requirements of established anti-money laundering and anti-corruption legislation, it ensures that virtual assets are subject to the same legal standards as traditional assets. |
| (2) Without prejudice to the generality of sub regulation (1), the powers of investigation, preservation, seizure, production of records, compensation and forfeiture applicable under the Proceeds of Crime and Anti-Money Laundering Act, the Anti-Corruption and Economic Crimes Act or any other relevant law shall, with the necessary modifications, apply to virtual assets and Virtual Asset Service Providers. | ||
| (3) Nothing in these Regulations shall be construed as limiting the competent authority to seek orders under the Proceeds of Crime and Anti-Money Laundering Act, the Anti-Corruption and Economic Crimes Act or any other relevant law for the recovery of virtual assets that constitute proceeds of crime or unexplained assets. | ||
| Regulations 136 | (1) Every licensee shall comply effectively with any freezing order and seizure orders. | This regulation is critical for law enforcement and anti-money laundering efforts. It makes clear that licensees are not just passive observers but have an active duty to cooperate. The requirement to produce records in a timely and effective manner is essential for investigations. |
| (2) Without prejudice to the generality of sub regulation (1), cooperation under this regulation shall include— | ||
| (a) responding promptly to lawful requests for information, documents, records, or other materials relevant to any investigation or proceedings; | ||
| (b) providing access to virtual asset transaction records, consumer identification data, beneficial ownership information, and any other data maintained pursuant to these Regulations; | ||
| (c) producing documents, records, or information in such form and within such timeframe as may be specified by the competent authorities; | ||
| (d) maintaining systems and procedures to enable timely and effective responses to competent authority’s requests; | ||
| (e) cooperating in the execution of court orders, warrants, directives, or other lawful instruments issued by competent authorities. | ||
| Regulations 137 | A licensee served with a freezing order shall— | A freeze order is ineffective if it can be circumvented by moving assets to a non-compliant sub-custodian. This obligation ensures the order has full effect. |
| (a) immediately freeze the specified virtual assets; | ||
| (b) prevent withdrawal, transfer or conversion related to the frozen assets; | ||
| (c) preserve all records relating to the frozen assets, including consumer information, transaction logs, wallet addresses, keys and any other relevant data; | ||
| (d) ensure that any internal or third-party custodian, sub-custodian, exchange partner or distributed ledger technology-infrastructure provider engaged by the licensee also complies with the order to the extent that they maintain control over the assets; | ||
| (e) comply with competent authorities and provide all documents, records, data, or technical information required in the freezing order, including— | ||
| (i) Preservation of value. addresses or accounts; | ||
| (ii) consumer identification records; | ||
| (iii) transaction histories, logs, consumer records and meta-data; | ||
| (iv) wallet identifiers, addresses, and associated credentials; and | ||
| (v) transaction histories; | ||
| (f) any other information that the competent court may order. | ||
| Regulations 138 | (1) An authorised officer shall take all reasonable measures to maintain the value and integrity of seized virtual assets. | This regulation addresses a unique challenge of virtual assets such as extreme price volatility. |
| (2) The authorised officer may, upon approval of the competent court, convert volatile virtual assets into fiat currency to preserve value, where necessary. | ||
| Regulations 139 | A licensee served with a seizure order shall— | Sub-regulation (e) is particularly significant as it recognizes that virtual assets are often controlled through physical devices) or written backups This grants authorised officers the power to seize these physical objects, acknowledging that access to virtual assets may require possession of tangible items. |
| (a) immediately surrender control of the specified virtual assets to the competent authority; | ||
| (b) provide full access to relevant wallets, addresses or accounts, digital records or as may be specified in the order; | ||
| (c) transfer the virtual assets to a designated, secure digital wallet controlled by the competent authority; | ||
| (d) provide transaction histories, logs, consumer records and technical information necessary for enforcement of the order; | ||
| (e) grant an authorised officer access to any premises where the virtual asset devices are suspected to be and the authorised officer may seize and detain any physical device, hardware wallet, seed phrase backup or electronic system necessary to access the virtual assets. | ||
| Regulations 140 | (1) All seized virtual assets shall be transferred to a secure wallet controlled by the relevant government agency. | This regulation adapts evidentiary standards to the technological medium. The value monitoring requirement recognizes the volatility risk even after seizure. |
| (2) The competent authority shall— | ||
| (a) maintain a detailed chain-of-custody record, including transaction hashes and transfers executed pursuant to the seizure order; and | ||
| (b) monitor the value of the seized virtual assets. | ||
| Regulations 141 | (1) A licensee that fails to comply with a freezing or seizure order commits an offence. | The substantial penalty signals the gravity of non-compliance with lawful orders. |
| (2) A person convicted under subregulation (1) shall be liable to a fine not exceeding ten million shillings, or imprisonment for a term not exceeding five years, or to both. | ||
| PART XV – GENERAL PROVISIONS | ||
| Regulations 142 | (1) Pursuant to section 6(1)(g) of the Act, there is established a coordination committee to be known as the Relevant Regulatory Authorities Coordination Committee, hereinafter referred to as the “Coordination Committee”. (2) The Coordination Committee shall consist of representatives nominated from the agencies specified in the Sixth Schedule. | This regulation implements the multi-agency coordination mandated by the principal Act. Given that virtual assets touch on multiple regulatory domains. There is potential for "regulatory overlap" or conflicting directives if this committee's mandate is not perfectly aligned with the existing powers of the Central Bank of Kenya (CBK) or the Capital Markets Authority (CMA). Nonetheless, it is noted that the CBK and CMA form part of this committee |
| Regulations 143 | The Coordination Committee shall— Committee. Conduct of business of the Coordination Committee. | The mandate addresses the multi-faceted nature of virtual asset regulation. Information sharing is critical to prevent regulatory trade where a licensee might be non-compliant with one agency's requirements while compliant with another's. The power to issue joint advisories provides a mechanism for consistent public communication across agencies. |
| (a) coordinate supervisory and regulatory activities relating to virtual asset service providers; | ||
| (b) facilitate timely sharing and exchange of supervisory, enforcement, and risk-based information; | ||
| (c) harmonize regulatory approaches and resolve cross-sectoral issues affecting virtual asset services; | ||
| (d) support joint inspections, risk assessments, and compliance appropriate; | ||
| (e) issue joint advisories or sector notices where matters cut across more than one relevant regulatory authority; prepare and submit to the Cabinet Secretary periodic reports of its activities. | ||
| (f) prepare and submit to the Cabinet Secretary periodic reports of its activities. | ||
| Regulations 144 | (1) The Coordination Committee shall meet at least once every quarter and may hold special meetings as required. | The quarterly meetings provide regular, predictable engagement. Further, the ability to establish sub-committees allows for focused work on specific issues. We also note that the confidentiality obligation is essential to ensure sensitive supervisory and enforcement information is not improperly disclosed. The Secretariat structure ensures administrative continuity. |
| (2) The Coordination Committee may establish such sub-committees as it may consider necessary to assist in the performance of its functions. | ||
| (3) The Coordination Committee shall determine its own procedures. | ||
| (4) All members shall comply with confidentiality obligations under section 42 of the Act when sharing information through the Coordination Committee. | ||
| (5) The Coordination Committee shall be supported by a Secretariat consisting of persons nominated by the relevant regulatory authorities. | ||
| Regulations 145 | The relevant regulatory authority shall, before imposing a penalty on a licensee under these Regulations, give the licensee a notice to show cause, requiring the licensee to demonstrate why the penalty should not be imposed. | This regulation enshrines the principle of procedural fairness by requiring the relevant regulatory authority to give the licensee an opportunity to be heard before imposing penalties. |
| Regulations 146 | (1) Subject to the Insolvency Act, a licensee may, with the approval of the relevant regulatory authority, voluntarily liquidate itself if it is unable to meet all its liabilities. | This regulation provides an orderly exit mechanism for failing licensees. The requirement for relevant regulatory authority approval ensures that liquidations do not occur in a manner that harms consumers or destabilizes the market. |
| (1) Subject to the Insolvency Act, a licensee may, with the approval of the relevant regulatory authority, voluntarily liquidate itself if it is unable to meet all its liabilities. (2) An application for the relevant regulatory authority’s approval for the purposes of sub regulation (1) shall be in the manner specified by the relevant regulatory authority. | ||
| (3) The relevant regulatory authority may, upon receipt of an application under sub regulation (2), approve the application if satisfied as to the insolvency of the licensee. | ||
| (4) Where the relevant regulatory authority approves an application by a licensee under this section, such licensee shall forthwith cease all its operations except such activities as are incidental to the orderly realisation, conservation and preservation of its assets and settlement of its obligations. | ||
| (5) A licensee, where it holds consumer funds, shall discharge its liability to its consumers as soon as practicable after the commencement of the liquidation and shall then rank all other creditors in accordance with the Insolvency Act. | ||
| Regulation 147 | If an application for the liquidation of a licensee is presented by a person other than the relevant regulatory authority, the applicant shall serve a copy of the application to the relevant regulatory authority, and the relevant regulatory authority shall be entitled to be a party to the proceedings. | This regulation ensures the relevant regulatory authority has visibility into and participation rights in any liquidation proceedings involving a licensee, even if initiated by third parties. |
| Establishment of the Coordination Committee, Mandate, Conduct of Business, Notice to Penalise, Voluntary Liquidation, Involuntary Liquidation | (2) The relevant regulatory authority may make an application to the court for the liquidation of a licensee in accordance with Part VI of the Insolvency Act. |