Blog

  • Commercial Arbitration in Kenya in 2026: A Complete Business Guide

    Commercial Arbitration in Kenya in 2026: A Complete Business Guide

    commercial arbitration in Kenya MN Legal

    Quick Overview

    Commercial arbitration in Kenya is one of the fastest paths to resolving a business dispute without going through the court system. If your contract has a dispute resolution clause, or you are dealing with a counterparty who refuses to perform, your arbitration options right now could save your business months of expensive litigation. This guide covers the full process under the Arbitration Act, Cap. 49, the landmark January 2026 Court of Appeal ruling on award finality, and what the Arbitration (Amendment) Bill 2025 means for businesses operating in Kenya.

    What Is Commercial Arbitration in Kenya?

    Commercial arbitration in Kenya is a private, binding process for resolving business disputes outside the courts. A neutral third party, the arbitrator, hears both sides and issues an award. That award is enforceable in the same way as a court judgment.

    The governing statute is the Arbitration Act, Cap. 49 (originally enacted in 1995, revised in 2012). It is modelled closely on the UNCITRAL Model Law, which means Kenya-seated awards align with international standards and are recognisable across most jurisdictions.

    Your business can use commercial arbitration in Kenya when your contract contains an arbitration clause, or when both parties agree to arbitrate after a dispute arises. Courts in Kenya consistently respect and enforce written arbitration agreements.

    Practical rule: If you are signing any commercial contract with a counterparty in Kenya or East Africa, include a well-drafted arbitration clause now. Retrofitting it after a dispute arises requires the other party’s consent, which you are unlikely to get when a dispute has already started.

    Arbitration vs. Litigation: What Your Business Needs to Know

    Litigation and arbitration serve different needs. The right choice depends on your dispute, your contract, and your commercial priorities.

    Factor Arbitration Litigation
    Privacy Proceedings are private Proceedings are public record
    Speed Variable; can be faster with tight timelines Can take years in Kenya’s courts
    Cost Higher upfront (arbitrator fees: USD 150-800/hour) Lower court fees; costs vary with complexity
    Expertise Arbitrator can be a sector specialist Judges handle all case types
    Finality Award is final; very limited grounds to challenge Multiple appeal levels available
    Enforceability Enforceable globally under the New York Convention Enforceable domestically and by treaty

    Arbitration works best for high-value commercial disputes where confidentiality matters and the parties want a specialist decision-maker. Litigation is appropriate when costs are the primary concern, or the dispute involves a remedy only a court can grant, such as an injunction or a contempt order.

    Important context: Kenya’s courts have been consistent in refusing to intervene in arbitration proceedings without strong cause. The January 2026 Court of Appeal ruling has made that position even more pronounced.

    From our experience: Most businesses draft arbitration clauses as boilerplate, then discover how important the specific wording is when a dispute actually starts. The dispute resolution clause deserves the same attention as the payment clause.

    The Legal Framework for Commercial Arbitration in Kenya

    Commercial arbitration in Kenya operates under three layers of authority.

    1) The Arbitration Act, Cap. 49. This is the primary statute. It governs the validity of arbitration agreements, appointment of arbitrators, conduct of proceedings, and recognition and enforcement of awards.

    2) The Nairobi Centre for International Arbitration Act, No. 26 of 2013. This established the NCIA as a government-backed institution to administer both domestic and international arbitrations. The NCIA published its most recent procedural rules in 2019, which parties can adopt by reference in their arbitration clause.

    3) Party agreement. Within the framework of the Act, parties have wide freedom to agree on the number of arbitrators, how they are appointed, the seat of arbitration, the language, and the applicable substantive law.

    Important context: If your arbitration clause does not specify institutional rules or a procedure for appointing an arbitrator, disputes about the clause itself may end up before the court before any substantive arbitration begins.

    Key 2026 Developments in Commercial Arbitration in Kenya

    The landscape for commercial arbitration in Kenya has shifted in the first half of 2026:

    • Award finality reinforced (January 2026): The Court of Appeal held in County Government of Kitui v Power Pump Technical Company Limited (Civil Appeal 176 of 2020) that a party cannot challenge an arbitral award through judicial review after failing a Section 35 application. [[1]](https://www.cliffedekkerhofmeyr.com/en/news/publications/2026/Kenya/Dispute-Resolution/dispute-resolution-alert-3-march-No-second-bite-at-the-cherry-Court-of-Appeal-bars-judicial-review-of-arbitral-awards-after-failed-section-35-challenge)
    • Arbitration (Amendment) Bill 2025 before Parliament: The Bill introduces emergency arbitration, third-party funding disclosure requirements, and a new specialist Arbitral Court. It is currently under parliamentary review. [[2]](https://globalarbitrationreview.com/review/the-middle-eastern-and-african-arbitration-review/2026/article/kenya-arbitration-amendment-bill-2025-signals-reset-nairobis-arbitral-ambitions)
    • Nairobi emerging as a regional hub: Kenya is increasingly the preferred seat for East African disputes, supported by an English common law system and improving institutional infrastructure. [[3]](https://www.cliffedekkerhofmeyr.com/en/news/publications/2026/Kenya/Corporate-Commercial/how-Kenyas-success-in-alternative-dispute-resolution-ADR-is-positioning-the-country-as-a-leading-hub-for-African-arbitration)
    • Cost concerns for SMEs persist: Arbitrator fees in Kenya run from USD 150 to USD 800 per hour depending on seniority and dispute complexity. For lower-value disputes, mediation may be a more proportionate first step. [[4]](https://koyaadvocates.co.ke/alternative-dispute-resolution-in-business-disputes-and-arbitration-in-kenya/)

    The January 2026 Ruling Every Business With a Commercial Contract Should Know

    On 30 January 2026, the Court of Appeal decided County Government of Kitui v Hon. Justice E. Torgbor and Power Pump Technical Company Limited (Civil Appeal 176 of 2020). This ruling is now one of the most important decisions on award finality in recent Kenyan arbitration jurisprudence. [[1]](https://www.cliffedekkerhofmeyr.com/en/news/publications/2026/Kenya/Dispute-Resolution/dispute-resolution-alert-3-march-No-second-bite-at-the-cherry-Court-of-Appeal-bars-judicial-review-of-arbitral-awards-after-failed-section-35-challenge)

    The question before the court was direct: can a party that has already failed to set aside an arbitral award under Section 35 of the Arbitration Act seek judicial review of that same award?

    The court’s answer was no.

    Section 35(2) of the Arbitration Act, Cap. 49 sets out eight grounds on which a party may apply to the High Court to set aside an award. These include: a party to the arbitration agreement was under incapacity; the agreement was invalid; proper notice was not given; the award went beyond the scope of the reference; the tribunal’s composition breached the agreement; or the award conflicts with Kenyan public policy. An application under Section 35 must be filed within three months of receiving the award.

    The Court of Appeal found that where a party has invoked this regime and failed, judicial review is not available as a fallback. The Arbitration Act creates a self-contained statutory framework. Repackaging a failed Section 35 challenge as a judicial review application is not permissible.

    What this means for your business: If you receive an arbitral award you believe is wrong, your window to challenge it is narrow. File a Section 35 application within three months. Make that application your strongest possible case. After that window closes, the award stands.

    Practical rule: When you receive any arbitral award, have a lawyer assess the Section 35 grounds within the first two weeks. The three-month clock is strict, and the January 2026 ruling has removed the judicial review route entirely.

    The Arbitration Amendment Bill 2025: What Businesses Need to Know

    The Arbitration (Amendment) Bill 2025 is currently before Parliament. Once enacted, it will represent the most significant update to Kenya’s arbitration framework since the original Arbitration Act was passed in 1995. Key provisions of the Bill include the following.

    1) Emergency Arbitration. The Bill resolves a longstanding ambiguity by expressly including emergency arbitrator decisions within the definition of “award.” Emergency arbitrator orders will be enforceable in the same way as final awards, provided the parties have consented to emergency arbitration procedures under their chosen institutional rules. [[2]](https://globalarbitrationreview.com/review/the-middle-eastern-and-african-arbitration-review/2026/article/kenya-arbitration-amendment-bill-2025-signals-reset-nairobis-arbitral-ambitions)

    2) Third-Party Funding Disclosure. The Bill introduces a new Section 39A to regulate third-party funding in international arbitration seated in Kenya. Funded parties will be required to disclose the existence of the funding arrangement, the identity of the funder, and the nature of the arrangement to the tribunal and the opposing party. This aligns Kenya with standards adopted in Singapore and Hong Kong. [[2]](https://globalarbitrationreview.com/review/the-middle-eastern-and-african-arbitration-review/2026/article/kenya-arbitration-amendment-bill-2025-signals-reset-nairobis-arbitral-ambitions)

    3) A Specialist Arbitral Court. The Bill formalises a new Arbitral Court with a dedicated Registrar to handle arbitration-related applications. This channels disputes to judges with arbitration expertise rather than the general commercial division.

    4) Summary Determination. The Bill gives tribunals power to summarily dismiss claims or defences that have no real prospect of success, reducing the ability to use arbitration proceedings as a delay tactic.

    Important context: The Arbitration (Amendment) Bill 2025 is proposed legislation, not yet in force as at the date of this article. Check its current parliamentary status before relying on any of its provisions. The Arbitration Act, Cap. 49 remains the governing statute.

    How Commercial Arbitration in Kenya Works: Step by Step

    Understanding the procedural sequence prevents the mistakes that derail valid claims.

    Step 1: Check your contract for a dispute resolution clause.

    Most commercial contracts contain an arbitration clause specifying whether the process is ad hoc or institutional. Read the clause carefully before taking any other step. The clause will dictate everything that follows.

    Step 2: Follow any pre-arbitration steps.

    Multi-tier clauses requiring negotiation or mediation before arbitration are common and enforceable in Kenya. Courts will enforce these pre-conditions. If your contract requires 30 days of negotiation before arbitration can begin, you should not skip that step.

    Step 3: Issue a notice of arbitration.

    The claimant sends written notice to the respondent stating that the dispute is being referred to arbitration, identifying the nature of the dispute, and invoking the arbitration clause. If you are using NCIA Rules, the notice must meet NCIA’s formal requirements.

    Step 4: Appoint the arbitrator or tribunal.

    The clause will specify the number of arbitrators and the appointment mechanism. A sole arbitrator is common for lower-value disputes. A three-member tribunal is used for complex or high-value matters. Where the parties cannot agree, the court or the NCIA may be asked to make the appointment.

    Step 5: Settle the terms of reference.

    The tribunal and parties agree on the issues in dispute, the procedure, the timeline, and the venue. This step sets the boundaries of what the tribunal will decide.

    Step 6: Exchange statements and evidence.

    Each party files its statement of claim or defence, supported by documents and witness statements. Disclosure obligations in arbitration are limited compared to court litigation, which helps manage costs.

    Step 7: The hearing.

    The tribunal hears witnesses and legal submissions. In simpler cases the tribunal may decide on documents alone, without a hearing.

    Step 8: The award.

    The tribunal issues a written award. It is binding on both parties. It is enforceable in Kenya under the Arbitration Act, Cap. 49, and internationally under the New York Convention on the Recognition and Enforcement of Foreign Arbitral Awards (Kenya acceded in 1989).

    Bottom line: Commercial arbitration in Kenya follows a structured sequence, but every step requires procedural compliance. A procedural failure can delay the proceedings or give the other side grounds to challenge the award under Section 35.

    Who Needs Commercial Arbitration Support in Kenya?

    Commercial arbitration in Kenya is relevant across a wide range of business types. Here are the situations we see most often.

    Contractors and subcontractors: Construction contracts in Kenya frequently require NCIA arbitration. Payment disputes and scope disagreements are the most common triggers.

    Foreign investors: Businesses investing in Kenya prefer arbitration because it offers a neutral forum and an internationally enforceable award, rather than a domestic court judgment that may be difficult to recognise abroad.

    Financial institutions: Banks and lenders use arbitration clauses in facility agreements to resolve default and enforcement disputes privately and outside the court’s public record.

    Technology and fintech companies: Commercial arrangements in this sector move fast. Confidentiality and specialist arbitrators make arbitration the preferred mechanism for contract disputes.

    Business partners in shareholder disputes: When a partnership or shareholder relationship breaks down, an arbitration clause in the shareholder agreement provides a structured, private path through the dispute.

    Common Mistakes Businesses Make in Commercial Arbitration in Kenya

    1) Drafting a vague arbitration clause.

    The clause must specify: the number of arbitrators, the method of appointment, the seat of arbitration, the institutional rules (if any), and the governing law. A clause that says only “disputes shall be referred to arbitration” leaves too much undefined and invites a court application before any merits are heard.

    2) Missing the Section 35 deadline.

    You have three months from receiving the award to apply to set it aside. This is a hard deadline. The January 2026 Court of Appeal ruling closes the judicial review door once that window passes.

    3) Ignoring pre-arbitration steps in a multi-tier clause.

    If your clause requires 30 days of good faith negotiation before arbitration begins and you skip that step, the respondent can challenge the tribunal’s jurisdiction.

    4) Choosing an arbitrator without sector knowledge.

    A commercial arbitration in Kenya involving a fintech or construction dispute needs an arbitrator who understands the sector. General legal experience is not enough for specialist matters.

    5) Treating arbitration like court litigation.

    Arbitration has different disclosure rules, timelines, and procedures. Running it like a court case drives up costs without the procedural protections that court litigation provides.

    From our experience: The disputes that produce the worst outcomes are ones where the arbitration clause was drafted without legal input and the procedural framework was left ambiguous. A short review at the contract stage prevents years of procedural uncertainty.

    How MN Legal Handles Commercial Arbitration in Kenya

    MN Legal is a Nairobi-based commercial law firm. Our Litigation and Dispute Resolution practice covers the full spectrum: domestic commercial arbitration in Kenya, international arbitration, mediation, debt recovery, shareholder disputes, and judicial review.

    Mutundu Chege co-heads the litigation practice. He has represented commercial banks, manufacturing conglomerates, and telecom companies in landmark cases before Kenya’s superior courts and arbitral tribunals.

    MN Legal also has a London-based Of Counsel, Konstantina Zariou, who specialises in international arbitration. Clients with cross-border commercial disputes, particularly those with a European or UK counterparty, benefit from counsel who understands both Kenyan and international arbitration frameworks. This is a depth that most Nairobi-only practices cannot match.

    We handle the full cycle of commercial arbitration in Kenya: contract review and clause drafting, pre-arbitration advisory, representation through the hearing, and post-award enforcement or challenge.

    Practical rule: Engage an arbitration lawyer before you receive an adverse award. The best time to build a case is when the dispute is still being framed, not after the award has been issued and the Section 35 clock is running.

    If you are dealing with a commercial dispute now, or you want your contracts reviewed for arbitration readiness, contact MN Legal.

    FAQs

    What Is Commercial Arbitration in Kenya?

    Commercial arbitration in Kenya is a private dispute resolution process in which a neutral arbitrator or tribunal hears and decides a business dispute. It is governed by the Arbitration Act, Cap. 49 and produces a binding award that is enforceable in Kenya and internationally under the New York Convention. It is used as an alternative to court litigation for contract disputes, shareholder disagreements, and other commercial matters.

    How Does Commercial Arbitration in Kenya Differ From Mediation?

    In arbitration, the arbitrator imposes a binding decision on both parties. In mediation, a neutral facilitator helps the parties reach a voluntary settlement. Neither party can be forced to settle in mediation. Arbitral awards, like court judgments, can be enforced against an unwilling party. Most Kenyan commercial contracts use a multi-tier clause requiring mediation or negotiation before arbitration begins.

    What Are the Grounds to Set Aside an Arbitral Award in Kenya?

    Section 35(2) of the Arbitration Act, Cap. 49 provides eight grounds: incapacity of a party, invalidity of the arbitration agreement, lack of proper notice, the award going beyond the scope of the reference, improper tribunal composition, conflict with Kenyan public policy, the subject matter not being arbitrable, or the award being procured by fraud, bribery, or undue influence. The application must be filed within three months of receiving the award.

    Can a Failed Section 35 Challenge Be Brought Back as a Judicial Review?

    No. The Court of Appeal ruled in January 2026 in County Government of Kitui v Power Pump Technical Company Limited that a party that has already failed to set aside an award under Section 35 cannot seek judicial review of the same award. The Arbitration Act, Cap. 49 creates a self-contained regime. Judicial review is not available as a second attempt after the statutory route has failed.

    Is Commercial Arbitration in Kenya Confidential?

    Yes. Unlike court proceedings, arbitration hearings and awards in Kenya are private. The parties and the tribunal are generally bound to keep the proceedings confidential unless the parties agree otherwise or disclosure is required by law. This confidentiality is one of the primary reasons businesses prefer arbitration for sensitive commercial disputes.

    How Long Does Commercial Arbitration in Kenya Typically Take?

    The timeline depends on the complexity of the dispute, the efficiency of the arbitrator, and whether the parties comply with procedural directions. Simpler disputes can conclude in six to twelve months. Complex commercial matters may take two to three years. Proceedings under the NCIA Rules include procedural timelines, but compliance depends on both parties.

    How Much Does Commercial Arbitration in Kenya Cost?

    Arbitrator fees in Kenya range from approximately USD 150 to USD 800 per hour, depending on the arbitrator’s seniority and the nature of the dispute. [[4]](https://koyaadvocates.co.ke/alternative-dispute-resolution-in-business-disputes-and-arbitration-in-kenya/) Institutional fees, venue costs, and legal representation add to the total. For lower-value matters, mediation is often more proportionate.

    What Is the NCIA and How Does It Support Commercial Arbitration in Kenya?

    The Nairobi Centre for International Arbitration (NCIA) was established by the Nairobi Centre for International Arbitration Act, No. 26 of 2013 as a government-backed institution to administer both domestic and international arbitrations. It provides procedural rules (last revised in 2019), a panel of arbitrators, and administrative support for proceedings. Parties who include NCIA Rules in their arbitration clause give the NCIA a role in administering the process and resolving procedural disputes.

    What Does the Arbitration Amendment Bill 2025 Mean for Businesses?

    The Arbitration (Amendment) Bill 2025, currently before Parliament, proposes four main changes to commercial arbitration in Kenya: it formalises emergency arbitration and makes emergency orders enforceable; it requires disclosure of third-party funding arrangements; it introduces a specialist Arbitral Court; and it gives tribunals summary determination powers. Once enacted, it will be the first major update to the Arbitration Act since 1995. The existing Act governs until then.

    Is a Kenyan Arbitral Award Enforceable Internationally?

    Yes. Kenya acceded to the New York Convention on the Recognition and Enforcement of Foreign Arbitral Awards in 1989. An award issued in a Kenya-seated arbitration is enforceable in over 170 countries that are party to the Convention. For cross-border commercial disputes, this enforceability is a significant practical advantage over a domestic court judgment.

    Which Firms Handle Commercial Arbitration in Kenya?

    MN Legal handles both domestic and international commercial arbitration in Kenya through its Litigation and Dispute Resolution practice. Mutundu Chege co-heads the team with experience representing commercial banks, manufacturers, and telecoms in high-stakes proceedings. Konstantina Zariou, MN Legal’s London-based Of Counsel, adds international arbitration depth for cross-border matters. The team covers the full cycle: clause drafting, pre-arbitration strategy, representation at hearings, and post-award enforcement.

    Extra Resources

    Citations

    [1] Cliffe Dekker Hofmeyr. (2026, March 3). No second bite at the cherry: Court of Appeal bars judicial review of arbitral awards after failed section 35 challenge. CDH Dispute Resolution Alert.

    [2] Global Arbitration Review. (2026). Kenya: Arbitration (Amendment) Bill 2025 signals a reset for Nairobi’s arbitral ambitions. The Middle Eastern and African Arbitration Review 2026.

    [3] Cliffe Dekker Hofmeyr. (2026). How Kenya’s success in alternative dispute resolution is positioning the country as a leading hub for African arbitration. CDH Corporate Commercial Alert.

    [4] Koya and Company Advocates. (2023). Alternative Dispute Resolution in Business Disputes and Arbitration in Kenya.

    [5] Kenya Law. (2022). Arbitration Act, Cap. 49 (Revised Edition 2022).

    [6] Nairobi Centre for International Arbitration. (2019). NCIA Arbitration Rules 2019.


    Legal Disclaimer

    This article is intended for general informational purposes only and does not constitute legal advice. The information provided does not create an attorney-client relationship between MN Legal (MN Advocates LLP) and the reader. Laws and regulations change; confirm current status with qualified legal counsel before acting on anything in this article. For advice specific to your situation, contact MN Legal.

  • Finance Bill 2026: KRA’s New Data Powers and What Founders Must Know    |    MNL Advocates LLP

    Finance Bill 2026: KRA’s New Data Powers and What Founders Must Know | MNL Advocates LLP

    When the Taxman Becomes the Data Collector: KRA’s New Powers Under Finance Bill 2026 and What Founders Must Know

    Quick Summary: The Finance Bill 2026, published on 5 May 2026 and tabled before the National Assembly, proposes a new Section 18A into the Tax Procedures Act. The provision empowers the Kenya Revenue Authority Commissioner to issue tax assessments using secondary data including eTIMS records, withholding tax declarations, and whistleblower reports. This creates a direct collision with the Data Protection Act 2019 and raises constitutional questions under Articles 24, 27, 31, and 47 of the Constitution of Kenya. Founders and business operators need to act now.

    Every year, Kenya’s Finance Bill arrives with new proposals. Every year, businesses brace. Most founders read the headline changes, note the new rates, and move on. Finance Bill 2026, published on 5 May 2026 and formally tabled before the National Assembly, deserves considerably more attention than that.

    Buried within its proposed amendments to the Tax Procedures Act is a provision that fundamentally changes the relationship between the Kenya Revenue Authority, your business data, and the law enacted specifically to protect it.

    The provision is proposed Section 18A. It would empower the KRA Commissioner to determine whether a person has entered into or carried out a tax avoidance scheme and to issue tax assessments accordingly, using secondary data. The data sources the Bill authorises are broad: withholding tax declarations, employer tax filings, eTIMS transaction records, whistleblower reports, third-party information, KRA audit findings, and any information obtained under other written laws. KRA would have up to five years to issue assessments arising from such determinations.

    This is not a routine tax measure. It is a structural realignment of how the state can access, interpret, and act on your personal and business information, without necessarily asking you first.

    The Finance Bill 2026 matters to every founder running transactions through eTIMS, every fintech operator filing withholding tax records, every digital asset platform with user data sitting in third-party systems, and every business operator whose tax position could be assessed by a regulator who has access to data you have never personally disclosed to KRA.

    Understanding what the Bill proposes, where it conflicts with existing law, and what you should do right now is not optional. It is operational necessity.

    What Section 18A of the Finance Bill 2026 Actually Proposes

    The plain-language version of Section 18A is this: the KRA Commissioner gains the power to form a view that you have engaged in a tax avoidance scheme, and to assess your tax liability on that basis, using data that was collected by other parties for other purposes.

    The secondary data sources the Bill lists are not hypothetical. They are systems already in operation. eTIMS records reflect every transaction your business has processed through the electronic tax invoice management system. Withholding tax declarations carry financial information filed by your counterparties. Employer tax filings show your payroll obligations. Whistleblower reports can come from anyone. Third-party information can originate from financial institutions, other government agencies, or individuals with no direct relationship to your business. KRA audit findings from entirely separate investigations are included.

    The five-year assessment window means that KRA can revisit your tax position for up to five years after identifying a suspected avoidance scheme, using data aggregated across that entire period.

    Two parallel provisions compound the picture. The Bill introduces mandatory annual information returns for virtual asset service providers, requiring them to file detailed user and transaction data with KRA. It also proposes expanded royalty definitions that capture digital payment platforms, card schemes, and switching systems, widening the net of entities under heightened reporting obligations.

    The government frames all of this as modernising Kenya’s tax administration, aligning with global digital enforcement trends, and closing longstanding revenue leakages. That framing is not entirely without foundation. But the mechanism chosen to achieve those objectives raises serious legal questions that no founder operating in Kenya should ignore.

    Data SourceOriginal PurposeProposed New Use Under Section 18A
    eTIMS transaction recordsInvoice compliance and VAT trackingEvidence of tax avoidance schemes
    Withholding tax declarationsThird-party tax deduction reportingSecondary data for income assessments
    Employer tax filingsPAYE and payroll complianceCross-referencing business income positions
    Whistleblower reportsVoluntary information from informantsEvidentiary basis for avoidance determination
    Third-party informationVarious, including financial institutionsSupporting data for assessments
    KRA audit findingsConclusions from separate audit processesCross-use in new avoidance determinations

    Not sure how these provisions affect your specific business? Speak with MNL’s compliance team.

    Finance Bill 2026 Kenya tax documents being reviewed and annotated at a legal desk
    Section 18A of the Finance Bill 2026 proposes to allow KRA to issue tax assessments using secondary data collected by third parties for entirely different purposes.

    Where Finance Bill 2026 Collides with Kenya’s Data Protection Framework

    Kenya’s Data Protection Act 2019 is not aspirational. It is operational, enforceable, and backed by the Office of the Data Protection Commissioner, which has demonstrated a willingness to act. The Act gives effect to Articles 31(c) and 31(d) of the Constitution. It applies to every entity that collects and processes personal data, including financial data, and it applies to government bodies as much as it applies to private ones.

    The proposed KRA framework under Section 18A cuts against four of the DPA’s core principles.

    Purpose Limitation

    Data collected for one purpose cannot be repurposed for another without a fresh lawful basis. When a supplier’s withholding tax data, visible on iTax for payroll compliance purposes, is used to compute an entirely separate tax liability under a suspected avoidance scheme, the purpose for which that data was originally collected has been exceeded. The DPA does not permit this without explicit authority and proportionality.

    Transparency

    Data subjects have the right to know who is accessing their information and why. When whistleblower reports, whose sources a taxpayer may never be permitted to know, form the evidentiary basis of a tax assessment, the transparency requirement has been circumvented. The taxpayer has no visibility into the origin, accuracy, or context of the information driving the assessment against them.

    Automated Processing and Profiling

    The DPA provides that individuals have the right not to be subjected to decisions made solely through automated processing, including profiling. When eTIMS transaction records are fed into KRA’s digital systems to profile business behaviour and generate assessments, this prohibition is directly engaged. KRA has not published the technical architecture of how these assessments will be generated. The absence of that disclosure is itself a transparency problem.

    Data Accuracy

    As EY Associate Director Rachel Njuguna noted in published commentary on the Bill, the risk is concrete: data held by third parties may not accurately reflect a taxpayer’s actual tax position. The proposed framework offers no mechanism for a taxpayer to verify or challenge the accuracy of the source data before an assessment is issued. The burden of disproving an assessment derived from potentially inaccurate data falls on the taxpayer after the fact.

    KRA Proposed PowerConflicting DPA 2019 Protection
    Use eTIMS data to determine tax avoidancePurpose limitation: data must be used only for the purpose collected
    Use whistleblower reports without source disclosureTransparency: data subjects must know who accesses their data and why
    Profile business behaviour through transaction dataRight not to be subject to automated processing with legal effects
    Issue assessments before taxpayer can review source dataRight to challenge inaccurate personal data before legal consequences arise
    Proposed KRA exemption from DPA accuracy obligationsDPA requires all data controllers to maintain accurate, current data

    The Constitutional Dimension

    Kenya’s Constitution is explicit. Article 31 guarantees every person the right to privacy, including the right not to have information relating to their family or private affairs unnecessarily required or revealed. Any law that limits this right must satisfy Article 24, which requires that the limitation be reasonable and justifiable in an open and democratic society, and that it be proportionate to the objective being pursued.

    Civil society organisations, including Amnesty International Kenya and ARTICLE 19 Eastern Africa, have assessed the proposed expansion of KRA’s data powers directly. Their conclusion is unequivocal: the provision does not meet the Article 24 threshold. The limitation goes beyond what is necessary to achieve the stated objective of closing tax revenue leakages. Less intrusive enforcement mechanisms already exist and are in active use.

    The due process concern is compounded by the proposed exemption of KRA from certain DPA accountability obligations. If the Bill is enacted as drafted, KRA would face reduced obligations to ensure that the data it uses is accurate, to maintain clear data retention policies, and to give taxpayers meaningful visibility into how their information is being used. For a framework that will determine tax liabilities, with direct legal and financial consequences for individuals and businesses, that is a significant gap.

    Article 47, the right to fair administrative action, reinforces the concern. Where an administrative decision is likely to adversely affect a person, that person is entitled to written reasons and an opportunity to be heard. An assessment issued on the basis of third-party secondary data, without prior disclosure of that data to the taxpayer, raises serious questions about compliance with Article 47 obligations.

    This Pattern Is Not New

    Finance Bill 2026 is not the first time this boundary has been tested, and understanding the pattern matters for how you position your business going forward.

    Finance Bill 2025 contained a provision seeking to repeal Section 59A(1B) of the Tax Procedures Act, a statutory safeguard that then prohibited KRA from compelling taxpayers to disclose personal data or trade secrets obtained during business operations. That proposal drew fierce opposition from the Law Society of Kenya, KPMG East Africa, and Ernst and Young. KRA’s Commissioner General subsequently committed, before the Departmental Committee on Finance and Economic Planning, to work with the Office of the Data Protection Commissioner on a Data Minimisation Strategy under the 9th Corporate Plan.

    Finance Bill 2026 returns to the same contested territory. The mechanism is different but the practical effect is the same: expanding KRA’s reach to data that the existing legal framework was not designed to accommodate without additional safeguards.

    The policy direction is now clear across successive Finance Bills. Kenya is moving toward a data-driven tax enforcement model. Whether Parliament enacts or moderates these specific provisions, the trajectory will not reverse. Businesses need to be positioned for a compliance environment where the state has broader access to financial data than it has had at any previous point, where assessments can be generated from aggregated secondary sources, and where the burden of proving inaccuracy may rest with the taxpayer.

    Preparation now costs far less than litigation later. That is not a theoretical observation. It is the consistent finding of every business that has waited for enforcement pressure before addressing its compliance posture.

    Five Things Founders and Business Operators Should Do Right Now

    This is about operational readiness, not legal panic. The Bill has not passed. You have time to act intelligently. Here is where to start.

    1. Audit Your Digital Data Footprint

    Every transaction processed through eTIMS, every withholding tax record filed against your PIN, and every employer filing associated with your payroll is already visible within KRA’s digital systems. Under the proposed framework, this data can be aggregated, cross-referenced, and used to assess your tax position without a prior audit flag. Accuracy in your digital records is no longer merely good practice. It is your first line of defence. Reconcile your eTIMS records against your own books now, before any assessment process begins.

    2. Know Your Rights as a Data Subject

    Even before these amendments are enacted, the Data Protection Act 2019 gives you rights that apply today. You can request to know what personal data KRA holds on you. You can challenge inaccuracies in that data. You have the right to be informed about automated processing that produces legal effects. These rights exist under current law, and exercising them proactively creates a documented record that is valuable if an assessment dispute arises. Understand your Data Protection Act 2019 obligations and the corresponding rights they give you.

    3. Engage the Public Participation Process

    Finance Bill 2026 is at the public participation stage before the National Assembly. This is a formal legal opportunity to submit memoranda, appear before the committee, or support industry associations presenting evidence-based objections. Bowmans and other firms have already made public submissions on specific provisions. The window is open. Founders with direct knowledge of how data-driven tax assessments would affect their operating models have information the committee needs and does not yet have from affected parties at scale.

    4. Assess Your Obligations If You Operate in Fintech or Digital Assets

    Virtual asset service providers and digital payment platforms face the most immediate and specific new obligations under the Bill. If your business falls within those categories, the question of what data you will be required to file, when, and under what governance framework requires legal advice now, before enactment. The fintech reporting compliance Kenya landscape is changing materially with this Bill, and the obligations are not minor.

    5. Document Your Internal Data Governance

    If your data is going to be used in an assessment against you, the best protection is records that speak for themselves. Clear internal policies on data retention, transaction documentation, and reconciliation processes that can withstand external scrutiny are not just compliance infrastructure. They are your evidentiary foundation in any dispute. Building strong corporate data governance in Kenya now converts a future risk into a managed position.

    Not sure how Finance Bill 2026 affects your specific business model? Our Team can walk you through the risk exposure and what documentation you need in place before this Bill passes. Book a compliance review with MNL.

    The Window to Act Is Open

    Finance Bill 2026 does not exist in a regulatory vacuum. Kenya has a Data Protection Act. It has a functioning Office of the Data Protection Commissioner. It has a Constitution with an enforceable bill of rights. None of these are suspended by a Finance Bill.

    The legal question Parliament must answer before enacting Section 18A is not whether tax enforcement matters. It plainly does. The question is whether this particular mechanism, with its current absence of taxpayer safeguards, data accuracy obligations, and transparency requirements, is the proportionate and lawful means of achieving that objective.

    For businesses, the practical question is narrower but no less urgent: are you operationally prepared for a tax environment where secondary data can drive assessments, where the burden of proving inaccuracy may fall on you, and where the data generating those assessments may be held by parties you have never directly dealt with?

    The Bill is before the National Assembly. The public participation window is open. Your records are either accurate and documented or they are not. Your data rights are either understood and exercised or they are not. The cost of getting ahead of this is low. The cost of responding to an assessment after the fact is not.

    Ready to understand exactly how Finance Bill 2026 affects your business?
    MNL Advocates LLP advises clients across fintech, technology, and commercial law on regulatory compliance, data protection, and tax matters in Kenya and across East Africa.
    Initiate a Confidential Consultation with MNL.

    Frequently Asked Questions: Finance Bill 2026 and KRA Data Powers

    What does Section 18A of the Finance Bill 2026 allow KRA to do?

    Section 18A proposes to empower the Kenya Revenue Authority Commissioner to determine whether a person has entered into or carried out a tax avoidance scheme and to issue tax assessments accordingly using secondary data. The authorised sources include withholding tax declarations, employer tax filings, eTIMS transaction records, whistleblower reports, third-party information, KRA audit findings, and information obtained under other written laws. KRA would have up to five years to issue assessments arising from such

  • The Silicon Savannah’s Social Contract: A Critical Deep Dive into Kenya’s Artificial Intelligence Bill, 2026

    The Silicon Savannah’s Social Contract: A Critical Deep Dive into Kenya’s Artificial Intelligence Bill, 2026

    For over a decade, Kenya has been the poster child for “permissionless innovation.” We built a global fintech hub on the back of regulatory forbearance, allowing code to outpace the law. But with the introduction of the Kenya Artificial Intelligence Bill 2026, the era of the algorithmic “Wild West” is officially over.

    Working at the intersection of law and digital transformation, I view this Bill not merely as a regulatory hurdle. It is a profound re-architecting of the Kenyan tech ecosystem’s social contract.

    It attempts a delicate, and at times precarious, balancing act: importing the rigorous rights-based framework of the European Union while preserving the developmental agility of an emerging market economy.

    This is the analytical breakdown of what AI regulation in Kenya means for the lawyers, founders, general counsel, and operators who call the Silicon Savannah home.

    1. The Architecture of Power: The Rise of the AI Commissioner

    The Bill establishes the Office of the Artificial Intelligence Commissioner Kenya, and this is not a ceremonial post. It is a “body corporate” with the power to sue, be sued, and, most critically, to enter premises and inspect AI systems upon reasonable notice.

    The Advisory Committee on Artificial Intelligence brings together representatives from the ICT sector, the National Commission for Science, Technology and Innovation (NACOSTI), the Data Protection Commissioner, and independent experts in ethics and human rights.

    Two nominees from the Council of Governors complete the committee. This is a structural acknowledgment of Kenya’s devolved constitutional reality: AI’s most consequential impacts on healthcare and agriculture will be felt most acutely at the county level, not in Nairobi boardrooms.

    The Commissioner is a presidential appointee, subject to parliamentary approval.

    The Critique:

    The Bill creates a highly centralised power structure. The Commissioner’s “independence” is stated, yet the appointment mechanism runs through the executive.

    For a sector that moves at the speed of innovation, the risk of a regulatory bottleneck is not hypothetical. It is structural. Founders and multinationals must factor regulatory lag into their compliance timelines from day one.

    2. The Philosophy of “Protective Developmentalism”

    The Bill adopts a risk-based regulatory posture that mirrors the EU AI Act in its fundamental architecture, categorising AI systems into four tiers:

    • Unacceptable Risk: Flatly prohibited systems.
    • High Risk: The Bill’s primary compliance battleground.
    • Limited Risk: Targeted transparency obligations.
    • Minimal Risk: Largely unregulated.

    High-risk AI systems compliance Kenya covers the most strategically significant sectors: healthcare, education, agriculture, finance, security, and public administration. These systems face the most stringent oversight requirements, including pre-deployment assessments and ongoing monitoring obligations.

    But Kenya’s philosophy diverges from pure restriction in one critical way. The Commissioner is mandated to promote “equitable access to AI infrastructure” and “digital inclusion in underserved areas.” This is not incidental language. It is a developmental directive embedded in a compliance statute.

    This is what I call “Protective Developmentalism”: law as an instrument of directed innovation, not merely restriction.

    Unlike purely restrictive regulatory models, Kenya is attempting to channel AI toward national development priorities. The Bill does not just police AI. It attempts to shape where it goes.

    3. The “Human-Centric” Mandate: A Corporate Burden?

    Sections 32 and 33 are, arguably, the most commercially consequential provisions in the entire Bill. They deserve surgical examination.

    Section 32 establishes a “human-in-the-loop” requirement for AI systems that affect human rights or safety. AI must be designed to enhance, not replace, human capabilities. A qualified person must retain the ability to override an AI system’s output. If your AI architecture is a closed loop, it is a legal liability under this Bill.

    Section 33 goes further, and this is where significant industry friction will emerge.

    The Workforce Impact Assessment Obligation

    Any enterprise deploying an AI system likely to impact employment must conduct a formal AI workforce impact assessment Kenya and, more controversially, implement reskilling programmes in direct collaboration with the government.

    This is not aspirational corporate social responsibility language. It is a statutory obligation.

    The Critique:

    In virtually every other jurisdiction that has grappled with AI-driven displacement, reskilling is a policy goal, a government initiative funded by public resources.

    Here, it is a legal burden placed directly on the private sector. Enterprises in BPO, manufacturing, and large-scale agriculture will need to weigh the efficiency gains from AI adoption against the mandatory compliance cost of reskilling the workforce it displaces.

    For businesses operating at scale, this provision is a material factor in AI investment decisions. The employment law advisory implications are significant, and they begin from the moment you identify an AI implementation that touches any human role.

    Is your business prepared for workforce compliance under the Kenya AI Bill 2026?

    Our employment law advisory team is ready to map your exposure and build a compliant reskilling framework before the Bill comes into force.Initiate a Confidential Consultation →

    4. Strengths: The Forward-Thinking Provisions Kenya Got Right

    Despite the legitimate tensions above, the Bill contains several genuinely visionary provisions that position Kenya as a potential global leader in ethical AI governance.

    Environmental Stewardship

    Section 30(2)(d) requires that AI ethical guidelines address environmental sustainability, including assessments of the carbon footprint and energy consumption of AI systems.

    In an era of hyperscale data centres driving unprecedented energy demand globally, this provision is ahead of the regulatory curve. It signals that Kenya is thinking about AI governance in systemic, not merely transactional, terms.

    Synthetic Media and Deepfake Accountability

    The Bill takes an uncompromising position on AI-generated synthetic media. Explicit consent is required before using a person’s likeness in AI-generated content, and clear labelling of synthetic media is mandated.

    This directly addresses the legal implications of deepfakes under the Kenya AI Bill, filling a gap that many advanced jurisdictions have left open. This also carries significant intellectual property protection dimensions for creators, public figures, and brand owners operating in Kenya.

    The Regulatory Sandbox

    This is the Bill’s olive branch to innovators building at the frontier. The AI regulatory sandbox Kenya provides a controlled environment for testing novel AI systems with oversight from the Commissioner’s office, allowing for “safe innovation” that serves national priorities while actively mitigating risk.

    For founders building in regulated sectors, the sandbox is not optional. It is a strategic instrument, and the only formal path to regulatory protection during the development phase.

    5. The Gaps: Ambiguities and Implementation Risks

    No legislative instrument of this ambition ships without gaps. Intellectual honesty demands we name them clearly.

    The Definition Problem

    The Bill defines AI broadly as any “machine-based system leveraging data processing” to infer outputs. In strict legal construction, a sufficiently complex Excel macro or legacy rule-based enterprise software could fall within this definition.

    The risk of over-compliance for non-AI technologies is real. Until the Cabinet Secretary issues clarifying regulations, General Counsel will need to err on the side of caution, at significant cost.

    The “Unacceptable” Void

    The Bill prohibits “unacceptable risk” AI systems but defers the detailed criteria to future subsidiary legislation. This creates a foreseeable period of “regulatory chill”: investors and founders may be reluctant to fund borderline-category technologies until the list is formally published. In a fast-moving venture ecosystem, that hesitation has a measurable cost.

    Director Criminal Liability: Section 35(3)

    This is the sharpest provision in the Bill, and it requires careful reading by every board member and company officer in Kenya’s tech sector.

    Section 35(3) establishes that if a body corporate commits an offence under the Act, every director or officer who had knowledge of the offence and failed to exercise due diligence is personally guilty of the same offence. The AI Bill 2026 penalties at stake are not trivial: a fine of KES 5 million and/or up to two years imprisonment.

    For an offence such as failing to conduct a workforce impact assessment, the personal exposure for directors is considerable. The risk of talented professionals avoiding directorships in Kenyan tech companies is not speculative.

    It is the rational response to poorly calibrated criminal liability. This is a corporate governance crisis waiting to happen for any board that does not proactively establish documented AI oversight frameworks and due diligence trails before the Bill comes into force.

    Concerned about director liability under Kenya’s AI Bill 2026?

    Our corporate governance team delivers surgical precision on AI compliance risk, mapping your exposure before it becomes a legal event.Schedule a Consultation →

    6. Positioning Kenya in the Global Regulatory Landscape

    The Kenya AI Bill vs EU AI Act comparison is instructive, but it only tells part of the story.

    Kenya is clearly rejecting the United States’ “hands-off,” innovation-first regulatory philosophy. The Bill explicitly references the EU AI Act in its objects clause, a deliberate signal to the international investor community that AI systems built under Kenyan law are structurally “export-ready” for the European market.

    This is the Brussels Effect in action: global regulatory gravity pulling smaller jurisdictions toward the EU’s standard-setting model.

    But Kenya is not simply transposing EU law. It is adding what I call the “African Layer”, embedding devolved governance through county-level representation, mandating workforce reskilling as a corporate obligation, and centering digital inclusion as a core regulatory objective.

    The result is a genuine “Third Way” of AI regulation: rights-based in architecture, yet explicitly developmental in ambition. Neither purely protective nor purely permissive.

    For businesses and multinationals with data privacy compliance obligations spanning multiple jurisdictions, Kenya’s deliberate alignment with EU standards simplifies the compliance matrix considerably, provided implementation keeps pace with legislative ambition.

    7. The Legal-by-Design Framework: Actionable Guidance for Businesses

    For founders, General Counsel, and enterprise operators in Kenya, “wait and see” is not a strategy. The Legal-by-Design AI framework demands proactive action now, while the regulatory landscape is still being formed.

    1. Risk Triage: Conduct an immediate audit of every AI-enabled product and process in your stack. Operating in finance, healthcare, agriculture, education, or public administration? Begin scoping your Human Rights Impact Assessments (HRIA) immediately. The compliance infrastructure for HRIA takes time to build. Do not wait for a commencement date.
    2. Data Hygiene: The Bill requires maintaining records of training datasets and AI system outputs for a minimum of five years. If your data logging practices are informal or inconsistent, you are already non-compliant by the standards this Bill will impose.
    3. Human Override Audit: Review every automated decision-making process in your business. Under Section 32, a fully closed-loop AI system, one that makes consequential decisions without a documented human override capability, is a legal liability. Build the “Red Button” into your architecture before the Bill requires it.
    4. Workforce Planning: If your AI implementation automates tasks currently performed by human staff, begin mapping your AI workforce impact assessment obligations now. Under Section 33, the government will be your mandatory partner in workforce transition planning. Getting ahead of this is both a compliance strategy and a talent retention strategy.
    5. Engage the Sandbox: If you are building innovative AI systems at the frontier of regulated sectors, apply for the AI regulatory sandbox Kenya programme early. The sandbox provides the only formal mechanism for testing novel systems with the Commissioner’s oversight during development.

    Frequently Asked Questions: Kenya’s AI Bill 2026

    What is the Kenya Artificial Intelligence Bill 2026?

    The Kenya Artificial Intelligence Bill 2026 is proposed legislation establishing a comprehensive regulatory framework for the development, deployment, and use of AI systems in Kenya.

    It creates the Office of the AI Commissioner as an independent regulatory body, defines four risk tiers (Unacceptable, High, Limited, and Minimal), and imposes specific compliance obligations including impact assessments, data record-keeping, and human oversight mechanisms.

    What are the penalties for non-compliance with the Kenya AI Bill 2026?

    Under Section 35(3), penalties extend to individual directors and officers. Any director who had knowledge of a corporate offence and failed to exercise due diligence is personally guilty.

    Penalties include fines of up to KES 5 million and/or imprisonment for up to two years, making director-level AI oversight a matter of personal legal risk, not just corporate policy.

    What qualifies as a high-risk AI system in Kenya?

    AI systems deployed in healthcare, education, agriculture, finance, security, and public administration are classified as high-risk. These face the most stringent compliance requirements, including pre-deployment human rights impact assessments, mandatory human-in-the-loop oversight, and ongoing monitoring and record-keeping obligations.

    What is the AI regulatory sandbox in Kenya?

    The AI regulatory sandbox is a controlled testing environment under the Bill allowing startups and innovators to develop and test novel AI systems with formal oversight from the Office of the AI Commissioner. It enables “safe innovation” in real-world conditions while managing risk and ensuring alignment with national development priorities, providing regulatory protection during the development phase.

    How does the Kenya AI Bill compare to the EU AI Act?

    Kenya’s Bill mirrors the EU AI Act’s risk-based, tiered regulatory architecture and explicitly references EU standards, signalling that AI systems built under Kenyan law are “export-ready” for European markets. However, Kenya adds a distinctive “African Layer”: devolved governance, statutory workforce reskilling as a corporate obligation, and digital inclusion as a core mandate. The result is a “Third Way” of AI regulation, rights-protective in structure, yet explicitly developmental in purpose.

    Final Verdict: Trust-as-a-Service

    The Kenya Artificial Intelligence Bill 2026 is a sophisticated, deliberately opinionated piece of legislation. It refuses to treat AI as merely another software update. It treats AI as a societal shift, one that demands a recalibration of the relationship between technology, commerce, and citizenship.

    The workforce reskilling mandates will generate industry pushback. The personal criminal liability of directors will send a chill through boardrooms. The definitional ambiguities will create compliance uncertainty in the near term.

    But the Bill’s animating logic is sound. In a global technology market increasingly wary of algorithmic bias, opaque decision systems, and unchecked AI power, the Bill offers Kenyan businesses a strategic proposition: “Trust-as-a-Service.”

    A “Made in Kenya” seal of approval, backed by this rigorous, rights-based Act, could become East Africa’s most valuable technology export credential. Not a constraint on innovation. A premium attached to it.

    The Silicon Savannah is getting a fence. Our job, as Innovators, lawyers, founders, and operators, is to ensure it functions as a gateway to the global digital economy.

    Not a wall. A gateway.

    Navigate Kenya’s AI Bill 2026 with confidence.

    MN Legal’s LegalTech practice provides end-to-end AI compliance advisory for Kenyan businesses, corporates, and multinationals, from risk triage and workforce assessments to board-level governance frameworks.Speak With Our Team Today →

    Explore more analysis from our team at our legal insights.


    Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific legal guidance on your situation, please contact our team. © 2026 MN Legal. All rights reserved.

  • Mauritius – An Emerging Hub for Fintech & Payment Solutions in Africa

    Mauritius – An Emerging Hub for Fintech & Payment Solutions in Africa

    Mauritius – An Emerging Hub for Fintech & Payment Solutions in Africa

    In the past decade, Mauritius has emerged as a strategic location for a variety of financial services in Africa. Under the guidance of the Mauritius Financial Services Commission (FSC), a robust framework now exists for the regulation of derivatives activities, payment & banking services, as well as digital asset / virtual currency projects. 

    Payment Services for Africa & The Globe

    Starting off with payment services, Mauritius offers two distinct licenses: Payment Intermediary Services (PIS) and Payment Service Provider (PSP). There are major differences between these licenses which are worth delving into greater detail. 

    The major distinction between the PIS and PSP license is that the former is overseen by the Mauritius FSC while the Bank of Mauritius issues all PSP licenses. From our professional experience, the PIS license is more attractive due to lower capital requirements (2,000,000 MUR), a speedier license approval period as well as lower substance requirements. Furthermore, the PIS license is a better fit for cross-border payment services with the PSP license being issued primarily for local business in Mauritius itself. Finally, the Payment Intermediary Services license focuses primarily on card issuance services. Experience has shown that higher demand exists for card and mobile payment services throughout Africa, making the PIS license a better fit for the majority of new payment projects.  

    Derivatives & Virtual Currency

    Moving on to exchange traded products, Mauritius has two distinct regulatory paths for brokers and digital asset providers / crypto exchanges. On the brokerage side, the FSC has a unique license class for brokerage services, known as an Investment Dealer. This license allows one to offer brokerage services in derivatives, stocks, and futures which can be used to target a global audience. An additional benefit of the Investment Dealer license is the underwriting permission. By upgrading the Investment Dealer license to this permission set, licensed brokerage firms in Mauritius will have the ability to initiate stock listings on the Mauritius public stock exchange. 

    In addition to derivatives regulation, Mauritius also for the establishment of fully regulated digital asset firms. VAITOS 2021, which is the regulatory framework for crypto licensing in Mauritius, sets the standard for Virtual Asset Service Provider (VASP) regulation. Licensed activities include: exchange permissions, wallet services, custodian of tokens, and exchange services. 

    Investment Banking Activities

    Finally, the Mauritius FSC also provides a clear pathway for the establishment of an Investment Banking license. A key advantage is flexibility as a variety of financial activities are permitted under this license. Examples of permitted activities include: merger & acquisition advisory, asset management, securities dealing, the underwriting of securities, as well as corporate finance. It is important to highlight that receiving deposits and other types of banking activities do require separate authorisation from the Bank of Mauritius, making a clear distinction between investment and commercial banking activities. 

    In addition to this level of flexibility, Mauritius offers two major incentives to firms looking to establish a presence on the island. First, Mauritius currently has 46 Double Tax Agreements with a variety of countries around the world, examples include China, South Africa, UK and France. Additionally, any new investment bank will enjoy a 5 year tax holiday from the standard 15% corporate tax rate. 

    Discover the Benefits of Mauritius Regulation Today!

    As interest in mobile payment services and digital assets continues to grow throughout Africa and the world, Mauritius will remain the ideal jurisdiction for the quick and efficient regulation of these emerging financial services. We hope this brief overview was useful in providing a basic introduction to Mauritius.

    For many businesses, it strikes the right balance between innovation and compliance.

    At MNL Advocates LLP, we work closely with fintech companies, financial institutions, and investors to navigate complex regulatory landscapes across Africa and offshore jurisdictions such as Mauritius.

    Our support includes:

    • Advising on the most suitable licensing structures (PIS, PSP, VASP, Investment Dealer, Investment Banking)
    • Managing end-to-end license applications and regulatory engagement
    • Structuring cross-border operations and corporate entities
    • Drafting compliance frameworks and internal policies
    • Providing ongoing legal and regulatory support
    • Acquisition of a fully licensed Investment Dealer or VASP firm.

    Whether you are launching a fintech startup or expanding an existing operation, our team is well-positioned to guide you through every stage of the process.

    Have questions or exploring Mauritius as your next hub? Get in touch with MNL ADVOCATES LLP to start the conversation.

  • Kenya’s VASP Act 2025: What It Means for Foreign Investors and Operators

    Kenya’s VASP Act 2025: What It Means for Foreign Investors and Operators

    Kenya’s VASP Act 2025: What It Means for Foreign Investors and Operators

    Kenya’s enactment of the Virtual Asset Service Providers Act 2025 is the most significant development in the country’s digital finance regulatory landscape to date. Passed by Parliament in October 2025, the Act establishes the first comprehensive legal framework governing crypto exchanges, digital wallet providers, custodians, and related virtual asset service platforms in Kenya. It marks a decisive shift away from the informal and legally ambiguous crypto environment that preceded it, toward a structured, supervised, and internationally aligned regulatory regime.

    For foreign companies and individuals, who have been among Kenya’s most active blockchain and digital asset sector participants, the implications are both substantial and immediate. This insight sets out what the Act introduces, how it affects foreign operators and investors, and what practical steps responsible organisations should take now, ahead of the implementing guidelines that will give the regime its operational detail.

    Kenya VASP Act 2025 impact on foreign investors and operators abstract blockchain compliance graphic
    Kenya’s VASP Act 2025 transforms the country from a loosely regulated crypto market into a structured, compliance-oriented digital asset environment.

    Important context: The VASP Act 2025 establishes the legislative framework. Implementing guidelines from the National Treasury are awaited. Until those guidelines are issued, certain procedural details including licensing timelines, fee structures, and specific AML/KYC thresholds remain subject to those forthcoming rules. This article reflects the framework as currently enacted.

    1) A formal licensing regime: what it requires and who it covers

    The most structurally significant change introduced by the VASP Act is the requirement that all virtual asset service providers obtain a licence before operating in Kenya. The Act covers a broad range of activities: crypto exchanges, digital wallet operators, custodians, digital asset brokers, token issuers, and platforms facilitating cross-border payments using digital assets. Licensing is supervised jointly by the Central Bank of Kenya and the Capital Markets Authority, reflecting the dual financial and capital markets dimensions of virtual asset activity.

    Infographic showing who needs a VASP licence in Kenya including crypto exchanges, wallet providers, custodians, brokers, token issuers and cross-border payment platforms
    Six categories of virtual asset activity require licensing under the VASP Act 2025, supervised jointly by CBK and CMA.

    For foreign operators, this creates a structural decision point. Informally onboarding Kenyan users from offshore is no longer a viable or legally defensible model. Foreign VASPs must either obtain a local licence, which involves meeting fit and proper requirements and satisfying the CBK and CMA’s supervisory expectations, or operate through a licensed Kenyan VASP partner under a model that allocates responsibilities clearly between the parties.

    This approach mirrors the direction taken by regulators in the EU, Singapore, and the UAE, all of whom have moved to require territorial authorisation or regulated partner arrangements for virtual asset activities affecting their residents. Kenya’s decision to align with that direction raises its standing among internationally operating digital finance businesses and signals that the country intends to be a credible regulatory jurisdiction rather than a permissive offshore gateway.

    2) AML/KYC and consumer protection standards

    The VASP Act introduces mandatory anti-money laundering and know-your-customer obligations for all licensed providers. This includes customer identity verification, ongoing transaction monitoring, and suspicious activity reporting. Consumer protection safeguards are also embedded in the framework, addressing fraud prevention, data misuse, and the standards of disclosure owed to users of digital asset platforms.

    For foreign investors using Kenyan platforms, the practical consequence is that the anonymous or lightly verified access that characterised earlier market participation is no longer available. Identity verification will be required and enforced. For foreign firms operating in Kenya, AML compliance is an additive obligation that sits alongside their home-country AML framework, increasing the operational complexity and cost of serving the Kenyan market.

    The longer-term benefit, however, is a more trusted and fraud-resistant market. The period before the VASP Act saw a significant number of unregulated offshore platforms operating in Kenya, some of which exposed users to exit scams, insolvency events, and fraud with no regulatory recourse. The new framework is specifically designed to close that gap.

    3) Cross-border investment and remittances

    Kenya is consistently ranked among the highest-adoption crypto markets globally, and a significant portion of that activity is remittance-driven. The VASP Act acknowledges the importance of digital assets in cross-border financial flows and provides a legal structure within which those flows can operate with certainty.

    Diaspora communities and foreign workers in Kenya benefit from a predictable, legally recognised framework for using digital asset platforms to send and receive funds. Transactions through licensed VASPs will be documented and compliant, which carries secondary benefits: those records can support immigration, tax, and financial reporting obligations in other jurisdictions. Foreign fintech businesses with a cross-border remittance focus gain access to a regulated Kenyan operating environment that was previously unavailable to them in a structured form.

    Kenya’s established position in mobile money, built significantly through M-Pesa’s growth, and its large crypto adoption base make it a strategically important market for any firm seeking East African expansion with digital asset capabilities. The VASP Act gives that expansion a compliant and structured pathway.

    4) A more orderly market: what the removal of unregulated operators means

    One of the most commercially significant effects of the VASP Act is the exclusion of unlicensed foreign platforms from the Kenyan market. Before the Act, offshore entities with no local presence, no supervisory accountability, and no compliance infrastructure could and did operate in Kenya. The consequences for Kenyan users were well-documented: fraud exposure, custody risks, and losses from platform failures with no legal recourse.

    Infographic showing opportunities and obligations for foreign operators under Kenya VASP Act 2025
    The VASP Act creates both a compliance obligation and a commercial opportunity for foreign operators who choose to engage properly.

    The Act changes this materially. Unregistered foreign platforms are barred from serving Kenyan clients. Foreign investors engaging with the Kenyan digital asset market are directed toward licensed, regulated, and accountable entities. The reduction in regulatory ambiguity also helps foreign individuals whose trading or investment activity from within Kenya previously created uncertainty for tax reporting and cross-border financial disclosure purposes.

    5) Compliance obligations vs reduced legal risk

    The VASP Act increases the compliance obligations of foreign companies seeking to participate in the Kenyan market. This includes audit requirements, transaction reporting, record retention, cybersecurity standards, and the resourcing of compliance functions capable of meeting ongoing supervisory expectations. These costs are real and should be factored into any market entry plan.

    Against that, the Act removes the legal uncertainty that previously made institutional engagement with the Kenyan crypto market difficult. Banks, telecom operators, and regulated financial institutions that were reluctant to partner with crypto firms, due to the absence of a legal framework and the reputational and regulatory risk of association with unregulated entities, have a clearer basis for engagement once licensing becomes operational. For larger foreign players, this unlocks commercial relationships that were structurally blocked before the Act.

    6) Tax transparency and reporting implications

    Although the VASP Act is not a tax statute, its licensing and record-keeping architecture supports the broader direction of Kenya’s digital economy tax policy. Kenya has been developing its approach to taxation of digital market participants, and the documentation trail created by licensed VASP operations provides infrastructure on which tax obligations can be more accurately assessed and enforced.

    For foreign crypto investors, this means a greater likelihood of clearer and enforceable tax obligations on Kenya-related digital asset activity. Foreign VASPs operating locally will need reporting systems capable of supporting both domestic tax filings and, where applicable, cross-border information exchange obligations. For foreign individuals transacting through Kenyan exchanges, structured records create a more straightforward basis for international tax compliance, which is increasingly expected by regulators in major economies.

    7) Summary: the dual impact on foreign participants

    The VASP Act transforms Kenya from a loosely regulated and legally uncertain crypto market into a structured digital asset environment with compliance standards comparable to leading international jurisdictions. For foreign participants, the impact falls into two categories that operate simultaneously.

    On the opportunity side, the Act provides legal certainty for compliant foreign firms, a legitimate gateway for East African market expansion, the possibility of institutional partnerships with banks and regulated financial entities previously unavailable, and a safer operating environment for foreign individuals using digital asset platforms for trading, investment, or remittances.

    On the obligation side, the Act requires local licensing or a licensed partner arrangement, ongoing AML/KYC compliance, consumer protection adherence, transaction reporting and record-keeping, and cybersecurity standards. These obligations are not trivial, but they are the standard expected of any serious digital finance business operating in a regulated market.

    Infographic showing five-step VASP compliance readiness guide for foreign firms entering Kenya
    Foreign firms should begin compliance readiness planning now, ahead of the implementing guidelines.

    Strategic point: The firms that will be best positioned when implementing guidelines are released are those that begin compliance readiness planning now: classifying their activities, assessing their licensing pathway, and building the internal frameworks that any licence application will require.

    How MN Legal helps

    MN Legal supports virtual asset businesses, fintech operators, and foreign investors navigating Kenya’s evolving digital asset regulatory landscape. As implementing guidelines from the National Treasury are issued, our regulatory and fintech team will be ready to support clients with precision and depth.

    Our support covers

    Preparing and submitting VASP licence applications, including documentation and regulatory engagement with CBK and CMA. Designing compliant AML/KYC and risk management frameworks tailored to Kenya’s revised standards. Structuring market entry strategies for foreign firms, including subsidiaries, partnership models, and local agent arrangements. Developing internal policies, governance systems, and reporting mechanisms to ensure ongoing compliance. Advising on tax, data protection, and consumer protection considerations that arise under the new regime.

    Schedule a consultation  |  Fintech and Regulatory practice

    FAQ

    What is the Kenya VASP Act 2025?

    The Virtual Asset Service Providers Act 2025 is Kenya’s first comprehensive legal framework governing virtual asset service providers including crypto exchanges, wallet providers, custodians, and related platforms. It was passed by Parliament in October 2025 and introduces licensing, AML/KYC obligations, and consumer protection standards under joint CBK and CMA supervision.

    Do foreign crypto businesses need a licence to operate in Kenya?

    Yes. Under the VASP Act, foreign VASPs can no longer informally serve Kenyan users from offshore. They must either obtain a local licence or operate through a licensed Kenyan VASP partner. The specific licensing procedures will be detailed in the implementing guidelines from the National Treasury.

    When will the implementing guidelines be released?

    The implementing guidelines are expected from the National Treasury but had not been released at the time of writing. The practical details of licensing procedures, fee structures, and specific compliance thresholds will be contained in those rules. Monitoring their release and preparing in advance is the recommended approach.

    What does the VASP Act mean for foreign individuals using Kenyan platforms?

    Foreign individuals will face identity verification requirements under AML/KYC standards. In exchange, they gain a more regulated and fraud-resistant environment. Documented transactions through licensed platforms may also support tax and financial reporting obligations in their home jurisdictions.

    How should a foreign firm start preparing for VASP Act compliance?

    The recommended starting point is to classify your activities under the Act, assess whether a local licence or a licensed partner model is appropriate, begin building AML/KYC and risk management frameworks, and align data protection and cybersecurity standards with what a licence application will require. Legal structuring advice at this stage reduces rework when implementing guidelines are issued.


    Disclaimer: This article is general information and does not constitute legal or regulatory advice. The VASP Act 2025 implementing guidelines had not been released at the time of publication. Requirements may change as guidelines are issued. Consult a qualified Kenyan regulatory lawyer for advice specific to your business model and activities.

  • Legal Compliance for Hiring in Kenya: A Guide for Foreign Companies and SMEs.

    Legal Compliance for Hiring in Kenya: A Guide for Foreign Companies and SMEs.

    Employing People in Kenya: A Legal Compliance Guide for Foreign Companies and Growing SMEs

    The first hire in a new market is where many foreign employers discover that employment law has practical consequences. Kenya’s employment framework is procedurally demanding, statutory in its obligations, and increasingly data-aware. Getting it right from the start is measurably cheaper than correcting it under pressure.

    Employing people in Kenya legal compliance guide for foreign companies and SMEs featured header
    Employment compliance in Kenya starts before the first contract is signed.

    This guide covers the compliance areas that matter most for foreign employers: classification, contracts, statutory setup, work permits, employee data, and termination procedure. It includes sector notes for technology, professional services, and manufacturing, and is accompanied by a downloadable employer compliance checklist.

    Practical framing: Many employment disputes and compliance exposures that reach lawyers are preventable. They typically result from one of three failures: the wrong classification, an absent or deficient contract, or a termination handled without following the required procedure.

    1) Employee or contractor: get this right first

    Classification is the decision that precedes every other employment compliance question. It determines which statutory deductions apply, what rights the individual holds, and whether unfair dismissal protections are available. Critically, a written agreement that describes someone as a contractor does not, on its own, determine their legal status.

    Kenyan courts and the Employment and Labour Relations Court look at the substance of the relationship, not the label. A person who works exclusively for one business, uses the business’s tools, is integrated into its operations, and has tax deducted at source is likely to be treated as an employee regardless of what the agreement says.

    Employee versus contractor classification test in Kenya showing six practical indicators

    A written agreement alone does not determine employment status in Kenya.

    The practical risk of misclassification is threefold: unpaid statutory contributions and associated penalties, tax exposure, and unfair dismissal claims if the engagement is terminated without following the employment procedure. Many foreign employers inherit this risk from early-stage arrangements that were not revisited as the engagement matured.

    Practical action: If you have contractors who work exclusively for your business, have been engaged for more than a few months, and are integrated into your workflows, review their classification before scaling or restructuring.

    2) The employment contract: what must be in writing

    Kenya’s Employment Act requires that certain information be provided to an employee in writing. Foreign employers often use home-country templates which typically miss Kenya-specific requirements and can create enforceability gaps or ambiguity on termination, post-employment obligations, and dispute resolution.

    A compliant Kenya employment contract should address the nature of the employment and probation period, remuneration and the basis of payment, working hours and leave entitlements, notice periods and termination conditions, governing law and the forum for disputes, and any post-employment restrictions. Where the employer intends to rely on confidentiality obligations or non-solicitation provisions, these must be proportionate and clearly drafted to have a reasonable prospect of enforcement in a Kenyan court.

    Non-compete clauses deserve particular attention. Kenyan courts apply a reasonableness standard and have in a number of decisions declined to enforce broad or disproportionate restraints. The clause must be limited in scope, geography, and duration to have a realistic chance of standing.

    3) Statutory registrations and payroll setup

    Before the first payroll run, three statutory frameworks require attention: PAYE administered through KRA, NSSF contributions, and SHIF contributions which replaced the former NHIF structure. These obligations arise at the point of hiring and late or missing remittances attract penalties.

    Kenya statutory employer obligations showing PAYE, NSSF and SHIF requirements at a glance

    Statutory registrations should be in place before the first payroll cycle.

    Beyond the mechanics of remittance, payroll compliance also requires accurate and timely payslips, recordkeeping for audit purposes, and the ability to produce records on demand from regulators or in litigation. Foreign employers should confirm that their payroll systems can generate Kenya-compliant outputs from day one.

    Key references: Kenya Revenue Authority, NSSF, and SHIF.

    4) Work permits and immigration for foreign staff

    Foreign nationals working in Kenya require an appropriate work authorisation before commencing employment. The permit category depends on the nature of the role, the level of the individual, and in some cases the sector. Permit applications involve documentation of the employer, the role, and the individual, and timelines should be factored into hiring plans.

    Kenya’s immigration framework also engages citizen-to-foreigner ratio considerations in certain sectors. Foreign employers should confirm the applicable requirements for their industry before making overseas hires and should treat permit renewals as a calendar-managed compliance item, not an ad hoc task.

    Reference: Department of Immigration Services.

    Practical tip: Start work permit applications as early as possible. Processing times can affect onboarding plans, and a foreign employee working without the correct authorisation creates legal risk for the employer.

    5) HR data and employee privacy

    Employment generates significant personal data: identity documents, payroll records, performance history, health information, device and system access logs, and in some cases location data or biometric attendance records. Kenya’s data protection framework applies to this data, and employers should not assume that existing home-country privacy notices and policies are sufficient.

    A defensible employment data posture includes a clear HR privacy notice that tells employees what data is collected, why, how long it is retained, and who it is shared with. It also requires appropriate vendor terms for payroll providers, HR platforms, and cloud-based systems. Where biometric data is used for attendance or access control, a higher standard of care is required, including risk assessment and documented justification.

    The ODPC has published guidance and issued determinations that are relevant to employer data practices. The safest approach is to treat HR data compliance as part of market entry, not a post-launch consideration. Reference: Office of the Data Protection Commissioner.

    6) Discipline and termination: the procedural standard

    This is the area where foreign employers most frequently face exposure, because the Kenyan employment framework is procedurally demanding in a way that differs from many other jurisdictions. An employer may have a substantively valid reason for dismissal and still face an unfair dismissal finding if the required procedure was not followed.

    Termination in Kenya procedural requirements flow showing five steps from valid reason to right of appeal

    Procedural failure can result in an unfair dismissal finding even where the substantive reason for dismissal is valid.

    The procedure requires that the employee receives written notice of the allegation, is given a genuine opportunity to respond and be heard, receives a written decision, and is offered an internal right of appeal. Documentation at each stage is essential: if the procedure is not evidenced, it is difficult to defend.

    Redundancy is separately regulated and requires a different process that includes notice to the relevant authority, notification to the union where applicable, and payment of redundancy entitlements. Foreign employers planning workforce restructuring should not apply home-country redundancy procedures in a Kenyan context.

    7) What to have in place before you scale

    Employment exposure grows as headcount grows. Small teams often operate on informal arrangements that become difficult to manage as the business scales. The transition point, where employment records, policies, and procedures need to be formalised, is typically earlier than most founders expect.

    Practically, employers should have written contracts for all staff, an HR data policy and privacy notice, a basic disciplinary and grievance procedure, payroll records that are complete and audit-ready, and documented onboarding that includes statutory disclosures. For employers using commission-based, flexible, or non-standard arrangements, the terms should be clear, documented, and consistent with statutory minimums.

    8) Sector notes

    Technology and SaaS businesses

    Tech businesses often rely heavily on contractor arrangements for product development and sales. Classification risk is particularly acute where contractors are embedded, exclusive, and long-term. IP assignment clauses in employment and contractor agreements are critical: the default position on who owns work created by an employee or contractor may not align with what the business intends. HR data exposure is also higher where platforms, devices, and access systems generate significant volumes of employee metadata.

    Professional services businesses

    Professional services firms face particular risk around restrictive covenants, client relationship ownership, and the enforceability of non-solicitation provisions when senior staff depart. Employment contracts in this sector should address client and staff solicitation, confidential information obligations, and gardening leave in a way that is proportionate and likely to be upheld.

    Manufacturing and industrial businesses

    Manufacturing employers should pay particular attention to working hours compliance, overtime calculations, health and safety obligations, and the statutory rules around collective bargaining where staff numbers are significant. Redundancy processes in this sector require careful management given union engagement obligations and the reputational and operational risks of a poorly handled workforce restructuring.

    9) Download the Kenya Employer Legal Compliance Checklist (2026)

    Kenya Employer Legal Compliance Checklist 2026 gated PDF cover

    Kenya Employer Legal Compliance Checklist (2026)

    A 12-area PDF checklist covering every employment compliance obligation for employers in Kenya, from pre-hire classification through to termination and post-employment obligations. Used by HR leads, COOs, and compliance teams at foreign companies expanding into Kenya.

    Covers: classification, contracts, statutory deductions, work permits, HR data, discipline, termination, and more.

    Download the Checklist (Free PDF)

    You will receive the checklist by email. No spam.

    FAQ

    Do foreign companies need written employment contracts in Kenya?

    Yes. Kenya’s Employment Act requires written contracts for most employment relationships. Using a home-country template without localisation can create enforceability gaps and compliance exposure.

    What happens if we misclassify an employee as a contractor?

    Misclassification creates exposure across three areas: unpaid statutory contributions and penalties, tax liability, and the risk of unfair dismissal claims on termination. Classification is determined by the substance of the relationship, not the label in the agreement.

    Can we terminate an employee in Kenya without a formal process?

    No. Kenyan employment law requires a procedurally fair process including notice of the allegation, a hearing, a written decision, and an opportunity to appeal. Skipping steps can result in an unfair dismissal finding even where the reason for termination is substantively sound.

    Are non-compete clauses enforceable in Kenya?

    They can be, but only if they are proportionate in scope, geography, and duration. Broad or poorly drafted non-compete clauses are regularly declined enforcement by Kenyan courts.

    What data protection obligations apply to HR data in Kenya?

    Employee data is subject to Kenya’s data protection framework. Employers should maintain HR privacy notices, appropriate vendor terms, and documented data handling policies. Biometric processing for attendance requires heightened care. Reference: ODPC.


    Need an employment contract review or HR compliance audit for Kenya?

    MN Legal supports foreign companies and growing SMEs with employment contract localisation, statutory compliance setup, work permit guidance, HR data governance, and termination procedure advice.

    Contact MN Legal  |  Employment and Labour practice


    Disclaimer: This article provides general information and does not constitute legal or employment advice. Requirements can change and may depend on your sector, workforce structure, and operating model. Consult a qualified Kenyan employment lawyer for advice on your specific facts.

  • Entering the Kenyan Market: A Practical Legal Roadmap for SMEs

    Entering the Kenyan Market: A Practical Legal Roadmap for SMEs

    Kenya is a strong gateway into East Africa, with a mature services economy and a growing technology and consumer base. For foreign SMEs, the opportunity is real, but the first ninety days often determine whether expansion is smooth or whether the business spends months correcting avoidable compliance gaps.

    This guide is a practical legal roadmap focused on two foundations: incorporation and compliance. It is written for foreign SMEs who want a clear sequence of steps, realistic expectations, and a defensible operating posture.

    Entering the Kenyan market legal roadmap for SMEs with Nairobi skyline and checklist motif
    Plan entry as a sequence: structure, incorporation, registrations, and compliance controls.

    Practical framing: Treat incorporation as the start of operations, not the end of setup. Tax registration, employment readiness, data protection, and sector licensing are where market entry succeeds or stalls.

    1) The First 90 Days: A Realistic Timeline for Foreign SMEs

    Market entry is rarely linear. The fastest approach is to run tasks in parallel, while keeping the legal sequence correct. The timeline below is a practical planning tool. It is not a promise of regulator processing time, which can vary.

    Use a 90-day plan to coordinate incorporation, tax, hiring, privacy, and sector approvals.

    Need a Tailored Entry Plan?

    If you share your sector, revenue model, and hiring plan, we can map the relevant registrations, licensing triggers, and the most efficient sequence.

    Contact MN Legal

    2) Choose the Right Entry Structure and Avoid Expensive Rework

    Your entry structure affects liability, tax posture, banking onboarding, licensing, and your ability to hire and contract locally. Many foreign SMEs default to a local company without checking whether a subsidiary, branch, or distributor model best fits their operating plan.

    A structure choice should match your contracting needs, tax plan, and licensing pathway.

    Subsidiary

    A Kenyan private company limited by shares is often the preferred structure for foreign SMEs seeking local operational flexibility, easier contracting, and a clearer separation of liability from the parent.

    Branch

    A branch can work where the foreign parent wants to operate directly and keep governance centralised. It may, however, present different tax and risk implications and can be perceived as less local for certain procurement and banking workflows.

    Distributor or Agent Model

    This can be a lower overhead route to test the market, but it shifts risk into contracts. If you enter through an intermediary, your agreements must address IP protection, pricing control, compliance obligations, and termination.

    3) Incorporation and BRS Filings: What the Process Looks Like

    Most company registration is processed through the Business Registration Service using the government eCitizen platform. In practice, delays usually come from incomplete documentation, unclear ownership chains, or inconsistencies in director and shareholder details.

    Filing portals and references: eCitizen and Business Registration Service.

    Foreign SMEs should plan beneficial ownership disclosures early, especially where a shareholder is a foreign company and the ownership chain is multi-layered. Cleaning this up after filing can create unnecessary friction with banks and counterparties during onboarding.

    4) Tax and Statutory Registrations: Align Early With How You Will Trade

    Tax posture should be addressed at the beginning, not after revenue starts. It affects pricing, invoicing, contract drafting, and cash flow. Registration and ongoing compliance requirements depend on your model, including whether you hire staff, import goods, or provide taxable services.

    Authority reference: Kenya Revenue Authority.

    Practical tip: Align your contracting and invoicing templates to your tax plan early. A common expansion mistake is signing customer contracts before the tax and invoicing model is settled.

    5) Employment and Payroll Readiness: Plan Before the First Hire

    Hiring is often the first operational move after incorporation. That is also where compliance risk begins to compound. SMEs should treat employment documentation, payroll systems, and statutory registrations as part of market entry, not an HR afterthought.

    Key agency references: NSSF and SHIF.

    6) Data Protection Compliance: A Common Blind Spot for Foreign SMEs

    If you collect personal data in Kenya including customer data, employee data, prospect lists, or analytics identifiers data protection compliance should be treated as a baseline operational requirement. This is especially true if you use a CRM, third-party marketing platforms, payroll providers, cloud hosting, or cross-border processing.

    Regulator reference: Office of the Data Protection Commissioner.

    A defensible posture typically requires clear privacy notices, appropriate vendor terms, and evidence that rights requests and opt-outs are handled reliably. Where processing is high-risk, an impact assessment is a practical safeguard, even where it is not explicitly demanded in every scenario.

    7) Sector Licensing and Permits: Confirm Triggers Before You Sign Leases or Launch

    Many foreign SMEs underestimate the number of licences and approvals that can apply depending on sector and county. Licensing triggers can affect timelines, banking onboarding, and procurement. The best approach is to map licensing requirements before signing a lease, importing equipment, or launching customer acquisition.

    Where relevant to your sector, you may also need approvals from sector regulators. For energy-related business models, see: EPRA.

    8) Common Mistakes Foreign SMEs Make and How to Avoid Them

    Mistake One: Incorporating Before Confirming Licensing and Tax Implications

    This leads to restructuring, amended contracts, and launch delays. Avoid it by mapping the revenue model, staffing plan, and regulated activities before filing.

    Mistake Two: Using Generic Templates for Kenya Contracts

    Templates often miss Kenya-specific issues such as tax clauses, limitation of liability, dispute resolution, and enforceability details. Localisation is cheaper than litigation or renegotiation.

    Mistake Three: Delaying Privacy Compliance Until After Launch

    Once you onboard staff or customers, you are processing personal data. Early privacy-by-design is almost always less costly than remediation after complaints.

    FAQ

    Can we incorporate in Kenya without a physical visit?

    Many steps can be coordinated remotely, depending on documentation and onboarding requirements. Banking and sector licensing can require additional local coordination.

    Which structure is best for a foreign SME?

    It depends on liability appetite, tax strategy, licensing requirements, and how you intend to hire and contract locally. A subsidiary is common, but not always optimal.

    Which agencies are usually involved early?

    Common touchpoints include BRS via eCitizen, KRA, statutory payroll agencies such as NSSF and SHIF, and ODPC for data protection compliance where relevant.


    Next Step: Get an Entry Plan You Can Execute

    If you are a foreign SME expanding into Kenya, a short scoping call can clarify your structure, registrations, licensing triggers, and the most efficient setup sequence for your first 90 days.

    Make an enquiry

    Disclaimer: This article provides general information and does not constitute legal or tax advice. Requirements can change and may depend on your sector, ownership, and operating model.

  • Guide to Licensing Payments in Kenya: A Strategic Approach

    Guide to Licensing Payments in Kenya: A Strategic Approach

    PSP and e-money pathways, VASP developments, and compliance as a commercial asset for fintechs operating in Kenya.

    Kenya’s payments market is often described in the language of speed: faster checkout, instant transfers, real-time settlement, embedded finance. That narrative is accurate but incomplete. Payments innovation at scale is not only a product story. It is a regulatory perimeter story, and increasingly a governance and resilience story.

    When a business operates in payments in Kenya, whether through a gateway, a digital wallet, merchant acquiring, or a platform layered onto mobile money rails, the question that matters is not simply whether the product works. It is whether the product is operating inside a licensing framework that regulators, counterparties, and sophisticated customers can recognise as safe.

    Key insight: Licensing is not merely an approval step. It is an operating standard testing capital, governance, AML/CFT readiness, cybersecurity, reporting capability, and data governance.

    Contents

    1. The core shift: licensing as operational readiness
    2. Who regulates payment services in Kenya
    3. The payments licensing perimeter
    4. PSP licensing pathways: why “PSP” is not one licence
    5. Virtual assets: what the VASP Act signals
    6. When payments drifts into banking-style regulation
    7. Compliance as a commercial asset
    8. Timelines and capital: planning realistically
    9. FAQ

    1. The Core Shift: Licensing as Operational Readiness

    Early-stage teams sometimes treat licensing as a binary hurdle: licensed or not licensed. In practice, regulators treat licensing as a continuous assurance framework. It requires firms to demonstrate, before launch and throughout operations, that they can manage financial risk, conduct and consumer risk, financial crime risk, technology and operational risk, and data governance.

    This changes how founders should plan. If licensing is treated as a late-stage filing exercise, it often collides with reality: incomplete governance, unclear control ownership, weak documentation, and vendor arrangements that do not match the regulatory story the firm wants to tell.

    2. Who Regulates Payment Services in Kenya

    For most payment service providers and payment systems, the Central Bank of Kenya (CBK) is the anchor regulator under the National Payment System framework. CBK’s focus is pragmatic: safeguarding the integrity and stability of the payment ecosystem and protecting users.

    Depending on the business model, other authorities may also be relevant:

    • Capital Markets Authority (CMA) where virtual assets or investment-adjacent features appear.
    • Communications Authority where telecom rails or authorisations are integral to the model.
    • Financial Reporting Centre (FRC) for AML/CFT reporting obligations.
    • Office of the Data Protection Commissioner (ODPC) for data protection compliance.
    • Kenya Revenue Authority (KRA) for tax compliance.

    3. The Payments Licensing Perimeter: Substance Over Labels

    The fastest way to understand licensing is to describe the product functionally rather than in marketing terms. Regulators are generally less interested in whether a product is called a “platform” or a “technology provider,” and more interested in what it controls:

    • Transaction initiation and processing.
    • Issuance of stored value.
    • Operation of a payment instrument or payment system.
    • Control over settlement flows.
    • The integrity of communications to users.

    In practical terms, licensing outcomes often turn on where the business sits in the value chain: whether it is processing payments, operating payment rails, issuing e-money, or touching customer funds even briefly.

    4. PSP Licensing Pathways: Why “PSP” Is Not One Licence

    “PSP licence” is commonly used as shorthand, but in practice there are distinct categories that reflect different risk profiles, particularly the distinction between facilitating payments and issuing stored value.

    Electronic Retail Payments and Transfer Services (Without E-Money)

    This category generally captures providers facilitating electronic retail payment transactions such as gateways, acquiring and processing, and bill payments, without issuing stored value.

    Small E-Money Issuer (SEMI)

    SEMI structures recognise that some wallet products are low-value or limited in scope. While thresholds may differ, the underlying supervisory expectations remain meaningful: governance, AML/CFT controls, cybersecurity posture, and reporting capability must be credible.

    E-Money Issuer

    Where a platform issues, stores, and redeems e-money, particularly where it is usable with third parties, the regulatory intensity typically rises. At this level, safeguarding structures, reconciliations, consumer risk, and operational resilience become central.

    Payment Instruments and Payment Systems

    Where a business owns or operates payment instruments or systems, including switching or settlement-adjacent infrastructure, the authorisation posture can shift again, particularly where scale raises systemic considerations.

    5. Virtual Assets: What the VASP Act Signals for Kenya Fintechs

    Kenya’s Virtual Asset Service Providers Act, 2025 signals a formal shift toward licensing and supervision of digital asset activity. While implementing regulations and guidelines are awaited, the strategic implication for product teams is immediate: classify activities honestly (custody, exchange, issuance, advisory) and build for licensing readiness in governance, AML/CFT maturity, cybersecurity controls, and defensible disclosures.

    6. When Payments Drifts Into Banking-Style Regulation

    A common strategic risk is designing a payments product that quietly begins to resemble deposit-taking or bank-like services. Where a model involves deposit-like accounts, savings behaviour, or lending structures, the licensing framework can shift into a materially stricter regime under the Banking Act.

    Product design should therefore be treated as regulatory design, particularly where the roadmap includes credit, savings, or account-like features.

    7. Compliance as a Commercial Asset for Kenya Fintechs

    For growth-stage fintechs, licensing and compliance are often viewed as cost centres. In reality, they are frequently deal accelerators. Sophisticated counterparties increasingly ask for evidence: who owns AML/CFT controls, what cybersecurity standards are implemented, how personal data is handled, what incident response looks like, and whether vendor relationships allocate responsibilities clearly.

    Firms that can answer these questions with coherent documentation, including governance papers, policies, logs, and enforceable contracts, move faster in negotiations and inspire confidence in partners and investors.

    8. Timelines and Capital: Planning Realistically

    Licensing is a project, not a form. A realistic plan allows time for pre-application engagement, application review, regulator queries, and final issuance steps. Depending on the model and readiness, timelines can extend over several months and, in some cases, closer to a year.

    Minimum capital requirements vary by category. Examples commonly referenced for certain PSP categories include:

    • Small E-Money Issuer (SEMI): KES 1,000,000
    • Electronic retail payments services: KES 5,000,000
    • E-Money Issuer: KES 20,000,000
    • Designated payment instrument issuer: KES 50,000,000

    Capital, however, is rarely the only determinant of speed. Governance and operational controls are often what determine momentum through the licensing process.

    MN Legal supports clients across the lifecycle of payment and digital finance businesses, from early model structuring to licensing submissions and ongoing compliance posture. This includes mapping transaction flows to the right authorisation pathway, preparing governance and compliance documentation, aligning AML/CFT and operational resilience expectations, advising on data protection governance, and structuring partner and vendor contracts so the operating model matches the regulatory position.

    Make an enquiry  |  Explore Practice Areas

    Frequently Asked Questions

    What licence does a payment service provider need in Kenya?

    It depends on the model. The CBK regulates most PSP activity under the National Payment System framework. The right category depends on whether the business is processing payments, issuing e-money, operating payment instruments, or touching settlement flows. There is no single “PSP licence.”

    How long does payment licensing take in Kenya?

    Realistically, several months from pre-application engagement to issuance, and in some cases closer to a year. Governance and operational controls readiness often determines pace more than capital alone.

    What does the VASP Act mean for digital asset businesses in Kenya?

    The Virtual Asset Service Providers Act, 2025 introduces a formal licensing and supervision framework for digital asset activity. Businesses should classify their activities honestly and begin building for licensing readiness now, ahead of implementing regulations.

    Can a payments product drift into banking regulation?

    Yes. Where a model begins to resemble deposit-taking, savings, or lending, the applicable framework can shift toward the Banking Act, which carries significantly stricter requirements. Product design should be treated as regulatory design from the outset.

    Why does licensing matter commercially, not just regulatorily?

    Sophisticated partners, investors, and enterprise customers increasingly ask for evidence of governance, AML/CFT controls, cybersecurity posture, and data protection compliance. Firms with coherent documentation move faster in commercial negotiations and due diligence processes.

    How can MN Legal help with Kenya payments licensing?

    MN Legal advises on model structuring, licensing pathway selection, governance and compliance documentation, AML/CFT readiness, data protection governance, and vendor and partner contracting for payment and digital finance businesses operating in Kenya.


    Disclaimer: This article is for general information only and does not constitute legal advice. Licensing requirements vary by jurisdiction and specific facts. For advice on your specific model, contact MN Legal.

  • How Capital Markets Licensing Affects Legal Tech Providing Investment, Crowdfunding or Securities Solutions

    How Capital Markets Licensing Affects Legal Tech Providing Investment, Crowdfunding or Securities Solutions

    The most commercially successful legal-tech products in capital markets are often the least dramatic: tools that help licensed
    intermediaries keep clean records, onboard investors efficiently, deliver disclosures with audit trails, and demonstrate compliance
    during due diligence.

    Yet licensing questions arise precisely because these products sit close to the regulatory frontier. A platform may be built as
    “workflow software” and still be treated as a regulated service if, in substance, it gives investment recommendations, arranges
    transactions, holds client money, or functions as part of the public offering machinery.

    Abstract capital markets licensing and legal-tech compliance graphic (no logos)
    Licensing risk is rarely about labels. Regulators look at function, control, and investor impact.

    Executive summary: Capital markets regulators tend to apply a functional approach. If your platform performs, controls,
    or materially influences regulated activity, licensing or a licensed partner model may be required, regardless of how the product is marketed.

    The licensing perimeter: the standard regulators apply

    Across most capital markets regimes, licensing is not triggered by a company’s branding (“we are a technology company”) but by what
    the company does. This is sometimes described as a substance-over-form or functional approach.

    In practical terms, the perimeter tends to tighten around four activities:
    (i) giving investment advice or making personalised recommendations,
    (ii) arranging, placing, routing, or executing transactions,
    (iii) handling client money, securities, or custody-like flows, and
    (iv) facilitating public offering communications in a way that creates mis-selling or disclosure risk.

    Legal-tech tools can sit safely outside the perimeter when they operate as internal compliance infrastructure for a licensed intermediary
    and remain subject to clear boundaries: the tool supports, records, and evidences; the licensed entity decides, approves, and executes.

    Where legal-tech products typically trigger perimeter concerns

    Licensing risk most often appears not in a single feature, but in the way features combine into a workflow. Products designed for
    investor onboarding, digital disclosures, and transactional workflow can become “front office” infrastructure very quickly.

    Where licensing risk appears in legal-tech products (onboarding, disclosures, transaction flow, custody)

    Onboarding, disclosures, order flow, and custody-adjacent design are the most common perimeter pressure points.

    Investor onboarding and eligibility

    KYC and onboarding tooling is generally defensible when it remains a controlled workflow with clear oversight. Risk escalates when
    the platform begins to make final determinations (who may invest, what products are suitable) without the licensed intermediary’s
    meaningful review, or where the “profiling” output becomes a de facto recommendation.

    Digital disclosures and investor communications

    Digital disclosure tools are often low-risk, and highly valuable, when they solve the evidence problem: document versioning,
    distribution logs, acknowledgements, and audit trails. Concerns arise where communications drift into promotion of an offer to the
    public without adequate controls, or where disclosures are delivered without traceable evidence of what the investor received and when.

    Order and transaction workflows

    Interfaces that display information are one thing; workflows that route orders, “match” investors to opportunities, or control
    execution logic may look like arranging or execution activity depending on the jurisdiction and the facts.

    Custody, payments, and settlement-adjacent flows

    Products that touch client funds directly or through accounts the platform controls require particular care. Even where a third-party
    payment provider is involved, the question regulators ask is who controls the flow and who bears responsibility for safekeeping.

    A practical perimeter test for founders and buyers

    The most efficient way to avoid late-stage licensing surprises is to run an early perimeter test and write down the conclusion.
    Think of it as a short internal legal memo that you can update at every major release.

    Regulatory perimeter test flowchart for legal-tech serving capital markets
    A simple test helps teams classify risk before product scope drifts.

    The test is deliberately plain. It asks: what service is the product enabling; who is the client; who touches money; who influences
    decisions; who executes; and who controls the communications. If the honest answers point toward advice, arranging/execution, custody-like
    flows, or public offer facilitation, then the product should be structured around a licensed entity either by obtaining the relevant
    permissions or by partnering with a licensed intermediary and allocating responsibilities clearly.

    Designing for compliance: standards that travel across jurisdictions

    Legal-tech teams operating internationally need principles that work across regimes even where definitions differ. The following
    standards tend to be robust:

    Build vs partner vs avoid matrix for licensing-sensitive product features
    A product decision matrix keeps commercial teams, engineers, and compliance aligned.

    First, keep regulated functions with the licensed entity where required. Second, build systems that generate evidence: approvals,
    versioning, acknowledgements, exception handling, and user action logs. Third, ensure that governance is not merely documented,
    but operational meaning there are named owners, review points, and the ability to demonstrate what happened in a specific investor journey.

    The strategic benefit is commercial as much as legal. Strong evidence and clearly bounded operating models reduce friction in procurement,
    accelerate partner onboarding, and make regulatory discussions more orderly.

    A realistic scenario: when “crowdfunding software” becomes a regulated service

    Consider a platform built initially to support issuers with document workflows: issuer onboarding, disclosure templates, and investor
    acknowledgements. The tool performs well and demand grows. Then the roadmap adds convenience features: investor “matching,” automated
    eligibility approval, and in-platform collection of funds “to simplify settlement.”

    Each feature looks incremental. Collectively, the platform may now resemble the machinery of a public offer and transaction facilitation.
    At that point, the perimeter question becomes unavoidable: is the platform merely enabling a licensed intermediary, or is it effectively
    arranging participation, influencing investment decisions, and controlling flows that look custody-adjacent?

    The fix is usually not a full rebuild. It is a structural decision: allocate regulated steps to a licensed partner (or obtain the
    necessary permissions), revise workflows to ensure meaningful oversight, and strengthen disclosures and records so the investor journey
    is defensible.

    Governance and documentation: what sophisticated partners will ask for

    Intermediaries, institutional partners, and sophisticated clients increasingly require evidence of regulatory thinking. A premium posture
    is to maintain a living file that includes: a perimeter memo, a feature risk register, an operating model diagram, vendor allocations,
    and a compliance evidence map (what logs exist, who reviews them, and how exceptions are handled).

    This is where legal-tech has an advantage. Unlike traditional paper processes, well-designed systems can produce reliable logs and
    demonstrate accountability. The goal is not to generate paperwork; it is to make compliance auditable.

    How MN Legal helps

    Perimeter advice, partner models, and defensible product workflows

    MN Legal advises legal-tech founders and capital markets intermediaries on regulatory perimeter mapping, licensing and partnering
    structures, disclosure and onboarding workflow design, and the contractual allocation of responsibilities between platforms and
    licensed entities. Where appropriate, we also support incident readiness and records strategy so your compliance posture is
    evidenced not assumed.

    Make an enquiry

    External reference points that inform global standards include
    IOSCO (securities regulation principles),
    FATF (AML/KYC expectations),
    and market regulators such as
    ESMA and the
    FCA.

    FAQ

    Does every investment or crowdfunding tool require licensing?

    No. Many tools remain outside the perimeter when they are genuinely internal compliance or recordkeeping infrastructure for a licensed
    intermediary. Risk depends on function and control particularly advice, arranging/execution, custody-like flows, and public communications.

    What features most often create licensing pressure?

    Personalised recommendations, investor matching/placement functions, order routing or execution logic, custody-adjacent payment flows,
    and public offer communications without robust controls.

    How should international legal-tech teams manage multi-jurisdiction uncertainty?

    Start with consistent standards: a perimeter memo, a feature risk register, a partner model where regulated steps are performed by
    licensed entities, and strong evidence (audit trails, disclosure versioning, acknowledgements, exception workflows).


    Disclaimer: This article is general information and not legal advice. Licensing requirements vary by jurisdiction and facts. For advice on your specific model, contact MN Legal.

  • AI Vendor Contracts: Key Clauses to Demand in 2026

    AI Vendor Contracts: Key Clauses to Demand in 2026

    A practical guide to negotiating AI vendor terms: data use, training limits, security, audit rights, and liability, without slowing procurement.

    AI adoption is now routine. What is not routine is how most organisations buy AI. Many businesses still procure AI tools like ordinary software: click accept, sign an order form, and move on. In 2026, that approach creates avoidable risk. AI changes the procurement risk surface: data may be reused in unexpected ways, outputs may affect customers and employees, and models can change after signature.

    Practical rule: AI risk starts before the first prompt, inside your contract.

    AI vendor contract negotiation: why contracts are where privacy, security, IP, and liability become enforceable
    Contracts are where privacy, security, IP, and liability become enforceable.

    Contents

    1. What changed in 2026 and why AI contracts matter more
    2. The AI procurement risk map
    3. The 12 clauses to demand
    4. Case example: AI support tool adoption
    5. Common mistakes companies make
    6. 30-minute contract review checklist
    7. 30-day implementation plan
    8. FAQ

    1. What Changed in 2026 and Why AI Vendor Contracts Matter More

    Three shifts make AI contracts materially different from standard SaaS procurement:

    • AI is embedded into core operations. Support, marketing, finance, HR, fraud, and analytics workflows increasingly depend on AI features.
    • Models update continuously. What you buy today can change next month, affecting accuracy, cost, and risk.
    • Evidence expectations have increased. Partners and enterprise customers now ask for vendor terms, security posture, and governance controls as part of due diligence.

    Helpful global references include the NIST AI Risk Management Framework and the NIST Privacy Framework.

    2. The AI Procurement Risk Map: What You Are Really Buying

    Before negotiating clauses, align internally on what the tool actually does. Most procurement surprises happen because teams do not map data and decision pathways before signing.

    AI procurement risk map: inputs, processing, outputs, storage, transfers, third parties, and decision pathways
    Map inputs, processing, outputs, storage, transfers, third parties, and who relies on AI decisions before you sign.

    Questions Your Team Should Answer Before Signing

    • Inputs: What data goes in: customer tickets, IDs, HR data, financial data, call recordings?
    • Outputs: What comes out: recommendations, replies, scores, summaries?
    • Training: Does the vendor train on your content by default?
    • Location: Where is data stored and processed? Are there cross-border processing concerns?
    • Third parties: Which sub-processors or model providers are involved?
    • Change control: Can the vendor materially change the model or terms without notice?

    3. The 12 AI Vendor Contract Clauses to Demand in 2026

    12 essential AI vendor contract clauses for 2026: data use, training, security, sub-processors, audit rights, liability
    A practical clause set that aligns AI procurement with privacy, security, and business risk.

    1) Data Use Restrictions

    Limit processing strictly to service delivery. Avoid broad “business purposes” language that could expose your data to reuse you did not intend.

    2) Training and Improvement: Opt-In, Not Default

    Require an explicit opt-in before your data, prompts, or outputs are used to train or improve models. Without this, your confidential information could become part of a vendor’s training dataset.

    3) Retention, Deletion, and Exit Obligations

    Define retention periods, deletion timelines, and how deletion is confirmed after termination. Ensure you have audit rights to verify compliance.

    4) Confidentiality Covering Prompts, Outputs, and Derived Data

    Prompts can contain trade secrets and personal data. Outputs can create sensitive derivatives. Your contract must cover both explicitly.

    5) Security Controls That Are Specific, Not Vague

    Anchor security to concrete commitments: encryption standards, access controls, logging, and vulnerability management. Demand specifics, not general assurances.

    6) Sub-Processor Controls and Change Notifications

    Get an up-to-date sub-processor list, notice periods for changes, and a right to object where risk is high. Ensure flow-down obligations are in place.

    7) Incident and Breach Notification Timelines

    Define notice timelines and cooperation obligations so you can meet your own regulatory and client requirements after an incident.

    8) Audit Rights and Reporting

    Where full audits are not feasible, require structured alternatives: SOC2 or ISO reports, penetration test summaries, and security questionnaires. You need real visibility, not just promises.

    9) Change Control for Material Model Updates

    Require notice of material changes, transparency on impact, and exit or rollback rights where risk or performance materially changes. The model you signed up for may not be the one you are using next month.

    10) IP and Output Rights

    Clarify your rights to use outputs commercially, address restrictions, and ensure your inputs remain your property. Do not assume ownership without a clear contractual basis.

    11) Warranties and Disclaimers

    For critical use cases, avoid accepting “as-is” terms without meaningful commitments on security, performance, or compliance. Negotiate warranties that match your actual risk profile.

    12) Liability Allocation That Matches Risk

    Liability caps and exclusions should reflect the sensitivity of data processed and the impact of the use case. Consider tailored indemnities where appropriate.

    For broader governance guidance, see the EDPB and UK ICO.

    4. Case Example: SME Adopts an AI Support Tool

    A growing services company implements an AI support assistant integrated into its helpdesk. Staff begin pasting screenshots into the tool to speed up ticket resolution. Those screenshots include customer IDs, account details, and internal notes.

    A customer subsequently complains after receiving a response that reveals information that should not have been shared. No security breach occurred. The business now faces a confidentiality issue, a data protection question about what data was processed and under what terms, and commercial risk as clients begin asking for vendor due diligence evidence.

    The first document everyone opens is the vendor agreement. What it says about data use, retention, training, security, incident notice, and cooperation determines how fast and how effectively the business can respond.

    5. Common Mistakes Companies Make in AI Procurement

    • Shadow procurement. Teams buy AI tools without legal or security review, so risk accumulates unnoticed.
    • No AI use register. The business cannot state what AI tools are in use or what data they process.
    • Assuming terms are non-negotiable. Many vendors negotiate, especially for business plans. Always ask.
    • Ignoring cross-border processing. The tool stack is often global by default, creating transfer obligations that go unaddressed.
    • Relying on staff care alone. Without clear policy, training, and technical restrictions, sensitive data will be entered into external tools.

    6. 30-Minute AI Vendor Contract Review Checklist

    30-minute AI vendor contract review checklist: data use, security, change control, sub-processors, and liability
    Use this checklist to triage AI vendor terms before signature.

    MN Legal supports organisations reviewing and negotiating AI vendor contracts and DPAs, mapping cross-border and vendor risk, drafting AI usage policies and governance frameworks, and advising on incident readiness where AI touches personal or confidential data.

    Make an enquiry  |  Explore Practice Areas

    7. What Businesses Should Do Next: 30-Day Plan

    Week 1: Inventory and Ownership

    • Create an AI use register: tool, owner, purpose, data types, vendor, and risk rating.
    • Flag high-risk uses such as customer decisions, HR screening, and sensitive data processing.

    Week 2: Procurement Controls

    • Set a minimum contract standard covering DPA, security, change control, and incident notice.
    • Define when legal and security sign-off is mandatory before a tool is adopted.

    Week 3: Contract Cleanup

    • Negotiate high-risk vendor terms or implement a contractual addendum.
    • Document cross-border processing and sub-processors for critical tools.

    Week 4: Training and Operational Rules

    • Train teams on what data cannot be entered into external AI tools.
    • Implement a practical escalation process for AI incidents such as harmful outputs or data exposure.

    Frequently Asked Questions

    Are AI vendor terms negotiable?

    Often yes, especially for business and enterprise tiers. Where standard terms apply, use addenda to address data use, security, incident notice, audit rights, and change control.

    Do we need a DPA when buying AI tools?

    If the vendor processes personal data on your behalf, you typically need data processing terms covering purpose, security, sub-processors, international transfers, and deletion obligations.

    What if the vendor changes the AI model after we sign?

    Include a change control clause requiring notice of material changes, transparency on impact, and rights to pause, roll back, or terminate if risk or performance materially changes.

    What is the biggest contractual risk in AI procurement?

    Unrestricted data use including training on your content, unclear retention and deletion obligations, weak incident notification requirements, and liability caps that do not match the sensitivity of data or the use case.

    How can MN Legal help with AI vendor contracts?

    MN Legal helps businesses implement practical procurement controls and defensible vendor terms for AI tools, aligned with privacy, security, and commercial realities. If you are procuring AI tools this quarter, a scoped contract and risk review can prevent expensive rework later.


    Disclaimer: This article is for general information only and does not constitute legal advice. Requirements vary by jurisdiction and specific facts. For advice on your organisation’s situation, contact MN Legal.