Back to Blog
Kenya's Draft Payments Bill Would Open Bank and M-PESA Data by Law
Technology

Kenya's Draft Payments Bill Would Open Bank and M-PESA Data by Law

September 23, 2026GashoTech Team

The short version



Kenya's National Treasury and the Central Bank of Kenya published the draft National Payment System Bill, 2026 on 21 September. It repeals and replaces the National Payment System Act, Cap. 491A, the law that has governed Kenyan payments since 2011.

Two things in it matter more than the rest. First, open finance stops being a product decision and becomes a legal obligation. Second, the Bill invents two new licence categories that let a company move money and read account data without holding a shilling of customer funds.

Comments close on 9 October 2026. County public participation forums run from 28 September.

What open finance means in the Bill



Section 29 is three subsections long, and it does a lot of work.

Each payment service provider or payment system operator must use systems capable of securely sharing customer data with third parties for open finance purposes. The Central Bank may require a provider to implement a mechanism to securely share customer data with third parties after obtaining the customer's consent. CBK then makes regulations to give effect to the section.

That last clause is where the fight will be. The Bill does not say what data can be accessed, on what terms, at what cost, or who carries liability when a third party mishandles it. All of that is deferred to regulations CBK has not written yet.

The scope is what makes it consequential. It covers banks and mobile money providers, which means the customer records sitting inside bank core systems and the M-PESA wallet. Those records have been the competitive moat for both. Under the Bill, keeping them closed is no longer a choice the provider gets to make.

Two new licences, and the cheapest entry point in Kenyan payments



The First Schedule lists nine licence categories. Seven are familiar. Two are new.

Payment Initiation Service Providers can initiate online payments on a customer's behalf without the customer going through their own bank or wallet interface. Account Information Service Providers can pull account data and present a consolidated view across accounts held with different providers.

Neither is built to hold customer funds. That is the point of the design. Their role is to sit in front of the account, not replace it.

The Third Schedule sets minimum capital:

  • Payment Initiation Service Provider: KSh5 million

  • Account Information Service Provider: KSh5 million

  • Payment Gateway: KSh10 million

  • Payment Messaging System Operator: KSh20 million

  • Money Remittance Service Provider: KSh30 million

  • Merchant Acquirer: KSh50 million

  • Electronic Wallet Provider: KSh50 million

  • Card Scheme Operator: KSh50 million

  • Payment Switching and Clearing System Operator: KSh50 million

  • Electronic Money Issuer: KSh250 million


Read the two lists together and the market structure becomes visible. The licence that gives a firm the right to reach into someone else's customer base costs KSh5 million. The licence that lets a firm issue the money people hold costs fifty times that. Kenya is pricing access to rails cheaply and ownership of float at a premium.

A firm holding more than one licence pays the highest applicable tier plus fifty per cent of the next one. Banks, microfinance banks, building societies and specified state enterprises skip the separate payment licence but still need CBK authorisation and still meet the capital rules.

Where customer money has to sit



Part VIII handles the money itself. An issuer of electronic money or provider of electronic wallets must hold all monies received from customers in a trust account, at a bank licensed under the Banking Act or a microfinance bank.

The Fourth Schedule caps concentration: a firm cannot hold more than KSh500 million or more than 25 per cent of trust monies, whichever is higher, in a single bank. Trust balances also get protection in insolvency, and Part VIII deals with commingling and income from trust accounts.

For anyone who has watched a wallet provider fail elsewhere on the continent, this is the section that matters. It separates customer money from operating money, and it makes the separation a licence condition.

The parts that are not settled



Three gaps stand out.

The technical standard. The Bill says systems must be capable of secure sharing. It does not name an API standard, an authentication protocol or a messaging format. CBK's earlier open banking work pointed at REST APIs, OAuth 2.0 and ISO 20022, but the Bill does not carry those across.

Liability. When a payment initiation service executes a payment the customer did not intend, or an account information service leaks data it pulled, the Bill does not allocate the loss. Consent is required. Accountability is undefined.

Enforcement of the one-year clock. Transitional provisions in section 79 give every existing payment service provider one year from commencement to comply. CBK issues guidance to give effect to it. One year from a date that has not been set, against a regulation that has not been published, is a schedule worth watching closely.

Section 74 lets CBK establish a regulatory sandbox by regulation, so firms can test payment and settlement services without a full licence. That is the pressure valve for the two new licence categories.

Who should respond before 9 October



Fintech founders building account aggregation, payment initiation or lending on transaction data have the most to gain and the shortest window. The licence categories, the capital tiers and the consent mechanics will decide what they can build for the next decade, and they are still editable.

Banks and wallet providers have the most to lose, and the strongest incentive to argue about cost recovery, reciprocity and liability caps.

Security leads should read Part VIII alongside section 29. Consent-based data sharing creates a new API surface on the systems that hold Kenyan financial records. Authentication, rate limiting, fraud detection and incident reporting will all need to be designed for third-party traffic that the provider does not control.

Anyone can submit using the template on the Treasury or CBK website, by email to paymentslawreview@centralbank.go.ke, or in person at one of the eleven county forums running from 28 September to 9 October.

What to watch



The regulations that follow section 29 will decide whether Kenyan open finance works in practice or stalls in a technical annex. CBK has been drafting open banking rules since 2024, so the framework is not starting from zero. This time it has a statute behind it.

The other signal is the capital schedule. If parliament keeps KSh5 million for payment initiation and account information licences, Kenya gets the lowest-cost open finance entry point in the region. If those tiers rise in committee, the access argument weakens.

Either way, the deadline is real. The country is writing the rules for who gets to touch customer payment data, and the comment period ends on 9 October 2026.

Want to learn more?

Contact GashoTech for personalized consultations on AI, automation, and cybersecurity solutions.

Get in Touch