Back to Blog
Kenya Raises Terror-Financing Fines to Sh20 Million: Why the 24-Hour Freeze Clock Matters More
Cybersecurity

Kenya Raises Terror-Financing Fines to Sh20 Million: Why the 24-Hour Freeze Clock Matters More

September 21, 2026GashoTech Team

The short version



Kenya gazetted new terror-financing regulations on 7 September 2026. The maximum fine for a company that breaches them rose from Sh3 million to Sh20 million. That is the figure that travelled — and the least important change in the document.

The instrument is Legal Notice No. 172 of 2026, formally the Prevention of Terrorism (Implementation of the United Nations Security Council Resolutions on Suppression of Terrorism) Regulations, 2026. It revokes the 2023 version and rebuilds how Kenya applies United Nations targeted financial sanctions.

Three provisions do the real work. Regulation 2 defines "without delay" for the first time as action within "a matter of hours" of a designation, and in any event not later than twenty-four hours. Regulation 9 requires a freeze without prior notice across four categories of funds, including funds that cannot be tied to any particular plot. Regulation 11 requires a report inside 24 hours that maps related accounts and captures attempted transactions.

Read together, they convert sanctions compliance from a periodic review into a systems problem with an hours-scale service level. The fine is the price tag on failing it.

What actually changed on 7 September



Start with the penalty, because it is genuinely different. Regulation 32 now sets a tiered scale tied to section 50(4) of the Prevention of Terrorism Act:

  • A legal person: a fine not exceeding Sh20 million.

  • A natural person: imprisonment not exceeding ten years, and/or a fine not exceeding Sh1 million.


The clause it replaces was flatter and far older. Since the 2013 regulations, the residual penalty for contravening the regulations where no specific penalty was provided carried a fine not exceeding Sh3 million, or a prison term not exceeding seven years. It did not distinguish between a company and a person.

Be precise: this is the catch-all clause, applying where the regulations provide no specific penalty elsewhere. Coverage framing the change as "fines are now six times higher" describes that residual clause, not the whole instrument; earlier versions already carried larger ceilings in particular clauses. What is new is that the residual clause now mirrors a criminal-statute scale with a ten-year maximum.

Why "a matter of hours" is the operative phrase



The genuinely new language sits in the interpretation section. Regulation 2 defines "without delay" as:

> within a matter of hours of a designation by the United Nations Security Council or its relevant Sanctions Committee or by the Committee, as the case may be and, in any event, not later than twenty-four hours of that designation.

The prior assumption was simpler: you had a day. The revised text keeps the 24-hour outer limit but adds an expectation of faster action, and anchors the clock to the moment of designation, not the moment your institution notices it.

That distinction is the ballgame for anyone running screening. If a listing is published at 03:00 Nairobi time and your sanctions list refresh runs nightly at midnight, those hours are unmonitored exposure — and the regulation's clock started without you.

Regulation 9 then sets out what must be frozen, and it is broader than most manual processes assume. Without prior notice:

  • All funds or assets owned or controlled by the designated person, not only those tied to a particular terrorist act, plot or threat.

  • Funds or assets wholly or jointly owned or controlled, directly or indirectly.

  • Funds or assets derived or generated from those assets.

  • Funds or assets of any person acting on behalf of, or at the direction of, the designated person.


Regulation 10 requires that implementation be undertaken "cumulatively without delay." Not one account. Not one action. The full set, fast.

The report is the hard part



A freeze is a switch. A report is a data problem, and regulation 11 is where compliance teams will struggle.

Within twenty-four hours of acting under regulation 9, the person who effected the action must file a report with the Committee through the Secretary. For a freezing of funds it must include the account number and holder, the time of freezing of all subject accounts, the balance at that time, the related accounts including their balances, and an explanation of the grounds for identifying each related account.

Two of those requirements deserve a second read. "Related accounts" asks an institution to establish inside a day which other accounts connect to a sanctioned person — across its own books, its other products, potentially other entities in the group — and to articulate why each link holds. That is analysis, not a data dump.

Then the attempted-transaction obligation. The report must also cover attempts made after the freeze, stating the account, the holder, the time of the attempt and all subject accounts, and the balance at the moment of attempt. Regulation 11(2)(c) leaves no room for "we blocked it and moved on."

An institution that freezes correctly but cannot evidence the related-account analysis and the attempted-transaction trail within 24 hours has complied with the easy half.

Virtual asset firms are named, explicitly



Regulation 2 defines a reporting institution as a financial institution, a designated non-financial business and profession, or a virtual asset service provider, under section 2 of the Proceeds of Crime and Anti-Money Laundering Act.

Naming virtual asset service providers in the interpretation section is not cosmetic. It places crypto exchanges, custodians and wallet providers inside the same freeze-without-notice and report-within-24-hours regime as commercial banks. For a sector that spent 2026 preparing for VASP licensing, this is the second shoe dropping: not just "get licensed," but "operate sanctions controls that can act in hours."

The raw material problem is real. The Financial Reporting Centre issues targeted financial sanctions notices through the year, each one testing whether an institution's refresh and screening pipeline can absorb a change without a manual rebuild.

The FATF clock behind the reform



Kenya has been on the Financial Action Task Force grey list — jurisdictions under increased monitoring — since February 2024, and remained there after the June 2026 review.

The FATF's asks map almost directly onto what these regulations compel: stronger risk-based supervision, better preventive measures and suspicious transaction reporting, more effective investigations, better use of financial intelligence, and stronger transparency around trusts. A residual penalty unchanged at Sh3 million and seven years since 2013 was enforcement out of step with the obligation it backs.

Where the capability gap sits



The requirements are unevenly matched to sector readiness. A Central Bank of Kenya survey of digital lenders found 71 percent screened customers against global sanctions lists, but fewer than half kept those lists up to date, and only 35 percent conducted enhanced due diligence.

Screening is common. Keeping screening data current is not. A freeze obligation anchored to the moment of designation, with a 24-hour reporting window, is precisely the obligation a stale list cannot meet.

Nor is this solved by buying a tool. Automated screening flags matches; it does not produce the analysis of why two accounts are linked, which is the part a supervisor reads first. A tier-one bank is tightening timelines; a smaller lender on a spreadsheet is being asked to build a function — under the same Sh20 million ceiling.

What reporting institutions should do next



Four things are worth doing before the next designation lands.

First, measure listing-to-screen latency. Not review frequency. The elapsed time between a UN designation being published and your system reflecting it. That number tells you whether you meet the "matter of hours" standard or are living on the 24-hour backstop.

Second, test the related-account analysis. Pick a match, simulated or real, and ask what your institution can produce within a day: the other accounts, their balances at the freeze moment, and a written justification for each link. Most organisations discover the answer is an analyst, three systems and a lot of email.

Third, instrument attempted transactions. The obligation runs after a freeze and it is reportable. If blocked attempts land in a log nobody exports, you are building a reporting failure inside the report you do file.

Fourth, treat the residual penalty as a governance signal. A section 50(4) scale with a ten-year maximum makes these criminal-law obligations, which changes who owns them at board level.

The bottom line



The story that travelled was the number: Sh3 million to Sh20 million. The story that decides readiness is the clock.

A residual penalty static since 2013 is now tied to a statutory scale with a ten-year maximum. "Without delay" has a definition that begins with the words "a matter of hours." The report due a day later must show not just that you froze, but that you understood the account relationships and captured everything that tried to move afterwards.

That is not a compliance upgrade. It is a demand for a capability most firms have not had to build yet — and it applies, by name, to crypto firms as well as banks.

Primary source: Legal Notice No. 172 of 2026, Kenya Gazette Supplement No. 218, 7 September 2026.

Want to learn more?

Contact GashoTech for personalized consultations on AI, automation, and cybersecurity solutions.

Get in Touch