SDS East Africa AML/CFT brief

EAST AFRICA'S
AML/CFT TEST IS
NOW EXECUTION.

Grey-list remediation, virtual-asset exposure, and the intelligence value of reporting.

Richard Kabiru

SDS analysis

Reporting date

13 July 2026

Geographic scope

East Africa and the Horn

Core audience

Financial institutions, DNFBPs, and public authorities

Listen to the brief

Choose the depth that fits your time.

Start with the concise briefing for the core argument. Continue with the debate for a deeper examination of how banks and DNFBPs contribute different forms of financial intelligence.

Audio brief01:41

Catching illicit money in East Africa

A fast orientation to the brief's central finding and the controls that matter now.

Download audio ↓
Extended debate21:47

Banks versus DNFBPs for financial intelligence

A longer discussion on transaction depth, ownership context, and what makes reporting useful to an FIU.

Download audio ↓

Executive perspective

The formal position is largely unchanged. The burden of execution is not.

Kenya and South Sudan remain under FATF increased monitoring. Kenya's virtual-asset framework is still moving from legislation to supervision. On 8 July, the United Nations amended one entry on the ISIL and Al-Qaida sanctions list. Together, these developments point to a common regional problem. The rules are becoming clearer, but the quality of implementation remains uneven.

For financial institutions, the immediate task is to convert policy into reliable data, working controls, and useful intelligence. Virtual-asset exposure may appear through personal accounts, mobile-money collections, processors, and offshore providers.

DNFBPs face the same problem from a different position. They may see fewer transactions than banks, but often hold better information on ownership, authority, source of funds, and commercial purpose.

Institutions now need to show how a change in policy affected customer behaviour, payment routes, report quality, and the ability to act.

SDS assessment

The next phase of AML/CFT reform will be judged less by the number of rules adopted and more by the quality of supervision, intelligence, and enforcement they produce.

A note for DNFBPs

DNFBPs include designated non-financial businesses and professions such as lawyers, accountants, real-estate actors, dealers in precious metals and stones, casinos, and trust or company service providers, subject to national law.

Finding 01

Implementation is now the test

Kenya's reform agenda links supervision, reporting, ownership data, financial intelligence, and enforcement. Weak performance at one stage reduces the value of progress elsewhere.

Finding 02

Virtual-asset exposure is indirect

Most institutions will encounter the risk through ordinary payment rails and customer relationships, not through transactions labelled as virtual assets.

Finding 03

Reporting volume is a weak proxy

An increase in STRs may reflect supervisory pressure. It does not show that reports can be linked, disseminated, or used in an investigation.

Questions for management

Q1

Can we evidence the latest sanctions update?

Record the source file, ingestion time, field mapping, screening run, and any required rescreening.

Q2

Can we identify indirect VASP exposure?

Test counterparties, devices, transaction velocity, common beneficiaries, and links to known providers.

Q3

Can an external analyst follow the suspicion?

Explain the expected activity, the observed deviation, the parties involved, and the movement of value.

Q4

Are we measuring activity or effect?

Submission counts show work completed. Linkage, investigation, and intervention show value.

01 / Increased monitoring

Grey-list remediation will be judged by the connection between supervision, intelligence, and enforcement.

FATF's statement of 19 June 2026 retained Kenya and South Sudan among jurisdictions under increased monitoring. This is not a direction to reject every customer, payment, or business relationship linked to either jurisdiction. A risk-based approach requires institutions to distinguish jurisdictional weakness from the risk presented by a specific customer or transaction.

Kenya's remaining action areas form a single operating chain covering risk-based supervision, STR quality, beneficial ownership, use of financial intelligence, money-laundering investigations, targeted financial sanctions, and oversight of non-profit organisations.

South Sudan requires a different analytical response. Institutional constraints and exposure to cash, procurement, and politically connected networks support greater use of relationship and network analysis.

A grey list identifies a jurisdictional weakness. It does not determine the risk of every customer.
7Reform areas that need to operate as one control chain.
3Practical tests covering supervision, intelligence use, and enforcement outcomes.
JurisdictionPrimary execution gapImplication for institutions
KenyaConverting reform into better reporting, ownership resolution, and case outcomes.Track report quality, linkage, ownership enrichment, dissemination, and investigative use.
South SudanCapacity constraints and high exposure to cash, procurement, and politically connected networks.Prioritise common controllers, repeated counterparties, oil intermediaries, NGO contractors, and regional property.
Regional institutionsPressure to use broad de-risking instead of customer-level analysis.Document the risk drivers and apply proportionate enhanced measures.

The policy error

Broad de-risking is administratively simple but analytically weak. It can move activity into smaller institutions, informal channels, and less transparent payment routes while leaving the underlying risk intact.

A practical effectiveness dashboard

Trend by sector and reporting institution.
IndicatorWhat it showsWeak performance
Identifier completenessThe ability to match subjects, accounts, and counterparties without manual reconstruction.High report volume with missing, inconsistent, or unreliable identifiers.
Ownership resolutionThe ability to identify the natural person who owns or controls the customer, company, or asset.Legal persons reported repeatedly without controller-level information.
Network linkageThe share of reports connected to prior subjects, beneficiaries, devices, addresses, or transactions.Reports remain isolated despite recurring names and counterparties.
Analytical conversionThe share of reporting that supports enrichment, dissemination, investigation, or another risk action.Submission counts increase while downstream use remains flat.

02 / Regulatory transition

Virtual-asset exposure is becoming an ordinary-payments problem.

Kenya's draft Virtual Asset Service Providers Regulations signal the direction of travel. They do not, by themselves, give reporting institutions a complete view of exposure during the transition to licensing and supervision.

Most customers will not present as virtual-asset users. Exposure may be routed through personal bank accounts, mobile-money collections, informal peer-to-peer traders, payment processors, offshore exchanges, and merchants that use stablecoins for settlement.

Differences in regulatory timing across Kenya, Uganda, Rwanda, and Tanzania create scope for substitution. Customers and providers can shift to the jurisdiction, platform, or payment corridor that presents the least friction, while the underlying economic activity remains regional.

Transaction monitoring should therefore begin with behaviour and relationships, not product labels.

Customers and providers select the lowest-friction corridor

Offshore VASPExchange / wallet / OTC
UgandaBanks / PSPs / traders
KenyaBanks / mobile money / P2P
TanzaniaP2P / FX / merchants
RwandaLicensed perimeter / fintech

Risk migrates before supervisory practice converges

Pattern

Retail collection accounts

Numerous incoming payments are consolidated and transferred to a provider, trader, or common beneficiary soon after receipt.

Pattern

Misstated payment purpose

Payments are described as imports, gaming, consulting, or online services, but invoices and account behaviour do not support the explanation.

Pattern

Fiat on- and off-ramps

Value moves outside the visible banking chain while cash, bank, or mobile-money conversion occurs at the entry and exit points.

Minimum data view for VASP exposure

Start with a usable view before adding complex models.
01

Customer and account

KYC profile, occupation, expected activity, source of funds, and linked accounts.

02

Counterparty

Known exchanges, traders, processors, repeated payees, and common beneficiaries.

03

Channel and device

Bank, mobile money, card, IP address, device, agent, and access location.

04

Flow behaviour

Collection, consolidation, pass-through, cash-out, and rapid cross-border movement.

05

Economic purpose

Invoice, goods, service, trade route, and an explanation consistent with the value moved.

03 / Intelligence yield

STR growth matters only when the reports can be converted into intelligence.

Grey-list remediation often increases filing volumes. Institutions become more cautious, supervisors ask for evidence of compliance, and borderline cases are escalated. This may be rational in the short term, but it can also increase the number of reports without improving their analytical value.

A useful STR does three things. It identifies the parties with enough precision to support matching. It explains how the activity differs from the customer's known profile or stated purpose. It provides enough transaction and ownership detail for the FIU to test links, reconstruct the movement of value, and assess the wider network.

Banks and payment firms can contribute transaction depth. DNFBPs can contribute context on ownership, legal authority, property, source of funds, and the commercial purpose of a transaction.

The relevant performance question is not how many reports were filed. It is how many could be enriched, linked, disseminated, and used.

The intelligence value chain

1. Report received
2. Identifiers + transactions
3. Ownership + counterparties
4. Network + typology
5. Actionable

Each missing field reduces the probability that a report survives the path from filing to investigative use.

Five questions before filing

  1. 01What activity would be expected from this customer, business, or transaction?
  2. 02What changed, and why is the deviation material rather than merely unusual?
  3. 03Who owns, controls, instructs, or benefits from the parties involved?
  4. 04How did value move across accounts, products, channels, and jurisdictions?
  5. 05What evidence supports the suspicion, and which links should the FIU test first?

A concise report can still be complete. A vague report cannot.

Measure

Data sufficiency

Names, identification numbers, accounts, contacts, addresses, and ownership links that can be matched reliably.

Measure

Linkage potential

The extent to which a report can be connected to other subjects, transactions, locations, devices, or prior intelligence.

Measure

Downstream utility

Dissemination, investigative uptake, restraint, recovery, prosecution, or another documented risk intervention.

Analytical judgement

Defensive filing moves uncertainty from the reporting institution to the FIU. It does not improve the quality of the underlying information.

04 / Network analysis

Terrorist-financing analysis should follow the commercial network, not the payment product.

RemittancesFamily / diaspora / agents
ExtortionTaxation / collections
LogisticsTransport / warehousing
LivestockTrade / markets / levies
Operational financingNetwork, not one channel
Fuel + telecomServices / airtime / access
Small businessFronts / merchant flows
CharitiesBeneficiaries / contractors
ProcurementChemicals / electronics

Operational financing is a network, not one channel

Al-Shabaab-related risk is regional because revenue collection, movement, procurement, and commercial support extend beyond Somalia. Kenya, Ethiopia, Djibouti, Uganda, and Tanzania can appear within the same financial or supply chain.

Remittances remain relevant, but they are neither unusual nor distinctive on their own. The wider picture may include taxation and extortion, transport, livestock and agricultural trade, fuel, telecommunications, small-business fronts, and procurement.

A single sender or transfer is rarely sufficient. Greater weight should be placed on repeated beneficiaries, linked merchants, common controllers, border locations, procurement patterns, and activity that conflicts with the stated business.

A network-based approach can also reduce false positives. Analytical confidence increases when transaction behaviour is supported by network, geographic, ownership, and commercial indicators.

Transaction behaviour

Splitting, rapid pass-through, unusual cash conversion, repeated merchant collections, or unexplained cross-border settlement.

Network and control

Common controllers, repeated beneficiaries, shared devices, linked merchants, border locations, or circular flows.

Commercial contradiction

Activity inconsistent with the stated business, trade route, procurement need, customer profile, or source of funds.

No single indicator establishes terrorist financing. Confidence increases when independent sources point to the same explanation.

Sanctions control

The UN amended entry QDi.439 on 8 July 2026. Institutions should update machine-readable list data, validate field mapping, test aliases and transliterations, and rescreen affected activity. Vendor confirmation should not replace internal evidence that the update was applied correctly.

05 / Control agenda

Institutions should focus the response on control weaknesses they can measure.

Selected control agenda

Build an indirect exposure view

Virtual-asset and sanctions risk should be visible through linked customers, counterparties, channels, and transaction behaviour.

0/4

Use the checklist as a quick self-assessment. Your selections stay on this page only.

The test

A control should be judged by what it enables: better identification of risk, a clearer explanation of activity, or a timely intervention. Controls that add paperwork without improving any of these outcomes deserve review.

What to watch next

The next signal is likely to appear in implementation data before it appears in another headline.

01

Kenyan VASP regulations

Final rules, licensing mechanics, supervisory allocation, and the treatment of customers and providers during the transition period.

02

FATF remediation evidence

Changes in STR quality, beneficial-ownership access, sanctions implementation, investigations, prosecutions, and asset outcomes.

03

Regional enforcement patterns

Cases involving virtual assets, mobile money, trade, property, professional intermediaries, and cross-border payment corridors.

East Africa's AML/CFT frameworks are becoming denser. The remaining gap is execution.

For management, the question is no longer simply if a policy exists. The question is whether the institution can show, from its own data, that the policy is changing what it detects and how it responds.

Selected public sources

  1. 1. Financial Action Task Force, Jurisdictions under Increased Monitoring, 19 June 2026.
  2. 2. Central Bank of Kenya, Invitation for Comments on the Draft Virtual Asset Service Providers Regulations, 2026, 18 March 2026.
  3. 3. United Nations Security Council, List of updates to the UNSC Consolidated List, entry QDi.439 amended 8 July 2026.
  4. 4. Financial Action Task Force, An Effective System to Combat Money Laundering and Terrorist Financing.
  5. 5. Financial Action Task Force, Guidance on AML/CFT-related Data and Statistics.
  6. 6. Public regulatory and sanctions material reviewed for the reporting period ending 13 July 2026.

About the author

Richard Kabiru

Richard works across financial intelligence, AML/CFT, data analytics, and systems design.

Method + disclaimer

This publication separates confirmed public developments from the author's analytical judgement. It does not represent the position of any public institution and is not legal or regulatory advice.

Download the original PDF