A POCAMLA Compliance Checklist for Kenyan Businesses

Whether you are a bank, a SACCO, a fintech or a designated non-financial business, compliance under the Proceeds of Crime and Anti-Money Laundering Act rests on a common set of building blocks. Use this checklist to see how you measure up.
The essentials
- Register with the FRC. Reporting institutions must register with the Financial Reporting Centre and file reports through goAML.
- Documented AML/CFT policy. A board-approved policy covering onboarding, KYC, sanctions screening, beneficial ownership, record retention and suspicious transaction escalation.
- Risk assessment. An enterprise-wide assessment of your customer, product, channel and geographic risks.
- Customer due diligence. CDD and enhanced due diligence procedures, including checks on source of funds and PEPs.
- A reporting officer. A designated officer responsible for monitoring, reporting and compliance oversight.
- Suspicious transaction reporting. A clear internal escalation process and timely STR filing via goAML.
- Record-keeping. Retention of customer and transaction records for the period required by law.
- Training. Regular, role-based training with documented evidence.
How do you score?
If you can confidently tick every box, and evidence it, you are in good shape. If several give you pause, you are not alone, and the gaps are fixable. An independent health check turns this checklist into a prioritised action plan tailored to your business.
Need help with a pocamla compliance checklist for kenyan businesses? Schedule a consultation with our team.
