As of 30 September 2026, the Central Bank of Kenya has licensed 281 digital credit providers, up 29 in the latest round. Every one of them operates under the Central Bank of Kenya (Digital Credit Providers) Regulations, 2022. Most of those rules show up in day-to-day operations, which means they show up in your loan system.

This is a practical summary for lenders, not legal advice. Check the regulations themselves and talk to your compliance adviser before relying on it.

1. Tell borrowers the full cost before they borrow

Before a loan is granted, the borrower must receive the terms in a clear, summarised form: the loan amount, interest rate and how it is calculated, other charges, repayment dates, total cost of credit and annual percentage rate.

What your system should do: generate that summary for every product automatically, show it before acceptance, and keep a record that the borrower saw and accepted it.

2. Issue receipts and keep records ready

Lenders must issue a receipt or acknowledgement for transactions and make books and records available to the CBK on request.

What your system should do: confirm every repayment to the borrower, reconcile M-Pesa daily, and let you pull a full history for any loan in minutes, not days.

3. Resolve complaints within 30 days

You need a formal complaints process, and each complaint must be addressed within thirty days of being reported, with records available to the CBK.

What your system should do: log complaints against the borrower’s record, show the age of every open complaint, and keep the resolution history.

4. Follow the credit reference bureau rules

Lenders share credit information with licensed bureaus, but negative information cannot be reported for amounts of KSh 1,000 or less. Borrowers must be notified at least 30 days before negative information is submitted.

What your system should do: apply the threshold automatically, schedule the notices, and record when each was sent.

5. Collect debts without harassment

The regulations prohibit threats, violence, profane language, shaming and contacting a borrower’s phone contacts about their debt.

What your system should do: send reminders only to the borrower, on a schedule you control, with every message logged so you can show how collection was done.

6. Protect borrower data

Lenders must keep information confidential and systems secure, and get consent before sharing credit data. The Data Protection Act, 2019 applies on top.

What your system should do: limit access by role, require two-factor sign-in for staff, keep an audit trail, and record borrower consent.

A quick checklist

  • Cost-of-credit summary shown and accepted before disbursement
  • Receipts for every repayment, with daily M-Pesa reconciliation
  • Complaints logged and aged against the 30-day limit
  • Bureau threshold and 30-day notices applied automatically
  • Reminders go to the borrower only, and every message is logged
  • Role-based access, two-factor sign-in and a full audit trail

Where LendRange fits

LendRange includes role-based access, two-factor sign-in and a full audit trail on every tier, automatic M-Pesa repayment allocation with daily reconciliation, borrower agreements through the borrower portal, and credit-bureau integration on the Institution tier. Book a 30-minute walkthrough and we will run one of your own loan products through it.

Sources

Fledge Solutions Limited builds valuation and lending software and installs IT, networks and CCTV from Aqua Plaza, Nairobi.

Book a LendRange walkthrough