Most of us went into practice to advise clients, draft agreements and argue matters, not to run compliance checks. Yet over the last few years, anti-money laundering (AML) obligations have become part of the everyday reality of running a law firm in Kenya.

Customer due diligence for Kenyan advocates means identifying and verifying clients and beneficial owners, understanding the purpose of their instructions, assessing risk, and monitoring the relationship. For work covered by section 48 of the Proceeds of Crime and Anti-Money Laundering Act (POCAMLA), these are practical compliance obligations, not simply an onboarding form.

Whether you are a sole practitioner in a small town or a partner in a large Nairobi firm, the question is whether your firm understands when these rules apply and is applying them properly.

This article walks through what customer due diligence (CDD) means for advocates, when it is required, what it involves in practice, and what to do when something about a client or a transaction does not add up.

Why Kenyan advocates are covered by POCAMLA

POCAMLA includes advocates, notaries and other independent legal professionals, whether sole practitioners, partners or employees in a firm, within the definition of designated non-financial businesses and professions (DNFBPs).

Section 48 of POCAMLA is the provision to keep in mind. It applies the obligations in Part IV when an advocate is preparing or carrying out specified transactions for a client, including:

  • buying and selling real estate;
  • managing client money, securities or other assets;
  • managing bank, savings or securities accounts;
  • organising contributions for the creation, operation or management of companies; and
  • creating, operating or managing business entities or legal arrangements, and buying or selling business entities.

If your practice touches conveyancing, company formation, trusts or holding funds on behalf of clients, you need to assess your instructions against these categories. The scope of the work matters. Reporting obligations also need to be read with the professional-privilege provisions in section 44, discussed below.

The domestic framework includes the Proceeds of Crime and Anti-Money Laundering Regulations, 2023, alongside other applicable legislation and guidance from the Financial Reporting Centre (FRC) and Law Society of Kenya (LSK).

So what is customer due diligence?

Customer due diligence is closely associated with “Know Your Customer” or “Know Your Client”, usually shortened to KYC. In plain terms, it is the set of steps a firm takes to work out who it is really dealing with, why they are instructing the firm, and whether their activity continues to make sense over time.

It involves identifying the client, verifying their identity, understanding the purpose of the relationship, monitoring what happens along the way, and keeping the information current. Collecting an ID is part of the process. It is not the whole process.

It is not paperwork for its own sake. It helps protect your firm from being used to launder money or finance terrorism, supports compliance with the law, and protects the reputation you have spent years building.

When must advocates carry out CDD?

For business within the applicable AML framework, regulation 14(5) of the 2023 Regulations identifies the occasions that trigger CDD. You should carry it out:

  • when establishing a business relationship with a client;
  • when undertaking an occasional or one-off transaction;
  • when carrying out occasional wire transfers covered by regulation 32;
  • whenever there is cause to suspect money laundering or terrorism financing; and
  • whenever you doubt the accuracy or adequacy of information you collected earlier.

It applies to new clients, existing clients and occasional clients. For existing relationships, section 45(2) and regulation 14(6) require a materiality-and-risk approach, taking account of earlier checks and the adequacy of the information held. A file opened ten years ago and never revisited is a weak spot.

Step one: identify and verify the client

For a natural person, start with an appropriate official identity document, such as a National ID or passport. Section 45(1A)(a) lists acceptable forms of official identification. Regulation 15 sets out further identifying information and additional measures, including a KRA PIN where one has been issued.

For a company, section 45(1A)(b) and regulation 16 call for information on its legal existence, registered and business addresses, authority to transact, and the people managing, controlling or owning it. Incorporation documents and constitutional documents are part of that picture. Partnerships and trusts have their own requirements under regulations 17 and 18.

Collecting documents is only half the job. Verification means checking the information against reliable, independent sources. A photocopy handed to you by the client, without any cross-check, is not much of a safeguard. The whole purpose is to avoid a situation where your client is simply a front for someone else who is staying out of sight.

Record what you checked, the source you used, and any discrepancy that still needs resolving.

Step two: check people acting on behalf of the client

In practice, the person sitting across from you is often not the actual client. A director may instruct you on behalf of a company, or an agent may act under a power of attorney.

Under section 45(3) and regulation 23, you must verify that the person is authorised to act and identify and verify that person’s identity. In practice, you should:

  • obtain documentary proof of authority, such as an appropriate board resolution, power of attorney or other authorisation;
  • verify the representative’s identity; and
  • check that the authority covers the transaction or instructions you are being asked to handle.

A familiar face or an impressive job title is not a substitute for authority to act.

Step three: find the beneficial owner

This is where many files fall short. Regulation 14(2)(b) requires you to identify the beneficial owner and take reasonable measures to verify their identity, so that you are satisfied you know who they are and understand the ownership and control structure.

A beneficial owner is the natural person who ultimately owns or controls the customer, or on whose behalf a transaction is conducted. The person named on the incorporation documents may not be the person exercising that control.

For companies, regulation 3(2) of the Companies (Beneficial Ownership Information) Regulations sets out criteria that include:

  • holding at least 10% of the issued shares, directly or indirectly;
  • exercising at least 10% of the voting rights, directly or indirectly;
  • having the right to appoint or remove a majority of the board, directly or indirectly; or
  • exercising significant influence or control, directly or indirectly.

Do not treat 10% as a universal stopping point for AML enquiries. Ownership is only one route to control, and regulation 16(2) of the AML Regulations addresses control through other means and the relevant senior managing official where no natural person is identified through the preceding tests. Companies limited by guarantee also have specific criteria under regulation 3(2A) of the beneficial-ownership rules.

If a corporate client’s ownership chain disappears into layers of other companies and you cannot get to a real human being at the end of it, treat that as a finding in itself.

Step four: risk profile the client

Not every client carries the same level of risk, and the law does not expect you to treat them all the same. A sensible risk profile looks at:

  • the client’s profile, including their business, legal structure, ownership and source of funds or wealth;
  • the industry or sector they work in;
  • geography;
  • the services they are asking for;
  • how the relationship is delivered, including remotely or through intermediaries; and
  • sanctions, politically exposed person (PEP) status and relevant adverse information.

The rating you give the client then determines how much work you do next. Record the reasons for the rating, not just a tick beside “low”, “medium” or “high”.

Enhanced due diligence for higher-risk clients

Where a client presents higher risk, regulation 20 calls for additional measures:

  • obtaining further information to establish identity;
  • applying extra measures to verify documents supplied;
  • obtaining senior management approval for the new relationship or transaction;
  • establishing the source of funds; and
  • carrying out ongoing monitoring of the relationship.

Examples of situations that deserve closer attention include opaque ownership, unexplained nominee arrangements, cash-intensive businesses and connections to higher-risk jurisdictions. The applicable response depends on the facts and the relevant legal requirements, including section 45A on higher-risk countries.

PEPs require particular care. Regulation 26 sets out additional measures for foreign PEPs, including establishing source of wealth and source of funds. For domestic PEPs and people entrusted with prominent functions by international organisations, the additional measures apply where the relationship is higher risk. PEP status is a risk consideration, not a finding of wrongdoing.

Red flags worth watching for

Certain patterns should prompt closer attention:

  • Behaviour: the client is secretive about their identity, beneficial ownership or source of funds, or cannot provide suitable identification.
  • Funds: capital is out of proportion to the size or value of the business, or money moves through several foreign accounts without a clear reason.
  • Opaque identities: the instructions involve unexplained third parties, complex corporate structures or a refusal to identify the people behind them.
  • Unusual capital movements: sudden unexplained cash payments, property purchases that do not fit the client’s known circumstances, or requests to park large sums in your client account without substantive legal work.

The FRC’s guidance notes on suspicious transaction and activity reporting for the legal profession are worth having every fee earner read. A warning sign needs assessment in context; it is not, by itself, proof of a crime.

Unusual versus suspicious transactions

One distinction that is often blurred is the difference between an unusual transaction and a suspicious one.

An unusual transaction departs from the profile you built at onboarding. That alone does not automatically establish suspicion. It is a prompt to ask questions, collect appropriate information and assess whether there are grounds to suspect a link to money laundering, terrorism financing, proliferation financing or proceeds of crime.

Useful questions include: Where is the money coming from, and where is it going? Is there pressure to hurry beyond what is normal? Does the transaction fit the client’s stated business or financial standing?

Once suspicion arises, further enquiries must not be used to postpone a reporting duty. Section 44(2) requires a report in the specified manner within two days after suspicion arises, and section 44(3) includes attempted suspicious transactions.

Reporting, professional privilege and tipping off

The reporting duty must be read with sections 44(3A) and 44(3B). These protect information obtained in the specified circumstances of professional secrecy or legal professional privilege, including ascertaining a client’s legal position and defending or representing the client in the listed proceedings. This is not a blanket exemption for everything on a lawyer’s file.

Section 44(3) permits lawyers to submit reports through the LSK, which is to establish reporting channels to the FRC. Follow the applicable FRC and LSK reporting procedures and assess privilege carefully. Section 8 also addresses tipping off: do not disclose that a suspicious report is being prepared or has been made in circumstances prohibited by the Act.

What if you cannot complete identity checks?

Missing identification is not something to leave unresolved indefinitely. Regulation 25(2) sets out restrictions on starting or continuing the relationship or transaction where the applicant does not supply identity evidence as soon as reasonably practicable, together with an STR requirement. Apply these provisions alongside the Act’s privilege protections.

Regulation 25(6) also addresses the situation where pursuing CDD would risk tipping off a client: where its conditions are met, the reporting institution may stop pursuing that process and must instead file an STR. Escalate these situations promptly through your firm’s compliance arrangements.

CDD does not end at onboarding

Ongoing due diligence means keeping an eye on the client’s activity and making sure it stays consistent with what you know about their business, risk profile and source of funds. It also means refreshing documents and data so your records do not go stale.

How often you review depends on risk. Higher-risk clients need closer attention. Reviews can be periodic, or triggered by an event such as:

  • a change in the client’s identity or beneficial ownership;
  • a change in the services you provide;
  • suspicion of money laundering, terrorism financing or proliferation financing;
  • a significant change in key office holders;
  • PEP involvement; or
  • changes in legislation.

A real-world lesson: the Windward Trading case

In February 2016, Windward Trading Limited pleaded guilty to four counts of money laundering before the Royal Court of Jersey. The Government of Jersey’s account identifies its beneficial owner as Samuel Gichuru, then Chief Executive of Kenya Power and Lighting Company during the relevant period, and describes corrupt payments made to Windward by companies awarded KPLC contracts.

For advocates, the lesson is practical. The name of a company is only the beginning of the enquiry. Who controls it, where its money comes from, and whether those funds fit the person’s known role can matter far more than the appearance of an ordinary corporate vehicle.

A practical CDD checklist for your firm

If you have not reviewed your firm’s AML arrangements recently, a good starting point is to check that you have:

  • a written policy and procedure covering CDD, enhanced due diligence, reporting and record keeping;
  • an internal risk assessment for your practice areas;
  • a designated person responsible for AML compliance and reporting;
  • an onboarding checklist covering identity, authority to act, beneficial ownership, the purpose of the instructions, and source-of-funds enquiries appropriate to risk;
  • a record of checks completed and reasons for the client’s risk rating;
  • regular training for lawyers and support staff;
  • a process for periodic and event-driven reviews of existing clients; and
  • a clear retention and retrieval process for compliance records.

Section 46(4) requires relevant records to be kept for at least seven years from completion of the relevant business or transaction, or termination of the account or relationship, as applicable. The FRC may require a longer period, and other legal retention obligations remain relevant.

Common questions about CDD for Kenyan advocates

Is collecting a client’s ID enough?

No. CDD also covers verification, beneficial ownership, the purpose of the relationship and ongoing monitoring. A copy of an ID does not answer all those questions.

Do you need to review existing clients?

Yes. The Act and Regulations require CDD on existing relationships according to materiality and risk, taking earlier checks and the adequacy of the information into account.

Does every unusual transaction require an STR?

Unusual activity requires assessment. A suspicion-based reporting obligation arises when the relevant threshold is met, subject to the statutory privilege provisions. Separate duties, including regulation 25 where identity evidence is not supplied, must also be considered.

Making CDD work in your practice

CDD can feel like an extra burden on top of an already busy practice. But it is increasingly part of professional competence, and the cost of getting it wrong, in penalties, reputation and potential involvement in a criminal matter, can be far higher than the cost of doing it well.

A few good questions at the start of a relationship, and the discipline to keep asking them, go a long way.

MN Legal provides AML and CDD advisory in Kenya. If your firm needs advice on its obligations or has questions about its current arrangements, speak to MN Legal about AML/CDD compliance. Let us know whether your enquiry concerns onboarding, beneficial ownership, higher-risk clients or your firm’s wider compliance arrangements.

Email: info@mnlegal.net · Telephone: +254 700 325 089

About the author: Husna (A.) Mohammed is a Senior Associate at MN Legal and an Advocate of the High Court of Kenya. Her practice focuses on corporate commercial and real estate law.

This article is intended for general information only and does not constitute legal advice. Please refer to the current text of POCAMLA, the applicable Regulations and FRC/LSK guidance, or speak to us directly for advice on your specific situation.