Skip to content
TrustList
News

Kenya's central bank consults on revised prudential and risk management guidelines, including outsourcing and cyber risk; comments by 7 November 2026

Editorial

By TrustList Editorial

The Central Bank of Kenya invites comments by 7 November 2026 on draft revised Prudential Guidelines, Risk Management Guidelines, guidance notes and a framework for systemically important banks. The drafts cover cyber and third-party risk.

About Kenya's central bank consults on revised prudential and risk management guidelines, including outsourcing and cyber risk; comments by 7 November 2026

Kenya's central bank consults on revised prudential and risk management guidelines, including outsourcing and cyber risk; comments by 7 November 2026

10 September 2026 — The Central Bank of Kenya (CBK) has published for public comment a set of draft rules for banks: revised Prudential Guidelines, Risk Management Guidelines, guidance notes and a framework for domestic systemically important banks (D-SIBs). It asks for feedback by 7 November 2026.

Not yet independently verified. Both sources are the central bank's own documents; no independent news report was read. The notice's date is taken from its publication folder (September 2026), and the drafts may change after consultation. We will update this when it can be confirmed, and remove this note.

What is being consulted on

The CBK says it is carrying out public participation under the Constitution and the Statutory Instruments Act. The package covers the core prudential rules banks operate under, the risk management standards they must meet, explanatory guidance, and a framework that will identify banks whose failure would threaten the system and may subject them to additional requirements.

For technology buyers and vendors, the draft Risk Management Guidelines matter most. They contain sections on cybersecurity risk and third-party risk, and an outsourcing section that asks banks to plan for disruption at critical third parties and for cyber incidents affecting them. In practice this shapes what banks will demand from cloud providers, core-banking vendors and managed security providers.

How to comment

The CBK asks for comments on its template, sent to fin@centralbank.go.ke with the subject line naming the draft guidelines, or in hard copy to its Director of Bank Supervision, by 7 November 2026.

Who is affected

Commercial banks in Kenya, and the software, cloud, data-centre and security companies that serve them, including regional vendors selling across East Africa where Kenyan rules often set the pattern.

What to do

  1. Banks: compare the drafts with your current policies on outsourcing, cloud, cyber resilience and incident reporting, and note where they would require new contract terms or testing.
  2. Vendors: read the outsourcing and third-party sections and expect them in your next contract renewal or due-diligence questionnaire: audit rights, exit plans, incident notification and data location.
  3. Send comments by 7 November, especially where a requirement would be impractical for cloud services.
  4. Watch for the final guidelines and their effective dates.

Why it matters for buyers

Regulators across Africa are tightening rules on how banks rely on outside technology providers. A bank's obligations become its vendors' obligations through contracts, so these drafts are as relevant to the software industry as to banks.

Sources

Categories & features