Skip to content
MAESTRO IRWIN

S/Solutions by sector

A bank and a telco do not fail at AI the same way.

The register is the same discipline everywhere. What it finds, who asks to see it, and what it costs you to be unable to produce it are not. Five sectors, and what the work looks like inside each.

Talk to an expertHow we work

Kenya and the wider region·Regulator-mapped·Evidence-led

Index

Sector schedules

W/P ref
S-0.1
Status
CURRENT
Index of the five sector schedules on this page, each with its primary AI exposure and the regulator that supervises it.
RefSectorPrimary exposureSupervised by
B-1Banking and financial servicesCredit decisioningCBK · ODPC
B-2Insurance and health coverUnderwriting and claimsIRA · ODPC
B-3Telecoms and mobile moneyPersonal data at scaleCA · ODPC
B-4Public sector and developmentAutomated eligibilityODPC · donors
B-5Professional services and legalClient confidentialityICPAK · LSK · ODPC

Sectors are a starting point, not a boundary. Manufacturing, agri-export, retail and education engagements run on the same method.

Index sheet·schedules follow

BSectors

Five schedules

Same method. Different things go wrong.

Each schedule sets out where AI actually creates exposure in that sector, what we do about it, and who inside the organisation usually owns the problem. The engagements themselves are the same four — register, guidance, guardrails, literacy — scoped to what the sector has to defend.

B-1/Banking and financial services

Central Bank of Kenya · ODPC · Data Protection Act 2019 · Basel model risk practice

Credit is where AI meets a customer's life first.

Lending, fraud, AML and collections are already model-driven across Kenyan banks, SACCOs, microfinance and digital credit providers. The models work. What is usually missing is the file behind them: who approved this score, on what data, tested against whom, and what a customer is told when the answer is no.

65%

of Kenyan lenders already using AI apply it to credit risk scoring — rising to 80% among digital credit providers.11

Where it goes wrong

Credit scoring on alternative data
Mobile-money and behavioural data make thin-file lending possible and make proxy discrimination easy. Both need testing, not assurance by assertion.
Adverse action you cannot explain
A declined applicant is entitled to a reason. A model that cannot produce one is a regulatory finding waiting to be written.
Vendor and embedded models
Core banking, scoring bureaux and fraud vendors ship models you did not build and cannot see inside. They are still yours to govern.

What we do

  • Model inventory across credit, fraud, AML, collections and customer service
  • Bias and stability testing on protected and proxy characteristics
  • Adverse-action explainability that a branch officer can actually deliver
  • Model risk management aligned to CBK expectations and your own board appetite
  • Third-party and alternative-data due diligence, including bureau feeds
  • Board and ALCO reporting pack, plus internal audit walkthroughs

Usually bought by

Chief Risk Officer · Head of Credit · Chief Internal Auditor · Data Protection Officer

B-2/Insurance and health cover

Insurance Regulatory Authority · ODPC · Data Protection Act 2019 · IFRS 17 model controls

Pricing, underwriting and claims are decisions about people.

Insurers are moving fast into AI-driven underwriting, claims triage and fraud detection, and the regulator has noticed. The exposure is concentrated: a pricing model that drifts on geography or age, or a triage model that quietly declines the same cohort twice, is a conduct problem before it is a technical one.

2026

The IRA is drafting tighter digital insurance rules covering cybersecurity, data protection and oversight of AI-driven underwriting.12

Where it goes wrong

Rating and underwriting drift
Models trained on historic books inherit historic exclusions. Without fairness testing across age, gender, geography and health status, you are automating them.
Claims triage without a human
Speed is the point of triage. Oversight has to be designed in deliberately, or there is nobody in the loop when it matters.
Health data classification
Health data is sensitive personal data under the Data Protection Act. Most insurers' AI systems touch it without the classification being written down anywhere.

What we do

  • Register of pricing, underwriting, triage, fraud and reserving models
  • Fairness testing across age, gender, geography and health status
  • Human oversight design for claims decisions, with escalation thresholds
  • Sensitive-data classification and DPIA support under the Data Protection Act
  • Actuarial and reserving model governance that ties into existing controls
  • Evidence pack for IRA engagement and reinsurer due diligence

Usually bought by

Chief Actuary · Chief Risk Officer · Head of Claims · Data Protection Officer

B-3/Telecoms and mobile money

Communications Authority of Kenya · ODPC · CBK for mobile money · NC4 for incidents

The largest personal data estates in the region.

Telcos and mobile money operators hold more behavioural data on more people than anyone else in East Africa, and they are deploying AI against it in churn, credit, KYC, fraud and increasingly in agentic customer service. Scale is the whole risk: a control that fails quietly fails against millions of people.

Where it goes wrong

Agents that act, not just answer
A customer-service agent with permission to change an account, issue a refund or unlock a line is taking actions, not drafting text. It needs release gates.
Consent and marketing automation
Opt-in consent, sender-ID registration and permitted sending hours are enforced. AI-driven campaign targeting does not get an exemption.
Mobile money and financial crime models
Transaction monitoring sits across two regimes at once — communications and financial services — and is audited by both.

What we do

  • Register spanning network, customer, credit and mobile-money AI
  • Consent, targeting and marketing-automation control review
  • Agent permissioning and staged release gates, assisted through to autonomous
  • Financial-crime and transaction-monitoring model governance
  • Cross-border transfer review for offshore model processing
  • AI incident response, tied into existing cyber and NC4 reporting routes

Usually bought by

CISO · Data Protection Officer · Head of Regulatory Affairs · Chief Internal Auditor

B-4/Public sector and development organisations

ODPC · Kenya National AI Strategy 2025–2030 · donor assurance frameworks

Decisions about people who cannot take their business elsewhere.

Government agencies and the donor-funded organisations headquartered in Nairobi are both moving AI into eligibility, targeting, verification and case management. Neither has a customer who can walk away, which is exactly why the standard of evidence has to be higher, not lower.

4 Aug 2026

Public consultation on the draft Kenya AI and Other Emerging Technologies Policy 2026 closes today.10

Where it goes wrong

Automated eligibility and targeting
A model that decides who receives a service, a grant or a payment is making a determination about a person. It has to be explainable to that person.
Donor and grant assurance
Funders increasingly ask what AI touched programme data and beneficiary records. An answer assembled after the question is asked is worth very little.
Procurement without AI clauses
Most vendor contracts predate the systems now being bought under them. The obligations you cannot pass through, you keep.

What we do

  • AI register across service delivery, case management and programme systems
  • Algorithmic impact assessment for citizen and beneficiary-facing decisions
  • Human-in-the-loop design for eligibility, verification and exception handling
  • AI clauses and due-diligence questions for procurement and grant agreements
  • Donor-ready assurance pack, mapped to the frameworks funders cite
  • Role-based literacy for programme, M&E and field staff

Usually bought by

Country Director · Programme Director · Head of Risk and Compliance · Grants lead

B-5/Professional services, audit and legal

ICPAK · Law Society of Kenya · ODPC · client contractual obligations

Privilege does not survive a paste into the wrong window.

Audit firms, law firms and consultancies hold other people's most sensitive material and bill on judgement. That combination makes unsanctioned AI use both the likeliest incident and the most expensive one — a confidentiality breach, a professional-conduct question and a client-relationship problem arriving together.

98%

of organisations have staff using AI tools that were never approved. In this sector, those tools are handling privileged material.1

Where it goes wrong

Client material in personal-plan tools
The fastest route to a reportable breach in this sector is a fee earner under deadline pressure with a free-tier account and good intentions.
Engagement letters that say nothing
If your terms do not address AI use on client matters, you are either in breach of an expectation or relying on one nobody wrote down.
Judgement that cannot be evidenced
Work product shaped by a model still has to be defensible in a quality review, an inspection or a court. That means a record of what the model did.

What we do

  • Register including personal-plan subscriptions and browser extensions
  • Confidentiality, privilege and matter-level data segregation controls
  • Client consent and engagement-letter language for AI-assisted work
  • Quality review and file-documentation standards for AI-assisted output
  • Independence and conflicts considerations where tooling is shared
  • Role-based literacy from partner through to graduate intake

Usually bought by

Managing Partner · Head of Risk and Quality · General Counsel · Data Protection Officer

CCoverage

What we map your controls to

One control library. Every framework anyone asks you about.

Controls get built once and referenced many times. We write them against your operating model, then map each one to the frameworks your regulators, your customers and your funders actually cite — so a new question does not start a new project.

ISO/IEC 420014

Voluntary in law, mandatory in procurement. Roughly two in five enterprise AI tenders in Europe now ask whether you hold it. Six to nine months if you already run ISO 27001; twelve to eighteen from a standing start.

NIST AI RMF5

Govern, Map, Measure, Manage across 72 subcategories, plus the Generative AI Profile and its twelve risk areas. The de facto control vocabulary for US enterprises and their suppliers.

Kenya DPA 20199

Registration with the ODPC is mandatory, and financial services, healthcare and telecommunications must register regardless of size. Penalties reach KES 5 million or 1% of annual turnover for controllers.

Policy packs held for

  • EU AI ActRegulation (EU) 2024/1689
  • ISO/IEC 42001AI management systems
  • NIST AI RMFAI 100-1
  • NIST AI 600-1Generative AI profile
  • Kenya DPA 2019ODPC registration, DPIA
  • Kenya AI Strategy2025–2030
  • Nigeria NDPA2023
  • South Africa POPIAAct 4 of 2013
  • AU AI StrategyContinental, 2024
  • ISO/IEC 27001Information security
  • SOX 404Model-driven controls
  • IFRS 17Insurance model controls

Hold a framework we have not listed? It maps to the same control library. Ask.

DKenya

The Kenyan position, as at 4 August 2026

The rules are further along than most boards think.

There is a persistent belief that Kenya has no AI regulation to speak of, so nothing needs doing yet. The Data Protection Act has been enforceable for years, registration is mandatory in the sectors that use AI most, and the policy layer above it is being written right now.

Nov 2019

In force

Data Protection Act 2019. Registration with the Office of the Data Protection Commissioner is mandatory, and financial services, healthcare and telecommunications must register regardless of size or revenue. High-risk processing requires a data protection impact assessment.9

27 Mar 2025

In force

Kenya National AI Strategy 2025–2030 launched: three pillars covering AI infrastructure, data ecosystems and governance, and research and commercialisation, with governance, talent, investment and ethics as cross-cutting enablers.10

4 Aug 2026

Closes today

Public consultation closes on the draft Kenya Artificial Intelligence and Other Emerging Technologies Policy 2026 — the document that will set the country's supervisory approach.10

2026

Being finalised

A Central Bank of Kenya Guidance Note on AI. In CBK's own survey, 93% of institutions asked for it — and half of lenders have not adopted AI at all yet, so it will land on a sector with little to show.11

2026

In drafting

Insurance Regulatory Authority rules on digital insurance, covering cybersecurity, data protection and supervision of AI-driven underwriting, blockchain fraud detection and IoT risk monitoring.12

ENext

Start with your sector. Finish with your file.

The first conversation is short. Tell us the sector, the regulator you answer to and what triggered the question — a board paper, a tender, an audit finding, or a tool somebody found. We will tell you plainly whether we can help.

Talk to an expert