AI Governance Workbench for Small Regulated Lenders
Regulated lenders are adopting AI faster than they are formalising governance, and nearly all respondents to a regulator’s survey asked for guidance that has not yet been issued.
Evidence
The Central Bank of Kenya’s Bank Supervision Annual Report 2025 (section 2.10.3, published 22 September 2026) restates a survey issued in March 2025 on data as of 31 December 2024. Of surveyed institutions, 50 percent had adopted AI (66 percent of commercial banks, 57 percent of microfinance banks, 43 percent of digital credit providers, and no credit reference bureaus); 30 percent had a formal AI strategy; and 93 percent of respondents recommended that CBK issue comprehensive guidance on AI covering governance and compliance, risk management, and incident management and reporting. Among institutions that had adopted AI, the leading uses were credit risk assessment (65 percent), cybersecurity (54 percent), and customer service (43 percent). Respondents named limited AI-skilled staff, high costs, and data and governance compliance as challenges. CBK says the findings will inform a Guidance Note on AI for the banking sector. Kenya’s Office of the Data Protection Commissioner issued its own Guidance Note on Artificial Intelligence in July 2026, which defines credit scoring as a high-risk application and covers automated decision-making and data protection impact assessments. The survey is self-reported, and the standalone survey lists 125 respondents, more than half of them digital credit providers. A governance workbench is an AfriAI build hypothesis; these sources do not show demand or willingness to pay.
First customer
Microfinance institutions and digital credit providers in Kenya that already use or pilot AI for credit scoring, fraud, or e-KYC. Zambian lenders are a follow-on market once local guidance is clear.
Build path
- 1. Ship an AI system inventory and risk-tier template built around the survey’s use-case categories and the three areas respondents asked guidance on.
- 2. Add model documentation, challenger-versus-incumbent validation reports, and a data protection impact assessment checklist based on the ODPC guidance, adapted after local legal review.
- 3. Add an incident log and an exportable regulator pack; pilot with two lenders and keep the schema easy to re-cut when CBK’s guidance note is issued.
Risks
- Guidance is not yet issued, so requirements may differ from what is built.
- Documentation tooling can become checkbox compliance that changes no outcomes.
- Survey results are self-reported, date from March 2025, and are dominated by digital credit providers.
Next action
Interview 10 risk and compliance officers at microfinance banks and digital lenders: what would they need to answer a regulator’s AI questionnaire this quarter?
Last reviewed 2026-09-29 · Monthly review cadence
Get the next Field Desk brief by email
Sourced African tech signals — one email, every Monday.
More FinTech teardowns
AI Credit Scoring for Informal Economy Workers
Map three lenders with default data and one mobile-money partner with consented transaction access.
Consent and Statement-Sharing Tooling for Zambian Lenders Ahead of Open Finance
Interview 8-10 Zambian lenders on how they obtain and verify statements today and how many applications stall on missing or unverifiable data; ask the Bank of Zambia Payment Systems Department for its consultation timetable.
Read the weekly radar
Signals that mature into teardowns like this one — delivered every week.
Subscribe on the blogOpportunity teardowns are editorial analysis, not investment, financial, or business advice. Market sizes and projections are estimates — do your own diligence. Read the full disclaimer.