Infrastructure engineering for East Africa's operators, platforms and regulators See the work →
CBK Outsourcing Approval for Cloud and Disaster Recovery
Cloud 8 min read

CBK Outsourcing Approval for Cloud and Disaster Recovery

CBK outsourcing approval comes before you sign, not after. What PG/16 counts as material, the access test that decides offshore, and the January report.

AH
Amina Hassan
Cybersecurity, Compliance, Network Security
5 September 2026
cbkoutsourcingcompliancedisaster recovery

The board paper is approved, the provider is chosen, the contract is with the lawyers. If your institution is licensed under the Banking Act, you are already out of sequence.

CBK outsourcing approval is not a notification and not a form. It is a written proposal, submitted before the arrangement is entered into, that CBK either approves or does not. CloudSpinx builds and runs disaster recovery and cloud estates for regulated institutions in Kenya, and we write the submissions that go with them, so what follows is CBK/PG/16 read from the delivery side. Every quote is from the guideline's own text inside the Prudential Guidelines, which is published in full and searchable.

What CBK counts as material outsourcing

There is a bright line, and most people arguing about materiality have never read it. Paragraph 1.4.5 lists the qualitative tests you would expect, being the importance of the activity, the impact on earnings and risk profile, the reputational damage if the provider fails, the cost as a proportion of total operating costs, and your aggregate exposure to that one provider. Then it ends with a number: "An activity is considered material if it accounts for at least five percent (5%) of the institution's revenues or costs."

The guideline also names examples, eleven of them, and four are exactly what an infrastructure buyer is shopping for:

  • Information system management and maintenance, which it spells out as data entry and processing, data centers, facilities management, end user support and help desks
  • Business continuity and disaster recovery
  • Application processing, including loan originations and credit cards
  • Provision of mobile financial services channels and technology

So a DR site, a managed data center footprint, a service desk and a mobile banking channel are all material outsourcing by the guideline's own examples, not by anybody's interpretation.

Two details catch institutions that did their filing years ago. An arrangement that was not material can become material later: paragraph 4.5.9.3 says so directly, through incremental activities going to the same provider, a rise in volume, a change in the nature of the activity, or the provider changing its own subcontracting. The support contract nobody filed in year one is a different animal in year four. And non-material outsourcing is not silent either, because 4.1.3 requires notification for courier, mail, printing, background checks and contract staff. There is no tier at which CBK hears nothing.

CBK outsourcing approval comes before the arrangement, not the design

Paragraph 4.6.1 is one sentence: an institution should not enter into any outsourcing arrangement of a material function before getting approval from CBK. Proposals go in writing "well in advance of the date on which it is intended that the outsourcing will commence".

What the proposal contains decides how long it takes to write, and 4.6.4 sets it: the rationale, details of the proposed service provider, a risk matrix identifying the risks and how each is mitigated, the draft outsourcing agreement, and a description of the methods the institution will use to retain its ability to control and monitor the outsourced function.

Read that list against a project plan and the sequence inverts. The draft agreement has to exist before the approval, and the approval has to exist before signature, so contract negotiation moves ahead of a decision most institutions treat as the last step. The item that takes longest to write is the last one, because retained control describes an operating model rather than a product: who watches the provider, against what, with which reports, and what you do when the numbers slip. A provider who cannot help you write that paragraph has told you something about how they intend to run the service.

Then it repeats annually. Paragraph 4.11 requires every institution to report to CBK what it has outsourced, by 15 January each year, naming the activity and the date the arrangement commenced. The register that report comes out of is a separate requirement: a central record of all material outsourcing, kept current and readable by the board.

The offshore test is access, not geography

Nothing in PG/16 bars a foreign provider. The constraint is narrower and sharper: an institution "should not outsource to jurisdictions where unfettered access to information by CBK or its authorized person, and the internal and external auditors of the bank, may be impeded by legal or administrative restrictions", and CBK may go directly to the home or host regulator of the provider to confirm the position.

Around that sit three conditions worth putting in a shortlist rather than discovering in legal review. Offshore arrangements should only be with parties in jurisdictions that generally uphold confidentiality clauses. The governing law of the arrangement has to be clearly specified. Country risk needs contingency and exit strategies, monitored continuously rather than assessed once. And 4.7.6 carries the clause that collides quietly with a global cloud contract: you must seek CBK authority if any overseas authority seeks access to your customer information.

CBK's outsourcing test is access to the records, not the country
CBK's outsourcing test is access to the records, not the countryTwo placements enter the same test. A provider in Kenya and a cloud region abroad both arrive at one question from paragraph 4.7.5 of CBK/PG/16: whether CBK, the persons it authorizes and the institution's internal and external auditors can reach the records held by the provider within a reasonable time, unimpeded by legal or administrative restrictions. Where the agreement carries that access route, either placement can be approved. Where it does not, neither can, because paragraph 4.6.5 applies the same duty whether the provider sits in Kenya or abroad.IN KENYAProvider down the roadNairobi colocation or managed DROFFSHORECloud region abroadCape Town or FrankfurtThe testcan CBK, the persons itauthorizes and your auditorsreach the records withina reasonable time?PG/16 4.7.5IF YESApprovableon the clause plus prior approvalIF NONot approvable4.6.5 includes Kenya too
A rack in Nairobi is not compliance and a rack in Frankfurt is not a breach. The agreement either gives the regulator and your auditors a route to the records, or the arrangement fails the test wherever the rack is.

The test is passed or failed at drafting. Access is a clause somebody either negotiated into the agreement or did not, months before an examiner asks to follow it.

The same test reaches a provider down the road. Paragraph 4.6.5 says outsourcing, whether the provider sits in Kenya or abroad, must not impede the institution's ability to oversee its activities or impede CBK in carrying out its supervisory functions. "We kept it in Kenya" answers a residency question that PG/16 never asked. The instrument that does put infrastructure in the country is elsewhere, and we walk through which Kenyan rule actually catches you separately, because it is regulation 28 rather than anything from CBK.

The clauses the agreement has to carry

Paragraph 4.5.6 lists what the contract must contain, and four items are the ones a provider will push back on.

You get the right to audit the provider, through your internal or external auditors or agents acting for you, and to obtain copies of audit and review reports on that provider. CBK gets a clause allowing it, or persons it authorizes, to reach your documents, records of transactions and other information given to, stored or processed by the provider within a reasonable time, and the clause carries a tail: where those are not made accessible within a reasonable time, CBK may pursue the remedial actions and administrative sanctions under the Banking Act. CBK also keeps the right to cause an inspection of the provider itself, its books and its accounts. And the contract must require your approval before the provider uses subcontractors for any part of the work.

That last one is the same exposure as the sub-processor chain in an ordinary commercial contract, and it is the clause that quietly breaks when a provider changes a backup vendor. We covered the general version in what a managed IT contract has to say, including the breach clocks under the Data Protection Act. Keep them separate in your head: those clocks answer to the Data Commissioner, and the ones here answer to CBK.

Security breaches have their own line here too. Under 4.5.7 the institution notifies CBK immediately of any breach of security or leakage of confidential customer information, and the guideline states plainly that in those events the institution is liable to its customers for damage.

Payment service providers get a stricter version

If you are authorized under the National Payment System Act instead, the clock is explicit. The Guideline on Cybersecurity for Payment Service Providers requires you to notify CBK of an intention to outsource functions, services and infrastructure at least thirty days before the agreement is executed.

Its contract list is shorter and pointed: security incident reporting, the PSP's and CBK's right to audit the service provider, and penalty clauses for security lapses. The CBK access clause is there as well, with sanctions under the NPS Act rather than the Banking Act. Incident notification runs at 24 hours for a PSP and 2 hours for a system-wide important or systemically important payment system, which is the tightest clock in this stack of instruments. The governance, oversight and management functions of the CISO cannot be outsourced at all, whatever else moves, which shapes what a security retainer can honestly cover and is why our security work sits under a named person on your side.

Nairobi cityscape, where most Kenyan banks, microfinance banks and payment service providers hold their head offices

If you are not licensed under the Banking Act

Paragraph 1.3 is where the guideline states its own reach: it "applies to all institutions licensed under the Banking Act (cap 488) who desire to outsource aspects of their activities". A deposit-taking microfinance bank is licensed under the Microfinance Act, so on the text PG/16 does not bind it. A deposit-taking SACCO answers to SASRA.

The honest position is that the text and the practice differ. CBK supervises microfinance banks under the same risk-based framework, examiners and external auditors ask the same outsourcing and continuity questions, and CBK has itself identified the absence of dedicated cyber and continuity guidance for microfinance as a gap. So treat the banking instruments as the standard you will be measured against, and say out loud which parts are law and which parts are supervisory expectation. If a vendor tells a microfinance CEO that PG/16 legally binds them, the CEO reads paragraph 1.3 and the vendor loses the room. Institutions in that position usually want the operating discipline without the filing, which is closer to how we scope managed IT than a bank engagement.

What people get wrong

That approval is a formality to complete after go-live. It is not: 4.6.1 puts it before the arrangement is entered into, and the twelve-month window in Part V was a transitional provision for arrangements that already existed when the guideline commenced, not a grace period for new ones.

That offshore is banned. It is not. The test is whether CBK and your auditors can reach the records, which is a question about the jurisdiction and the contract rather than the distance.

That the provider carries the compliance. Paragraph 4.2.1 says outsourcing does not diminish the institution's legal obligations and the board and senior management retain ultimate responsibility. A good provider does not absorb your obligation, it makes your side of it provable: the reports, the test evidence, the access route, the exit.

If you are weighing a move, send us your license type and the systems you are thinking of moving, and we will tell you whether it looks material, what the submission has to contain, and where the honest answer is to keep it where it is. That review is free and commits you to nothing: use the scoping form or WhatsApp us on +254 713 403 044.

WhatsApp