When a customer walks into a shop in Kenya, whether they pay through M-Pesa, Airtel Money, a bank app, or another digital wallet determines which payment route they and the merchant use.
But a new proposed law could make these distinctions less important by pushing Kenya’s digital financial sector toward systems that can communicate with each other and allowing customers to share their financial data with other service providers.
The National Payment System Bill, 2026, introduces mandatory interoperability and open finance, which would reshape how fintechs build their products.
The proposed law requires payment service providers and payment system operators to use systems that can connect with those of other providers, operators and their agents.
Payment service providers handle customer-facing transactions, such as M-Pesa and Airtel Money, while payment system operators such as Pesalink own the underlying infrastructure for settling funds between financial institutions.
The Central Bank of Kenya (CBK) would also have the power to require providers to enter into interoperability arrangements.
This means fintechs would have less room to operate entirely closed payment systems. Different networks would connect, allowing money and payment instructions to move more easily between providers.
Kenya has already moved toward this model through mobile money interoperability and bank-to-mobile-money connections. For example, customers using Airtel Money can pay for goods at stores that use Safaricom’s M-Pesa till numbers.
The Bill seeks to make interoperability a broader feature of the national payment infrastructure rather than something individual providers choose to offer.
“Each payment service provider or payment system operator shall use systems that are interoperable with the systems used by other payment service providers and payment system operators, and their agents,” the Bill says.
For fintechs, this could change how they design their products. Instead of building around a single bank, wallet or payment network, a startup could build services that connect to several providers.
The bill defines open finance as allowing a third party, with a customer’s permission, to access and use data held by a payment service provider to offer new or improved services or develop new business models.
It also creates the concept of an account information service, which could allow information from accounts held with different providers to be brought together.
For instance, a Kenyan can have a salary account at one bank, a savings account at another, M-Pesa for everyday spending and a digital loan elsewhere.
Today, each institution largely sees only part of that person’s finances and the customer has to move between different apps, while the institutions have limited visibility of accounts held elsewhere.
Under open finance, the customer could authorise third-party applications to access information from several accounts and present it in one place.
This information could support other financial services: a personal-finance app could analyse spending across accounts, and a lender could, with permission, assess a customer’s financial activity across several providers instead of relying only on its own records.
Similarly, a small business seeking working capital could allow a lender to examine its transaction history across different payment channels.
The proposed law also introduces payment initiation services, enabling users to initiate online payments without directly interacting with their bank or financial service provider. This could allow fintechs to build new payment services on top of existing financial infrastructure. This model is already more developed in markets such as the UK, where regulated third-party providers can access account information and initiate payments with customer permission.
For Kenya’s fintech sector, this could create room for startups built around the data and infrastructure of established financial institutions. However, the financial system also creates new risks.
Because transaction histories can reveal income, spending habits, regular payments, relationships and financial difficulties, giving more third parties access to this information makes cybersecurity, data protection and clear customer consent critical.
Recent research by UK law firm TLT Solicitors found that half of financial services companies are concerned about the increased fraud risk as a result of the larger ‘attack surface’ open banking can give hackers.
The technology also raises the question of fraud and liability. If a customer authorises a payment through a third-party fintech and the transaction turns out to be fraudulent, the industry will need clear rules on who is responsible – the bank, fintech, payment system or customer.
As such, regulators globally have had to develop rules covering authentication, consent, data security, liability, complaints and the responsibilities of third-party providers.
Kenya’s bill does not specify how access would work and says the CBK “shall make regulations to give effect to this section.”
Details on what data can be accessed, under what conditions, and at what cost would be left to subsequent CBK regulations.
Opening access to financial infrastructure could also make it easier for smaller fintechs to compete with established institutions.
However, experts have warned that this may give large financial and technology companies room to exploit their customer bases and datasets, meaning open finance does not automatically produce a more competitive market.