Skip to content
Compliance guide · Kenya

What are SASRA IT audit requirements?

SASRA Circular SASRA/GG/1/2023 sets binding IT-audit, penetration-testing, and vendor-security requirements for any third-party system integrator serving a Kenyan SACCO.

The actual source, not a rumor

There isn't a single document called "the SASRA IT audit requirements" — but there is a real, binding one that answers the question: Circular SASRA/GG/1/2023, "Minimum Requirements for Engagement of Third-Party Financial System Integrators and Vendors," dated 6 June 2023. It sets out what SASRA expects from any fintech or system vendor a SACCO engages — which in practice is where most of a SACCO's IT-audit exposure actually comes from, since core banking, mobile money processing, and member channels are usually vendor-delivered.

What the circular requires of a vendor

  • Bi-annual penetration testing by a reputable audit firm.
  • Annual full IT audit covering governance and internal policies, change management, application controls, identity and access management, business continuity, disaster recovery, and penetration testing.
  • Unfettered access for SASRA to systems and audit reports on request.
  • 24/7 cybersecurity monitoring, with attack or attempted-attack incidents reported to SASRA within 12 hours.
  • Financial backing for the float: a bank guarantee covering at least 10% of the float held at the SACCO's mobile-money B2C (Paybill) account, plus an insurance indemnity policy covering the remaining balance.
  • Segregated environments per SACCO served, and separate development, test, and production environments.
  • For M-Pesa integrations specifically: mandatory onboarding to the "Umbrella Fraud Detection" solution named in the circular.
  • Annual staff due-diligence checks, with exit reporting to SASRA when integrator staff leave.
  • Compliance with the Data Protection Act, the National Payment System Act, and referenced technical standards including ISO 27001, COBIT, NIST, and CIS.

What this means for a SACCO evaluating a vendor

A SACCO board doesn't need to take a vendor's security claims on faith — these are the specific, named things SASRA expects from any third-party integrator, and a SACCO can ask a prospective vendor for evidence against each one: current penetration-test and IT-audit reports, the bank guarantee, and confirmation of segregated per-SACCO environments. SASRA also reserves the right to bar a SACCO from continuing to use an integrator that doesn't meet these standards or has a poor security track record.

Related pages