Compliance & Due Diligence

Regulatory framework, licensing pathways, data protection, AML/KYC, and partnership structuring for the Ethiopian market

1. Regulatory Bodies & Their Roles

BodyFull NameRole in This Project
NBENational Bank of EthiopiaPrimary regulator for all financial services. Issues banking, MFI, PII licenses. Sets interest rate caps, prudential standards, and AML/CFT requirements.
FICFinancial Intelligence CenterAML/CFT authority. Receives suspicious activity reports (SARs). Threshold: report cash transactions ≥ ETB 200,000.
ECAEthiopian Communications AuthoritySupervisory authority for data protection under PDPP 1321/2024. All data controllers/processors must register.
FCAFederal Cooperative AgencyRegulates SACCOs under Cooperative Proclamation 985/2016. Important if partnering with SACCOs.
MoFMinistry of FinanceFiscal policy, taxation for financial institutions. Coordinates with NBE on macro-stability.

2. Licensing Pathways

There are three viable paths for a tech company to operate a digital microcredit platform in Ethiopia. Each has different capital, regulatory, and operational implications.

Path A: Payment Instrument Issuer (PII) License High Barrier

Governed by the Licensing and Authorization of Payment Instrument Issuers Directive (latest: NPS/10/2025). A PII can offer digital wallets, micro-savings, micro-loans, and insurance.

Requirements:

⚠️ Not recommended for initial entry. ETB 50M capital requirement is prohibitive for a startup. The PII license also brings full regulatory burden (quarterly reporting, NBE examinations, prudential ratios). The pending digital lending bill may create a separate, lighter license category — waiting for this could be strategic.

Path B: Bank/MFI Partnership Model Recommended

Operate as a technology and distribution platform that partners with licensed banks or microfinance institutions. The bank/MFI holds the lending license and provides the capital; the tech company provides the platform, customer acquisition, and credit scoring.

How it works (proven model — Michu, Efoyta, Abol):

  1. Partnership agreement with a licensed bank or MFI — the institution retains regulatory responsibility for lending decisions
  2. Technology platform built and operated by the tech company — KYC, application, scoring, disbursement, repayment tracking
  3. Loan capital comes from the bank/MFI's balance sheet — the tech company does not hold the loan portfolio
  4. Revenue model: Technology fee (per-transaction or monthly SaaS) + revenue share on interest income + possible service fee from borrowers
  5. KYC/AML handled through the bank/MFI's existing compliance infrastructure
✅ This is the proven path. Michu (CBO + Kifiya), Efoyta (Wegagen + Qena), Abol (Bunna), Lewedaje (Amhara Bank), and Malefiya (Enat Bank) all operate under this model. No additional NBE license needed for the tech company itself. Faster time-to-market, lower capital requirement, shared regulatory burden.

Key Contractual Considerations:

Path C: MFI License (if scaling to direct lending) Future Option

Governed by NBE Directive MFI/47/2018. An MFI can directly originate and hold loans.

Capital Requirements (Tiered):

TierMinimum CapitalOperational Scope
Tier 3ETB 500,000Woreda-level operations
Tier 2ETB 5,000,000Zone-level operations
Tier 1ETB 20,000,000Regional / national operations
Key constraint: MFIs face a 16% annual interest rate cap on all microloans (Directive MFI/47/2018). Maximum single loan: ETB 100,000. MFI licensing also requires 8% minimum capital adequacy, quarterly prudential reporting, and NBE examinations. This path only makes sense if the company intends to become a direct lender.

3. Data Protection — Proclamation 1321/2024

Ethiopia enacted its first comprehensive data protection law on July 24, 2024. The Personal Data Protection Proclamation No. 1321/2024 (PDPP) is modeled on the EU GDPR and applies to all entities processing personal data of individuals in Ethiopia.

Key Requirements

RequirementDetailImpact on Project
RegistrationBoth data controllers and data processors must register with the ECA before processing dataMust do before launch — apply for ECA registration early
Data LocalizationPersonal data collected in Ethiopia must be stored domesticallyArchitectural constraint — use in-country data centers (no AWS/GCP outside Ethiopia)
ConsentInformed, explicit consent required for all data processingClear consent flows in the app; granular opt-in for data sharing with partners
Breach NotificationNotify ECA within 72 hours of a data breachNeed incident response plan; 24/7 monitoring capability
Data Subject RightsRight to access, rectification, erasure, portability, objectionMust build user-facing data management features
Cross-Border TransferRequires ECA approval (typically denied)All data processing must happen within Ethiopia
Post-Mortem RightsData subject rights survive for 10 years after deathUnique to Ethiopian law — plan for estate/death handling
PenaltiesFinancial and operational consequences for non-complianceNon-compliance could result in fines, license issues, or operational shutdown
⚠️ Data protection is non-negotiable. A microcredit app processes highly sensitive data: National IDs, trade licenses, facial biometrics, financial history, location data, contacts. The combination of PDPP 1321/2024 + NBE data residency requirements + AML data handling rules creates a strict compliance envelope. Build compliance into the architecture from day one — retrofitting is expensive and risky.

4. AML / KYC Requirements

Governed by NBE Directive AML/01/2021. All financial service providers must implement comprehensive customer due diligence.

Customer Identification (CIP)

Enhanced Due Diligence (EDD)

Transaction Monitoring & Reporting

ℹ️ Practical note on KYC: The original proposal used National ID + Trade License + selfie/liveness check. This is aligned with NBE requirements. For the expanded platform, consider adding mobile money account verification (Telebirr/M-Pesa transaction history as alternative credit data) and Kebele ID as a supplementary ID document.

5. Interest Rate Regulations

Institution TypeRate FrameworkCap / Guideline
MFIsHard cap16% per annum on all microloans (Directive MFI/47/2018). Penalties for violations include fines and license suspension.
Commercial BanksMarket-basedNo hard cap. NBE monitors excessive spreads (>6-7% between deposit and lending rates). Typical range: 14-22%.
SACCOsMember-approved"Reasonable" rates set by general assembly. Typical range: 10-18%.
Digital Lenders (via PII)No specific cap yetTelebirr charges 3% facilitation fee + 0.3-1.2% daily penalty. No explicit NBE cap for PII-originated digital credit.
Strategic implication: If partnering with an MFI, the 16% cap applies and limits revenue. If partnering with a bank, rates are more flexible but subject to NBE monitoring. The pending digital lending bill may introduce a specific rate framework for digital credit — this is a key variable to watch.

6. Credit Reference Bureau (CRB)

⚠️ Critical gap: The NBE Credit Reference Bureau (established under Directive CRB/02/2019) is not yet open for digital lender referencing. As of 2025, the CRB primarily serves traditional banks and MFIs. Digital lending platforms must build their own credit scoring capabilities using alternative data — they cannot rely on centralized credit bureau data for borrower assessment.

This means:

7. Pending Digital Lending Bill

First reported in late 2022, the NBE has been developing a draft bill to establish a special licensing framework for digital credit providers. As of July 2025, this bill has not been enacted.

What We Know:

ℹ️ Strategic recommendation: Do not wait for this bill to launch. Structure operations under the bank partnership model (which is already legal and proven), but build the architecture to be adaptable. If the new law creates a lighter license category, you can pivot. If it imposes stricter requirements, compliance features are already built in.

8. Compliance Checklist

ItemPriorityStatusNotes
ECA data controller registration (PDPP 1321/2024)CriticalNot startedMust complete before any data processing
Data localization infrastructureCriticalNot startedIn-country data center; evaluate local cloud providers
Bank/MFI partnership agreementCriticalNot startedLegal counsel needed; define revenue share, liability, data ownership
AML/KYC policy documentCriticalNot startedMust align with NBE Directive AML/01/2021
FIC registration for SAR reportingHighNot startedRequired before handling transactions ≥ ETB 200K
Alternative credit scoring systemHighNot startedCRB not available; must build proprietary
Privacy policy & T&C (PDPP-compliant)HighNot startedInformed consent, data subject rights, breach notification process
Incident response plan (72-hr breach)HighNot started24/7 monitoring capability needed
Annual security audit capabilityMediumNot startedPenetration testing, IDS, encryption validation
Business continuity / disaster recoveryMediumNot startedRTO < 24hrs, daily backups within Ethiopia
Record retention system (5+ years)MediumNot startedImmutable audit trails with timestamp verification
NBE digital lending bill monitoringMediumOngoingAssign someone to track NBE circulars

9. Foreign Investment Considerations

In December 2024, Ethiopia passed a law allowing foreign banks and financial institutions to enter the market. Key provisions:

ℹ️ Relevance: If Forge Technologies seeks foreign investment or partnerships for this platform, the 40% foreign ownership cap applies. This is relevant for structuring equity arrangements with potential international fintech partners or investors.

10. Recommended Legal Structure

Suggested Architecture

Based on the analysis above, the recommended compliance architecture is:

  1. Forge Technologies operates as the technology platform provider (not a licensed financial institution)
  2. Partnership agreements with 2-3 licensed banks/MFIs — each institution provides lending license coverage and loan capital
  3. Data controller registration with ECA under PDPP 1321/2024 — Forge is the data controller for customer data
  4. KYC handled through bank/MFI compliance infrastructure — Forge collects and verifies, bank/MFI approves
  5. Telebirr/M-Pesa integration for disbursement and repayment — leverage existing mobile money rails
  6. Proprietary credit scoring engine — AI/ML model using alternative data, deployed on in-country infrastructure
  7. Revenue model: SaaS fee to bank/MFI + revenue share on interest + borrower service fee