Compliance & Due Diligence
Regulatory framework, licensing pathways, data protection, AML/KYC, and partnership structuring for the Ethiopian market
1. Regulatory Bodies & Their Roles
| Body | Full Name | Role in This Project |
| NBE | National Bank of Ethiopia | Primary regulator for all financial services. Issues banking, MFI, PII licenses. Sets interest rate caps, prudential standards, and AML/CFT requirements. |
| FIC | Financial Intelligence Center | AML/CFT authority. Receives suspicious activity reports (SARs). Threshold: report cash transactions ≥ ETB 200,000. |
| ECA | Ethiopian Communications Authority | Supervisory authority for data protection under PDPP 1321/2024. All data controllers/processors must register. |
| FCA | Federal Cooperative Agency | Regulates SACCOs under Cooperative Proclamation 985/2016. Important if partnering with SACCOs. |
| MoF | Ministry of Finance | Fiscal policy, taxation for financial institutions. Coordinates with NBE on macro-stability. |
2. Licensing Pathways
There are three viable paths for a tech company to operate a digital microcredit platform in Ethiopia. Each has different capital, regulatory, and operational implications.
Path A: Payment Instrument Issuer (PII) License High Barrier
Governed by the Licensing and Authorization of Payment Instrument Issuers Directive (latest: NPS/10/2025). A PII can offer digital wallets, micro-savings, micro-loans, and insurance.
Requirements:
- Minimum paid-up capital: ETB 50 million (for large-scale fintechs)
- NBE licensing application with business plan, capital proof, fit & proper assessment of directors
- Stringent KYC and AML compliance systems
- Data localization — all customer data stored within Ethiopia
- Cybersecurity standards: encryption, IDS, penetration testing, incident response plans
- Interoperability via national switch (EthSwitch) or licensed switch operator
⚠️ Not recommended for initial entry. ETB 50M capital requirement is prohibitive for a startup. The PII license also brings full regulatory burden (quarterly reporting, NBE examinations, prudential ratios). The pending digital lending bill may create a separate, lighter license category — waiting for this could be strategic.
Path B: Bank/MFI Partnership Model Recommended
Operate as a technology and distribution platform that partners with licensed banks or microfinance institutions. The bank/MFI holds the lending license and provides the capital; the tech company provides the platform, customer acquisition, and credit scoring.
How it works (proven model — Michu, Efoyta, Abol):
- Partnership agreement with a licensed bank or MFI — the institution retains regulatory responsibility for lending decisions
- Technology platform built and operated by the tech company — KYC, application, scoring, disbursement, repayment tracking
- Loan capital comes from the bank/MFI's balance sheet — the tech company does not hold the loan portfolio
- Revenue model: Technology fee (per-transaction or monthly SaaS) + revenue share on interest income + possible service fee from borrowers
- KYC/AML handled through the bank/MFI's existing compliance infrastructure
✅ This is the proven path. Michu (CBO + Kifiya), Efoyta (Wegagen + Qena), Abol (Bunna), Lewedaje (Amhara Bank), and Malefiya (Enat Bank) all operate under this model. No additional NBE license needed for the tech company itself. Faster time-to-market, lower capital requirement, shared regulatory burden.
Key Contractual Considerations:
- Revenue share structure — Must be compliant with NBE interest rate caps (16% for MFIs, market-based for banks)
- Data ownership — Clearly define who owns borrower data, especially under PDPP 1321/2024
- Liability allocation — Who bears default risk? Typically the bank/MFI, but terms vary
- Exclusivity vs. multi-partner — Avoid exclusive lock-in; the expanded vision requires multiple bank/MFI partners
- Termination clauses — Protect against sudden partnership dissolution
Path C: MFI License (if scaling to direct lending) Future Option
Governed by NBE Directive MFI/47/2018. An MFI can directly originate and hold loans.
Capital Requirements (Tiered):
| Tier | Minimum Capital | Operational Scope |
| Tier 3 | ETB 500,000 | Woreda-level operations |
| Tier 2 | ETB 5,000,000 | Zone-level operations |
| Tier 1 | ETB 20,000,000 | Regional / national operations |
Key constraint: MFIs face a 16% annual interest rate cap on all microloans (Directive MFI/47/2018). Maximum single loan: ETB 100,000. MFI licensing also requires 8% minimum capital adequacy, quarterly prudential reporting, and NBE examinations. This path only makes sense if the company intends to become a direct lender.
3. Data Protection — Proclamation 1321/2024
Ethiopia enacted its first comprehensive data protection law on July 24, 2024. The Personal Data Protection Proclamation No. 1321/2024 (PDPP) is modeled on the EU GDPR and applies to all entities processing personal data of individuals in Ethiopia.
Key Requirements
| Requirement | Detail | Impact on Project |
| Registration | Both data controllers and data processors must register with the ECA before processing data | Must do before launch — apply for ECA registration early |
| Data Localization | Personal data collected in Ethiopia must be stored domestically | Architectural constraint — use in-country data centers (no AWS/GCP outside Ethiopia) |
| Consent | Informed, explicit consent required for all data processing | Clear consent flows in the app; granular opt-in for data sharing with partners |
| Breach Notification | Notify ECA within 72 hours of a data breach | Need incident response plan; 24/7 monitoring capability |
| Data Subject Rights | Right to access, rectification, erasure, portability, objection | Must build user-facing data management features |
| Cross-Border Transfer | Requires ECA approval (typically denied) | All data processing must happen within Ethiopia |
| Post-Mortem Rights | Data subject rights survive for 10 years after death | Unique to Ethiopian law — plan for estate/death handling |
| Penalties | Financial and operational consequences for non-compliance | Non-compliance could result in fines, license issues, or operational shutdown |
⚠️ Data protection is non-negotiable. A microcredit app processes highly sensitive data: National IDs, trade licenses, facial biometrics, financial history, location data, contacts. The combination of PDPP 1321/2024 + NBE data residency requirements + AML data handling rules creates a strict compliance envelope. Build compliance into the architecture from day one — retrofitting is expensive and risky.
4. AML / KYC Requirements
Governed by NBE Directive AML/01/2021. All financial service providers must implement comprehensive customer due diligence.
Customer Identification (CIP)
- Full name, date of birth, nationality, address verification
- Government-issued ID (National ID, Passport, Driver's License)
- Kebele ID for Ethiopian residents
- Beneficial ownership disclosure for legal entities
- Source of funds declaration for high-value accounts
- Occupation, employer, and income verification
Enhanced Due Diligence (EDD)
- Required for Politically Exposed Persons (PEPs) — senior management approval
- High-value customers (>ETB 1M deposits)
- Foreign nationals and non-resident accounts
- Source of wealth documentation and annual review
Transaction Monitoring & Reporting
- Cash transactions ≥ ETB 200,000 → report to FIC
- Suspicious activity reports (SAR) filed within 3 business days
- Wire transfers ≥ ETB 200,000 flagged for review
- Structuring pattern detection (multiple small deposits)
- Monthly AML compliance report to board
ℹ️ Practical note on KYC: The original proposal used National ID + Trade License + selfie/liveness check. This is aligned with NBE requirements. For the expanded platform, consider adding mobile money account verification (Telebirr/M-Pesa transaction history as alternative credit data) and Kebele ID as a supplementary ID document.
5. Interest Rate Regulations
| Institution Type | Rate Framework | Cap / Guideline |
| MFIs | Hard cap | 16% per annum on all microloans (Directive MFI/47/2018). Penalties for violations include fines and license suspension. |
| Commercial Banks | Market-based | No hard cap. NBE monitors excessive spreads (>6-7% between deposit and lending rates). Typical range: 14-22%. |
| SACCOs | Member-approved | "Reasonable" rates set by general assembly. Typical range: 10-18%. |
| Digital Lenders (via PII) | No specific cap yet | Telebirr charges 3% facilitation fee + 0.3-1.2% daily penalty. No explicit NBE cap for PII-originated digital credit. |
Strategic implication: If partnering with an MFI, the 16% cap applies and limits revenue. If partnering with a bank, rates are more flexible but subject to NBE monitoring. The pending digital lending bill may introduce a specific rate framework for digital credit — this is a key variable to watch.
6. Credit Reference Bureau (CRB)
⚠️ Critical gap: The NBE Credit Reference Bureau (established under Directive CRB/02/2019) is not yet open for digital lender referencing. As of 2025, the CRB primarily serves traditional banks and MFIs. Digital lending platforms must build their own credit scoring capabilities using alternative data — they cannot rely on centralized credit bureau data for borrower assessment.
This means:
- No centralized credit history lookup for new borrowers
- Must develop proprietary scoring using: mobile money transaction data, POS/merchant activity, trade license history, employer/income data, device metadata
- Cross-platform default tracking is not possible via CRB — creates risk of over-indebtedness
- The NBE's Digital Payments Strategy 2026-2030 includes "developing a framework for private-sector credit reference bureaus" — but this is in early stages
7. Pending Digital Lending Bill
First reported in late 2022, the NBE has been developing a draft bill to establish a special licensing framework for digital credit providers. As of July 2025, this bill has not been enacted.
What We Know:
- The bill aims to create a dedicated license category for digital credit issuers (separate from banking and PII licenses)
- The NBE's Digital Payments Strategy 2026-2030 (Action 75) calls for "clear directives for digital lending (credit, peer-to-peer lending), digital savings, and digital insurance products" within 24 months
- Kenya's experience with the Digital Credit Providers Regulations (2022) is being studied as a model
- No timeline or specific requirements have been published
ℹ️ Strategic recommendation: Do not wait for this bill to launch. Structure operations under the bank partnership model (which is already legal and proven), but build the architecture to be adaptable. If the new law creates a lighter license category, you can pivot. If it imposes stricter requirements, compliance features are already built in.
8. Compliance Checklist
| Item | Priority | Status | Notes |
| ECA data controller registration (PDPP 1321/2024) | Critical | Not started | Must complete before any data processing |
| Data localization infrastructure | Critical | Not started | In-country data center; evaluate local cloud providers |
| Bank/MFI partnership agreement | Critical | Not started | Legal counsel needed; define revenue share, liability, data ownership |
| AML/KYC policy document | Critical | Not started | Must align with NBE Directive AML/01/2021 |
| FIC registration for SAR reporting | High | Not started | Required before handling transactions ≥ ETB 200K |
| Alternative credit scoring system | High | Not started | CRB not available; must build proprietary |
| Privacy policy & T&C (PDPP-compliant) | High | Not started | Informed consent, data subject rights, breach notification process |
| Incident response plan (72-hr breach) | High | Not started | 24/7 monitoring capability needed |
| Annual security audit capability | Medium | Not started | Penetration testing, IDS, encryption validation |
| Business continuity / disaster recovery | Medium | Not started | RTO < 24hrs, daily backups within Ethiopia |
| Record retention system (5+ years) | Medium | Not started | Immutable audit trails with timestamp verification |
| NBE digital lending bill monitoring | Medium | Ongoing | Assign someone to track NBE circulars |
9. Foreign Investment Considerations
In December 2024, Ethiopia passed a law allowing foreign banks and financial institutions to enter the market. Key provisions:
- Foreign entities can open branches or subsidiaries
- Maximum foreign ownership capped at 40%
- FDI must be made in foreign currency
- First investment banking licenses issued March 2025 (CBE Capital, Wegagen Capital)
ℹ️ Relevance: If Forge Technologies seeks foreign investment or partnerships for this platform, the 40% foreign ownership cap applies. This is relevant for structuring equity arrangements with potential international fintech partners or investors.
10. Recommended Legal Structure
Suggested Architecture
Based on the analysis above, the recommended compliance architecture is:
- Forge Technologies operates as the technology platform provider (not a licensed financial institution)
- Partnership agreements with 2-3 licensed banks/MFIs — each institution provides lending license coverage and loan capital
- Data controller registration with ECA under PDPP 1321/2024 — Forge is the data controller for customer data
- KYC handled through bank/MFI compliance infrastructure — Forge collects and verifies, bank/MFI approves
- Telebirr/M-Pesa integration for disbursement and repayment — leverage existing mobile money rails
- Proprietary credit scoring engine — AI/ML model using alternative data, deployed on in-country infrastructure
- Revenue model: SaaS fee to bank/MFI + revenue share on interest + borrower service fee