Skip to main content

Zade Associates

Zade

Governance, The New Competitive Advantage

Governance, The New Competitive Advantage

by Zade

Credits to Robert Maithia | Business Dev. Officer | Zade Associates LLP

Tomorrow’s market leaders will be defined not only by what they sell, but by how they are governed.

Picture two companies standing side by side. Same industry, same revenue and same ambition to expand across borders and raise capital for the next stage of growth. One has a founder who still signs every cheque personally, a board that exists mostly on paper and financial records that live in someone’s head as much as in the ledger. The other has an independent board that challenges management, a finance function that closes its books the same way every quarter and a succession plan that doesn’t depend on one person staying healthy and interested forever. Ask an investor which one they’d rather back. You already know the answer, and it has nothing to do with either company’s product.

For decades, the growth playbook was straightforward, build something better than the competitor, execute well, and let the market reward you. That playbook hasn’t disappeared, but it’s no longer enough on its own. Markets are more connected, disruption moves faster, regulators ask sharper questions, and everyone is paying closer attention to what happens behind the scenes. The thing quietly deciding who wins from here isn’t visible on any balance sheet. It’s governance.

Not the compliance-binder version of governance, committees and policies gathering dust in a filing cabinet. The real thing – the systems, habits and culture that let an organization make good decisions, catch problems early and earn the kind of trust that opens doors. The businesses that thrive over the next decade won’t just have the best products; they’ll be the ones that people trust to build value and to keep it.

Governance Is an Asset, Not Paperwork

Ask most people what “governance” means and they’ll picture board meetings, minute-taking and a stack of policies nobody reads twice, sadly, that’s often how it’s practiced. Governance’s actual job is to make an organization think clearly with better decisions, sharper oversight, risks caught while they’re still small and leadership that’s accountable to something beyond its own instincts.

In a world full of uncertainty, confidence is scarce and valuable. Organizations that govern themselves well hand that confidence to everyone watching from outside – investors, lenders, regulators and employees. Confidence isn’t just a nice feeling. It shows up in cheaper financing, stronger partnerships and doors that open a little faster. We ought to treat governance like an economic asset, because that’s exactly what it’s become.

Money Follows Trust

No investor writes a cheque purely because they like the product. They write it because they trust that the story will hold together after they’ve handed over their money. So, before capital moves, serious investors quietly run through a checklist:

  • Can this board actually push back on management, or does it just nod along?
  • Does leadership own its mistakes, or explain them away?
  • Are risks being tracked, or are they usually discovered the hard way?
  • Do the internal controls hold up, or are they held together with good intentions?
  • Can the numbers be trusted at face value?

Every “yes” lowers the perceived risk of the investment. Good governance doesn’t just feel responsible, it makes money cheaper to raise.

The investors writing the biggest cheques: private equity firms, pension funds, sovereign wealth funds and development finance institutions have been quietly raising their standards for years. Strong financials still get you in the room. They just don’t get you the deal anymore. Increasingly, these investors are digging into board effectiveness, risk management maturity, ESG integration, succession readiness and even how seriously a company takes cybersecurity.

What they’re really testing is a simple question, can this business grow without depending on the people currently running it? Governance is how that question gets answered and it’s usually the difference between “promising” and “investable.”

The Founder Isn’t the Succession Plan

Family-owned enterprises are the backbone of huge parts of the African economy. Yet so many of them hit the same wall at the same point, the handover to the next generation. It’s rarely a commercial problem because the products are fine, the customers are loyal and the market is there. The problem is structural; succession becomes an emotional negotiation instead of a planned transition. Decisions live in one person’s head instead of an institution’s process. Family dinner-table dynamics start showing up in boardroom decisions and nobody quite knows where the line is anymore.

Governance is what draws that line. Clear roles, independent oversight, a succession plan written down before it’s urgently needed and decision-making that doesn’t evaporate the day the founder steps back. That’s an institution built to last.

The Road to an IPO Begins with Governance

“Governance, internal controls, financial discipline, and board effectiveness determine IPO success long before a company enters the public markets.”

A lot of leadership teams treat governance as something to sort out in the run-up to an IPO, a box-ticking sprint a few months before listing. That’s backwards, governance doesn’t prepare a company for going public, it’s the reason a company becomes ready to go public in the first place.

Public markets expect transparency, financial discipline and risk oversight as a baseline, not an aspiration. None of that gets built in a few frantic months. It’s the product of years of decisions made the right way, quietly, long before anyone outside the company was watching. An IPO isn’t the starting gun for good governance. It’s the proof that good governance was already there.

ESG Without Governance Is Just a Press Release

Sustainability reporting has become one of the most significant developments in corporate reporting. Yet much of the conversation remains focused on the environmental and social pillars. Carbon reduction targets, community initiatives, diversity commitments and climate pledges.

Remove the governance behind any ESG claim, and what remains?

  • Sustainability goals with no clear ownership or accountability. 
  • Disclosures that cannot be independently verified. 
  • Climate commitments that resemble marketing campaigns more than measurable strategies. 
  • Performance metrics that fail under assurance or external scrutiny. 

Governance is what transforms ambition into accountability. It establishes oversight, assigns responsibility, strengthens internal controls and ensures sustainability information is reliable, consistent and useful.

Case Scenario

Imagine a company announcing that it has achieved carbon neutrality by purchasing carbon credits. The announcement attracts positive media attention and strengthens its sustainability profile.

Months later, investors request independent assurance over the claim. The company cannot demonstrate how the credits were selected, verified, approved, or monitored. There is no documented governance process, no Board oversight, and no reliable evidence linking the credits to its reported emissions.

The issue is no longer about carbon credits, It is about governance.

Without robust governance, even legitimate sustainability initiatives lose credibility because stakeholders cannot distinguish measurable performance from well-intentioned claims. As sustainability reporting becomes a business expectation rather than a differentiator, organizations will be judged not only by what they report, but by how confidently they can substantiate it. ESG may shape the narrative, but governance determines its credibility.

Trust Travels Across Borders, Governance Is the Passport

Expanding internationally means being judged by people who have never met you and have no reason to extend the benefit of the doubt. Global investors, multinational partners, and development finance institutions conduct due diligence that extends far beyond products and financial performance. They evaluate governance, leadership, internal controls, compliance culture, financial reporting, and risk management to determine whether an organization can sustain long-term partnerships. A great product may secure the first meeting. Governance determines whether there is a second one.

The Myth That Governance Is a Cost Centre

One of the most persistent myths in business is that governance is overhead, a tax on efficiency and a brake on momentum. Flip that around and look at what weak governance actually costs: strategic decisions made on gut feeling that turn out badly, inefficiencies nobody catches until they’ve compounded, reputational damage that takes years to repair, regulatory penalties, succession crises, fraud that hides in plain sight and capital that gets harder and more expensive to raise. Good governance has a visible, budgeted cost. Bad governance has an invisible one, right up until the moment it isn’t invisible anymore, and by then it’s usually a crisis instead of a line item.

Conclusion – The businesses that win from here.

Products will keep evolving. Technology will keep getting more accessible, which means it’ll stop being a reliable point of difference. AI will narrow the operational gaps between competitors faster than most people expect. Information will keep getting harder to hide.

In a world like that, trust becomes one of the few things that’s genuinely hard to copy. And trust isn’t built with a tagline, it’s built through governance, decision by decision, over years. The companies that stand out over the next decade won’t just have sharper products or bigger market share. They’ll have leadership people believe in, oversight that actually works, risk management that catches things early, reporting that people don’t have to squint at and a culture that earns confidence. The future doesn’t just belong to the most innovative organizations. It belongs to the best-governed ones.

Through our Boardroom Insights series and our Audit, Assurance and Advisory services, Zade Associates LLP remains committed to helping organizations navigate emerging challenges, strengthen governance frameworks and build institutions equipped for long-term success.

ARTIFICIAL INTELLIGENCE AND THE FUTURE OF AUDIT & ASSURANCE – A Kenyan and East African Perspective

ARTIFICIAL INTELLIGENCE AND THE FUTURE OF AUDIT & ASSURANCE – A Kenyan and East African Perspective

by Zade

Introduction

Audit and assurance are undergoing their most significant transformation since the move from paper working papers to digital audit files. Artificial Intelligence (AI), machine learning, and generative AI are moving rapidly from experimentation into everyday practice. For Kenya and the wider East African Community (EAC), this transition comes at a pivotal moment as sustainability reporting requirements emerge, digital adoption accelerates and a new generation of technology-enabled professionals enters the workforce.

Why This Matters Now for Kenya and East Africa

Two regulatory developments make this a live issue rather than a future one for the region:

  1. Mandatory sustainability disclosures – Kenya is preparing to introduce mandatory IFRS S1 and S2 sustainability disclosures starting in January 2027, under a phased roadmap led by the Institute of Certified Public Accountants of Kenya (ICPAK), while the global assurance standard ISSA 5000 is expected to take effect around December 2026. Assuring ESG and carbon data at scale is very difficult to do manually, which is why AI-enabled continuous monitoring tools are already being piloted in the Kenyan market.
  1. A live example – Grant Thornton Kenya and Newtral Technologies have partnered to deploy an AI platform called Noa, which continuously monitors organizational data, reconciles information, identifies reporting gaps and prepares audit-ready disclosures for carbon accounting and ESG reporting. A concrete illustration of how continuous, machine-assisted assurance is starting to replace the old model of periodic, sample-based review.

At the same time, the profession’s own institutions are actively discussing what this means for practice. KCA University and the Institute of Internal Auditors (IIA) Kenya jointly hosted a forum on the future of internal auditing in May 2026, focused explicitly on AI, governance reform, and strategic risk management across public and private sectors.

Where AI Is Already Showing Up in East African Audit Practice

Adoption in the region is uneven but real and it clusters around a few use cases:

  1. Document and data extraction – Tools that read invoices, receipts, and bank statements and pull the data straight into working papers are gaining traction locally. These are the most immediately useful forms of AI for East African practices because it attacks the single most labour-intensive part of a traditional audit, manual data capture and reconciliation.
  2. Public-sector audit management – Kenya’s Office of the Auditor-General relies on audit management platforms such as TeamMate+ to track the entire audit lifecycle in a secure environment, which is important for institutional transparency on large public projects. As these platforms add AI-assisted risk scoring and anomaly detection, public-sector audit stands to benefit significantly from earlier detection of irregular spending patterns.
  3. Locally built infrastructure – ICPAK itself has developed an online audit automation platform, commonly referred to as myAudit, built around IFRS for SMEs and the official ICPAK Audit Manual, allowing auditors to collaborate remotely, manage client access, and centralize working papers in the cloud. 
  4. Continuous assurance for ESG and compliance – Platforms like Noa point toward a model where assurance is not a once-a-year exercise but an ongoing check against live organizational data, such a meaningful departure from the traditional audit cycle.

The Opportunities

  1. Efficiency and cost – Manual vouching, reconciliation and sampling are time-consuming and expensive. AI-driven data extraction and continuous monitoring can shrink fieldwork time substantially, potentially making quality audits more affordable and accessible to a broader base of businesses including the large informal and semi-formal sector that currently receives little or no assurance coverage at all.
  2. Better risk detection – Instead of testing a sample of transactions, machine learning models can scan entire populations of data for anomalies, unusual relationships or patterns consistent with fraud. In markets where financial crime, mobile-money fraud and public procurement irregularities are recurring concerns, full-population testing is a genuine upgrade over sample-based methods.
  3. Freeing auditors for judgment work – If AI absorbs routine testing and drafting, auditors can spend more time on professional skepticism, client dialogue and complex judgment calls, the parts of the job regulators most want strengthened and the parts hardest to outsource to a machine.

The Risks and Constraints

  1. Data and connectivity gaps – AI tools are only as good as the data feeding them. Many East African businesses, particularly SMEs and informal enterprises keep incomplete, paper-based, or inconsistent records and rural connectivity remains patchy. An AI tool trained or tuned on data-rich, well-digitized environments may perform poorly, or produce misleading confidence, when applied to messier local datasets.
  2. Cost and the small-firm reality – Enterprise AI-audit platforms (of the kind used by large multinational networks) are often priced well beyond what a small Kenyan, Ugandan, Tanzanian or Rwandan practice can afford. Without deliberate low-cost alternatives the ICPAK myAudit approach is a useful model. AI adoption risks widening the gap between large and small firms rather than levelling the playing field.
  3. Skills and training – Auditors need to understand not just how to use AI tools but how to evaluate them: what data they were trained on, where they are likely to be wrong and how to document reliance on their output. This is a new competency area and East African accountancy curricula, and CPD programmes are only beginning to catch up. The KCA University/IIA Kenya forum on the future of internal audit is an early sign that institutions recognize this gap.
  1. Overreliance and the “black box” problem – Auditing standards require auditors to understand and be able to explain the basis for their conclusions. Many AI models, particularly deep learning ones, do not readily explain their outputs. Regulators globally are grappling with how auditors can rely on a tool whose reasoning cannot be fully inspected, without simply treating the AI’s output as ground truth.
  2. Data protection and confidentiality – Client financial data is highly sensitive. Kenya’s Data Protection Act, 2019, and equivalent frameworks in neighbouring countries impose obligations on how personal and financial data is processed, stored and transferred, obligations that become more complex when AI tools process data via cloud infrastructure that may sit outside the region. Firms need clear policies on what data can be fed into third-party AI systems, especially where models are hosted abroad.
  3. Talent and job-displacement concerns – Junior audit roles have traditionally been where vouching, ticking and reconciliation work is learned. If AI absorbs that work, the profession needs a deliberate plan for how junior staff still develop the foundational skills and judgment that senior auditors rely on, otherwise the pipeline of well-trained future partners and Audit staff could weaken over time.

What are Standard-Setters and Regulators Doing?

The global standard-setting response is directly relevant to Kenya and East Africa because ICPAK and its counterparts across the EAC adopt International Standards on Auditing.  The International Auditing and Assurance Standards Board (IAASB) held global roundtables in the second half of 2025 with more than 240 stakeholders across six continents to explore how AI and other emerging technologies affect audit engagements and the application of quality management standards, concluding that robust quality management of AI-enabled tools is the starting point for maintaining trust and consistency in their use. The IAASB has also been building out guidance on “Automated Tools and Techniques” – a deliberately broad term covering AI, robotic process automation and other evolving technologies. In December 2025 the Board approved development of non-authoritative material on this topic, meaning more detailed guidance is on its way rather than already finalized.

Domestically, ICPAK maintains direct responsibility for quality assurance review in Kenya and supports members through mandatory training on audit quality assurance, quality management, and inspection readiness, alongside implementation tools such as audit software and illustrative financial statements. As AI tools proliferate, this quality-assurance apparatus will need to explicitly extend to reviewing how firms select, validate and rely on AI in engagements not just whether the final opinion was correctly formed.

A Regional, Not Just Kenyan, Concern!

While Kenya has the most visible activity the same dynamics apply across Uganda, Tanzania, Rwanda and Burundi. All EAC member states’ professional bodies are IFAC members that base their standards on the same International Standards on Auditing, meaning:

  • Any AI-related guidance the IAASB eventually issues will apply, in principle, across the whole region.
  • Cross-border audit networks operating in multiple East African markets will face pressure to apply consistent AI tools and controls across offices of very different sizes and levels of digital maturity.
  • Regional bodies have an opportunity to coordinate, through the Pan African Federation of Accountants, for instance: on shared, affordable AI-audit tooling and joint training, rather than each country building parallel, under-resourced solutions.

Recommendations

  1. For audit firms, especially SMPs: start with narrow, well-understood use cases (data extraction, reconciliation) rather than end-to-end AI decision-making; document clearly where AI output was used and how it was reviewed and invest in staff training on AI literacy alongside traditional technical training.
  2. For regulators and professional bodies: issue interim local guidance on AI use in audits while global standards catch up; extend quality assurance inspections to cover AI tool governance; and keep licensing and technology costs) low enough that small firms are not locked out.
  3. For educators: integrate AI literacy, including its limitations into accountancy curricula now, so that the next generation of auditors enters practice already able to evaluate, not just operate, these tools.
  4. For businesses and audit clients: improve the quality and digitization of underlying financial records, since AI-enabled audit and assurance can only be as reliable as the data it is given.

Conclusion

AI is not going to replace professional judgement in audit and assurance, but it is already changing what auditors spend their time on. How much of a population can be tested and how quickly assurance can be delivered. East Africa is an active participant in this shift, the region’s challenge is to capture the efficiency and quality gains that AI offers without deepening the divide between large, well-capitalized firms and the small practices that make up most of the profession. Getting the balance right will depend on deliberate, affordable and locally grounded choices by ICPAK, its regional counterparts, the firms and universities that train the next generation of auditors.

Credits to Robert Maithia | Business Dev. Officer | Zade Associates LLP

Ransomware and the SACCO: Closing the Gap Between Assumed and Verified Security

Ransomware and the SACCO: Closing the Gap Between Assumed and Verified Security

by Zade

Credits: Ernest Hawi | System Auditor | Zade Associates LLP

Ransomware is no longer a distant or theoretical risk for Sacco’s and mid-sized financial institutions. It is an active, well-organised criminal industry that increasingly targets exactly this segment: organisations that hold significant amounts of sensitive financial and personal data, but that typically run on lean IT teams, legacy core banking platforms, and IT budgets sized for keeping the lights on rather than for dedicated security functions.

Ransomware and extortion groups do not select victims based on size, prestige, or public profile. They select victims based on opportunity an exposed login, an unpatched system, a poorly segmented network, or a backup that turns out to be reachable by the very attacker it was meant to protect against. A SACCO holding members’ deposits, loan books, and identity documents represents exactly this kind of opportunity, and the consequences of a successful attack extend well beyond a technical outage: operational disruption, member panic, regulatory scrutiny, and reputational damage that can outlast the incident itself by years.

Ransomware groups do not select victims by size or prestige. They select victims by opportunity, and an under-resourced SACCO can present exactly that opportunity.

The Anatomy of a Ransomware Attack

Ransomware incidents follow a consistent structure. Understanding each stage matters because every stage represents a point where a specific control often inexpensive relative to the cost of an incident can stop the attack before it escalates. 

  1. Initial access 

The overwhelming majority of ransomware intrusions begin one of four ways: a phishing email carrying a malicious attachment or link; an exposed Remote Desktop Protocol (RDP) or VPN endpoint secured with a weak or reused password; exploitation of an unpatched internet-facing system such as a mail server, VPN appliance, or file transfer tool; or a compromised connection through a third-party vendor. Public-facing assets a member portal, an online loan-application form, an SMS or USSD gateway are disproportionately common entry points precisely because they are, by design, reachable from anywhere on the internet.

  1. Establishing a foothold 

Once inside, attackers typically deploy a lightweight tool that grants interactive, hands-on access to the compromised environment. At this point the incident stops being an automated malware infection and becomes a human-operated intrusion an actor actively exploring the network, often over a period of days or weeks before taking further action.

  1. Privilege escalation and credential harvesting

Attackers extract credentials from system memory, exploit misconfigured directory service permissions, and search scripts, configuration files, and browser storage for saved passwords. Each credential recovered extends their reach further into the environment, and an IT account that doubles as a domain administrator account hands an attacker a master key far earlier than it should.

  1. Lateral movement 

This is frequently the stage that determines whether an incident remains contained or becomes catastrophic. Flat networks where teller terminals, administrative workstations, and core banking servers all sit on the same network segment without meaningful separation allow an attacker who compromises one ordinary workstation to reach the most critical systems with little additional effort. The absence of network segmentation is one of the most common and most consequential findings in technical security reviews of financial institutions.

  1. Data exfiltration 

Before deploying encryption, modern ransomware operators typically copy sensitive data member KYC records, loan histories, identification documents to infrastructure they control. This is the mechanism behind “double extortion”: even an institution with fully functional backups can still be blackmailed with the threat of a public data leak, because the attacker’s leverage no longer depends on the encryption succeeding at all.

  1. Encryption 

Attackers typically disable security tooling and destroy accessible backups before deploying the encryption payload, and often time detonation for a weekend or public holiday when response capacity is thinnest. A backup reachable using the same administrative credentials as the production environment is not a meaningful control it is simply a second target sitting adjacent to the first.

  1. Extortion 

A ransom note follows, generally including a payment deadline, a cryptocurrency wallet address, and instructions for further contact. Some groups now bypass encryption entirely and proceed straight to data-leak extortion, since the threat of exposure alone is often enough to force a payment.

Why These Incidents Recur

A recurring pattern across ransomware incidents generally, not tied to any single case, is that organisations frequently resolve the immediate symptom of an attack restoring an affected system, paying to have data decrypted, rebuilding a compromised server without a corresponding investigation into how the attacker gained access in the first place, and without independent verification that the same path has actually been closed. The visible problem is fixed. The underlying condition that produced it remains in place, and eventually produces a repeat incident, sometimes against the same organisation.

A related observation is that reputational damage from a ransomware or extortion incident is frequently independent of whether sensitive data is ultimately confirmed to have been stolen. The threat itself the possibility of a public leak, communicated to a nervous membership base produces real reputational and operational consequences regardless of the technical outcome. Institutions should not treat “no data loss confirmed” as equivalent to “no real incident occurred.”

Why This Is Difficult to Catch From the Inside

The conditions that produce ransomware incidents an unpatched service, a flat network, an over-privileged account, a backup with an overlooked access path, an incident response plan that has never been rehearsed rarely look dangerous during normal operations. They look like ordinary configuration. This is precisely why they tend to persist undetected for long periods: the people who built and maintain a system are accustomed to its structure and are not well positioned to independently identify its weaknesses. A system audit exists to provide exactly this independent perspective, examining evidence rather than accepting assurances.

A properly scoped system audit asks specific, testable questions: What is actually reachable from the internet, verified through scanning rather than assumed from documentation? Can the core banking database be reached directly from an ordinary staff workstation, tested rather than presumed impossible? Has the most recent backup actually been restored end-to-end, with a documented result, rather than merely logged as a completed job? Has the incident response plan been rehearsed by the people who would execute it, or does it exist only as an unread document? Does the current list of administrative access holders match the list of people who genuinely require that access today?

“A system audit converts an untested assumption of security into either verified assurance or a specific, prioritised, and fixable list of gaps.”

A Practical Defense Program

Once gaps are identified, addressing them is a matter of implementing a set of well-established and proportionate controls.

  1. Identity and access management

Mandatory MFA on all remote access and privileged accounts; least-privilege access with administrative and daily-use accounts kept separate; no RDP or admin panels exposed directly to the internet; unique, rotated service account credentials.

  1. Network architecture

The core banking environment segmented onto its own zone with explicit, tested firewall rules, isolated from teller networks, administrative networks, and guest access; workstation-to-workstation communication restricted where feasible.

  1. Patch and vulnerability management

A current, reconciled inventory of internet-facing assets; time-bound patching SLAs, tightest for internet-facing systems; regular vulnerability scanning tracked to closure.

  1. Endpoint and email security

Behavioural EDR rather than legacy antivirus; application allow-listing on core banking servers; email filtering with attachment sandboxing and macros disabled by default.

  1. Backup and recovery

The 3-2-1-1 principle — three copies, two media types, one offsite, one immutable or fully offline; backups isolated from production domain credentials; full restoration tested on a regular schedule with documented results.

  1. Monitoring and detection

Centralised logging across domain controllers, core banking, VPNs, and firewalls; alerting on high-signal indicators such as disabled security tooling, mass file renaming, or unusual login times and locations.

  1. Governance and third parties

A ransomware-specific incident response plan naming ransom decision authority rehearsed at least annually; vendor contracts with enforceable security and audit clauses; cyber risk as a standing board agenda item.

Conclusion

Ransomware and extortion operations succeed not through sophistication but through opportunism, targeting whichever organisation presents the weakest set of basic controls at the time of the attack. The gap between what an institution believes about its own defences and what an independent, evidence-based review would actually find is common, persistent, and rarely visible from the inside and closing that gap is precisely the purpose of a system audit.

The relevant question for any SACCO or financial institution is straightforward: ”If an attacker gained a foothold on an ordinary staff device today, how far could they reach into the institution’s systems before being detected  and has that question actually been tested, with evidence, or only assumed?

Credits: Ernest Hawi | System Auditor | Zade Associates LLP

Why Strong Credit Governance Determines Institutional Resilience?

Why Strong Credit Governance Determines Institutional Resilience?

by Zade

Every institution that extends credit faces one common challenge: managing the risk that borrowers may fail to repay. While borrower default is often viewed as the greatest threat, experience shows that the root cause of deteriorating credit portfolios usually lies within the institution itself.

Key Pointer: Weak governance, inconsistent policy implementation, inadequate oversight, and poor lending decisions often create the conditions for financial losses long before repayments begin to fail.

Credit deterioration is rarely the result of one poor decision. It develops gradually through:

  • Repeated policy exceptions
  • Inadequate credit appraisals
  • Delayed recognition of emerging risks
  • Ineffective portfolio monitoring

By the time non-performing loans begin to increase or liquidity comes under pressure, the underlying weaknesses have often existed for months or even years.

Whether an organisation is a SACCO, bank, microfinance institution, NGO, school, manufacturing company, or commercial enterprise — strong credit governance remains essential for protecting financial stability and supporting sustainable growth.

1. Credit Management Begins with Governance

Credit management extends far beyond loan recovery and debt collection. It starts with the governance structures that guide every lending decision:

  • Effective policies
  • Independent approval processes
  • Competent credit assessments
  • Reliable management information
  • Strong oversight

These form the foundation for a healthy credit portfolio.

Key Pointer: When governance weakens, credit quality inevitably follows approval decisions become subjective, policy exceptions become routine, and monitoring shifts from proactive to reactive. Bottom line: Credit governance is not simply an operational responsibility  it is a strategic function that protects capital, strengthens stakeholder confidence, and supports long-term institutional resilience.

2. Credit Risk Exists Across Every Sector

Although credit risk is commonly associated with financial institutions, virtually every organisation extends credit in one form or another.

SectorHow Credit Risk Shows Up
SACCOs & Microfinance InstitutionsLoan portfolios directly influence liquidity, member confidence, regulatory compliance, and financial sustainability. Weak affordability assessments or ineffective recovery processes quickly affect portfolio quality.
BanksRegulation alone cannot prevent poor credit decisions. Aggressive growth targets, concentration risk, weak collateral management, and ineffective oversight remain leading causes of deterioration.
NGOs & Development OrganisationsExposure comes through revolving funds, beneficiary financing, supplier credit, and staff loan schemes. Weak controls can undermine donor confidence and restrict future funding.
Schools, Healthcare, Manufacturing, Property, Commercial EnterprisesCredit extends through unpaid fees, trade receivables, instalment arrangements, and customer financing. Without effective receivables management, strong revenues can mask real cash flow problems.

Key Pointer: Regardless of industry, ineffective credit management eventually becomes a governance issue before it becomes a financial one.

Key Pointer: Regardless of industry, ineffective credit management eventually becomes a governance issue before it becomes a financial one.

3. Warning Signs of a Weak Credit Environment

Institutions rarely encounter problems without warning. Watch for these five red flags:

  1. Inadequate Credit Appraisal Lending decisions should be based primarily on a borrower’s demonstrated repayment capacity — not collateral or personal relationships. Collateral reduces exposure; it should never replace a thorough cash flow and affordability assessment.
  2. Erosion of Policy Discipline Credit policies exist to promote consistency, accountability, and objectivity. When exceptions become commonplace or approval authorities are routinely bypassed, lending decisions grow inconsistent and institutional risk rises.
  3. Weak Portfolio Monitoring Relying solely on periodic financial statements means problems surface too late. Effective monitoring requires continuous analysis of repayment behaviour, loan ageing, sector concentrations, and arrears trends — enabling early intervention.
  4. Poor Segregation of Duties When one individual approves credit, authorises disbursements, maintains records, and oversees recoveries, this creates openings for fraud, error, and weak oversight. Clearly defined responsibilities and independent reviews strengthen governance significantly.
  5. Understated Impairment Provisioning Understated provisions may temporarily flatter profitability, but they distort financial performance and mislead regulators, investors, members, and donors.

4. Why Independent Credit Audits Matter

An independent credit audit provides far more than regulatory assurance — it gives Boards and senior management an objective assessment of whether the institution’s credit governance framework can support sustainable growth.

A comprehensive review typically examines the full credit lifecycle:

  • Governance structures
  • Policy adequacy
  • Credit appraisal methodologies
  • Approval processes
  • Documentation standards
  • Collateral management
  • Portfolio monitoring
  • Impairment provisioning
  • Recovery practices
  • Management reporting
  • Board oversight

Key Pointer: Small control weaknesses that appear insignificant in isolation often combine to create substantial institutional risk. Early identification allows corrective action before profitability, liquidity, compliance, or stakeholder confidence are affected.

5. Questions Every Board Should Be Asking

Effective governance requires more than reviewing credit reports. Boards should continuously challenge management with questions such as:

  • How has portfolio quality changed over the past year?
  • Which sectors or borrower groups present the highest concentration risk?
  • Are impairment provisions supported by objective evidence?
  • How frequently are policy exceptions approved?
  • Are recovery strategies delivering measurable results?
  • Does management receive timely information to identify emerging risks?

Institutions that can confidently answer these questions are better equipped to manage risk proactively rather than reacting after financial deterioration occurs.

6. Building Resilient Institutions

Strong credit portfolios are not built by avoiding risk — they are built through:

  • Disciplined governance
  • Objective decision-making
  • Effective oversight
  • Reliable information
  • A culture of accountability

Credit risk can never be eliminated, but it can be understood, measured, governed, and managed. Organisations that embed these principles throughout the credit lifecycle are better positioned to preserve capital, maintain stakeholder confidence, and achieve sustainable growth.

As today’s operating environment becomes increasingly complex, institutions that invest in strong credit governance are not simply reducing financial risk they are building resilient organisations capable of sustaining growth, maintaining trust, and delivering long-term value.

Kenya’s Finance Bill 2026:What Every Organisation Must Know

Kenya’s Finance Bill 2026:What Every Organisation Must Know

by Zade

The Finance Bill 2026 was tabled on 30th April and is expected to become law by 30th June. At Zade Associates, we have reviewed the proposals and summarised below the key changes that affect most organisations, including SACCOs, NGOs, and trade unions.

The Big Picture

The Finance Bill 2026 proposes significant tax changes across Income Tax, VAT, Excise Duty, and Tax Procedures. The government’s goals appear to be:

  • Broaden the tax base (digital economy, virtual assets, informal sector)
  • Reverse recent court decisions (Supreme Court rulings on withholding tax)
  • Tighten compliance (shorter deadlines, stricter penalties, eTIMS enforcement)
  • Clean up obsolete provisions (removing outdated sections)

With that context, here are the specific proposals our clients should understand.

Tax Amnesty

The Bill waives penalties and interest on tax liabilities for periods up to 3rd December 2025. Taxpayers who have already settled principal taxes receive automatic relief. Those with outstanding principal must apply to the Commissioner and enter a payment plan, settling the principal by 31st December 2026. This is a genuine opportunity to clear historical exposures at reduced cost.

Who benefits: Taxpayers with historic tax debts who cannot afford the full amount including penalties. It encourages people to come clean and pay the principal without fear of punishment.

Who does NOT benefit: Taxpayers who have already paid their taxes on time (no debt to forgive). Some argue it penalizes compliant taxpayers.

 Proposed Charge of VAT on Digital and Platform-Based Financial Services

Digital payment services including mobile money transfers, payment processing, merchant acquiring, and gateway services will now attract 16% VAT. This affects loan collections, beneficiary payments, staff disbursements, and supplier settlements. Organisations using mobile money channels should expect higher transaction costs.

Impact: This is one of the most controversial proposals. It will increase the cost of digital financial services. A Ksh 100 M-Pesa transfer fee could become Ksh 116. The Kenya Private Sector Alliance (KEPSA) warns this could “cripple digital payments and drive traders back to cash transactions.” Contradicts the government’s goal of a cash-lite economy.

Commissioner’s Power to Recover Input VAT on Unsold Supplies

If a business claims input VAT (refund) on goods it purchased, but those goods remain unsold when the VAT rate changes, the Commissioner of KRA can demand that refund back.

Example:

  • January 2026: Retailer buys 1,000 phones for Ksh 10,000 each, pays Ksh 1,600,000 VAT, claims refund.
  • July 2026: Government reduces VAT rate from 16% to 10% on phones.
  • Retailer still has 500 unsold phones.
  • KRA demands repayment of input VAT on those 500 phones (500 × Ksh 10,000 × 16% = Ksh 800,000).

Impact: Punishes businesses with slow-moving inventory. Discourages bulk purchasing. Adds complexity to inventory management. Could lead to cash flow crises for businesses that bought stock in good faith but couldn’t sell before a rate change.

Zero-Rated to Exempt (Hidden Tax Increase)

Several goods will move from zero-rated to exempt status. Under zero-rated, businesses claim refunds on input VAT. Under exempt, they cannot. The consumer pays 0% at the till, but prices rise because manufacturers absorb unrecoverable VAT on raw materials.

Affected items include locally assembled phones, electric buses and motorcycles, solar and lithium-ion batteries, animal feeds, and sugarcane transportation services. Organisations with solar installations, e-mobility investments, or agricultural exposure should reassess project costs.


Rental Income Tax Increase

The final tax on gross residential rental income rises from 7.5% to 10%. This applies to any organisation owning residential property. Annual tax on Ksh 500,000 monthly rent increases from Ksh 37,500 to Ksh 50,000.

Who pays: Landlords earning gross rental income up to Ksh 10 million per year (above that uses standard corporate/personal income tax rates).

Impact: Landlords may increase rent to pass on the tax to tenants. Could make housing more expensive for renters.

Filing Deadline Compression (Effective January 2027)

Income tax returns will be due four months after year end, down from six months. Nil returns are due within one month. For organisations with December year ends, the deadline moves from 30th June to 30th April, compressing audit, board approval, and filing. Early engagement with auditors is advised.

Impact: Less time for taxpayers and accountants to prepare. Pressure on KRA to process faster. Increased penalties for late filing.

Calendar Days for Objections and Appeals

Current law: Time limits for filing objections and appeals are counted in working days (Monday–Friday,excluding public holidays).
Proposed: Time limits counted in calendar days (every day including weekends and public holidays).

Impact: Taxpayers and their advisors have less actual time to respond. A notice issued on a Friday before a long weekend could expire before the taxpayer even sees it. Favours KRA over taxpayers. Increases risk of default judgments against taxpayers who miss deadlines.

Deemed Dividends (Minimum 60% Floor)

Where a company retains profits without commercial justification, the Commissioner may treat at least 60% as deemed dividends, triggering withholding tax. Retained earnings will face scrutiny. Board minutes and financial policies must clearly document the rationale for profit retention, including reinvestment plans, capital expenditure, or regulatory reserve requirements.

Impact: This benefits KRA by increasing tax collections from retained earnings. It disadvantages closely held companies, including many SACCOs structured as companies, that retain profits for reinvestment, expansion, or regulatory reserves. Under previous law, the Commissioner had discretion with no minimum floor. The 60% floor removes flexibility. A SACCO retaining Ksh 10 million for a new branch may now face a deemed dividend assessment on Ksh 6 million, triggering withholding tax even though no cash distribution occurred. Proper documentation of reinvestment plans, board approvals, and regulatory requirements is no longer optional.

Withholding Tax on Interchange Fees and Card Payments

Following the Supreme Court decision in Barclays Bank v. Commissioner, the Bill expands the definition of management fees to include interchange fees, merchant service fees, and payments to card companies. These will now attract withholding tax, reversing the Court’s ruling.

What the proposal does: Requires the payer (usually a Kenyan bank) to withhold tax at source when paying these fees to card companies (which are often foreign entities like Visa Inc. in the US) and to other banks.

Impact: Increases the cost of card payments. May lead to higher merchant fees, which are eventually passed to consumers as higher prices. Contradicts the Supreme Court ruling, potentially leading to legal challenges

Income Tax on Imported Second-Hand Clothing (“Mitumba”)

Imported second-hand clothing will attract income tax at an effective rate of 1.5% of customs value, calculated as 5% deemed profit subjected to 30% corporate rate. This increases costs for traders and consumers.

Impact: Will increase the price of mitumba, which is a source of affordable clothing for many low-income Kenyans. May reduce imports and hurt thousands of small traders who rely on the mitumba value chain.

Excise Duty on Mobile Phones (Effective January 2027)

Excise duty on mobile phones will be payable at point of activation, not importation. This shifts liability from importers to network operators and consumers.

Impact: This benefits mobile phone importers and wholesalers who no longer pay duty upfront, improving their cash flow. It disadvantages consumers who will likely face higher prices as the duty is passed on, and network operators who must administer collection. The shift from importation to activation means phones imported but never activated (lost, damaged, or resold outside Kenya) escape duty entirely, creating a potential revenue loophole.

Virtual Assets

Virtual Asset Service Providers (VASPs) must file information returns on users. Penalties for non-compliance reach Ksh 1 million. Excise duty of 10% applies to fees charged on virtual asset transactions.

Impact: This benefits KRA through increased visibility into cryptocurrency and digital asset transactions, closing a previous tax gap. It disadvantages VASPs who face heavy compliance burdens, and users who may face higher transaction costs and reduced privacy. For most SACCOs, NGOs, and unions, there is no direct impact unless they hold or transact in virtual assets. However, members who trade cryptocurrencies may face additional reporting.

Bad Debt VAT Refunds

The waiting period for VAT refunds on bad debts reverts from two years to three years, undoing the 2025 amendment. This delays cash flow recovery for businesses with unpaid supplies.

Impact: This benefits KRA by retaining revenue longer and reducing refund claims. It disadvantages businesses, including SACCOs and NGOs that supply goods or services on credit, by delaying cash flow recovery on unpaid invoices. A customer who defaults after two years but before three years now yields no VAT refund. This reversal within 12 months of the 2025 amendment creates policy unpredictability.

IFRS S1 & S2: Preparing SACCOs for the Future of Sustainability Reporting

IFRS S1 & S2: Preparing SACCOs for the Future of Sustainability Reporting

by Zade

The business landscape is changing rapidly, and financial performance is no longer the only measure of an organization’s success. Members, regulators, lenders, investors, and development partners increasingly want to know how organizations manage environmental, social, and governance (ESG) matters that could influence their long-term performance and resilience. In response to this growing demand, the International Sustainability Standards Board (ISSB), under the IFRS Foundation, introduced IFRS S1 and IFRS S2, creating a global baseline for sustainability-related financial disclosures.

Although these standards have attracted significant attention among listed companies, they are equally relevant to SACCOs. As member-owned financial institutions, SACCOs play a vital role in supporting communities, promoting financial inclusion, and financing economic activities. Their ability to identify and manage sustainability-related risks is becoming increasingly important in maintaining financial stability and member confidence.

Understanding ESG

Environmental, Social, and Governance (ESG) refers to the three key pillars used to evaluate how an organization manages sustainability risks and opportunities.

  1. The Environmental pillar focuses on an organization’s impact on the environment through issues such as energy use, waste management, carbon emissions, and responsible resource utilization. For SACCOs, this may include promoting digital services to reduce paper consumption, financing renewable energy projects, or supporting climate-smart agricultural practices.
  2. The Social pillar considers how an organization manages relationships with employees, members, customers, and the wider community. Issues such as financial inclusion, customer protection, employee welfare, diversity, data privacy, and community investment fall under this category. Since SACCOs exist primarily to improve members’ economic well-being, strong social practices are already central to their operations.
  3. The Governance pillar addresses leadership, accountability, ethics, internal controls, regulatory compliance, and effective risk management. Strong governance remains the foundation of sustainable organizations and is essential for safeguarding members’ resources.

What is IFRS S1?

IFRS S1 establishes the general requirements for disclosing sustainability-related risks and opportunities that could reasonably affect an organization’s financial performance, cash flows, access to finance, or long-term value.

Rather than requiring organizations to report every environmental or social initiative, the standard focuses on information that is financially material to users of financial statements.

The standard is built around four key pillars:

  • Governance requires organizations to explain how the Board and management oversee sustainability matters and allocate responsibilities.
  • Strategy requires entities to disclose how sustainability-related risks and opportunities influence their business model, strategic objectives, and financial planning.
  • Risk Management focuses on how sustainability risks are identified, assessed, monitored, and integrated into the organization’s overall enterprise risk management framework.
  • Metrics and Targets require organizations to disclose the indicators used to measure sustainability performance together with any targets established to monitor progress.

Together, these four pillars encourage organizations to integrate sustainability into everyday decision-making rather than treating it as a separate reporting exercise.

What is IFRS S2?

While IFRS S1 addresses sustainability broadly, IFRS S2 focuses specifically on climate-related disclosures.

Climate change presents both risks and opportunities that may significantly affect an organization’s future performance. The standard requires organizations to assess and disclose these impacts using the same four-pillar framework of governance, strategy, risk management, and metrics and targets.

Climate-related risks are generally classified into two categories.

  • Physical risks arise from the direct effects of climate change, including floods, droughts, prolonged heat waves, and other extreme weather events. For SACCOs, these events may affect members’ ability to repay loans, particularly those engaged in agriculture, transport, or small-scale businesses.
  • Transition risks emerge as economies shift towards lower-carbon and more sustainable practices. These include changing regulations, technological advancements, evolving consumer preferences, and increased demand for sustainable financing.

At the same time, climate change also creates opportunities. SACCOs can develop green financing products, support renewable energy investments, finance climate-smart agriculture, expand digital financial services, and improve operational efficiency through sustainable business practices.

Why Should SACCOs Care?

Although many SACCOs may not yet be required to report under IFRS Sustainability Disclosure Standards, the principles behind IFRS S1 and S2 provide valuable guidance for strengthening governance and managing emerging risks.

Climate-related events increasingly affect members’ incomes, particularly in sectors such as agriculture, transport, manufacturing, and trade. These risks ultimately influence loan performance, liquidity, and portfolio quality. By understanding sustainability risks, SACCOs can make more informed lending decisions and improve long-term resilience.

Strong sustainability practices also enhance transparency and accountability. Members gain greater confidence when they understand how their SACCO manages risks, protects their investments, and contributes to sustainable economic development.

In addition, development finance institutions and funding partners are increasingly incorporating ESG considerations into financing decisions. Demonstrating sound sustainability practices may therefore improve access to funding and strategic partnerships.

Preparing for the Future

  • Implementing IFRS S1 and S2 is not simply about producing another report. It requires organizations to strengthen governance structures, improve data collection processes, and integrate sustainability considerations into strategic planning.
  • Boards should provide clear oversight of sustainability matters and ensure ESG risks are considered alongside financial and operational risks.
  • Management should establish reliable processes for collecting sustainability data, monitoring performance, and reporting meaningful information.
  • Finance, risk management, internal audit, compliance, ICT, and operations teams should work collaboratively to ensure sustainability information is accurate, consistent, and capable of supporting decision-making.

As sustainability reporting continues to evolve, investing in appropriate systems and staff capacity today will position SACCOs to meet future regulatory expectations with confidence.

Conclusion

IFRS S1 and IFRS S2 mark an important shift in corporate reporting by recognizing that long-term organizational success depends not only on financial performance but also on how sustainability-related risks and opportunities are managed. For SACCOs, these standards present an opportunity to strengthen governance, improve risk management, enhance member confidence, and support sustainable growth.

While sustainability reporting is still evolving, organizations that begin integrating ESG principles into their operations today will be better prepared for tomorrow’s expectations. Ultimately, sustainability is not simply about protecting the environment it is about building stronger, more resilient institutions that continue creating value for their members and the communities they serve.