5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

Kenya

eTIMS validation: why every expense now needs an electronic tax invoice

From the 2026 tax year, all income and expenses declared in income tax returns must be supported by valid electronic tax invoices generated and transmitted through eTIMS or TIMS. The one-year transitional relief, which allowed taxpayers filing 2025 returns to declare valid business expenses without eTIMS support, ended with the 30 June 2026 filing deadline. Expenses that cannot be matched to a valid invoice — correctly transmitted, and carrying the buyer's PIN where applicable — now risk being administratively disallowed. This is the shift from invoicing compliance to return validation, and it changes who bears the consequence: your supplier's failure to transmit becomes your disallowed deduction.

How Barzel applies here Start free with BarzelVault

What changed with eTIMS validation, and when?

DateWhat happened
29 Dec 2023Tax Procedures (Electronic Tax Invoice) Regulations 2023 (LN 225/2023) commenced.
28 Mar 2024LN 225/2023 repealed and replaced by LN 64/2024, the current regulations.
1 Jan 2026KRA begins validating income and expenses declared in income tax returns against TIMS/eTIMS invoices, withholding tax data and customs import records.
30 Jun 2026Transitional relief ends. It applied only to 2025 returns.
2026 tax year onwardAll declared income and expenses must be supported by valid electronic tax invoices.
31 Aug 2026KRA and the National Treasury announce eTIMS integration with IFMIS for government supplier payments.

The IFMIS integration is recent and its implementation date has not been published — KRA describes an ongoing sensitisation and transition period. The direction is clear: government suppliers will need a valid eTIMS invoice before submitting a payment request, with invoice data matching across both systems.

Who must onboard to eTIMS?

All persons carrying on business — not only VAT-registered taxpayers. This is the point most often misunderstood. In scope:

  • companies, partnerships, sole proprietorships, associations and trusts;
  • taxpayers filing monthly rental income, turnover tax and annual income tax;
  • the informal sector;
  • non-VAT entities supplying exempt goods and services — hospitals, schools, NGOs.

Businesses below KES 5 million annual turnover can be covered by buyer-initiated invoicing instead of onboarding directly. The software itself is free; third-party integrators may charge.

Exemptions

Under the regulations, salaries and wages, imported goods and services, airline passenger ticketing, financial institution interest and charges, businesses below the KES 5 million threshold, and non-residents without a Kenyan permanent establishment fall outside the requirement. Verify the current list against the gazetted LN 64/2024 before relying on a specific exemption.

What must a valid eTIMS invoice contain?

  • seller PIN
  • date and time
  • serial number
  • buyer PIN — required where the buyer intends to claim the expense
  • gross and tax amounts
  • item descriptions, quantities and units
  • tax rate
  • QR code
  • unique system and invoice identifiers

The buyer PIN is the field that determines whether your customer can deduct the expense. An invoice transmitted without it is valid for the seller and useless to the buyer — and the buyer will discover this at filing, not at purchase. In an automated invoicing pipeline, the presence and correctness of the buyer PIN deserves a hard validation rule, not a best-effort field mapping.

Separately, the regulations require maintaining continuous system functionality and notifying KRA within 24 hours of system failure. That obligation is easy to miss and needs an owner.

Integration: OSCU versus VSCU

eTIMS offers genuine system-to-system integration through published specifications, with a sandbox available at etims-sbx.kra.go.ke. Two control-unit models:

OSCUVSCU
Full nameOnline Sales Control UnitVirtual Sales Control Unit
SuitsSystems that are continuously onlineHigh-volume invoicing; environments without continuous connectivity
ConnectivityRequires constant connectivitySupports batched and offline operation

Businesses may self-integrate or engage a KRA-verified third-party integrator. The other options — eTIMS Lite (web, USSD on *222#, mobile app), eTIMS Client and the Online Portal — suit lower volumes and do not require development work.

The design decision that matters

OSCU's constant-connectivity requirement is a real constraint in Kenyan operating conditions. A system built on OSCU that loses connectivity has to either stop invoicing or queue — and if it queues without an idempotency key attached before the first transmission attempt, the retry after reconnection will create duplicate invoices. VSCU exists partly to avoid this, and for any high-volume or distributed operation it is usually the safer architecture.

Kenya has a comparatively strict automated-decision rule

Worth knowing if you deploy automated systems that affect people, because it is stricter than many assume and closer to the European model than the American one.

Section 35 of the Data Protection Act, 2019 gives every data subject a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or significantly affects them. Exceptions: necessary for performance of a contract, authorised by law with suitable safeguards, or based on express consent. Data subjects may request reconsideration or a new decision that is not based solely on automated processing.

Other obligations that bite:

  • Data protection impact assessment (s.31) where processing is likely to result in high risk — reports submitted 60 days prior to processing.
  • Breach notification (s.43) — controllers notify the ODPC without delay, within 72 hours; processors notify controllers within 48 hours.
  • Registration with the ODPC is mandatory unless the entity is both under KES 5 million turnover and has fewer than 10 employees — and that exemption does not apply at all, regardless of size, to entities processing for financial services, telecommunications, health administration, education, direct marketing, transport, hospitality, digital credit and several other listed purposes. Registration applies to controllers and processors handling data about people in Kenya regardless of where the entity is established, so foreign vendors serving Kenyan customers are in scope.

Penalties: administrative fines up to KES 5 million or 1% of annual turnover, whichever is lower.

Kenya has no AI law

State this plainly, because a lot of content implies otherwise:

  • The Kenya National AI Strategy 2025–2030, launched March 2025, is a strategy document. It creates no obligations.
  • The draft Kenya AI and Other Emerging Technologies Policy (July 2026) closed for public comment on 4 August 2026. Still draft.
  • The Artificial Intelligence Bill, 2026 (Senate Bills No. 4 of 2025) was published 19 February 2026, had its first reading on 2 April 2026 and was referred to committee. It has not passed. It proposes EU-style risk tiers, an Office of the Artificial Intelligence Commissioner, a public register of high-risk systems, and retention of input, output and performance records for at least five years — but none of that is law.

What actually binds AI use in Kenya today is the Data Protection Act 2019, the Computer Misuse and Cybercrimes Act 2018, the Consumer Protection Act 2012, and sector regulation such as CBK requirements for financial services.

Cyber incident reporting: know which rule applies to you

The 24-hour reporting duty under the Computer Misuse and Cybercrime (Critical Information Infrastructure and Cybercrime Management) Regulations, 2024 applies to designated critical information infrastructure owners, who also must appoint a CISO, keep the infrastructure physically located in Kenya and conduct annual risk assessments. An ordinary business not so designated has no general 24-hour cyber reporting duty. Its binding incident obligation is the 72-hour ODPC breach notification under DPA s.43. These two are routinely conflated.

Practical checklist

  1. Confirm onboarding status for every entity in the group, including non-VAT and exempt-supply entities.
  2. Make the buyer PIN a hard validation rule on outbound invoices, not an optional field.
  3. Reconcile supplier invoices against eTIMS transmission — an untransmitted supplier invoice becomes your disallowed expense.
  4. Choose OSCU or VSCU deliberately based on connectivity, not convenience.
  5. Attach an idempotency key before the first transmission attempt, so reconnection retries do not duplicate invoices.
  6. Assign an owner for the 24-hour system-failure notification to KRA.
  7. Check ODPC registration — the small-entity exemption does not apply to most regulated sectors at any size.
  8. If you operate automated decisioning affecting individuals, assess it against DPA s.35 and the s.31 DPIA duty.

Frequently asked questions

Who must use eTIMS?

All persons carrying on business, not only VAT-registered taxpayers. Businesses under KES 5 million turnover may be covered by buyer-initiated invoicing.

Is the transitional relief still available?

No. It applied only to 2025 returns and ended with the 30 June 2026 filing deadline.

What happens to expenses without a valid invoice?

They risk being administratively disallowed on validation against TIMS/eTIMS, withholding tax data and customs records.

What is the difference between OSCU and VSCU?

OSCU requires constant connectivity; VSCU supports high-volume and batched or offline operation.

Does Kenya have an AI law?

No. The strategy and draft policy are policy; the AI Bill 2026 has not passed. The Data Protection Act 2019 is what binds automated decisions.

Does my business have a 24-hour cyber reporting duty?

Only if designated as a critical information infrastructure owner. Otherwise the applicable duty is the 72-hour ODPC personal-data breach notification.

Where this leads

eTIMS is a continuous transaction control regime with an API, which means invoicing errors surface as tax consequences rather than accounting ones. Where invoices are generated and transmitted by automated systems, the questions that follow are the same ones every CTC jurisdiction asks: did it transmit exactly once, can you prove what was sent, and who authorised it.

BarzelVault enforces policy and approval thresholds and records each operation before it executes. FinOps Atlas measures the cost of automated workflows and API operations.

In practice

The control has to run before the invoice becomes irreversible.

An accepted structured invoice can be corrected but never deleted, and from the penalty date every defect has a price. Barzel puts the approval threshold, the duplicate check and the signed record in front of submission, so the process can be defended on the day an auditor or the tax authority asks.

eTIMS validation applies from the 2026 tax year

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Barzel FinOps Atlas

Intelligent financial operations for AI agents and automation.

  • Cost per action, workflow and business outcome, allocated as it happens.
  • Spend limits and anomaly detection before the bill, not after.
  • Financial evidence tracing and close-readiness for SOX, SOC 2 and external audit.

Free tier: 500 calls a monthPaid plans from $29 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.


Sources

  1. Tax Procedures Act (Cap 469B), section 23A.
  2. Tax Procedures (Electronic Tax Invoice) Regulations, 2024 (Legal Notice 64 of 2024), replacing LN 225/2023.
  3. KRA public notice, Validation of income and expenses in the income tax returns, 10 November 2025.
  4. KRA notice on 2025 return filing relief, June 2026.
  5. KRA, eTIMS system-to-system integration; OSCU and VSCU specifications v2.0.
  6. Data Protection Act, 2019, sections 31, 35 and 43; ODPC registration guidance.
  7. Computer Misuse and Cybercrime (Critical Information Infrastructure and Cybercrime Management) Regulations, 2024 (LN 44/2024).

This article is for information and does not constitute tax or legal advice.