Payments & FintechAugust 31, 20267 min read

Kenya, Uganda and Rwanda Just Started Writing the Region's Payment Rulebook. Ethiopia Isn't in the Room

The EAC just moved its Cross-Border Payment System Masterplan into implementation. Ethiopia isn't a member, but the governance gap it's building around is one Ethiopian risk teams can benchmark against now.

D
Daracorp Team

From 18 to 22 August 2026, central bank technical staff from across the East African Community met in Mombasa for the first joint session of three new Technical Working Groups, chaired by the Bank of Uganda with the National Bank of Rwanda as rapporteur, to move the EAC Cross-Border Payment System Masterplan from a plan on paper into something regulators actually operate. The World Bank, GIZ, FSD Network and TradeMark Africa sat in as development partners. What the working groups reviewed was not marketing material. It was a Monitoring and Reporting Framework, a Regional Cooperative Oversight Framework and a Mutual Recognition Framework, the machinery that lets eight central banks trust each other's licensing and supervision decisions well enough to let payments cross borders without every transaction being re-checked at the frontier.

Who this is for: Risk Managers and Internal Auditors at Ethiopian banks and payment service providers who are building or governing cross-border payment capability.

Three countries, three different jobs, one rulebook

The roles at Mombasa were not accidental. Kenya hosted because Nairobi already runs the region's most tested real-time payment rails, PesaLink for interbank transfers and M-Pesa for mobile money, both of which had to solve interoperability domestically years before anyone asked them to solve it regionally. Uganda chaired because it has its own history of forcing two competing mobile money operators to interconnect inside one market, a smaller version of exactly the coordination problem the EAC Masterplan is trying to solve at regional scale. Rwanda took the rapporteur's pen because the National Bank of Rwanda has spent the last several years building one of the region's more assertive digital-finance regulatory postures, the kind of institution comfortable drafting the paperwork other central banks will eventually sign.

None of that is a coincidence. A regional oversight framework only works if it borrows its structure from countries that have already solved a version of the same problem at home. What Mombasa produced is not a fresh idea; it is domestic experience, from three different capitals, being generalised into a shared rulebook the whole bloc can use.

What the four pillars actually commit a central bank to build

The Masterplan sits on four pillars, Governance, Legal, Regulatory and Oversight; Infrastructure; Inclusivity; and Capacity Building, covering 20 strategic initiatives. The Monitoring and Reporting Framework reviewed at Mombasa sets results chains, indicators, baselines and targets for those 20 initiatives, and explicitly aligns them with the G20's own targets for faster, cheaper, more transparent and more accessible cross-border payments. That alignment matters more than it looks. It means a national supervisor cannot report progress by its own private yardstick; it has to show its numbers against a standard other G20-aligned jurisdictions are also being measured against.

The Regional Cooperative Oversight Framework and the Mutual Recognition Framework are the pieces that turn intention into practice. Cooperative oversight is the agreement that lets Kenya's supervisor rely on Rwanda's supervision of a payment provider operating in both markets, rather than duplicating the whole licensing process. Mutual recognition is what lets a licence or an AML control regime approved in one EAC state count for something in another. Put together, they are the opposite of what most Ethiopian institutions are used to when they think about cross-border payment risk, which is a single national supervisor, a single rulebook and a single point of accountability.

Where Ethiopia sits, and where it doesn't

Ethiopia is not an EAC member; it sits in COMESA, a different regional bloc with its own, less advanced payment-integration track. That is worth saying plainly rather than assuming readers will infer it: nothing signed at Mombasa binds the National Bank of Ethiopia or any Ethiopian payment provider. But the direction of travel is one Ethiopia has already committed to domestically. EthSwitch's EthioPay-IPS, launched in February 2026, connects 32 banks, 12 microfinance institutions and around half a dozen payment service operators and issuers into a single instant payment rail, and NBE's own National Digital Payments Strategy 2026-2030 explicitly sets out ambitions for cross-border integration, low-value retail transfers through cards, wallets and digital banking, and a national data-exchange platform, the same strategy we walked through capital, ownership and interoperability terms for in nine questions every Ethiopian payment provider's risk team should be able to answer. NBE has also taken part in a COMESA survey of national payment systems, mobile money and cross-border SME trade across nine member states, an early and much softer version of the coordination work EAC's working groups are now doing formally.

The gap is not ambition. It is governance infrastructure. Ethiopia has built the domestic rail; it has not yet built, because it has had no regional partner requiring it to, the equivalent of a cooperative oversight agreement or a mutual recognition framework with any neighbouring supervisor. That is precisely the kind of gap that becomes visible late, at the point a payment provider or a bank actually wants to move money across a border and discovers no institutional bridge exists to carry it safely, rather than early, when it could still be designed on purpose.

A four-pillar benchmark Ethiopian risk teams can borrow now

None of the EAC's frameworks apply to an Ethiopian institution today, and none should be treated as if they do. But a risk or audit function does not need a binding obligation to benchmark its own readiness against a structure three central banks have just spent a week validating. Before any cross-border corridor opens, whether through COMESA, a correspondent relationship or a future EAC-adjacent arrangement, it is worth being able to answer:

  • Governance, legal and oversight: is there a named function inside the institution that owns cross-border payment risk specifically, distinct from domestic payments risk, with a documented view of which foreign supervisors or counterpart institutions it would need to coordinate with.
  • Infrastructure: does EthioPay-IPS connectivity, or any correspondent banking arrangement in use, have documented resilience, settlement finality and dispute-resolution procedures that would survive a cross-border incident, not just a domestic one.
  • Inclusivity: has anyone mapped which customer segments, remittance senders, small exporters, SMEs trading regionally, would actually use a cross-border rail if one opened, or is the infrastructure being built ahead of any evidenced demand.
  • Capacity building: do the staff who would operate a cross-border payment desk understand mutual recognition and cooperative oversight as concepts, or would the institution be learning those terms for the first time from a counterparty's compliance team.

A risk function that can answer all four honestly is not compliant with anything, because there is nothing yet to be compliant with. It is simply ready for the day a directive, a COMESA initiative or a correspondent bank's own due diligence asks the same four questions under time pressure.

Why this is an AML question as much as an infrastructure one

Cross-border payment corridors are exactly the kind of channel a laundering scheme is built to exploit, because they multiply the number of supervisory blind spots a bad actor can move through before any single institution sees the whole picture. The EAC's Mutual Recognition Framework exists partly to close that gap between member states, letting supervisors trust each other's AML controls well enough to treat a cross-border transaction as something other than a fresh, unverified risk each time. Ethiopia has no equivalent arrangement with any neighbouring jurisdiction yet, which means every cross-border flow through EthioPay-IPS-adjacent channels, or through the correspondent relationships Ethiopian banks already run, is currently carrying its full source-of-funds and beneficial-ownership burden with no regional recognition regime to lean on. That is not a reason to slow domestic instant-payment rollout. It is a reason to treat cross-border transaction monitoring, of the kind we set out when NBE tightened its own foreign exchange retention rules, as a standing discipline rather than an afterthought bolted on once volumes justify it.

Building that discipline before a directive forces it is exactly what DaraCorp's AML & CFT course is designed to embed in a risk and compliance function's daily judgement calls, and it pairs naturally with Risk Management & Compliance for the wider control environment a cross-border payment capability eventually needs.

This article describes how East African regulators are building cross-border payment governance and what that suggests for Ethiopian institutions' own readiness; it is not legal advice and does not describe any binding Ethiopian obligation. Confirm current developments against the primary source at eac.int and nbe.gov.et, and take professional advice on your organisation's particular circumstances.

Filed under
EACcross-border paymentsEast African CommunityKenyaUgandaRwandaEthiopiaEthioPay-IPSfinancial integrationAML/CFT
DaraCorp AI assistant

How can I assist you today?

Powered by CopilotKit

EAC Payment Masterplan: What It Means for Ethiopia