What Every SACCO Board Should Know Before Approving a Core Banking System

What Every SACCO Board Should Know Before Approving a Core Banking System

Share This Post

What Every SACCO Board Should Know Before Approving a Core Banking System.

Choosing a core banking system is a strategic, long-term decision that shapes member experience, compliance, costs and growth.

Boards should evaluate total cost of ownership (TCO) and measurable ROI, vendor credibility and support, regulatory compliance (SASRA + Kenya’s Data Protection Act), integration with mobile/agency channels, implementation risk, and future-proofing (AI, data, APIs).

This guide gives the questions to ask, metrics to require, and a simple checklist to approve a system with confidence.

 

 

Why does this matter for your board?

Every time a SACCO upgrades or replaces its core banking system, it’s not just buying software, it’s changing how members save, borrow and interact with the society. A core banking system determines:

  • Member onboarding speed and member experience (which affects membership growth).

  • Operational costs (automation reduces manual work and errors).

  • Regulatory compliance (reporting to SASRA & data protection).

  • The SACCO’s ability to add mobile banking, agency banking and diaspora services.

SASRA supervises and licenses deposit-taking SACCOs and expects regulated institutions to have systems and controls proportionate to their risks. Boards must therefore treat system procurement as a governance decision, not an IT project.

1. Understanding the business purpose of a core banking system.

The core banking system is the SACCO’s operational engine, ie,  accounting, member ledger, loans, savings, interest, reporting and the integration point for mobile and agency banking. Think of it as the SACCO’s ‘operating model’ codified in software.

Business outcomes to expect:

  • Faster member onboarding and loan turnaround lead to higher member satisfaction and retention.

  • Accurate, auditable financials make it easier for SASRA reporting and audit readiness.

  • Automation of routine tasks (reconciliations, postings) leads to reduced staff costs and human error.

Boards should insist on vendor case studies that demonstrate these business outcomes in SACCOs similar in size and complexity.

2. The board’s role is governance, not micro-management

Board responsibilities include:

  • Setting the strategy and objectives for the system (e.g., increase membership 15% in 24 months, reduce loan processing time to 48 hours etc).

  • Reviewing and approving the budget and TCO.

  • Ensuring the SACCO has a risk-aware implementation plan and a structured vendor SLA.

  • Requiring measurable KPIs (uptime, report delivery, onboarding time, error rates etc).

3. Financials: Evaluating TCO and ROI

Boards often focus on the system price while missing major cost drivers. Ask for a comprehensive Total Cost of Ownership (TCO) and a 3- to 5-year ROI model.

TCO components to insist on:

  • License/subscription or perpetual fees.

  • Implementation & customization costs (data migration, configuration).

  • Hardware, hosting and infrastructure (cloud hosting vs on-premise).

  • Integration costs (mobile money, agency banking & payment switches).

  • Training, change management and documentation.

  • Annual maintenance, support and upgrade costs.

  • Contingency for extended support after go-live.

How to calculate ROI 

List expected annual benefits (reduced staff processing hours, fewer errors, increased fee income from digital channels, new members etc) and subtract annual costs. Express as payback period and IRR over 3 years. Boards should ask vendors for actual customer ROI studies rather than modelled figures.

Financial risks of choosing the wrong vendor

  • Hidden recurring costs and expensive customizations.

  • Operational downtime causing lost transactions and reputational harm.

  • Vendor lock-in with limited exit/portability (costly migration later).

 

 

4. Member-centric growth.

A modern core banking system should actively help you acquire and retain members.

Key capabilities that drive member growth:

  • Seamless mobile and internet banking integrations — allow members to check balances, pay loans, and transact without visiting the branch.

  • Agency and merchant integrations — extend reach to remote members.

  • Self-service onboarding and e-KYC, where allowable (reduces friction).

  • Scaled reporting and analytics for targeted product campaigns (e.g., micro-savings, emergency loans).

Serving diaspora & remote members

Enable secure international remittance on-ramps, multi-currency support where relevant, and asynchronous support channels (chat, WhatsApp, email) to serve members abroad.

5. Risk, security & regulatory compliance

Boards must ensure that compliance and data protection are non-negotiable.

Regulatory anchors

  • SASRA sets licensing, prudential and reporting standards for deposit-taking SACCOs; systems must produce SASRA-required reports and support supervisory inspections.

  • Kenya’s Data Protection Act (2019) requires lawful processing, data subject rights, breach notification and appropriate technical and organisational measures. Ensure your vendor complies and can support data portability, retention and lawful cross-border transfers.

 

Security & controls to require

  • Role-based access control, audit trails and segregation of duties.

  • Secure encryption at rest and in transit; documented key management.

  • Incident response and breach notification process aligned to ODPC guidance.

  • Anti-fraud and Anti-Money Laundering (AML) integrations (transaction monitoring, alerts).

  • Regular third-party penetration testing and security attestations.

6. Vendor selection. What to ask and what to weigh

Essential vendor evidence.

  • Local experience- number of Kenyan SACCOs or financial institutions implemented and contactable references.

  • Regulatory familiarity- evidence of generating SASRA reports and previous liaison with regulators.

  • Support model- local support team, hours of coverage & SLA (uptime and ticket resolution).

  • Migration story- documented experience migrating from common legacy SACCO systems (data mapping examples).

  • Product roadmap- clear plans for APIs, mobile channels and analytics.

 

Key questions for vendors (board should approve these as mandatory).

  1. Show 2 SACCO case studies with measurable business outcomes (membership, costs, TAT).

  2. Can you produce SASRA-formatted reporting from day one?

  3. What is your average time to resolve a Sev-1 production issue (a critical, high-impact incident in a live system that renders a service or a significant part of it unusable for all users, with no viable workaround)? What SLA credits apply?

  4. What data residency and backup model do you use? Where are backups stored?

  5. How easily can we export all member and transaction data in an open and standard format?

7. Implementation & change management — what to expect

A software implementation is a change project. Boards should require a clear plan before approval.

Typical implementation phases

  1. Discovery & requirements (2–4 weeks)

  2. Design & configuration (4–12 weeks)

  3. Data migration & testing (6–12 weeks)

  4. UAT & parallel run (2–6 weeks)

  5. Go-live & hypercare (2–8 weeks)

  6. Post-implementation review (30–90 days)

(Actual durations vary by SACCO size and customizations.)

How To Minimise disruption.

  • Running parallel systems for a defined period to validate balances and critical workflows.

  • Phased rollouts: e.g., piloting a region or product line before full cutover.

  • Investing in staff training and a ‘super-user’ program to embed knowledge.

  • Having the board receive a fortnightly implementation dashboard during rollout and a go-live readiness sign-off checklist.

 

 

9. Quick approval checklist (one-page for the board)

  • Business case with 3-year ROI and measurable KPIs.

  • Full TCO (licenses, implementation, integrations, support, contingency).

  • SASRA reporting capability confirmed in writing.

  • Data protection & privacy compliance statement and evidence (DPA alignment).

  • Local support & SLA (uptime %, response times).

  • Data export, backup & portability guarantees.

  • Two SACCO references and one live demo on a similar scope.

  • Phased implementation plan with parallel run and training budget.

  • Exit & migration clause (how to move to another system).

  • Signed security attestation

 

 

Conclusions

As SACCOs continue to evolve in a highly competitive and regulated environment, board members play a crucial role in ensuring that technology investments align with both short-term operational needs and long-term strategic goals. By understanding what to evaluate before giving the green light, boards can make more confident, data-driven decisions that deliver sustainable value to members.

If your SACCO is currently exploring a new core banking system or upgrading an existing one, we invite you to book a discovery session with our experts. In this session, you will have the opportunity to share your challenges, goals, and current setup. We will help you identify the right digital path forward to enhance member experience, strengthen compliance, and maximize ROI.

 

Subscribe To Our Newsletter

Get updates and learn from the best

More To Explore