
Automation and ownership of revenue collection platforms are now compulsory for all the devolved units in new rules aimed at enhancing own-source revenue collection in counties.
The Commission on Revenue Allocation has published the tough standards and guidelines on the automation of county own-source revenue.
The rules seek to curb revenue leakages, end fragmented systems and improve accountability in revenue collections.
“Ownership of the CRMS platform, including the core infrastructure and all vendor contracts, shall vest in the respective county government,” the guidelines state.
Every county must now run a county revenue management system (CRMS)- a one-stop shop for all revenue collections.
The system must register taxpayers and link them to National ID, KRA PIN and Business Registration Service numbers.
It must handle multi-stream billing, accept mobile money, cards, USSD and agency banking and issue instant receipts.
It must perform daily bank reconciliations, generate aging reports and support debt enforcement with automated reminders and GPS-stamped field actions.
“Each county government shall retain exclusive operational and administrative rights over its CRMS, including user management, system configuration, data access and revenue reporting,” the rules state.
According to the rules, systems must stay up at least 99.5 per cent of the time each month. This is aimed at reducing the downtime that has slowed revenue collections in most counties.
They must handle at least 1,200 transactions per second at peak. Offline work must be possible, with secure sync later.
Article 216 of the constitution mandates CRA to define and enhance the revenue sources of the national and county governments; and encourage fiscal responsibility.
The commission said it consulted the National Treasury, the Council of Governors, the Auditor General, the Controller of Budget and the ICT Authority.
“These guidelines supersede any previous guidelines issued by the commission in relation to the automation of County Own Source Revenue and shall serve as the reference framework for the National Government, the County Governments and service providers,” the rules read.
According to the latest reports by the Controller of Budget and CRA, many counties are still underperforming in their own source revenue collections.
Under Article 209(3) of the constitution, counties can levy property rates, entertainment taxes and charges for services they provide.
However, continued reliance on manual systems, limited automation and poor links to national databases have undermined collections.
The CRA also cited non-standard procurement practices that create vendor lock-in, weak audit trails, poor data security and resistance by staff to automation.
“These challenges have resulted in revenue leakages and reduced fiscal sustainability,” the guidelines note.
“They also cause inconsistent reporting, compromised service delivery, weakened oversight and increased exposure to fraud. A unified standards framework is therefore necessary.”
According to the new rules, all revenue data must be encrypted, while multi-factor authentication will be mandatory for system administrators.
Counties must also conduct quarterly security scans and integrate their revenue systems with IFMIS, the Standard Chart of Accounts, IPRS, BRS, NTSA and GIS.
“These guidelines supersede any previous guidelines issued by the Commission in relation to the automation of County Own Source Revenue and shall serve as the reference framework for the National Government, the County Governments and service providers,” the rules read.
Each county will be required to establish a Joint Technical Committee chaired by the County Treasury. Project Implementation Units will also oversee the rollout of the systems.
Procurement must comply with the Public Procurement and Asset Disposal Act, while counties will be required to favour open standards and include source-code escrow arrangements to prevent vendor lock-in.
Contracts with technology providers must contain clear service-level agreements covering system uptime, incident response and transfer of technical knowledge to county staff.
The CRA will require counties to submit quarterly compliance reports, with the Auditor General required to conduct annual audits.
INSTANT ANALYSIS
Performance will be measured against indicators including automatic transaction posting, a minimum 80 per cent user satisfaction rate and zero tolerance for unresolved critical security incidents. Counties that fail to comply will face enforcement measures. The CRA and Council of Governors will issue a formal Compliance Notice giving the affected county 90 days to remedy the breach. Persistent violations can be escalated to the Intergovernmental Budget and Economic Council.