Yes you do, you can either add the permissions to the role, or to the key policy.
https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/encryption.usagenotes.html#dynamodb-kms-authz