Banking
An account in the name of the licensed entity, in a bank that accepts your flow. Frequently the longest single item, and the one most often assumed to be easy.

Approval is the start of the operating problem, not the end of it. Three things follow immediately: a bank account, without which the licence does not let you trade; the compliance obligations that begin on day one; and the question of whether the permission you have covers what the business is about to become. Most licences that fail, fail here.
Licensing projects are usually planned as though approval is the destination. In practice it is the point at which the operating problems begin, and they are the problems that determine whether the permission was worth obtaining.

A licence answers one question, asked by one party: the regulator's question about whether you may carry on the activity. It does not answer the bank's question about whether it wants your transactions on its books, the card scheme's question about whether your programme meets its standards, or an exchange's question about whether it will take you as a counterparty. Each of those is asked separately, by an institution with its own risk appetite and no obligation to you.
This is why businesses arrive at approval feeling finished and then spend the next several months unable to trade. The licence made those conversations possible. It did not conclude them.
An account in the name of the licensed entity, in a bank that accepts your flow. Frequently the longest single item, and the one most often assumed to be easy.
The procedures you filed have to start actually running: onboarding, monitoring, record-keeping, reporting. Filed and operating are different states.
Exchanges, liquidity providers, custodians and payment partners each run their own diligence. The licence helps; it does not substitute.
Confirm that what you are about to launch is inside the permission you were granted. This is the check that prevents the most expensive kind of surprise.
Four workstreams, listed above, and they run in parallel rather than in sequence.
Banking is usually the critical path. An account in the name of the licensed entity, at an institution that will accept your flow of funds. The licence helps enormously — it gives the bank a supervised counterparty and a framework someone else has already reviewed — and it does not make the outcome certain. What determines the outcome is largely a narrative the bank's analyst can follow: where money comes from, what happens to it, where it goes, and why each step exists. That is set out at length on banking and card issuing.
The compliance operation has to start operating. There is a meaningful difference between procedures that were filed and procedures that are running. Onboarding checks actually performed, monitoring rules actually configured, records actually retained, reports actually made. The first audit tests the second state, not the first, and the gap between them is where most findings come from.
Counterparty onboarding runs on its own schedule. Liquidity providers, custodians, payment processors — each runs diligence, and each will ask for the same corporate and ownership material a bank does. Having it prepared once and kept current shortens all of them.
Scope review is the cheapest of the four and the most often skipped. Before launching, confirm that the thing you are about to launch is inside the permission you were granted.
Changes that usually need the regulator's attention before they happen
The checklist above covers the common triggers, and the word before is the important one. Most regimes require certain changes to be notified — often approved — in advance. Doing the thing and reporting it afterwards converts routine administration into a breach, and a breach in your first year is disproportionately damaging because it establishes a pattern with a supervisor who has no other data about you.
| What the business does | Why it is a regulatory event | Usual timing |
|---|---|---|
| Adds a product with a new fund flow | May fall outside the granted scope | Confirm before build, not before launch |
| Opens a corridor to a new country | Changes the geographic risk profile the file described | Update the risk assessment first |
| Replaces the AML officer | An approved individual is changing | Fit-and-proper material in advance |
| Takes investment that shifts control | Change of controller, assessed like a new applicant | Approval before completion |
| Outsources monitoring or custody | A critical function moves outside the entity | Notify, and keep accountability internal |
The pattern in that table is worth stating directly: a regulator's interest is triggered by changes in what happens to money and to customer assets, not by changes that feel significant internally. A rebrand is not a regulatory event. A new settlement account is.
The most common second-year question is how to reach another market. The answer is usually that a permission does not travel. It authorises activity in the jurisdiction that granted it, and serving customers elsewhere generally requires a separate authorisation there.
The exception is explicit passporting. Within the EEA, authorisation as a crypto-asset service provider under MiCA passports the authorised services across member states — which is the single strongest argument for that route if the EU is in your plans, and its transitional period ended on 1 July 2026. Outside such arrangements, assume a second application. Where speed matters more than a clean history, acquiring an entity that already holds the second permission is a legitimate alternative, with the trade-offs set out on new application versus ready-made licence.
What expansion should not do is destabilise the first permission. A business that stretches into a new market without updating the risk assessment, the procedures and the notifications in its original jurisdiction can find itself with a problem in the market it already had — which is a more expensive outcome than simply having waited.
Card issuing is the most-asked-about next step and the most underestimated. It needs a permission that supports holding customer balances — usually an e-money or equivalent footing, covered on fintech licences — plus a relationship with a scheme or an issuing partner, each with onboarding standards independent of any regulator. Programme economics also depend on settlement mechanics that determine how much working capital you must hold. None of that appears in a licence application, and all of it decides whether the product works.
Everything above sits on top of the recurring obligations described on post-licence compliance: annual audit, reporting, training, procedure updates. Those begin at approval and continue for as long as the permission does.
Concretely: banking opened and stable, the compliance procedures genuinely running rather than filed, the first audit passed without material findings, and no unnotified change sitting in the business waiting to be discovered. That is a low bar in description and an uncommon one in practice, because each item competes for attention with a product team that has just been unblocked after months of waiting.
The businesses that manage it tend to do one thing differently: they treat the compliance calendar as a real operational commitment with a named owner, rather than as something the founder will deal with when the notice arrives. The obligations of a permission are individually simple and collectively easy to lose, and the cost of losing track of them is asymmetric — a missed filing is a minor administrative matter until it becomes the first line of a supervisory history that follows the entity for years. The baseline duties in almost every regime trace back to the FATF recommendations, which is why the shape of that first year looks broadly the same whichever jurisdiction granted the licence.
No regulatory outcome can be guaranteed — on an application, a variation or a change of controller. This page is general information, not legal advice, and reflects the position as at August 2026. CryptoLicense is an advisory firm, not a regulator and not a law firm.
Tell us your business model and target markets and we will set out the jurisdictions that fit, the stages on each route, and what you will need to prepare. Free consultation. Approval is at the regulator's discretion and we promise nothing about it.
Book a call