After the licence

Key points

  • A licence you cannot bank does not let you operate
  • Compliance obligations begin at approval, not at the first anniversary
  • Adding a product or a market can require a variation before you launch it
  • A second jurisdiction is a second application, not an extension of the first
  • Card issuing needs an e-money footing plus a scheme relationship

Approval is the start of the operating problem, not the end of it. Three things follow immediately: a bank account, without which the licence does not let you trade; the compliance obligations that begin on day one; and the question of whether the permission you have covers what the business is about to become. Most licences that fail, fail here.

Licensing projects are usually planned as though approval is the destination. In practice it is the point at which the operating problems begin, and they are the problems that determine whether the permission was worth obtaining.

Why approval is not the finish line

The licence answers the regulator's question. The bank, the scheme and the counterparties each have their own, and they ask them separately.

A licence answers one question, asked by one party: the regulator's question about whether you may carry on the activity. It does not answer the bank's question about whether it wants your transactions on its books, the card scheme's question about whether your programme meets its standards, or an exchange's question about whether it will take you as a counterparty. Each of those is asked separately, by an institution with its own risk appetite and no obligation to you.

This is why businesses arrive at approval feeling finished and then spend the next several months unable to trade. The licence made those conversations possible. It did not conclude them.

What happens immediately after approval?

The four workstreams that start on day one

Banking

An account in the name of the licensed entity, in a bank that accepts your flow. Frequently the longest single item, and the one most often assumed to be easy.

This guide covers

Compliance operation

The procedures you filed have to start actually running: onboarding, monitoring, record-keeping, reporting. Filed and operating are different states.

Counterparty onboarding

Exchanges, liquidity providers, custodians and payment partners each run their own diligence. The licence helps; it does not substitute.

Scope review

Confirm that what you are about to launch is inside the permission you were granted. This is the check that prevents the most expensive kind of surprise.

Four workstreams, listed above, and they run in parallel rather than in sequence.

Banking is usually the critical path. An account in the name of the licensed entity, at an institution that will accept your flow of funds. The licence helps enormously — it gives the bank a supervised counterparty and a framework someone else has already reviewed — and it does not make the outcome certain. What determines the outcome is largely a narrative the bank's analyst can follow: where money comes from, what happens to it, where it goes, and why each step exists. That is set out at length on banking and card issuing.

The compliance operation has to start operating. There is a meaningful difference between procedures that were filed and procedures that are running. Onboarding checks actually performed, monitoring rules actually configured, records actually retained, reports actually made. The first audit tests the second state, not the first, and the gap between them is where most findings come from.

Counterparty onboarding runs on its own schedule. Liquidity providers, custodians, payment processors — each runs diligence, and each will ask for the same corporate and ownership material a bank does. Having it prepared once and kept current shortens all of them.

Scope review is the cheapest of the four and the most often skipped. Before launching, confirm that the thing you are about to launch is inside the permission you were granted.

What needs notifying before you do it?

Changes that usually need the regulator's attention before they happen

  • A change of controller, or any material change in beneficial ownership
  • A new regulated activity, or a product that extends beyond the granted scope
  • A change of AML officer, director or other approved individual
  • A material change in business model, customer segment or geographic exposure
  • New outsourcing of a critical function, including custody or monitoring
  • A change of registered office or the loss of local presence the application relied on

The checklist above covers the common triggers, and the word before is the important one. Most regimes require certain changes to be notified — often approved — in advance. Doing the thing and reporting it afterwards converts routine administration into a breach, and a breach in your first year is disproportionately damaging because it establishes a pattern with a supervisor who has no other data about you.

What the business doesWhy it is a regulatory eventUsual timing
Adds a product with a new fund flowMay fall outside the granted scopeConfirm before build, not before launch
Opens a corridor to a new countryChanges the geographic risk profile the file describedUpdate the risk assessment first
Replaces the AML officerAn approved individual is changingFit-and-proper material in advance
Takes investment that shifts controlChange of controller, assessed like a new applicantApproval before completion
Outsources monitoring or custodyA critical function moves outside the entityNotify, and keep accountability internal

The pattern in that table is worth stating directly: a regulator's interest is triggered by changes in what happens to money and to customer assets, not by changes that feel significant internally. A rebrand is not a regulatory event. A new settlement account is.

Expanding without breaking what you have

The most common second-year question is how to reach another market. The answer is usually that a permission does not travel. It authorises activity in the jurisdiction that granted it, and serving customers elsewhere generally requires a separate authorisation there.

The exception is explicit passporting. Within the EEA, authorisation as a crypto-asset service provider under MiCA passports the authorised services across member states — which is the single strongest argument for that route if the EU is in your plans, and its transitional period ended on 1 July 2026. Outside such arrangements, assume a second application. Where speed matters more than a clean history, acquiring an entity that already holds the second permission is a legitimate alternative, with the trade-offs set out on new application versus ready-made licence.

What expansion should not do is destabilise the first permission. A business that stretches into a new market without updating the risk assessment, the procedures and the notifications in its original jurisdiction can find itself with a problem in the market it already had — which is a more expensive outcome than simply having waited.

What about cards, specifically?

Card issuing is the most-asked-about next step and the most underestimated. It needs a permission that supports holding customer balances — usually an e-money or equivalent footing, covered on fintech licences — plus a relationship with a scheme or an issuing partner, each with onboarding standards independent of any regulator. Programme economics also depend on settlement mechanics that determine how much working capital you must hold. None of that appears in a licence application, and all of it decides whether the product works.

Everything above sits on top of the recurring obligations described on post-licence compliance: annual audit, reporting, training, procedure updates. Those begin at approval and continue for as long as the permission does.

What does a good first year look like?

Concretely: banking opened and stable, the compliance procedures genuinely running rather than filed, the first audit passed without material findings, and no unnotified change sitting in the business waiting to be discovered. That is a low bar in description and an uncommon one in practice, because each item competes for attention with a product team that has just been unblocked after months of waiting.

The businesses that manage it tend to do one thing differently: they treat the compliance calendar as a real operational commitment with a named owner, rather than as something the founder will deal with when the notice arrives. The obligations of a permission are individually simple and collectively easy to lose, and the cost of losing track of them is asymmetric — a missed filing is a minor administrative matter until it becomes the first line of a supervisory history that follows the entity for years. The baseline duties in almost every regime trace back to the FATF recommendations, which is why the shape of that first year looks broadly the same whichever jurisdiction granted the licence.

No regulatory outcome can be guaranteed — on an application, a variation or a change of controller. This page is general information, not legal advice, and reflects the position as at August 2026. CryptoLicense is an advisory firm, not a regulator and not a law firm.

Start by finding out which licence you actually need

Tell us your business model and target markets and we will set out the jurisdictions that fit, the stages on each route, and what you will need to prepare. Free consultation. Approval is at the regulator's discretion and we promise nothing about it.

Book a call