Post-licence compliance

Key points

  • Most revocations and penalties originate after approval, not during it
  • The risk assessment has to change when the business does
  • A material change often requires notifying the regulator before it happens
  • Training and procedure updates are evidence obligations, not good practice
  • Banking relationships depend on this record as much as regulators do

A licence is a continuing obligation, not a certificate. Annual audit, periodic regulatory reporting, staff training, procedure updates and a risk assessment that keeps pace with the business are all conditions of keeping it. Most enforcement action we see arises during maintenance rather than at application, because maintenance is where attention lapses.

This is the least glamorous thing we do and the one that most often decides whether a licensing project was worth the money. A permission that is lost in year three cost more than it delivered.

What does maintenance actually involve?

The recurring obligations, and what each one is really testing

ObligationTypical cadenceWhat it is really testing
External or SRO auditAnnualWhether the operation matches the procedures you filed
Regulatory reportingQuarterly or annual, regime-dependentWhether volumes and exposures match what was approved
Risk assessment refreshAnnual, and on material changeWhether you noticed your own business changing
Staff trainingAnnual, evidencedWhether the procedures exist outside the document
Procedure updatesOn regulatory changeWhether anyone is reading the regulator's publications
Change notificationsBefore the change, usuallyWhether you understand what needs pre-approval
Fit-and-proper refreshOn personnel changeWhether the approved individuals are still the actual ones

The specifics vary by regime, but the shape is consistent: an annual audit against the standard your regulator or SRO applies, periodic reporting, evidenced staff training, procedure updates when the rules change, and a risk assessment refresh when your business changes. In Switzerland the SRO conducts or commissions the audit directly, under the framework FINMA oversees. In EU regimes the obligations flow from the authorising instrument — for crypto-asset service providers, from MiCA, whose transitional period ended on 1 July 2026.

The table above sets out what each obligation is really testing, which is more useful than the obligation itself. An audit is not checking whether you have policies; it is checking whether the operation matches the policies you filed. Those are very different tests, and the second is the one businesses fail.

How are licences actually lost?

Almost never through a single dramatic breach. The usual pattern is drift. The company adds a product line, starts serving customers in a country that was not in the original geographic risk profile, changes who holds client assets, or replaces the compliance officer with someone the regulator never approved. Each step is reasonable in isolation. None of them is reflected in the filed documents. Two years later, an auditor reads the risk assessment and the transaction data together and the gap is obvious.

The second pattern is notification failure. Most regimes require certain changes to be notified — often approved — before they happen: a change of controller, a new regulated activity, a material change in business model. Doing the thing first and telling the regulator afterwards converts a routine filing into a breach.

What we do

What we take on

  • Maintaining the compliance calendar, so no filing date arrives as a surprise
  • Preparing the annual audit file and handling the auditor's or SRO's questions
  • Drafting and filing the periodic regulatory reports the permission requires
  • Refreshing the institutional risk assessment when the business changes materially
  • Running and evidencing staff training, including for new joiners
  • Tracking regulatory change in the relevant jurisdiction and updating procedures against it
  • Preparing change-notification and variation filings before the change takes effect, not after

The list above is the scope. The part clients value most is the compliance calendar: the obligations of a licence are individually simple and collectively easy to lose track of, particularly for a small team whose attention is on the product. Everything else follows from not missing dates.

We also monitor regulatory change in the jurisdictions our clients hold permissions in. Crypto regulation is not stable, and a procedure written against a rule that has since been amended is worse than no procedure, because it evidences that nobody has looked at it.

Why does this matter beyond the regulator?

Banks and payment partners assess this record too. A clean audit history and current documentation is a significant part of why an account survives periodic review, and its absence is a common reason a relationship is closed with little warning. That connection is set out on banking and card issuing, and the wider picture of what happens after approval is on after the licence.

If you hold a permission we did not obtain for you, we take on maintenance for it. The first step is a review of the current position against the licence conditions, which frequently finds items nobody had realised were outstanding.

No adviser can guarantee a regulatory outcome, including on a maintenance matter — regulators retain full discretion. This page is general information, not legal advice; CryptoLicense is an advisory firm, not a regulator and not a law firm.

Start by finding out which licence you actually need

Tell us your business model and target markets and we will set out the jurisdictions that fit, the stages on each route, and what you will need to prepare. Free consultation. Approval is at the regulator's discretion and we promise nothing about it.

Book a call

Part of a series: the full guide is at Choosing a licence.