Key points
- Most revocations and penalties originate after approval, not during it
- The risk assessment has to change when the business does
- A material change often requires notifying the regulator before it happens
- Training and procedure updates are evidence obligations, not good practice
- Banking relationships depend on this record as much as regulators do
A licence is a continuing obligation, not a certificate. Annual audit, periodic regulatory reporting, staff training, procedure updates and a risk assessment that keeps pace with the business are all conditions of keeping it. Most enforcement action we see arises during maintenance rather than at application, because maintenance is where attention lapses.
This is the least glamorous thing we do and the one that most often decides whether a licensing project was worth the money. A permission that is lost in year three cost more than it delivered.
What does maintenance actually involve?
The recurring obligations, and what each one is really testing
| Obligation | Typical cadence | What it is really testing |
|---|---|---|
| External or SRO audit | Annual | Whether the operation matches the procedures you filed |
| Regulatory reporting | Quarterly or annual, regime-dependent | Whether volumes and exposures match what was approved |
| Risk assessment refresh | Annual, and on material change | Whether you noticed your own business changing |
| Staff training | Annual, evidenced | Whether the procedures exist outside the document |
| Procedure updates | On regulatory change | Whether anyone is reading the regulator's publications |
| Change notifications | Before the change, usually | Whether you understand what needs pre-approval |
| Fit-and-proper refresh | On personnel change | Whether the approved individuals are still the actual ones |
The specifics vary by regime, but the shape is consistent: an annual audit against the standard your regulator or SRO applies, periodic reporting, evidenced staff training, procedure updates when the rules change, and a risk assessment refresh when your business changes. In Switzerland the SRO conducts or commissions the audit directly, under the framework FINMA oversees. In EU regimes the obligations flow from the authorising instrument — for crypto-asset service providers, from MiCA, whose transitional period ended on 1 July 2026.
The table above sets out what each obligation is really testing, which is more useful than the obligation itself. An audit is not checking whether you have policies; it is checking whether the operation matches the policies you filed. Those are very different tests, and the second is the one businesses fail.
How are licences actually lost?
Almost never through a single dramatic breach. The usual pattern is drift. The company adds a product line, starts serving customers in a country that was not in the original geographic risk profile, changes who holds client assets, or replaces the compliance officer with someone the regulator never approved. Each step is reasonable in isolation. None of them is reflected in the filed documents. Two years later, an auditor reads the risk assessment and the transaction data together and the gap is obvious.
The second pattern is notification failure. Most regimes require certain changes to be notified — often approved — before they happen: a change of controller, a new regulated activity, a material change in business model. Doing the thing first and telling the regulator afterwards converts a routine filing into a breach.
What we do
What we take on
- Maintaining the compliance calendar, so no filing date arrives as a surprise
- Preparing the annual audit file and handling the auditor's or SRO's questions
- Drafting and filing the periodic regulatory reports the permission requires
- Refreshing the institutional risk assessment when the business changes materially
- Running and evidencing staff training, including for new joiners
- Tracking regulatory change in the relevant jurisdiction and updating procedures against it
- Preparing change-notification and variation filings before the change takes effect, not after
The list above is the scope. The part clients value most is the compliance calendar: the obligations of a licence are individually simple and collectively easy to lose track of, particularly for a small team whose attention is on the product. Everything else follows from not missing dates.
We also monitor regulatory change in the jurisdictions our clients hold permissions in. Crypto regulation is not stable, and a procedure written against a rule that has since been amended is worse than no procedure, because it evidences that nobody has looked at it.
Why does this matter beyond the regulator?
Banks and payment partners assess this record too. A clean audit history and current documentation is a significant part of why an account survives periodic review, and its absence is a common reason a relationship is closed with little warning. That connection is set out on banking and card issuing, and the wider picture of what happens after approval is on after the licence.
If you hold a permission we did not obtain for you, we take on maintenance for it. The first step is a review of the current position against the licence conditions, which frequently finds items nobody had realised were outstanding.
No adviser can guarantee a regulatory outcome, including on a maintenance matter — regulators retain full discretion. This page is general information, not legal advice; CryptoLicense is an advisory firm, not a regulator and not a law firm.



