Key points
- Seven stages, with the classification work done before anything is drafted
- We draft the documents; you supply the facts and make the decisions
- Entity, address, AML officer and banking are sourced as part of the work
- Regulator questions are answered from one consistent position
- The applicant is always you — accountability cannot be outsourced
Seven stages. Assess the business model and target markets; choose the route and jurisdiction; establish the entity and the local substance the regime requires; draft the full document set; submit and handle the regulator's questions; take handover at approval; and maintain the licence afterwards. You supply facts and decisions. We do the drafting, sourcing and correspondence.
Seven stages. The order matters more than the list does: three of the four most expensive failures we see are caused by starting at stage four, because drafting is the part that feels like progress.
How long does it take?
We do not answer that with a number, and we would treat a firm that does with suspicion. The stages we control move at the speed of your document turnaround; the stages a regulator controls move at the regulator's. What we will say is that a founder's own response time during the question round at stage five is, in our experience, the single largest variable that either side can actually influence.
Who does what?
What we need from you, and what we do not
- From you: accurate facts about the business, shareholder and beneficial-ownership documents, and decisions at the points where a decision is genuinely yours
- From you: timely responses — a slow reply during a regulator's question round costs more time than any other single factor
- From us: the classification work, the full document set, the sourcing of entity, address, officer and banking, and all correspondence
- From us: a written position on each route's risks, including the ones that argue against the route we are recommending
- From neither of us: a guarantee. Regulators retain full discretion, and substance cannot be outsourced — the people and the operation have to be real, and yours
The division is simple. You supply facts and make decisions. We do the classification, the drafting, the sourcing and the correspondence. Where a route has a real risk we write it down, including when it argues against the route we are recommending — an adviser who only produces reasons to proceed is not giving you a basis for a decision.
What cannot be delegated?

Two things, and both are worth being blunt about. The applicant is always you. A regulator holds the licensed entity and its directors and compliance officer accountable — not the firm that drafted the file. And substance cannot be outsourced. The local presence, the people, the controls: they have to be real and they have to be yours. Where a regime demands a compliance officer, it means someone who can genuinely perform the role, and regimes have become steadily less tolerant of arrangements where that is nominal. This is covered in detail on substance, cost and risk.
The standards underlying most of these regimes trace to the FATF recommendations, with each jurisdiction adding its own detail — FINMA in Switzerland, the Monetary Authority of Singapore, and their equivalents elsewhere. If you are weighing whether to run this yourself, the honest version of that trade-off is on this site too.
No approval can be guaranteed; regulators retain full discretion. This page is general information, not legal advice — CryptoLicense is an advisory firm, not a regulator and not a law firm.
How it works, step by step
Stage one: assess the business model and target markets
We take the business apart: what the product does, how funds move, who holds client assets and from what moment, which countries the customers are in, where revenue comes from, and who the shareholders and ultimate beneficial owners are. The purpose is to establish which regulated category you fall into in each jurisdiction under consideration, and to surface anything clearly unworkable. If your model sits outside where we have real experience, we say so here rather than signing first and working it out later.
Stage two: choose the route and the jurisdiction
A trade-off between one or more viable paths. The comparison covers whether the licence's scope matches where your customers are, capital and personnel thresholds, local entity and substance requirements, the ongoing reporting and audit burden, and how the resulting permission is treated by banks. We set out the risks of each route including, where it applies, the possibility of having to re-select later. The decision is yours; our job is to supply the full basis for it.
Stage three: entity, address and the people the regime requires
Almost every credible regime assumes a real local entity, a verifiable registered address, and a compliance officer with appropriate credentials who can actually perform the role. These are separate recruitment and procurement tasks with their own lead times, and they depend on each other in a specific order — an account application will usually wait on the entity, which waits on the address. We source and sequence them rather than handing you a list.
Stage four: draft the document set
The business plan, the AML and CFT policy, the institutional risk assessment, the customer due diligence and ongoing monitoring procedures, the governance and responsibility map, outsourcing arrangements, IT and operational resilience, and financial projections. These are written against your actual operation, not filled in from a template: a regulator reads them alongside what you say you do and looks for the places where the two do not match.
Stage five: submit, then answer the questions
Most serious regulators come back with supplementary questions, and the quality of the first round of answers sets the tone of the whole file. There is no second first impression. We answer from a single consistent position across every document already filed, and you confirm the factual parts. Some of this stage runs at the regulator's pace rather than ours, which is why we never quote a date.
Stage six: approval and handover
On approval you receive the complete file: the permission itself, the approved policies and procedures, the conditions attached to the licence, and a plain statement of what those conditions require of you month by month and year by year. A licence handed over without that becomes a compliance failure twelve months later, when the first annual obligation falls due and nobody inside the business knows it exists.
Stage seven: keep it
Annual audit, regulatory reporting, staff training, procedure updates, and revisiting the risk assessment whenever the business changes materially — a new product, a new market, a new custody arrangement. Most revocations and penalties originate here rather than at the application stage, which is why we treat maintenance as part of the work instead of an upsell.



