Key points
- Licence applications are the largest line; Swiss SRO membership is the single biggest
- Compliance maintenance is where most enforcement actually happens
- Banking and card issuing are treated as part of the job, not an afterthought
- Buying a licensed entity is a real option, and sometimes the wrong one
- We decline work that sits outside where we have genuine experience
Five lines of work. Licence applications are the largest — Swiss SRO membership above all, then El Salvador BSP and DASP, New Zealand FSP registration and Latvian EMI or CASP authorisation. Around that sit post-licence compliance maintenance, cross-border regulatory advisory, introductions for banking and card issuing, and the purchase or sale of already-licensed entities.
Five lines of work, in the order they matter to the businesses that come to us. They are not independent: almost every engagement that starts as an application ends up touching banking, and every licence granted turns into a maintenance obligation the following year.
Which of the five do you need?
Which line fits which situation
| If this is your situation | The line that fits | What decides it |
|---|---|---|
| No licence anywhere, building for a European customer base | Licence applications | Which regulated category the model falls into |
| Licensed already, struggling with annual obligations | Compliance maintenance | What the licence conditions actually require of you |
| Payments, remittance or e-wallet rather than pure crypto | Fintech licences | Whether you hold client funds, and where |
| Licensed but no bank will open an account | Banking and card issuing | The bank's own risk appetite, and your file |
| Need to be live in a market sooner than a fresh application allows | Licence transfer | Whether the target entity's history survives due diligence |
| Expanding into a second or third market | Cross-border advisory | Whether the existing permission travels at all |
The honest answer is that most founders do not know yet, because the question underneath it — which regulated category does this business fall into — has not been settled. If that is where you are, start with choosing a licence rather than with a service line.
What does each line actually do?
Licence applications are the largest part of the practice, and Swiss self-regulatory organisation membership is the single biggest within it. Under Swiss anti-money-laundering law a financial intermediary joins a recognised SRO rather than applying to FINMA directly; the full route is described on the Swiss SRO route. Alongside it we run El Salvador BSP and DASP, New Zealand FSP registration, and Latvian EMI and CASP work.
Fintech licences are the payments-side equivalent: Latvian API and EMI, Singapore's Major Payment Institution licence, Canadian MSB with RPAA registration, UK API and EMI, Hong Kong MSO. The dividing line is usually whether you hold client funds and in what form — set out on fintech licences.
Compliance maintenance is the least visible line and the one that decides whether a licence survives. Annual audit, regulatory reporting, staff training, procedure updates, and revisiting the risk assessment when the business changes. Detail on post-licence compliance.
Banking and card issuing exists because a licence you cannot bank is not an operating business. Account opening across the UK, EU and Singapore, and card programmes including U Card in Singapore and Hong Kong — see banking and card issuing.
Licence transfer covers buying or selling an entity that already holds a permission. It can be genuinely faster, and it can also mean inheriting a compliance history you did not create. The trade-off is on new application versus ready-made licence.
What will we not take on?
We do not give legal advice, we do not promise timelines, and we do not quote an approval rate. No adviser can guarantee that a regulator will approve an application — they retain full discretion, and that is true regardless of how good the file is. What we can say is that the file will be written against your real operation, and that while a regulator works through its queue the other workstreams keep moving.
This page is general information rather than legal advice. CryptoLicense is an advisory firm, not a regulator and not a law firm.
Licence applications
Swiss self-regulatory organisation membership is the line we handle most, and suits crypto businesses that need a mature, verifiable compliance identity in Europe. Alongside it: El Salvador BSP and DASP, New Zealand FSP registration, and Latvian EMI or CASP authorisation. We run the whole path — eligibility assessment, drafting, and correspondence with the body itself.
02Fintech licences
Latvian API and EMI, Singapore's Major Payment Institution licence, New Zealand FSP registration, Canadian MSB including RPAA registration, UK API and EMI, Hong Kong MSO. For payments, remittance and e-wallet businesses rather than pure crypto ones.
03Post-licence compliance maintenance
Annual audit, regulatory reporting, staff training, procedure updates, and keeping the risk assessment aligned with what the business has actually become. This is where most revocations and penalties originate, and it is the least glamorous work we do.
04Banking and card issuing
Bank account opening in the UK, EU and Singapore, and card issuing programmes including U Card in Singapore and Hong Kong. A licence that cannot be banked does not let you operate, so we treat this as part of the same problem rather than a separate one.
05Licence transfer and ready-made entities
Buying or selling an already-licensed entity. Sometimes materially faster than a fresh application, sometimes an expensive way to inherit somebody else's compliance history. We will tell you which case you are in before you commit.
Most revocations and penalties do not happen at the application stage. They happen during maintenance.
CL Global advisory team



