Annual audit
Conducted or commissioned by the SRO against its own standard. It tests whether the operation matches the procedures you filed.

Switzerland supervises anti-money-laundering compliance in two tiers. FINMA recognises and oversees self-regulatory organisations; those SROs admit and directly supervise financial intermediaries. A firm carrying on financial intermediation must be affiliated with a recognised SRO — it does not apply to FINMA for a crypto licence, because that instrument does not exist.
Switzerland is the route we handle most, and the one most often described inaccurately in marketing material. This page sets out what it actually is, what it requires, and what it does not give you.

Swiss anti-money-laundering supervision is organised in two tiers. The Swiss Financial Market Supervisory Authority, FINMA, recognises and oversees a set of self-regulatory organisations. Those SROs in turn admit financial intermediaries as members and supervise them directly — reviewing the application, deciding on admission, and auditing them every year afterwards.
So your counterparty is the SRO, not FINMA. That structure has two practical consequences that surprise people. The first is that admission standards are set and applied by a body with its own membership, its own reputation to protect, and its own appetite for the kinds of business it wants. The second is that the relationship is continuous: the SRO is not a gatekeeper you pass once, it is a supervisor you have for as long as you are affiliated.
The question that determines whether this route applies to you at all. Swiss anti-money-laundering law captures financial intermediation on a functional basis rather than by product name — activities such as accepting or holding assets belonging to others, or assisting in their investment or transfer. For crypto businesses, exchange, transfer and custody activity is the common ground on which affiliation is required.
What matters is that the assessment is about what you do, not what you call it. That is the same analysis as on choosing a licence, and it is worth completing before committing to Switzerland rather than after.
Being blunt about this saves everyone time. Affiliation confirms that your firm is within the scope of the Anti-Money Laundering Act and is supervised for that purpose by a recognised body. It gives you a status that banks, exchanges and institutional counterparties recognise and can diligence quickly, which is a large part of its commercial value.
It is not a banking licence: it does not permit deposit-taking. It is not a securities licence. And it is not EU authorisation — Switzerland is outside the European Union, and Swiss affiliation does not permit you to serve EU customers. If your customer base is in the EU, MiCA authorisation is the relevant instrument, and its transitional period ended on 1 July 2026. The three-way comparison is on Swiss SRO vs MiCA vs El Salvador.
The seven things that usually have to exist before submission
The seven items above are the honest minimum, and this is where Swiss files most often fail — quietly, because the application describes an organisation that does not yet exist.
| Requirement | What is actually being tested | Where it commonly falls short |
|---|---|---|
| Swiss entity and registered office | That there is a real, locatable company | An address with no management presence behind it |
| Appointed AML officer | That a qualified person can genuinely perform the function | A name lent to the file who cannot answer questions about the business |
| AML procedure set | That the controls are specific and executable | Generic text that could describe any firm |
| Risk analysis | That you understand your own exposure | Template risk categories with no reference to your customers |
| Fit-and-proper material | Who ultimately controls the business | Ownership chains that do not resolve to natural persons |
| Business plan and source of funds | That the model is coherent and funded | Projections inconsistent with the stated volumes |
| Monitoring tooling | That the written procedures can actually be executed | Procedures describing monitoring no system performs |
The right-hand column is the useful one. Almost every shortfall is the same shape: a document that is true in the abstract and unconnected to the specific business it describes. Reviewers read these files constantly and recognise generic text immediately.
An operational organisation, not a plan. The mental model that makes this route go smoothly is that the SRO wants to see a firm that could begin taking customers the day it is admitted: the entity exists, the officer is appointed, the procedures are written and the tooling can perform them. Files framed as "we will build this once we are approved" are read exactly as written.
This is also the honest reason the route is not for everyone. It requires committing real cost — a Swiss entity, a qualified officer, monitoring infrastructure — before there is any certainty of admission. A business that cannot carry that is better off looking at a different route than at a cheaper version of this one.
Conducted or commissioned by the SRO against its own standard. It tests whether the operation matches the procedures you filed.
Delivered and evidenced. The evidence is the point: it demonstrates the procedures exist outside the document.
When the rules change, or when your business does. A procedure describing a superseded rule is worse than none.
New product, new market, new custody arrangement — each is a trigger, not an optional review.
Certain changes must be notified, often before they take effect. Doing the thing first turns a filing into a breach.
A change of AML officer or key personnel has to be run past the SRO, with fit-and-proper material for the incoming individual.
The six cards above. The one that catches people out is notification: most material changes must be notified, and often approved, before they take effect. A change of controller, a new regulated activity, a materially different business model. Doing the thing first and reporting afterwards converts routine administration into a breach — a distinction that matters far more than the paperwork suggests.
Beyond that, the year-two pattern is the same one described on post-licence compliance: the business grows, the filed documents describe the company it used to be, and an audit puts the two side by side. Membership is not lost through dramatic failures; it is lost through drift.
Eligibility assessment first — whether your activity genuinely falls within Swiss financial intermediation, and whether this route serves your customer base better than the alternatives. Then the entity and local arrangements, the AML officer, the full internal procedure set drafted against your operation, the fit-and-proper and business-plan material, submission, and every question round answered from a single consistent position. The practical detail is on Swiss SRO membership application, and what the substance requirements cost in practice is on substance, cost and risk.
Admission is at the SRO's discretion and cannot be guaranteed by anyone. The framework described here reflects the position as at August 2026; Swiss regulation has been comparatively stable but is not fixed. This page is general information, not legal advice — CryptoLicense is an advisory firm, not a regulator and not a law firm.
Tell us your business model and target markets and we will set out the jurisdictions that fit, the stages on each route, and what you will need to prepare. Free consultation. Approval is at the regulator's discretion and we promise nothing about it.
Book a call