Switzerland does not hand most crypto operators a FINMA licence. If your business falls under the Anti-Money Laundering Act you must join a FINMA-recognised self-regulatory organisation, which then supervises you directly. Admission runs a set sequence: application and fee, completeness check, professional review, interview, decision.
The phrase "Swiss crypto licence" is a translation error that has cost a lot of people a lot of time. For the large majority of exchanges, brokers, payment firms and wallet providers, Switzerland does not issue a licence at all. It requires membership of a private-law body that has itself been recognised by the regulator, and it is that body — not FINMA — that reads your files, asks your questions and audits you afterwards.
Understanding that one structural fact changes how you prepare. You are not writing for a state supervisor with a published application form. You are applying to join an organisation whose own rulebook FINMA has approved, and which is answerable to FINMA for how strictly it applies it.
What is a Swiss SRO, and why is it not a FINMA licence?
FINMA states the position plainly: "The Anti-Money Laundering Act states that financial intermediaries must become members of a self-regulatory organisation (SRO) under civil law as a way of preventing money laundering." And the consequence, in the same place: "Such financial intermediaries are supervised by the SROs where they are affiliated, and not by FINMA."
FINMA recognises an SRO only where it meets four conditions, which are worth reading as a description of what will happen to you. The SRO must have "a set of regulations which set out the AMLA due diligence requirements in detail for its members"; it must monitor "compliance with these regulations by affiliated financial intermediaries"; it must give "a guarantee of irreproachable business activity"; and it must ensure that the audit firms and lead auditors carrying out those controls meet the AMLA authorisation requirements.
VQF, one of the recognised SROs, calls the arrangement "state-supervised self-regulation", and describes the population it covers as the para-banking sector — fiduciaries, asset managers, payment service providers and financial advisers who must comply with the Anti-Money Laundering Act. Nothing in that description is decorative. Every one of those four words appears again in the questions you will be asked.
Are you actually within scope?
The scope test is behavioural, not sectoral. VQF frames it around whether the activity is carried out "on a professional basis" and whether "third-party assets are accepted, held, invested or transferred", and lists the triggering activities as accepting or holding third-party assets, transferring payments or assets on behalf of clients, processing financial transactions for third parties, managing assets for third parties, and assisting in investing or transferring third-party assets. VQF is explicit that this overview "is for guidance purposes only and does not constitute legal advice", and that applicability "must always be assessed on the basis of the specific activity and business model".
For crypto specifically, FINMA removes the ambiguity: "Trading with virtual currencies (Bitcoin, etc.) and operating a payment system fall under the Anti-Money Laundering Act (AMLA)", and "If the business you do is subject to the AMLA, you must become a member of a self-regulatory organisation (SRO)."
Which SRO should you approach?
FINMA publishes the list of recognised SROs, and as at 10 August 2026 it names eleven. Five of them describe their own membership in their names — the SRO of the Swiss Bar Association and the Swiss Notaries Association, the SRO of the Swiss Insurance Association, the Swiss Leasing Association, the SRO of the Swiss Association of Investment Companies, and the Ticino fiduciaries' body OAD FCT. The remainder, including AOOS, ARIF, PolyReg, SO-FIT, SRO-Treuhand Suisse and VQF, take financial intermediaries more broadly.
The choice is not cosmetic. Because each SRO writes its own regulations within the AMLA framework, the document set you prepare, the audit cycle you enter and the person who ultimately interviews you all differ by body. Read the target SRO's regulations before you draft anything, not after.
The admission sequence, stage by stage
VQF publishes its own process, and it is a useful model for what any SRO admission looks like. The stages, in VQF's own ordering:
| Stage | What happens | What it turns on |
|---|---|---|
| 1. Application submitted | The required documents are submitted together with payment of the processing fee | VQF states that "processing of the application for membership begins once the processing fee has been received" |
| 2. Preliminary review | The submission is checked for "completeness and formal correctness" | Incomplete or improperly submitted documents are requested by email, and the file waits |
| 3. Document verification | The application advances only once everything is in, in the correct form | This stage is entirely inside your control, and is the one most often lost |
| 4. Professional assessment | The Legal & Compliance team conducts an "in-depth professional review" | May require "additional documents or supporting evidence" depending on the business model |
| 5. Admission interview | Outstanding questions are addressed and the business model discussed in detail | Your description of the business has to survive being explained out loud |
| 6. Decision | "The VQF decides on the application for membership" | Successful applicants receive written confirmation by post |
Notice what stage four and stage five have in common. Both are conversations about the business model rather than about paperwork. A file that reads as a template survives neither. This is why the substantive work happens long before submission — see how we work for the sequence we run.
What should be built before you apply?
There is no universally published checklist, and we will not invent one. But the published framework tells you what the review is testing. FINMA requires each SRO to hold regulations that "set out the AMLA due diligence requirements in detail for its members" and to monitor compliance with them, so your file is assessed against a specific SRO's rulebook rather than a generic standard. VQF's own basic AMLA training, in turn, covers "Fundamentals of the Anti-Money Laundering Act", "Due diligence obligations for financial intermediaries" and "Requirements of the VQF SRO regulations" — a fair map of the ground you will be held to.
In our experience of running these files, an applicant that moves quickly arrives with a Swiss entity already formed, a named person accountable for AML compliance, written due-diligence and monitoring procedures drafted against that SRO's regulations rather than copied, a risk analysis derived from its own business, and one consistent description of the business across every document. That last one is unglamorous and decides more outcomes than the rest.
What SRO affiliation does not authorise
Affiliation covers you for anti-money-laundering purposes. It is not a banking permission, and it is not a trading-venue permission. FINMA's own authorisation guidance draws the lines:
| If your business | Then Switzerland requires |
|---|---|
| Trades virtual currencies or operates a payment system, and is subject to AMLA | Membership of a FINMA-recognised SRO |
| Accepts client deposits up to a maximum of CHF 100 million, or takes collective custody of crypto-based assets, where deposits are neither invested nor interest-bearing | A FinTech licence |
| Accepts deposits from more than twenty clients, or client assets exceeding CHF 100 million | A banking licence |
| Operates a facility for DLT securities trading | A DLT trading facility licence |
Describing SRO membership as a "Swiss financial licence" in your marketing is therefore inaccurate, and inaccurate in a direction any sophisticated counterparty can check in a minute. Describe it as what it is: affiliation to a FINMA-recognised SRO under the Anti-Money Laundering Act.
What happens after you are admitted?
Admission starts the obligations rather than ending them. The SRO's job, in VQF's description of SRO duties, is "Establishing rules for the implementation of legal obligations" and "Monitoring their members' compliance with these rules" — which in practice means annual AML audit, staff training, procedural updates and cooperation with inspections.
Above that sits FINMA's supervision of the SRO itself, and it is worth knowing how it works, because pressure travels downhill. FINMA "carries out a risk analysis and categorisation for SROs, looking in particular at their membership structure, their policies regarding business, risk and supervision, and their organisation". Its supervisory tools "include periodic on-site supervisory reviews, regular bilateral supervisory consultations and analysis of an SRO's annual reports", and "once a year or every second year, depending on their risk category, all SROs are sent assessment letters detailing any weak points and indicating where action is required". An SRO that has just received such a letter is not a lenient SRO. Ongoing obligations are covered further in post-licence compliance maintenance.
How does a bank verify that you are a member?
Easily, which is the point of the structure. FINMA operates an SRO member search where anyone can "search for financial intermediaries that are members of a self-regulatory organisation (SRO)" and "find here the SROs responsible for supervising these financial intermediaries". FINMA also directs reports and complaints about an affiliated intermediary to the responsible SRO. Assume every serious counterparty will run that search before your first call, and make sure the entity name on your pitch deck is the entity name in the register. That principle runs through our own verifiable entity proof page too.
Timing, fees, and what cannot be promised
VQF does not publish a duration for admission on its membership page, and neither will we. What it does publish is that processing begins once the processing fee has been received — so a file that has not paid has not started, whatever the internal tracker says. Beyond that, the honest framing is the one our own FAQ uses: a well-prepared application may take several months, and a more demanding authorisation may take a year or longer.
No approval can be guaranteed. The decision belongs to the SRO, and it retains full discretion to refuse. Part of the elapsed time is theirs, set by their workload rather than by anything either of us does. What can be committed to is that the waiting is not dead time: while a file sits with an SRO, banking, procedures, personnel and any second jurisdiction keep moving in parallel.
Where we fit
Swiss SRO membership is the single largest line of work we do. We draft the application rather than review yours, and we source what the file requires, including bank account introductions, a local address and local personnel where the structure calls for them. CryptoLicense is an advisory firm — not a regulator and not a law firm — and nothing on this page is legal advice. If you are still comparing Switzerland against the EU and El Salvador rather than preparing a Swiss file, start with the three-route comparison.
本文属于系列指南:完整指南见 瑞士SRO.
