Introduction What This Page Covers
Obtaining a FINMA crypto licence in Switzerland is the gateway for any digital-asset business that wants to operate lawfully from one of the world’s most established fintech jurisdictions. Switzerland offers three distinct authorisation paths the FINMA FinTech licence, the full banking licence, and membership of a FINMA-recognised Self-Regulatory Organisation (SRO) such as VQF and each path carries different permissions, capital expectations, timelines and compliance burdens.
This guide is written for founders, Chief Compliance Officers and General Counsel who need to decide which route fits their business model, assemble the right documentation pack, and estimate realistic end-to-end timelines. By the end of this page you will be able to map your product to the correct FINMA authorisation path, understand the key eligibility criteria and common pitfalls, and prepare a submission-ready file that minimises regulator queries.
Quick Decision Flow Which FINMA Route Fits Your Crypto Model?
At-a-Glance Decision Checklist
Before diving into detailed requirements, answer the following threshold questions about your intended business activities:
- Deposit-taking: Will you accept public deposits (fiat or stablecoin) from clients? If yes, how large could aggregate deposits become?
- Custody: Will you hold, safeguard or administer crypto assets on behalf of clients including custody-as-a-service, staking, or delegated key management?
- Investment or lending: Will you invest or on-lend client funds, offer interest-bearing products, or manage portfolios?
- Token type: Are you dealing primarily with payment tokens, asset/security tokens, or utility tokens? Token classification affects whether securities-law obligations also apply.
- Fiat on-ramp / off-ramp: Will you convert crypto to fiat (or vice versa) for clients, triggering financial-intermediary status under the Anti-Money Laundering Act (AMLA)?
Short Flowchart Decision Rules
Use the following logic to identify your starting point:
- If you accept public deposits up to CHF 100 million and do not invest or pay interest on those deposits → the FINMA FinTech licence is the purpose-built route. It covers deposit-linked crypto services without requiring a full banking licence.
- If you accept deposits above CHF 100 million, invest client funds, pay interest, or provide lending products → a full banking licence under the Federal Act on Banks and Savings Banks is required.
- If your crypto services do not involve deposit-taking for example, brokerage, exchange, payment processing, or custody-only models below banking thresholds you are likely classified as a financial intermediary under AMLA and can operate through SRO membership (e.g., VQF) rather than holding a direct FINMA licence.
Where your business model spans multiple categories (for instance, exchange services and public deposit-taking), the highest-tier authorisation governs. When in doubt, a pre-application model validation is the essential first step addressed below under the process section.
Process Step-by-Step: How to Obtain Crypto Licensing in Switzerland
Regardless of the path chosen, every FINMA crypto licence application in Switzerland follows a broadly similar lifecycle: model analysis, documentation, submission, regulatory review, remediation and, finally, authorisation or admission. The path-specific nuances are outlined within each step below.
Step 1 Pre-Application Model Validation
Conduct a thorough legal and regulatory gap analysis before engaging the regulator or an SRO. This step should confirm:
- Token classification: Is the token a payment token, utility token or asset token under FINMA’s framework?
- Fiat flow analysis: Map all fiat on-ramps, off-ramps, custody chains and settlement flows.
- Service scope: Enumerate every intended service custody-as-a-service, staking, lending, deposit-taking, brokerage because each may trigger separate regulatory obligations.
- Jurisdictional touchpoints: Identify cross-border elements (foreign clients, foreign nodes, outsourced infrastructure) that could require additional authorisations or enhanced AML measures.
Pragmatic tip: document this analysis in a concise regulatory memo (5–10 pages). Regulators and SROs appreciate structured self-assessments; providing one up front can shorten the overall Q&A cycle considerably.
Step 2 Decide Route (FinTech vs Banking vs SRO)
Using the decision rules above and the comparison table below, confirm which authorisation path matches your validated model. For firms whose activities fall close to a boundary for example, deposit volumes that may approach CHF 100 million within 12–24 months consider whether the FinTech licence provides sufficient runway or whether a banking licence application should begin immediately. For many crypto firms focused on exchange, brokerage or custody-only services, SRO membership through VQF offers the fastest route to lawful operation.
Step 3 Prepare the Documentation Pack
A complete, well-organised file is the single most important factor in accelerating approval. The precise requirements vary by path (detailed in the documentation section below), but every application should include:
- Executive summary and business plan: Clear description of the business model, revenue drivers, target clients and growth projections.
- Organisational chart and governance framework: Board and management structure, reporting lines, compliance function, fit-and-proper documentation for key persons.
- AML/KYC manual: Detailed policies covering customer due diligence, enhanced due diligence, transaction monitoring, suspicious-activity reporting to MROS and sanctions screening.
- IT security and outsourcing documentation: Architecture diagrams, penetration-test summaries, business-continuity plans, third-party service provider assessments.
- Financial projections and capital adequacy: Three-year forecasts, capital plan, and for banking applicants detailed risk-weighted-asset calculations.
Pragmatic tip: use a consistent file-naming convention (e.g., [CompanyName]_FINMA_01_ExecSummary_v1.0.pdf) and supply all documents in both German (or French/Italian, depending on canton) and English where possible. This minimises administrative friction during review.
Step 4 Application Submission
For direct FINMA authorisation (FinTech or banking), the application is submitted to FINMA electronically. Key pointers:
- Language: FINMA accepts submissions in German, French, Italian and English, but official correspondence is typically in one of the three national languages.
- Fees: FINMA charges application fees and ongoing supervisory levies. Fees are set annually and scale with the complexity of the licence and the institution’s balance sheet.
For SRO admission (e.g., VQF), the application is submitted directly to the SRO, not to FINMA. VQF has its own membership application form and documentation requirements, covered in the checklist section below.
Step 5 Review Period, Questions and Remediation
Once submitted, expect an iterative review process. FINMA or the SRO will raise questions often in writing and may request clarifications, supplementary documents, or policy revisions.
- FinTech licence: FINMA has publicly committed to digitalisation and increased efficiency in supervisory processes, including faster internal processing for FinTech enquiries. Industry observers note that well-prepared files now move through initial assessment materially faster than in prior years.
- Banking licence: The review is more granular. Expect multiple rounds of questions covering capital adequacy, governance, risk frameworks and outsourcing arrangements.
- SRO (VQF): VQF conducts its own admissions review and may require an on-site pre-admission assessment. Responsiveness and the quality of AML documentation are the primary drivers of speed.
Pragmatic tip: designate a single point of contact for all regulator correspondence. Provide sample policies (e.g., a draft AML manual) at the outset rather than waiting for the regulator to request them this can shorten the Q&A cycle by weeks.
Step 6 Approval, Conditions and Ongoing Supervision
Upon successful completion of the review:
- Authorisation or registration is granted, often with conditions (e.g., implement a specific control before go-live, appoint an external auditor within a set period).
- Ongoing supervision: FINMA-licensed entities are subject to prudential supervision, periodic reporting and regulatory audits. SRO members are supervised by the SRO, which itself is overseen by FINMA.
- Audit expectations: Both FINMA-licensed entities and SRO members must engage a recognised audit firm. Audit frequency varies typically annually for banking licensees, and at regular intervals defined by the SRO for its members.
Comparison Table FinTech Licence vs Banking Licence vs SRO
The table below provides a side-by-side comparison of the three FINMA crypto licence pathways available in Switzerland. Use it as a quick reference when evaluating your options.
| Criteria |
FINMA FinTech Licence |
Banking Licence |
SRO Membership (e.g., VQF) |
| When to use |
Accepting public deposits ≤ CHF 100 m; digital-asset services not requiring full banking functions |
Full banking services including lending, interest-bearing deposits, large-scale custody |
Crypto brokerage, exchange, payment, or custody-only models that do not involve deposit-taking |
| Key permissions |
Public deposit-taking (no interest); limited custody-like activities if deposits are not invested |
Full banking activities deposits, lending, investment, custody at scale |
AML-supervised financial intermediary services; KYC/CTF compliance; client onboarding & reporting |
| Deposit / custodian limits |
CHF 100 million deposit cap (public deposits) |
No explicit cap; full prudential rules apply |
No deposit-taking beyond payment-service thresholds; custody-only models may be eligible |
| AML supervision |
Direct FINMA supervision |
Direct FINMA prudential supervision |
Supervision through recognised SRO (e.g., VQF), with FINMA oversight of SROs |
| Typical timeline (complete file) |
3–9 months |
9–18+ months |
2–6 months |
| Use-cases |
Crypto deposit platforms, stablecoin issuers (non-interest), neo-banks with limited scope |
Crypto banks, lending platforms, security-token depositories |
Exchanges, brokers, payment processors, wallet providers, OTC desks |
Key Requirements and Eligibility by Path
FinTech Licence Core Eligibility Criteria
Under the FINMA FinTech licence, applicants must meet the following baseline criteria:
- Legal form: The entity must be a Swiss legal entity (typically a corporation AG or GmbH) with its registered office and effective place of management in Switzerland.
- Deposit restriction: Public deposits accepted under this licence must not exceed CHF 100 million and must not be invested or bear interest.
- Governance: Adequate organisational structure, internal controls and risk management. At least two qualified persons must direct the business.
- Capital: Minimum capital requirements apply (currently 3% of accepted deposits or CHF 300,000, whichever is higher).
Banking Licence Prudential Requirements
A full banking licence demands significantly more rigorous preparation:
- Capital adequacy: Full prudential capital requirements aligned with Basel standards, including risk-weighted-asset calculations and capital buffers.
- Governance: Board independence, risk-committee structure, fit-and-proper assessments for all directors and senior managers.
- Risk frameworks: Comprehensive credit, market, operational and liquidity risk management frameworks subject to ongoing FINMA review.
SRO Route AML Program and Operational Readiness
For firms choosing SRO membership, the core requirements centre on AML compliance:
- AML program: A fully documented AML/KYC/CTF compliance framework aligned with AMLA and the SRO’s own regulations.
- MLRO appointment: A designated Money Laundering Reporting Officer with sufficient authority, resources and expertise.
- MROS reporting channel: Operational processes for filing suspicious-activity reports with the Money Laundering Reporting Office Switzerland (MROS).
- Audit readiness: Preparedness for periodic on-site and desk-based audits conducted by the SRO or its appointed auditors.
Required Documentation and Submission Checklist
Mandatory Documents (Per Route)
Below is a consolidated list of the core documents required across all three FINMA authorisation paths. Items marked with an asterisk (*) are specific to the banking-licence path; items marked with a dagger (†) are SRO-specific.
- Executive summary: 3–5 page overview of the business model, regulatory path chosen and key personnel.
- Detailed business plan: Market analysis, product descriptions, client segments, revenue model and three-year financial projections.
- Organisational chart: Legal structure, group diagram (if applicable), reporting lines and outsourcing relationships.
- Ownership and UBO disclosure: Detailed ownership chain to the ultimate beneficial owners, including shareholding percentages and source-of-funds documentation.
- Governance and compliance policies: Board charter, compliance-function mandate, internal-control framework, code of conduct.
- AML/KYC manual: Customer due diligence procedures, enhanced due diligence triggers, sanctions screening, PEP identification, transaction-monitoring rules and MROS reporting processes.
- IT security and outsourcing documentation: System architecture, data-protection measures, penetration-test results, cloud-service-provider assessments, business-continuity and disaster-recovery plans.
- Financial forecasts and capital plan: Balance-sheet projections, capital-adequacy calculations*, liquidity planning*, stress-test scenarios*.
- Audit-firm appointment letter: Confirmation of engagement with a FINMA-recognised audit firm (or SRO-recognised auditor for the SRO route†).
- Fit-and-proper documentation: CVs, criminal-record extracts, reference letters, declarations of interest and competence assessments for all directors and senior managers.
SRO-Specific Pack (VQF)
Applicants for VQF membership should prepare the following additional items:
- VQF membership application form: Completed in accordance with VQF’s published template.
- AML manual tailored to VQF regulations: Must reference VQF-specific thresholds, reporting timelines and audit standards.
- Compliance officer details: Contact information, qualifications, and confirmation of appointment for the designated MLRO/compliance officer.
- Onboarding and transaction-monitoring procedures: Step-by-step workflow documents demonstrating how clients are onboarded and how ongoing monitoring is conducted.
[Download the full FINMA crypto application checklist available as a structured PDF with file-naming guidance and submission tips.]
Realistic Timelines and Fees
End-to-end timelines depend heavily on the completeness of the submitted file, the complexity of the business model, and the responsiveness of the applicant during the review phase. Realistic estimates, assuming a substantially complete file at submission, are:
- SRO admission (VQF): 2–6 months the fastest operational route for many crypto firms.
- FinTech licence: 3–9 months FINMA has emphasised digitalisation and efficiency improvements that have shortened internal processing for FinTech enquiries since 2023.
- Banking licence: 9–18+ months reflecting the depth of prudential review and the capital-planning cycle.
Common variables that extend timelines include:
- Audit qualifications or reservations requiring corrective action before authorisation.
- AML gaps identified during review incomplete transaction-monitoring rules, weak PEP screening.
- Foreign ownership complexity multi-jurisdictional group structures requiring additional UBO verification.
- Material product novelty first-of-a-kind services or token structures that require FINMA to develop new assessment criteria.
Common Pitfalls and How to Avoid Them
Across all three authorisation paths, the same recurring issues account for the majority of delays and rejections:
- Weak AML/KYC policies: Generic templates that do not reflect the applicant’s actual crypto activities. Tailor every policy to your specific product flows.
- Unclear custody separation: Failure to demonstrate clear segregation between client assets and proprietary holdings both legally and operationally.
- Under-specified IT controls: Vague references to “industry-standard security” without detailed architecture documentation, penetration-test results and incident-response plans.
- Incomplete UBO disclosures: Missing or outdated beneficial-ownership information, particularly in multi-layered corporate structures.
- Weak financial projections: Overly optimistic revenue forecasts without stress-testing or adequate capital buffers.
- Underestimated capital needs: Particularly for banking-licence applicants, failing to model the full impact of prudential capital requirements on the business plan.
Remediation priority: address AML and governance gaps first these are the most common grounds for regulator pushback. For firms planning the SRO route, engage VQF early in the process to ensure documentation standards are aligned before formal submission.
Next Steps SRO Membership with VQF and Recommended Practical Actions
For firms for which SRO membership is the appropriate path, the practical workflow is as follows:
- Readiness assessment: Conduct an internal gap analysis against VQF’s membership requirements and AMLA obligations.
- Submit VQF application: Complete the membership application with all supporting documentation (AML manual, compliance officer details, onboarding procedures).
- Implement AML program: Ensure all systems, policies and training are operational before the pre-admission assessment.
- Audit and admission: Cooperate with VQF’s review, address any findings, and secure formal admission.
- Ongoing monitoring: Maintain compliance through regular internal reviews, staff training, and periodic SRO audits.
When to consider switching from SRO to direct FINMA authorisation: if your business grows to include deposit-taking, if aggregate client funds approach regulatory thresholds, or if you launch new product lines (e.g., lending, interest-bearing accounts) that exceed SRO scope, begin the FINMA licence application process proactively ideally 12–18 months before the anticipated trigger event.
Sources