Romania’s financial-services landscape has shifted dramatically in the space of a few years, and any business entering the market, whether a lending platform, a payment app or a crypto exchange, must now navigate a layered system of regulatory licensing for fintech and financial institutions in Romania that spans national statutes and directly applicable EU regulations. The convergence of the Digital Operational Resilience Act (DORA), the Markets in Crypto-Assets Regulation (MiCA) and ongoing updates to Romania’s AML framework under Legea nr. 129/2019 has created what I consider the most demanding compliance environment this jurisdiction has ever seen.
At Olawru, we advise fintech founders and in-house teams through exactly these licensing processes, and this guide distils the practical decision points, document requirements and timelines that matter most. What follows is a business-model-driven roadmap: who regulates what, which licence fits your activity, and how to prepare a dossier that survives scrutiny.
Before diving into detail, here is the high-level picture for any fintech or financial institution evaluating market entry or product expansion in Romania:
The sections below map each of these regimes to concrete business models, walk through the application dossier, and highlight the enforcement risks I see clients under-estimate most frequently.
Understanding who does what is the first step toward a clean application. Romania’s fintech regulatory architecture distributes supervisory power across several bodies, each with distinct mandates under national and EU law.
| Authority | Primary mandate | Key legal basis |
|---|---|---|
| BNR (Banca Națională a României) | Licensing and prudential supervision of credit institutions, IFNs, payment institutions and EMIs | Legea nr. 93/2009; Legea nr. 209/2019; BNR Regulation No. 4 and related norms |
| ASF (Autoritatea de Supraveghere Financiară) | Capital-markets, insurance and private-pensions supervision (relevant for security-token offerings and certain investment services) | EU prospectus and MiFID II transpositions |
| ONPCSB | AML/CFT supervision, VASP registration, suspicious-transaction reporting oversight | Legea nr. 129/2019 (AML Law) |
| Ministry of Finance | Tax policy, fiscal-compliance framework for financial entities | Fiscal Code / Fiscal Procedure Code |
On top of this national structure sit two directly applicable EU regulations that every fintech must now factor into its licensing plan: DORA, which has been applicable since January 2025, and MiCA, whose full CASP-authorisation provisions have taken effect. In my experience, the most common planning mistake is treating these EU instruments as “future work”, they are live obligations today, and Romanian supervisors are actively integrating them into their review processes.
The answer to “do I need a BNR licence?” depends entirely on what your platform actually does. Below is a business-model decision tree I use when onboarding new clients. Start with your core revenue-generating activity and follow the path.
If your fintech extends credit, consumer loans, peer-to-peer lending, buy-now-pay-later, or invoice financing, you are likely captured by Legea nr. 93/2009 and must register with BNR as a non-bank financial institution (IFN). BNR maintains a special register and imposes prudential requirements including minimum capital thresholds, governance fit-and-proper standards, provisioning rules and ongoing reporting. Depending on the scale and risk profile, IFNs may fall into a general register or be elevated to BNR’s special register with stricter supervision.
If your product facilitates payment transactions, issues e-money or provides account information / payment-initiation services, the governing framework is Legea nr. 209/2019, Romania’s transposition of PSD2. BNR authorises both payment institutions and electronic-money institutions under this law. EMI licence applicants must satisfy initial-capital requirements and demonstrate safeguarding arrangements for customer funds. Passporting is available: an EMI or payment institution authorised in another EU member state may provide services in Romania through freedom-of-establishment or freedom-of-services routes, subject to host-state notification to BNR.
Entities providing services of exchange between virtual currencies and fiat currencies, or custodial wallet services, must register with ONPCSB under Legea nr. 129/2019. This is the current national AML-driven VASP registration regime. In parallel, MiCA now requires firms that wish to offer crypto-asset services across the EU, including operation of a trading platform, brokerage, custody, or advice on crypto assets, to obtain CASP authorisation from the designated national competent authority.
Fintechs that partner with a licensed bank or EMI to offer financial products under the licence-holder’s authorisation do not typically require their own licence. However, the underlying licence-holder remains responsible for compliance, and BNR increasingly scrutinises outsourcing arrangements and agent-network structures. In my view, the practical constraints of BaaS models in Romania are tightening, DORA’s third-party ICT oversight requirements add a further layer of contractual and governance demands that both the fintech and the bank must satisfy.
| Entity type | Licensing authority | Key obligations |
|---|---|---|
| IFN (non-bank lending) | BNR (under Legea nr. 93/2009) | Prudential reporting, governance fit & proper, capital & provisioning, AML reporting |
| EMI / Payment Institution | BNR (per Legea nr. 209/2019, PSD2) | PSD2 requirements, e-money issuance rules, fund safeguarding, passporting, regulatory reporting |
| VASP (pre-MiCA / AML scope) | ONPCSB (AML registry) | AML registration, CDD/KYC, suspicious transaction reporting |
| CASP (under MiCA) | National competent authority (per MiCA) | MiCA authorisation, whitepaper requirements (if issuing tokens), operational & conduct standards |
Regulation (EU) 2022/2554, the Digital Operational Resilience Act, represents a paradigm shift in how financial entities must manage technology risk. If your entity holds any form of regulatory licensing for fintech or financial institution status in Romania (IFN, EMI, PI or, under MiCA, CASP), DORA almost certainly applies to you. In my practice, I find that many fintechs were already applying good ICT hygiene, but DORA requires documented, testable, and board-accountable processes that go beyond ad-hoc best practice.
From what I am seeing in practice, the following items are where Romanian fintechs most frequently need remediation work:
The European Commission has published implementing and delegated acts supplementing DORA’s framework, and additional regulatory technical standards continue to be finalised. I advise clients to treat DORA compliance as a rolling programme rather than a one-off exercise.
Legea nr. 129/2019 is Romania’s primary AML/CFT statute. It transposed the EU’s Fifth Anti-Money Laundering Directive and specifically extended reporting obligations to virtual-asset service providers. Any entity that provides services of exchange between virtual currencies and fiat currencies, or that operates custodial digital-wallet services, falls within the definition of a VASP and must comply with the registration and ongoing obligations set out in this law.
The ONPCSB has issued sectoral guidance setting out expectations for VASP registration. Based on my experience guiding clients through this process, the key steps are:
In my view, the most under-estimated risk in VASP registration is the quality of the AML programme itself. ONPCSB has signalled, through its published sectoral evaluations, that generic, template-driven AML policies are insufficient. Firms must demonstrate risk-based, operationally embedded controls tailored to their specific product flows and customer base.
Whether you are applying for BNR authorisation as an IFN, EMI or payment institution, or assembling a VASP registration package for ONPCSB, the quality and completeness of your dossier is the single biggest determinant of outcome. BNR Regulation No. 4 and its related norms prescribe detailed documentary requirements. Below is a consolidated licensing dossier checklist I use with clients across all major authorisation routes.
In my experience, BNR and ONPCSB most frequently return applications or raise objections for the following reasons:
The authorisation process typically follows a five-stage sequence: pre-application engagement with the regulator, formal dossier submission, completeness review (during which the regulator may request clarifications), substantive assessment, and final decision. In practice, I advise clients to budget the following indicative timeframes:
Cost drivers beyond regulatory fees include initial-capital requirements, local-office establishment, legal and advisory fees for dossier preparation, ICT-resilience remediation, and ongoing compliance-function costs. I always recommend that clients complete a detailed cost-benefit analysis before committing to an authorisation route, sometimes passporting from another EU jurisdiction or partnering under a BaaS model is more efficient.
One of the most common questions I receive is whether MiCA replaces the need for national VASP registration. The short answer is no, at least not yet. MiCA and the national AML framework under Legea nr. 129/2019 address different regulatory objectives and operate in parallel.
MiCA (Regulation (EU) 2023/1114) establishes a harmonised EU-level authorisation framework for crypto-asset service providers. A firm that obtains CASP authorisation under MiCA benefits from an EU passport to offer its services across all member states. However, CASP authorisation covers market-conduct, prudential and consumer-protection requirements, it does not displace national AML/CFT obligations. Romanian VASPs must therefore maintain their ONPCSB registration and continue to comply with CDD, STR and sanctions-screening duties under Legea nr. 129/2019.
For firms currently operating under a national VASP registration, my advice is to begin preparing the MiCA CASP application now. MiCA’s transitional provisions allowed existing providers a grace period, but that window is closing. Firms that delay risk either losing the ability to operate or facing an accelerated application timeline with less room for regulatory dialogue. For those considering launching a crypto exchange, it is now essential to plan for dual compliance from day one.
Romania’s enforcement landscape for fintech and financial institutions has matured considerably. BNR has the power to impose administrative sanctions, withdraw authorisations and require corrective action where prudential or governance requirements are breached. ONPCSB can levy substantial fines for AML non-compliance, including failure to file suspicious-transaction reports or inadequate CDD procedures.
On the sanctions-screening front, Romanian entities are bound by both EU restrictive measures (directly applicable regulations) and national implementing provisions. The obligation to screen customers against EU sanctions lists, freeze assets of designated persons and report any matches is absolute, it applies to IFNs, EMIs, PIs, VASPs and CASPs alike. I have seen cases where otherwise well-run fintechs faced enforcement action simply because their sanctions-screening technology failed to catch name variations or transliterations.
Cross-border risk is amplified for fintechs using passporting or providing services digitally to customers in multiple jurisdictions. Under MiCA, home-state and host-state supervisors share competences, and DORA’s oversight of critical ICT third-party providers operates at EU level through the lead overseer framework. My advice to clients is straightforward: build compliance architecture for the most demanding regime you will face, and you will satisfy the others by default.
The regulatory licensing landscape for fintech and financial institutions in Romania is more structured, and more demanding, than it has ever been. Between BNR authorisation requirements, ONPCSB VASP registration, DORA operational-resilience mandates and MiCA CASP authorisation, founders and compliance teams face a multi-track process that rewards early preparation and penalises gaps in documentation or governance.
In my experience, the firms that navigate this landscape most efficiently are those that begin with a licensing-readiness assessment, map their business model to the correct authorisation route, and assemble their dossier against a detailed checklist before engaging the regulator. At Olawru, we work with clients to compress timelines and pre-empt the objections that cause costly delays. If you are evaluating regulatory licensing for fintech activities in Romania, I would encourage you to start the dossier-preparation process as early as possible, the regulator’s expectations are only moving in one direction.
For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru.
posted 36 minutes ago
posted 2 hours ago
posted 6 hours ago
posted 7 hours ago
posted 7 hours ago
posted 8 hours ago
posted 8 hours ago
posted 9 hours ago
posted 9 hours ago
posted 10 hours ago
posted 12 hours ago
posted 12 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message