[codicts-css-switcher id=”346″]

Global Law Experts Logo
regulatory licensing fintech financial institutions romania

How to Tackle Regulatory Licensing for Fintech & Financial Institutions in Romania: BNR, VASP & DORA Compliance

By Razvan Alexandru Olaru
– posted 4 weeks ago

FAQs

Do fintech companies need a bank licence in Romania?
Not necessarily. Whether you need a full banking licence, an IFN registration, or a payment-institution or EMI authorisation depends on your specific activity. Lending platforms typically require IFN registration under Legea nr. 93/2009, while payment services and e-money issuance fall under Legea nr. 209/2019, Romania’s PSD2 transposition. Use the business-model decision tree above to identify your route.
No. The national authorisation and registration procedure for virtual-currency exchange and digital-wallet providers, in article 30¹ of Legea nr. 129/2019, was repealed by OUG nr. 10/2025 with effect from 13 March 2025, and it had never become operational in any event. Crypto-asset service providers are now treated as financial institutions and reporting entities under the AML law, supervised by BNR or ASF, with no separate national registration to obtain.
Not at present. ASF has confirmed that no Romanian authority is currently designated as competent under Regulation (EU) 2023/1114, so no application can be filed or decided, and none has been. Authorisation will become possible once national implementing legislation enters into force and names the competent authority. Until then, firms authorise in another member state and passport into Romania.
MiCA’s transitional period under article 143(3) expired. Providers that had operated under prior national law could continue only until that date, or until an authorisation was granted or refused, whichever came first. From 1 July 2026, providing crypto-asset services without MiCA authorisation is unlawful, and the date cannot be extended by any national measure.
Under Regulation (EU) 2022/2554, in-scope financial entities must classify ICT-related incidents according to the criteria in article 18 and report major incidents to their competent supervisory authority within defined timeframes. Firms need incident-classification procedures, pre-formatted reporting templates and internal escalation workflows to meet those deadlines in practice.
Yes. EMIs and payment institutions authorised in another member state may provide services in Romania through freedom of establishment or freedom of services under PSD2, as transposed by Legea nr. 209/2019. The home-state regulator notifies BNR, and the passporting entity must comply with applicable host-state rules, including AML obligations under Romanian law. Nine changes, in descending order of consequence: ONPCSB is no longer described as the VASP registration gate — art. 30¹ repealed by OUG 10/2025 (13 Mar 2025); it had never been operational anyway (the implementing HG was never adopted). ONPCSB reframed as FIU throughout, including in the authority table and the rejection-triggers list. New section: “The MiCA Position in Romania: An Authorisation Gap” — the 1 July 2026 expiry, ASF’s confirmation that it can’t take applications, the political cause, and the three routes out. “The window is closing” → it closed, with art. 143(3) cited. “Both tracks run in parallel” corrected — MiCA replaced the authorisation layer; AML obligations continue in parallel, but there is no parallel registration. The whole “How to register as a VASP” section rewritten as standing AML obligations, plus the OUG 10/2025 single-point-of-contact duty for passporting-in providers (new, and practically useful). AML lineage fixed — Law 129/2019 transposed 4AMLD (2015/849); the virtual-currency provisions came via OUG 111/2020 transposing 5AMLD (2018/843), not the original law. “BNR Regulation No. 4” pinned to no. 4/2019 (payment institutions/AISPs) and no. 5/2019 added for EMIs — your source link was dead, so the sources list now points to BNR’s authorisation index. VASP timeline “2–4 months” deleted; CASP timeline marked unavailable in Romania. Passporting direction corrected — the home-state regulator notifies BNR, not the firm. Title changed from “BNR, VASP & DORA” to “BNR, MiCA & DORA” — the slug still says bnr-vasp-dora, which is fine for SEO continuity but worth mentioning to GLE if they can 301 it.
The most frequent grounds for objection are directors or shareholders failing fit-and-proper assessment; generic AML/KYC policies that do not reflect the applicant’s actual operations; insufficient initial capital or unclear source-of-funds documentation; and weak ICT risk-management frameworks — a gap DORA has made significantly more consequential in the review process.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Tackle Regulatory Licensing for Fintech & Financial Institutions in Romania: BNR, VASP & DORA Compliance

Send welcome message

Custom Message