[codicts-css-switcher id=”346″]

Global Law Experts Logo
regulatory licensing fintech financial institutions romania

How to Tackle Regulatory Licensing for Fintech & Financial Institutions in Romania: BNR, VASP & DORA Compliance

By Razvan Alexandru Olaru
– posted 1 hour ago

Romania’s financial-services landscape has shifted dramatically in the space of a few years, and any business entering the market, whether a lending platform, a payment app or a crypto exchange, must now navigate a layered system of regulatory licensing for fintech and financial institutions in Romania that spans national statutes and directly applicable EU regulations. The convergence of the Digital Operational Resilience Act (DORA), the Markets in Crypto-Assets Regulation (MiCA) and ongoing updates to Romania’s AML framework under Legea nr. 129/2019 has created what I consider the most demanding compliance environment this jurisdiction has ever seen.

At Olawru, we advise fintech founders and in-house teams through exactly these licensing processes, and this guide distils the practical decision points, document requirements and timelines that matter most. What follows is a business-model-driven roadmap: who regulates what, which licence fits your activity, and how to prepare a dossier that survives scrutiny.

Executive Summary, What You Need to Know

Before diving into detail, here is the high-level picture for any fintech or financial institution evaluating market entry or product expansion in Romania:

  • Banca Națională a României (BNR) is the primary licensing authority for non-bank financial institutions (IFNs under Legea nr. 93/2009), payment institutions and electronic-money institutions (EMIs under Legea nr. 209/2019, Romania’s PSD2 transposition).
  • ONPCSB (the National Office for the Prevention and Control of Money Laundering) holds the registration gate for virtual-asset service providers (VASPs) under Legea nr. 129/2019 and its subsequent amendments.
  • DORA (Regulation (EU) 2022/2554) imposes ICT risk-management, incident-reporting and third-party oversight obligations on most regulated financial entities, and it applies directly in Romania.
  • MiCA (Regulation (EU) 2023/1114) introduces a harmonised EU-level authorisation route for crypto-asset service providers (CASPs), but it does not replace national AML registration. Both tracks run in parallel.

The sections below map each of these regimes to concrete business models, walk through the application dossier, and highlight the enforcement risks I see clients under-estimate most frequently.

How Romania’s Regulatory Architecture Is Organised

Understanding who does what is the first step toward a clean application. Romania’s fintech regulatory architecture distributes supervisory power across several bodies, each with distinct mandates under national and EU law.

Authority Primary mandate Key legal basis
BNR (Banca Națională a României) Licensing and prudential supervision of credit institutions, IFNs, payment institutions and EMIs Legea nr. 93/2009; Legea nr. 209/2019; BNR Regulation No. 4 and related norms
ASF (Autoritatea de Supraveghere Financiară) Capital-markets, insurance and private-pensions supervision (relevant for security-token offerings and certain investment services) EU prospectus and MiFID II transpositions
ONPCSB AML/CFT supervision, VASP registration, suspicious-transaction reporting oversight Legea nr. 129/2019 (AML Law)
Ministry of Finance Tax policy, fiscal-compliance framework for financial entities Fiscal Code / Fiscal Procedure Code

On top of this national structure sit two directly applicable EU regulations that every fintech must now factor into its licensing plan: DORA, which has been applicable since January 2025, and MiCA, whose full CASP-authorisation provisions have taken effect. In my experience, the most common planning mistake is treating these EU instruments as “future work”, they are live obligations today, and Romanian supervisors are actively integrating them into their review processes.

Regulatory Licensing by Business Model in Romania: A Decision Tree

The answer to “do I need a BNR licence?” depends entirely on what your platform actually does. Below is a business-model decision tree I use when onboarding new clients. Start with your core revenue-generating activity and follow the path.

Lending platforms, IFN (Instituție Financiară Nebancară)

If your fintech extends credit, consumer loans, peer-to-peer lending, buy-now-pay-later, or invoice financing, you are likely captured by Legea nr. 93/2009 and must register with BNR as a non-bank financial institution (IFN). BNR maintains a special register and imposes prudential requirements including minimum capital thresholds, governance fit-and-proper standards, provisioning rules and ongoing reporting. Depending on the scale and risk profile, IFNs may fall into a general register or be elevated to BNR’s special register with stricter supervision.

Payment services & e-money, PI / EMI

If your product facilitates payment transactions, issues e-money or provides account information / payment-initiation services, the governing framework is Legea nr. 209/2019, Romania’s transposition of PSD2. BNR authorises both payment institutions and electronic-money institutions under this law. EMI licence applicants must satisfy initial-capital requirements and demonstrate safeguarding arrangements for customer funds. Passporting is available: an EMI or payment institution authorised in another EU member state may provide services in Romania through freedom-of-establishment or freedom-of-services routes, subject to host-state notification to BNR.

Crypto-asset activities, VASP registration and MiCA CASP authorisation

Entities providing services of exchange between virtual currencies and fiat currencies, or custodial wallet services, must register with ONPCSB under Legea nr. 129/2019. This is the current national AML-driven VASP registration regime. In parallel, MiCA now requires firms that wish to offer crypto-asset services across the EU, including operation of a trading platform, brokerage, custody, or advice on crypto assets, to obtain CASP authorisation from the designated national competent authority.

Banking-as-a-Service (BaaS) and agent models

Fintechs that partner with a licensed bank or EMI to offer financial products under the licence-holder’s authorisation do not typically require their own licence. However, the underlying licence-holder remains responsible for compliance, and BNR increasingly scrutinises outsourcing arrangements and agent-network structures. In my view, the practical constraints of BaaS models in Romania are tightening, DORA’s third-party ICT oversight requirements add a further layer of contractual and governance demands that both the fintech and the bank must satisfy.

Comparison table: authorisation routes at a glance

Entity type Licensing authority Key obligations
IFN (non-bank lending) BNR (under Legea nr. 93/2009) Prudential reporting, governance fit & proper, capital & provisioning, AML reporting
EMI / Payment Institution BNR (per Legea nr. 209/2019, PSD2) PSD2 requirements, e-money issuance rules, fund safeguarding, passporting, regulatory reporting
VASP (pre-MiCA / AML scope) ONPCSB (AML registry) AML registration, CDD/KYC, suspicious transaction reporting
CASP (under MiCA) National competent authority (per MiCA) MiCA authorisation, whitepaper requirements (if issuing tokens), operational & conduct standards

DORA Compliance: What Romanian Fintechs Must Do

Regulation (EU) 2022/2554, the Digital Operational Resilience Act, represents a paradigm shift in how financial entities must manage technology risk. If your entity holds any form of regulatory licensing for fintech or financial institution status in Romania (IFN, EMI, PI or, under MiCA, CASP), DORA almost certainly applies to you. In my practice, I find that many fintechs were already applying good ICT hygiene, but DORA requires documented, testable, and board-accountable processes that go beyond ad-hoc best practice.

Core DORA obligations

  • ICT risk-management framework. Entities must implement a comprehensive, documented framework covering identification, protection, detection, response and recovery. This must be approved and overseen at board level.
  • ICT incident reporting. Major ICT-related incidents must be classified according to DORA’s criteria and reported to the competent supervisory authority within prescribed timeframes. Firms should map their internal incident taxonomy to DORA’s classification and maintain reporting templates ready for activation.
  • Digital operational resilience testing. In-scope entities must conduct regular testing, including, for significant institutions, threat-led penetration testing (TLPT), to validate their resilience posture.
  • Third-party ICT risk management. Contracts with ICT service providers (cloud, SaaS, infrastructure) must include specific provisions on access, audit, data location, sub-outsourcing, exit strategies and business-continuity commitments. For an in-depth analysis of what constitutes an ICT service under DORA, I recommend reviewing the regulatory technical standards issued by the European Supervisory Authorities.
  • Information sharing. DORA encourages (and in certain cases mandates) participation in cyber-threat intelligence-sharing arrangements.

DORA readiness checklist

From what I am seeing in practice, the following items are where Romanian fintechs most frequently need remediation work:

  • Board-approved ICT risk-management policy with named responsible officer
  • Incident classification and reporting procedure aligned to DORA Article 18 criteria
  • Register of all ICT third-party arrangements, including risk assessment and contractual gap analysis
  • Annual testing programme (penetration tests, vulnerability assessments, scenario-based exercises)
  • Business-continuity and disaster-recovery plans with documented RTO/RPO targets
  • Exit strategy documentation for critical ICT service providers

The European Commission has published implementing and delegated acts supplementing DORA’s framework, and additional regulatory technical standards continue to be finalised. I advise clients to treat DORA compliance as a rolling programme rather than a one-off exercise.

AML, VASP Registration and KYC Obligations in Romania

Legea nr. 129/2019 is Romania’s primary AML/CFT statute. It transposed the EU’s Fifth Anti-Money Laundering Directive and specifically extended reporting obligations to virtual-asset service providers. Any entity that provides services of exchange between virtual currencies and fiat currencies, or that operates custodial digital-wallet services, falls within the definition of a VASP and must comply with the registration and ongoing obligations set out in this law.

How to register as a VASP in Romania

The ONPCSB has issued sectoral guidance setting out expectations for VASP registration. Based on my experience guiding clients through this process, the key steps are:

  1. Preliminary self-assessment. Confirm that your activity falls within the VASP definition under Legea nr. 129/2019. Map your product features to the categories of virtual-currency exchange or custodial wallet services.
  2. Prepare AML/KYC programme. Draft and adopt internal policies covering customer due diligence (CDD), enhanced due diligence (EDD) for high-risk clients, suspicious-transaction identification and reporting, record-keeping, and employee training.
  3. Appoint a compliance officer. Designate a person responsible for AML compliance with appropriate seniority and direct board-reporting access.
  4. Notify ONPCSB. Submit the registration notification together with company documentation, beneficial-ownership declarations, the AML programme, and evidence of fit-and-proper assessments for management.
  5. Ongoing obligations. Once registered, maintain continuous CDD monitoring, file suspicious-transaction reports (STRs) with ONPCSB, apply sanctions screening, and update policies as regulatory expectations evolve.

In my view, the most under-estimated risk in VASP registration is the quality of the AML programme itself. ONPCSB has signalled, through its published sectoral evaluations, that generic, template-driven AML policies are insufficient. Firms must demonstrate risk-based, operationally embedded controls tailored to their specific product flows and customer base.

Practical Dossier and Submission Checklist

Whether you are applying for BNR authorisation as an IFN, EMI or payment institution, or assembling a VASP registration package for ONPCSB, the quality and completeness of your dossier is the single biggest determinant of outcome. BNR Regulation No. 4 and its related norms prescribe detailed documentary requirements. Below is a consolidated licensing dossier checklist I use with clients across all major authorisation routes.

Core dossier items

  • Company formation documents. Articles of incorporation, trade-register extract, shareholder register, beneficial-ownership declarations.
  • Business plan. Three-to-five-year financial projections, description of target market, product architecture, revenue model, customer-acquisition strategy and risk appetite statement.
  • Governance and organisational structure. Organisational chart, job descriptions for key function holders, board and committee charters, internal-control framework.
  • Fit-and-proper documentation. CVs, criminal-record certificates, declarations of interest, professional-reference letters and evidence of relevant experience for all directors, senior managers and qualifying shareholders.
  • Capital adequacy. Evidence of paid-up initial capital meeting the applicable statutory minimum; bank confirmation letter; source-of-funds declarations.
  • AML/KYC policies. Full AML programme (CDD, EDD, PEP screening, sanctions screening, STR procedures, record-keeping, training calendar), risk assessment matrix and compliance-officer appointment letter.
  • ICT and operational-resilience policies. ICT risk-management framework, incident-response plan, business-continuity and disaster-recovery plan, third-party ICT register, all aligned to DORA requirements where the applicant is an in-scope entity.
  • Outsourcing and agent agreements. Copies of material outsourcing contracts, agent-appointment agreements, cloud-service agreements with DORA-compliant provisions.
  • Audited financial statements. Where applicable (existing entities), the most recent audited annual accounts and, if available, interim management accounts.
  • Safeguarding arrangements. For EMI/PI applicants, evidence of client-fund segregation methodology (trust accounts, insurance or guarantee arrangements).

Common rejection triggers

In my experience, BNR and ONPCSB most frequently return applications or raise objections for the following reasons:

  • Incomplete or generic AML/KYC policies that do not reflect the applicant’s actual product flows
  • Directors or shareholders who fail fit-and-proper checks (criminal history, regulatory sanctions, undisclosed conflicts)
  • Insufficient initial capital or unclear source-of-funds documentation
  • Weak or absent ICT risk-management documentation, a gap that DORA has made even more consequential
  • Missing or poorly structured outsourcing agreements that lack audit rights, data-location clauses or exit provisions

Sample timeline and typical fees

The authorisation process typically follows a five-stage sequence: pre-application engagement with the regulator, formal dossier submission, completeness review (during which the regulator may request clarifications), substantive assessment, and final decision. In practice, I advise clients to budget the following indicative timeframes:

  • IFN registration (BNR): approximately 3–6 months from a complete submission.
  • EMI / PI authorisation (BNR): approximately 6–9 months, depending on dossier complexity and regulator queries.
  • VASP registration (ONPCSB): typically faster, 2–4 months, but increasingly subject to deeper review as ONPCSB builds sectoral experience.
  • CASP authorisation (MiCA): timeframes are still stabilising as national competent authorities operationalise MiCA processes; firms should plan for at least 6–12 months.

Cost drivers beyond regulatory fees include initial-capital requirements, local-office establishment, legal and advisory fees for dossier preparation, ICT-resilience remediation, and ongoing compliance-function costs. I always recommend that clients complete a detailed cost-benefit analysis before committing to an authorisation route, sometimes passporting from another EU jurisdiction or partnering under a BaaS model is more efficient.

Interaction Between MiCA and National Requirements for Crypto Businesses

One of the most common questions I receive is whether MiCA replaces the need for national VASP registration. The short answer is no, at least not yet. MiCA and the national AML framework under Legea nr. 129/2019 address different regulatory objectives and operate in parallel.

MiCA (Regulation (EU) 2023/1114) establishes a harmonised EU-level authorisation framework for crypto-asset service providers. A firm that obtains CASP authorisation under MiCA benefits from an EU passport to offer its services across all member states. However, CASP authorisation covers market-conduct, prudential and consumer-protection requirements, it does not displace national AML/CFT obligations. Romanian VASPs must therefore maintain their ONPCSB registration and continue to comply with CDD, STR and sanctions-screening duties under Legea nr. 129/2019.

For firms currently operating under a national VASP registration, my advice is to begin preparing the MiCA CASP application now. MiCA’s transitional provisions allowed existing providers a grace period, but that window is closing. Firms that delay risk either losing the ability to operate or facing an accelerated application timeline with less room for regulatory dialogue. For those considering launching a crypto exchange, it is now essential to plan for dual compliance from day one.

Enforcement, Sanctions and Cross-Border Risk

Romania’s enforcement landscape for fintech and financial institutions has matured considerably. BNR has the power to impose administrative sanctions, withdraw authorisations and require corrective action where prudential or governance requirements are breached. ONPCSB can levy substantial fines for AML non-compliance, including failure to file suspicious-transaction reports or inadequate CDD procedures.

On the sanctions-screening front, Romanian entities are bound by both EU restrictive measures (directly applicable regulations) and national implementing provisions. The obligation to screen customers against EU sanctions lists, freeze assets of designated persons and report any matches is absolute, it applies to IFNs, EMIs, PIs, VASPs and CASPs alike. I have seen cases where otherwise well-run fintechs faced enforcement action simply because their sanctions-screening technology failed to catch name variations or transliterations.

Cross-border risk is amplified for fintechs using passporting or providing services digitally to customers in multiple jurisdictions. Under MiCA, home-state and host-state supervisors share competences, and DORA’s oversight of critical ICT third-party providers operates at EU level through the lead overseer framework. My advice to clients is straightforward: build compliance architecture for the most demanding regime you will face, and you will satisfy the others by default.

Conclusion and Recommended Next Steps

The regulatory licensing landscape for fintech and financial institutions in Romania is more structured, and more demanding, than it has ever been. Between BNR authorisation requirements, ONPCSB VASP registration, DORA operational-resilience mandates and MiCA CASP authorisation, founders and compliance teams face a multi-track process that rewards early preparation and penalises gaps in documentation or governance.

In my experience, the firms that navigate this landscape most efficiently are those that begin with a licensing-readiness assessment, map their business model to the correct authorisation route, and assemble their dossier against a detailed checklist before engaging the regulator. At Olawru, we work with clients to compress timelines and pre-empt the objections that cause costly delays. If you are evaluating regulatory licensing for fintech activities in Romania, I would encourage you to start the dossier-preparation process as early as possible, the regulator’s expectations are only moving in one direction.

Need Legal Advice?

For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru.

Sources

  1. Banca Națională a României, BNR Regulation No. 4 (English)
  2. Legea nr. 93/2009, Portal Legislativ
  3. Legea nr. 209/2019, Portal Legislativ
  4. Legea nr. 129/2019, Portal Legislativ
  5. ONPCSB, VASP Sectoral Evaluation Guidance
  6. Regulation (EU) 2022/2554 (DORA), EUR-Lex
  7. Regulation (EU) 2023/1114 (MiCA), EUR-Lex
  8. European Commission, DORA Implementation

FAQs

Do fintech companies need a bank licence in Romania?
Not necessarily. Whether you need a full banking licence, an IFN registration, or a payment-institution/EMI authorisation depends on your specific activity. Lending platforms typically require IFN registration under Legea nr. 93/2009, while payment services and e-money issuance fall under Legea nr. 209/2019 (PSD2 transposition). Use the business-model decision tree above to identify your correct route.
VASPs must comply with Legea nr. 129/2019 (Romania’s AML Law) and register with the National Office for the Prevention and Control of Money Laundering (ONPCSB). The process requires submitting company documentation, beneficial-ownership declarations, a tailored AML/KYC programme, and evidence of fit-and-proper management. ONPCSB’s sectoral guidance provides detailed expectations for the registration dossier.
Under Regulation (EU) 2022/2554, in-scope financial entities must classify ICT-related incidents according to DORA’s prescribed criteria and report major incidents to their competent supervisory authority within defined timeframes. Firms must maintain incident-classification procedures, pre-formatted reporting templates and internal escalation workflows to ensure timely compliance.
No. MiCA introduces EU-level authorisation for crypto-asset service providers (CASPs) covering market-conduct and prudential standards. However, national AML obligations, including VASP registration with ONPCSB under Legea nr. 129/2019, customer due diligence and suspicious-transaction reporting, continue to apply in parallel. Firms must plan for both regulatory tracks.
In my experience, the most frequent grounds for objection or rejection include: directors or shareholders failing fit-and-proper assessments; generic AML/KYC policies that do not reflect the applicant’s actual operations; insufficient initial capital or unclear source-of-funds documentation; and weak ICT risk-management frameworks, a gap that DORA has made significantly more consequential in the review process.
Yes. EMIs and payment institutions authorised in another EU member state may provide services in Romania through freedom-of-establishment or freedom-of-services passporting under PSD2 (transposed by Legea nr. 209/2019). However, the home-state regulator must notify BNR, and the passporting entity must comply with applicable host-state rules, including AML obligations under Romanian law.
negotiate saas agreement under romanian law
By Razvan Alexandru Olaru

posted 7 hours ago

prepare dora ict outsourcing review romania
By Razvan Alexandru Olaru

posted 8 hours ago

saas customer refusing pay after platform
By Awatif Al Khouri

posted 9 hours ago

company formation oman
By Jonathon Richards

posted 10 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Tackle Regulatory Licensing for Fintech & Financial Institutions in Romania: BNR, VASP & DORA Compliance

Send welcome message

Custom Message