Operating a payments business in Central Asia without the right regulatory foundation carries a precise set of risks: enforcement action, suspended fiat rails, and the near-permanent loss of banking relationships that took years to build. The Astana International Financial Centre (AIFC) – a common-law financial enclave inside Kazakhstan – offers a credible, internationally recognized path to a payment institution licence that resolves all three. The Astana Financial Services Authority (AFSA) supervises that regime, and the AIFC's English-law foundations make the resulting authorization legible to correspondent banks, card schemes, and institutional counterparties in a way that a typical CIS registration cannot. This page explains how the licensing process works, where the cross-border complications arise, and what a business needs to decide before filing.
What Is the AIFC Payment Institution Regime – and Who Does It Cover?
A payment institution licence issued by the AFSA authorizes a company to provide payment services, including account issuance, payment execution, money remittance, and – subject to the relevant rulebook provisions – services connected to digital payment tokens. The AIFC operates as a standalone jurisdiction within Kazakhstan: it applies English-law common-law principles, has its own courts, and publishes its regulations in English. The AFSA, as the prudential and conduct regulator within that zone, administers the licensing regime for payment institutions and digital-asset-related service providers under the same framework.
The practical reach of an AIFC payment institution licence is broader than a purely domestic Kazakhstani authorization. Because the AIFC is designed as a cross-border financial hub – connecting the Eurasian Economic Union zone with the Gulf and with Central and East Asian markets – its authorizations carry weight in onboarding discussions with regional and international banks. In our practice, we regularly advise businesses selecting the AIFC precisely because correspondent banks in the UAE, Singapore, and the UK treat AFSA-regulated status as a meaningful compliance marker, in a way they do not treat generic offshore registrations.
The licence does not, however, constitute a passport into the EU in the manner of a MiCA CASP authorization or an EEA-passportable EMI licence. A business serving EU customers at scale must layer the AIFC licence with an EU-facing structure. That cross-border reality is not a defect in the regime – it is the planning context every operator must address before committing to the AIFC as a single structural home.
The AFSA administers payment institution licensing within the AIFC under its own rulebook, which draws on English-law payment services concepts. The regulated activities include issuance of payment instruments, execution of payment transactions, and money remittance services – covering both fiat and, in the digital-asset context, stablecoin-adjacent payment flows.
For a contact assessment of whether the AIFC payment institution route fits your entity and user geography, write to OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis.
How Does the AIFC Compare for Digital-Asset Payment Flows?
For a business that combines fiat payment rails with digital-asset settlement, the AIFC offers a structural advantage: AFSA regulates both payment services and digital-asset trading and custody activities under the same legal perimeter. A company can hold a payment institution licence alongside a digital asset trading facility or custody authorization, creating a consolidated regulated stack in one common-law jurisdiction rather than maintaining separate registrations across multiple regimes.
Compare that with the EU approach: under MiCA, a CASP authorization covers crypto-asset services but payment services – particularly for electronic money tokens (EMTs, stablecoins denominated in a single fiat currency) – require separate EMI authorization under the EU's e-money rules. A MiCA CASP that wants to issue an EMT must also be authorized as an EMI. The AIFC's consolidated framework avoids that structural split for operators whose primary market is not the EU.
Against Singapore's MAS Payment Services Act, the AIFC competes credibly on timeline and initial cost of compliance, though MAS authorization remains the stronger signal for Southeast Asian banking relationships. Against the FCA's UK regime – which requires cryptoasset registration under the Money Laundering Regulations and a separate payment institution authorization – the AIFC again offers consolidation, but without the FCA's established correspondent-banking network.
The honest comparative answer: the AIFC works well as a primary licensing base for operators whose user geography spans the Eurasian, Gulf, and Central Asian markets, and as a complement to an EU or UK licence for operators seeking a lower-cost regulated entity for non-EU payment flows. It does not substitute for MAS authorization if Singapore or Southeast Asia is the core market, and it does not substitute for MiCA passporting if EU retail volumes are material.
We regularly advise clients who present the AIFC as a single global solution. The analysis almost always reveals that a second licence – or at minimum a legal opinion on the jurisdictional reach of the AIFC authorization – is necessary before live operations begin.
What Does the AIFC Application Process Require?
The AFSA application for a payment institution licence requires the business to demonstrate legal substance, governance readiness, and a compliance program proportionate to the regulated activities sought. The process runs in structured stages, and the quality of pre-application preparation directly affects timeline.
At the formation stage, the applicant must establish a company in the AIFC. The AIFC operates its own company registry; incorporation is a prerequisite, not a parallel step. The company must have a registered office in Nur-Sultan (Astana) and, depending on the licence category, a qualified head of compliance and a money-laundering reporting officer who meet the AFSA's fitness-and-propriety criteria.
The regulatory business plan is the core document. It must describe the payment services to be offered, the customer types, the transaction volumes projected, the AML/CFT program, the IT and operational arrangements, and the outsourcing structure if any payment-processing functions are contracted to third parties. The AFSA conducts a substantive review – not a tick-box registration – and routinely asks clarification questions during the assessment period.
A fit-and-proper assessment runs in parallel for each controller, beneficial owner holding above the applicable threshold, and each approved person. The AFSA's vetting standard draws on the same principles as the FCA and MAS: criminal-record checks, financial soundness, professional competence, and absence of regulatory censure in any other jurisdiction.
The application dossier typically includes incorporation documents, a detailed regulatory business plan, a financial model, AML/CFT policies, IT security documentation, and personal declarations for all controllers and approved persons. Missing or underprepared documents extend the timeline; the AFSA will pause its assessment clock until information requests are satisfied.
Timeline is qualitative by regulatory design – the AFSA does not publish a guaranteed determination period – but applications with complete, well-structured dossiers tend to move through assessment in a matter of weeks to a few months. Applications that arrive incomplete, or where the compliance framework requires rebuilding during review, extend materially beyond that range. Pre-application engagement with the AFSA – which the regulator actively encourages – compresses the formal review period by surfacing structural issues before the application is filed.
What Are the AML and Travel Rule Obligations at the AIFC?
The AIFC's AML/CFT framework is built on the FATF Recommendations, including FATF Recommendation 15, which extends the standard AML obligations to virtual asset service providers. Payment institutions licensed by the AFSA are required to implement know-your-customer controls, transaction monitoring, suspicious transaction reporting, and record-keeping obligations consistent with the FATF baseline.
The Travel Rule – the obligation to pass originator and beneficiary identification data with each qualifying transfer – applies within the AIFC regime to the extent required under AFSA rules, which track the FATF standard. The specific threshold above which the Travel Rule data obligation attaches varies by jurisdiction and is subject to ongoing FATF guidance updates; operators must confirm the current AFSA position at the time of application rather than rely on a figure stated in any secondary source.
For a payment institution that also handles digital-asset transfers, the operational implication is significant. The business needs a Travel Rule solution – whether an industry protocol or a bilateral data-sharing arrangement with counterparty VASPs – before it can process qualifying transfers in compliance. Many applicants underestimate the technical and commercial effort of achieving Travel Rule compliance and discover mid-application that their planned product requires re-architecture. We have seen this issue delay go-live by a quarter or more when it is not addressed in the initial planning phase.
The AFSA also expects enhanced due diligence on customers in higher-risk geographies, on politically exposed persons, and on accounts presenting unusual transaction patterns. The compliance program must be documented, tested, and reviewed at intervals – not a static policy set filed once and ignored.
How Does Banking and Fiat Rail Onboarding Work After the AIFC Licence?
A payment institution licence from the AFSA establishes the regulatory status the business needs – but it does not automatically open a bank account. Banking onboarding is a separate commercial process, and for crypto-adjacent payment institutions, it remains the longest and least predictable element of the overall build.
The practical dynamic: a bank's financial-crime compliance team will review the AIFC licence, the regulatory business plan filed with the AFSA, the AML/CFT documentation, the customer profile, and the transaction flow. AFSA regulation is a positive signal in this review. It is not sufficient on its own. Banks in Kazakhstan, the UAE, Singapore, and the UK – all common banking targets for AIFC-licensed entities – each apply their own proprietary due-diligence frameworks, and approval is never guaranteed at any institution.
The accounts an AIFC payment institution typically needs include: a safeguarding account for customer funds, an operational account for the business's own funds, and – if the product involves foreign-currency settlement – accounts in the relevant currency pairs. Segregation between client money and firm money is a regulatory requirement, not optional practice: the AFSA's safeguarding expectations track the standard model applied in the UK and EU.
For digital-asset businesses, the cross-border banking challenge is compounded by the need for fiat rails (the correspondent banking connections that move money between the payment institution and its customers and counterparties). An EMI relationship – where the payment institution either holds an EMI licence directly or processes through an authorized electronic money institution – is one structural solution. In our practice, we advise on the routing of fiat flows through regulated payment infrastructure before any account applications are submitted, because the sequence matters: applying to a bank before the product architecture and compliance documentation are final is one of the most common and costly mistakes operators make.
If prior account applications have stalled or banking relationships have been closed, a structural review can identify the root cause and the most viable route to a compliant banking stack. Write to info@oboluslaw.com to discuss your situation.
What Are the Tax and Cross-Border Structuring Considerations?
The AIFC operates a preferential tax regime for entities incorporated and operating within its perimeter. The applicable tax treatment – including the scope of any corporate income tax exemption, the VAT position, and the withholding tax obligations on outbound payments – is a function of the AIFC's founding legislation and the specific activities of the entity. These rules should be confirmed with qualified tax counsel at the time of structuring, as the interaction between AIFC tax preferences and Kazakhstan's general tax code, and the entity's treaty position with other jurisdictions, varies by facts.
From a cross-border structuring standpoint, a common architecture pairs an AIFC payment institution with a holding company in a jurisdiction that has a broad treaty network – the UAE, Singapore, or an EU member state being the most common. The AIFC entity handles the regulated payment function; the holding entity manages IP, treasury, and investor relationships. This split has tax, substance, and regulatory implications in all three layers and must be designed as a whole rather than assembled incrementally.
Token issuers or stablecoin operators using the AIFC for payment infrastructure must also consider the classification of their token under both the AIFC framework and the laws of every jurisdiction where they issue or redeem. A token that functions as an e-money token under MiCA may trigger EMI authorization requirements in the EU even if the AIFC entity holds it as a payment instrument. The principle that a substance-based classification of the token's rights governs – rather than the label used in marketing – applies across every regime.
Kazakhstan's general corporate tax environment, its double-tax treaty network, and the AIFC's specific preferences make the jurisdiction genuinely competitive on a cost basis. The analysis is jurisdiction-specific and fact-sensitive; a general statement that "Kazakhstan is a low-tax location" is less useful than a modeled comparison of effective rates across the structure's layers.
What Common Mistakes Do Payment Institution Applicants Make at the AIFC?
The most consistent error we see is treating the AIFC licence as a self-contained solution. It is not. The licence resolves the regulatory status question for the AIFC perimeter. It does not resolve the banking question, the user-jurisdiction question, or the token-classification question for markets outside Kazakhstan. Operators who treat the AIFC authorization as the finish line – and begin onboarding customers before the banking, compliance, and legal-opinion stack is complete – expose themselves to the precise operational and enforcement risk the licence was meant to eliminate.
The second common error is underpreparing the regulatory business plan. The AFSA conducts a substantive review. A plan that describes intended activities in vague terms, that lacks a realistic financial model, or that proposes a compliance program the applicant cannot actually staff or operate will generate a sustained round of information requests. Every information request adds time. Applications that arrive with a professional, detailed dossier close faster.
The third error is ignoring the cross-border reach problem. A single AIFC licence is not sufficient to serve clients globally. A business with EU customers at material scale needs a MiCA CASP or EMI authorization. A business serving UK retail needs FCA registration. A business whose users are primarily in Southeast Asia needs to assess MAS requirements. The AIFC licence does not substitute for those authorizations, and marketing regulated products to users in those jurisdictions without the local authorization carries enforcement risk in the user's home market – regardless of what the AIFC licence says.
In a recent matter, a payments company incorporated in the AIFC had built a functioning product and an established user base before discovering that a segment of its users triggered regulatory obligations in another major hub. We worked through a remediation path that involved a parallel licensing application in the second jurisdiction, a phased suspension of certain user categories pending authorization, and a revised AML program across both entities. The timeline and cost of remediation far exceeded what the initial planning exercise would have cost. Early structural analysis almost always pays.
Decision Profile: Which Operators Should Choose the AIFC?
The AIFC payment institution licence is a strong primary choice for a defined set of operator profiles. It is a poor choice – or at best a complement, not a substitute – for others.
Profile A – Eurasian or Gulf-focused payments operator: A business whose core market is Central Asia, the Eurasian Economic Union zone, or the Gulf Cooperation Council region, and whose institutional counterparties are banks in those regions, is well-positioned to use the AIFC as its primary licensed entity. The AFSA's authorization carries recognized weight in banking onboarding discussions within those corridors, the common-law legal framework is accessible to international counsel and counterparties, and the AIFC's consolidated digital-asset and payment services regime avoids the split-authorization complexity of the EU approach. Timeline from application to authorization is qualitative but can be measured in months for a well-prepared applicant.
Profile B – Global operator seeking a second licensed entity: A business already holding a MiCA CASP or MAS authorization that wants a lower-cost regulated entity for non-EU, non-Singapore payment flows can use an AIFC payment institution as an efficient second structure. The AIFC entity handles regional payment routing; the primary licence handles the core market. Key risk: the cross-border compliance and banking coordination between two licensed entities adds operational overhead that must be managed actively.
Profile C – Early-stage company not yet ready for MiCA or MAS: A startup that needs regulatory status to open banking discussions but is not yet ready for the cost and complexity of a full MiCA or MAS application may use the AIFC as a first regulated step. This is viable – with the important caveat that the AIFC licence does not create a credible basis for serving EU or Singapore retail customers without the additional authorizations those markets require. The AIFC route should not become a permanent workaround for jurisdictions the business cannot yet afford to license in directly.
Profile D – EU retail-focused crypto operator: For this profile, the AIFC is not the primary answer. A MiCA CASP or an EMI authorization in an EU member state is the right instrument. The AIFC may complement that structure as a non-EU entity in the group, but building the EU user-facing product on an AIFC licence creates regulatory exposure in every EU member state where users are located.
The decision matrix is not a checklist – it is a facts-to-structure mapping exercise. We map the licence, banking, and tax stack for each operator profile before recommending a path.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for digital-asset businesses – how we structure payment licensing and banking access across jurisdictions
- Electronic money institution (EMI) – a legal guide for digital-asset businesses – what an EMI licence covers, who needs one, and how it interacts with crypto operations
- Crypto exchange setup in Lithuania – the EU alternative: CASP authorization in a Baltic hub with MiCA passporting
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of financial-crime compliance risk appetite – the combination of transaction monitoring complexity, high exposure to money-laundering and sanctions risk, and the reputational consequences of a regulatory finding. Accounts tied to unregistered or inadequately documented crypto businesses are the most vulnerable. An AFSA payment institution licence, a credible AML program, and clear documentation of the client profile are the structural elements that convert a bank's reflex decline into an onboarding approval. Regulatory status does not guarantee an account; it is the prerequisite for a substantive conversation.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) onboards with an EMI (electronic money institution) by demonstrating that its AML/CFT controls, corporate structure, and transaction profile meet the EMI's risk-acceptance criteria. In practice, this means providing regulated status documentation, a detailed compliance program, and transaction-flow data that allows the EMI to model its own exposure. VASPs with AFSA or AFSA-adjacent regulatory status have a clearer onboarding path than unregistered operators. The process is commercial and bilateral; there is no automatic right of access.
What does client-money safeguarding require?
Client-money safeguarding requires a payment institution to hold customer funds in a designated account – segregated from the firm's own funds – at a qualifying credit institution or through an insurance or guarantee arrangement approved under the applicable rulebook. The AFSA's safeguarding framework tracks the model applied in the UK and EU: the firm must maintain daily reconciliations, keep records that allow customer balances to be identified at any time, and ensure that safeguarded funds are not exposed to the firm's own insolvency. Failure to maintain segregation is among the most common causes of enforcement action against payment institutions in any leading regime.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and payment institutions on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance that sit around them. Digital assets are the entirety of our practice. We map the licence, banking, and tax stack across the operating, custody, and payment layers before you commit – so structural errors surface before they cost you banking access or a regulatory finding. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory and Compliance Analyst – specialises in cross-border payment institution licensing and AFSA/AIFC regulatory frameworks for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.