EST · MMXXVI
Home/Jurisdictions/Switzerland/AML and travel rule regime in Switzerland
Compliance, AML & Travel Rule

AML and travel rule regime in Switzerland

Aml and travel rule regime in Switzerland. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Switzerland operates one of the most demanding AML and Travel Rule regimes in digital-asset regulation. Under the Anti-Money Laundering Act (AMLA) and the oversight of FINMA (the Swiss Financial Market Supervisory Authority), every financial intermediary handling digital assets must satisfy ongoing due-diligence, transaction-monitoring and data-transfer obligations. For an inbound crypto business, the question is not whether these rules apply – they do – but whether the firm is structured correctly to meet them before the first client account is opened.

Switzerland's regulatory architecture predates the current wave of global crypto supervision. FINMA published its first ICO guidance in 2018 and has since developed a detailed token taxonomy distinguishing payment, utility and asset tokens. That taxonomy determines which AML obligations attach, which licence route is required, and how the Travel Rule – the obligation to pass originator and beneficiary data with every qualifying transfer – interacts with the firm's operational stack. Getting the classification right at the outset is the single most consequential step in Swiss compliance planning.

This page maps the Swiss AML and Travel Rule regime for operators entering or already active in Switzerland, with particular attention to the cross-border interactions that create the most enforcement exposure.

The Swiss AML Architecture for Digital-Asset Businesses

Swiss AML obligations for digital-asset businesses flow primarily from AMLA and its implementing ordinances, administered by FINMA and by self-regulatory organizations (SROs) that FINMA recognizes as supervisory bodies. A crypto firm that qualifies as a financial intermediary under Swiss law must either affiliate with a recognized SRO or obtain direct FINMA supervision. Both paths impose equivalent substantive AML standards, but they differ in process, cost and supervisory intensity.

The FINMA token taxonomy is the entry point for any compliance analysis. Payment tokens – those functioning as a medium of exchange – attract AML obligations from the moment a firm offers transmission, exchange or custody services. Asset tokens, which confer rights analogous to equity or debt, may additionally trigger securities-law obligations. Utility tokens sit in a separate category, though hybrid instruments are common and FINMA examines economic substance rather than labels.

FINMA has repeatedly signaled that it treats operational substance over nominal structure. A foreign firm routing Swiss-resident transactions through an offshore entity does not thereby avoid Swiss AML obligations. Regulators in the leading hubs increasingly expect the supervised entity to be the entity that actually controls the client relationship and the funds flow. Operators we advise routinely discover that their existing offshore registration does not satisfy this expectation when Swiss clients represent a meaningful share of volume.

The SRO pathway is the more common entry point for smaller or mid-market crypto businesses. SROs such as VQF (the Association for Quality Assurance in Financial Services) have developed crypto-specific onboarding frameworks. They carry out ongoing supervision of member firms and report material AML concerns to FINMA. Direct FINMA supervision – required for larger or systemically significant intermediaries – involves a more intensive licensing process, including capital assessments and governance reviews.

Key structural obligation: the firm must have a compliance function and a nominated money-laundering reporting officer (MLRO) in place before client onboarding begins. This is not a post-authorisation addition. FINMA and SROs expect the compliance infrastructure to be documented, tested and operational at the point of authorization.

What Does the Travel Rule Require in Switzerland?

The Swiss Travel Rule requires a VASP (virtual asset service provider) to collect, verify and transmit originator and beneficiary data alongside every qualifying virtual-asset transfer. Switzerland implemented this obligation through AMLA amendments aligned with the FATF Recommendation 15 standard, making it one of the earlier jurisdictions to impose Travel Rule compliance on crypto operators as a statutory matter rather than a supervisory expectation.

In practice, the Swiss Travel Rule applies at a de-minimis threshold that is set by the applicable ordinance. Because numeric thresholds are subject to amendment, operators must consult current FINMA guidance for the precise figure in force. What is clear from FINMA's supervisory posture is that the obligation applies to both Swiss-to-Swiss and Swiss-to-foreign transfers, and that the direction of travel does not reduce the obligation. A transfer leaving Switzerland to a counterpart VASP in a jurisdiction without an equivalent Travel Rule still requires the Swiss sending VASP to transmit the required data.

The cross-border dimension is where most compliance programs fail. When a Swiss-licensed VASP sends a transfer to a counterpart in a jurisdiction that has not implemented the Travel Rule, the Swiss VASP must still transmit the data – even if the receiving VASP cannot process it. FINMA's supervisory expectations place the compliance burden on the sending institution. In our practice, we see this asymmetry create operational friction for businesses serving clients who hold wallets at unhosted or offshore custodians.

For transfers to or from unhosted wallets (wallets not held at a regulated VASP), Swiss rules impose additional due-diligence requirements. The firm must take reasonable steps to establish the identity of the beneficial owner of the unhosted wallet, particularly for transfers above the applicable threshold. FINMA has issued supervisory guidance on the acceptable methods for this verification – including transaction-pattern analysis and on-chain forensic checks – though the precise standard is fact-specific and evolving.

Practical implication: Travel Rule compliance in Switzerland is not satisfied by deploying a messaging protocol. The firm must also maintain documented policies for handling transfers where the counterpart VASP cannot receive or respond to Travel Rule data, and must apply enhanced scrutiny to unhosted-wallet transfers. These policies must be reviewed and updated as FINMA guidance develops.

To assess how your current transfer architecture maps against FINMA's Travel Rule expectations, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.

KYC and Transaction-Monitoring Obligations Under Swiss Law

Swiss KYC obligations under AMLA require financial intermediaries to verify client identity before establishing a business relationship, to identify the beneficial owner of assets, and to apply enhanced due diligence to higher-risk clients and transactions. For digital-asset businesses, this translates into a framework that must account for the pseudonymous nature of blockchain transactions without allowing that pseudonymity to become a compliance gap.

FINMA's supervisory practice has made clear that the verification standard expected of crypto firms is equivalent to that applied to traditional financial intermediaries. A crypto exchange cannot accept self-certification that a customer's source of funds is legitimate without corroborating evidence where the risk profile warrants it. The sophistication of the KYC programme – automated screening, risk scoring, periodic review – is assessed against the volume and risk profile of the firm's client base.

Transaction monitoring in the Swiss context must address both on-chain and off-chain indicators. FINMA expects firms to monitor for structuring (breaking transactions into smaller amounts to avoid reporting thresholds), for rapid movement of funds following deposit, and for counterpart addresses associated with sanctioned entities or known illicit activity. The use of blockchain analytics tools is now an operational standard. In our cross-border practice, we find that firms that treat analytics as a box-checking exercise rather than an integrated risk tool face the sharpest supervisory scrutiny.

Reporting obligations under AMLA require the MLRO to file a suspicious activity report (SAR) with the Money Laundering Reporting Office Switzerland (MROS) where there is reasonable suspicion of money laundering or terrorist financing. Unlike some other jurisdictions, Swiss law imposes a statutory freeze on the assets of the reported client for a defined period following a SAR, during which the intermediary must not tip off the client. This freeze-and-hold mechanism has direct operational implications for crypto businesses, which must be able to technically freeze client balances at short notice.

The Fintech Licence and the Banking Licence Route

Switzerland offers a fintech licence as a distinct regulatory pathway for firms that accept public deposits up to a prescribed threshold but do not engage in active credit business – a structure that suits certain crypto custodians and payment intermediaries. The fintech licence sits below the full banking licence in regulatory intensity, but it is not a light-touch option. FINMA requires a demonstrably qualified management team, robust internal controls and a compliance programme meeting the same AMLA standards as a banking licence.

For larger or more complex digital-asset businesses – particularly those seeking to offer a broader suite of financial services or to hold client assets above the fintech threshold – a banking licence is the appropriate route. Swiss banking licences carry significant capital, governance and ongoing compliance obligations. The process involves a detailed application to FINMA, including a business plan, organisational regulations, and evidence of fit-and-proper status for all key individuals. Timelines vary depending on the complexity of the proposed activity and the completeness of the initial application.

The FINMA fintech sandbox also permits limited digital-asset activity under reduced regulatory requirements for firms that are genuinely in an early developmental phase. However, sandbox status is time-limited and cannot substitute for a full licence once commercial operations reach scale. We regularly advise businesses that entered Switzerland under the sandbox on the transition to full authorisation, including the sequencing of compliance infrastructure build-out and the timing of FINMA pre-application engagement.

How Does Swiss AML Interact with Cross-Border Tax and Banking?

The AML and Tax Rule regime in Switzerland does not operate in isolation. For an inbound digital-asset business, the AML programme sits at the intersection of Swiss banking access, tax reporting obligations and the regulatory expectations of home jurisdictions where the firm or its clients are based.

Swiss banking access for crypto businesses is not automatic. Swiss banks apply their own AML and reputational due-diligence standards when onboarding a crypto firm as a client. In practice, this means the firm must be able to demonstrate, at the point of bank onboarding, that its own AML programme meets or exceeds the standards the bank applies. A gap between the firm's declared compliance programme and the standard that FINMA or a recognised SRO would expect is grounds for denial or withdrawal of banking services. Operating without the right licence risks enforcement, frozen rails and lost banking – and we see this pattern consistently in businesses that delayed compliance investment while scaling.

On the tax side, Swiss digital-asset businesses face a multi-layered analysis. The firm's own tax position depends on its legal form, the nature of its activities and the applicable cantonal tax regime. Token-related income, trading gains and staking rewards are treated differently depending on classification. For clients of the firm, Swiss intermediaries must comply with automatic exchange of information (AEOI) obligations under the Common Reporting Standard (CRS) where the assets held qualify as financial accounts. FINMA and the Swiss Federal Tax Administration coordinate on this point, and the scope of crypto assets within CRS is expanding.

Cross-border operators serving clients in the EU face the additional layer of MiCA (Markets in Crypto-Assets Regulation), administered by ESMA and national competent authorities. A Swiss-licensed firm does not benefit from MiCA passporting and must address EU access separately. The intersection of Swiss AMLA obligations and MiCA's Travel Rule implementation across EU member states creates a dual-compliance burden that requires careful operational design. Allied counsel in the relevant EU jurisdictions can map the residual gaps that a Swiss authorisation does not cover.

If your banking or tax structure has not been reviewed alongside your AML programme, there is likely a gap that FINMA or a bank relationship manager will find first. Write to info@oboluslaw.com before that conversation happens. Map your options.

What Are the Most Common AML Compliance Mistakes in Switzerland?

The most common structural failure we see in Swiss AML programmes is the assumption that SRO affiliation satisfies the full compliance obligation. SRO membership establishes the supervisory relationship and the obligation to follow SRO rules. It does not replace the firm's own documented policies, risk assessments, training records and transaction-monitoring logs. FINMA and SROs audit the substance of the programme – not just the membership certificate.

A second recurring failure is inadequate Travel Rule operationalisation. Many firms deploy a VASP-messaging protocol and consider the obligation met. In practice, the Travel Rule requires documented procedures for: counterpart VASP verification, handling of Travel Rule data that cannot be transmitted, escalation of unhosted-wallet transfers above threshold, and periodic review of counterpart relationships. A messaging protocol without these surrounding procedures is an incomplete programme.

The third failure pattern is the offshore-only structure. A common assumption among operators entering Switzerland is that a single offshore licence – whether in a low-supervision jurisdiction or a well-recognised hub – is sufficient to serve Swiss clients. It is not. FINMA applies an economic-substance analysis. If Swiss clients represent a material share of the business, if marketing is directed at Switzerland, or if operational decisions affecting Swiss clients are made from Switzerland, FINMA will treat the firm as a financial intermediary subject to Swiss supervision. The offshore entity does not insulate the business. We address this directly in the structuring work we do for inbound operators.

A micro-matter illustrates the risk. In a recent pre-authorisation review, a custody business operating under a well-regarded offshore registration engaged OBOLUS after a Swiss bank declined to open its operational account. The bank's due-diligence team had identified that the majority of the firm's assets under custody belonged to Swiss-resident clients, triggering AMLA obligations that the offshore structure did not satisfy. We mapped the supervisory exposure, identified the correct SRO affiliation route and structured the firm's Swiss compliance programme to meet the bank's onboarding standard. The bank relationship was established in the following quarter.

Decision Matrix: Which Structure Fits Which Operator Profile?

The right Swiss compliance structure depends on the operator's activity type, client base and scale. Three profiles cover most inbound situations.

An exchange or OTC desk serving retail and institutional clients with Swiss addresses, holding client assets and transmitting between wallets, needs SRO affiliation at minimum and should assess whether volume or asset thresholds trigger the fintech-licence requirement. The timeline to SRO affiliation varies by SRO and by the completeness of the application; expect a process measured in months, not weeks. The key risk is the gap between commencing operations and completing SRO onboarding – FINMA treats this gap as a supervisory breach.

A custody provider holding client digital assets without operating a trading venue sits in a similar position, with the additional consideration that custody is a regulated activity in Switzerland. The safeguarding and segregation expectations that apply under AMLA and FINMA guidance are detailed. The fintech licence is more commonly the right structure for a custody-only business above the de-minimis threshold, and the capital requirement associated with that licence is set by the applicable ordinance – a figure that must be confirmed with current FINMA guidance before a commitment is made.

A token issuer conducting a public offering in Switzerland, or directing a token offering at Swiss investors, must address both AMLA obligations and FINMA's token-classification analysis. If the token is an asset token or a payment token with AML-relevant functionality, the issuer becomes a financial intermediary at the point of offering. The whitepaper and AML obligations interact: the issuer's KYC programme must be in place before the offering opens, not as a post-close remediation.

Self-Assessment Checklist Before Engaging FINMA or an SRO

Before making first contact with FINMA or a recognized SRO, an operator should be able to answer the following questions affirmatively. Each gap identified at this stage represents a compliance exposure that will surface during the supervisory process.

  • Has the firm completed a FINMA token-classification analysis that identifies which token types it handles and which licence/SRO route follows?
  • Is there a documented AML/CFT risk assessment covering client types, jurisdictions, product risk and distribution channels?
  • Has a qualified MLRO been identified, and do their qualifications meet the standard that the relevant SRO applies?
  • Does the firm have documented KYC procedures, including enhanced due-diligence triggers and unhosted-wallet verification methods?
  • Is a Travel Rule-compliant messaging solution in place, with surrounding policies for counterpart verification and non-compliant-counterpart handling?
  • Has the firm assessed which transfers involve unhosted wallets, and is the due-diligence procedure for those transfers documented?
  • Is the transaction-monitoring system configured with Swiss-specific indicators, and is a blockchain analytics tool integrated?
  • Has a SAR-filing and asset-freeze procedure been drafted and tested?
  • Is the banking relationship confirmed, and has the bank's AML onboarding process been completed?
  • Has the cross-border scope been assessed – specifically, whether clients in the EU, UK or US trigger additional compliance obligations beyond AMLA?

In our practice, a firm that can answer all ten points affirmatively before the SRO application is submitted will move through the supervisory process materially faster than one that addresses gaps reactively.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so that the compliance programme your bank and regulator will examine is the one you built intentionally, not the one you inherited. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your situation, contact info@oboluslaw.com.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a VASP to collect, verify and transmit originator and beneficiary information alongside every qualifying virtual-asset transfer. In Switzerland, this obligation flows from AMLA amendments aligned with FATF Recommendation 15. It applies to both domestic and cross-border transfers. Where a counterpart VASP cannot receive Travel Rule data, the Swiss VASP must apply documented escalation procedures rather than simply omit the required information. Unhosted-wallet transfers above the applicable threshold attract additional due-diligence requirements.

Who must act as MLRO for a crypto firm?

Swiss law requires every financial intermediary, including a crypto firm affiliated with a recognized SRO, to designate a qualified money-laundering reporting officer (MLRO). The MLRO is responsible for receiving internal suspicious-activity reports, assessing them and filing externally with MROS where warranted. The SRO sets the qualification standard for the MLRO role. In practice, the MLRO must have demonstrable AML expertise and sufficient seniority to act independently. Outsourcing the MLRO function is possible but requires SRO approval and does not transfer the legal responsibility.

How do regulators audit crypto AML programs?

FINMA and recognized SROs audit crypto AML programmes through periodic on-site and off-site reviews. They examine written policies, transaction-monitoring logs, SAR records, KYC files and Travel Rule data. Auditors assess whether the documented programme matches actual operational practice. Common findings include gaps between the stated risk appetite and the transaction types being accepted, and Travel Rule procedures that exist on paper but are not operationally embedded. Firms should expect to produce evidence of staff training, policy review cycles and escalation decisions as part of any regulatory examination.

By Victor Olsen, Regulatory & Compliance Analyst – specializing in FINMA supervision, AMLA compliance design and cross-border AML programme reviews for digital-asset businesses entering Switzerland and the EU.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours