Switzerland sits at an unusual intersection. Its regulator, FINMA (the Swiss Financial Market Supervisory Authority), has applied a substance-over-label approach to digital assets since before most jurisdictions had a framework at all. For an inbound exchange operator, that means two things: the regime is coherent and well-developed, but there is no single "crypto exchange licence" to apply for. What you need depends on what your platform actually does – and getting that analysis wrong before incorporation is expensive.
Setting up a crypto exchange in Switzerland requires the operator to identify which regulated activity its business model triggers under Swiss financial-market law, then obtain the corresponding FINMA authorisation or, at minimum, affiliate with a recognized self-regulatory organisation for AML purposes. The applicable regimes include the banking licence, the fintech licence (a limited banking authorisation for deposit-taking up to a statutory threshold without on-lending), and the securities-firm licence for platforms handling tokens classified as securities under FINMA's token taxonomy. Cross-border operators also face the question of where users sit and where banking is arranged, because Swiss authorisation does not resolve compliance obligations in the user's home jurisdiction.
This page sets out the regulated basis, the application path, the cross-border interaction with tax and banking, and the decision points that determine which structure makes sense for your exchange.
What does FINMA actually regulate for crypto exchanges?
FINMA regulates the activity, not the asset class. Its published token taxonomy divides tokens into three functional categories – payment tokens, utility tokens, and asset tokens – and the classification drives the licence requirement. An exchange that matches orders in asset tokens is likely operating a securities firm. An exchange that holds client fiat or stablecoins above a de-minimis threshold may trigger the banking law or the fintech licence. A pure peer-to-peer matching engine in payment tokens may trigger only AML obligations.
The FINMA token taxonomy, first articulated in the regulator's 2018 ICO guidelines and refined in subsequent guidance, is the analytical starting point for every exchange build in Switzerland. Hybrid tokens – tokens with both utility and asset characteristics – are assessed on a case-by-case basis. In our practice, the majority of exchange operators handling a broad token set find that at least a subset of their listed assets attracts the asset-token classification, which pulls securities-firm requirements into the analysis.
A securities firm authorisation in Switzerland permits the operator to trade financial instruments on a professional basis, to hold client assets, and to operate a multilateral trading facility. The conditions – capital, organisational requirements, fit-and-proper standards for management and shareholders – are material. They are not insurmountable, but operators who treat them as administrative formalities consistently underestimate the lead time and cost.
Who needs a FINMA licence, and who needs only SRO membership?
Not every Swiss crypto exchange requires a FINMA licence; the threshold question is whether the platform triggers a licensed activity under the relevant Swiss financial-market statutes.
AML obligations are near-universal. Any business that professionally exchanges, transfers, or provides custody for virtual assets in Switzerland must affiliate with a self-regulatory organisation (SRO) recognised under the Swiss Anti-Money Laundering Act, or operate as a directly supervised financial intermediary under FINMA. SRO membership is the standard entry point for smaller operators. It does not substitute for a FINMA licence where one is required, but for a platform whose token set falls entirely outside the securities perimeter and that does not hold client deposits above the fintech-licence threshold, SRO membership may be the primary regulatory touch point.
The moment the platform holds client fiat balances – even temporarily, in a payment flow – the banking law analysis engages. The fintech licence addresses exactly this scenario: it permits the acceptance of public deposits up to the applicable statutory maximum without the obligation to on-lend, making it well-suited to exchanges that custody user fiat as part of the trading flow. Where the exchange intends to custody assets beyond that threshold or to on-lend, the full banking authorisation becomes necessary.
Regulators in the leading hubs increasingly expect operators to have completed this mapping before they submit any application. FINMA is no exception. A submission that does not clearly articulate the regulatory basis for the chosen structure invites a request for further information – and with it, a delay to the timeline.
For a scoped assessment of which FINMA authorisation your exchange model triggers, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your token set, your custody model, and your user geography will each shift the analysis.
What does the FINMA authorisation process look like in practice?
The FINMA authorisation process is structured, document-intensive, and unforgiving of gaps in the organisational submission. There is no single application form: the regulator issues guidance on the required dossier content, and the applicant assembles a package that addresses business model, governance, capital, AML/KYC programme, IT security, and outsourcing arrangements.
The standard path runs as follows. The operator first establishes a Swiss legal entity – a stock corporation (Aktiengesellschaft) is the standard vehicle for a licensed financial intermediary. The entity must have a qualifying registered office in Switzerland, not merely a mailbox. Senior management responsible for Switzerland-based operations must generally be resident or demonstrably accessible to FINMA. Qualified shareholders above applicable ownership thresholds are subject to fitness and propriety review.
The dossier then addresses the regulated activity in detail: the business plan, the token classification analysis, the operational model (own book, agency, or matched-principal), the custody arrangements, the AML/KYC framework, and the IT architecture. For a securities-firm application, the capital must be demonstrated as at the date of authorisation – not merely committed.
Timeline from submission to authorisation is not fixed in statute and varies materially by application complexity. Simple structures with clean governance and a focused business model generally move faster than multi-activity applications or those involving novel token types that require FINMA to form a view on classification. Operators we advise routinely plan for a process measured in months, not weeks, and build that timeline into their go-to-market schedule accordingly.
A common error is to begin the Swiss entity formation and capital commitment before the token-classification analysis is complete. If the analysis later reveals that a different licence category is required, the entity structure may need revision. Front-loading the legal analysis is not bureaucratic caution – it is the fastest path to authorisation.
What cross-border complications should an exchange operator expect?
Swiss authorisation governs the operator's activity within Switzerland and, in some cases, activity directed at Swiss users. It does not address the regulatory obligations that arise in every other jurisdiction where users are located.
This is the single most common misconception we encounter. An exchange licensed under FINMA may still require registration or notification in the EU under MiCA (the Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities), a VASP (virtual asset service provider) registration in the UK under the FCA's Money Laundering Regulations, or local licensing in any number of other markets. Switzerland's position outside the EU means there is no passporting bridge between a FINMA authorisation and MiCA-covered jurisdictions. A Swiss CASP authorisation under MiCA does not exist – the operator serving EU users needs a separate MiCA footprint.
Banking is a related pressure point. Swiss banks apply rigorous onboarding standards to crypto businesses. The so-called "crypto-friendly banking" environment that Switzerland once represented has become more selective. Operators that present a complete regulatory picture – FINMA authorisation, a documented AML programme, a clear source-of-funds narrative – are materially better positioned to open accounts with Swiss financial institutions than those who arrive with an incomplete compliance stack. We have seen operators delay their launch by months because the banking relationship was not initiated in parallel with the licence application.
Cross-border tax treatment adds another dimension. Switzerland applies its own rules to the issuance and trading of tokens, including rules on whether token proceeds constitute taxable income at the entity level, whether VAT applies to exchange services, and how wealth tax interacts with token holdings at the beneficial-owner level. None of these questions has a single universal answer; they depend on the entity structure, the jurisdiction of beneficial owners, and the character of the tokens. Allied counsel in the relevant tax jurisdiction must be engaged wherever the beneficial-owner profile is international.
How do AML and the Travel Rule apply to Swiss crypto exchanges?
Switzerland has implemented the Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data with virtual-asset transfers – through its own AML framework, and the obligations apply to exchanges as VASPs under the relevant FINMA and SRO guidance.
In practice, this means every qualifying transfer between exchanges or to a non-custodial wallet must carry structured data about the originator and beneficiary. Swiss implementation sets out which transfers are in scope and the data fields required; the de-minimis threshold and precise technical standards are defined under the applicable Swiss rules, which operators should verify against current FINMA and SRO guidance before system build.
The operational consequence for exchange operators is significant. A platform that routes transfers through or into Switzerland without a Travel Rule-compliant messaging layer will face compliance failures that SRO supervisors and FINMA will flag during examination. The technical integration of Travel Rule tooling is not optional and should be scoped as a core infrastructure item, not a post-launch add-on.
FINMA also maintains expectations around transaction monitoring, suspicious-activity reporting, and wallet-screening against sanctions lists. Switzerland has implemented the relevant FATF Recommendations in full; the AML programme submitted with a licence application is expected to reflect that standard. An AML policy that references generic FATF standards without jurisdiction-specific calibration consistently draws examiner comments.
A recent matter: an inbound exchange establishing a Swiss presence
In a recent matter, a digital-asset exchange operator incorporated in a non-EU common-law jurisdiction sought to establish a Swiss entity to serve European professional clients. The operator's existing platform listed a broad token set, including several tokens with characteristics that placed them within FINMA's asset-token category. We conducted a full token-classification mapping and identified that the business model as initially structured required a securities-firm authorisation – a more demanding pathway than the fintech licence the operator had assumed would apply. We restructured the listing perimeter so that the initial Swiss entity operated across a payment-token and utility-token set only, deferring the securities-firm application to a subsequent phase once the governance infrastructure was in place. Separately, we advised that the EU user base required a parallel MiCA authorisation and engaged allied counsel in a leading EU member state to run that process concurrently. The Swiss entity reached SRO affiliation and began operating within the planned timeline; the MiCA application entered the review phase in the same quarter.
Which structure fits which operator profile?
The right structure depends on three variables: the token set, the custody model, and the user geography. The following analysis maps the common operator profiles to the applicable Swiss instrument.
Profile A – Payment and utility tokens only, no fiat custody: The operator lists only tokens that FINMA classifies as payment or utility tokens, holds no client fiat balances, and routes fiat in and out via an independent payment institution. The primary Swiss obligation is SRO affiliation under the AML Act. The capital requirement is proportionate to the SRO's own rules, not to a FINMA licence. Timeline to operational status is materially shorter than for a licensed route. The key risk is that the token classification may shift as the token set expands; any addition of an asset-token triggers re-analysis.
Profile B – Mixed token set including asset tokens, no fiat custody: The operator lists tokens that include asset tokens under FINMA's taxonomy. A securities-firm authorisation is required. Capital is at the level FINMA specifies for that category; governance and organisational requirements apply in full. Timeline is longer. The advantage is that the securities-firm licence permits the operator to market itself as FINMA-regulated to professional counterparties – a meaningful commercial differentiator for institutional clients.
Profile C – Exchange with fiat custody up to the fintech threshold, payment and utility tokens: The operator holds user fiat balances as part of the trading flow but does not on-lend. The fintech licence is the primary instrument. It is a limited banking authorisation with its own capital and governance requirements, calibrated below a full banking licence but above SRO-only obligations. Timeline sits between the SRO path and the securities-firm path. The key risk is the deposit threshold: exceeding it triggers the full banking licence requirement.
Profile D – Full-service exchange with securities and fiat: The operator lists asset tokens, holds user fiat, and may provide ancillary services such as staking or lending. This profile likely requires multiple FINMA authorisations or a combined authorisation structure. It is the most demanding path and requires the longest planning horizon. Operators in this category should engage counsel before entity formation.
If a prior application stalled or a banking relationship was refused, there is usually a structural reason. To surface it and identify the route forward, write to OBOLUS at info@oboluslaw.com. A second read of the submission or the entity structure often identifies the point of failure and the remedy.
What are the most common mistakes in a Swiss exchange setup?
A common assumption among inbound operators is that Switzerland's historic openness to crypto business means the regulatory process is light-touch. It is not. FINMA is a sophisticated regulator with high documentation standards and a track record of withdrawing or refusing applications that present governance gaps or underdeveloped AML programmes.
The most consistent failure points we observe are: (1) incomplete token-classification analysis at the outset, leading to a mismatch between the entity structure and the actual licence required; (2) governance documentation that names Swiss-resident directors but does not demonstrate genuine management presence in Switzerland; (3) AML programmes that are templated rather than operationally calibrated to the specific exchange model; and (4) a banking relationship that is not initiated until after FINMA authorisation, leaving the operator unable to demonstrate the operational readiness that the authorisation process itself requires.
The Swiss resident-management expectation deserves emphasis. FINMA will assess whether the persons responsible for Swiss operations genuinely manage from Switzerland, not whether a name appears in the articles of association. Operators that structure nominal Swiss management while running the business from another jurisdiction risk a supervisory finding that the Swiss entity is a shell – with consequences for the licence and for the AML programme that depends on it.
A further point concerns the interaction between Swiss law and the operator's home jurisdiction. Where the beneficial owners are subject to reporting obligations in another country – the US, the UK, Germany – those obligations do not disappear because the operating entity is Swiss. A structure that achieves Swiss regulatory compliance while creating an undisclosed exposure in another jurisdiction is not a solution. It is a deferred problem.
Related at OBOLUS
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – end-to-end licence mapping across 70+ jurisdictions for exchanges, custodians and issuers
- VARA Licence Application in Germany – BaFin – regulatory authorisation pathway for digital-asset businesses under BaFin supervision
- Enforcement of Foreign Judgment in the Cayman Islands – cross-border judgment recognition and enforcement for digital-asset matters
FAQ
How long does a crypto licence take to obtain?
In Switzerland, the timeline depends on the licence category and the completeness of the submission. An SRO affiliation is typically the fastest path – measured in weeks for a well-prepared application. A fintech licence or securities-firm authorisation involves a more intensive review by FINMA, with timelines generally measured in months. Complex or novel structures, or those requiring FINMA to form a view on token classification, take longer. Engaging counsel before entity formation and beginning the banking relationship in parallel materially reduces the overall timeline.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. Switzerland suits operators that value regulatory credibility with institutional counterparties, a coherent legal framework for token classification, and a stable operating environment. It is a strong choice for professional or institutional-facing exchanges. It is not a passporting gateway to the EU – operators serving EU users need a separate MiCA footprint. For businesses with a primarily retail EU user base, an EU CASP authorisation under MiCA may be a more efficient primary licence, with Switzerland as a secondary hub. The right answer depends on the operator's token set, user geography, and banking requirements.
Do I need a separate custody licence?
In Switzerland, custody of client assets is a regulated activity that is assessed as part of the overall FINMA authorisation rather than under a separate standalone custody licence. A securities firm authorised by FINMA may hold client assets as part of that authorisation, subject to the applicable safeguarding and segregation requirements. An exchange that holds client virtual assets but falls below the securities-firm perimeter must still address the custody question within its SRO AML programme. Whether a separate authorisation is required depends on the custody model and the asset types held; the analysis should be conducted as part of the initial regulatory scoping.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise crypto exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, custody and payment stack before you commit – so the structure that goes into FINMA is the right one. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in FINMA authorisation pathways and cross-border licence structuring for inbound digital-asset operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.