EST · MMXXVI
Home/Jurisdictions/Switzerland/KYC and onboarding framework in Switzerland
Compliance, AML & Travel Rule

KYC and onboarding framework in Switzerland

Kyc and onboarding framework in Switzerland. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Switzerland imposes one of the most demanding KYC and onboarding regimes for digital-asset businesses in the world. A virtual asset service provider (VASP) – any entity exchanging, transmitting, storing or brokering crypto-assets commercially – must satisfy FINMA-supervised anti-money-laundering obligations before it accepts a single client. Failure to do so exposes the business to supervisory action, frozen banking relationships and potential criminal referral. This page sets out the regulated basis, the practical onboarding sequence, the cross-border pressures and the decision point for an inbound operator.

What is the regulated basis for KYC in Switzerland?

Switzerland's KYC regime for VASPs rests on the Anti-Money Laundering Act (AMLA) and is supervised either directly by FINMA or, for smaller operators, through an FINMA-authorised self-regulatory organisation (SRO). The obligation to conduct customer due diligence is not optional and is not calibrated to the size of the business. It applies from the first transaction that crosses the applicable threshold. Operators choosing the SRO route affiliate with a body such as VQF or PolyReg; those holding a fintech licence or a banking licence answer directly to FINMA.

The choice between SRO membership and a direct FINMA authorisation matters enormously for an inbound digital-asset business. SRO affiliation is typically the entry path for exchange operators and custodians that do not take deposits or operate as banks. Direct FINMA oversight – whether under the fintech licence, the banking licence or the securities firm licence – brings a heavier capital and governance burden but also a stronger market signal. In our practice, we see operators underestimate the compliance infrastructure that the SRO route still demands: an SRO is not a lighter regime, it is a different supervisory channel with the same substantive rules.

Token taxonomy matters here. FINMA's classification of a token as a payment token, a utility token or an asset token determines which additional regulatory regime may apply on top of AML. A token with security-like characteristics – conferring economic rights or resembling a collective investment – attracts the full securities-firm regime and its KYC obligations. The AMLA baseline, however, applies regardless of token classification: if you are commercially operating as a financial intermediary in the virtual-asset space, customer due diligence is mandatory.

Contact OBOLUS before you build your onboarding stack. The process above describes the standard path. Your facts – the entity structure, the user base, the banking relationships and the token classification – change the analysis materially. For a scoped assessment of your Swiss compliance posture, contact OBOLUS at info@oboluslaw.com.

Who must comply with Swiss AML obligations?

Any entity that qualifies as a financial intermediary under the AMLA is caught, and FINMA's guidance makes clear that most commercial VASP activities cross that threshold. Exchange operators, custodians, token issuers conducting public sales, payment processors routing crypto and OTC desks all fall within scope. The test is functional: it turns on the activity, not the corporate form or the domicile of the legal entity.

For a foreign business serving Swiss clients or routing transactions through Swiss infrastructure, the question of whether the AMLA applies is separate from the question of where the legal entity sits. FINMA takes a market-access view: if the business targets Swiss residents or operates through Swiss personnel or systems, Swiss law may apply. Operators we advise regularly underestimate cross-border exposure when they structure through a non-Swiss entity but maintain Swiss-facing operations. The correct analysis addresses the facts of access, not just the corporate address.

Financial intermediaries caught by the AMLA must affiliate with an SRO or obtain a direct FINMA licence within a defined period of commencing activity. Operating as an unaffiliated financial intermediary is a criminal offence under Swiss law. Enforcement in recent years has become more active, particularly for firms that grew rapidly during high-volatility market periods and deferred compliance infrastructure.

What does the KYC onboarding sequence look like in practice?

The AMLA-compliant onboarding sequence for a Swiss VASP follows a structured customer due diligence process covering identity verification, beneficial ownership determination, risk classification and ongoing monitoring – in that order, and before the business relationship is activated. Each step has a documented basis in FINMA guidance and, for SRO members, in the relevant SRO rules.

Identity verification requires collecting and verifying documents that establish who the client is. For individual clients, this typically means a government-issued identity document and a liveness check. For legal entities, it means articles of association, a register extract and documentation tracing the control structure to a natural person. FINMA does not prescribe a single technical method for remote verification, but it expects the method to be proportionate to risk and to produce a reliable, documented result.

Beneficial ownership determination is a distinct step. Knowing who the client is does not satisfy the obligation to know who controls the client. The AMLA requires the financial intermediary to identify the beneficial owner – the natural person who ultimately owns or controls the legal entity or on whose behalf a transaction is conducted. For structures with multiple layers, this requires tracing through holding companies, trusts and nominee arrangements. In our cross-border practice, this is where onboarding stalls most often: complex structures, incomplete corporate records and clients who are unfamiliar with Swiss standards.

Risk classification follows. The financial intermediary assigns each client a risk profile – standard or enhanced – on the basis of the client's domicile, business activity, transaction patterns and proximity to higher-risk categories such as politically exposed persons (PEPs) or high-risk jurisdictions identified by the FATF. Enhanced due diligence applies to higher-risk relationships and requires additional documentation, senior-management sign-off and more frequent review.

Ongoing monitoring is continuous, not a one-time exercise. Transactions are screened against sanctions lists and monitored for patterns inconsistent with the declared business relationship. When an anomaly surfaces, the financial intermediary must decide whether to file a suspicious activity report with the Money Reporting Office Switzerland (MROS). The obligation to report suspicion – and the prohibition on tipping off the client – applies regardless of whether the underlying activity is eventually confirmed as illicit.

How does the Travel Rule apply to Swiss VASPs?

The Travel Rule – the obligation to pass originator and beneficiary information alongside a virtual-asset transfer – applies to Swiss VASPs under the AMLA and associated FINMA guidance, mirroring the FATF standard that Switzerland has adopted as a FATF member. The threshold above which Travel Rule data must accompany a transfer is set by the applicable regulations; where the threshold is not met, the intermediary still retains the data. FINMA has been explicit that Swiss VASPs must implement the Travel Rule in their technical infrastructure, not merely acknowledge it as a policy matter.

The cross-border dimension creates friction. A Swiss VASP sending funds to a counterpart VASP in a jurisdiction that has not yet implemented the Travel Rule faces a data-exchange gap. FINMA's position – consistent with FATF guidance – is that the Swiss side must still attempt to transmit the required data and must document the outcome. Where the counterpart cannot receive structured data, the Swiss VASP must assess the risk of proceeding with the transfer and maintain records of its decision. Operators we advise frequently discover this gap only when a counterpart exchange declines to accept a transfer or when an SRO audit surfaces incomplete Travel Rule records.

Choosing a Travel Rule messaging protocol is an operational compliance decision with legal consequences. FINMA does not mandate a single solution, but it expects the solution to be interoperable and auditable. Firms implementing the Travel Rule for the first time often underestimate the vendor-integration timeline and the policy documentation required alongside it.

If your Travel Rule implementation is incomplete or your onboarding records are under SRO scrutiny, contact OBOLUS. A second read of your compliance posture – before the audit – is materially better than a remediation engagement after it. Write to us at info@oboluslaw.com or message us via t.me/oboluslaw.

How do Swiss banking and tax requirements interact with KYC compliance?

Swiss banking access for VASPs has become more selective, not less, as the major Swiss banks have clarified their risk appetite for digital-asset clients. A VASP with demonstrably strong KYC infrastructure – documented policies, clean beneficial ownership records, a functioning Travel Rule solution – is materially better positioned to open and maintain a Swiss bank account than one that treats compliance as a later concern. Banking relationships and AML compliance are therefore not parallel workstreams; one conditions the other.

Swiss banks applying their own AML due diligence to a VASP client will look at the same questions the SRO or FINMA would: who are the beneficial owners, what is the client base, what is the transaction monitoring infrastructure, who is the MLRO, and what is the geographic scope of the business? A VASP that cannot answer those questions clearly, in writing, will not open an account at a Swiss bank that applies rigorous correspondent-banking standards.

On the tax side, Switzerland does not impose a blanket VAT on crypto transactions, but the treatment of specific activities – staking rewards, token issuances, trading income – requires jurisdiction-specific analysis. The AML and tax compliance layers interact where transaction monitoring data surfaces income or gain that must be reported. For a business with Swiss clients and Swiss banking, both layers must be managed together. We regularly advise cross-border operators on the interaction between AMLA compliance, Swiss withholding tax and the CRS/AEOI reporting obligations that apply to Swiss-based financial institutions.

What governance structure does a Swiss VASP need?

A Swiss financial intermediary must designate a responsible person for AML compliance – in substance, an MLRO (money laundering reporting officer) – with the authority, resources and access to fulfil that role. FINMA and the SROs expect this person to have genuine seniority in the organisation, not a nominal title. For smaller operators, this is often a founder or a senior manager; for larger entities, it is typically a dedicated compliance officer reporting to the board.

The governance expectations go beyond naming an individual. The financial intermediary must maintain a written AML programme covering policies, procedures, training, internal audit and escalation paths. The programme must be reviewed regularly and updated when the business model or the regulatory environment changes. FINMA's inspection teams and SRO auditors assess the programme as a document and then test whether the organisation actually operates it. The gap between policy and practice is the most common source of findings in AML audits.

Board-level oversight of AML compliance is not optional. Senior management bears accountability for the programme's adequacy, and that accountability is personal. In Switzerland, as in most FATF-aligned jurisdictions, AML failures can generate both entity-level sanctions and personal liability for responsible officers. The risk profile of an under-resourced compliance function is therefore not merely regulatory – it is personal for the individuals named in the governance structure.

A cross-border compliance matter: Travel Rule gap identified pre-audit

In a recent engagement, a digital-asset trading platform domiciled outside Switzerland but serving Swiss-resident institutional clients approached us ahead of a scheduled SRO audit. The platform had implemented a Travel Rule solution but had not configured it to handle transfers to VASPs in jurisdictions that had not yet adopted the FATF standard. Its records showed several hundred outbound transfers over a two-year period with no corresponding Travel Rule data transmitted. We mapped the gap, designed a remediation protocol consistent with FINMA guidance and SRO expectations, and produced the compliance narrative the platform's auditors required. The audit concluded without adverse findings. The platform subsequently applied for, and obtained, SRO affiliation on the basis of the remediated programme.

What should an inbound operator decide before committing to Switzerland?

For a digital-asset business evaluating Switzerland as a base of operations, the decision turns on four axes: the activity it intends to conduct, the token classification that applies to its product, the client base it intends to serve and the compliance infrastructure it is prepared to build and maintain. Switzerland is a serious jurisdiction. Its legal system is stable, its courts are respected, and access to the Swiss financial system carries reputational weight. But it demands a corresponding seriousness from its financial intermediaries.

Profile A – an exchange operator with a global retail client base seeking EU-accessible infrastructure – may find the EU MiCA passporting route more efficient, using a Swiss vehicle for specific institutional services while holding a CASP authorisation in an EU member state for EU-facing activity. The SRO path in Switzerland and the CASP path in the EU are not mutually exclusive; they can be layered for different business lines.

Profile B – an institutional custody or OTC desk targeting Swiss family offices and private banks – is a natural candidate for Swiss SRO affiliation or a fintech licence, with a banking partner sourced from the small cohort of Swiss banks that actively serve the digital-asset sector. The compliance investment is higher, but the client access and the relationship credibility are commensurate.

Profile C – a token issuer conducting a public sale that may include Swiss purchasers – must address both the AMLA KYC obligations and the question of whether the token constitutes a security under Swiss law. FINMA's token classification guidance is functional: the structure of the token, not the label applied to it, determines the regulatory path. Getting the classification wrong at issuance creates compliance remediation costs that dwarf the cost of a structured pre-issuance analysis.

A common assumption among operators at this stage is that an offshore licence – a BVI or Cayman registration, for instance – is sufficient to serve Swiss clients without further Swiss compliance obligations. That assumption is incorrect. Swiss law, like most modern AML frameworks, is access-based: serving Swiss clients, routing transactions through Swiss banking or employing Swiss personnel can each, individually or together, trigger the AMLA. The offshore licence does not disappear the Swiss nexus; it merely adds a compliance gap that FINMA or an SRO auditor will eventually surface.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a VASP to collect and transmit originator and beneficiary information – name, account identifier and, where applicable, address – alongside a virtual-asset transfer above the applicable threshold. Switzerland, as a FATF member, has incorporated this obligation into its AML regime under FINMA supervision. VASPs must implement a technical solution capable of exchanging this data with counterpart VASPs, document transfers where the counterpart cannot receive the data, and retain records for the period required by the AMLA.

Who must act as MLRO for a crypto firm?

A money laundering reporting officer (MLRO) – or an equivalent senior compliance designee – must be appointed by every Swiss financial intermediary, including VASPs operating under SRO affiliation or a direct FINMA licence. FINMA and the SROs expect this person to hold genuine authority within the organisation, have direct access to senior management and the board, and possess the technical knowledge to discharge the role effectively. A nominal appointment without operational authority is not compliant. Personal accountability for AML failures attaches to the named individual under Swiss law.

How do regulators audit crypto AML programs?

FINMA and authorised SROs audit VASP AML programmes through a combination of document review and operational testing. Auditors assess the written programme – policies, procedures, risk methodology and training records – and then sample transaction files, onboarding records and suspicious-activity reports to verify that the organisation operates as documented. The gap between written policy and actual practice is the most common source of adverse findings. Boards should treat the AML audit as a test of the compliance function's operating reality, not merely of its documentation.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before a client commits – and coordinate AML programme design, Travel Rule implementation and SRO audit defence as integrated workstreams. Digital assets are the whole of our practice. To discuss your Swiss compliance situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AMLA compliance programme design and FINMA-supervised AML audit readiness for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours