Payment institution licensing in Switzerland sits at the intersection of FINMA's tiered authorization regime, the Swiss Anti-Money Laundering Act, and the practical reality that Swiss banks scrutinize every digital-asset operator on its books. For a crypto business expanding into Continental Europe or seeking a credible fiat-on-ramp, Switzerland offers genuine regulatory depth – but the path from incorporation to licensed operation requires precise sequencing of the legal, compliance and banking workstreams. Operating without the correct authorization exposes the business to enforcement by FINMA (the Swiss Financial Market Supervisory Authority), disruption of fiat rails and, in serious cases, criminal referral under Swiss financial-market law.
This page explains the regulated basis for payment-related activities in Switzerland, the authorization routes available to digital-asset businesses, the cross-border interaction with tax and banking, and the structural decision a business must make before it files.
Who needs a payment institution licence in Switzerland?
Any business that accepts funds from the public and transmits them on behalf of clients – including businesses whose underlying product is a crypto exchange, a stablecoin platform or a payment API – requires authorization under Swiss financial-market law before it operates. FINMA applies a substance-over-label test: the economic function of the activity determines the regulatory category, not the name the business gives its product.
The three primary authorization tracks relevant to payment-adjacent digital-asset businesses are the fintech licence (a purpose-built, lower-threshold authorization introduced specifically for deposit and payment innovators), the full banking licence, and affiliation with a self-regulatory organization (SRO) under the Swiss Anti-Money Laundering Act for businesses whose activity is limited to money-changing or transmission without deposit-taking. Most inbound digital-asset operators land on the fintech licence or the SRO track, with the banking licence reserved for businesses that genuinely take deposits at scale.
The cross-border dimension is immediate. A business incorporated in an EU member state and passporting under MiCA does not automatically carry passporting rights into Switzerland. Switzerland is not an EU member, and FINMA runs an independent authorization process. Operators managing clients in both the EU and Switzerland must hold separate authorizations – or carefully structure service delivery to avoid triggering Swiss nexus.
The process above describes the standard path. Your facts – the entity, the user base, the banking stack – change the analysis materially. For a scoped review of whether your Swiss activities require authorization, contact OBOLUS at info@oboluslaw.com or map your options here.
The fintech licence: what it covers and who can use it
The Swiss fintech licence authorizes a business to accept public deposits up to a prescribed threshold and to provide payment services, without requiring a full banking licence. FINMA introduced the fintech licence to give payment innovators, including crypto-related businesses, a proportionate regulatory home that sits below the capital and organizational demands of full banking authorization.
Under the fintech licence, the authorized entity may hold client funds in segregated accounts and process transfers. It may not on-lend those funds or pay interest – the prohibition on interest is the structural dividing line between the fintech licence and a banking licence. For most crypto exchanges and payment platforms, this restriction is acceptable: the business model turns on fees and spreads, not on deploying client balances.
FINMA's authorization process for the fintech licence requires the applicant to demonstrate adequate organization, internal controls, fit-and-proper management, and compliance infrastructure proportionate to the business model. The capital requirement for the fintech licence is set at a level below the banking licence threshold; the precise figure is confirmed by FINMA during the pre-application dialogue and varies with the scope of the intended activity. In our practice, businesses that invest in the pre-filing dialogue with FINMA – establishing the business model, the AML framework and the governance structure before submitting – move through the process materially faster than those that file cold.
The SRO track is available where the business performs money-changing or value-transfer services but does not hold client deposits at all. Affiliation with a FINMA-recognized SRO satisfies the AML/CFT obligation under the Swiss Anti-Money Laundering Act and is a lighter-touch entry point. It does not, however, authorize deposit-taking. Businesses that start on the SRO track and subsequently begin holding client balances must upgrade to the fintech or banking licence before crossing that threshold.
How does the application process work in practice?
The Swiss authorization process for a payment institution begins with a structured pre-filing phase, moves through a formal application, and concludes with FINMA's authorization decision. Each phase has defined deliverables, and the timeline from initial engagement to authorization depends heavily on the completeness of the filing and the complexity of the business model.
In the pre-filing phase, FINMA typically expects the applicant to submit a business model description, an organizational chart, draft internal regulations (including AML/CFT policies), and a financial plan. FINMA may ask clarifying questions before confirming the correct authorization track. We regularly advise clients to treat the pre-filing phase as a rehearsal for the formal application: weaknesses in the AML programme or governance structure surfaced at this stage are far cheaper to fix than deficiencies raised after formal filing.
The formal application phase requires submission of a complete dossier. The key documents include the articles of association, the business plan, audited or projected financial statements, fit-and-proper documentation for directors and significant shareholders, the compliance manual, and evidence of the IT and operational infrastructure. FINMA reviews the dossier and may request supplementary information; the clock on the statutory review period does not begin until the dossier is accepted as complete. Authorization timelines vary by category and complexity – businesses operating simple payment models with well-structured documentation have seen timelines in the range of several months; more complex models involving token issuance or custody can take longer. These are working estimates from our cross-border practice, not regulatory guarantees.
Once authorized, the entity is subject to ongoing FINMA supervision, annual audit reporting, and compliance with the Swiss AML Act – including the Travel Rule (the obligation to pass originator and beneficiary data alongside a transfer), which FINMA enforces with reference to the FATF Recommendations and Switzerland's domestic implementing provisions.
Cross-border reality: tax and banking for Swiss payment institutions
Authorization by FINMA is the legal foundation, but it does not resolve the banking and tax questions that determine whether the licensed entity can actually operate. In our experience, this is where the gap between theory and practice bites hardest.
Swiss banks apply enhanced due diligence to financial-services firms that hold client funds – and they apply a further layer of scrutiny to any entity whose underlying business involves digital assets. The Swiss Banking Act and the Swiss AML Act create a framework within which correspondent and account-servicing banks assess their own risk appetite. A FINMA-authorized entity with a well-documented compliance programme is in a demonstrably stronger position than an unlicensed operator, but authorization alone does not guarantee account approval. We have seen authorized entities declined by Swiss institutions and subsequently onboarded successfully once the business model description, the AML narrative and the source-of-funds documentation were restructured for a banking audience rather than a regulator audience – a distinction that matters more than most founders expect.
On the tax side, a Swiss payment institution is subject to Swiss corporate income tax at the federal and cantonal level. The effective combined rate varies significantly by canton; businesses that choose their domicile canton purely for speed of company formation, without modeling the tax interaction, routinely discover a meaningful difference in long-run cost. The VAT treatment of payment and crypto services in Switzerland requires careful analysis: FINMA authorization does not resolve the VAT question, and the Federal Tax Administration applies its own classification logic. Digital-asset businesses should obtain a VAT ruling before commencing operations where volume is material.
For businesses sitting between Switzerland and an EU hub – a common structure where the Swiss entity holds the payment licence and an EU entity holds a MiCA CASP authorization for EU clients – the intercompany flows, transfer pricing and substance requirements across both entities must be modeled at design stage. A structure built on paper without testing the banking and tax interaction often requires expensive restructuring after the first audit cycle.
If a prior application stalled or a Swiss banking account was declined, a second read can identify the structural reason and the route forward. Write to info@oboluslaw.com or map your options here.
AML, the Travel Rule, and VASP obligations in Switzerland
Swiss AML obligations apply to payment institutions from the moment of authorization – and, under FINMA's expansive interpretation, often before. The Swiss Anti-Money Laundering Act requires a payment institution to establish a compliance programme that covers customer due diligence, transaction monitoring, suspicious-activity reporting and record retention. For entities that also handle digital assets, FINMA expects the AML programme to address the specific risks of pseudonymous transfers, cross-chain activity and high-velocity transaction patterns.
The Travel Rule, derived from the FATF Recommendations and implemented under Swiss law through the Financial Institutions Act provisions and FINMA guidance, requires that originator and beneficiary information accompany every qualifying transfer. Switzerland has not adopted a zero-threshold version: the de-minimis figure below which the Travel Rule does not apply is set by applicable Swiss provisions and may change; the current threshold should be confirmed against the current FINMA guidance at the time of application rather than assumed from prior years.
For crypto-native businesses, the Travel Rule creates an immediate counterparty question: how does the business obtain and transmit the required data when the receiving entity is an unhosted wallet or an exchange that does not participate in a Travel Rule messaging network? FINMA has published guidance on this question, and the practical answer involves a combination of technical solutions (TRUST, OpenVASP and similar protocols) and risk-based policies for unhosted wallets. Operators we advise routinely underestimate the lead time required to build or integrate a compliant Travel Rule solution before launch – and FINMA will ask about it during the authorization review.
Does token issuance change the licensing picture?
Yes. A Swiss payment institution that also issues a token – whether a stablecoin, a payment token or an asset-referenced instrument – faces a layered regulatory analysis that goes beyond the payment licence. FINMA applies its published token taxonomy to classify any token into one of three categories: payment tokens, utility tokens and asset tokens. The classification determines whether the token issuance triggers banking, securities or collective-investment-scheme regulation – independently of the payment institution authorization.
A payment token issued by a FINMA-authorized payment institution may fall within the fintech licence perimeter if it is functionally equivalent to a stored-value instrument and the issuer does not on-lend the underlying. An asset token – one that confers rights analogous to equity or debt – will typically trigger securities regulation under the Financial Market Infrastructure Act, requiring a separate authorization or exemption analysis. The practical consequence is that a business planning to issue a token alongside a payment service must complete the token classification analysis before filing the payment institution application, because FINMA's review of the payment application will surface the token issuance and ask for the regulatory basis.
Switzerland's comparative advantage here is that FINMA's taxonomy is well-developed and well-documented. Operators moving from a jurisdiction with binary security/not-security classification logic often find the Swiss three-part taxonomy more workable, because the payment-token and utility-token categories provide a credible basis for a compliant issuance without triggering the full securities regime. That advantage is real, but it requires precise structuring of the token rights from the outset – retrofitting after issuance is expensive and sometimes impossible.
Practical illustration: payment platform expanding from Switzerland into the EU
In a recent cross-border structuring matter, a payments company held a fintech licence in Switzerland and was expanding its stablecoin payment service to EU corporate clients. The initial structure routed all EU flows through the Swiss entity on the basis that the fintech licence covered the service. On review, the EU-facing activity triggered MiCA CASP authorization requirements in the home-member-state of the operator's EU clients – the Swiss fintech licence carried no EU passporting effect. We restructured the entity stack to add a MiCA-authorised subsidiary in a responsive EU jurisdiction, mapped the intercompany payment flows for transfer-pricing compliance, and reconfigured the banking arrangements so that the Swiss and EU entities each held segregated client-fund accounts with institutions comfortable with the dual-entity structure. The client launched on schedule in both markets with a compliant authorization stack across both regulators.
Which authorization track fits your business?
Choosing between the fintech licence, the banking licence and the SRO track is not a branding decision – it is a structural commitment with capital, governance and operational consequences that compound over time.
A business that holds client funds temporarily in the course of payment processing, charges fees on transaction volume and does not pay interest on balances is the paradigm fintech-licence candidate. The capital threshold is proportionate, the ongoing supervision is manageable, and the authorization timeline – with good preparation – is measurable in months rather than years. The key risk for this profile is underestimating the compliance build: FINMA expects a functioning AML programme, not a policy document.
A business that takes deposits at scale, pays returns to depositors or deploys client funds in any form is a banking-licence candidate. The capital requirement is materially higher, the organizational demands are greater and the timeline is longer. Very few digital-asset businesses need a banking licence; most that apply for one do so after discovering that the fintech licence does not accommodate a feature of their model – typically an interest or yield component.
A business that performs value-transfer or money-changing functions but does not hold client balances is an SRO candidate. The SRO track is the fastest entry point and the lightest ongoing burden, but it is also the most constrained: the moment client funds are held, even briefly, the SRO affiliation is insufficient and FINMA expects an upgrade.
For businesses sitting between two or more regulatory environments – Switzerland plus an EU jurisdiction, or Switzerland plus a common-law offshore hub – the authorization stack must be designed as a whole. The banking, tax and compliance workstreams interact, and a decision taken in one layer (for example, choosing a fintech licence rather than a banking licence) has downstream consequences for the banking relationships and the tax profile of the group.
Common mistakes operators make when licensing in Switzerland
The most common error we see is conflating AML registration with authorization. Affiliating with an SRO satisfies the Swiss AML Act obligation but does not authorize the acceptance of client funds. Businesses that begin onboarding clients after SRO affiliation, on the assumption that FINMA authorization will follow, create a period of unlicensed activity that FINMA takes seriously and that Swiss banks treat as a red flag during account opening.
A second recurring mistake is treating the business plan submitted to FINMA as a regulatory document and the pitch deck submitted to banks as a commercial document, when in fact both audiences are asking the same underlying questions: who controls the funds, what are the flows, and how is risk managed? A single, integrated narrative that answers both questions in the same idiom saves weeks of back-and-forth at the bank-onboarding stage.
A common assumption is that a single offshore licence – for example, a BVI VASP registration or a Cayman CIMA registration – is sufficient to serve Swiss and EU clients. It is not. Switzerland and the EU each operate independent authorization regimes, and FINMA does not recognize offshore registrations as equivalent. The offshore entity may serve clients in its own jurisdiction and, in limited cases, on a reverse-solicitation basis – but active marketing to Swiss residents without FINMA authorization is a regulatory risk that enforcement action has made concrete in recent years.
Finally, operators routinely underestimate the banking timeline relative to the licensing timeline. FINMA authorization can precede Swiss banking approval by months. Planning the operating capital and the launch timeline without a confirmed banking solution is a structural vulnerability that has forced several authorized businesses to delay commercial launch.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – structuring the full licence, banking and payment stack for operators worldwide
- De-Risking and Account Closure Defence in Bermuda – navigating bank account closure and de-risking for digital-asset businesses in Bermuda
- Digital-Asset Licensing in the Czech Republic – VASP and licensing requirements for digital-asset operators in the Czech Republic
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of perceived AML and compliance risk. Most closures occur where the business cannot demonstrate a documented AML programme, clear source-of-funds trails and an intelligible business model. A FINMA-authorized entity with well-structured compliance documentation is in a stronger position than an unlicensed operator – but authorization alone does not eliminate the bank's own risk assessment. Operators that present their compliance posture in banking-audience language rather than regulatory language experience fewer closures in our practice.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) seeking to onboard with an EMI (electronic money institution) must satisfy the EMI's AML and risk onboarding requirements, which typically include a detailed business model description, a compliance programme, source-of-funds documentation and, in many cases, audited financials. The EMI will assess the VASP's own regulatory status – an authorized VASP with a documented compliance function is materially easier to onboard. We advise VASPs to prepare a banking memorandum specifically for this purpose, distinct from the FINMA authorization dossier.
What does client-money safeguarding require?
Under the Swiss fintech licence regime and the applicable provisions of Swiss financial-market law, client funds must be segregated from the firm's own assets. Segregated client balances must be held with a licensed Swiss bank or another qualifying custodian, and must be protected from claims by the institution's creditors. The practical requirements include documented segregation policies, regular reconciliation and audit confirmation. For digital-asset businesses holding a mix of fiat and crypto balances, the safeguarding obligation applies to the fiat component; the custody treatment of the crypto component requires a separate analysis under applicable FINMA guidance.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit, and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specializing in FINMA authorization processes, cross-border payment institution structuring and Swiss digital-asset regulatory compliance.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.