top of page

The Pragmatic Guide to Your Swiss SRO Application

  • Mar 20
  • 9 min read

Updated: Aug 1

What the membership actually permits, and what's about to change.



Most of my conversations with founders start in the same place. They've read that Switzerland is crypto-friendly, that SRO membership takes three or four months, and that it costs a fraction of a FINMA licence. All of that is true.


Then they describe the product they want to build, and somewhere around minute six I have to tell them that a third of it sits outside the perimeter.


That's rarely a Swiss problem. It's a mapping problem. The Swiss framework is unusually clear once you know where the lines are — but the lines are drawn in places that don't match how founders describe their own businesses. What follows is the map I wish more people had before they incorporated.



First: there are two doors, not one

Under the Anti-Money Laundering Act, anyone acting as a financial intermediary in Switzerland must either hold a FINMA authorisation or affiliate with a FINMA-recognised self-regulatory organisation. That's the whole architecture. Banks, securities firms, trading venues and fund managers go through FINMA. Everyone else goes through an SRO.


Here's the part that gets lost: SRO membership is not a crypto licence. It is supervision of your AML obligations. It says nothing about whether your underlying activity is permitted.

So you're always answering two separate questions:

  1. Is what I'm doing a licensed activity? Taking deposits, running a trading venue, dealing in securities, managing a fund. If yes, no SRO can help you — that's FINMA territory.

  2. If not, am I a financial intermediary under AMLA? If yes, you need an SRO.


The SRO route covers everything in the second box. What surprises applicants is that the SRO will still turn you away if your model needs a FINMA licence. They have no appetite for an unlicensed bank in their membership. So in practice the admission process does function as a business-model review — just not the one most people prepare for.



The perimeter, activity by activity

What follows is a working map, not legal advice. Every case is assessed individually and the details matter enormously. But if you understand the logic below, you'll know which of your features are going to be a problem before you pay anyone to tell you.

Throughout, "crypto" means payment and utility tokens as FINMA classifies them. Security tokens and derivatives sit outside the SRO world entirely and change the analysis completely.


Brokerage and exchange — mostly green

Fiat-to-fiat, fiat-to-crypto, crypto-to-fiat, crypto-to-crypto. All workable. You are dealing with your client as a counterparty.


The line is order matching. The moment you match one client against another, you start to look like financial infrastructure, and infrastructure needs FINMA authorisation. Narrow exceptions exist for matching limited strictly to payment tokens, but that's a case-by-case assessment, not a design assumption.


If your product spec contains the words "order book," budget for a regulatory opinion before you budget for engineers.


Custody — where most models actually break

Custody in Switzerland isn't one thing. It's a spectrum, and where you land is decided by your plumbing, not by what you call it in your pitch deck. Three questions decide it: are assets pooled or segregated, for how long, and who controls the keys?



Pooled or omnibus custody works, but only inside the deposit-taking exemptions. Broadly, that means one of three shelters: funds held briefly for settlement purposes, in a window measured in weeks rather than years; the sandbox exemption allowing acceptance of up to CHF 1 million provided you pay no interest, don't invest the funds, and tell clients they sit outside FINMA supervision and deposit protection; or funds loaded onto a payment instrument such as a prepaid card. Step outside all three and you are accepting public deposits, which is banking.


Segregated custody removes the caps. No amount limit, no time limit, held off balance sheet. Where you hold the keys, you carry a continuous obligation to keep the assets fully and immediately available to the client, you can't pay interest on them, and AML obligations apply. In a non-custodial setup the client keeps control of their keys, amounts and duration are unlimited, and AML duties can still attach depending on what else you do for them.

The practical takeaway: if your roadmap involves holding meaningful client balances, segregation isn't a nice-to-have. It's the difference between a viable SRO model and a banking licence application.


Staking — one specific thing to check

Non-custodial staking is permitted without SRO membership and without AML obligations attaching. Segregated custodial staking is permitted, with AML obligations, provided each client is assigned a single blockchain address used consistently for custody, staking and withdrawal. Pooled custodial staking is not permitted.


That last line is the single most common product feature I send back to the drawing board. It's almost always an engineering decision made months before anyone thought to ask a compliance question — and almost always fixable at the design stage, at roughly a tenth of the cost of fixing it afterwards.


Payments and cards — workable, with a partner

Payment facilitation and processing, fiat and crypto transfers, and electronic transfers including third-party outbound payments in fiat are all within scope, subject to how your settlement account is structured.


Card issuance is a different animal. Debit cards are workable where the underlying holdings comply with the custody rules, or where a licensed third party provides custody and the end customer has a direct contractual relationship with that party, which is legally obliged to repay or transfer the funds. Credit cards are possible in defined circumstances. In both cases, issuance is realistically structured through a licensed card network member — a BIN sponsor or principal member — who supplies the regulatory and technical rails. You're renting someone else's licence, and their risk appetite becomes yours.


Asset management — narrower than it sounds

Advisory or discretionary mandates over crypto assets classified as payment or utility tokens are permitted, on a segregated basis. Managing or investing securities, asset tokens or fiat on a client's behalf is not.



Substance: less than you fear, more than you hope

Switzerland doesn't do letterboxes, but it also doesn't demand a hundred-person office on day one. The minimum shape of a Swiss VASP is roughly this:

  • A Swiss-domiciled director or board member with sole signing rights, to satisfy substance requirements

  • A Swiss-domiciled AML Officer, plus a deputy or second person with access to AML data — both of which can be outsourced

  • An external AML auditor, with an audit conducted annually

  • A physical office and Swiss servers


Then comes the requirement that gets skipped in planning and scrambled over later. Within one year of obtaining membership you need a local employee doing real work — business development, operations or both — and a local board member or manager with genuine decision-making authority and sole signing rights.


Plan for that person from the start. Not because the rule is strict, but because it's the reason a Swiss membership still means something to your bank, your investors and your institutional counterparties. Jurisdictions that let you run on paper produce licences worth exactly what they cost.


On the AML Officer function specifically, outsourcing is common and, done properly, better than the alternative: you get someone who already has working relationships with the SRO and the auditor rather than a first-timer learning on your file. I've set out how that arrangement works in practice, including where outsourcing ends and consulting begins. The responsibility never leaves your board either way.



The timeline, and what actually makes it slip

The realistic shape is about a month for incorporation, three to four months for the application and SRO review, and a final month for operational implementation. Live and serving clients in five to six months from a standing start.


Whether you hit that isn't down to the SRO. It's down to two things.


Document readiness. The business plan and the AML policy have to describe the same company. It sounds obvious. It's the most common reason files stall — a business plan written for investors and an AML policy written from a template, describing two businesses that only partly overlap.


Complexity of the business case. A straightforward brokerage moves fast. A model with novel custody mechanics, a token that needs classifying, or a cross-border structure may need a legal opinion or a FINMA no-action letter. Both add weeks. Both are usually worth it, because certainty purchased at the start is cheaper than certainty litigated at the end.

Then there's the admission interview, attended by the AML Officer together with the CEO or board president. It isn't a formality. Expect to be walked through a specific transaction: how it enters your system, what triggers an alert, who looks at it, what happens if that person is on holiday. The answer that works describes your operating model. The answer that doesn't quotes your policy.


If you want the process broken down step by step, from discovery through documentation to submission, I've laid it out here.



What changes in 2026 and 2027

Three things are moving at once, and they don't all move in the same direction.

The FinIA reform will narrow the SRO perimeter. In October 2025 the Federal Council opened a consultation on amendments to the Financial Institutions Act, proposing two new FINMA-supervised licence categories: payment instrument institutions, replacing the 2018 FinTech licence, removing the CHF 100 million deposit cap and reserving stablecoin issuance to this category; and crypto-institutions, covering custody, client trading and staking. The consultation closed on 6 February 2026. A dispatch to Parliament and parliamentary debate follow, with entry into force realistically 2027 at the earliest, plus a transition period.


My read: SROs aren't going away, but the custody-and-trading end of the current perimeter is heading toward direct FINMA supervision. Non-custodial intermediaries, brokerage desks and payment businesses should expect the SRO to remain their home. If you're custody-heavy, plan on the assumption that you'll eventually sit inside the FINMA perimeter, and build a compliance function that survives the upgrade rather than one that just clears admission.


The transparency register arrives on 1 October 2026. The Federal Act on the Transparency of Legal Entities, together with a partial revision of the AMLA, enters into force then. It creates a federal, non-public beneficial ownership register that most Swiss legal entities must report into, with transitional periods meaning first filings for many structures land in late 2026 or early 2027.


Two practical consequences. If your ownership structure is layered, opaque or simply undocumented, fix it now rather than under a filing deadline. And the same revision extends AMLA duties to certain advisory activities for the first time, meaning some advisory firms will discover they need SRO affiliation who have never thought about it.


FINMA tightened the custody screws in January 2026. Guidance 01/2026, published on 12 January, addresses custody of crypto-based assets. It's aimed at FINMA-supervised institutions rather than SRO members, so it doesn't bind you directly — but read it anyway, because it shows where supervisory thinking is going: client-level segregation, genuine bankruptcy remoteness, and accountability that stays with the Swiss institution even when custody is delegated down a chain of sub-custodians.


There's a second-order effect worth knowing. It changes what FINMA-supervised institutions can accept from custodians who are only SRO-supervised. If part of your commercial model is serving Swiss regulated institutions, that conversation just got harder.



When Switzerland is the wrong answer

Some of the most useful advice I've given clients has been about where not to do things in Switzerland. A structure you have to defend every year costs more than the one you never built.


Switzerland is probably not your answer if:

  • You're targeting EU retail. Switzerland sits outside MiCA. Actively marketing into the EU — localised pages, paid acquisition, affiliates, direct sales — points toward a MiCA CASP authorisation or a licensed EU partner. Reverse solicitation is a narrow exception, not a market-entry strategy.

  • You want to run a venue. Order matching is infrastructure. Different licence, different capital, different timeline.

  • Security tokens or derivatives are the core product. Outside the SRO framework by definition.

  • Pooled custodial staking is the product. Not permitted, and no amount of structuring fixes it.

  • You need to hold large fiat balances indefinitely and unsegregated. That's a bank. Apply as one, or redesign.

  • You can't put real decision-makers in Switzerland. The substance requirements are the point, not an obstacle to route around.


The right answer is often a split: some activities in Switzerland, others in a jurisdiction that fits them better. That isn't a failure of the Swiss framework. It's what using it well looks like.



Five questions before you spend money

  1. What am I doing, in verbs? Holding, matching, transferring, advising, issuing. Nouns like "platform" and "ecosystem" hide the regulatory trigger. Verbs expose it.

  2. Do I ever control client assets or keys, and are they pooled? This one question decides more of your regulatory outcome than anything else on the list.

  3. Who is my client and where do they live? Distribution questions often bite before Swiss ones do.

  4. What token types am I touching? Payment and utility are one world. Security tokens are another.

  5. Who in Switzerland has real decision-making authority, and when do they start? If the honest answer is "we'll figure that out later," you've found your first bottleneck.


Switzerland remains one of the few places where you can go from incorporation to a regulator-recognised financial intermediary in under six months, under a framework built by people who understood the technology. That window is still open, and for most business models the SRO route is still the smart entry point.


But the framework rewards precision. Get the perimeter right at the design stage and everything downstream is straightforward. Get it wrong, and you spend a year and a good deal of money discovering that your product was never the one you were allowed to build.


I spent four years as COO and then CEO of a Swiss SRO-affiliated crypto brokerage, acting as AML Officer through regulatory and financial audits, and earlier contributed to one of Switzerland's first FINMA crypto asset manager licence applications. Today I act as external AML Officer for financial intermediaries and VASPs in Switzerland, and take companies through the SRO application from first scoping to admission.


This article is for informational purposes, isn't exhaustive, and doesn't constitute legal advice. Requirements depend on the specific business case and have to be assessed individually.

 
 
bottom of page