01
Functional perimeter map
- Client money
- Who accepts, stores and transfers funds
- Payment initiation
- Who gives instructions to the bank on behalf of the client
- Account information
- Who aggregates and displays bank data
- Credit
- Who finances and bears the credit risk
- Investment
- Advice, dealing, arranging, custody and management
- Crypto
- Exchange, brokerage, custody, portfolio and issuance
- Insurance
- Underwriting, brokering and distribution
02
CR does not replace CBB license
The MOIC registers the legal entity and activities, and the CBB authorizes regulated financial activities. Category, permitted services, capital, controllers, key persons, systems and safeguarding are determined before the final operating model is developed.
03
Payment Service Provider
For acquiring, payment processing, wallets, money transfer and other payment functions, PSP perimeter Volume 5 is checked. The model describes the flow of funds, settlement, merchant/customer contract, safeguarding, reconciliation, complaints, outsourcing, fraud and operational resilience.
EU terminology does not transfer mechanically to Bahrain. The actual CBB category and permitted services are used on the client’s website and in documents.
04
AISP, PISP and open banking
Account information and payment initiation are divided by function. Customer consent, strong authentication, API security, data minimization, incident response and a clear distribution of responsibilities between the bank, provider and customer are required.
05
Crypto-assets and stablecoins
Crypto-asset services and stablecoin issuance are analyzed using a special CBB framework. Token label does not solve the issue: the rights of holder, reserve assets, redemption, custody, trading, promotion, technology, market abuse and AML/CFT are assessed.
- Exchange / brokerage
- Category and permitted crypto-asset services
- Custody
- Keys, segregation, recovery and cyber controls
- Stablecoin
- Issuer, reserve, redemption and disclosure
- Marketing
- Fair, clear and within permitted perimeter
- Cross-border
- Local license and restrictions of each target country
06
Regulatory Sandbox - test, not license
Sandbox is available to eligible local/foreign fintech and existing licensees for an innovative solution with customer benefits and controlled risks. The CBB specifies a trial period of up to 12 months. The participant creates a Bahrain company; If funds from volunteer customers are used, a bank account is required. Sandbox participant status cannot be presented as a CBB license.
07
Corporate route
- 01Perimeter memo
Product, features, funds/data flow and exclusions.
- 02Regulatory route
Direct license, sandbox, partner or unregulated tech.
- 03Entity
Legal form, controllers, capital and MOIC activity.
- 04Application
Business plan, governance, policies and systems.
- 05Build and test
Conditions, integrations, audit and readiness.
08
What does the regulator check?
Controllers, board, CEO, compliance, MLRO, risk and technology.
Source, minimum, runway and prudential reporting.
AML, safeguarding, cyber, outsourcing and complaints.
Architecture, access, testing, BCP/DR and incident reporting.
09
Application pack
- Business plan
- Market, customers, revenue and three-year forecast
- Programme of operations
- Each service and end-to-end process
- Ownership
- Controllers, UBO, source of funds and group
- Governance
- Committees, reporting lines and fit-and-proper evidence
- Policies
- AML/CFT, risk, compliance, cyber, outsourcing, conduct
- Agreements
- Customer, merchant, bank, processor and cloud/vendor
- Readiness
- Demo, testing, bank account and operational evidence
10
Route selection
- New product needs to be tested
- Sandbox when executing criteria
- Payment service for clients
- PSP/accurate CBB category
- Only software for licensed bank
- Tech/outsourcing model with bank accountability
- Account aggregation
- AISP perimeter
- Payment initiation
- PISP perimeter
- Crypto / stablecoin
- Special CBB framework
- Go-live without license
- Not valid for regulated service
+7 (495) 221 31 46