Financial institutions · FinTech

Financial licences: PSP, EMI, exchange house and bank

We design a regulated business from product to filing: licensing perimeter, jurisdiction and legal form, capital, owners, governance, AML/CFT, technology, safeguarding and banking infrastructure.

Perimeterproduct and client money
Ownerscontrol and source of funds
ControlsAML · sanctions · risk
Launchlicence before business

01

Describe the product before choosing an attractive licence label

The analysis identifies whose money the firm receives, the legal basis for holding or transferring it, who provides an account or IBAN, and who performs FX, acquiring, remittance, card issuing, lending, custody, brokerage or virtual-asset activity. Similar interfaces can conceal different regulated functions. Agency, outsourcing and white label do not remove licensing risk where the firm actually provides a regulated service or controls client money.

Product
Services, customers, contracts and every movement of money
Regulator
Country, competent authority and category
Capital
Regulatory floor, runway and liquidity
People
Board, CEO, compliance, MLRO, risk, finance and IT
Systems
Ledger, screening, monitoring, security and reporting
Partners
Safeguarding, settlement, cards, FX and correspondents

02

PSP, EMI, exchange business and banking permissions are different

The category defines permitted services, clients, territories, capital, safeguarding, reporting and supervision. The UAE requires a separate analysis of CBUAE payment, stored-value and exchange-business regimes and of financial-free-zone rules. Oman places PSPs and payment systems within the CBO perimeter; Bahrain uses categories under the CBB Rulebook. Ordinary company registration, a trade licence or a sandbox does not replace regulated permission.

03

Capital without suitable owners and management is not a licence project

The regulator reviews direct and ultimate owners, controllers, source of capital and wealth, reputation, conflicts and group transparency. Board, CEO, compliance, MLRO, risk, finance, internal audit and technology resources should fit the category, scale and outsourcing model. Minimum capital is only a floor; the business plan, pre-break-even cost, liquidity and ability to meet client obligations also matter.

Client money cannot be accepted merely because an application is pending

Pre-application, sandbox, in-principle approval and a filed application have different effects. Business begins only within the scope and from the date permitted by law and the regulator's decision.

04

AML/CFT, sanctions and technology should work before filing

The framework covers enterprise risk assessment, customer-risk methodology, CDD/EDD, PEP and sanctions screening, transaction monitoring, suspicious-activity reporting, fraud, complaints, data, cyber security, incident response, business continuity and independent testing. Policies must reflect the product, countries, channels and actual systems. Virtual-asset models also require VASP perimeter and travel-rule analysis.

05

A licence does not automatically produce safeguarding or correspondent accounts

Launch requires realistic relationships with a bank or eligible safeguarding institution, settlement and card partners, FX and liquidity providers and, for cross-border transfers, payment rails and correspondents. Each conducts institutional KYC on the licence or application, ownership, financial model, clients, countries, AML/CFT controls, expected flows and downstream access.

06

Licensing workstream

  1. 01

    Map the product, contracts, users, countries and full funds flow.

  2. 02

    Match functions to permissions and select a jurisdiction without regulatory arbitrage.

  3. 03

    Prepare ownership, source of funds, governance, team and financial model.

  4. 04

    Design AML/CFT, safeguarding, technology, outsourcing and risk controls.

  5. 05

    Conduct pre-application and prepare forms, policies and evidence.

  6. 06

    Answer regulatory requests, satisfy conditions and only then launch.

07

Financial licence questions

Can an existing licence be acquired?

A change of control normally requires prior approval and review of the buyer, funds and business plan. A licence is not transferred like an ordinary asset.

Can we operate under a partner's licence?

Only where the actual agency or outsourcing model is permitted by law and the partner's licence. A contract does not alter the real service.

Does a sandbox guarantee licensing?

No. It may permit limited testing on regulator conditions but does not replace a full assessment and final licence.

When is the bank account opened?

Institutional banking runs in parallel, but the bank decides timing and conditions. Regulatory approval does not compel account opening.

Legal basis

The competent regulator confirms the category and conditions

Official frameworks reflect the same principle: payment, exchange and client-money activities are licensed by substance and remain subject to supervision and AML/CFT duties.

01

CBUAE — Exchange Business Regulation

In-force licensing and supervision framework for currency exchange and money transfer in the UAE.

Open source
02

Central Bank of Oman — PSP Licensing Policy

Official licensing policy for payment service providers in Oman.

Open source
03

Central Bank of Bahrain — Licensing Directory

Official directory and route to the CBB Rulebook for regulated financial categories.

Open source
04

FATF Recommendations

International AML/CFT standards, including licensing and supervision of covered financial activities and VASPs.

Open source

Confidential consultation

Design the licence around the actual product

We map perimeter and funds flow, compare jurisdictions and prepare owners, team, policies, technology and banking infrastructure for filing and launch.

Discuss the matter
WAWhatsAppTGTelegram