What License Does Our Payments Business Actually Need?

We assess your business model, activities, jurisdictions, and flow of funds to determine which licenses, registrations, or exemptions may apply.

The most expensive mistake in payments is often made before the first customer arrives. A founder describes the company as a “fintech,” a “remittance platform,” a “crypto payments business,” or a “global wallet,” then starts shopping for whatever license appears to match the label. The problem is that regulators do not license labels. They regulate activities, control over funds, customer relationships, geography, and risk.

A license analysis therefore begins with a less glamorous question: what exactly happens to the money, from the moment a customer initiates a transaction until the beneficiary can use the funds? That movement—not the pitch deck—is the real product.

The direct answer is that there is no universal “payments license.” A business may need a money transmitter license, payment institution authorization, electronic money authorization, virtual-asset registration or authorization, consumer-credit permission, acquiring approval, foreign-exchange permission, or a combination of these. It may also be able to operate through a regulated sponsor, as an authorized delegate or agent, under a carefully tested exemption, or by redesigning the flow so that it never performs the regulated activity itself.

The correct route is found by mapping the business model before selecting the license.

Start with the Activity, not the Company Name

Two companies can use nearly identical websites and require completely different regulatory structures. One may merely provide software that sends payment instructions to a bank. The other may receive customer funds, hold them overnight, convert them, and direct a payout through a third party. To a user, both products may look like a “send money” button. To a regulator, one may be a technology vendor and the other a money transmitter.

The activity map should answer six questions:

  1. Who receives the customer’s money?

  2. In whose name is the relevant account or wallet held?

  3. Who has legal or practical control over the funds?

  4. Who decides when, where, and to whom the money is released?

  5. Does the customer retain a stored balance or redeemable claim?

  6. Is value converted between currencies, crypto-assets, or other instruments

A seventh question is often decisive: who bears the obligation to the customer if the transaction fails? A company can outsource technology, KYC, settlement, and even customer support, yet still remain the party that has promised to deliver the funds. That obligation can keep the company inside the regulatory perimeter.

What license do we need - Faisal Khan LLC

The Licensing Stack has Several Layers

Licensing discussions become confused because founders use “license,” “registration,” “approval,” “exemption,” and “sponsorship” as if they were interchangeable. They are not.

A registration may place a company on a government database and subject it to anti-money-laundering obligations, but it may not authorize the company to conduct every activity in every location. In the United States, for example, federal MSB registration with FinCEN is an important Bank Secrecy Act requirement, but it does not replace state money-transmitter licensing where state law requires it. At the other extreme, a state license may authorize activity in that state but does not automatically solve federal obligations, banking access, or another state’s requirements.

An exemption is narrower still. It means a law does not apply, or applies differently, when specified facts are present. An exemption is not a portable license. It cannot be carried into a different transaction, state, customer segment, or country merely because a company owns an entity formed in the exempting jurisdiction.

Sponsorship and agency models are contractual operating routes. They can enable a business to enter a market under the regulatory umbrella of a licensed principal, but they do not erase compliance. The sponsor will impose its own underwriting, customer, product, geography, reserve, reporting, and operational requirements. The company gains speed but gives up some control and economics.

The Five Dimensions that Determine the Answer

1. The Regulated Activity

The first dimension is what the company actually does. Common triggers include receiving money for transmission, holding customer funds, issuing stored value or e-money, converting currencies, facilitating card payments, acquiring merchants, providing crypto custody, operating an exchange, arranging credit, or A product may contain several regulated activities at once. A “multicurrency wallet” may involve receiving funds, safeguarding, e-money issuance, foreign exchange, payment execution, and cross-border settlement. A stablecoin payout product may combine fiat collection, crypto conversion, wallet control, virtual-asset transfer, and local cash-out.

The license analysis must separate the product into these functional components. Treating the entire product as one activity usually hides the most important trigger.

2. The Flow of Funds

The second dimension is custody and control. Regulators and banks will want to know where funds sit, whose balance sheet or trust structure holds them, whether funds are commingled, how they are reconciled, and who can move them.

A diagram that shows only “customer → platform → recipient” is insufficient. A serious flow-of-funds map identifies the legal entity at every step, the account title, the bank or custodian, the asset, the timing, the ledger entry, the settlement instruction, the fees, and the failure path. It should also show who returns money if a payout fails.

This is why the words “we never touch the funds” require evidence. If the company can instruct a bank or provider to move customer money, controls the user balance, or determines the beneficiary, it may exercise enough control to attract regulation even if the funds never pass through its operating bank account.

3. Geography

The third dimension is geography, and it is more complicated than the place of incorporation. Relevant locations may include the customer’s residence, the sender’s location, the beneficiary’s location, where the transaction is initiated, where funds are received, where the company markets, where employees perform regulated functions, and where accounts or wallets are maintained.

A Delaware company does not become nationally licensed by being incorporated in Delaware. A European company does not necessarily avoid U.S. rules when it serves U.S. customers or uses U.S. payment infrastructure. A Canadian MSB registration does not answer whether the business is also a payment service provider subject to the Bank of Canada’s retail-payments regime. Geography follows activity and nexus, not branding.

4. Customer and Product Type

The fourth dimension is who uses the product and for what purpose. Consumer remittances, B2B supplier payments, marketplace settlement, payroll, gaming, crypto trading, charitable transfers, and high-value treasury transactions create different legal and supervisory questions.

The same payment rail can be low risk in one context and unacceptable in another. A domestic B2B payment between verified companies is not assessed like a consumer cash remittance into a sanctioned or high-risk corridor. The product’s limits, funding methods, payout methods, speed, reversibility, and anonymity all influence the regulatory analysis.

5. The Role the Company Chooses to Play

The fifth dimension is strategic. A company can decide to be the regulated principal, a program manager, a distributor, an agent, a technology provider, a marketplace, or an introducer. Each role brings a different balance of control, cost, revenue, liability, and dependence.

Sometimes the best licensing decision is not to obtain a license immediately. A sponsor model may validate demand faster. Sometimes sponsorship becomes too restrictive and the company should begin its own licensing program. In other cases, the activity can be redesigned so that a regulated institution contracts directly with the customer and the technology company never controls funds. The goal is not to collect licenses. It is to build a lawful, bankable, scalable operating model.

A Practical Licensing Decision Matrix

Business feature

Likely regulatory significance

Questions to resolve

Receiving funds from customers

May trigger money transmission or payment-services rules

Who receives, owns, and controls the funds?

Customer balance or wallet

May involve stored value or e-money

Is the balance redeemable and who owes it?

Currency conversion

May add FX, money transmission, or crypto obligations

Who is principal to the conversion and how is pricing set?

Crypto custody or transfer

May trigger virtual-asset authorization and AML duties

Who controls private keys and initiates transfers?

Merchant settlement

May involve acquiring, payment facilitation, or agency rules

Who contracts with merchants and bears chargeback risk?

Cross-border customers

Creates multiple regulatory nexuses

Where are customers, counterparties, accounts, and marketing?

Sponsor or licensed principal

Can accelerate market entry

What activity remains with the program and what does the sponsor control?

Claimed exemption

May remove a requirement only in narrow facts

Is the exemption transaction-specific, state-specific, or activity-specific?

Three Recurring Traps

The first trap is buying a company because its seller describes it as “licensed.” A company may have a federal registration, a local exemption, a dormant permission, or an authorization that does not cover the intended activity. Even a genuine license may be unusable if it cannot survive a change of control, has no operating history, lacks required capital, or has unresolved compliance issues.

The second trap is assuming a bank account proves regulatory legitimacy. Banks conduct their own risk analysis. A company can be properly licensed and still be rejected because its corridors, customer types, ownership, transaction monitoring, or expected volumes fall outside the bank’s appetite. Conversely, an account opened for ordinary corporate expenses does not authorize the company to receive or safeguard customer money.

The third trap is confusing an outsourced function with an outsourced obligation. Hiring a compliance vendor does not transfer regulatory accountability. Using a licensed exchange does not automatically make a fiat-to- crypto payment product unregulated. Using a bank’s API does not necessarily make the business a software company. The substance of the customer promise remains central.

What a Proper Licensing Assessment Should Produce

A professional assessment should not end with a one-line answer such as “you need an MSB.” It should produce a decision package:

  • A product and activity map;

  • A detailed flow-of-funds diagram;

  • A jurisdiction and nexus analysis;

  • A list of likely licenses, registrations, exemptions, and contractual models;

  • Assumptions that could change the conclusion;

  • A comparison of own-license, acquisition, sponsor, and agent routes;

  • A sequence for banking, compliance, technology, and partner onboarding;

  • A list of prohibited or deferred features for the first launch;

  • A budget and critical-path estimate; and

  • A clear recommendation with fallback options.

This output becomes the foundation for regulator conversations, legal opinions, bank applications, sponsor underwriting, compliance design, and investor planning. Without it, each adviser answers a different version of the business and the company accumulates contradictory advice.

The Answer is a Structure, not a Certificate

The correct license is the one that fits the activity, geography, customer promise, custody model, and route to market. It must also work with the company’s bank, sponsor, liquidity providers, technology, and compliance capabilities. A permission that exists only on paper is not a commercial solution.

For an early-stage company, the right answer may be a sponsor and a narrow product. For an established operator, it may be a multijurisdictional licensing program. For a buyer, it may be the acquisition of a genuinely operational regulated company. For a technology business, it may be a redesign that keeps regulated activity with licensed institutions.

The discipline is the same in every case: map the money, identify the obligation, test the nexus, and then choose the authorization. Everything else is decoration.

How Faisal Khan LLC Can Help

Faisal Khan LLC helps payment companies, fintechs, remittance operators, crypto businesses, marketplaces, and investors determine what regulatory structure their business model actually requires. The work begins with the product and flow of funds, then connects licensing, banking, sponsorship, compliance, liquidity, and operating partners into a practical route to market.

A structured assessment can determine whether the better path is a new application, an acquisition, a sponsor or authorized-delegate arrangement, an exemption analysis, or a redesigned model. The objective is not to sell a particular license. It is to identify the structure that can lawfully operate, obtain banking, pass partner diligence, and scale.

Request a Licensing Assessment

Start with the business model, flow of funds, jurisdictions, counterparties, and intended transaction. The assessment is designed to identify the viable structure, the missing dependencies, and the route that can withstand bank, provider, regulator, and operational scrutiny.

Selected Authoritative References

These references support the current regulatory and supervisory context. They are not a substitute for jurisdiction-specific legal advice.

  1. FinCEN - Money Services Business Registration

  2. CSBS - Money Transmission Modernization Act

  3. New York DFS - Virtual Currency Business Licensing

  4. Bank of Canada - Retail Payments Supervision

Share
Page Last Updated: 04/Aug/2026 (5470397)