Need a structured review of a Swiss SRO target? Contact Faisal Khan with the information memorandum, company name, asking price, and intended post-acquisition business.
1. Corporate Due Diligence
Request:
current commercial-register extract;
articles of association;
incorporation documents;
share register;
shareholder agreements;
board minutes;
authorized signatories;
historical changes;
group structure;
subsidiaries/branches;
material powers of attorney.
Confirm that the seller actually owns or controls the shares being sold.
2. Share Capital
For a Swiss AG, verify:
nominal capital;
amount paid in;
amount unpaid/callable;
share classes;
treasury shares;
shareholder loans;
whether stated company cash still exists;
any pledges or encumbrances on shares.
A company advertised as “CHF 100,000 capital” may have only CHF 50,000 paid or may have deployed the historical cash long ago.
3. SRO Status
Verify independently:
recognized SRO name;
active membership status;
membership number;
date of admission;
current category;
current business-activity description;
any conditions on admission;
pending changes/mutations;
SRO correspondence.
Do not rely exclusively on a PDF certificate supplied by the seller.
The broader Swiss SRO acquisition page explains why the SRO status should be evaluated together with banking and operations.
4. AML Audit and Compliance History
Request, subject to lawful disclosure:
all AML audit reports;
management letters;
deficiencies;
remediation plans;
SRO warnings/sanctions;
open supervisory matters;
annual self-declarations;
AML policies;
enterprise risk assessment;
training records;
compliance testing;
suspicious-activity escalation procedures.
A company described as “no clients / no activity” should have records consistent with that statement.
5. AML Officer and Management
Verify:
employment/outsourcing contract;
qualifications;
VASP experience;
time commitment;
notice period;
change-of-control rights;
compensation;
deputy/backup arrangements;
willingness to remain after sale.
If the asking price assumes the AML Officer remains, that assumption should be documented.
6. Banking
For every bank/payment provider, obtain:
account-opening confirmation;
recent statements;
signed terms;
KYC/business description;
known transaction limits;
currencies;
payment rails;
crypto permissions;
client-fund permissions;
current compliance queries;
change-of-control terms;
termination notices.
For high-value targets, banking should be verified directly where the process permits rather than inferred from screenshots.
See global banking infrastructure for the difference between a corporate account and a production payment stack.
7. Customer Accounts and IBANs
If the target advertises IBANs, request:
actual provider agreement;
regulatory status of provider;
account structure;
named vs virtual vs pooled design;
eligible countries;
pricing;
KYC responsibility;
safeguarding/segregation;
crypto acceptance;
production status;
change-of-control requirements.
“Potential” or “integration available” should not be valued like a signed program.
8. Custody
Request:
wallet architecture;
private-key/MPC control matrix;
individual vs omnibus addresses;
Fireblocks/Copper/other contracts;
insolvency analysis;
custody terms;
supported assets;
hot/cold wallet policy;
security audits;
incident history;
insurance;
FINMA/SRO regulatory analysis.
Collective custody can create a different licensing perimeter from individually attributable wallets.
9. KYC, Blockchain Analytics and Travel Rule
Verify live contracts and production status for:
KYC/KYB;
sanctions/PEP;
transaction monitoring;
blockchain analytics;
Travel Rule;
case management;
fraud tooling.
Check data ownership and whether historical customer data can legally transfer with the company.
10. Technology and IP
For a target including a “proprietary platform,” verify:
source-code ownership;
Git repository ownership;
developer assignments;
third-party libraries;
software licenses;
cloud accounts;
domains;
trademarks;
API contracts;
security testing;
data-protection documentation;
administrator access.
A white-label platform licensed month-to-month is not proprietary IP.
11. Customers and Transaction History
If active, review:
customer count;
geographic breakdown;
customer type;
monthly transaction volume;
average ticket;
revenue;
chargebacks/fraud;
complaints;
blocked/frozen customers;
high-risk clients;
concentration;
sanctions exposure.
If the company is advertised as clean with no clients, verify that bank statements and accounting support the claim.
12. Financial, Tax and Liabilities
Review:
audited/reviewed accounts;
management accounts;
bank reconciliation;
accounts payable/receivable;
shareholder loans;
taxes;
VAT;
payroll/social contributions;
leases;
guarantees;
litigation;
creditor claims;
contingent liabilities.
A “no liabilities” representation should become a contractual warranty, not remain marketing text.
13. Regulatory Perimeter of the Buyer's New Model
The buyer's future activity may be very different from the seller's historical activity.
Prepare a gap analysis covering:
new countries;
new products;
custody changes;
client balances;
new tokens;
stablecoins;
cards;
IBANs;
higher volumes;
retail customers;
institutional clients.
Determine what must be notified to VQF and what may require separate FINMA or foreign authorization.
14. Change-of-Control Checklist
Identify notifications/consents for:
VQF;
commercial register;
bank;
AML Officer;
auditor;
custody provider;
KYC provider;
liquidity providers;
customer-account provider;
card/BIN sponsor;
landlord;
insurers;
major contracts.
Our general buyer and seller due-diligence framework can be used alongside the Swiss-specific checklist.
15. Transaction Protections
Depending on findings, consider with counsel:
conditions precedent;
warranties;
indemnities;
escrow;
purchase-price holdback;
working-capital adjustment;
seller cooperation covenant;
non-circumvention/confidentiality;
bank/vendor continuity conditions;
termination right if critical infrastructure is lost.
Related Swiss SRO Guides
Related reading: buying a Swiss SRO company and Swiss SRO banking and PostFinance.
Frequently Asked Questions
What is the single most important diligence item?
There is no single item, but regulatory standing, banking continuity, liabilities, and the fit between current and future activities are usually critical.
Can I rely on the FINMA/SRO member search alone?
It confirms an important status point but does not tell you the company's liabilities, banking permissions, audit findings, or future-model fit.
How do I verify “no commercial activity”?
Review accounting, bank statements, customer records, invoices, AML files, tax filings, and management representations.
Should due diligence happen before the purchase agreement?
At least core diligence should happen before an unconditional purchase commitment. Detailed sequencing depends on the deal.
Regulatory References
Run Swiss SRO Due Diligence Before You Value
The purpose of diligence is not merely to find defects. It is to determine exactly what the buyer is acquiring and what should be reflected in price and closing conditions.
Contact Faisal Khan to discuss due diligence for a Swiss SRO company.
