DeFi protocol frontend in Switzerland
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Switzerland with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- KYC mandatory for transactions exceeding CHF 1,000 per month; must prove ownership of non-custodial wallets (ch.aml.threshold-kyc-mandatory-for-transactions)
- Enhanced Due Diligence (EDD) required for high-risk clients (e.g., PEPs), unusual transactions, or third-party involvement (ch.aml.enhanced-due-diligence-edd-required)
- Joining a recognized SRO (e.g., VQF, SO-FIT, AOOS) with full KYC/CDD compliance, record-keeping, and reporting obligations (ch.aml.anti-money-laundering-act-amlagwg-core)
- Collect personally identifiable information (PII) for identity verification (ch.aml.collect-personally-identifiable-information-pii)
- Internal controls, staff training, and transaction monitoring (e.g., blockchain analytics for amounts over CHF 1,000) (ch.aml.internal-controls-staff-training-and)
- Retain client identification data, beneficial owner details, and transaction records for at least 10 years (ch.aml.retain-client-identification-data-beneficial)
- Suspicious activity reporting to MROS (Money Laundering Reporting Office Switzerland) (ch.aml.money-laundering-reporting-office-switzerland)
- Conduct regular risk-based reviews to keep KYC data current (ch.aml.conduct-regular-risk-based-reviews-to)
- Travel Rule obligations apply (ch.licensing.legislation-amla-anti-money-laundering-act)
Key Restrictions
- If the frontend takes fees (e.g., swap fees, routing fees), it acts as a financial intermediary and must join an SRO and comply with AMLA (ch.licensing.technology-neutrality-regulation-focuses-on)
- If the frontend holds or takes custody of user crypto assets, a FinTech license (CHF 300K capital) or banking license (CHF 10M+) is required (ch.licensing.custody)
- Geofencing required if the frontend does not implement KYC — must block Swiss residents when aggregated transaction volume exceeds CHF 1,000/month to avoid triggering AML obligations (ch.aml.threshold-kyc-mandatory-for-transactions)
- Regulation focuses on economic function, not technology — operating a DeFi frontend that intermediates transactions is treated similarly to a VASP under Swiss law (ch.licensing.technology-neutrality-regulation-focuses-on)
Key Risks
- FINMA may treat any fee-collecting frontend as a financial intermediary regardless of the protocol's decentralization (ch.licensing.technology-neutrality-regulation-focuses-on)
- Ambiguity around whether a non-custodial, fee-free frontend aggregator with full geofencing is regulated — FINMA has not issued specific DeFi frontend guidance
- Enforcement risk: FINMA has taken action against unlicensed crypto intermediaries in the past, and the trend is toward expanding VASP classification
- SRO membership (1-3 months) is straightforward but brings recurring compliance costs; failure to join can result in criminal liability under AMLA
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Technology Neutrality: Regulation focuses on the economic function and purpose of an asset or activity, not the underlying technology. This means that if a crypto asset or service performs a function traditionally regulated by financial law, it will be subject to those regulations.
VASP: Activity-dependent — no single 'crypto license'. SRO membership (1-3 months, no minimum capital): exchange, brokerage. FinTech license (3-6 months, CHF 300K): deposit-taking up to CHF 100M without lending. Banking license (12-18 months, CHF 10M+): full banking. DLT Trading Facility (6-12 months): multilateral DLT securities trading.
CUSTODY: Banking license or FinTech license required for holding client crypto assets. DLT Act provides legal certainty — client crypto segregated in custodian bankruptcy.
AMLA (Anti-Money Laundering Act) (1998) — AML/CFT for VASPs — strict KYC/CDD, suspicious activity reporting, Travel Rule
Anti-Money Laundering Act (AMLA/GwG): Core legislation mandating AML/CFT obligations for financial intermediaries, including VASPs handling cryptocurrencies, custodians, and exchanges. It requires joining a recognized SRO and full compliance with KYC, record-keeping, and reporting.
Threshold: KYC mandatory for transactions exceeding CHF 1,000 per month; prove ownership of non-custodial wallets.
Enhanced Due Diligence (EDD): Required for high-risk clients (e.g., PEPs), unusual transactions, or third-party involvement; includes ongoing risk reviews and client segmentation.
Collect personally identifiable information (PII) to prevent fraud, identity theft, and money laundering.
Internal controls, staff training, and transaction monitoring (e.g., blockchain analytics for amounts over CHF 1,000) are required.
Retain client identification data, beneficial owner details, and transaction records for at least 10 years (per AMLA standards).
Money Laundering Reporting Office Switzerland (MROS): Handles suspicious activity reports under AMLA.
Conduct regular, risk-based reviews to keep data current; applies to both supervised and SRO-affiliated VASPs.
FINMA — All financial market supervision — licensing, AML enforcement, ICO/STO guidance, stablecoin regulation
SROs (VQF, SO-FIT, AOOS) — Self-regulatory organizations for financial intermediation — common path for smaller crypto businesses
Definition: Tokens intended to be used purely as a means of payment and are not linked to a specific project. Examples: Bitcoin, Ether.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — Operating a DeFi protocol frontend in/from Switzerland is treated as a regulated financial intermediary activity under AMLA if the frontend takes fees or facilitates transactions above CHF 1,000/month per user, requiring SRO membership and full KYC/CDD obligations; non-custodial, fee-free frontends that geofence Swiss users may avoid licensing but face regulatory ambiguity.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?