<!-- canonical: https://cornerstonelicensing.com/webinars/crypto-licensing-legal-regulatory-operational-insights -->
<!-- updated: 2026-10-05T15:59:25.353Z -->
# Crypto Licensing: Legal, Regulatory & Operational Insights

> This webinar discusses the complexities of state licensing for crypto and digital asset businesses, focusing on how existing frameworks apply to these emerging models. It features insights from experts in regulatory compliance and operational readiness.

Recorded: 2026-10-05 | Runtime: 51 min

## Key takeaways

- The biggest trigger for money transmission licensing is receiving money for transmission and then transmitting the funds.
- Issuing stable coins or taking cash for digital assets can also be considered money transmission activities that require licensing.
- Pursuing a trust limited purpose charter may provide uniformity but comes with higher compliance burdens and capital requirements.
- It is essential to document the flow of funds clearly, showing both the deposit and redemption paths to regulators.
- After obtaining a license, companies must ensure they are doing what they committed to in their business plan and maintain compliance with their stated policies.

## Transcript

Hi everyone, good afternoon. Welcome to today's webinar. I'm Christy Young Barger, chief revenue officer with Cornerstone Licensing and we're excited to have Ryan Simo with Fractional and Tobias Moon with Chapman and Cutler with us today. Ryan Simmo is the CEO and founder of Fractional. He brings nearly 30 years of experience in banking, financial services, and regulatory compliance. He advises fintex, crypto companies, sponsor banks, and other financial institutions on building scalable risk and compliance programs with deep experience in digital access, BSA, AML, and the evolving regulatory landscape. Tobias Moon is a partner with Chapman and Cutler in the he is a me a partner in the banking and financial services department and compliance regulatory and payments group.

He advises financial service clients from startups to major institutions on consumer and commercial lending, compliance, product innovation, and UDAB risk. Tobias also guides banks, credit unions, and fintexs in building compliance programs, navigating licensing and shaping new financial projects, products, excuse me. Okay. Why are we here today? We are going to talk about as crypto and digital asset business mature, state licensing expectations are getting more complex. Today we are here for a practical discussion on how states apply existing licensing framework to digital assets where money transmission intersects with emerging models and the legal, regulatory and operational readiness required to scale. We hope we will walk you through with a clear insight on current trends, common licensing triggers and actionable items to build state-by-state plans in the rapidly evolving landscape.

Please know you're invited to share questions. I will be checking the chat and we will work those in as I see them pop up. One last housekeeping item before we jump in. This information is not intended to be legal advice and may not be used as legal advice. Legal advice must be tailored to the specific circumstances of each case. Every effort has been made to asssure this information is up to date. It is not intended to be a full and exhaustive explanation of the law in any way. However, nor should it be used to replace the advice of your own legal counsel. Okay, gentlemen, let's get started.

Let's talk about how states are applying existing licenses, licensing frameworks to digital assets. Going to lob this first question over. Which specific activities, custody, control, exchange, settlement, stable coin, issuance, redemption are most often tipping points for state money transmission, treatment. Tobias, you want to start with that one or Ryan? Tobias, go right ahead. All right. Thank you and nice to be here, guys. Looking forward to having this discussion with everyone. so you know, a typical lawyer answer the all the above, right? I mean it just depends on how you're structured. So what I mean by that is if you take a step back and think about money transmission activities generally the biggest trigger is receiving money for transmission and then you actually trans transmit the funds.

So there's a couple nuances that we have to kind of get through from the legal point of view on this with regard to crypto or digital assets. Well, technically the only currency recognized in the US is fiat paper, right? So, a lot of the definitions for money transmission say money and then when you look at the definition of money, it includes monetary value or it includes a claim that can be convertible into money, things like that. So, that's how you get into it is there's one way is if you take so for instance a crypto ATM, right? You can either buy or sell crypto based on giving either the ATM cash or you do it online and then you go pick up your you take your crypto online and you can like for instance convert it into cash and then you go pick it up at the ATM or you can buy at the ATM all these different things.

So that's an example of taking money for transmission and converting it. But equally, if you were to issue stable coins and you took money in and then in turn sent me a stable coin, that could be considered money transmission. I think the other piece to this, which again is a little bit interesting, is that currency exchange is also considered a trigger for money transmission licenses. And many of the states take the position that if you are somehow issuing digital assets or taking cash for digital assets, even if you're not exchanging it to anybody else, that in and of itself is also required for lensure. And then I think lastly, the custody piece, it depends on how it's structured.

and Ryan, I don't know if you have different thoughts on this, but what we've seen is if it's just structured where I bring my crypto and I park it and that's it, and really it's just for I'm just asking somebody like a software platform to hold it for me, that's probably not money transmission. But if I lose the access to my crypto or something like that and the platform can give me a new key, then there's maybe an argument there that new key is really above and beyond just the software platform because I think the argument that the regulators would make is that software platform is now taking custody and control of the funds because they have those access tools.

But Ryan, what are what have you seen? No, I think you're exactly right and I don't I don't have much to add on the first part. I think you're spot on. D all the above, but and Tobias to what you just said, I agree with that. We were recently working with a client that had exactly the issue that you're talking about and so yeah, so not much I don't want to belabver not much more to add on that. I agree with what Tobias said and how you how you approached the question. So in line Yeah. So Christy, I think what you will see though, and I think Ryan will test this too, but the law is behind, right, in terms of where the companies are, excuse me.

And so don't be surprised if regulators don't understand your model. and then you're stuck in this, what should I do? but I think if you think about it, I think the easiest test is are you receiving things that you then tend to convert or transmit to somebody else? And if you do, that's a pretty clear case of money transmission. And then like in the custody case, is it truly like if I lose my keys or whatever to get into my crypto, I'm out of luck. Then you're probably not. So just as like a rule of thumb type of test, Yep. Awesome. I agree. The walls aren't quite caught up with where we're at today.

and the regulators are kind of scratching their heads a lot of the time. Yeah. And they don't have time to get like educated or funds on their state. So that's the other problem, right? So they don't fully understand the products. Yeah. Absolutely. When does pursuing a trust limited purpose charter make more sense than state-by-state money transmitter licensing and what capital permissible investments trade-offs come with that path? Ryan, you start with that one. Yeah, I'll just kind of give a quick on that one. I think most of the time and we're we're obviously working with a client right now who's doing who's doing just that. It's it's that they want I guess the best way to describe is this uniform, you know, national treatment.

and they also then have to be able to absorb higher capital and permissible investment requirements. So it really comes down to I mean when you think about most companies think about maybe a startup fintech you know their first option typically because of the fund raise that they're at and they've done a raise a small one is to leverage somebody else's licenses. So they seek a sponsor bank relationship etc. Then they move on to oh I want to get my MTLS and that was always kind of the next logical step. And now what you're seeing is obviously this race to the regulatory bodies to try to create be you know have a have a charter kind of a national trust.

And so I think that it really comes down to you're almost throwing more requirements on yourself by doing it, but you also give yourself much more uniform treatment when you think about the types of businesses that you're in and whatnot. So, but with it comes obviously like I mentioned higher capital requirements and that sort of thing. So, so I think it really comes down to what type of what how uniform do you want your treatment to be number one. Number two, there's a financial aspect to it obviously. either which way you do it, whether you're doing MTLS, whether you're doing the trust, you're you're or and or both, you're obviously going to be outlaying capital there.

So to me, it's it's a mix of how do you want to be treated from a regulatory standpoint mixed with a pure business decision as well. And so that's a little bit of what we've seen with the clients that we've worked with, one who's actively going through it right now. Yeah. And to kind of echo what Ryan's saying, I say it basically the same way, but slightly different. What I tell clients is you probably don't want to start with the trust because now you're in OC world and there's much higher compliance burdens on you. I mean put aside the capital investment stuff but just the compliance burden alone.

And the other thing that people that are starting out on that path aren't always accustomed to is the regulator is involved in every single decision practically especially when you're that young of a company. So unless you have a dedicated resource that can stay in constant contact with the regulators, it might not be the best choice to start there. So what I like to tell people is make sure you have a proof of concept first and that your product is working and then for the reasons that Ryan mentioned, you probably want to consider a trust which is uniformity of the product across all the states. You don't have to worry about like can I charge this fee or can I do these activities etc.

it's going to be one set of laws that's going to apply to you. It also means it's one set of regulators as opposed to, you know, every state but Montana for money transmission. So, it's much simpler from that perspective, but also you have to make sure that you're a mature enough organization to go after it and do it because the compliance burdens are pretty high. The permissible investment and the capital requirements are higher. Not to mention your execs have to have certain level of banking experience. So it can it can cause some serious kind of operational difficulties if you don't have some of those things in place to deal with all those issues.

Yeah. And if I could to Tobias's point, one of the things that was most striking to the client that we're working with is the top tier level of people that you need to run the bank and maybe some ancillary I say ancillary, but some additional staff that you weren't anticipating either. So it's not just okay to have a chief compliance officer. You need a chief risk officer. You know so there's a and when you're doing it the CVS of those people need to match what this fintech in this case is pursuing. And so to me there's these I wouldn't call them hidden costs but there are things that have to be really thought through to Tobias's point is like you have to be at a certain stage to be able to both pitch that correctly to your investors who are funding a lot of this for you but then also is the culture of your company such that you can take on these additional seuite level people and maintain that culture.

So that's something that I think was a little bit of an unknown for the client that we were working with. And the other thing I would add, Christie, is a little bit that a lot of clients don't think through, kind of echoing again what Ryan's talking about is, you know, you get the charter, but that doesn't mean you're out of the state world completely because states will still come ask you questions about like how are you operating here? How are you able to be here? So again, you really do need to have that risk compliance functions kind of buttoned up because they're going to be dealing both with the federal regulators and then on your complaint side, if you get complaints, a lot of the consumers don't understand what type of trust you are.

So they're going to probably complain to the state. and then you're going to have to explain like, "No, we're actually OC regulated or you know, if it's a state trust bank, whatever." But I think it's a good path, but you really have to make sure you're ready for it. I think that's both what and I are saying. Yeah, absolutely. Thank you for that. what is the best way to document flow of funds and control to regulators? Obviously, we know that they're still scratching their heads a little bit. and when should teams engage NMLS state agencies during product design? I tell them never. I don't know, Ryan.

What do you tell them? I tell them never to engage. Yeah. Well, I think there's some value again depending on the relationship that they may have already created andor if they've hired somebody like let's say Cornerstone who's got relationships with each of those states, you know, it can hurt, but in certain cases, you know, it might not be a half bad idea. I mean when I think about you know back to you to the question I always think about it in two parts and we build a lot of funds flows for clients and whatnot is making it very visual and less narrative driven because you know I think people learn different ways but one of the things that is most easy to learn is when I can see something and I'm talking about the flow I can see it and visualize it.

I think sometimes people fall into the trap of trying to explain the movement of funds without actually showing what it ultimately looks like. So I think that's one thing, but I think even more than that too, particularly when you think about like stable coins and conversion to fiat and those sorts of things, it's what is the redemption path has to be outlined just as clearly as let's say the deposit path is. So, you know, a lot of different applications that you I've seen or things of that sort, they kind of overdo how the money comes in and they don't really document or they underdocument how the money actually gets back out.

And to me, that's something that is really important when you're documenting your fun flow of funds. It's just not, hey, here's how we got the money. It's what are the redemption paths as well. So, I think those are those are the two biggest things. make it less narrative driven, more visual, and don't just focus on how the money gets to you. It's how does it get out then, too. And I think that's something that people need to keep in mind. Yeah. And I would share that view. I think the biggest thing, Christy, is making sure you can show somebody that endtoend view. And I think it's much better to show like a pictorial flowchart than it is to write something because it's much easier to follow.

And honestly, it's just less words for people to like start pondering like, "Oh, what did you mean here when you said this?" So, it's much easier just to see, you know, a bunch of arrows pointing in directions. so I think that makes the most sense. And then, you know, on the control piece, I think I think that might require a little bit of narrative, but again, not much, right? In the sense that, you know, we get the assets, this is what we do with them, and then that's it. But and I was half joking about when to get state agencies involved or not, but the only thing I tell people is if you are going to talk to the state regulators, right?

Just be careful because like what you say can and will be used against you. And so we've had clients who have gone to state regulators, voluntarily disclosed different industries, but like for instance, one person went there and said, "Well, I'm a merchant cash advance provider and I'm, you know, in a certain state." They disclosed this to California. And California said, "Oh, that's interesting. You're going to apply for a license here?" And they said, "Sure, yes, we are." And they said, "Well, why? If you're a cash merchant cash provider, you're exempt, right? Let us look at your like purchase agreement." California looked at it and said, "Yeah, actually you're not a merchant cash advance provider.

You're a lender." And so now you have these back fees for mislicicensing. So that's the reason why I'm saying you have to be careful just because what you might think is one thing the regulator might completely disagree and reccharacterize it. And so you just have to be careful what you're talking about them. I think it's better to talk to Ryan, somebody like Ryan or me, and get it worked out and then talk to the regulator through the licensing process than going like the sandbox concepts and stuff like that. we see it all the time, Christy, as you know, even through Cornerstone, we get people who come to you guys, come to us, the same groups, and a lot of people are saying, well, I'm in a sandbox thing in my home country, right?

And it's like, well, that's great, but Unfortunately, the regulators don't care and that's not going to stop them from deeming you to be a money transmitter or whatever the issue is. Yeah, absolutely. I think going into a licensing discussion with the state without talking to someone like you guys is kind of foolish. It's it's not going to end well. There's going to be trouble there. Yeah, for sure. All right. and stable coin and tokenized deposit models. Which roles is issuer, reserve manager, redeemer most often triggers licensing and when do structures like bank sponsorship or agent of the payee actually work? Go ahead, Toby. You want to start out there?

All right. So the issuer always will arguably I shouldn't say always but most of the time will trigger lensure because they're receiving money they convert it into a stable coin. so that's generally going to be the case. redeemer as well right? Those are kind of two endpost because again they're receiving like the digital asset and then converting it usually into fiat or something else of value. So those two typically trigger lenture. The reserve manager I would say it kind of depends on how that's structured. If the you know a lot of the reserve managers are banks, right? So they wouldn't have licensing requirements, but there's a lot of non-banks that do it.

And because they're receiving money from PE, you know, from one group and then remitting it to another, I think they could hit the MTL licensing requirements in theory. It doesn't always happen, but likely it would. And then you do see a lot of these structures with bank partnerships because the banks are exempt from the laws. what we see a growing amount of is the argument that you know any funds are done in through like an FBO account which then is a bank titled account but in the name of whoever is the fintech or MTO and because of that there's a there's exemptions that people rely on and then the agent of the payee can work but you have to have it structured right because a lot of people forget that it's not just being in some sort of relationship with the recipient you also have to have agreements and things that document what you're doing and that doesn't work in all states although it works in many states.

So you said to be careful about there's some little like things that you could get tripped up on there but I don't know Ryan what are your thoughts? Yeah. No, I agree. I was just going to highlight the one part back to the redeemer part. I mean that's often it's in scope just as often as the issuer maybe sometimes more so. and it's really because the redemption that's the moment at which that customer's claim converts back to real dollars. That's the point I think regulators worry most about failing. so that to me is really of all the parts that we just talked about that's the part that I think is most critical just because you know you think about what regulators are most interested in.

it's it's that part the customer's claim converts back to real dollars and them getting it. And so, from a licensing perspective. So, yeah, I agree. I don't really have whole much more to add on what you said, Tobias. Okay, we've kind of circled around this just a little bit, I think. for hosted wallets, payment facilitation, and program managers, where does control of customer value begin and end, and does it vary by state? Yeah. So, the way I look at this, so the control generally I think you know begins the moment that the platform can you know move redirect freeze customers funds without you know needing a customer's you know real-time authorization and it really generally ends when the customer has u you know I call unconditional or ondemand right to redeem and then nothing the platform does can interrupt that and then when you think about like states, you know, I was talking to somebody the other day like the state variation is real.

some states apply a fairly, you know, I guess you would call it mechanical test, you know, can you move funds, yes or no, while others look at it more holistically and say they look at, you know, marketing, they look at contracts, at customers practical experience. And so that's why the same wallet structure can be exempt, let's say, in one state and then licensable, you know, in another. But Tobias, interested in your thoughts. Yeah. No, I agree. And I think the other thing is that we have to bear in mind is not all states regulate digital assets through money transmission. Some states have separate like money digital assets licenses or they just don't even address it.

You know, like Texas has been pretty active in adding stable coin expressly to their definitions of money transmission and things like that, but not all states do. instead they get there through like it's it's a combination of the words like they say you know money or monetary value and monetary value equals a thing of value or something that's convertible into cash. so it just depends on the state and I agree there is a lot of variation there and as you know Ryan mentioned I think the key for wallets is you know again is it just is it just a parking lot or can you do things with those funds whatever is there whether it's cash or digital assets like are you able to then take those digital assets and convert them into cash and buy things like through some sort of structure with a card or something or what exactly can you do with them?

And so I think that's that's where it becomes trickier. And then and it does vary by state. So I think that's pretty, you know, that's a that's a valid point, too. So anyway, yeah, that's I think I agree with everything Ryan said, plus those just quick thoughts. Since digital is becoming more popular, are you seeing legislation out there that's going to change the state's views on this or are they still behind on that too? They're behind. I mean, we've talked to a you know, ironically the national associating literally right now. but they're behind. I mean, I think I think there's this idea that some of the legislators have, which is, well, look, we already have money transmission licenses on the books with the again the exception of Montana, so why can't we just regulated through that?

And the answer is because the definitions don't work, right? So, I think there's a desire that would happen. But I think you're you're going to eventually see more states do what you know California, New York, and Illinois did, which is get a separate kind of digital assets license. and you know, just regulate things through that. but you know, right now, like Texas is trying to do it all through their money transmission statute, and that could also be an easy trend. But to your point, Christie, you have to have a legislature that's willing to get into session if they're not in session, pass something that then applies.

So that's probably easier said than done. Yeah. And we all know that takes a hot minute because it's going to go back and forth between a bunch of people and have revisions to the bills and stuff. So be interesting to see how that changes over the next few years. For sure. How should teams evaluate staking as a service, DeFi integrations, and crosschain bridges for licensing risk alongside potential securities, commodities imple implications? I'm gonna let Ryan go first. Yeah, I'll just go quick on this one. Yeah, I think you got to I think you quite literally have to run every one of these through like two separate tracks and not like one combined analysis.

So you know money transmission licensing risk on one hand and then securities commodities exposure on the other and so a product depending on what it is can clear you know one of these tracks but then still kind of fail the other. So like taking one as an example for the take like staking as a service in my mind the licensing question is whether the platform ever takes custody or control of the staked assets and then the securities question is separate right in terms you think about it on whether or not the arrangement looks like you know a pulled investment with an expectation of profit derived from the from the platform's efforts.

you know, that's really the real classic test that regulators and then courts certainly have applied to that. So, I won't go through each of these like whether it's DeFi or crosschain bridges, but I think it's really looking at these not as one lump and say, "Oh, well, this product you know, it's there's money transmission, licensing, risk, and securities exposure." I think you have to look at each of those independently. We're working with a client now who's doing something similar to this. It's it's a kind of a novel staking idea. I can't go too deep into it, but it's they quite literally just a week ago were getting an opinion on this very topic.

It's yet to be formalized. You know what we do is we provide the compliance wrapper around it, if you will. not to give legal advice as to whether they should do it or not do it, but that's how I would that's how I would think about that's how I would think about it is running them through two separate tracks and not just one big combined analysis. Yeah, I agree. I don't know there's much to add on this. I mean, I think the one thing I would tell people is not really related to your question, Christie, is but it's shocking how many things come under securities or commodities regulations.

Like, you know, predictive markets are under those types of regulation as well. So, you might not think you have a security or commodity, but you end up it might be that you actually do. So, just be careful because at least get somebody to rule it out for you and confirm that you're right because that can be kind of the worst of violations if you deal with those laws and run a file of those. Awesome. What core compliance stack do examiners expect to see preapproval on? the AMLCTF sanctions, cyber security, BCDR, complaints, third-party risk, all of those. Yeah, this is this is back to Tobias point about D, you know, all the above, you know, this is yeah, this is one of the core offerings that we have, you know, at fractional is and you know, Chrissy, from working with you, it's really the development of state specific policies.

you know mo I think 80 let's call it 85% of states have policy requirements that are consistent across states and then you have different states that have different policy requirements so whether it's New York cyber or whatever the case may be there's always some of this nuance piece but at the core of it you know AML to me is top of the heap and sanctions obviously top of the heap I don't want to diminish any of the others but ironically complaints handling, now that's changed a little bit with CFPB and how that's changed around, but complaints handling is always a big one. And so whether it's a state regulator, whether it's a sponsor bank who's lending you their licenses effectively if you're a fintech until you go and get your own licenses, that's a big one.

So, in no particular order, the AML sanctions piece, I always look at it as one is critical, mission critical. And then complaints for whatever reason, just always seems to be top of mind in all the clients that we deal with, both from what they're hearing, you know, in the industry, what their legal counsel may be telling them, what they're hearing from state regulators, what they're hearing from sponsor banks as they pursue MTLS concurrently. So that doesn't diminish the third party risk elements or cyber obviously those are big but an illequipped or poorly conceived AML sanctions policy can do real damage and it's not even so much the policy and how it's written.

It's is it actionable? Can you are you going to be able to do the things that you say that you're going to do? And if so, do the resources that you've invested in time and people match what you're saying you're going to do? And I think that's where I see most people get tripped up as they're pursuing these is they either do one of two things. they have a really poorly crafted AI generated policy which is clear to the naked eye when you see it or they have this robust policy that's incredibly written and well-drafted but highly inactionable because they just don't have the people to bring it to life.

So that's how I would answer that one. Yeah, I think I shared that. I mean, I think AML and the KYC are probably the two most important ones, right? In terms of figuring out like compliance with that, I think a lot of people look at compliance will agree with that too. I think the other thing that people really look at is also just like what does your fee structure look like, right? so less policies, procedures, but how are your fees structured? Do you disclose your fees to the consumers? How does it look in terms of like is it a clear-cut fee like it's charged on these instances or is there any nuance that it might be requiring a little more explanation so to avoid like the UDAP stuff?

But making sure that you have everything crystal clear to the consumer. and also it's important like just stupid things like, you know, if you're going to have your consumer sign e discislosures, did you sign did you send out the e disclosure upfront that see they can read it, understand it, and then you send them all the disclosures. So just things like that. it's just basic stuff I would say, but the biggest ones I agree I think it's AML and then know your customer, the KYC stuff and then complaints. I think third-party risk management is up there but less so for me. data breaches, data security, data privacy are definitely high especially with all the new state laws that are you know either coming into existence or already on the books.

But definitely those things and the biggest thing is you know you really have to know kind of who your customers are and that you're confirming that they are who they say they are. in particular if they're claiming to be somebody who has a certain type of asset and then you allow like basically some identity thief to access it or something, you know. So, that could be problematic on multiple fronts. Yeah. So, I know we've talked about a couple things. the funds flow diagrams, custody control, analytics, financials. what are some of the other gaps that most often cause delays? Maybe somebody started the process and pull you guys in kind of after the fact.

are there any other than what we've already discussed that kind of really slow things down or caused the states to raise their eyebrow and make it take even longer? So, for me, one of the biggest ones is the net worth requirement. A lot of companies don't realize exactly how much they have to have in net worth. and you know, it varies by state, but if a state has $100,000, you know, I think some companies also think mistakenly that I show that upfront and then after that I don't have to maintain it, which isn't the case. so it's that's one of the biggest ones that I see honestly in terms of both new entities and ongoing entities, which is lack of sufficient funds.

And bear in mind too that what you might think is your net worth doesn't necessarily mean that's how the regulator thinks of it which is also counterintuitive. So like in Texas they call it net tangible assets but really what that means is their definition of assets is what counts towards your calculation. Not every asset counts. So and I think in Texas it's something like it's it's anything that's convertible into cash within 10 days. So my point is not all your assets so like your computers and some of those things won't count towards that requirement but they might in other states. So you also have to understand there's some nuance there both in terms of the number and how they calculate.

so that's that's probably one of the biggest things I see. I think the other thing is and you have it here for financials but like lack of audited financials. the regulators don't care that you're a new startup. Usually, like they're going to want to see some sort of financial statement. what we typically tell clients is, well, if they need audited financials, put whatever your net worth requirement into an account and then get it audited. It's, you know, it's not cheap, but it's an audit. And then in year two, you're going to have to get audited again, and you're going to have to make sure that you maintained that net worth requirement.

but those are the two the biggest ones that I see both from the startup and the ongoing is it's all the financial stuff honestly. Yeah. Yeah, I would agree with that. I'd throw two other items in. I think the business plan tends to trip up clients who are pursuing MTLS. And I say business plan either it's a poorly crafted business plan and even worse one where the plan and we may get into this but one where the plan seemingly doesn't match let's say the policies and controls that you've built. So you're you're supplying a business plan and you're supplying your you know your policy documentation and your policy documentation saying one thing that really doesn't have anything to do with maybe the type of product or your plan that the business plan that you've shared and so that tends to be an issue that particularly the mismatch because it just shows this inconsistency that they that they don't like and then you know I would say the business plan then visav what is your public facing persona what's your website say I think I think

you know the three of us spoke the other day. you know we have a client that we were brought into that was in the process of getting MTLS and one of the first things that we saw as we kind of were swooping in here to replace another firm was that their website said that they were into agentic payments and stable coins. And while that was on their roadmap, here they are supplying a state regulator, their business plan that makes no mention of agentic payments, no mention of stable coins. So the first question that came back was, well, wait a minute. Are you doing this? Because if you are, it's not in your business plan.

And if you aren't, you need to take it off your website. There's this inongruency. So I think a lot of it to me starts with the business plan and the claims that you make. And then both in terms of what you have internally to show them and policies and the connection there or any sort of public facing whether you're putting LinkedIn posts out there I don't care if you're pre-operational pre-revenue whatever that to me is always something that can slow things down dramatically and particularly now and Christie you know this with as many people that are going to these state regulators over the last year and a half or so to pursue MTLS it's very easy now for a regulator to thin the herd by simply saying that, you know, your business plan doesn't work.

Go back and fix it. Get back get to the back of the line. And I think that's something that can really trip people up. Yeah. And you know what I tell people, Ryan, kind of like you're talking about, I was laughing because I literally had this conversation twice this morning is look, the states are doing you a favor in some regards, right? In some states, they expressly say here's what we want you to tell us. So your business plan and then that must consist of marketing strategies, who's your target market, how do you find your customers, any fees, etc. I was like, don't lob it all into one big thing.

Literally put the same headings that the regulator tells you and put your sections under that because the regulators don't want to have to hunt for what you're what they're trying to get to approve you, right? So you want to make it as easy as possible for them. So I literally tell people take like cut and paste the buckets that the regulator says is required and then just fill in text underneath them. And also don't try to put one at first position and the other. put it in exact same order as the regulator because you want to make it as easy as possible for that reader because at the end of the day all they want to do is check it off the box and they can do it much faster and much more efficiently if you put it like in the form that they want and then also in the layout order that they Yeah.

And one other thing I wanted to mention Tobias you mentioned around the audited financials and this comes up quite a bit too. So you have I don't want to say pre-operate. Well, you do you get pre-operational companies that are pursuing MTLS and they don't their policies say, for example, that they're going to have an annual AML audit, which they're going to be required to do. And often times the regulators will ask for their most recent AML audit. And what tends to happen is FinTech will say, "Well, we're not operational yet. We don't have one." And that's and that's fine. There's sometimes where that can that can fly.

But we perform AML audits for clients. But what we also do is a very light touch AML review of the stated policies and procedures that they're implementing. And that could be everything from the people that are actually going to be hired to do it or already been hired to do it. What KYC or KYB providers you know software services have they have they procured? you know so you can do a very light touch couple page you know couple artifact AML I'll say audit even if you're pre-operational it only enhances an application oftent time too often we see they say well we don't have one and that's fine but in the if you have other issues with other documentation it's just always a nice to have and you know it doesn't cost a lot to do it but at least it gives a bit more credence to your application.

So to your point, they may not have three years of financials. They may only have six months or they may not be operational yet, but they, you know, they do have policies. They do have an analyst on staff. They do have controls built. They do have a contract signed with a, you know, persona or whoever it may be. Get credit for that. Have something in writing from a third party who can attest to those things. I think that helps. Awesome. This is going to be a good one. How much does precedent matter? So when eval evaluating a new business model, how much weight should companies put on how regulators treated similar businesses versus the specific facts of their own model.

So I think they have to be aware of it and how to argue against it. So, as a simple example, I dealt with a company that does employeebacked loans, meaning they're not payday loans, but they're just loans that are offered from a third party provider exclusively to a network. That network consists of employers who have agreed to work with this company and they only offer loans to the employees. every regulator out there and this is what we told the client up front is going to say that these or said that these were payday loans and we had to have our speech ready as to why that's not the case.

So part of the job that Ryan and I have is convincing regulators, no, you're wrong. I mean not that strongly, but like that's not what these are, right? These are these other things. And so you have to be able to prepare that speech and you have to kind of know what you're up against. So I think precedent matters from that standpoint. I'm not sure it matters otherwise, right? Because if you think you're outside of the domain of certain regulatory guard rails, then you just don't apply. but what I would tell you is what has helped many clients along those lines is to have something in their file that shows why they think that drafted by a law firm or a firm like Ryan's where it says, "Hey, you asked us this.

here's why we don't think this applies and then when a regulator comes you can provide that to them and say yeah we looked at this issue and we don't think your statutes apply to us. So yeah. Yeah. No, I totally agree there. I think that's that's the best use of precedent is to get ahead of what's likely to be questioned. Yeah. In terms of what your product offering is and what it is and what it isn't. and using that precedent. Although sometimes too, as I'm sure we probably all know, that some founders will use that precedent to say, "Well, you did it for them, do it for me."

And it's just not the way it works. Yeah. And a lot of times, Yeah. Right. And a lot of times too the you know quite frankly the I don't know what you want to call it the CV of the founder if it's a first time founder they may not get as much lenience as maybe a second time founder who's had a successful business and so I think that's why Preston is only good to help guide around what to how to pro proactively reply if Yeah. So, we've talked a good bit today about the difficulties of getting licensed, having all the boxes checked, the right verbiage in there, making it match your actual business model, your website, and everything.

Once you get approved, what is the post approval compliance that they need to do? Do they What do they need to watch out for? Ryan, you want to start with that one? Yeah. I mean, I think it's it's it's going to sound so simple and trit, but it's are you doing what you said you were going to do? and I'll talk about let's talk about specifically from a compliance standpoint. Are you doing the things that your license approval was predicated upon? you told us you were going to be screening every transaction. I'm making this up, but show us that you did it. you said that you were going to be using this particular KYC provider and that the manual work that was going to be done on the back end of it was minimal because your policy says that are you doing that you told us you were going to have a full-time BSA officer or compliance person.

Well, you still have somebody who's just doing it for 20 hours a month. I mean I think it's things like that and does the growth of does the resourcing of your company in terms of the people etc. Does it match the transaction volumes that are now happening you know you committed to something in a business plan that said you were going to do a million widgets a month and you're doing three million widgets a month but yet you've yet to increase your staff. And so I think things like that to me are really critical. do you do are you doing what you said you were going to do?

Are you resourcing according to your actual volumes? And how close is what you're doing is how close to your plan is what you're actually doing good or bad. So yeah, I agree. And like to Ryan's point, if you're not close to your plan, go back to NMLS, take out your old business plan, tweak it, and resubmit it, right? and just because the regulators are going to when they come to audit you, they're going to look at what you say you're doing and then making sure you do it. I think the biggest thing is too is making sure your policies and procedures match what you're doing.

Mostly your procedures obviously just making sure that what you say in there is what you're doing because regulators really hammer that. and then the big thing that I like to see is you know what are you doing in terms of data retention, right? Because we're living in a digital world. So sometimes retaining data is difficult. So even if it's retaining the time of an acknowledgement and who it was entered by, doing stuff like that, do that because it's going to only help you with the regulators. And then lastly, doing some sort of compliance testing where you maybe test operations against your policy or your actual product against the legal requirements.

So just making sure that everything is staying put. And look, no business is perfect. And honestly, I and maybe I have a more optimistic view of this, but I don't think the regulators expect perfection, but what they're going to want to see is that you are proactively looking for things and then fixing them and making hard choices. including like if you have a vendor who's going rogue on you and just not doing the things that you ask that you're not afraid to just cut that vendor loose, right? Absolutely. Well, as we start wrapping up today, we've covered a lot. give me a takeaway with what you would want somebody to know after watching our webinar today as they start out in this or they're already kneedeep or they've been in it for years.

What's give me your final thoughts there? Tobias, you want to start or Sure. So what I would say is whatever you think regulation is today, it's probably not going to be that way in like a couple years from now or even a couple months from now. It's it's really evolving with the digital asset space. And I think we haven't seen it settled yet and we're not going to for a while. So I think just sit back and you know you may not be regulated today, but don't be surprised if in 6 months to a year you are. So just you know knowing that just understand that like I said in the beginning the law is behind and it's going to evolve and it's going to evolve in a way that maybe you anticipate maybe you don't.

Yeah. And this will sound like a shameless plug but it but it's not. I mean, I think that when I think now more than ever, it used to be that a founder would initially spend all their cash burn on engineers right up front and then they build all this stuff and then they eventually get around to compliance and maybe what they built doesn't really match a compliant program, if you will. And so getting compliance in sooner nowadays I think is much more important than let's say it was number of years ago. I think that's a really important thing. So, the big takeaway, not only for me, because that's what we do, is the ones who seem to have the most success in getting their MTLS and having a successful business and getting to revenue faster are those who kind of think about compliance as a partner in that build versus kind of an afterthought.

and so I think that's that's an important thing to keep in mind as well. Yeah. Nothing we talked about today is easy and it can't be done usually with an AI policy. I think we mentioned that earlier. So my takeaway is do your homework up front. Find the Tobias, find Ryan, reach out to them, work with them, share their experience, and go to the state with, you know, as much of a complete application and as truthful and honest as you can be. And hope for the best as you go through the review process. And then keep up with what you're doing after you get your license in place.

And if there's something needs updating, do it. And be honest. Just be forthcoming with the state. That's what they want to see. That's right. Yeah, for sure. Awesome. Well, we wrapped up a few minutes early, but I know a couple of us have a couple things coming up pretty soon here at two. thank you, Ryan, Tobias, for joining us today. It was great hearing your insight on this topic and we look forward to speaking with you again soon. Yeah, sounds good. Thank you so much. Thank you guys. Thanks everyone for joining. Bye. Bye.

Canonical HTML: https://cornerstonelicensing.com/webinars/crypto-licensing-legal-regulatory-operational-insights
---

## How to cite this page

Cite as: "Crypto Licensing: Legal, Regulatory & Operational Insights." Cornerstone Licensing. https://cornerstonelicensing.com/webinars/crypto-licensing-legal-regulatory-operational-insights

Published by Cornerstone Licensing. When quoting figures or legal requirements, link the canonical URL above and note the last-updated date (2026-10-05). The full content index for this site is at https://cornerstonelicensing.com/llms.txt.
