AI Can Strengthen Cybersecurity—But It Can Also Break It

Artificial Intelligence (“AI”) is no longer a concept associated solely with innovation and operational efficiency. It has become one of the defining technologies shaping the future of cybersecurity, offering financial institutions significant opportunities to strengthen their cyber defences while simultaneously introducing a new generation of sophisticated threats. As organisations increasingly integrate AI into their operations, cybercriminals are doing the same, fundamentally changing the way cyber-attacks are planned, executed and scaled.

Against this backdrop, the Cyprus Securities and Exchange Commission (“CySEC”) recently issued Circular C786, drawing the attention of regulated entities to the cybersecurity implications of frontier Artificial Intelligence models and reminding firms of their obligations under the Digital Operational Resilience Act (“DORA”). While the Circular does not introduce new legal requirements, it reinforces an important regulatory expectation: ICT risk management frameworks must continuously evolve to address emerging technologies and the changing cyber threat landscape.

This message is particularly significant because AI is reshaping cyber risk at a pace that traditional security frameworks were never designed to address. Financial institutions can no longer rely solely on historical threat patterns or traditional security controls. Instead, they must ensure that operational resilience, governance and ICT risk management remain dynamic, proportionate and capable of responding to increasingly intelligent and automated attacks.

 

Frontier AI Has Changed the Cybersecurity Landscape

Artificial Intelligence has already demonstrated enormous value in strengthening cybersecurity. Financial institutions increasingly rely on AI-powered solutions to detect unusual activity, analyse vast quantities of security data, identify potential fraud, automate threat intelligence and improve incident response. These capabilities allow security teams to identify threats more quickly than traditional manual processes and, in many cases, prevent cyber incidents before they materialise.

However, AI is inherently neutral. The same technologies that improve cyber resilience can equally be exploited by malicious actors.

CySEC’s Circular focuses specifically on frontier AI models—highly advanced AI systems capable of analysing software, generating code, identifying vulnerabilities and adapting their outputs with remarkable speed and sophistication. These models significantly reduce the technical barriers traditionally associated with cyber-attacks, enabling threat actors to automate activities that previously required substantial expertise and time.

This development represents a fundamental shift in the cyber threat landscape. Rather than relying on manual techniques to identify weaknesses, attackers can increasingly leverage AI to scan software for vulnerabilities, generate malicious code, develop highly personalised phishing campaigns and identify new attack methods within a fraction of the time previously required. As a result, organisations face an environment in which vulnerabilities may be discovered and exploited much faster than conventional remediation processes were designed to accommodate.

CySEC also highlights that these risks extend beyond regulated entities themselves. As financial institutions continue to rely on cloud providers, software vendors and other ICT third-party service providers, AI-driven attacks targeting supply chains may create significant operational disruptions across multiple organisations simultaneously.

 

DORA Was Designed to Address Exactly These Types of Risks

One of DORA’s greatest strengths lies in its technology-neutral approach. Rather than regulating individual technologies, the Regulation establishes a comprehensive framework requiring financial entities to identify, assess, manage and continuously monitor ICT risks irrespective of how those risks emerge.

This means that although DORA contains no dedicated chapter on Artificial Intelligence, AI-generated cyber threats naturally fall within its scope. Financial entities remain responsible for ensuring that their ICT risk management framework is capable of protecting information assets, maintaining operational resilience and responding effectively to evolving cyber threats.

The Circular reinforces this principle by encouraging regulated entities to critically assess whether their existing ICT governance arrangements remain adequate in light of frontier AI developments. Importantly, this assessment should not be treated as a one-off compliance exercise. DORA is built around continuous improvement, recognising that operational resilience depends upon organisations regularly reviewing, testing and enhancing their controls as technologies and risks evolve.

This principle reflects one of the core objectives of DORA: resilience is not achieved simply by implementing security controls. It requires organisations to continuously evaluate whether those controls remain effective within an increasingly complex technological environment.

 

Operational Resilience Must Now Evolve Alongside Artificial Intelligence

CySEC’s Circular encourages regulated entities to revisit several key components of their ICT risk management frameworks, many of which already form central pillars of DORA.

One of the most immediate considerations concerns vulnerability management. As AI significantly accelerates the identification of software vulnerabilities, financial institutions must ensure that their own processes for vulnerability monitoring, patch management and remediation operate at a comparable pace. Delays that may previously have represented acceptable operational risks could now create significantly greater exposure, particularly where critical systems or traditional infrastructure are involved.

Similarly, organisations should carefully reassess whether their security architecture continues to provide sufficient protection against increasingly sophisticated attacks. Identity and access management, privileged access controls, authentication mechanisms and network segmentation should all be evaluated through the lens of AI-enabled cyber threats. Security by design is no longer simply a regulatory expectation under DORA—it has become an operational necessity.

CySEC also places considerable emphasis on monitoring and detection capabilities. Traditional monitoring solutions that rely heavily on predefined rules or manual analysis may struggle to identify increasingly complex AI-generated attacks. Firms should therefore consider whether their existing detection capabilities remain proportionate to the evolving threat landscape and whether greater automation, threat intelligence integration or security coordination could improve their ability to identify incidents before they escalate.

Equally important is an organisation’s ability to recover from a cyber incident. DORA deliberately shifts the regulatory focus away from prevention alone and towards operational resilience. No organisation can eliminate cyber risk entirely. Instead, firms must demonstrate that they can continue operating, restore critical services promptly and minimise disruption even when attacks occur.

This makes robust backup arrangements, disaster recovery planning and restoration testing increasingly important. CySEC specifically reminds firms to ensure that backup systems remain appropriately segregated from production environments and are tested regularly under realistic operational conditions. These measures become particularly relevant when responding to AI-driven attacks that may spread rapidly across multiple systems or attempt to compromise recovery environments themselves.

 

Third-Party Risk Management Has Become More Important Than Ever

Another important message arising from both DORA and CySEC’s Circular concerns ICT third-party risk.

Financial institutions increasingly rely on external providers for cloud infrastructure, software development, cybersecurity solutions, managed services and data processing. While outsourcing delivers considerable operational benefits, it also extends an organisation’s attack surface beyond its own internal environment.

AI further amplifies these risks. A vulnerability affecting a single ICT provider may now be identified and exploited far more rapidly, potentially affecting multiple regulated entities simultaneously. Consequently, organisations should ensure that their third-party risk management arrangements remain sufficiently robust to address these evolving threats.

This extends beyond contractual compliance. Firms should maintain ongoing oversight of critical ICT providers, assess their cybersecurity maturity, understand their incident response capabilities and ensure that appropriate contingency arrangements remain in place should disruptions occur. Effective third-party risk management has become an essential component of operational resilience rather than merely a procurement exercise.

 

Strong Governance Will Ultimately Determine Operational Resilience

Perhaps the most important message conveyed by CySEC is that managing AI-related cyber risks is not solely the responsibility of ICT departments.

Operational resilience begins with governance.

Boards of Directors and senior management remain ultimately responsible for ensuring that ICT risks are properly identified, assessed and managed throughout the organisation. As frontier AI continues to reshape cybersecurity, governance arrangements must evolve accordingly. AI-related cyber risks should be incorporated into ICT risk assessments, operational resilience planning and Board-level discussions to ensure that strategic decisions reflect the changing technological environment.

This also requires organisations to foster a culture of continuous learning. Lessons arising from cyber incidents, penetration testing, vulnerability assessments and emerging threat intelligence should feed directly into governance processes, enabling firms to strengthen their resilience over time rather than merely reacting to individual incidents.

 

Conclusion

Artificial Intelligence is transforming both cybersecurity and the cyber threat landscape, creating new opportunities as well as new risks for financial institutions. CySEC’s Circular C786 serves as an important reminder that firms must ensure their ICT risk management frameworks, governance arrangements and operational resilience measures continue to evolve in line with these emerging threats.

While DORA already provides the framework for managing ICT risks, organisations should proactively reassess whether their existing controls remain effective in an increasingly AI-driven environment. Firms that embed AI-related cyber risks into their governance and resilience strategies will be better positioned to safeguard their operations, meet regulatory expectations and strengthen their overall digital resilience.

 

How FiveComply Can Help

Whether you are reviewing your DORA compliance programme, strengthening your ICT risk management framework, or preparing for regulatory expectations surrounding emerging technologies such as Artificial Intelligence, our team is here to support you.

 

Get in touch with our team to discuss your DORA compliance framework, ICT governance, or operational resilience strategy.

📞 +357 25 34 00 25
📧 regulatory@fivecomply.com

Author

Dafne Achniotou

Compliance Consultant – EU & MENA Region

The First 90 Days After Obtaining a Forex Licence: What Most Firms Underestimate

Receiving Your Licence Is Only the Beginning

For many firms, obtaining a forex licence feels like crossing the finish line.

In reality, it marks the beginning of a far more challenging phase.

Regulators assess applicants based on their proposed business model. Once the licence is issued, the focus shifts to something entirely different: demonstrating that the firm is capable of operating safely, compliantly and sustainably.

The first 90 days after licensing often determine whether a newly authorised firm transitions smoothly into operations or encounters delays with banking, service providers, regulatory filings and the whole activation process.

At FiveComply, we have supported numerous regulated financial institutions through this transition. One consistent observation is that firms often underestimate the amount of work that follows licence approval.

1. Regulatory Approval Must Become Operational Reality

A licence authorises a business to operate but it does not make it operational overnight.

During the first few months, firms typically need to:

  • open bank accounts
  • fund minimum regulatory capital
  • arrange professional indemnity insurance where required
  • finalise agreements with local service providers
  • complete corporate filings
  • implement governance arrangements

These are often conditions that must be satisfied before full business operations commence.

 

2. Your Compliance Framework Must Become “Live”

One of the biggest misconceptions is that AML and compliance become relevant only after clients begin trading.

In reality, regulators expect firms to have fully operational compliance systems before onboarding their first customer.

This includes:

  • AML/CFT procedures
  • Customer Due Diligence (CDD)
  • sanctions screening
  • risk assessment methodology
  • complaints handling procedures
  • conflicts of interest management
  • record retention
  • internal governance

Policies sitting on a shelf are rarely sufficient. Regulators increasingly expect firms to demonstrate that these controls are functioning in practice.

 

3. Building the Operational Ecosystem

A licensed broker depends on far more than a trading platform.

Successful launches require coordination between multiple providers, including:

  • banking partners
  • payment providers
  • liquidity providers
  • trading platform providers
  • CRM systems
  • KYC verification providers
  • screening software
  • hosting and cybersecurity providers
  • outsourced compliance and audit providers

Many projects are delayed simply because these relationships are not established early enough.

 

4. Governance Must Be Evidenced

Corporate governance begins immediately after licensing.

Examples include:

  • holding the first Board meeting
  • approving operational policies
  • adopting client documentation
  • approving outsourcing arrangements
  • documenting key business decisions
  • defining reporting lines

These governance records often become some of the first documents requested during regulatory inspections.

5. Your Brand Must Be Ready for Regulatory Scrutiny

Many firms focus on launching their website quickly.

However, regulators increasingly review:

  • website disclosures
  • legal documentation
  • risk warnings
  • client agreements
  • privacy notices
  • marketing material
  • domain ownership
  • trademark protection

Marketing that is inconsistent with the scope of the licence can create regulatory concerns from the outset.

 

6. Client Onboarding Is More Than Opening Accounts

Before accepting clients, firms should ensure they have clearly documented:

  • onboarding workflows
  • KYC responsibilities
  • source of funds verification
  • sanctions screening
  • client risk classification
  • ongoing monitoring procedures
  • transaction reporting processes

The first client often tests whether internal procedures actually work in practice.

 

7. Reporting Obligations Begin Earlier Than Many Expect

Newly licensed firms frequently assume reporting only starts once they become profitable.

In reality, many jurisdictions require firms to maintain ongoing compliance from the first day of authorisation, including:

  • capital adequacy monitoring
  • regulatory notifications
  • AML registrations
  • CRS/FATCA registrations
  • annual audits
  • compliance certifications
  • board reporting
  • periodic regulatory returns

Missing an early filing can quickly attract unnecessary regulatory attention.

 

8. Operational Resilience Should Not Be an Afterthought

Today’s regulators expect firms to prepare for disruption.

This includes:

  • disaster recovery planning
  • business continuity arrangements
  • cybersecurity measures
  • secure data storage
  • staff training
  • outsourced provider oversight

Operational resilience is increasingly viewed as part of sound governance rather than an optional IT exercise.

 

Common Mistakes During the First 90 Days

Some of the most common issues we encounter include:

  • Delaying bank account activation.
  • Waiting too long to engage liquidity and payment providers.
  • Treating compliance manuals as paperwork rather than operational tools.
  • Launching a website before legal and regulatory reviews are completed.
  • Underestimating governance documentation.
  • Missing initial regulatory registrations and reporting deadlines.
  • Failing to document internal decision-making.
  • Assuming post-licensing support is no longer required.

 

Why Post-Licensing Support Matters

The licensing process demonstrates that a business can meet regulatory entry requirements.

The first 90 days demonstrate whether it can operate as a regulated financial institution.

At FiveComply, we support firms beyond licence approval by assisting with operational activation, governance implementation, compliance framework deployment, regulatory registrations, provider coordination and ongoing compliance support. Our objective is to help firms move from being licensed to being fully operational while meeting regulatory expectations from day one.

 

Disclaimer: This article is provided for general informational purposes only and does not constitute legal, regulatory, tax, or professional advice. Readers should seek independent professional advice before acting on any information contained herein.

Author

Nayia Xiari

Partner / General Manager – Offshore Division

Why Seychelles Continues to Be a Preferred Jurisdiction for Securities Dealers

In an increasingly regulated global financial environment, choosing the right licensing jurisdiction is no longer simply a compliance exercise, it is a strategic business decision that can directly influence a firm’s ability to scale, attract clients, establish banking relationships and compete internationally.

While numerous offshore jurisdictions compete for financial services business, Seychelles has consistently positioned itself as a preferred destination for forex brokers offering a balanced framework of regulatory credibility, operational flexibility, and commercial efficiency within a well-supervised AML/CFT environment.

At the heart of this appeal lies the Seychelles Securities Dealer Licence (SDL), issued by the Seychelles Financial Services Authority (FSA), enabling firms to conduct a broad range of securities and investment-related activities within a recognised regulatory framework, providing a solid foundation for businesses seeking to establish or expand their presence in international financial markets.

For licensed entities, this translates into a regulatory environment that is increasingly recognised by international banks, liquidity providers, payment service providers (PSPs), Electronic Money Institutions (EMIs) and institutional counterparties. As a result, Seychelles offers more than just a licensing solution, it provides a platform from which regulated firms can build, operate and grow globally focused financial services businesses with confidence.

1. Competitive Capital Requirements

A key advantage of Seychelles for Securities Dealers is its balanced approach to capital adequacy.

The current minimum paid-up capital of USD 100,000 reflects regulatory robustness while remaining more accessible than many European regimes, where requirements can exceed several hundred thousand euros depending on the scope of permissions.

This allows firms to allocate more resources toward growth areas such as technology, infrastructure, client acquisition and compliance, while still maintaining a properly capitalised regulated entity.

2. Global Client Reach

Most licensed Securities Dealers utilise Seychelles as an international operating hub and provide services to clients across multiple jurisdictions, subject to the regulatory requirements applicable within those countries.

This international orientation makes Seychelles particularly attractive for firms seeking to establish scalable brokerage operations capable of supporting clients across emerging markets, estalishing one of the strongest jurisdictional advantages.

3. Broad Scope of Permitted Activities

The Securities Dealer Licence supports a broad range of investment activities and financial instruments, allowing firms to operate as diversified business models under a single regulatory authorisation.

Depending on the approved scope of business, a Securities Dealer may engage in activities relating to among others:

  • Contracts for Difference (CFDs);
  • Equities / Shares;
  • Bonds;
  • Futures;
  • Options;
  • Other Derivatives and Securities as per Schedule 1 of the Securities Act;

enabling firms to expand their product offering without the complexity associated with multiple licensing structures.

4. Competitive Trading Environment

Unlike several heavily regulated onshore jurisdictions where retail leverage caps significantly restrict product flexibility, Seychelles offers a more commercially adaptable regulatory framework.

The jurisdiction does not impose statutory limits on trading leverage, allowing brokers to determine leverage levels based on their risk management policies and target markets subject to an appropriateness test, enabling firms to structure trading conditions that remain competitive in international markets, supporting both client acquisition and retention while operating within a regulated environment.

For brokers targeting global retail audiences remains one of the jurisdiction’s key advantages.

5. Banking, EMIs and PSP Accessibility

Equally important is access to banking, payment solutions, liquidity providers and settlement services.

While onboarding remains subject to AML and due diligence checks, Seychelles-licensed entities are generally better positioned than unregulated offshore structures.

This importantly offers to brokers stable payment processing and international financial connectivity.

6. Tax Efficiency Through Economic Substance

Another key advantage of Seychelles is its substance-based tax framework. Securities Dealers that meet the Substantial Activity Requirements (SAR) may qualify for a preferential tax treatment, including a reduced rate of 1.5% on gross revenue.

Unlike traditional offshore models focused purely on tax optimisation, this benefit is conditional on genuine economic presence in the jurisdiction. Firms are required to demonstrate real substance, including a local office, qualified personnel, core income-generating activities conducted in Seychelles, adequate operational expenditure, and ongoing compliance with annual regulatory assessments.

This structure aligns with international transparency standards while maintaining an attractive and predictable tax environment for compliant businesses. In addition, Seychelles generally does not impose withholding taxes on outbound dividends, interest, or capital distributions to non-resident shareholders, supporting efficient international structuring.

7. Substance Requirements as a Competitive Advantage

Whilst economic substance requirements are sometimes viewed as an additional regulatory obligation, sophisticated market participants increasingly recognise them as a significant advantage.

The requirement to establish genuine operations within Seychelles helps distinguish licensed Securities Dealers from purely nominal structures and enhances credibility when dealing with:

  • Banks;
  • Liquidity providers;
  • Payment institutions;
  • Regulatory authorities; and
  • Institutional counterparties.

 8. A Balanced and Competitive Offshore Jurisdiction

While many offshore jurisdictions compete to attract financial services businesses, Seychelles distinguishes itself by offering a balanced combination of regulatory credibility, competitive costs, and operational flexibility for forex brokers and securities dealers.

Market participants are increasingly attracted by:

  • A recognised regulatory framework;
  • Competitive capital requirements;
  • Flexible trading environments;
  • Global client reach;
  • Tax efficiency through substance-based incentives;
  • Access to banking and payment infrastructure;
  • Broad investment permissions under a single licence; and
  • Ongoing regulatory development aligned with international standards.

For many brokerage groups, Seychelles successfully combines the credibility of a regulated jurisdiction with the operational flexibility required to compete in global financial markets.

How FiveComply Supports Clients from A to Z

Obtaining a Seychelles Securities Dealer Licence requires far more than submitting an application.

At FiveComply, we support clients throughout the entire licensing lifecycle, from initial structuring and business model assessment through to licence approval.

Our work covers:

  • Corporate structuring;
  • UBO identification;
  • KYC verification;
  • Source of wealth and funds checks;
  • Governance and substance planning;
  • Capital structuring;
  • AML/CFT framework implementation;
  • Preparation of business plans, financial projections and compliance manuals.

We also remain in direct communication with the FSA throughout the process, ensuring applications are clear, compliant and aligned with regulatory expectations.

Our support continues after authorisation through comprehensive ongoing compliance services, including AML/CFT and compliance support, regulatory reporting, compliance officer services,  internal reviews, policy updates, governance assistance, and regulatory correspondence management, ensuring that clients remain fully compliant while focusing on business growth.

Ultimately, FiveComply provides an end-to-end solution, from structuring and licensing to long-term regulatory support, helping firms establish and maintain regulated brokerage operations with confidence.

 

Disclaimer: This article is provided for general informational purposes only and does not constitute legal, regulatory, tax, or professional advice. Readers should seek independent professional advice before acting on any information contained herein.

Author

Yasmina Amhaz

Licensing Associate – Offshore Division

Seychelles VASP Paid-Up Capital Requirements: FSA Issues New Guidance for Virtual Asset Service Providers

The Financial Services Authority (FSA) of Seychelles has published its long-awaited Guidance Note on Paid-Up Capital Requirements for Virtual Asset Service Providers (VASPs), providing important clarification on how the paid-up capital provisions under the Virtual Asset Service Providers Act, 2024 will be applied in practice.

For businesses considering a Seychelles VASP Licence, the Guidance provides valuable insight into the Authority’s expectations regarding minimum capital, acceptable forms of paid-up capital, ongoing monitoring obligations and regulatory reporting requirements.

More importantly, the Guidance confirms that paid-up capital is not merely a licensing requirement—it is a continuous prudential obligation that must be maintained throughout the life of the licence.

Minimum Paid-Up Capital Requirements for Seychelles VASPs

The FSA has confirmed that the minimum paid-up capital required depends on the type of virtual asset service being provided.

Virtual Asset Service Minimum Paid-Up Capital
Virtual Asset Wallet Provider USD 75,000
Virtual Asset Exchange USD 100,000
Virtual Asset Broking USD 50,000
Virtual Asset Investment Provider USD 25,000

 

Where an applicant intends to provide more than one regulated virtual asset service, the applicable capital requirements must be satisfied in accordance with the Virtual Asset Service Providers (Capital and Other Financial Requirements) Regulations.

Seychelles VASP Capital Requirements Increase as the Business Grows

One of the most significant clarifications introduced by the Guidance concerns the ongoing capital obligation.

From the third year of operation, every Seychelles VASP must maintain paid-up capital equal to 2.5% of its annual turnover generated from licensed virtual asset services.

Importantly, only revenue derived from regulated virtual asset activities is included in this calculation. Income generated from other commercial activities is excluded.

The FSA will assess compliance using the VASP’s audited financial statements and may request additional supporting information where necessary.

This demonstrates that capital adequacy in Seychelles is intended to evolve alongside the scale of the business rather than remaining a fixed licensing threshold.

Acceptable Forms of Paid-Up Capital for a Seychelles VASP Licence

The Guidance provides welcome clarification regarding the forms of paid-up capital that the FSA considers acceptable.

The Authority confirms that cash remains the preferred and default form of regulatory capital.

However, the cash must be maintained with:

  • a bank licensed under the Seychelles Financial Institutions Act; or
  • a financial institution located in a jurisdiction meeting the Authority’s Basel II requirements.

One of the most notable clarifications is that funds maintained through:

  • Electronic Money Institutions (EMIs);
  • Payment Service Providers (PSPs);
  • digital wallets; or
  • similar payment arrangements,

will not be accepted as paid-up capital.

This clarification is particularly relevant for fintech and crypto businesses that commonly rely on alternative payment solutions instead of traditional banking relationships.

Can Alternative Capital Be Used for a Seychelles VASP Application?

Yes, but only with the prior assessment and approval of the FSA.

The Guidance explains that alternative forms of capital, including:

  • bonds;
  • shares;
  • debt securities; and
  • certain investment fund securities,

may be considered on a case-by-case basis.

However, applicants must demonstrate that the proposed capital is:

  • fully paid;
  • unencumbered;
  • readily available;
  • legally enforceable;
  • sufficiently liquid; and
  • capable of absorbing losses during periods of financial stress.

The Authority makes it clear that it will assess the economic substance of the proposed capital rather than relying solely on its accounting treatment or legal classification.

Ongoing Capital Monitoring and Reporting Requirements

The Guidance introduces clear expectations regarding ongoing capital management.

Every Seychelles VASP should maintain appropriate governance arrangements to monitor its capital position continuously.

Where paid-up capital falls below the required level, or no longer complies with the approved form, the FSA must be notified within 12 hours.

A detailed remediation plan must then be submitted within five working days, explaining:

  • the cause of the capital shortfall;
  • the corrective measures to be implemented; and
  • the expected timeframe for restoring compliance.

Failure to comply with these obligations may result in supervisory or enforcement action by the Authority.

What Does This Mean for Businesses Applying for a Seychelles VASP Licence?

The publication of this Guidance provides much-needed regulatory certainty for businesses preparing to establish a Virtual Asset Service Provider in Seychelles.

Applicants should ensure that:

  • their paid-up capital satisfies the applicable regulatory requirements;
  • their banking arrangements meet the FSA’s expectations;
  • future capital requirements are considered as the business grows;
  • any proposed alternative capital instruments are assessed before submission; and
  • appropriate governance and monitoring frameworks are implemented from the outset.

Taking these matters into consideration at an early stage can significantly reduce regulatory queries during the licensing process.

How FiveComply Can Assist with a Seychelles VASP Licence

FiveComply is currently assisting applicants seeking to establish Virtual Asset Service Providers in Seychelles.

Our team supports clients throughout the licensing process by assisting with:

  • assessing paid-up capital requirements;
  • reviewing acceptable capital structures;
  • advising on banking solutions and regulatory expectations;
  • preparing the VASP licence application and supporting documentation;
  • drafting governance, AML/CFT and compliance frameworks; and
  • liaising with the Financial Services Authority throughout the application process.

Our objective is to ensure that every application is prepared in line with the FSA’s regulatory expectations from the outset, helping applicants navigate the licensing process efficiently and confidently.

If you are considering establishing a Virtual Asset Service Provider in Seychelles, our team would be pleased to discuss your proposed business model and assist you throughout the licensing process.

 

Disclaimer: This article is provided for general informational purposes only and does not constitute legal, regulatory, tax, or professional advice. Readers should seek independent professional advice before acting on any information contained herein.

Author

Nayia Xiari

Partner / General Manager – Offshore Division

Bridging the Gap between Regulators and Industry: Insights from Seychelles

Early in my career as a regulator, I often wondered why firms struggled to implement what appeared to be straightforward regulatory requirements. From my perspective at the time, the purpose of the rules seemed clear, and the expectations appeared reasonable. Years later, after moving into industry, I found myself asking a very different question: why did regulators sometimes underestimate the complexity of putting those same requirements into practice?

Having worked on both sides of the regulatory table, I have come to appreciate that many of the tensions between regulators and regulated entities stem not from disagreement, but from differing viewpoints. While both are often working towards the same objective, each encounters distinct challenges, risks, and priorities.

From a regulatory standpoint, the focus is naturally on the risks that rules are designed to address. My supervisory experience highlighted recurring weaknesses across firms and demonstrated how inadequate controls can contribute to financial loss, misconduct, consumer harm, and risks to market integrity. Viewed through that lens, regulatory requirements often appear both necessary and proportionate.

What is not always visible, however, is the complexity involved in translating those requirements into day-to-day operations. A rule that seems straightforward on paper may require significant changes to systems, processes, governance structures, reporting lines, staff training, and internal controls. Firms must often manage multiple regulatory obligations simultaneously while operating within constraints of time, resources, technology, and competing business priorities.

I gained a much greater appreciation for these realities after moving into industry. One of the first things that struck me was how much work is required before implementation can even begin. Requirements must be interpreted, assessed against existing business models, discussed across multiple departments, and translated into practical actions. Compliance is rarely a simple exercise in applying rules. It requires coordination, planning, professional judgement, and often significant organizational change.

A recent example that illustrates this challenge is the implementation of legislative amendments affecting securities dealers. From a regulatory perspective, requirements such as the appointment of a resident director or increases in minimum paid-up share capital are intended to strengthen governance, accountability, and financial resilience. These objectives are both understandable and important. However, firms may face practical constraints in meeting them. In smaller jurisdictions, there may be a limited pool of suitably qualified individuals available to serve as resident directors. Increased capital requirements may also require firms to secure additional funding, reassess growth plans, or adjust their operating model. The policy objective may be clear, but achieving it can involve significant operational and financial considerations.

My experience in industry also reinforced the importance of the regulatory perspective. Within organisations, it can be easy to view certain requirements as administrative burdens, particularly when resources are stretched and deadlines are tight. Yet many regulatory obligations exist because previous failures exposed weaknesses in governance, risk management, or oversight. What may appear excessive from an operational standpoint is often rooted in lessons learned from real-world events.

One of the most valuable lessons I have learned is the importance of constructive engagement. During my years in supervision, I occasionally encountered firms that were reluctant to engage with regulators until issues had already become significant. There can be a perception within industry that regulators should only be approached when absolutely necessary, or that engagement may attract unwanted attention. As a result, firms may hesitate to seek clarification, discuss implementation challenges, or raise concerns at an early stage.

In reality, many regulatory issues become more difficult precisely because communication happens too late. Early engagement allows firms to clarify expectations, identify potential obstacles, and address concerns before they escalate. Equally, regulators benefit from understanding how proposed requirements operate in practice. Open dialogue can highlight implementation challenges, unintended consequences, and areas where additional guidance may be beneficial, often leading to more effective and proportionate outcomes.

From experience on the regulatory side, I have found that regulators generally recognize that firms operate in complex and constantly evolving environments. The focus is often not on perfection, but on whether firms understand their obligations, manage risks appropriately, and respond proactively when issues arise. Supervisory engagement, guidance, and ongoing dialogue can help bridge the gap between regulatory intent and practical implementation, while also providing supervisors with greater insight into the operational realities faced by the firms they oversee.

I have also found that the most productive regulatory relationships are characterized by trust, transparency, and constructive engagement rather than being driven solely by the prospect of enforcement. While enforcement remains an important part of the regulatory framework, it is only one aspect of a broader supervisory approach. Regulators often provide guidance, communicate expectations, and promote good practices alongside their supervisory and enforcement functions. Open communication can foster mutual understanding and help achieve better outcomes for firms, supervisors, and the wider market.

This philosophy also underpins FiveComply’s approach. We work alongside regulated entities to bridge the gap between regulatory expectations and operational implementation, helping firms develop practical compliance solutions, strengthen governance frameworks, and maintain constructive relationships with regulators. By combining regulatory insight with industry experience, we support firms in navigating increasingly complex regulatory environments while maintaining effective and sustainable compliance programmes.

Looking back, I recognize that there were occasions when I underestimated the practical challenges firms faced while working as a regulator, just as there were times in industry when I gained a deeper appreciation of the considerations that shape regulatory expectations. Experience on both sides has reinforced that neither viewpoint is complete on its own. Regulators have visibility of systemic risks and recurring weaknesses across the market, while firms are closer to the operational realities involved in implementing change within complex organizations.

The most successful regulatory outcomes rarely emerge from rules alone. They arise when regulatory objectives are clearly understood, implementation challenges are openly discussed, and both sides recognize their shared responsibility for maintaining trust, protecting stakeholders, and supporting well-functioning markets. Regulators and industry may approach issues from different angles, but they are ultimately working towards the same goal. Effective regulation is strengthened not by choosing one perspective over the other, but by recognizing the value of both.

 

Disclaimer: This article is provided for general informational purposes only and does not constitute legal, regulatory, tax, or professional advice. Readers should seek independent professional advice before acting on any information contained herein.

Author

Sheryl Laporte

Outsourced Compliance Officer

FSC Mauritius Issues New Guidelines on the Frequency of Customer Due Diligence Reviews

The Financial Services Commission (FSC) Mauritius has issued new Guidelines on the Frequency of Customer Due Diligence (CDD), providing greater clarity on the timing and frequency of customer reviews that financial institutions and other regulated entities must undertake as part of their AML/CFT obligations.

Issued under the Financial Services Act and the Financial Intelligence and Anti-Money Laundering Act (FIAMLA), the Guidelines become effective on 8 June 2026 and introduce specific minimum review periods for existing customers based on their risk profile.

Why the Guidelines Matter

Customer Due Diligence is a cornerstone of an effective AML/CFT framework. While firms have long been required to maintain up-to-date customer information and conduct ongoing monitoring, the FSC has now formalised minimum review frequencies to ensure that customer information remains accurate, relevant and risk sensitive.

The Guidelines emphasise that relying solely on trigger events is no longer sufficient. Instead, firms are expected to implement periodic reviews of customer information even where no specific event has occurred.

Minimum CDD Review Frequencies

Under the new Guidelines, firms are expected to conduct reviews of existing customer due diligence information at the following minimum frequencies:

Customer Risk Category Minimum Review Frequency
High Risk At least once every year
Medium Risk At least once every three years
Low Risk At least once every four years

These review periods represent minimum requirements and firms may choose to conduct reviews more frequently where justified by their risk assessment.

Trigger Events Still Apply

The FSC has clarified that periodic reviews do not replace event-driven reviews.

CDD reviews must also be undertaken whenever significant events or circumstances arise, including:

  • Material changes in ownership or management structures;
  • Changes in the risk classification of the customer’s jurisdiction;
  • Identification of a Politically Exposed Person (PEP);
  • Inconsistencies in customer information or verification documents;
  • Expired or invalid identification information;
  • Adverse media or negative information identified through screening processes; and
  • Requests for new products or services that carry a higher level of risk.

The list is not exhaustive, and firms are expected to exercise professional judgment in identifying circumstances that warrant additional due diligence.

One-Year Implementation Period

The FSC expects licensees to establish and implement appropriate procedures and timelines to comply with the new requirements.

Importantly, reviews of existing customers should be completed within one year from the effective date of the Guidelines. This means firms should begin assessing their customer populations, risk classifications, and existing review schedules without delay.

Practical Considerations for Licensees

The new requirements present an opportunity for regulated entities to reassess the effectiveness of their AML/CFT frameworks. Firms should consider:

  • Reviewing customer risk-rating methodologies;
  • Ensuring customers are appropriately categorised as low, medium or high risk;
  • Implementing automated review reminders and monitoring controls;
  • Updating AML/CFT policies and procedures;
  • Maintaining clear audit trails of completed reviews; and
  • Ensuring adequate compliance resources are available to meet review deadlines.

Particular attention should be given to high-risk customers, where annual reviews will now be a minimum regulatory expectation.

Regulatory Consequences of Non-Compliance

The FSC has indicated that compliance with the Guidelines will be supervised and enforced through its regulatory powers.

Failure to comply with directions issued by the FSC may result in regulatory action and may expose firms to sanctions under the Financial Services Act, including financial penalties and other enforcement measures.

How FiveComply Can Assist

The implementation of risk-based CDD review cycles may require enhancements to compliance frameworks, customer risk assessment methodologies, monitoring procedures and governance arrangements.

FiveComply assists regulated entities in Mauritius and other international financial centres with:

  • AML/CFT framework reviews;
  • Customer risk assessment methodologies;
  • Independent AML audits;
  • Compliance monitoring programmes;
  • Regulatory gap analyses; and
  • Ongoing Compliance support.

For further information on how these Guidelines may affect your business, please contact our team.

 

Disclaimer: This article is provided for general informational purposes only and does not constitute legal, regulatory, tax, or professional advice. Readers should seek independent professional advice before acting on any information contained herein.

Author

Nayia Xiari

Partner / General Manager – Offshore Division

End of Transition Period Approaches for Seychelles Securities Dealers

The Securities (Amendment) Act, 2024 and related regulations, which came into force on 1 January 2025, introduced a number of changes affecting the operations and compliance obligations of Seychelles Securities Dealers. Existing licensees were granted an 18-month transition period to implement the new requirements, with compliance required by 30 June 2026.

As the transition period draws to a close, securities dealers should assess whether any additional measures are required to comply with the amended requirements. Some of the key changes are outlined below.

 

Enhanced Local Presence and Oversight

Licensed entities are required to maintain at least two resident fit and proper individuals in Seychelles who serve as directors, compliance officers or members of managerial staff.

 

Improved Client Classification and Investor Protection

The amended Conduct of Business Regulations introduced client classification requirements, requiring securities dealers to categorise clients as either retail or professional clients.

For certain leveraged and higher-risk products, securities dealers must conduct appropriateness assessments to determine whether a retail client possesses sufficient knowledge, experience and financial capacity to understand and absorb the associated risks.

The regulations also limit a retail client’s liability to the funds held in the client’s trading account.

 

Strengthened Complaint Handling Requirements

Licensed entities are required to appoint a resident individual responsible for complaints handling and establish internal procedures for managing complaints effectively. These procedures must be submitted to the Seychelles Financial Services Authority for approval before implementation.

 

The amended regulations also introduced specific requirements relating to the documentation of client complaints and the maintenance of a complaints database.

 

Clearer Risk Warnings for Investors

Securities dealers must include prominent risk warnings in their advertisements. These warnings must inform investors about potential losses, the risks associated with leveraged trading and the complexity of products such as CFDs, futures and options.

These warnings must be clearly displayed, including on websites and mobile applications.

 

Higher Capital Requirements

The reforms increased the minimum issued and paid-up capital requirement for securities dealers from US$50,000 to US$100,000. The capital must also be maintained in an approved bank account.

 

For further information on the amendments, please contact FiveComply.

 

Disclaimer

For information purposes only. This publication does not constitute legal, regulatory, financial or investment advice.

 

Author

Sheila Chua

Outsourced Compliance Officer

Why AML Audits Matter in Mauritius: Key FSC Expectations for Regulated Entities

Mauritius continues to strengthen its position as a reputable international financial centre through an increasingly robust Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) framework. As the jurisdiction aligns more closely with Financial Action Task Force (FATF) standards, the Financial Services Commission (FSC) has placed growing emphasis on governance effectiveness rather than purely procedural compliance.

Recent FSC enforcement actions demonstrate a clear regulatory trend: AML compliance is no longer assessed solely on the existence of policies and documentation, but on whether governance frameworks operate effectively in practice.

For FSC-regulated entities, including Global Business Licence (GBL) entities, investment firms, insurers, and a wide range of licensed intermediaries, this means AML governance must become more proactive, risk-based, and operationally integrated.

At FiveComply, we support licensed and licence-seeking entities in Mauritius and internationally with AML governance reviews, compliance assessments, independent AML audits, and regulatory readiness projects aligned with FSC expectations and international best practice.

1.  The Regulatory Landscape in Mauritius

AML/CFT obligations in Mauritius are primarily governed by the Financial Intelligence and Anti-Money Laundering Act (FIAMLA), supported by the Financial Intelligence and Anti-Money Laundering Regulations, FSC-issued codes, and the detailed guidance set out in the FSC Handbook.

The FSC applies a risk-based supervisory approach aligned with FATF standards. Regulated entities are therefore expected not only to implement AML controls, but also to demonstrate that those controls are proportionate to their risk profile, properly implemented, and continuously monitored.

2. What AML Governance Means in Practice

Under FSC expectations, effective AML governance is generally built around:

  • Board and senior management oversight
  • Independent compliance functions
  • Enterprise-wide risk assessments (EWRA)
  • Clear escalation and reporting procedures
  • Internal audit and independent assurance
  • Risk-based customer due diligence and monitoring

A key regulatory expectation is that AML responsibility cannot be delegated entirely to compliance teams. Boards and senior management remain ultimately accountable for the effectiveness of the AML framework.

From our experience at FiveComply, many governance weaknesses observed in practice stem not from the absence of policies, but from the lack of meaningful oversight, ownership, and operational integration of those policies.

3. Common Weaknesses Identified in FSC Enforcement Actions

FSC enforcement actions continue to highlight recurring deficiencies across regulated entities.

Limited Board Engagement in AML Oversight

Boards often receive AML reporting without sufficient challenge, documentation, or active involvement in risk management decisions.

At FiveComply, we regularly support boards and senior management teams in strengthening AML reporting frameworks to ensure that oversight is both structured and demonstrable.

Weak or Static Enterprise-Wide Risk Assessments

Enterprise-wide risk assessments are frequently generic, outdated, or poorly connected to operational controls and onboarding processes.

Customer Due Diligence and Beneficial Ownership Gaps

Common issues include incomplete KYC files, insufficient beneficial ownership verification, and inconsistent application of enhanced due diligence measures.

Ineffective Transaction Monitoring Frameworks

Regulators increasingly focus on whether monitoring systems are properly calibrated, alerts are meaningfully investigated, and suspicious activity escalation processes function effectively.

Weak Compliance Function Independence

Insufficient resourcing, unclear reporting lines, and operational interference can significantly reduce the effectiveness of AML compliance functions.

4. Enforcement Actions Reflect Broader Regulatory Expectations

FSC enforcement actions should not be viewed purely as punitive measures. They also provide insight into the regulator’s evolving supervisory priorities.

Regulated entities are increasingly expected to demonstrate not only that controls exist, but that they are effective in practice and supported by appropriate governance structures.

In this environment, proactive governance reviews and independent AML assessments are becoming increasingly important components of regulatory preparedness.

5. Key Lessons for Regulated Entities

Based on current enforcement trends, regulated entities should focus on:

  • Embedding AML governance at board level
  • Maintaining dynamic and evidence-based risk assessments
  • Ensuring compliance functions are independent and properly resourced
  • Strengthening internal audit and independent AML testing
  • Enhancing governance documentation and escalation frameworks

At FiveComply, we assist regulated entities in Mauritius with AML governance assessments, EWRA reviews, independent AML audits, remediation projects, and FSC regulatory readiness support aligned with evolving regulatory expectations and international best practices.

As FSC supervision continues to evolve towards effectiveness-focused compliance, proactive governance reviews and independent AML assessments are becoming essential for regulated entities seeking to strengthen their AML/CFT frameworks and reduce regulatory risk.

Disclaimer
This article is provided for general informational purposes only and does not constitute legal, regulatory, or tax advice.

Author

Maria Andreou

Regulatory Audit Supervisor – Offshore Division

The Evolving Role of Internal Audit in Cyprus Regulated Firms

The Internal Audit Function forms an important part of the governance and internal control framework of Cyprus regulated firms. Both the Cyprus Securities and Exchange Commission (“CySEC”) and the Central Bank of Cyprus (“CBC”) require regulated entities to maintain an independent Internal Audit Function responsible for assessing the adequacy and effectiveness of the institution’s systems, internal controls, policies, and procedures, in a manner proportionate to the nature, scale, and complexity of its activities.

In parallel, increasing regulatory focus on ICT risk management and operational resilience, particularly following the introduction of DORA, has further expanded supervisory expectations relating to internal control and assurance functions.

 

CySEC Expectations for Internal Audit Functions

 CySEC’s framework, including Circular C056 and subsequent supervisory guidance, places particular emphasis on the provision of independent assurance to the Board of Directors and Senior Management on the quality and effectiveness of the regulated entity’s internal control, risk management and governance systems and processes, including the assessment of internal controls, governance arrangements, AML/CFT procedures, and ICT and cybersecurity controls.

In relation to ICT and cybersecurity risks, recent CySEC Circular C751 relating to the requirements of Regulation (EU) 2022/2554 (“DORA”) states that ICT risk management frameworks are expected to be subject to regular internal audit reviews in line with the regulated entity’s audit plan and ICT risk profile. CySEC further emphasises the importance of appropriate segregation and independence between ICT risk management functions, control functions, and internal audit functions, as well as the establishment of formal follow-up procedures for the remediation of ICT audit findings.

Internal audit is expected to operate with an unrestricted scope covering all activities of the regulated entity, including outsourced activities. In determining the scope of its work, the Internal Audit Function is expected to independently identify and assess the key risks faced by the institution, including emerging and systemic risks, and evaluate how effectively these risks are being managed.

There should be no impediment to the Internal Audit Function’s ability to challenge senior management and report its concerns to the Board of Directors (“Board”).

The Internal Auditor is also responsible for establishing, implementing, and maintaining a risk-based internal audit plan. Audit planning is expected to focus on areas where risks are considered higher, while also taking into consideration the views of the Board and other control functions.

 

CySEC’s framework also places emphasis on the content and quality of Internal Audit Reports (“IA Reports”). IA Reports are expected to include:

  • an overall description of the institution’s internal control, risk management, and governance framework;
  • a description of the audit plan and the risk-based approach followed;
  • details of regular and/or extraordinary audits performed;
  • major findings and weaknesses identified during the audit process;
  • recommendations proposed in relation to identified findings and deficiencies;
  • management responses and corrective actions taken;
  • any outstanding issues where remediation measures remain pending or insufficient; and
  • follow-up procedures relating to previously identified findings and outstanding matters.

CySEC also expects IA Reports to be discussed by the Board, with Board minutes clearly documenting the corrective measures to be taken and the timetable for their implementation. The IA Report must be submitted to CySEC along with the minutes within 20 days from the date of the relevant meeting and not later than 4 months from the end of the calendar year.

 

The Central Bank’s of Cyprus (“CBC”) Expectations for Internal Audit Functions

The CBC has also increased supervisory focus on the content, scope, structure, and quality of IA Reports submitted by Electronic Money Institutions and Payment Institutions.

The recent CBC Guidance issued in January 2026, sets out the CBC’s minimum expectations regarding the annual submission of IA Reports and emphasises that institutions should uphold high standards of independence, professionalism, and transparency in the execution of their Internal Audit Functions.

The CBC further states that institutions are encouraged to utilise the IA Report as a strategic tool for risk management and continuous improvement, rather than merely as a regulatory compliance deliverable.

 

According to the CBC Guidance, each IA Report should commence with a concise Executive Summary which should:

  • clearly state the audit scope, areas assessed, timeframe covered, and any exclusions or limitations concerning key risk areas;
  • provide the Internal Auditor’s opinion on the overall internal control environment of the institution;
  • summarise key audit findings, systemic weaknesses, and high-level recommendations for improvement; and
  • include comments on remediation progress, management corrective actions, and relevant timelines.

The CBC also states that the Audit Plan for the forthcoming year (for the year ending 31 December 2025) should be risk-based and forward-looking and communicated to the relevant approving Board Authority in a timely manner. The Internal Auditor is expected to determine audit work based on the severity and criticality of the respective risks and verify the integrity of processes ensuring the reliability of the institution’s methods, techniques, assumptions, and information sources used in internal calculations and models.

 

The CBC further expects IA Reports to include:

  • reference to the audit area or section reviewed;
  • detailed description of identified deficiencies and the audit work performed, including the sample selected for review;
  • classification of findings according to risk level and potential adverse impact;
  • recommendations for corrective actions;
  • management responses, agreed remediation plans, and expected timeframes for resolution; and
  • follow-up on outstanding issues from previous audit engagements, including implementation status, delays, responsible owners, and updated target completion dates.

The CBC Guidance also states that Internal Auditors are expected to cover, on a yearly basis, key operational areas including:

  • safeguarding of client funds;
  • adequacy of governance arrangements;
  • outsourcing arrangements and their review/monitoring;
  • ICT risks;
  • AML/CFT framework and monitoring;
  • controls relating to ongoing compliance with licensing obligations and capital adequacy requirements; and
  • controls relating to the ongoing correctness of regulatory reporting submissions.

In relation to ICT risks, the CBC specifically refers to review of the ICT risk management framework and ICT response and recovery plans under Regulation (EU) 2022/2554 (DORA). The Guidance also notes that micro-enterprises may perform these procedures on a best-effort basis.

Finally, the CBC states that IA Reports should be formally reviewed and approved by the institution’s Board of Directors, with Board minutes documenting the discussion and approval of the report made available to the CBC upon request.

 

Final Remarks

The role of internal audit within Cyprus regulated firms continues to evolve in line with increasing regulatory expectations relating to governance, internal controls, risk management, and operational resilience.

As regulatory frameworks continue to develop, Internal Audit Functions are expected to maintain effective and independent assurance processes capable of supporting sound governance and appropriate oversight of the institution’s activities.

A well-structured Internal Audit Function contributes not only to regulatory compliance, but also to the ongoing assessment and strengthening of the institution’s control environment and governance framework.

At FiveComply, we support Cyprus regulated firms through the provision of risk-based Internal Audit services tailored to the nature, scale, and complexity of each institution’s activities, while taking into consideration the evolving expectations of CySEC, the CBC, and the broader European regulatory framework. We seek to adopt a holistic approach in assessing the institution’s governance, control, risk management, operational, and compliance frameworks, while applying a risk-based methodology that places greater focus on areas carrying higher levels of risk and regulatory significance.

Author

Konstantina Makri

Compliance Associate – EU & MENA Region

How to Get a Seychelles Securities Dealer License: Requirements, Process & Benefits

Seychelles remains a popular jurisdiction for forex brokers, CFD providers and generally international financial groups seeking a regulated and commercially practical licensing framework.

A Securities Dealer Licence, issued by the Financial Services Authority (FSA) Seychelles, allows a company to conduct securities dealing activities under a recognised regulatory framework. For entities looking to expand internationally, the Seychelles SDL can be an attractive licensing route, provided that the application is properly structured from the outset.

At FiveComply, we support clients throughout the Seychelles Securities Dealer Licence application process, from the initial structuring stage to company incorporation, preparation of the application package and communication with the FSA.

1.What is a Seychelles Securities Dealer Licence?

A Seychelles Securities Dealer Licence, also known as an SDL, authorises a company to carry out securities dealing activities from Seychelles, subject to the scope approved by the FSA.

The FSA will assess the overall strength of the applicant, including its business model, ownership structure, financial position, governance arrangements, key appointments and operational readiness.

For this reason, the application should be prepared carefully and consistently, with all supporting documents aligned with the proposed activities of the company.

2. Minimum Capital and Structure Requirements

A key part of the Seychelles SDL application is ensuring that the company has a proper corporate and capital structure.

The current capital requirement for a Seychelles Securities Dealer Licence is USD 100,000. The applicant must be able to demonstrate that the capital is properly supported and that the structure is transparent and suitable for the proposed regulated business.

From a structuring perspective, the FSA will generally expect the applicant to have:

  • a properly incorporated Seychelles company;
  • a minimum of two fit and proper directors;
  • a minimum of two shareholders (corporate/legal entity or individuals);
  • at least one fit and proper director resident in Seychelles;
  • complaints officer resident in Seychelles;
  • fit and proper compliance officer (outsourced or inhouse) resident in Seychelles;
  • clearly identified ultimate beneficial owners;
  • sufficient KYC and due diligence documentation for all key persons;
  • a clear group structure, where corporate shareholders are involved.

 

The structure should be demonstrated properly, be transparent and supported by proper due diligence documentation. Where corporate shareholders are involved, the ownership chain must be clearly presented to the FSA.

As FiveComply, we add value during the whole licensing process by assisting clients in reviewing the proposed structure before submission, helping to identify any issues and prevent delays or additional regulatory queries.

3. Incorporation and SDL Application Process

The Seychelles SDL process begins with the proper setup of the applicant company as a domestic entity and the preparation of a complete application package for submission to the FSA.

At this stage, FiveComply takes a proactive and structured approach to ensure that the company is established under the correct corporate structure and in line with the intended licensing structure from the outset. Our team focuses on early identification of potential gaps, alignment of the corporate structure with the SDL requirements, and efficient coordination of the documentation required for the application.

Following incorporation, FiveComply prepares and coordinates the Securities Dealer Licence application package, ensuring that the business plan, policies, manuals, due diligence documentation and supporting information are consistent, professionally presented and aligned with the FSA’s expectations.

By managing the process efficiently and maintaining a regulator-focused approach, FiveComply helps clients reduce avoidable delays, respond effectively to FSA queries and move through the licensing process with greater clarity and confidence.

4. Substance Requirements

Substance is an important element of the Seychelles SDL application and is assessed in line with the applicant’s proposed activities and overall operating model.

As part of the application, the applicant is expected to demonstrate appropriate arrangements in Seychelles, including a suitable local business office, resident director arrangements, compliance and complaints handling functions and other operational arrangements relevant to the proposed business.

The substance structure should be proportionate to the scale and nature of the company’s activities and should be clearly reflected in the application documents, including the business plan, manuals and supporting information submitted to the FSA.

FiveComply can assist clients in assessing the appropriate substance approach for their proposed structure and, where required, coordinate the relevant local arrangements in Seychelles.

Through our established local presence and dedicated team of experts, we have developed a strong network of qualified and fit-and-proper professionals, allowing us to provide suitable and flexible solutions across our extensive international client portfolio.

5. Governance Requirements and Key Appointments

Governance is a central part of the FSA’s assessment.

The applicant must demonstrate that the company will be managed and controlled by suitable individuals with the necessary experience, integrity and understanding of the proposed regulated activities.

Key appointments include the Directors, Securities Dealer Representative, Compliance Officer, and Alternate Compliance Officer (where applicable).

The Securities Dealer Representative (SDR) is an important appointment in the SDL application. The SDR acts on behalf of the licensee in relation to securities business and should have relevant experience in securities dealing, brokerage, investment services or a related regulated environment.

The FSA will review the background and suitability of the proposed key persons as part of its fit and proper assessment. Therefore, selecting the right individuals from the beginning is essential for a strong application and this is where FiveComply’s expertise could be utilised.

6. Why Work with FiveComply for Seychelles SDL Licensing?

At FiveComply, our involvement goes beyond the preparation of application documents. We work with clients from the initial structuring stage to ensure that the proposed setup is commercially practical, operationally scalable and aligned with the expectations of the FSA Seychelles under the applicable Securities Act framework.

As a leading provider in Seychelles and through our experience in Seychelles licensing projects, we understand the regulatory and practical considerations surrounding corporate structure, capital planning, governance, local substance, key appointments and application preparation.

FiveComply has also established a strong operational network in Seychelles, working with local professionals and stakeholders involved in the licensing process. This allows us to provide efficient, practical and well-coordinated support throughout the SDL application journey.

Our Seychelles SDL licensing package includes:

  • assessment of the proposed corporate and ownership structure;
  • evaluation of CVs of proposed individuals;
  • guidance on Securities Dealer Licence requirements;
  • support with capital, governance and substance planning;
  • preparation of business plans and financial projections;
  • drafting of internal manuals, policies and operational documentation;
  • guidance on the appointment of the resident director and local office requirements;
  • provision of Compliance Officer and guidance on AML/CFT arrangements;
  • coordination with local professionals and service providers;
  • appointment of Complaints Officer;
  • preparation of the SDL application package;
  • regulatory communication and application management with the FSA, including regular follow-ups with the FSA officers.

 

Whether a business is launching a new brokerage, expanding into Seychelles or strengthening an existing international setup, proper structuring and preparation from the outset can make a significant difference to the licensing process.

If you are considering a Seychelles Securities Dealer Licence application, FiveComply can assist in assessing your proposed structure and preparing a clear, complete and professionally presented application for submission to the FSA.

Disclaimer

This article is provided for general informational purposes only and does not constitute legal or tax advice.

Author

Elli Crystalli

Licensing Associate – Offshore Division