What the First Half of 2026 Tells Us About the FSA Seychelles’ Regulatory Priorities

FiveComply’s Regulatory Analysis for Seychelles Securities Dealers
The first half of 2026 has been a significant period for Securities Dealers operating in Seychelles. A combination of legislative changes, new regulatory requirements, supervisory communications and implementation deadlines has altered both the substance of Securities Dealers’ obligations and the standard against which compliance is likely to be assessed.
Individually, each development addresses a particular regulatory concern. The resident director requirement strengthens local governance. The appointment of a Local Complaints Liaison Officer enhances local oversight and supports the coordination and escalation of complaints within the firm’s established framework. The increase in minimum paid-up share capital reflects a heightened prudential expectation that licensed entities maintain an appropriate capital base commensurate with the nature, scale and risks of their regulated activities. Negative balance protection and appropriateness assessments strengthen safeguards for retail clients. At the same time, the new Code of Corporate Governance places greater emphasis on Board accountability, risk oversight, internal controls, audit arrangements and transparent decision-making.
The FSA has also continued to reinforce expectations concerning new-product risk assessments, Financial Intelligence Unit registration, FATF monitoring and ongoing AML/CFT compliance.
When these developments are considered collectively, a broader regulatory direction begins to emerge.
At FiveComply, our assessment is that the Financial Services Authority is moving beyond a supervisory model focused primarily on whether a firm has formally addressed each regulatory requirement. Increasingly, the focus appears to be on whether the firm can demonstrate that its governance arrangements, internal controls and compliance processes operate effectively in practice.

For Securities Dealers, the relevant question is therefore no longer simply:
‘’Have we implemented the latest regulatory requirements?’’
The more important question is:
‘’Can we demonstrate that our governance, risk management and control environment work effectively, consistently and in accordance with the firm’s actual business model?’’

This article examines the principal regulatory themes emerging from H1 2026 and provides FiveComply’s assessment of the potential gaps Securities Dealers should now consider.

 

The Regulatory Direction Appears to Be Shifting from Form to Effectiveness
Financial services regulation often develops in stages. The first stage establishes the legal and licensing framework. Firms are required to appoint key persons, significantly enhance manuals, maintain capital and comply with prescribed reporting obligations.
The next stage focuses on implementation. Regulators begin examining whether the required appointments have been made, whether policies have been adopted and whether regulatory submissions are being completed correctly and on time.
As a regulatory framework matures, supervision increasingly moves towards effectiveness. At this stage, the regulator is no longer satisfied merely because a policy exists or an individual has been appointed. The focus shifts towards whether the firm can demonstrate that the policy is followed, that the appointed person performs a meaningful function and that the Board understands and oversees the risks arising from the business.
In our experience supporting regulated financial services firms across different jurisdictions, this transition is one of the most important stages in the development of a supervisory framework. It creates a clear distinction between firms that are compliant on paper and firms whose governance and control arrangements are genuinely embedded into their operations.
The regulatory developments introduced during H1 2026 suggest that this distinction is becoming increasingly relevant for Securities Dealers in Seychelles.
Corporate Governance Is Becoming a Core Supervisory Benchmark
The introduction of the FSA’s Code of Corporate Governance represents one of the most important developments affecting regulated entities.
The Code applies to licensees under the Securities Act, subject to specified exclusions, and introduces nine broad principles covering Board responsibilities, independence, Board composition, corporate culture, remuneration, risk oversight, corporate reporting, internal and external audit, and conflicts of interest. It operates on an “apply or explain an alternative” basis and has the force of law.
The importance of the Code lies not only in the individual requirements it introduces, but also in the supervisory philosophy it reflects.
Historically, a Securities Dealer may have demonstrated governance by maintaining the required number of directors, conducting Board meetings and obtaining resolutions for material decisions. The new framework expects considerably more. The Board is expected to understand the licensed entity’s strategy, oversee management, assess risk, challenge decisions, monitor internal controls and take responsibility for the effectiveness of the compliance function.
The Code also addresses Board committees, succession planning, director competence, conflicts of interest, internal audit, external audit, remuneration, business continuity and the quality of corporate reporting. In addition, licensees are required to complete an annual Corporate Governance Disclosure Form and submit it by 31 December each year.
In practical terms, governance is becoming a matter of evidence.
A Securities Dealer may have a Board Charter and documented terms of reference, but those documents will have limited value if the Board does not receive meaningful management information, challenge management decisions or regularly consider compliance and risk matters.
Similarly, a firm may hold the required number of Board meetings, but the minutes should demonstrate more than the formal approval of resolutions. They should provide evidence that directors received sufficient information, considered the relevant risks, raised questions and reached an informed decision.
This is where many governance gaps arise. Board minutes are often drafted as a record of outcomes rather than a record of oversight. They may confirm that a policy was approved without documenting the key issues considered, the questions raised or the basis on which the Board concluded that the policy was appropriate.
Another common gap concerns delegation. Securities Dealers frequently rely on outsourced compliance providers, group functions, external advisers or senior management. Such arrangements can be appropriate and efficient, but they do not remove the Board’s ultimate responsibility.
The Code specifically reinforces that delegation does not absolve the Board from responsibility for the sound governance of the company.
The regulatory gap is therefore not necessarily the absence of a policy or procedure. It may be the absence of evidence showing that the Board owns, understands and oversees the relevant matter.
In our view, Securities Dealers should now assess whether their governance framework reflects the reality of their operations. A generic Board Charter or governance manual will not be sufficient where the firm’s actual reporting lines, outsourcing model, target markets and decision-making processes are materially different.
A credible framework should explain who is responsible, what information is provided, how matters are escalated, how decisions are recorded and how the Board satisfies itself that delegated functions are operating effectively.
The FSA Appears to Be Placing Greater Weight on Local Substance
The regulatory reforms introduced during the first half of 2026, including the Resident Director requirement, the appointment of a Local Complaints Liaison Officer and the increase in minimum paid-up share capital, should not be viewed as isolated compliance obligations. In our view, these developments collectively indicate a broader regulatory emphasis on strengthening the operational substance and governance of licensed entities in Seychelles.

Rather than focusing solely on whether the prescribed appointments have been made or the applicable capital thresholds have been met, the broader regulatory objective appears to be ensuring that Securities Dealers maintain governance structures and prudential foundations that are proportionate to the nature, scale and complexity of their regulated activities. Collectively, these measures reinforce the expectation that licensed entities demonstrate a meaningful presence within the jurisdiction and maintain governance arrangements capable of supporting effective regulatory oversight.

The Resident Director requirement is a clear example of this direction. While the appointment itself satisfies a regulatory requirement, its broader significance lies in strengthening the governance framework of the licensed entity through local Board representation and facilitating effective oversight of the firm’s activities. However, the appointment should not be regarded as an end in itself. A Resident Director should be appropriately integrated into the firm’s governance framework by receiving timely management information, participating in Board deliberations and being provided with the information necessary to discharge the responsibilities of the role effectively.

Similarly, the introduction of a Local Complaints Liaison Officer should not be interpreted as transferring responsibility for complaints handling or regulatory compliance. Rather, the role supports the firm’s existing complaints-handling framework by providing a local point of coordination and facilitating effective communication and engagement where required. Ultimate responsibility for complaints handling, as with all regulatory obligations, remains with the licensed entity and its Board of Directors.

The increase in minimum paid-up share capital should also be considered within this broader context. In our view, this measure reflects a strengthened prudential expectation that licensed entities maintain an appropriate capital base commensurate with the nature, scale and risks of their regulated activities. While the minimum capital requirement remains a licensing condition, it also reinforces the importance of maintaining an appropriate level of financial standing to support the firm’s regulated activities and its ongoing compliance with the prudential framework.

From our experience advising regulated financial institutions, one of the most common implementation gaps is treating each of these requirements as an individual compliance exercise. Firms update their organisational chart, appoint the required individuals and submit the necessary notifications, yet the broader governance framework often remains unchanged. Reporting lines, Board procedures, governance documentation and internal escalation mechanisms are not always reviewed to reflect the new regulatory landscape.

In our assessment, this is where Securities Dealers should focus their attention. The regulatory developments introduced during H1 2026 suggest that the Authority is increasingly interested not only in whether the prescribed requirements have been implemented, but whether they have been meaningfully embedded into the firm’s governance and operating model. Demonstrating that appointments, governance arrangements and prudential safeguards operate cohesively within the organisation is likely to be considerably more persuasive than evidencing compliance with each requirement in isolation.

Capital Is Becoming a Governance Issue, Not Merely a Licensing Requirement
The increase in minimum paid-up share capital strengthens the prudential framework applicable to Securities Dealers.
Capital requirements are sometimes treated as a one-off licensing or finance exercise. The firm receives shareholder funding, obtains the necessary evidence and submits confirmation to the regulator. However, this approach overlooks the broader governance objective.
Capital is intended to support the firm’s ability to continue operating, absorb losses and meet its obligations. It should therefore be considered within the firm’s risk-management and strategic planning processes.
The Board’s consideration should extend beyond the initial capital contribution to ensuring that the licensed entity continues to maintain an appropriate capital position in accordance with the applicable regulatory requirements and remains capable of meeting its prudential obligations on an ongoing basis.
This becomes particularly important where a Securities Dealer is expanding into new markets, introducing new products, increasing marketing expenditure or relying on shareholder support to maintain operations.
A potential gap arises where capital compliance is tested only at a specific reporting date. The firm may be able to demonstrate that it met the threshold when the capital increase was completed but may not have an ongoing process for monitoring the adequacy and availability of those funds.
In our view, the enhanced capital requirements point towards a more forward-looking approach to prudential supervision. Firms should expect that capital may increasingly be considered alongside the business plan, financial projections, risk assessment and operational resilience arrangements.
The strongest governance approach would therefore involve regular Board oversight of the firm’s prudential position, supported by periodic reporting on compliance with the applicable regulatory capital requirements and consideration of any strategic or operational developments that may have implications for the firm’s ongoing prudential standing.
This is a good example of how technical compliance and governance effectiveness differ. Technical compliance confirms that the required capital was paid. Effective governance demonstrates that the Board understands the firm’s financial position and monitors it on an ongoing basis.
Retail Client Protection Is Becoming Embedded Across the Client Lifecycle
Negative balance protection and appropriateness assessments both strengthen the safeguards applicable to retail clients, although they operate at different stages of the client relationship.
An appropriateness assessment seeks to determine whether a client has the knowledge and experience required to understand the risks associated with the relevant financial products. Negative balance protection seeks to prevent the client from losing more than the funds available in the trading account.
Neither requirement should be treated as a standalone document or system setting.
An effective appropriateness framework should be aligned with the firm’s client classification, target market, onboarding process, product offering and record-keeping arrangements. The questionnaire should be sufficiently relevant to the products offered, and the firm should have a clear methodology for assessing the client’s responses.
The firm should also be able to demonstrate what happens where a client appears to have insufficient knowledge or experience. A warning that is not recorded, retained or linked to the client’s profile may be difficult to evidence during a regulatory review.
The treatment of existing clients requires equally careful consideration. A firm may conclude that a client’s trading history provides evidence of knowledge and experience, but that approach should be supported by a documented methodology and applied consistently.
Negative balance protection must also be reflected across the firm’s control environment. It should be included in client agreements and disclosures, but it should also operate correctly at system level.
The protection may appear straightforward during ordinary market conditions, but the more difficult questions arise during gaps, extreme volatility, system interruptions, multiple positions, corporate actions or delayed execution. Firms should therefore consider whether the system has been tested against realistic scenarios and whether the legal wording accurately reflects the operational outcome.
In our experience, client-protection gaps often arise because the legal documentation, trading systems, CRM and internal procedures are reviewed separately. The client agreement may promise one outcome while the operational system is configured differently. The appropriateness questionnaire may exist, but its result may not influence onboarding or subsequent monitoring.
The broader regulatory direction suggests that the FSA is likely to place increasing emphasis on the complete client journey. The assessment is not merely whether the firm has adopted a questionnaire or included a contractual clause. It is whether the relevant safeguard is consistently implemented from onboarding and trading through to monitoring, complaints handling and account closure.
Risk Management Is Expected to Begin Before the Business Decision
Circular No. 1 of 2026 reminds reporting entities of their obligation to assess money laundering and terrorist financing risks before introducing a new product, business practice or new or developing technology.
The assessment should consider the customer profile, geographic exposure, products, services, delivery channels, transactions, third-party due diligence and technological developments. The outcome must be documented, and where no new product or technology has been introduced, that position should also be stated in the firm’s risk assessment report.
The significance of this circular extends beyond AML/CFT.
It reflects a wider expectation that risk management should influence business decisions before implementation. Compliance should not be asked to review a product after commercial arrangements have been finalised, systems have been developed and the launch date has been announced.
The risk function should be involved early enough to identify concerns, propose mitigating measures and influence the final structure.
This is particularly relevant to Securities Dealers introducing new CFD products, copy-trading services, PAMM or MAM arrangements, automated onboarding, artificial intelligence, outbound dialling systems, new payment channels, new liquidity providers or expansion into higher-risk jurisdictions.
A new-product review should not focus on AML/CFT risk alone. The assessment should also consider licensing scope, target market, client classification, conduct risk, conflicts of interest, disclosures, systems, outsourcing, operational capacity and the impact on the firm’s overall risk profile.
A common gap is the fragmentation of the approval process. Legal may review the contract. Compliance may review the disclosures. Technology may test the system. Operations may establish the workflow. Yet there may be no single document bringing together the overall risk assessment, controls, residual risk and final approval.
In such circumstances, each department may have performed its task, but the firm may be unable to demonstrate that the product was assessed from an enterprise-wide perspective.
At FiveComply, we believe this is one of the clearest indications of the FSA’s evolving supervisory direction. Risk management is expected to become preventive rather than reactive. Firms should be able to demonstrate that risk considerations were part of the original decision, not added after the commercial decision had already been made.
AML/CFT Compliance Is Being Reinforced as a Continuous Governance Responsibility
The FSA’s 2026 AML/CFT communications reinforce that compliance obligations must be actively maintained rather than addressed only during annual reporting periods.
Circular No. 3 of 2026 reminds reporting entities of their obligation to register with the FIU and notify changes to the particulars of Compliance Officers and Alternative Compliance Officers within 30 days. It also highlights the requirement to register the relevant officers on the GoAML platform and the potential consequences of failing to comply.
This may appear to be an administrative obligation, but it has wider governance implications.
Firms often notify the FSA of the appointment or resignation of a Compliance Officer but fail to consider whether a separate FIU notification is required. The regulatory event is treated as a single process even though it may trigger different obligations involving different authorities, deadlines and systems.
This creates a common implementation gap. The appointment may be approved by the FSA, while the GoAML profile, internal reporting procedures and contact information remain outdated.
The FSA’s FATF circulars reinforce the same expectation of ongoing attention. Reporting entities are required to remain current with high-risk and increased-monitoring jurisdictions and apply enhanced due diligence and enhanced ongoing monitoring on a risk-sensitive basis.
The June 2026 FATF developments were subsequently addressed in Circular No. 4 of 2026, which continued to emphasise the need for firms to remain updated and apply the appropriate risk-based measures.
The relevant gap is not simply whether the country-risk list has been updated. The more important question is whether the update has affected the firm’s actual risk management.
Where a jurisdiction’s status changes, the firm may need to reconsider client risk ratings, enhanced due diligence requirements, transaction-monitoring rules, target-market decisions, payment relationships and Board-approved risk appetite.
A policy update that does not result in an operational response does not demonstrate effective compliance.
In our view, the recurring AML/CFT communications point towards a clear supervisory expectation: compliance should operate as a continuous governance function. It should identify external developments, assess their relevance, initiate internal action and report material implications to senior management and the Board.
Compliance Is Evolving from a Control Function into a Governance Function
One of the strongest themes emerging from H1 2026 is the increasing connection between compliance and governance.
Traditionally, the compliance function may have been viewed primarily as the department responsible for maintaining manuals, submitting reports and advising on regulatory questions.
That model is no longer sufficient for a complex Securities Dealer.
Compliance should provide the Board with meaningful insight into the firm’s regulatory exposure, emerging risks, implementation weaknesses and the potential impact of business decisions.
The distinction is important. An operational compliance report may confirm the number of files reviewed, reports submitted or policies updated. A governance-focused compliance report goes further. It explains why a matter is significant, what risk it creates, whether the issue is recurring, what action management has taken and whether the Board needs to intervene.
The Code of Corporate Governance reinforces the Board’s responsibility for the compliance function and requires directors to approve and review the compliance policy and manual annually or as required.
This means that compliance should have sufficient access, authority and independence to escalate concerns directly to the Board. Where the function is outsourced, the Board should still receive appropriate reporting and retain responsibility for assessing effectiveness.
A frequent gap is that compliance is present but not influential. The function produces reports, yet material business decisions are made without its involvement. Findings are raised, but implementation is not tracked. Policies are updated, but system or operational changes do not follow.
In our assessment, firms should expect future supervision to examine not only whether the compliance function exists, but whether it influences governance and decision-making.
The Central Regulatory Question Is Becoming Whether the Board Can Evidence Oversight
Many of the H1 2026 developments ultimately lead back to the Board.
The Board is responsible for the governance framework. It oversees capital, risk, client safeguards, compliance, audit, conflicts of interest and business continuity. It appoints or oversees key function holders and remains accountable even where responsibilities are delegated.
This does not mean that directors must perform management functions. It means that they should receive sufficient information, understand the firm’s risks and exercise informed oversight.
A Board that receives a large volume of operational data is not necessarily an effective Board. The quality of information matters more than quantity.
Board reporting should identify material issues, trends, breaches, overdue actions and decisions requiring approval. It should allow directors to understand the implications and challenge management where necessary.
The Board minutes should then record the substance of that oversight.
This is likely to become increasingly important because effective governance cannot be demonstrated through policies alone. It is evidenced through the firm’s decision-making history.
Where a regulator reviews a material event, it may examine when the Board became aware of the issue, what information it received, what questions were raised, what decision was made and whether the action was followed through.
From a gap-analysis perspective, Securities Dealers should therefore consider whether their governance records would allow an independent reviewer to understand how the Board discharged its responsibilities.
FiveComply’s Regulatory Gap Analysis: Where Firms May Be Most Exposed
Based on our experience advising financial services firms, the most significant regulatory gaps are rarely caused by the complete absence of documentation. They usually arise from inconsistency.
The governance manual may describe one reporting structure while the organisation operates another. The Board may approve a policy but receive no reporting on its effectiveness. A resident director may be appointed but excluded from material decisions. The appropriateness process may be documented but disconnected from the CRM. A FATF list may be updated without reassessing affected clients. A product may be legally reviewed but launched without a consolidated risk assessment.
These gaps are difficult to identify through a document-only review because each individual item may appear compliant when viewed separately.
An effective regulatory gap analysis should therefore assess the connections between governance, policy, systems, people and evidence.
For example, reviewing the complaints framework should involve more than confirming that a Complaints Handling Policy exists. It should consider whether the Local Complaints Liaison Officer is reflected in the policy, whether complaints are recorded consistently, whether root causes are analysed, whether trends are reported to the Board and whether changes are implemented where recurring issues are identified.
Similarly, reviewing negative balance protection should involve more than reviewing the client agreement. It should include system configuration, testing, exception handling, disclosures and complaints procedures.
This integrated approach is where regulatory experience becomes particularly important. Requirements rarely operate in isolation. They interact with the firm’s business model, target market, outsourcing arrangements, technology, governance structure and risk appetite.
A generic compliance checklist may identify whether a document exists. It will not necessarily determine whether the framework is coherent, proportionate or capable of withstanding regulatory scrutiny.
What Securities Dealers Should Prioritise During H2 2026
In our view, the priority for the second half of 2026 should not be the creation of further documents without first assessing the effectiveness of the existing framework.
Securities Dealers should begin by examining whether the changes implemented by 30 June have been fully embedded into their operations. This includes assessing whether local appointments are functioning effectively, whether capital monitoring has become an ongoing Board responsibility and whether retail-client safeguards operate consistently across documentation and systems.
Firms should also assess their readiness for the annual Corporate Governance Disclosure. The disclosure should not be approached as a form-completion exercise in December. The underlying governance arrangements should be reviewed early enough to identify weaknesses, implement changes and obtain appropriate Board approval.
The new-product approval process should also be reviewed. Compliance, risk, legal and operations should be involved before material changes are implemented, and the firm should maintain one consolidated record of the assessment and approval.
AML/CFT governance should be examined with particular attention to FIU registration, GoAML access, changes in key-person details, FATF updates and the operational consequences of changing geographic risks.
Finally, Boards should consider whether the information they receive is sufficient to demonstrate meaningful oversight. The quality of governance reporting and minutes will be central to evidencing that the firm does not merely comply formally, but manages regulatory risk effectively.
FiveComply’s Perspective
After years of advising regulated financial institutions, we have observed that the firms best prepared for regulatory scrutiny are not necessarily those with the greatest number of policies or the largest compliance departments.
They are the firms whose governance arrangements reflect their actual operations, whose Boards understand the material risks and whose control functions are involved before decisions are implemented.
They can demonstrate not only what the policy says, but how the control operates. They retain evidence of decisions, escalation and follow-up. They understand that proportionality does not mean reduced accountability and that outsourcing does not transfer responsibility away from the licensed entity.
Based on the regulatory developments observed during H1 2026, our view is that these characteristics are becoming increasingly important for Securities Dealers in Seychelles.
The FSA’s supervisory direction appears to be evolving beyond technical compliance and towards a more mature assessment of governance effectiveness, operational substance and proactive risk management.
This should not be viewed solely as an additional regulatory burden. Properly implemented governance and risk frameworks support better decisions, reduce operational weaknesses and improve the firm’s ability to respond to regulatory and market change.
The most important lesson from H1 2026 is therefore not that Securities Dealers are subject to more requirements.
It is that the standard of compliance appears to be changing.
The question is no longer only whether the requirement has been addressed.
It is whether the firm can demonstrate that the control works.
How FiveComply Can Assist
FiveComply supports Seychelles Securities Dealers in assessing the effectiveness of their regulatory frameworks and translating complex requirements into practical, proportionate and defensible arrangements.
Our regulatory gap analyses extend beyond confirming whether the required policies and appointments are in place. We assess whether governance arrangements, reporting lines, operational processes, systems and Board oversight work together and whether the firm can evidence that effectiveness under regulatory scrutiny.
Our support includes corporate governance reviews, Board-effectiveness assessments, governance and committee documentation, AML/CFT framework reviews, new-product risk assessments, appropriateness frameworks, negative balance protection implementation reviews, regulatory-notification matrices, client-protection assessments and ongoing implementation support.
For Securities Dealers, H1 2026 should be viewed not only as a period of regulatory change, but as an opportunity to strengthen the foundations of the business before those foundations are tested.

Author

Nicole Zodiatou

Head of Compliance and Legal Support – Offshore Division

CySEC Publishes Practical Guide on External Whistleblowing in the Financial Sector

On 14 July 2026, the Cyprus Securities and Exchange Commission (“CySEC”) announced the publication of a Practical Guide to facilitate the application of Circular C608 and the Protection of Persons who Report Breaches of Union and National Law of 2022 (Law 6(I)/2022), as amended.

 

The Guide provides practical guidance on the external reporting of breaches of Union law within the financial sector and is intended to facilitate the effective implementation of Cyprus’ whistleblowing framework.

 

The publication provides greater clarity on how the external reporting framework operates in practice, including the reporting process, the categories of reportable breaches and the protections available to reporting persons.

 

What is the Purpose of the Practical Guide?

The Guide explains CySEC’s role as the competent external reporting authority for financial services matters and sets out the procedures for receiving, assessing and following up on reports of breaches falling within its supervisory remit.

 

It also sets out the applicable timelines, responsibilities and procedures designed to ensure that reports are handled lawfully and efficiently.

 

Who Can Submit a Report?

The Guide confirms that the external reporting framework applies to a broad range of individuals who obtain information on breaches in a work-related context. Subject to the requirements of the Law, this includes:

  • employees;
  • members of Boards of Directors;
  • shareholders;
  • volunteers;
  • trainees;
  • contractors and subcontractors;
  • former employees; and
  • prospective employees who become aware of potential breaches during the recruitment process.

 

The Guide confirms that eligibility to submit an external report extends beyond current employees and applies to a broad range of individuals connected with an organisation in a work-related context.

 

What Types of Breaches Fall Within CySEC’s Competence?

A particularly valuable feature of the Practical Guide is the extensive collection of practical examples illustrating the types of breaches that may be reported.

 

CySEC explains how the framework applies in real-world situations across numerous areas of financial regulation.

 

Examples include potential breaches relating to:

  • MiFID II / MiFIR;
  • Market Abuse Regulation (MAR);
  • AIFMD;
  • EMIR;
  • Short Selling Regulation;
  • Benchmark Regulation;
  • Transparency Directive;
  • Takeover Bids;
  • Shareholder Rights;
  • Recovery and Resolution of Investment Firms;
  • Investor Compensation Fund requirements; and
  • other breaches of EU law within CySEC’s supervisory responsibilities.

 

The practical examples may also assist regulated entities in better understanding the types of regulatory breaches that could give rise to external reports.

 

Protection of Reporting Persons

The Guide also explains the key protections available to reporting persons, including:

  • confidentiality of the reporting process;
  • protection of personal data and
  • protection against retaliation.

 

Practical Considerations for Regulated Entities

Although the Guide is primarily intended for potential reporting persons, it is also relevant for Cyprus Investment Firms and other regulated entities. The Guide contains numerous practical examples involving investment firms and clarifies the types of regulatory breaches that may be reported to CySEC, the categories of persons who may submit reports and the procedures followed by CySEC in handling external reports. As such, it provides regulated entities with greater transparency regarding the operation of CySEC’s external reporting framework.

 

Key Takeaway

The publication of the Practical Guide complements Circular C608 by providing practical clarification on the operation of CySEC’s external reporting framework. Although it does not introduce new legal or regulatory obligations, it serves as a useful reference for understanding the external whistleblowing process, the categories of reportable breaches and the protections available to reporting persons.

 

 

Author

Konstantina Makri

Compliance Associate – EU & MENA Region

Meet the New Internal Audit Requirements under the Seychelles Corporate Governance Code

The Financial Services Authority of Seychelles has issued the Code of Corporate Governance, introducing enhanced governance expectations for regulated entities. Among the key developments is the increased emphasis on establishing and maintaining an effective Internal Audit function as part of a sound governance, risk management and internal control framework.

Under Principle 8 of the Code, boards are expected to establish independent and effective internal and external audit procedures to ensure the quality and integrity of corporate reporting. Organisations should now assess whether their governance and assurance arrangements meet the expectations set out in the Code.

Some of the key requirements are outlined below.

Dedicated Internal Audit Function

The Code provides that companies should establish a dedicated Internal Audit function with clearly defined oversight and reporting structures. The Internal Audit function should operate independently and provide the board with objective assurance on the effectiveness of the organisation’s governance, risk management and internal control processes.

Effective Internal Control Framework

Boards are expected to oversee the establishment and maintenance of an effective system of internal control to properly manage the organisation’s risks, assets and capital.

The Code further provides that the Internal Audit framework should be measured against internationally accepted internal audit standards and tested annually to assess its adequacy and effectiveness.

Alternative Assurance Arrangements

Recognising that the establishment of a dedicated Internal Audit function may not be appropriate for every organisation, the Code requires companies that have not established such a function to disclose the reasons for its absence to the Financial Services Authority.

In addition, companies must explain how they obtain adequate assurance that their internal control systems remain effective, including the alternative governance or assurance measures implemented.

Role of the Audit Committee

The Audit Committee plays an important role in supporting the board’s oversight responsibilities. Among its responsibilities is reviewing the effectiveness of the organisation’s risk management framework, system of internal controls and Internal Audit function.

Regular reporting and independent assurance assist the Audit Committee and the board in identifying control weaknesses, monitoring remediation efforts and strengthening the organisation’s overall governance framework.

Preparing for Compliance

Organisations should review their existing governance arrangements to determine whether they satisfy the expectations of the Corporate Governance Code. This may include establishing or enhancing an Internal Audit function, reviewing reporting and oversight structures, documenting alternative assurance arrangements where appropriate, and ensuring that internal control systems are subject to regular independent review.

At FiveComply, we assist organisations in designing, implementing and outsourcing Internal Audit functions that are aligned with internationally recognised standards and tailored to the size, complexity and risk profile of each business. We also support organisations in strengthening their governance and internal control frameworks to meet evolving regulatory expectations.

For further information on how FiveComply can assist your organisation in meeting the Internal Audit requirements under the Seychelles Corporate Governance Code, please contact us.

Disclaimer

For information purposes only. This publication does not constitute legal, regulatory, financial or investment advice.

Author

Maria Andreou

Regulatory Audit Supervisor – Offshore Division

AI Can Strengthen Cybersecurity—But It Can Also Break It

Artificial Intelligence (“AI”) is no longer a concept associated solely with innovation and operational efficiency. It has become one of the defining technologies shaping the future of cybersecurity, offering financial institutions significant opportunities to strengthen their cyber defences while simultaneously introducing a new generation of sophisticated threats. As organisations increasingly integrate AI into their operations, cybercriminals are doing the same, fundamentally changing the way cyber-attacks are planned, executed and scaled.

Against this backdrop, the Cyprus Securities and Exchange Commission (“CySEC”) recently issued Circular C786, drawing the attention of regulated entities to the cybersecurity implications of frontier Artificial Intelligence models and reminding firms of their obligations under the Digital Operational Resilience Act (“DORA”). While the Circular does not introduce new legal requirements, it reinforces an important regulatory expectation: ICT risk management frameworks must continuously evolve to address emerging technologies and the changing cyber threat landscape.

This message is particularly significant because AI is reshaping cyber risk at a pace that traditional security frameworks were never designed to address. Financial institutions can no longer rely solely on historical threat patterns or traditional security controls. Instead, they must ensure that operational resilience, governance and ICT risk management remain dynamic, proportionate and capable of responding to increasingly intelligent and automated attacks.

 

Frontier AI Has Changed the Cybersecurity Landscape

Artificial Intelligence has already demonstrated enormous value in strengthening cybersecurity. Financial institutions increasingly rely on AI-powered solutions to detect unusual activity, analyse vast quantities of security data, identify potential fraud, automate threat intelligence and improve incident response. These capabilities allow security teams to identify threats more quickly than traditional manual processes and, in many cases, prevent cyber incidents before they materialise.

However, AI is inherently neutral. The same technologies that improve cyber resilience can equally be exploited by malicious actors.

CySEC’s Circular focuses specifically on frontier AI models—highly advanced AI systems capable of analysing software, generating code, identifying vulnerabilities and adapting their outputs with remarkable speed and sophistication. These models significantly reduce the technical barriers traditionally associated with cyber-attacks, enabling threat actors to automate activities that previously required substantial expertise and time.

This development represents a fundamental shift in the cyber threat landscape. Rather than relying on manual techniques to identify weaknesses, attackers can increasingly leverage AI to scan software for vulnerabilities, generate malicious code, develop highly personalised phishing campaigns and identify new attack methods within a fraction of the time previously required. As a result, organisations face an environment in which vulnerabilities may be discovered and exploited much faster than conventional remediation processes were designed to accommodate.

CySEC also highlights that these risks extend beyond regulated entities themselves. As financial institutions continue to rely on cloud providers, software vendors and other ICT third-party service providers, AI-driven attacks targeting supply chains may create significant operational disruptions across multiple organisations simultaneously.

 

DORA Was Designed to Address Exactly These Types of Risks

One of DORA’s greatest strengths lies in its technology-neutral approach. Rather than regulating individual technologies, the Regulation establishes a comprehensive framework requiring financial entities to identify, assess, manage and continuously monitor ICT risks irrespective of how those risks emerge.

This means that although DORA contains no dedicated chapter on Artificial Intelligence, AI-generated cyber threats naturally fall within its scope. Financial entities remain responsible for ensuring that their ICT risk management framework is capable of protecting information assets, maintaining operational resilience and responding effectively to evolving cyber threats.

The Circular reinforces this principle by encouraging regulated entities to critically assess whether their existing ICT governance arrangements remain adequate in light of frontier AI developments. Importantly, this assessment should not be treated as a one-off compliance exercise. DORA is built around continuous improvement, recognising that operational resilience depends upon organisations regularly reviewing, testing and enhancing their controls as technologies and risks evolve.

This principle reflects one of the core objectives of DORA: resilience is not achieved simply by implementing security controls. It requires organisations to continuously evaluate whether those controls remain effective within an increasingly complex technological environment.

 

Operational Resilience Must Now Evolve Alongside Artificial Intelligence

CySEC’s Circular encourages regulated entities to revisit several key components of their ICT risk management frameworks, many of which already form central pillars of DORA.

One of the most immediate considerations concerns vulnerability management. As AI significantly accelerates the identification of software vulnerabilities, financial institutions must ensure that their own processes for vulnerability monitoring, patch management and remediation operate at a comparable pace. Delays that may previously have represented acceptable operational risks could now create significantly greater exposure, particularly where critical systems or traditional infrastructure are involved.

Similarly, organisations should carefully reassess whether their security architecture continues to provide sufficient protection against increasingly sophisticated attacks. Identity and access management, privileged access controls, authentication mechanisms and network segmentation should all be evaluated through the lens of AI-enabled cyber threats. Security by design is no longer simply a regulatory expectation under DORA—it has become an operational necessity.

CySEC also places considerable emphasis on monitoring and detection capabilities. Traditional monitoring solutions that rely heavily on predefined rules or manual analysis may struggle to identify increasingly complex AI-generated attacks. Firms should therefore consider whether their existing detection capabilities remain proportionate to the evolving threat landscape and whether greater automation, threat intelligence integration or security coordination could improve their ability to identify incidents before they escalate.

Equally important is an organisation’s ability to recover from a cyber incident. DORA deliberately shifts the regulatory focus away from prevention alone and towards operational resilience. No organisation can eliminate cyber risk entirely. Instead, firms must demonstrate that they can continue operating, restore critical services promptly and minimise disruption even when attacks occur.

This makes robust backup arrangements, disaster recovery planning and restoration testing increasingly important. CySEC specifically reminds firms to ensure that backup systems remain appropriately segregated from production environments and are tested regularly under realistic operational conditions. These measures become particularly relevant when responding to AI-driven attacks that may spread rapidly across multiple systems or attempt to compromise recovery environments themselves.

 

Third-Party Risk Management Has Become More Important Than Ever

Another important message arising from both DORA and CySEC’s Circular concerns ICT third-party risk.

Financial institutions increasingly rely on external providers for cloud infrastructure, software development, cybersecurity solutions, managed services and data processing. While outsourcing delivers considerable operational benefits, it also extends an organisation’s attack surface beyond its own internal environment.

AI further amplifies these risks. A vulnerability affecting a single ICT provider may now be identified and exploited far more rapidly, potentially affecting multiple regulated entities simultaneously. Consequently, organisations should ensure that their third-party risk management arrangements remain sufficiently robust to address these evolving threats.

This extends beyond contractual compliance. Firms should maintain ongoing oversight of critical ICT providers, assess their cybersecurity maturity, understand their incident response capabilities and ensure that appropriate contingency arrangements remain in place should disruptions occur. Effective third-party risk management has become an essential component of operational resilience rather than merely a procurement exercise.

 

Strong Governance Will Ultimately Determine Operational Resilience

Perhaps the most important message conveyed by CySEC is that managing AI-related cyber risks is not solely the responsibility of ICT departments.

Operational resilience begins with governance.

Boards of Directors and senior management remain ultimately responsible for ensuring that ICT risks are properly identified, assessed and managed throughout the organisation. As frontier AI continues to reshape cybersecurity, governance arrangements must evolve accordingly. AI-related cyber risks should be incorporated into ICT risk assessments, operational resilience planning and Board-level discussions to ensure that strategic decisions reflect the changing technological environment.

This also requires organisations to foster a culture of continuous learning. Lessons arising from cyber incidents, penetration testing, vulnerability assessments and emerging threat intelligence should feed directly into governance processes, enabling firms to strengthen their resilience over time rather than merely reacting to individual incidents.

 

Conclusion

Artificial Intelligence is transforming both cybersecurity and the cyber threat landscape, creating new opportunities as well as new risks for financial institutions. CySEC’s Circular C786 serves as an important reminder that firms must ensure their ICT risk management frameworks, governance arrangements and operational resilience measures continue to evolve in line with these emerging threats.

While DORA already provides the framework for managing ICT risks, organisations should proactively reassess whether their existing controls remain effective in an increasingly AI-driven environment. Firms that embed AI-related cyber risks into their governance and resilience strategies will be better positioned to safeguard their operations, meet regulatory expectations and strengthen their overall digital resilience.

 

How FiveComply Can Help

Whether you are reviewing your DORA compliance programme, strengthening your ICT risk management framework, or preparing for regulatory expectations surrounding emerging technologies such as Artificial Intelligence, our team is here to support you.

 

Get in touch with our team to discuss your DORA compliance framework, ICT governance, or operational resilience strategy.

📞 +357 25 34 00 25
📧 regulatory@fivecomply.com

Author

Dafne Achniotou

Compliance Consultant – EU & MENA Region

The First 90 Days After Obtaining an Offshore Forex Licence: What Most Firms Underestimate

Receiving Your Licence Is Only the Beginning

For many firms, obtaining a forex licence feels like crossing the finish line.

In reality, it marks the beginning of a far more challenging phase.

Regulators assess applicants based on their proposed business model. Once the licence is issued, the focus shifts to something entirely different: demonstrating that the firm is capable of operating safely, compliantly and sustainably.

The first 90 days after licensing often determine whether a newly authorised firm transitions smoothly into operations or encounters delays with banking, service providers, regulatory filings and the whole activation process.

At FiveComply, we have supported numerous regulated financial institutions through this transition. One consistent observation is that firms often underestimate the amount of work that follows licence approval.

1. Regulatory Approval Must Become Operational Reality

A licence authorises a business to operate but it does not make it operational overnight.

During the first few months, firms typically need to:

  • open bank accounts
  • fund minimum regulatory capital
  • arrange professional indemnity insurance where required
  • finalise agreements with local service providers
  • complete corporate filings
  • implement governance arrangements

These are often conditions that must be satisfied before full business operations commence.

 

2. Your Compliance Framework Must Become “Live”

One of the biggest misconceptions is that AML and compliance become relevant only after clients begin trading.

In reality, regulators expect firms to have fully operational compliance systems before onboarding their first customer.

This includes:

  • AML/CFT procedures
  • Customer Due Diligence (CDD)
  • sanctions screening
  • risk assessment methodology
  • complaints handling procedures
  • conflicts of interest management
  • record retention
  • internal governance

Policies sitting on a shelf are rarely sufficient. Regulators increasingly expect firms to demonstrate that these controls are functioning in practice.

 

3. Building the Operational Ecosystem

A licensed broker depends on far more than a trading platform.

Successful launches require coordination between multiple providers, including:

  • banking partners
  • payment providers
  • liquidity providers
  • trading platform providers
  • CRM systems
  • KYC verification providers
  • screening software
  • hosting and cybersecurity providers
  • outsourced compliance and audit providers

Many projects are delayed simply because these relationships are not established early enough.

 

4. Governance Must Be Evidenced

Corporate governance begins immediately after licensing.

Examples include:

  • holding the first Board meeting
  • approving operational policies
  • adopting client documentation
  • approving outsourcing arrangements
  • documenting key business decisions
  • defining reporting lines

These governance records often become some of the first documents requested during regulatory inspections.

5. Your Brand Must Be Ready for Regulatory Scrutiny

Many firms focus on launching their website quickly.

However, regulators increasingly review:

  • website disclosures
  • legal documentation
  • risk warnings
  • client agreements
  • privacy notices
  • marketing material
  • domain ownership
  • trademark protection

Marketing that is inconsistent with the scope of the licence can create regulatory concerns from the outset.

 

6. Client Onboarding Is More Than Opening Accounts

Before accepting clients, firms should ensure they have clearly documented:

  • onboarding workflows
  • KYC responsibilities
  • source of funds verification
  • sanctions screening
  • client risk classification
  • ongoing monitoring procedures
  • transaction reporting processes

The first client often tests whether internal procedures actually work in practice.

 

7. Reporting Obligations Begin Earlier Than Many Expect

Newly licensed firms frequently assume reporting only starts once they become profitable.

In reality, many jurisdictions require firms to maintain ongoing compliance from the first day of authorisation, including:

  • capital adequacy monitoring
  • regulatory notifications
  • AML registrations
  • CRS/FATCA registrations
  • annual audits
  • compliance certifications
  • board reporting
  • periodic regulatory returns

Missing an early filing can quickly attract unnecessary regulatory attention.

 

8. Operational Resilience Should Not Be an Afterthought

Today’s regulators expect firms to prepare for disruption.

This includes:

  • disaster recovery planning
  • business continuity arrangements
  • cybersecurity measures
  • secure data storage
  • staff training
  • outsourced provider oversight

Operational resilience is increasingly viewed as part of sound governance rather than an optional IT exercise.

 

Common Mistakes During the First 90 Days

Some of the most common issues we encounter include:

  • Delaying bank account activation.
  • Waiting too long to engage liquidity and payment providers.
  • Treating compliance manuals as paperwork rather than operational tools.
  • Launching a website before legal and regulatory reviews are completed.
  • Underestimating governance documentation.
  • Missing initial regulatory registrations and reporting deadlines.
  • Failing to document internal decision-making.
  • Assuming post-licensing support is no longer required.

 

Why Post-Licensing Support Matters

The licensing process demonstrates that a business can meet regulatory entry requirements.

The first 90 days demonstrate whether it can operate as a regulated financial institution.

At FiveComply, we support firms beyond licence approval by assisting with operational activation, governance implementation, compliance framework deployment, regulatory registrations, provider coordination and ongoing compliance support. Our objective is to help firms move from being licensed to being fully operational while meeting regulatory expectations from day one.

 

Disclaimer: This article is provided for general informational purposes only and does not constitute legal, regulatory, tax, or professional advice. Readers should seek independent professional advice before acting on any information contained herein.

Author

Nayia Xiari

Partner / General Manager – Offshore Division

Why Seychelles Continues to Be a Preferred Jurisdiction for Securities Dealers

In an increasingly regulated global financial environment, choosing the right licensing jurisdiction is no longer simply a compliance exercise, it is a strategic business decision that can directly influence a firm’s ability to scale, attract clients, establish banking relationships and compete internationally.

While numerous offshore jurisdictions compete for financial services business, Seychelles has consistently positioned itself as a preferred destination for forex brokers offering a balanced framework of regulatory credibility, operational flexibility, and commercial efficiency within a well-supervised AML/CFT environment.

At the heart of this appeal lies the Seychelles Securities Dealer Licence (SDL), issued by the Seychelles Financial Services Authority (FSA), enabling firms to conduct a broad range of securities and investment-related activities within a recognised regulatory framework, providing a solid foundation for businesses seeking to establish or expand their presence in international financial markets.

For licensed entities, this translates into a regulatory environment that is increasingly recognised by international banks, liquidity providers, payment service providers (PSPs), Electronic Money Institutions (EMIs) and institutional counterparties. As a result, Seychelles offers more than just a licensing solution, it provides a platform from which regulated firms can build, operate and grow globally focused financial services businesses with confidence.

1. Competitive Capital Requirements

A key advantage of Seychelles for Securities Dealers is its balanced approach to capital adequacy.

The current minimum paid-up capital of USD 100,000 reflects regulatory robustness while remaining more accessible than many European regimes, where requirements can exceed several hundred thousand euros depending on the scope of permissions.

This allows firms to allocate more resources toward growth areas such as technology, infrastructure, client acquisition and compliance, while still maintaining a properly capitalised regulated entity.

2. Global Client Reach

Most licensed Securities Dealers utilise Seychelles as an international operating hub and provide services to clients across multiple jurisdictions, subject to the regulatory requirements applicable within those countries.

This international orientation makes Seychelles particularly attractive for firms seeking to establish scalable brokerage operations capable of supporting clients across emerging markets, estalishing one of the strongest jurisdictional advantages.

3. Broad Scope of Permitted Activities

The Securities Dealer Licence supports a broad range of investment activities and financial instruments, allowing firms to operate as diversified business models under a single regulatory authorisation.

Depending on the approved scope of business, a Securities Dealer may engage in activities relating to among others:

  • Contracts for Difference (CFDs);
  • Equities / Shares;
  • Bonds;
  • Futures;
  • Options;
  • Other Derivatives and Securities as per Schedule 1 of the Securities Act;

enabling firms to expand their product offering without the complexity associated with multiple licensing structures.

4. Competitive Trading Environment

Unlike several heavily regulated onshore jurisdictions where retail leverage caps significantly restrict product flexibility, Seychelles offers a more commercially adaptable regulatory framework.

The jurisdiction does not impose statutory limits on trading leverage, allowing brokers to determine leverage levels based on their risk management policies and target markets subject to an appropriateness test, enabling firms to structure trading conditions that remain competitive in international markets, supporting both client acquisition and retention while operating within a regulated environment.

For brokers targeting global retail audiences remains one of the jurisdiction’s key advantages.

5. Banking, EMIs and PSP Accessibility

Equally important is access to banking, payment solutions, liquidity providers and settlement services.

While onboarding remains subject to AML and due diligence checks, Seychelles-licensed entities are generally better positioned than unregulated offshore structures.

This importantly offers to brokers stable payment processing and international financial connectivity.

6. Tax Efficiency Through Economic Substance

Another key advantage of Seychelles is its substance-based tax framework. Securities Dealers that meet the Substantial Activity Requirements (SAR) may qualify for a preferential tax treatment, including a reduced rate of 1.5% on gross revenue.

Unlike traditional offshore models focused purely on tax optimisation, this benefit is conditional on genuine economic presence in the jurisdiction. Firms are required to demonstrate real substance, including a local office, qualified personnel, core income-generating activities conducted in Seychelles, adequate operational expenditure, and ongoing compliance with annual regulatory assessments.

This structure aligns with international transparency standards while maintaining an attractive and predictable tax environment for compliant businesses. In addition, Seychelles generally does not impose withholding taxes on outbound dividends, interest, or capital distributions to non-resident shareholders, supporting efficient international structuring.

7. Substance Requirements as a Competitive Advantage

Whilst economic substance requirements are sometimes viewed as an additional regulatory obligation, sophisticated market participants increasingly recognise them as a significant advantage.

The requirement to establish genuine operations within Seychelles helps distinguish licensed Securities Dealers from purely nominal structures and enhances credibility when dealing with:

  • Banks;
  • Liquidity providers;
  • Payment institutions;
  • Regulatory authorities; and
  • Institutional counterparties.

 8. A Balanced and Competitive Offshore Jurisdiction

While many offshore jurisdictions compete to attract financial services businesses, Seychelles distinguishes itself by offering a balanced combination of regulatory credibility, competitive costs, and operational flexibility for forex brokers and securities dealers.

Market participants are increasingly attracted by:

  • A recognised regulatory framework;
  • Competitive capital requirements;
  • Flexible trading environments;
  • Global client reach;
  • Tax efficiency through substance-based incentives;
  • Access to banking and payment infrastructure;
  • Broad investment permissions under a single licence; and
  • Ongoing regulatory development aligned with international standards.

For many brokerage groups, Seychelles successfully combines the credibility of a regulated jurisdiction with the operational flexibility required to compete in global financial markets.

How FiveComply Supports Clients from A to Z

Obtaining a Seychelles Securities Dealer Licence requires far more than submitting an application.

At FiveComply, we support clients throughout the entire licensing lifecycle, from initial structuring and business model assessment through to licence approval.

Our work covers:

  • Corporate structuring;
  • UBO identification;
  • KYC verification;
  • Source of wealth and funds checks;
  • Governance and substance planning;
  • Capital structuring;
  • AML/CFT framework implementation;
  • Preparation of business plans, financial projections and compliance manuals.

We also remain in direct communication with the FSA throughout the process, ensuring applications are clear, compliant and aligned with regulatory expectations.

Our support continues after authorisation through comprehensive ongoing compliance services, including AML/CFT and compliance support, regulatory reporting, compliance officer services,  internal reviews, policy updates, governance assistance, and regulatory correspondence management, ensuring that clients remain fully compliant while focusing on business growth.

Ultimately, FiveComply provides an end-to-end solution, from structuring and licensing to long-term regulatory support, helping firms establish and maintain regulated brokerage operations with confidence.

 

Disclaimer: This article is provided for general informational purposes only and does not constitute legal, regulatory, tax, or professional advice. Readers should seek independent professional advice before acting on any information contained herein.

Author

Yasmina Amhaz

Licensing Associate – Offshore Division

Seychelles VASP Paid-Up Capital Requirements: FSA Issues New Guidance for Virtual Asset Service Providers

The Financial Services Authority (FSA) of Seychelles has published its long-awaited Guidance Note on Paid-Up Capital Requirements for Virtual Asset Service Providers (VASPs), providing important clarification on how the paid-up capital provisions under the Virtual Asset Service Providers Act, 2024 will be applied in practice.

For businesses considering a Seychelles VASP Licence, the Guidance provides valuable insight into the Authority’s expectations regarding minimum capital, acceptable forms of paid-up capital, ongoing monitoring obligations and regulatory reporting requirements.

More importantly, the Guidance confirms that paid-up capital is not merely a licensing requirement—it is a continuous prudential obligation that must be maintained throughout the life of the licence.

Minimum Paid-Up Capital Requirements for Seychelles VASPs

The FSA has confirmed that the minimum paid-up capital required depends on the type of virtual asset service being provided.

Virtual Asset Service Minimum Paid-Up Capital
Virtual Asset Wallet Provider USD 75,000
Virtual Asset Exchange USD 100,000
Virtual Asset Broking USD 50,000
Virtual Asset Investment Provider USD 25,000

 

Where an applicant intends to provide more than one regulated virtual asset service, the applicable capital requirements must be satisfied in accordance with the Virtual Asset Service Providers (Capital and Other Financial Requirements) Regulations.

Seychelles VASP Capital Requirements Increase as the Business Grows

One of the most significant clarifications introduced by the Guidance concerns the ongoing capital obligation.

From the third year of operation, every Seychelles VASP must maintain paid-up capital equal to 2.5% of its annual turnover generated from licensed virtual asset services.

Importantly, only revenue derived from regulated virtual asset activities is included in this calculation. Income generated from other commercial activities is excluded.

The FSA will assess compliance using the VASP’s audited financial statements and may request additional supporting information where necessary.

This demonstrates that capital adequacy in Seychelles is intended to evolve alongside the scale of the business rather than remaining a fixed licensing threshold.

Acceptable Forms of Paid-Up Capital for a Seychelles VASP Licence

The Guidance provides welcome clarification regarding the forms of paid-up capital that the FSA considers acceptable.

The Authority confirms that cash remains the preferred and default form of regulatory capital.

However, the cash must be maintained with:

  • a bank licensed under the Seychelles Financial Institutions Act; or
  • a financial institution located in a jurisdiction meeting the Authority’s Basel II requirements.

One of the most notable clarifications is that funds maintained through:

  • Electronic Money Institutions (EMIs);
  • Payment Service Providers (PSPs);
  • digital wallets; or
  • similar payment arrangements,

will not be accepted as paid-up capital.

This clarification is particularly relevant for fintech and crypto businesses that commonly rely on alternative payment solutions instead of traditional banking relationships.

Can Alternative Capital Be Used for a Seychelles VASP Application?

Yes, but only with the prior assessment and approval of the FSA.

The Guidance explains that alternative forms of capital, including:

  • bonds;
  • shares;
  • debt securities; and
  • certain investment fund securities,

may be considered on a case-by-case basis.

However, applicants must demonstrate that the proposed capital is:

  • fully paid;
  • unencumbered;
  • readily available;
  • legally enforceable;
  • sufficiently liquid; and
  • capable of absorbing losses during periods of financial stress.

The Authority makes it clear that it will assess the economic substance of the proposed capital rather than relying solely on its accounting treatment or legal classification.

Ongoing Capital Monitoring and Reporting Requirements

The Guidance introduces clear expectations regarding ongoing capital management.

Every Seychelles VASP should maintain appropriate governance arrangements to monitor its capital position continuously.

Where paid-up capital falls below the required level, or no longer complies with the approved form, the FSA must be notified within 12 hours.

A detailed remediation plan must then be submitted within five working days, explaining:

  • the cause of the capital shortfall;
  • the corrective measures to be implemented; and
  • the expected timeframe for restoring compliance.

Failure to comply with these obligations may result in supervisory or enforcement action by the Authority.

What Does This Mean for Businesses Applying for a Seychelles VASP Licence?

The publication of this Guidance provides much-needed regulatory certainty for businesses preparing to establish a Virtual Asset Service Provider in Seychelles.

Applicants should ensure that:

  • their paid-up capital satisfies the applicable regulatory requirements;
  • their banking arrangements meet the FSA’s expectations;
  • future capital requirements are considered as the business grows;
  • any proposed alternative capital instruments are assessed before submission; and
  • appropriate governance and monitoring frameworks are implemented from the outset.

Taking these matters into consideration at an early stage can significantly reduce regulatory queries during the licensing process.

How FiveComply Can Assist with a Seychelles VASP Licence

FiveComply is currently assisting applicants seeking to establish Virtual Asset Service Providers in Seychelles.

Our team supports clients throughout the licensing process by assisting with:

  • assessing paid-up capital requirements;
  • reviewing acceptable capital structures;
  • advising on banking solutions and regulatory expectations;
  • preparing the VASP licence application and supporting documentation;
  • drafting governance, AML/CFT and compliance frameworks; and
  • liaising with the Financial Services Authority throughout the application process.

Our objective is to ensure that every application is prepared in line with the FSA’s regulatory expectations from the outset, helping applicants navigate the licensing process efficiently and confidently.

If you are considering establishing a Virtual Asset Service Provider in Seychelles, our team would be pleased to discuss your proposed business model and assist you throughout the licensing process.

 

Disclaimer: This article is provided for general informational purposes only and does not constitute legal, regulatory, tax, or professional advice. Readers should seek independent professional advice before acting on any information contained herein.

Author

Nayia Xiari

Partner / General Manager – Offshore Division

Bridging the Gap between Regulators and Industry: Insights from Seychelles

Early in my career as a regulator, I often wondered why firms struggled to implement what appeared to be straightforward regulatory requirements. From my perspective at the time, the purpose of the rules seemed clear, and the expectations appeared reasonable. Years later, after moving into industry, I found myself asking a very different question: why did regulators sometimes underestimate the complexity of putting those same requirements into practice?

Having worked on both sides of the regulatory table, I have come to appreciate that many of the tensions between regulators and regulated entities stem not from disagreement, but from differing viewpoints. While both are often working towards the same objective, each encounters distinct challenges, risks, and priorities.

From a regulatory standpoint, the focus is naturally on the risks that rules are designed to address. My supervisory experience highlighted recurring weaknesses across firms and demonstrated how inadequate controls can contribute to financial loss, misconduct, consumer harm, and risks to market integrity. Viewed through that lens, regulatory requirements often appear both necessary and proportionate.

What is not always visible, however, is the complexity involved in translating those requirements into day-to-day operations. A rule that seems straightforward on paper may require significant changes to systems, processes, governance structures, reporting lines, staff training, and internal controls. Firms must often manage multiple regulatory obligations simultaneously while operating within constraints of time, resources, technology, and competing business priorities.

I gained a much greater appreciation for these realities after moving into industry. One of the first things that struck me was how much work is required before implementation can even begin. Requirements must be interpreted, assessed against existing business models, discussed across multiple departments, and translated into practical actions. Compliance is rarely a simple exercise in applying rules. It requires coordination, planning, professional judgement, and often significant organizational change.

A recent example that illustrates this challenge is the implementation of legislative amendments affecting securities dealers. From a regulatory perspective, requirements such as the appointment of a resident director or increases in minimum paid-up share capital are intended to strengthen governance, accountability, and financial resilience. These objectives are both understandable and important. However, firms may face practical constraints in meeting them. In smaller jurisdictions, there may be a limited pool of suitably qualified individuals available to serve as resident directors. Increased capital requirements may also require firms to secure additional funding, reassess growth plans, or adjust their operating model. The policy objective may be clear, but achieving it can involve significant operational and financial considerations.

My experience in industry also reinforced the importance of the regulatory perspective. Within organisations, it can be easy to view certain requirements as administrative burdens, particularly when resources are stretched and deadlines are tight. Yet many regulatory obligations exist because previous failures exposed weaknesses in governance, risk management, or oversight. What may appear excessive from an operational standpoint is often rooted in lessons learned from real-world events.

One of the most valuable lessons I have learned is the importance of constructive engagement. During my years in supervision, I occasionally encountered firms that were reluctant to engage with regulators until issues had already become significant. There can be a perception within industry that regulators should only be approached when absolutely necessary, or that engagement may attract unwanted attention. As a result, firms may hesitate to seek clarification, discuss implementation challenges, or raise concerns at an early stage.

In reality, many regulatory issues become more difficult precisely because communication happens too late. Early engagement allows firms to clarify expectations, identify potential obstacles, and address concerns before they escalate. Equally, regulators benefit from understanding how proposed requirements operate in practice. Open dialogue can highlight implementation challenges, unintended consequences, and areas where additional guidance may be beneficial, often leading to more effective and proportionate outcomes.

From experience on the regulatory side, I have found that regulators generally recognize that firms operate in complex and constantly evolving environments. The focus is often not on perfection, but on whether firms understand their obligations, manage risks appropriately, and respond proactively when issues arise. Supervisory engagement, guidance, and ongoing dialogue can help bridge the gap between regulatory intent and practical implementation, while also providing supervisors with greater insight into the operational realities faced by the firms they oversee.

I have also found that the most productive regulatory relationships are characterized by trust, transparency, and constructive engagement rather than being driven solely by the prospect of enforcement. While enforcement remains an important part of the regulatory framework, it is only one aspect of a broader supervisory approach. Regulators often provide guidance, communicate expectations, and promote good practices alongside their supervisory and enforcement functions. Open communication can foster mutual understanding and help achieve better outcomes for firms, supervisors, and the wider market.

This philosophy also underpins FiveComply’s approach. We work alongside regulated entities to bridge the gap between regulatory expectations and operational implementation, helping firms develop practical compliance solutions, strengthen governance frameworks, and maintain constructive relationships with regulators. By combining regulatory insight with industry experience, we support firms in navigating increasingly complex regulatory environments while maintaining effective and sustainable compliance programmes.

Looking back, I recognize that there were occasions when I underestimated the practical challenges firms faced while working as a regulator, just as there were times in industry when I gained a deeper appreciation of the considerations that shape regulatory expectations. Experience on both sides has reinforced that neither viewpoint is complete on its own. Regulators have visibility of systemic risks and recurring weaknesses across the market, while firms are closer to the operational realities involved in implementing change within complex organizations.

The most successful regulatory outcomes rarely emerge from rules alone. They arise when regulatory objectives are clearly understood, implementation challenges are openly discussed, and both sides recognize their shared responsibility for maintaining trust, protecting stakeholders, and supporting well-functioning markets. Regulators and industry may approach issues from different angles, but they are ultimately working towards the same goal. Effective regulation is strengthened not by choosing one perspective over the other, but by recognizing the value of both.

 

Disclaimer: This article is provided for general informational purposes only and does not constitute legal, regulatory, tax, or professional advice. Readers should seek independent professional advice before acting on any information contained herein.

Author

Sheryl Laporte

Outsourced Compliance Officer

FSC Mauritius Issues New Guidelines on the Frequency of Customer Due Diligence Reviews

The Financial Services Commission (FSC) Mauritius has issued new Guidelines on the Frequency of Customer Due Diligence (CDD), providing greater clarity on the timing and frequency of customer reviews that financial institutions and other regulated entities must undertake as part of their AML/CFT obligations.

Issued under the Financial Services Act and the Financial Intelligence and Anti-Money Laundering Act (FIAMLA), the Guidelines become effective on 8 June 2026 and introduce specific minimum review periods for existing customers based on their risk profile.

Why the Guidelines Matter

Customer Due Diligence is a cornerstone of an effective AML/CFT framework. While firms have long been required to maintain up-to-date customer information and conduct ongoing monitoring, the FSC has now formalised minimum review frequencies to ensure that customer information remains accurate, relevant and risk sensitive.

The Guidelines emphasise that relying solely on trigger events is no longer sufficient. Instead, firms are expected to implement periodic reviews of customer information even where no specific event has occurred.

Minimum CDD Review Frequencies

Under the new Guidelines, firms are expected to conduct reviews of existing customer due diligence information at the following minimum frequencies:

Customer Risk Category Minimum Review Frequency
High Risk At least once every year
Medium Risk At least once every three years
Low Risk At least once every four years

These review periods represent minimum requirements and firms may choose to conduct reviews more frequently where justified by their risk assessment.

Trigger Events Still Apply

The FSC has clarified that periodic reviews do not replace event-driven reviews.

CDD reviews must also be undertaken whenever significant events or circumstances arise, including:

  • Material changes in ownership or management structures;
  • Changes in the risk classification of the customer’s jurisdiction;
  • Identification of a Politically Exposed Person (PEP);
  • Inconsistencies in customer information or verification documents;
  • Expired or invalid identification information;
  • Adverse media or negative information identified through screening processes; and
  • Requests for new products or services that carry a higher level of risk.

The list is not exhaustive, and firms are expected to exercise professional judgment in identifying circumstances that warrant additional due diligence.

One-Year Implementation Period

The FSC expects licensees to establish and implement appropriate procedures and timelines to comply with the new requirements.

Importantly, reviews of existing customers should be completed within one year from the effective date of the Guidelines. This means firms should begin assessing their customer populations, risk classifications, and existing review schedules without delay.

Practical Considerations for Licensees

The new requirements present an opportunity for regulated entities to reassess the effectiveness of their AML/CFT frameworks. Firms should consider:

  • Reviewing customer risk-rating methodologies;
  • Ensuring customers are appropriately categorised as low, medium or high risk;
  • Implementing automated review reminders and monitoring controls;
  • Updating AML/CFT policies and procedures;
  • Maintaining clear audit trails of completed reviews; and
  • Ensuring adequate compliance resources are available to meet review deadlines.

Particular attention should be given to high-risk customers, where annual reviews will now be a minimum regulatory expectation.

Regulatory Consequences of Non-Compliance

The FSC has indicated that compliance with the Guidelines will be supervised and enforced through its regulatory powers.

Failure to comply with directions issued by the FSC may result in regulatory action and may expose firms to sanctions under the Financial Services Act, including financial penalties and other enforcement measures.

How FiveComply Can Assist

The implementation of risk-based CDD review cycles may require enhancements to compliance frameworks, customer risk assessment methodologies, monitoring procedures and governance arrangements.

FiveComply assists regulated entities in Mauritius and other international financial centres with:

  • AML/CFT framework reviews;
  • Customer risk assessment methodologies;
  • Independent AML audits;
  • Compliance monitoring programmes;
  • Regulatory gap analyses; and
  • Ongoing Compliance support.

For further information on how these Guidelines may affect your business, please contact our team.

 

Disclaimer: This article is provided for general informational purposes only and does not constitute legal, regulatory, tax, or professional advice. Readers should seek independent professional advice before acting on any information contained herein.

Author

Nayia Xiari

Partner / General Manager – Offshore Division

End of Transition Period Approaches for Seychelles Securities Dealers

The Securities (Amendment) Act, 2024 and related regulations, which came into force on 1 January 2025, introduced a number of changes affecting the operations and compliance obligations of Seychelles Securities Dealers. Existing licensees were granted an 18-month transition period to implement the new requirements, with compliance required by 30 June 2026.

As the transition period draws to a close, securities dealers should assess whether any additional measures are required to comply with the amended requirements. Some of the key changes are outlined below.

 

Enhanced Local Presence and Oversight

Licensed entities are required to maintain at least two resident fit and proper individuals in Seychelles who serve as directors, compliance officers or members of managerial staff.

 

Improved Client Classification and Investor Protection

The amended Conduct of Business Regulations introduced client classification requirements, requiring securities dealers to categorise clients as either retail or professional clients.

For certain leveraged and higher-risk products, securities dealers must conduct appropriateness assessments to determine whether a retail client possesses sufficient knowledge, experience and financial capacity to understand and absorb the associated risks.

The regulations also limit a retail client’s liability to the funds held in the client’s trading account.

 

Strengthened Complaint Handling Requirements

Licensed entities are required to appoint a resident individual responsible for complaints handling and establish internal procedures for managing complaints effectively. These procedures must be submitted to the Seychelles Financial Services Authority for approval before implementation.

 

The amended regulations also introduced specific requirements relating to the documentation of client complaints and the maintenance of a complaints database.

 

Clearer Risk Warnings for Investors

Securities dealers must include prominent risk warnings in their advertisements. These warnings must inform investors about potential losses, the risks associated with leveraged trading and the complexity of products such as CFDs, futures and options.

These warnings must be clearly displayed, including on websites and mobile applications.

 

Higher Capital Requirements

The reforms increased the minimum issued and paid-up capital requirement for securities dealers from US$50,000 to US$100,000. The capital must also be maintained in an approved bank account.

 

For further information on the amendments, please contact FiveComply.

 

Disclaimer

For information purposes only. This publication does not constitute legal, regulatory, financial or investment advice.

 

Author

Sheila Chua

Outsourced Compliance Officer