Business Model Mapping  ·  Activity Classification  ·  Licence Scope

Regulatory Perimeter Assessment for FinTech & Financial Services

Regulatory perimeter assessment for FinTech, payments, crypto and investment business models — identifying regulated activities, applicable regimes, permissions, exemptions, licensing dependencies and whether restructuring or a licensed partner is required.

Designed for FinTech, payments, crypto, tokenisation and investment business models before launch, restructuring, market entry or licensing.

Model
Who does what
and for whom
Flows
Fiat · crypto · tokens
contracts · data
Regime
MiCA · payments ·
MiFID II · related rules
Route
Licence · partner ·
restructure · proceed
Financial analysis and regulatory mapping
Pexels · free-use editorial visual
The starting point

Start With the Regulatory Perimeter — Not a Licence Name.

A product may combine crypto-asset services, fiat payments, e-money, token issuance, investment features, custody, data processing and outsourced technology. A partner's licence does not automatically cover activities performed by the platform itself.

The assessment therefore reconstructs the operating model first, then classifies the activities, regulatory triggers and dependencies before recommending a licensing, partner or restructuring route.

How the assessment works

From Product Architecture to a Defensible Regulatory Route.

01
Map the Operating Model
Entities, customers, counterparties, jurisdictions, contractual roles, money and asset flows, custody and technology dependencies.
02
Classify Activities
Identify which functions are performed by the business, partners and infrastructure providers — based on substance rather than labels.
03
Map Regulatory Regimes
Assess potential triggers under MiCA, payments/e-money rules, MiFID II and related AML/TFR, DORA and data-protection requirements.
04
Define the Route
Set out likely authorisation needs, partner dependencies, restructuring options, assumptions, unresolved legal questions and next steps.
Regulatory scope

Multi-Regime Analysis Where the Business Model Requires It.

The review is scoped to the actual model. Not every framework below will apply to every engagement.

Digital assets
MiCA & Crypto-Asset Services
CASP service classification, custody, exchange, execution, transfer, reception/transmission of orders, advice, portfolio management, token issuance and relevant exemptions or exclusions.
  • CASP function mapping
  • Token / ART / EMT classification
  • Service-provider vs issuer analysis
  • MiCA / MiFID boundary where relevant
Payments
Payment Services & E-Money
Assessment of payment-service, e-money and safeguarding triggers where the model handles fiat, payment accounts, merchant flows, cards, transfers or e-money / EMT functionality.
  • PI / EMI perimeter
  • Payment-account and execution analysis
  • Agent / partner models
  • Crypto-payment intersections
Investment services
MiFID II & Financial Instruments
Assessment where the model may involve financial instruments, investment services, tokenised securities, order handling, execution, advice or portfolio-management functionality.
  • Financial-instrument classification
  • Investment-service mapping
  • Execution / RTO / advice perimeter
  • Tokenised securities & DLT interfaces
Cross-regulatory
AML/TFR · DORA · GDPR & Related Rules
Secondary regulatory consequences are identified where they materially affect the operating model, launch route or partner structure.
  • AML/CFT and Travel Rule triggers
  • DORA / ICT third-party interfaces
  • Data-processing role mapping
  • Further local-law questions requiring specialist input
What is analysed

The Perimeter Is Determined by the Real Operating Model.

The assessment follows the business as it actually operates — across entities, customer journeys, money and asset flows, contracts, technology and market access.

01
Entities & Jurisdictions
Who contracts with the client, performs each function, receives revenue, controls the product and is exposed to EU or other jurisdictional rules.
02
Customer & Product Journey
How the customer moves through onboarding, funding, orders, transfers, settlement, redemption, withdrawals and other product interactions.
03
Money & Asset Flows
Where fiat, e-money, crypto-assets, tokens and client assets move — and where custody, control, settlement or safeguarding points arise.
04
Contracts & Responsibility
What sits with the platform, licensed partners, banks or EMIs, CASPs, brokers, custodians and technology providers — including responsibilities that cannot simply be outsourced away.
05
Technology & Control Points
Who controls wallets, keys, order routing, payment initiation, execution logic, customer instructions and other operational decisions relevant to regulatory classification.
06
Market Access
Where clients are targeted, how the product is marketed and distributed, and which cross-border activities affect regulatory exposure or reliance on exemptions.
Typical outcomes

The Result Is a Decision Framework — Not Just a List of Regulations.

Authorisation likely required
The business itself performs one or more regulated activities and should move to a licensing/readiness workstream.
Partner model possible
Certain functions may sit with an appropriately licensed provider, subject to contracts, customer journey and responsibility allocation.
Restructure before launch
The current architecture creates avoidable regulatory exposure and should be changed before product build or market entry.
Further legal analysis
A jurisdiction-specific legal opinion, local licensing analysis or specialist technical/tax input is required before a definitive conclusion.
Scope & fees

Choose the Depth of Regulatory Scoping You Need.

Preliminary
Regulatory Scoping
from €950
For a focused question or early-stage model where the immediate objective is to identify the most likely regulatory route and key unknowns.
  • Focused fact review
  • Primary regime / licence indicators
  • Key assumptions and red flags
  • Short written outcome
Complex
Multi-Regime Assessment
from €7,500
For multi-entity, cross-border or hybrid models combining crypto, payments, e-money, tokenisation or investment-service features.
  • Multi-regime analysis
  • Multiple entities / counterparties
  • Cross-border dependencies
  • Detailed structuring options

Final fee depends on the number of entities, jurisdictions, products, regulatory regimes and the completeness of the operating-model documentation. Formal local-law, tax or reserved professional opinions are scoped separately where required.

Deliverables

A Written Outcome You Can Use for the Next Decision.

Business Model Map
Entities, partners, customer relationships, contractual roles and material asset, money and data flows.
Activity / Licence Matrix
Functions mapped to the entity performing them, relevant regulatory regime and potential authorisation or partner dependency.
Assumptions & Risk Register
Facts that drive the conclusion, unresolved points, red flags and questions requiring confirmation before reliance.
Regulatory Roadmap
Prioritised next steps: licensing assessment, restructuring, partner contracting, gap assessment or specialist legal analysis.
Clear boundaries

Perimeter Assessment vs Licensing Assessment vs Gap Assessment.

Regulatory Perimeter Assessment: Which rules, regulated activities and authorisations may apply to this model?

Licensing Assessment: We have selected a specific licence and jurisdiction — is this route feasible and what would the applicant need?

Regulatory Gap Assessment: We already know which rules apply — where does the current organisation, framework or operating model fall short?

Why LEX ARTA

Perimeter Analysis Before Licensing Assumptions.

The central question is what the business actually does, for whom, where and through which contractual, payment and asset flows. That factual model drives the regulatory conclusion.

Business-model first
Classification starts with functions, customer journeys, money and asset flows, counterparties and geography — not with the licence the business hopes to obtain.
Cross-regime analysis
Where one model touches several regimes, the assessment maps the intersections and identifies dependencies rather than forcing a single-regulation answer.
Senior regulatory judgement
Material classification questions and final conclusions remain under experienced legal and compliance oversight.
Usable written outcome
The result is structured to support product decisions, licensing strategy, partner discussions, internal governance and the next regulatory workstream.
Selected credentials and practitioner background. ACAMS Certified · CySEC AML Certified · ACFE Member · PhD in Law · practitioner experience across AML/CFT, compliance, investigations and regulatory work. Artlex Consult s.r.o. is a regulatory and compliance advisory company; reserved local-law or other licensed professional work is handled by appropriately qualified practitioners where required.
Common questions

Regulatory Perimeter Assessment — FAQ.

We are not sure which licence our business needs. Is this the right service?
+
Yes. A Regulatory Perimeter Assessment is designed for situations where the correct regulatory route is not yet clear. The assessment maps the activities, entities, flows and control points first, then identifies which licences, registrations, exemptions or partner arrangements may need to be considered.
Can you review our business model before we launch?
+
Yes. Reviewing the model before launch can identify avoidable regulatory exposure early — before product design, contracts, technology or market-entry decisions become difficult or costly to change.
Can we operate through a licensed partner instead of obtaining our own licence?
+
Sometimes, but not automatically. The assessment examines which functions are genuinely performed by the licensed partner and which remain with your business. The customer journey, contracts, control points and operational responsibilities determine whether a partner model is workable.
Can one business model fall under several regulatory regimes?
+
Yes. Hybrid FinTech models can combine crypto-asset services, payments, e-money, investment services, tokenisation and related AML/TFR, DORA or data-protection obligations. The assessment can be scoped across several regimes where the facts require it.
What information do you need to perform the assessment?
+
Typically: a description of the product and customer journey, entity and jurisdiction structure, money and asset flows, partner roles, key contracts or term sheets, technology dependencies, target markets and any existing licensing or regulatory assumptions.
What do we receive at the end of the assessment?
+
The core output is a written regulatory assessment setting out the business-model map, activity and licence matrix, key assumptions and risks, and a practical next-step roadmap — for example licensing, restructuring, partner contracting, a gap assessment or further jurisdiction-specific legal analysis.
Not sure which regulatory regime or licence your model actually requires?
Start with the operating model. We map the activities, flows, control points and partner responsibilities before defining the regulatory route.