Most high risk merchants don’t lose payment accounts because they did something wrong. They lose them because their provider couldn’t show a bank, a regulator or an auditor exactly who supervises the flow of funds, and on what legal basis.
Switzerland is one of the few places where that question has a clear answer. Crypto and payment providers that handle other people’s assets sit inside a defined anti-money-laundering (AML) framework, supervised either by FINMA directly or by a FINMA-recognised self-regulatory organisation (SRO). The pressure is real: Switzerland’s reporting office received 21,087 suspicious activity reports in 2025, up from 15,141 the year before, according to PwC Switzerlands analysis.
This guide explains how a bitcoin and crypto merchant account fits into that framework, what “high-risk” means in practice, and what to check before you sign with a provider.

Key Takeaways
- An SRO is an AML supervisor, not a bank licence and not a direct FINMA licence. It works when your provider’s activity stays inside what the SRO framework covers.
- Swiss rules are strict for crypto: identification applies from CHF 1,000, and providers must verify that customers control the external wallets they send to or receive from.
- “High-risk” is a risk classification, not a ban. Transparent, lawful businesses with proper documentation can be onboarded; opaque ones can’t.
- Proposed new FINMA licences for payment and crypto institutions are not law yet, but they signal where custody, trading and payment activity is heading.
What is a crypto merchant account, and why choose Switzerland?
A crypto or bitcoin merchant account lets a business accept digital-asset payments from customers and, in most setups, settle in fiat or stablecoins. The provider sits between the customer’s wallet and the merchant. That position is exactly what makes it a regulated activity: it receives, converts, holds or forwards value that belongs to someone else.
Switzerland appeals to merchants and providers for three reasons: a mature banking ecosystem, a principles-based, technology-neutral regulatory approach, and legal clarity about who supervises what. For a merchant in a sector that banks treat cautiously, a provider with a verifiable Swiss supervisory status is easier for banks, partners and auditors to assess.
Who supervises a crypto payment provider: FINMA or an SRO?
Two layers exist, and confusing them is the most common mistake.
FINMA directly supervises institutions that hold a prudential licence, such as banks, securities firms and FinTech-licence holders. SROs supervise the AML compliance of financial intermediaries that need no such licence. Under the Anti-Money Laundering Act (AMLA), professional intermediaries must join an SRO recognised by FINMA, and are supervised by that SRO rather than by FINMA itself. FINMA in turn supervises the SROs.
There are currently eleven recognised SROs. Only a handful admit the broad range of para-banking intermediaries that crypto and payment models typically fall into, so choosing the right one matters.
What SRO membership is not:
- It is not a banking licence.
- It does not mean the company is licensed directly by FINMA.
- It does not guarantee a bank account or payment connection.
What it is: recognised, audited AML supervision. You can check any providers status yourself in FINMA SRO member search. A provider that won’t name its SRO should be treated with caution.
What does “high-risk” mean under Swiss AML rules?
Swiss law doesn’t publish a list of banned or “high-risk” merchant industries. It requires intermediaries to take a risk-based approach: classify each business relationship, apply enhanced clarification to higher-risk ones, and document the reasoning. Under the AMLA, unusual or suspicious situations trigger a special duty of clarification, and confirmed suspicion must be reported.
In practice, payment providers and banks commonly treat these as elevated-risk categories:
- Online gaming and gambling (in Switzerland, only lawful with the required licence)
- Forex, CFD and other trading platforms
- Adult content and subscription services
- CBD, nutraceuticals and other regulated consumer products
- Digital-goods marketplaces and high-ticket travel
- Crypto businesses themselves
Elevated risk also comes from factors unrelated to industry: complex ownership structures, high-risk customer geographies, politically exposed persons, unusual transaction patterns or unclear source of funds.
The practical point: high-risk doesn’t mean “declined”. It means more documentation, closer monitoring and stricter conditions. The merchants that succeed are the ones that arrive prepared.
Which AML duties must a compliant crypto merchant account provider run?
A provider handling crypto for merchants is a financial intermediary and must run a complete AML programme. The core duties:
- Know your customer and beneficial owner. Identify the merchant, verify its ownership and understand the business.
- Transaction monitoring. Detect unusual patterns against the risk profile agreed at onboarding.
- Sanctions screening of parties and, where relevant, wallet addresses.
- Record-keeping that lets an auditor reconstruct any transaction.
- Suspicious activity reporting. Under Article 9 AMLA, reports go to MROS, Switzerland’s financial intelligence unit.
- Periodic audits by the SRO or its appointed audit firm.
The Travel Rule is stricter in Switzerland
Since 1 January 2021, FINMA has required contracting parties to be identified when a cryptocurrency exchange exceeds CHF 1,000, down from CHF 5,000. Under FINMA Guidance 02/2019, providers must also confirm that a customer controls the external wallet involved. FINMA lists several accepted verification methods, including time-boxed procedures and wallet log-ins in the presence of staff, provided the process is documented.
For merchants, this affects checkout design. Payments from customers’ unhosted wallets need a compliant verification step, and a provider that skips it is carrying regulatory risk that eventually lands on your account.
When does the duty start?
An activity counts as professional under the AML ordinance once it passes defined thresholds, including gross revenue above CHF 50,000 a year, more than 20 contractual counterparties, control of third-party funds above CHF 5 million, or transaction volume above CHF 2 million a year (summary by 21 Analytics). Most merchant-facing providers cross these quickly.
What should a high risk merchant prepare before applying?
Preparation is the biggest lever you control. Typical onboarding requests:
| Document | Why it’s requested |
| Company registry extract and ownership chart | Establishes who the merchant is and who ultimately controls it |
| ID and proof of address for beneficial owners | Required beneficial-owner identification |
| Business description, URLs and product list | Lets the provider classify the risk and detect mismatches later |
| Licences for regulated activity (for example, gaming) | Shows the underlying business is lawful in its target markets |
| Expected volumes, average ticket size and refund policy | Baseline for transaction monitoring |
| Customer geographies | Sanctions and high-risk-country exposure |
| Source of funds and wealth information | Enhanced due diligence for higher-risk relationships |
| Settlement details and wallet addresses | Needed for Travel Rule and reconciliation |
| Terms of service, privacy and AML or KYC policies | Evidence of the merchant’s own controls |
Inconsistent answers between the application, the website and actual transactions are the fastest route to a refusal or a later suspension. Accurate, complete disclosure is what keeps the account stable.
Where does the SRO route stop? Custody, pooling and settlement
The SRO covers AML supervision. It doesn’t authorise every financial service. A direct FINMA licence or another approval may be needed if a structure accepts deposits from the public, pools client assets in a way that creates a repayment obligation, or operates regulated trading infrastructure.
Custody is the clearest example. FINMA’s current position is that no banking licence is needed when digital assets are held for safekeeping only and stored separately for each customer, so that every deposit is attributable to one client. Pooled custody, where the provider owes repayment, is treated differently. FINMA also published Guidance 01/2026 on crypto custody in January 2026, reflecting how closely custody arrangements are now examined.
Ask any provider to describe, in writing, who holds the funds at each step, who controls the keys, and whether client assets are segregated. Those answers determine whether the SRO route is enough.
What is Switzerland planning to change?
On 22 October 2025, the Federal Council opened a consultation on two new FINMA-supervised licence categories:
- Payment Instrument Institution: would replace the FinTech licence, remove the CHF 100 million deposit cap, and become the route for regulated Swiss stablecoin issuance.
- Crypto-Institution: would cover custody of crypto-based trading assets, client trading, market-making and custodial staking.
The consultation closed on 6 February 2026, and the provisions are not expected to enter into force before 2027. As of September 2026, this remains a proposal. Under the draft, businesses whose activity becomes licensable would have one year after entry into force to apply and could continue operating under SRO membership until FINMA decides.
What it means for merchants: the SRO route isn’t disappearing, but some crypto-custody, trading and payment activities may migrate to direct FINMA licensing. Choose a provider that has already mapped its model against the proposed categories and can explain its plan.
How to choose a crypto merchant account provider: a due diligence checklist
- Verifiable supervision. The provider names its SRO or licence, and you can confirm it on FINMA public search.
- Real Swiss substance. An operating entity with an office and qualified people, not only a registered address.
- A written fund-flow description covering custody, key control, segregation and settlement.
- Travel Rule tooling that handles unhosted-wallet verification without breaking checkout.
- A documented AML policy, including risk appetite, monitoring rules and an MROS reporting procedure.
- Banking and settlement relationships it can describe honestly, without guarantees.
- A clear list of what it won’t onboard. Providers that accept everything usually can’t sustain their own banking.
- A reform plan for the proposed payment and crypto licences.
How Webpays supports Swiss-compliant crypto payments
Webpays provides bitcoin and crypto merchant account solutions for businesses in higher-risk sectors, designed around Swiss supervisory requirements rather than around them.
- Supervised structure
- Risk-based onboarding
- AML programme in the produce
- Clear settlement mode
Regulatory readiness
Webpays doesn’t promise approval to every applicant. A merchant account is granted when the business is lawful, transparent and documented, and it stays stable when those conditions continue to hold.
Apply for a crypto merchant account → Webpays contact or onboarding page
Frequently asked questions
Is a crypto merchant account in Switzerland regulated by FINMA?
It depends on the provider’s structure. Providers with a prudential licence are supervised by FINMA directly. Providers operating as AML-only financial intermediaries are supervised by a FINMA-recognised SRO, and FINMA supervises the SRO.
Can a high-risk business get a Swiss crypto merchant account?
Often yes, if the activity is lawful, the ownership is transparent and the documentation is complete. High-risk classification means enhanced due diligence and monitoring, not automatic refusal. Sectors that require their own licence, such as online gaming, must be able to show it.
Does SRO membership guarantee a bank account?
No. SRO membership demonstrates recognised AML supervision. Banks and payment partners still make their own commercial and risk decisions.
Will the 2027 reform end the SRO route?
Not entirely. The proposal keeps the SRO system, but some activities, including crypto custody, client trading, market-making and qualifying payment services, may move to direct FINMA licensing. Details depend on the final law.
How fast can a merchant be onboarded?
It varies with the complexity of the business and how complete the documents are take 2-5 days, Ownership charts, licences and source-of-funds evidence are the most common causes of delay.
Conclusion: choose the structure before the provider
The right crypto merchant account isn’t the one with the fastest sign-up. It’s the one whose supervision, custody model and AML controls will still stand up when a bank, an auditor or a regulator asks about them. For high-risk merchants, that’s the difference between an account that survives its first review and one that doesn’t.
If you’re evaluating a Swiss-compliant setup for bitcoin and crypto payments,
talk to Webpays about your business model
Disclaimer: This article provides general information only and does not constitute legal, tax or regulatory advice. The Swiss FinIA proposal may change during the legislative process, and requirements depend on the specific facts of each business.
