
Bhutan's GMC Crypto License: A Practical Guide to the FSP Application Process
Last week, CryptoLicense team covered the broad landscape of Bhutan’s crypto regulatory environment: the dual-track system, the appeal of 0% tax and transplanted legal infrastructure, and several risk factors worth thinking through before committing to this path.
If you have not read it yet, we recommend starting there, as this article builds directly on that framework: Bhutan’s GMC: The Emerging Crypto Jurisdiction Quietly Gaining Ground.
This article focuses on one thing: how to actually obtain the license.
We walk through the FSP qualification requirements, the application process, what ongoing compliance looks like after approval, and the specific points where applications tend to stall.
Ⅰ. What the FSP License Covers
The Financial Services Permission (FSP) is the authorization required to conduct financial services activity within the GMC Special Economic Zone. It operates under the Financial Services and Markets Regulations 2015 (FSMR), the same framework used in ADGM.
Any entity wishing to operate an exchange, custody service, or brokerage within the GMC must hold an FSP. The categories of financial services covered include:
- Crypto asset trading platforms, both spot and derivatives
- Digital asset custody and cold wallet management
- Crypto asset brokerage and OTC services
- Payment services
- Clearing and settlement
- Asset management
In short, the FSP is the entry ticket for any crypto-related financial activity within the GMC.
Ⅱ. What It Takes to Qualify: Capital, Technology, and People
- Capital
The GMC Financial Services Office (GFSO) determines minimum capital requirements based on business type and risk exposure. Exchange and custody businesses are generally subject to higher thresholds. Capital adequacy is calculated on a risk-weighted basis, with specific standards set out in the Regulator’s Rules.
- Technology
Crypto asset businesses face more stringent requirements around system security, availability, and business continuity than traditional financial services applicants. Specific technical standards are similarly defined in the Rules.
People
The GMC adopts ADGM’s regulatory framework for key personnel, and the standards are applied carefully:Chief Compliance Officer (CCO) and Money Laundering Reporting Officer (MLRO)
These roles must be held by separate individuals and cannot be combined. Each undergoes independent review by the GMCA.CEO
Must hold demonstrable experience in financial services or the crypto industry.Local director
The company must have at least one director ordinarily resident in the GMC. Bhutanese citizenship is not required; holding GMC residency status or a valid work visa is sufficient (Companies Act 2025, Section 145).- Fit and Proper assessment
All senior managers and substantial shareholders must pass this review, covering background checks, criminal record verification, and industry experience evaluation.
Ⅲ. From Preparation to Approval: Walking Through the FSP Process
The process has two stages: preparation, and formal submission & review.
Stage 1: Preparation
There are four core workstreams to complete before submitting an application.
First, determine the applicant entity. Options include incorporating a new company in the GMC, establishing a subsidiary, or applying directly as a foreign Body Corporate under Financial Services Act 2025, Section 27.
Second, build the compliance infrastructure. This covers AML/KYC procedures, an anti-money laundering policy, a risk management framework, and an internal audit mechanism.
Third, deploy the technical infrastructure, including trading, custody, and clearing systems, as well as security controls and disaster recovery capabilities.
Fourth, prepare the application package: corporate documents, compliance documentation, technical materials, and financial and management records.
We strongly recommend engaging legal and compliance advisors with direct GMC application experience during this stage. Familiarity with the process has a material impact on overall efficiency.
Stage 2: Submission and Review
Once submitted, the GMCA first conducts a completeness check, then moves to substantive review. The review covers the compliance framework, technical infrastructure, management team qualifications, and capital adequacy. On-site inspection may be arranged during this phase.
Upon approval, the GMCA issues the FSP, specifying the regulatory obligations and ongoing compliance requirements attached to the license.
A Real Precedent: Matrixport's Timeline
Matrixport is currently the only entity to have completed the full FSP process. Based on public information, it received In-Principle Approval (IPA) in December 2025 and converted to a full FSP in February 2026. The window between IPA and formal issuance was approximately two months, used to satisfy pre-licensing conditions.
That said, every application is different. Actual timelines vary significantly based on business complexity and the quality of preparation. Matrixport’s timeline should be treated as a reference point, not a benchmark.
IV. Ongoing Compliance After Approval
Obtaining the FSP is the starting point, not the finish line. The ongoing compliance obligations are substantive:
- Financial and operational reporting must be submitted to the regulator on a periodic basis
- AML/KYC policies require regular review and updating
- Changes to key personnel or ownership structure must be notified or approved in advance
- Any changes to the scope of business require a license variation application
- Material security incidents must be reported immediately
The GFSO’s Regulator’s Rules are still being finalized. In the interim, the ADGM framework provides a reliable baseline for what to expect in terms of frequency and format.
V. Where Applications Stall: Five Things to Get Right
In our experience, FSP applications lose time not on the big structural questions, but on execution details. The five issues that come up most often:
- AML/KYC that does not fit the business
Generic compliance documents do not survive targeted regulatory questioning. Procedures need to be specific and executable. Template submissions lead to repeated RFIs, and each round adds to the timeline.
- Technology that does not meet the bar
System security, availability, and business continuity all have hard standards. Underdeveloped architecture or unconvincing audit reports rarely clear the review stage without remediation.
Key personnel who do not qualify
The experience requirements for CEO, CCO, and MLRO are non-negotiable. The Fit and Proper assessment is designed to surface exactly this.- Capital that looks sufficient but lacks credibility
The GFSO looks beyond the balance sheet figure. Unclear sources of funds or a capital structure that cannot support an operational buffer will draw scrutiny. - Insufficient substance in the GMC
The 0% tax rate requires genuine operational presence: physical office, local staff, real operating expenditure. This needs to be planned from the application stage, not added later.
VI. Closing Thoughts
That covers the FSP application from qualification requirements through to post-approval obligations. The bar is real, but the path is clear — and Matrixport has demonstrated that it is achievable.
If you are seriously evaluating Bhutan’s GMC, our recommendation is to work through the risk factors from first, then assess your readiness against the requirements and common sticking points covered here.
If you have questions or want to think through your specific situation, we are glad to help. Contact CryptoLicense — we will work through the details with you.