Ongoing Compliance After a Forex Licence: Broker Checklist

Quick answer: Receiving a forex licence does not complete the compliance project. A licensed broker normally has to keep its activities within the authorised scope, maintain the required capital and liquidity, protect client money, submit regulatory returns, complete audits, operate AML/KYC controls, handle complaints, approve marketing, maintain competent personnel and control changes to shareholders or directors. The reliable approach is not a generic “global annual checklist”. It is a board-owned compliance calendar built from the firm’s licence conditions, applicable law, regulatory portal and actual operating model.

Information last verified on 27 August 2026. This is a cross-jurisdiction planning framework, not legal advice for a particular country. The obligations that apply to a firm depend on its permissions, licence conditions, role in a transaction, client types and the rules in force for that legal entity.

Why is licence approval the beginning of ongoing compliance?

A regulator authorises a particular legal entity to conduct specified activities. It does not give the wider group an unrestricted operating passport. The permitted products, client categories, territories, dealing capacity and ability to hold or control client assets shape the firm’s ongoing capital, reporting and conduct obligations.

Before launch, senior management should be able to answer four questions without ambiguity: which entity contracts with the client, which entity holds or controls client money, which entity executes and hedges trades, and who approves marketing and complaints. If the website, client agreement, payment route or intragroup responsibilities differ from the application that the regulator assessed, the firm may be operating outside its permission or reporting an inaccurate business model even while the licence still appears active.

Cross-border activity remains a separate control. A firm must continue to assess the law of each client country rather than infer worldwide access from the licence jurisdiction. Our market-access guide for Asian, Middle Eastern and African clients explains how client location, solicitation and contracting arrangements interact.

Start with a licence-condition and responsibility matrix

The firm’s first post-approval control should begin with the licence, approval letter, applicable rulebook and regulator portal—not a checklist downloaded from another broker. The following matrix provides a practical starting point for organising forex licence compliance requirements.

Obligation area What must be controlled Evidence to retain Suggested owner
Permission scope Products, client categories, territories, dealing role and client-asset permissions Permission matrix, product approvals and prohibited-country list Board and compliance officer
Capital and liquidity Minimum resources, risk exposure, expense coverage and internal warning buffer Capital calculation, bank balances, management accounts and stress tests CFO and risk officer
Client money Collection accounts, segregation, books and records, reconciliation and breaks Bank statements, client ledger, reconciliations and escalation records Finance, operations and compliance
Regulatory reporting Prudential, transaction, client-asset, complaints, AML and statistical returns Submission receipts, review workpapers, version history and deadline register Compliance, finance and MLRO
Governance and people Fitness, competence and time commitment of directors, executives and control functions Training, CPD, minutes, conflicts register and annual declarations Board, HR and compliance
Change control Ownership, controllers, directors, auditor, address, services and outsourcing changes Pre-approval/notification matrix, regulator correspondence and resolutions Company secretary and compliance

“Annual” should not be the default frequency for every row. Some controls operate daily or monthly, some returns may be quarterly, half-yearly or annual, and some duties arise immediately after an event. Each obligation should identify its legal or licence basis, reporting period, due date, data source, preparer, independent reviewer and back-up owner.

How should client-money segregation and reconciliation work?

Where a licence permits a broker to hold or control client money, the applicable regime will usually require client assets to be distinguished from the firm’s own money, records that identify each client’s entitlement, and timely investigation of differences between bank or payment-provider balances and the internal client ledger. It is not safe to state that every jurisdiction requires a daily reconciliation. Frequency, account designation, eligible deposit institutions, trust arrangements and shortfall rules depend on the local client-asset regime and the firm’s permission.

What should a client-money control process cover?

  • Confirm that an account satisfies the applicable client-money rules before receiving customer funds, rather than explaining the account after deposits arrive.
  • Map deposits, withdrawals, fees, realised profit and loss, refunds and chargebacks to the same client ledger.
  • Separate preparation and review of reconciliations, and define who investigates, funds and escalates a break.
  • Preserve the full money trail across banks, EMIs, PSPs and liquidity providers.
  • If payment or technology processes are outsourced, retain data access, audit rights and a workable contingency arrangement.

A bank or PSP will conduct its own due diligence on the account structure. A valid licence does not guarantee that a provider will accept the proposed client-money flow. The factors normally examined are covered in our forex licence, banking and PSP onboarding guide.

Regulatory capital and liquidity are not one-time application balances

Minimum capital is normally a continuing condition. The calculation may depend on whether the broker deals as principal or agent, holds client assets, carries market or credit risk, and incurs a particular level of fixed overheads. Funding an account for the application and withdrawing the money after approval—or topping up only for a reporting date—does not amount to continuous capital management.

Management should set an internal warning level above the regulatory minimum rather than waiting for a breach. A useful capital dashboard connects the general ledger, client-asset records, unsettled balances, receivables, risk exposure and forward operating expenses. It should also state:

  • which dividends, related-party payments or expansion plans stop when the warning level is approached;
  • who verifies the source and regulatory treatment of additional capital;
  • when the issue is escalated to the board, auditor and regulator;
  • whether a group support letter or related-party receivable qualifies for the calculation.

Regulatory capital is distinct from application fees, professional costs and normal working cash. Brokers comparing the wider budget can use our offshore forex licence cost framework, while recalculating every obligation for the actual jurisdiction and permission.

Put regulatory returns, audit and annual charges in one calendar

An operational regulatory calendar can include prudential returns, financial statements, audit, transaction reports, client-asset reports, complaints statistics, AML reports, compliance attestations, annual licence charges and regulator questionnaires. They may use different reporting periods and due dates. Completion of the financial audit does not mean that every other filing has been made.

Regulatory route Illustrative ongoing focus Common planning error
UK FCA Returns through RegData according to the firm’s permissions and reporting schedule; CASS client-asset rules, prudential requirements and complaints duties where applicable Copying another firm’s reporting frequency or capital form
EU investment firm / CySEC Client assets, prudential requirements and transaction reporting under the applicable MiFID II, MiFIR and IFR/IFD classification, CySEC requirements and licence conditions Reading the EU framework without checking local notices and the firm’s class
Australia ASIC / AFS Continuing AFS licensee obligations, organisational competence and financial resources; client-money and reportable-situations regimes where applicable Treating a corporate annual return as the complete AFS compliance programme
South Africa FSCA / ODP Continuing Fit and Proper standards and FSP-category reporting; ODP duties where the firm acts as an OTC derivative counterparty Assuming ordinary FSP permissions automatically cover retail CFD issuance or market making
Mauritius FSC Investment Dealer Capital, governance, AML and client-money controls for the relevant licence category; audited accounts and statutory returns under the Securities Act and licence conditions Treating every Investment Dealer category as one capital and reporting regime
Seychelles FSA Securities Dealer Ongoing capital, audit, client-money, AML, consumer-protection, annual fee and compliance-document obligations that apply to the licensee Interpreting a continuing licence as freedom from annual charges or filings
Vanuatu VFSC Financial Dealer Deposit or security, audit, insurance, client-money and AML controls for the relevant class, plus anniversary-linked charges and statements Calling every annual charge a fresh licence application or relying on superseded class and capital information

For example, section 55 of the Mauritius Securities Act links an Investment Dealer’s annual report and audited financial statements to its balance-sheet date. Vanuatu’s 2026 consolidated Financial Dealers Licensing Act contains anniversary-linked provisions for audited statements and annual charges. These examples illustrate why a broker must calculate deadlines from its own legislation, licence conditions and corporate dates rather than copy a date from a generic compliance calendar.

AML/KYC must move from onboarding checks to ongoing monitoring

Passing a customer at onboarding does not complete the AML process. A licensed broker should apply a risk-based approach to customer and beneficial-owner identification, sanctions and politically exposed person screening, source of funds and source of wealth, and periodic or event-driven information updates. The monitoring intensity should reflect the customer, product, geography, payment path and trading behaviour.

Which evidence should ongoing AML controls produce?

  • A board-approved business-wide risk assessment, AML policy and risk-acceptance standard.
  • Records of customer, UBO, PEP, sanctions and higher-risk-country screening and review.
  • Investigation notes for complex, unusual or profile-inconsistent activity.
  • Internal escalation, MLRO decisions and confidentiality controls for suspicious activity reports.
  • Staff training, quality assurance, rule or model adjustments and remediation tracking.
  • Continuing due diligence on affiliates, introducing brokers and material outsourced providers.

“No suspicious activity was identified” is not a substitute for monitoring evidence. A regulator may ask how alerts were generated, who decided whether to close them, why the conclusion was reasonable, and whether recurring issues required a change to customer-risk ratings or system thresholds.

Can shareholder, director or key-person changes be completed before notification?

A broker should never assume that they can. A change in control, qualifying shareholding, director, senior manager, compliance officer, MLRO, auditor, registered address, capital source, brand or permission may require prior approval, notification within a specified period, or parallel steps under both company law and the licensing regime.

The firm should therefore maintain an event-driven change-control matrix. For every event, it should state the trigger or ownership threshold, whether approval is required before completion, which documents must be filed, who signs the board resolution and which systems, banks and counterparties need updating. Commercial teams should obtain compliance clearance before signing a share transfer, appointing a director or changing the payment entity.

These events also need to remain consistent with the group structure and money flow. Our forex broker licence and company-structure guide provides a practical entity-by-entity framework.

Marketing, risk disclosure and complaints are regulatory data

Websites, social media, affiliates, sales scripts and risk warnings should stay consistent with the firm’s permission, target clients and product facts. Describing a firm as “regulated” must not imply that a regulator guarantees client money, execution quality or investment returns. An affiliate cannot make an unsupported promise on the broker’s behalf merely because the affiliate is contractually independent.

Complaints are not only a customer-service matter. The firm should record receipt date, issue type, responsible team, response, remedy, reportability and root cause. Repeated complaints about withdrawals, slippage, bonuses or identity checks may indicate a systems, product-governance, liquidity or marketing problem. Closing each ticket separately without analysing the pattern can hide a reportable or systemic weakness.

Does outsourcing technology, support or compliance transfer responsibility?

Usually not. An external compliance adviser can interpret rules, prepare draft returns and test controls, but the board and licensed entity remain responsible for understanding and approving what is submitted. If a cloud service, trading platform, KYC vendor, call centre or payment provider fails, the regulator will expect the licensed firm to explain how the vendor was selected, monitored and replaceable.

A material outsourcing contract should address scope, data ownership, access and audit rights, subcontracting, incident notification, business continuity, exit assistance and regulatory access to information. The broker should test data recovery, key-person absence, payment interruption, cyberattack and provider insolvency scenarios rather than rely only on the supplier’s standard service description.

What should happen in the first 90 days after licence approval?

  1. Days 1–30: reconcile the licence and approval conditions with the proposed business; block unapproved products and countries; verify the names and functions of operating, client-money and payment accounts; and confirm board and key-person responsibilities.
  2. Days 31–60: implement operating procedures for capital, client money, AML, complaints, marketing, changes and outsourcing; allocate a preparer and an independent reviewer to every material control.
  3. Days 61–90: rehearse a regulatory return, client-money reconciliation, suspicious-activity escalation and major incident; correct data-definition gaps; and submit the evidence to the board for challenge and approval.

If the business has not launched, its obligations do not necessarily pause. Capital, key-person, audit, annual charge, reporting, company-record and licence-condition duties may still apply. A material departure from the approved business plan may also need regulatory discussion or approval before implementation.

How should annual compliance costs be budgeted?

Ongoing cost is broader than the annual licence charge. A realistic budget may include compliance and MLRO staff, local directors or controlled functions, audit, accounting and regulatory reporting, AML/KYC and transaction-monitoring systems, client-money banking, professional indemnity insurance, cybersecurity, legal advice, training, outsourced assurance and the cost of holding regulatory capital.

The budget should distinguish fixed costs, volume-based costs, event-driven costs and capital that remains tied up. Permissions to hold client assets, retail business, dealing as counterparty and the countries targeted can materially change the resource requirement. There is no single annual amount that safely represents every forex licence.

Common causes of post-licensing compliance failure

  • The application describes one model, but an unlicensed affiliate performs solicitation, collection or customer support after launch.
  • Capital is checked only at the filing date, with no warning threshold or cash-flow restriction between reports.
  • A client-money reconciliation shows a break, but there is no documented investigation, funding decision or escalation.
  • An adviser submits regulatory returns while directors and management cannot explain the data source.
  • Ownership, directors, auditor or address change before the firm confirms whether prior approval was required.
  • The AML system produces a high volume of alerts without enough trained staff to investigate and record decisions.
  • Affiliates continue using an outdated permission, risk warning or permitted-country list.
  • Payment of the annual fee is treated as evidence that audit, filings and every licence condition have been completed.

The recurring weakness is often not the absence of a policy. It is the inability of the workflow, system data and board record to show that the policy operates. A firm still designing its application can reduce these gaps by building ownership and evidence into the operating plan from the start; see our forex licence application guide.

Frequently asked questions

Can a broker serve clients worldwide immediately after licence approval?

No such assumption should be made. The licence confirms the activities authorised in the issuing jurisdiction. The client’s location, product, solicitation method and contractual arrangements may still trigger local licensing or restrictions.

Must client money be reconciled every day?

Daily reconciliation is not a safe universal rule. The firm must follow the frequency and method required by its client-asset regime and licence conditions, while ensuring that discrepancies are identified, investigated, funded and escalated promptly.

Is one annual regulatory audit enough?

Usually not. An annual financial audit is only one continuing obligation. Prudential, transaction, client-money, AML, complaints and incident reports may follow different cycles or be triggered by an event.

Can a shareholder or director change be completed before notification?

Not always. Some regimes require prior approval for changes in control, significant ownership, directors or key persons; others impose a notification deadline. The requirement should be established before signing or appointment.

Does paying the annual fee complete the licence renewal?

No. Some licences continue in force while annual charges and filings remain due; other regimes have a renewal process. Annual fees, annual compliance and licence renewal are separate matters that must be checked individually.

Can the compliance function be fully outsourced?

External specialists can assist, but outsourcing does not normally transfer the board’s or licensee’s accountability. The firm still needs adequate knowledge, personnel, data access, review capability and a supplier exit plan.

Do compliance obligations continue if the broker has no clients?

They often do. Capital, personnel, annual charges, audits, returns, company records and licence conditions may continue to apply, and a changed business plan may require regulatory approval.

How should a broker build its first compliance calendar?

Extract each obligation from the licence, approval letter, applicable law, regulator portal and company anniversary. Record its cycle or trigger, data source, preparer, reviewer, escalation route and submission receipt.


Discuss Your Licensing and Business Needs

Tell us what you need and our team will contact you shortly.