Takeaways
Your product team wants crypto and stablecoin buy and sell inside the app. Your compliance lead points out that you are not a licensed crypto business, and getting licensed in every market you serve is a multi-year programme you have no appetite for.
Both are right, and the disagreement is usually about the wrong question. The question is not whether crypto needs a license. It is who needs to hold it.
This guide covers how that works, where the line sits, and what you still own after a provider takes on the regulated part.
Do you need a license to offer crypto in your app?
Not necessarily. If a licensed provider is the party converting fiat to crypto, holding customer funds, and verifying identity, that provider is the regulated entity for those activities. Your app can present the experience under its own brand while the regulated obligations sit with the partner performing the regulated act.
What triggers a licensing requirement is doing the regulated thing yourself. In most markets that means exchanging fiat for crypto, transmitting customer money, or holding customer assets. Displaying a balance, referring a user, or embedding a partner's flow generally does not.
The practical consequence is that two neobanks can ship products that look identical to a customer, and only one of them needs a money transmitter license, because of what happens behind the interface.
Who is the regulated entity?
In a partner model there is always a regulated entity of record for each regulated activity.
For flows we run, that entity is us. Transak holds registrations in multiple key markets and we are ISO 27001:2022 certified and SOC 2 Type II compliant, and we take responsibility for identity verification, sanctions screening, fraud monitoring, and settlement on the transactions we process.
That is why over 600 apps can offer fiat-to-crypto without becoming crypto businesses themselves. The regulated perimeter sits with the provider, and the app keeps the customer relationship.
Also Read: What is a neobank, and how neobanks improve payments with crypto rails
The rule of custody
If you never hold customer crypto, you are distribution. The user buys through an embedded regulated flow, and the asset is delivered to a wallet the user controls or held by a licensed custodian. You are not holding customer property.
If you hold customer crypto balances, you are a custodian. You now have the asset, the obligation to return it, and in most markets a licensing requirement that follows from that.
What Google Play now requires
Since October 2025, Google Play's cryptocurrency exchanges and software wallets policy has required developers to hold government licensing to distribute custodial crypto apps in 17 jurisdictions.
|
Market |
What Google Play requires of the developer |
|
United States |
FinCEN MSB registration plus a state money transmitter license, or a chartered bank entity |
|
European Union |
CASP authorisation under MiCA |
|
United Kingdom |
FCA registration |
|
Japan |
Crypto asset exchange service provider registration with the FSA |
|
Also in scope |
Bahrain, Canada, Hong Kong, Indonesia, Israel, Philippines, South Africa, South Korea, Thailand, UAE |
Non-custodial wallets are explicitly out of scope, and Google confirmed after industry pushback that the policy targets custodial exchanges and custodial wallet apps rather than self-custody software.
How the integration actually works
Once the regulated perimeter sits with the provider, the remaining question is how much of the interface you want to own. There are three routes, and they trade speed against control:
- Hosted flow: You embed our checkout by redirect, iframe, or JavaScript SDK, or in a mobile WebView for native Android, iOS, and React Native. We own the interface, the identity verification, and card handling. Live in days.
- Semi-native: You run quotes and verification natively through our API, then hand off only the payment step to a hosted page. The journey feels like your product, and card data never enters your PCI scope.
- White-label API: You build every screen and call our backend. Full control of the interface, and the fit when you already run backend payments infrastructure. Two to four weeks is typical. As of July 2026 our Whitelabel API covers on-ramp, so sell flows run through the hosted or SDK routes.

Obligations of the neobank
A partner model moves the regulated activity, but not every obligation.
|
What stays with you |
What sits with the licensed provider |
|
Your customer relationship and brand |
Money transmission and fiat settlement |
|
Terms, disclosures, and how the feature is described in-app |
Identity verification and sanctions screening |
|
Marketing claims and financial promotions rules in your market |
Transaction monitoring and fraud decisioning |
|
App store listing, distribution, and platform policy compliance |
Regulatory reporting for the processed transactions |
|
First-line customer support and escalation |
Licensing in the markets where the flow runs |
Also Read: The Q2 2026 compliance cliff for payments companies
Conclusion
If you do not want to hold customer crypto, then the licensing burden mostly belongs to your provider, and your build is an integration rather than a regulatory programme. And that simple decision reduces your time to market from years to weeks!
Map your target markets and talk to our team about the flows you want to run.
Frequently asked questions
What is a VASP license and when does a neobank need one?
A VASP, or virtual asset service provider, license authorises a business to exchange, transfer, or custody virtual assets. A neobank typically needs one when it performs those activities itself. Working through a licensed provider that performs them instead is the standard route for firms that do not want to run their own licensing programme.
Can I offer crypto without a money transmitter license in the US?
In the US, money transmission licensing is attached to the entity transmitting customer funds. Where a registered provider handles the payment and conversion, that provider carries the FinCEN registration and state money transmitter licenses. Note that Google Play separately requires the app developer to hold licensing for custodial crypto apps distributed in the US.
Does Google Play require a license for crypto features in my app?
Since October 2025, Google Play requires developer licensing for custodial cryptocurrency exchange and software wallet apps in 17 jurisdictions, including the US, UK, EU, Japan, and Canada. Non-custodial apps are explicitly out of scope, so whether your app holds customer crypto determines whether the policy applies to you.
How long does it take to add crypto buy and sell to a neobank app?
A hosted flow can be live in days because the provider owns the interface and verification. A white-label integration typically takes two to four weeks depending on how many screens you rebuild. Building the licensing and compliance stack in-house instead usually takes 12 to 24 months per jurisdiction.
Will my users have to complete KYC twice?
Not if the integration uses verification reuse. KYC Reliance lets an already-completed verification carry over instead of being repeated, and Auth Reliance passes your authenticated session server-to-server so the user never sees a second login. Both remove the drop-off that a duplicate identity check normally causes.
What compliance obligations stay with the neobank?
You remain responsible for your customer relationship, your terms and disclosures, how the feature is marketed under financial promotions rules in your market, your app store listing and platform policy compliance, and first-line support. The provider carries money transmission, identity verification, transaction monitoring, and licensing for the flows it runs.




