Regulatory counsel · Kyiv · United Kingdom

Legal and compliance support for regulated digital business

Structuring, AML/KYC, licensing and banking onboarding for iGaming, FinTech, virtual assets and affiliate businesses. We work on what regulators, banks and payment partners actually check — and we say plainly when something cannot be done.

Since 2010In practice — advocate certificate No. 195
Since 2018Focused on regulated digital markets
1 dayReply to a written enquiry, in EN, UK or RU

How an engagement starts

No discovery calls that go nowhere. Four steps, each with a written output.

  1. BriefProduct, markets, payment flows, deadlines.
  2. AssessmentWhat is required, what is optional, what is not feasible.
  3. Scope and feeDeliverables, sequence and cost, in writing.
  4. DeliveryDocuments, filings and support during review.
Who we work with

A practice built around one question

Regulated digital businesses rarely fail because of a single legal document. They fail because the corporate structure, the money flow and the compliance file tell three different stories. Our work is to make them tell one.

ITLex is an advocate-led practice working with founders and management teams whose products sit inside a regulated perimeter: crypto-asset services, payments and e-money, online gaming, affiliate networks and the SaaS platforms that serve them. Client engagements are contracted through ITLEX LTD, a company registered in England and Wales under number 17044071, and the work is led by an advocate admitted to the Ukrainian bar in 2010.

Most of our clients arrive at one of three moments. They are about to enter a market and need to know which authorisation applies. They have been asked by a bank or a payment provider for a compliance file they do not have. Or they already hold a licence and have discovered that keeping it is a different discipline from obtaining it.

In each case the deliverable is the same in character: a written answer that a regulator, a bank compliance officer or an investor's counsel can read without needing you to explain it.

Typical first questions

  • Which authorisation does our model actually require — and in which member state?
  • Why did three banks decline our account, and what would change that?
  • Our AML policy was copied from a template. What happens when it is tested?
  • We hold a licence. What are we supposed to be doing quarterly that we are not?
  • Can this structure survive a due diligence by an acquirer?
Ask yours
Practice areas

Four modules of work

Take one module or combine them. Each has a defined output, so you always know what you are paying for.

01

Structuring and corporate set-up

Choosing the jurisdiction and the group shape that your payment rails, partners and future investors will accept — not the cheapest one on a comparison table.

  • Holding, operating and IP entities
  • Substance and governance expectations
  • Intragroup contracts and money flow
  • Ownership and control mapping
Practice areas
02

AML/KYC and internal control

Policies and procedures written for your actual product, plus the governance around them: who decides, who escalates, who reports and what is kept on file.

  • Risk assessment and risk appetite
  • CDD, EDD, PEP and sanctions screening
  • MLRO appointment and duties
  • Staff training and internal audit
AML/KYC
03

Licensing and authorisation

Preparing the application file and carrying it through the regulator's review: MiCA/CASP, payments and e-money, EU gaming regimes.

  • Regime selection and gap analysis
  • Application file and policies
  • Responses to regulator questions
  • Post-authorisation obligations
Licensing
04

Contracts and banking onboarding

The commercial paper the business runs on, and the file that decides whether a bank or PSP opens the account.

  • Platform, provider and affiliate agreements
  • NDA, DPA and data transfer terms
  • Bank and PSP onboarding packs
  • Written responses to compliance queries
Practice areas
Industries

Sectors we know in detail

iGaming and betting

Licensing, supplier and platform agreements, player-facing terms, responsible gaming and AML obligations.

FinTech, payments and e-money

Authorisation strategy, safeguarding, outsourcing and the operational compliance a supervisor expects.

Virtual assets (CASP)

MiCA authorisation, travel rule, market abuse controls and the custody and complaint procedures that go with them.

Affiliate and performance marketing

Network terms, traffic quality and fraud clauses, data protection and payout structures.

SaaS and platforms

Contract architecture, IP ownership, processor and controller roles, and readiness for enterprise due diligence.

Cross-border groups

Where the same product is sold from several entities and the paperwork has to agree with the money.

Method

How an engagement runs

Every stage ends with something written. You are never paying for a conversation you cannot forward to your team.

  1. Brief

    A written questionnaire plus one call. Product, clients, jurisdictions, payment flows, deadlines and appetite for risk. Typically 2–3 days.

  2. Assessment

    A memo setting out the applicable requirements, the realistic options and what each one costs in time and capital. Typically 5–10 working days.

  3. Documents

    Policies, procedures, corporate documents and application files, drafted for your model rather than adapted from a template.

  4. Support

    Regulator and bank correspondence, responses to requests for information, and the maintenance calendar once you are authorised.

What we will not tell you

We do not quote a date by which a licence will be granted, and we do not promise an outcome. Regulators set their own pace and their own standard. What we do commit to is the sequence, the quality of the file and a realistic range based on how comparable applications have actually moved.

The team

A team, organised by discipline

Regulatory work does not divide neatly into “legal” and “compliance”. Ours is organised around the four things a file actually needs, so the person drafting your monitoring rules is not the person who last saw them in a textbook.

Regulatory and licensing

Regime selection, application files, correspondence with supervisors and the obligations that start the day the licence is granted.

AML and financial crime

Risk assessments, policies and procedures, monitoring design, MLRO support and remediation after a supervisory finding.

Corporate and commercial

Group structures, intragroup agreements, platform and affiliate contracts, data protection documentation and transaction support.

Disputes and defence (Ukraine)

Advocate representation in Ukrainian proceedings, handled by the domestic practice — the reason our compliance documents are drafted with an eye on how they read under scrutiny.

Founded and owned by Roman Stoichev, advocate

Admitted to the Ukrainian bar in 2010 under certificate No. 195 (register entry) and a member of the Ukrainian National Bar Association. The practice began in commercial and criminal defence work; since 2018 it has been built around technology and regulated digital markets.

Every mandate has a named lead who stays with it from the first brief to delivery, and specialists join by discipline rather than by whoever happens to be free. Where a jurisdiction requires a locally admitted lawyer, we engage local counsel and tell you who they are before they are instructed — you are never handed to a subcontractor you have not met.

Ukrainian-market work — advocate representation, searches, questioning and criminal defence — sits with the domestic practice at itlex.legal.

Who you are contracting with

  • CompanyITLEX LTD
  • Reg. no.17044071, England and Wales
  • OfficeSuite 418, 37 St. Andrews Street, Norwich NR2 4TP, United Kingdom
  • Ukrainian practiceAttorneys-at-Law Bureau «Stoichev and Partners», EDRPOU 41551972
  • Kyiv17-V Hryhoriia Skovorody St., Kyiv 04070, Ukraine
  • Emailinfo@itlex.pro
  • Phone+44 7405 121015

Frequently asked questions

Do you obtain licences yourself, or do you work with providers?

We prepare and run the application file — the legal and compliance substance of it. Where a jurisdiction requires a local director, a registered office, an audit or a technical certification, those are supplied by vetted local providers under our coordination. You always know which part of the invoice is legal work and which part is a third-party cost.

Can you work with a company that is already operating?

Most of our work is exactly that. A live business has constraints a greenfield project does not: existing contracts, existing banking relationships, and a history that due diligence will look at. The assessment stage is designed to find those before they turn into a refusal.

What does the first stage cost?

The written assessment is a fixed fee agreed before we start, based on the number of jurisdictions and entities involved. It is quoted after the brief, so you are never asked to approve an open-ended budget. Larger mandates run either as fixed-scope projects or on a monthly retainer.

Do you sign an NDA before the first conversation?

Yes, on request, and it is not a formality — the advocate's professional duty of confidentiality applies to everything you tell us from the first enquiry, whether or not we go on to work together.

Tell us what you are building

A short description of the product, the markets and the payment flows is enough for us to say what is required, in what order and at what cost.

Describe your matter

We reply within one business day with a scope, the deliverables and an indicative fee — not a brochure.

Prefer another channel? Write to info@itlex.pro or t.me/itlexpro. Your data is used only to answer this enquiry.