Home/Legal and compliance services for digital and regulated business

Legal and compliance services for digital and regulated business

Five areas of work, each with a defined output and a fee agreed before it starts.

Five areas of work. They are listed in the order they usually have to happen — a licence application built on the wrong corporate structure fails on the structure, and a bank account application built on a weak AML file fails on the file.

Each area below sets out what is included, how the work runs, what we need from you and what you hold at the end. Fees are agreed in writing before work starts: a fixed fee for defined scopes, a monthly retainer for ongoing support.

01

Structuring and corporate set-up

The question is never “which jurisdiction is best”. It is which jurisdiction your bank, your payment provider, your regulator and your future acquirer will all accept for the specific thing you do. Those four answers frequently differ, and the structure has to survive all of them.

What is included

  • Mapping the business model: who contracts with the customer, who holds the licence, who owns the IP, where revenue lands and how it moves between entities.
  • Jurisdiction analysis against the criteria that actually bind you — authorisation requirements, substance expectations, banking acceptance, treaty position and exit options.
  • Group design: holding, operating and IP-holding entities, with the intragroup agreements that make the structure real rather than nominal.
  • Governance: directors, signing authority, board minutes and the decision trail a supervisor or an auditor will ask to see.
  • Ownership and control mapping for beneficial ownership registers and for counterparty due diligence.

What we need from you

A description of the product, your current and target markets, how money reaches you today, the entities that already exist and any commitments already made to banks, investors or partners. If a structure is already in place, the constitutional documents and the last set of accounts.

What you end up with

A written structuring memo with the recommended option, the rejected options and why, a step plan with sequence and dependencies, and the corporate and intragroup documents to implement it.

02

AML/KYC and internal control

A template policy is worse than no policy, because it creates obligations your team does not know it has. The point of this module is a framework your staff can actually operate on a Tuesday afternoon, and that holds up when a supervisor asks for the file behind a specific decision.

What is included

  • Business-wide risk assessment: customer, product, geography, channel and payment risk, with a documented methodology rather than a colour-coded table.
  • AML/CFT policy and the procedures beneath it — onboarding, ongoing monitoring, escalation, reporting.
  • CDD and EDD standards, PEP identification, sanctions and adverse-media screening, and what to do with a hit.
  • MLRO appointment: duties, reporting lines, independence and the records the role has to generate.
  • Transaction monitoring rules, thresholds and the tuning log that explains why they are set where they are.
  • Training programme, record retention schedule and an internal audit plan.

The detail sits on the dedicated page: AML/KYC, MLRO and internal control.

03

Licensing and authorisation

Three regimes account for most of what we do: crypto-asset services under MiCA, payment and electronic money institutions, and EU-facing online gaming. They differ in substance but the failure modes are identical — an incomplete file, a business plan that does not match the application, and key personnel who cannot evidence what the regulator requires.

What is included

  • Regime and jurisdiction selection, with a gap analysis against where you are today.
  • The application file: programme of operations, business plan, governance, capital evidence, policies, outsourcing arrangements and key-personnel documentation.
  • Fit-and-proper preparation for directors, shareholders and key function holders.
  • Handling requests for further information during the review, which is where most timelines are lost.
  • The post-authorisation obligation calendar — reporting, notifications, audits and change approvals.

Jurisdiction comparison, indicative capital requirements and the reasons applications are refused are set out on the licensing page.

04

Contracts and commercial paper

Regulated businesses tend to have excellent licence files and improvised contracts. That asymmetry shows up at the worst moment: a payment dispute, a partner exit or a data protection incident.

What is included

  • Customer-facing terms, acceptable use and complaint handling, aligned with the licence conditions.
  • Supplier, platform and white-label agreements, including the liability and audit rights a supervisor expects to see in an outsourcing arrangement.
  • Affiliate and performance marketing terms: traffic quality, fraud, chargeback treatment, payout and termination.
  • NDA, DPA and international transfer documentation, including standard contractual clauses where relevant.
  • Intragroup agreements that support the structure rather than contradict it.
05

Banking and PSP onboarding

Refusals are rarely about the business being unacceptable. They are about the file not answering the questions the compliance team is required to close. Those questions are predictable, which means the file can be built before the application rather than after the first decline.

What is included

  • An onboarding pack: corporate documents, ownership chain to natural persons, source of funds and source of wealth narrative, licence and regulatory status, AML framework summary and a clear description of the flow of funds.
  • A written explanation of the business model in the language a compliance officer uses, not the language of a pitch deck.
  • Institution selection: matching your risk profile to institutions that actually serve it, rather than applying broadly and accumulating declines.
  • Responses to requests for information, and remediation where a previous refusal is on record.

Background reading: why banks say no to regulated digital businesses.

Working together

Engagement formats

Written assessment

A fixed-fee memo answering a defined question: which authorisation applies, whether a structure holds, what a refusal was really about. Usually the right first step.

  • Fixed fee agreed in advance
  • 5–10 working days
  • Delivered in English

Defined project

A licence application, a full AML framework, a restructuring. Scope, deliverables, sequence and fee fixed at the outset, with agreed points at which scope can change.

  • Fixed or capped fee
  • Written scope document
  • Named deliverables

Ongoing support

A monthly retainer for businesses that are authorised and have to stay that way: reporting deadlines, change notifications, contract review and the questions that arrive without warning.

  • Monthly fee, agreed hours
  • Priority response
  • Obligation calendar maintained
Boundaries

What we do not do

This list is here because it saves both sides a conversation, and because a practice that claims to do everything is telling you something about how it works.

  • We do not sell licences as a product and do not quote a date by which one will be granted.
  • We do not act as a nominee shareholder or director, and do not arrange nominees whose role is to obscure beneficial ownership.
  • We do not advise on structures whose purpose is to conceal the origin of funds or to evade sanctions.
  • We do not provide accounting, audit or tax filing services — we work alongside your advisers, or introduce ones we have worked with.
  • We do not take instructions where the AML risk cannot be resolved. It is a professional obligation, not a preference.

Frequently asked questions

Can we start with one module and add others later?

Yes, and it is usually the sensible order. Most engagements begin with a written assessment, because it converts an open question into a scoped piece of work. Modules added later reuse the material already produced rather than starting again.

Do you work in English only?

Working languages are English, Ukrainian and Russian. Documents intended for EU regulators, banks and counterparties are drafted in English; filings in other languages are handled with certified translation and local counsel where the jurisdiction requires it.

How do you charge?

Fixed fee for defined scopes, monthly retainer for ongoing support, and hourly only where the scope genuinely cannot be defined in advance — which is rarer than the market suggests. Third-party costs (state fees, local providers, translations, audits) are passed through at cost and identified separately.

Who actually does the work?

Each mandate has a named lead who scopes it and stays with it to delivery, with specialists joining by discipline — regulatory, AML, corporate. Substantive documents are reviewed at senior level before they leave. Local counsel and specialist providers are engaged where a jurisdiction requires it, and you are told who they are before they are instructed.

Can you take over a matter another firm started?

Yes. It is worth budgeting for a short review stage first — inherited files often contain assumptions that were reasonable when made and are no longer true, and it is cheaper to find those before filing than after a request for information.

Tell us what you are building

A short description of the product, the markets and the payment flows is enough for us to say what is required, in what order and at what cost.

Describe your matter

We reply within one business day with a scope, the deliverables and an indicative fee — not a brochure.

Prefer another channel? Write to info@itlex.pro or t.me/itlexpro. Your data is used only to answer this enquiry.