Banking & Finance
Financial Services Licensing Vietnam: Readiness Guide
A readiness guide for businesses pursuing financial-services licensing in Vietnam. It connects proposed activities, ownership, capital, governance, personnel, systems, controls and regulator-facing documentation so the application reflects an operating model that can actually be maintained.
A financial-services label does not determine the required Vietnam licence. The regulatory perimeter follows what the product actually does with money, credit, investment, risk, customer assets and data. financial services licensing Vietnam should therefore begin with customer and funds-flow mapping, then test entity type, ownership, capital, governance, technology and continuing supervision. This guide explains how banks, finance companies, fintechs and investors can prepare an evidence-based licensing strategy.
For August 2026, analysis may involve the Law on Credit Institutions No. 32/2024/QH15 in its current amended form, the Anti-Money Laundering Law No. 14/2022/QH15, Decree No. 94/2025/ND-CP on the banking regulatory sandbox and product-specific instruments. The applicable framework depends on the exact regulated activity.
What financial services licensing Vietnam maps first
Describe the customer, onboarding, promise, contractual parties, money source, recipient, settlement path, custody, credit decision, fee, loss allocation and technology provider. Identify who holds customer funds, extends credit, executes payment, gives investment advice, assumes insurance risk or operates the user interface.
Create flow diagrams for normal use, refund, default, complaint, fraud and insolvency. Marketing language and accounting should match the legal structure. If a partner institution performs a regulated step, document where that partner’s responsibility ends and the applicant’s begins.

Define the regulatory perimeter before choosing an entity
Test each function against banking, credit, payment, securities, insurance, foreign-exchange, consumer and other financial rules. Avoid assuming a technology provider is unregulated merely because another entity touches the money. Agency, outsourcing and white-label arrangements still require precise responsibility.
Identify prohibited, licensed, sandbox-eligible and unregulated components separately. A product can contain several. State uncertainty and seek official clarification where commercially material rather than building the launch on an aggressive label.
| Function | Regulatory question | Evidence |
|---|---|---|
| Funds | Who receives, holds, settles or safeguards money? | Accounts and settlement diagram |
| Credit | Who decides, funds and bears borrower loss? | Underwriting and balance-sheet model |
| Customer | Who contracts, discloses and resolves complaints? | Terms and customer journey |
| Technology | Who controls systems, data and algorithms? | Architecture and vendor map |
| Risk | Who monitors fraud, AML and operational events? | Control framework |
| Revenue | What fee or spread does each party earn? | Economics and invoice flow |
Choose a structure that can lawfully operate
Compare a licensed institution, branch, representative presence, specialised company, partnership with an existing licensee and sandbox participation. Consider foreign ownership, market access, capital, scope, governance, operating limits and exit, and identify which structure remains workable when customer volume or product capability expands.
The quickest structure on paper may create dependency or prevent the intended economics. A partnership is not a substitute for the applicant’s own licence if it independently performs the regulated activity. Contracts and product design should reflect the chosen boundary.
“A credible financial licence application proves more than eligibility on filing day. It shows who controls customer money and decisions, how capital absorbs loss, how governance challenges management, how systems remain resilient and how the institution will evidence compliance during ordinary operation and crisis.”
Jurion & Partners — financial licensing principle
Map ownership and source of funds transparently
Identify direct, indirect and beneficial owners, controllers, affiliates and connected interests. Gather corporate, financial, regulatory, tax and integrity records. Explain the acquisition and funding chain and reconcile names and percentages across every document, including arrangements that create influence without formal equity ownership.
Test ownership limits, qualifying-shareholder conditions and change-of-control approvals under the current sector framework. Side agreements and nominee arrangements can undermine transparency and governance. Planned future funding should not contradict the filed ownership model.
Capital must support the actual risk plan
Distinguish legal capital, paid-up capital, prudential capital, liquidity, security deposits and working cash. Show timing, currency, contribution route, source and evidence. Model launch, growth, stress and wind-down rather than presenting only the minimum number, and reconcile capital with the ownership and financial statements supplied.
Capital assumptions should match credit losses, fraud, operational incidents, technology, customer redress and regulatory buffers. Define triggers for additional funding and the shareholder commitment process. Do not use temporary or undisclosed borrowing to simulate genuine capital.

Fit-and-proper evidence should match real responsibilities
Map the board, executive, control functions and key technology or risk roles. Verify qualifications, experience, integrity, conflicts, time commitment and appointment authority under applicable rules. A respected title does not replace required sector experience, and an impressive résumé does not prove availability to perform the role.
Job descriptions, organisation charts, committee mandates and delegation should agree. Plan succession and removal. The regulator should be able to see who owns credit, compliance, risk, audit, security and customer outcomes.
Do not present a nominee manager, borrowed credential, temporary capital deposit, undisclosed controller or vendor-owned control as the applicant’s own capability. Licensing evidence must describe the genuine operating institution. False or misleading material can jeopardise approval and create continuing enforcement exposure.
Governance must challenge commercial growth
Define board oversight, reserved matters, committees, conflicts, related-party transactions, risk appetite, compliance independence and internal audit. Management information should show customer, credit, liquidity, fraud, AML, technology and complaint risks, with thresholds that trigger investigation, restriction or board action.
For financial services licensing Vietnam, policies should identify thresholds, escalation and evidence, not copy generic principles. Test governance using a rejected customer, major outage, fraud alert, insider transaction and capital shortfall scenario.
AML controls should follow product risk
Under the Anti-Money Laundering Law No. 14/2022/QH15 and current instruments, map reporting-entity status and applicable duties. Build risk assessment, customer due diligence, beneficial-owner identification, monitoring, sanctions screening, reporting, record retention and training proportionate to actual flows.
Identify high-risk customers, channels, geographies, products and delivery partners. Automated controls need documented rules, tuning, review and human escalation. Outsourcing does not remove accountability.
Fraud and AML controls should exchange information lawfully
Define how fraud operations, transaction monitoring, customer service, cybersecurity and AML teams share alerts without collapsing distinct legal decisions. A blocked transaction, suspicious report, customer restriction and account closure may have different authority and confidentiality requirements.
Track alert source, review, decision, escalation and outcome. Tune thresholds from tested data and document false positives. Financial services licensing Vietnam evidence should demonstrate that staffing and systems can handle expected alert volume at launch and growth.
Customer onboarding must be reproducible
Define identity sources, liveness or authentication, beneficial ownership, purpose, risk rating, approval and refresh. Preserve evidence and exception reasons. The same customer facts should produce an explainable result under the approved rules.
Technology architecture is part of licensing evidence
Document systems, data flows, access, encryption, logging, resilience, backup, disaster recovery, change management and incident response. Identify local and cross-border hosting and current data-law implications. Test recovery objectives through exercises, record defects and verify corrective work before relying on the platform.
Algorithms for credit, fraud or matching require governance, input quality, bias or error review and override. The institution should understand and monitor critical vendor technology. A slide showing “secure cloud” is not a control framework.
Outsourcing needs inventory, diligence and exit
List critical and material service providers, subcontractors, data locations and concentration. Conduct financial, security, compliance and continuity diligence. Contracts should include service levels, audit, incident notice, regulator access, data, subcontracting and termination assistance, with internal owners monitoring performance and renewal risk.
Prepare an exit plan and alternative for critical services. The licensed entity remains accountable for regulated outcomes. A vendor should not control customer money or decisions beyond the approved and monitored arrangement.

Customer protection should be designed before launch
Prepare clear eligibility, pricing, interest or fee, risk, consent, privacy, cancellation, complaint and redress disclosures. Test the full user journey on mobile and paper. Marketing should not imply deposit protection, guaranteed return or regulatory approval beyond fact.
Define vulnerable-customer, collections, errors, unauthorised transactions and refund handling where relevant. Track complaint cause and remediation. Customer outcomes are operational evidence of governance.
Product approval needs independent challenge
Before launch, require legal, compliance, risk, finance, operations, security and customer review. Record target market, exclusions, pricing, stress, complaints, data, vendor and wind-down implications. The commercial sponsor should answer conditions before final approval.
Changes to scoring, fees, limits, onboarding or settlement can alter the regulatory perimeter and customer risk. Use material-change criteria and controlled release. Do not describe a major redesign as a software update to avoid governance.
Use the sandbox only within its actual scope
Decree No. 94/2025/ND-CP establishes the controlled banking sandbox for specified fintech solutions, including credit scoring, open API data sharing and peer-to-peer lending within its conditions. Sandbox participation is not a general financial-services licence.
Map eligibility, test population, duration, limits, reporting, customer protection, technology and exit. Explain how the product stops, transitions or seeks further authority when testing ends. Activities outside the approved sandbox remain subject to ordinary law.
Prepare one controlled application record
Use a master facts sheet, legal perimeter memo, ownership chart, business plan, financial model, policies, system description, personnel evidence and implementation schedule. Reconcile versions and translations. Assign a source owner for each statement and a review date for facts that may change during assessment.
Log regulator questions, answers and commitments. Update affected materials consistently. Do not promise a system or hire by approval date unless the implementation plan and funding support it.
Prepare management for regulatory interviews
Each proposed leader should understand the business model, role, risks, controls, capital plan and unresolved implementation work. Preparation should test genuine knowledge, not supply rehearsed false answers. Differences between management explanations and written policies should be resolved before submission.
Keep a record of factual commitments made to the regulator and assign delivery dates. If a statement later becomes inaccurate, update it through the proper channel. Financial services licensing Vietnam depends on continuing candour, not only a complete initial form.
Readiness testing should precede activation
Run end-to-end tests for onboarding, transaction, reconciliation, reporting, complaint, AML alert, outage and wind-down. Record defects, owner and closure evidence. Licence issuance should not be mistaken for operational readiness.
Post-licensing obligations begin immediately
Create a calendar for reporting, prudential ratios, fees, audits, policy review, penetration tests, business continuity, training and licence conditions. Monitor ownership, capital, personnel, branch, product, technology and outsourcing changes before implementation, and escalate every proposed material change through financial services licensing Vietnam review.
Maintain regulatory communications and inspection evidence. Investigate breaches, protect customers and report through current procedures. The licence should remain aligned with actual products and channels as they evolve.
Wind-down planning protects customers
Identify triggers, governance, funding, customer notice, transaction stop, fund return, data retention, vendor exit and regulatory engagement for an orderly wind-down. Test the plan against insolvency, cyber incident, licence restriction and unsuccessful sandbox exit.
Maintain access to critical systems and records after commercial service ends. Customer money and claims should not depend on a vendor that can terminate immediately. Update the plan when product scale, partner or settlement arrangements change.
A practical financial services licensing Vietnam workflow
Effective financial services licensing Vietnam legal services connect product design, institutional substance and supervision. Management should receive a perimeter memo, application tracker and operating obligations register with named owners, current evidence and escalation dates. A disciplined sequence that remains usable after licence issuance is:
- Map product, customer, funds, credit, data and revenue flows.
- Classify each regulated, prohibited and sandbox component.
- Select entity, partner and ownership structure.
- Prove capital, management, governance and risk capability.
- Build AML, technology, outsourcing and customer controls.
- Prepare a consistent evidence-led application.
- Test operational readiness before activation.
- Monitor licence conditions, reporting and material changes.
Questions to ask licensing counsel
Ask which exact product function triggers regulation, which entity holds responsibility and what facts could change the perimeter. Request an ownership and capital map, fit-and-proper checklist, regulatory gap assessment, application calendar and launch-readiness plan, including the decision point if the intended licence route is unavailable.
Clients may review Jurion & Partners’ Banking & Finance practice or Contact Jurion & Partners with the product journey, funds flow, ownership chart and financial model. Early financial services licensing Vietnam review can prevent technology and contracts from being built around an unlawful operating assumption.
Conclusion
Financial licensing is a continuing demonstration that the institution can control money, risk, technology and customer outcomes. Approval depends on substance as well as documents. financial services licensing Vietnam should align the product perimeter, ownership, capital, governance and operating evidence before filing and throughout supervised operation.
This article is general information, not advice for a specific financial product. Current law, regulator requirements, ownership and operating facts must be verified before relying on financial services licensing Vietnam.
Phân tích
Phân tích
Phân tích