Fintech regulation in Morocco: innovation meets a demanding licensing system
Morocco has no shortage of fintech ideas. Casablanca, Rabat and increasingly Tangier and Marrakech host startups working on mobile payments, merchant acquiring, remittances, embedded finance, digital insurance and alternative credit scoring. The difficulty begins when a promising product must be translated into a legal category understood by Bank Al-Maghrib, commonly referred to as BAM.
A situation we regularly encounter illustrates the problem. A Casablanca founder develops a wallet for small merchants, raises seed funding and signs technical partners. Only after the product is nearly ready does the team discover that holding customer balances, executing payments and presenting the application as an independent wallet may constitute regulated payment activity. The technology took eight months to build; regulatory restructuring then took longer than the original development cycle.
This is not merely bureaucratic caution. Payment companies handle customer funds, financial data and infrastructure that can be exploited for fraud or money laundering. Supervision is therefore justified. Yet the gap between startup timelines and regulatory timelines remains difficult to defend: a licensing project can take 12 to 24 months from initial structuring to commercial launch, even though the formal decision period is shorter once Bank Al-Maghrib considers the file complete.
The first lesson is simple: Morocco does not have a single, universal “fintech licence”. The required authorisation to conduct fintech activities in Morocco depends on what the company actually does. A payment institution falls under BAM. An insurer or insurance intermediary is supervised by the Autorité de Contrôle des Assurances et de la Prévoyance Sociale, or ACAPS. A collaborative financing platform may fall under Law No. 15-18 and involve BAM or the Autorité Marocaine du Marché des Capitaux, depending on its model. A technology vendor that never controls funds may need no financial licence at all, although data protection, cybersecurity and contractual rules still apply.
1. The legal map for digital financial services in Morocco
1.1 Law No. 103-12 remains the cornerstone
The central banking statute is Law No. 103-12 relating to credit institutions and similar bodies, promulgated by Dahir No. 1-14-193 of 24 December 2014 and published in Official Bulletin No. 6328 of 22 January 2015. It governs banks, finance companies, payment institutions and other assimilated bodies.
Article 1 of Law No. 103-12 reserves the habitual performance of banking operations to duly authorised credit institutions. These operations include receiving funds from the public, credit operations and making payment means available to customers or managing them.
Articles 15 and 16 of Law No. 103-12 are especially relevant to payment fintechs. Article 15 recognises payment institutions as legal persons, other than credit institutions, that provide one or more payment services. Article 16 identifies regulated payment services, including money transfers and services associated with payment accounts, subject to the exact scope and implementing regulations issued by BAM.
This classification has practical consequences. A software company supplying an API to a licensed bank is not automatically a payment institution. By contrast, a company that contracts directly with users, receives their money, maintains payment accounts or executes transfer orders in its own name is much more likely to require a Bank Al-Maghrib fintech authorisation.
1.2 A necessary correction concerning the alleged “Law No. 78-21”
Some online summaries describe a “Law No. 78-21 on payment services and electronic money”, supposedly promulgated in February 2021, and then use it as the basis for Moroccan fintech licensing. Founders should treat that reference with caution. The operative framework normally cited by Bank Al-Maghrib for payment institutions remains Law No. 103-12 and its implementing circulars. Before quoting Law No. 78-21 in an application, counsel should verify the Arabic and French text in the Official Bulletin and confirm that its number, title and provisions actually correspond to the proposed business.
The same warning applies to references to a supposed BAM Circular No. 19/G/21 creating a separate electronic-money issuer licence with capital of MAD 10 million. Morocco’s framework does not simply reproduce the European distinction between a payment institution and an electronic-money institution. Payment accounts, mobile wallets and stored value must instead be analysed under Law No. 103-12, BAM circulars governing payment institutions and the contractual structure of the product.
1.3 The principal regulators
Bank Al-Maghrib supervises credit institutions and payment institutions. Its Credit Institutions Committee, known in French as the Comité des établissements de crédit, is consulted during the approval process in the cases prescribed by law. BAM also oversees prudential soundness, governance, internal control, customer protection and anti-money laundering systems.
ACAPS, established under Law No. 64-12, supervises insurance and social welfare activities. The AMMC supervises capital markets and certain investment-based collaborative financing activities. The Commission Nationale de contrôle de la protection des Données à caractère Personnel, or CNDP, enforces Law No. 09-08 on personal data. The Office des Changes becomes relevant when foreign investment, cross-border services, foreign-currency payments or profit repatriation are involved.
In short, the Moroccan legal framework for digital financial services is institutional rather than technology-based. Regulators look beyond labels such as “marketplace”, “neobank” or “super-app” and examine the underlying flow of funds, contractual commitments and allocation of risk.
2. Who needs Bank Al-Maghrib approval?
2.1 Payment activities that normally trigger licensing
A startup should request a regulatory classification before launch if its model includes opening payment accounts, receiving money for execution of payment transactions, cash-in or cash-out, issuing or managing payment instruments, merchant acquiring, domestic money transfers or maintaining a wallet through which users can store and spend funds.
The decisive questions are concrete. Who receives the customer’s money? In whose books is the customer balance recorded? Who owes repayment to the customer? Who executes the order? Who bears settlement and fraud risk? Marketing language is secondary. Calling a payment account a “digital balance” does not remove it from BAM’s jurisdiction.
Credit requires a separate analysis. Under Article 1 of Law No. 103-12, the habitual extension of credit is a regulated banking operation. A fintech that lends its own funds, purchases receivables, advances salaries or finances merchants may need authorisation as a credit institution or finance company, depending on the structure. A pure marketplace that introduces borrowers to a licensed lender may avoid lending directly, but advertising, intermediation, customer-data processing and outsourcing obligations remain.
Buy-now-pay-later models deserve particular caution. A genuine interest-free commercial payment period granted by a seller is not automatically the same as a professional credit operation. Once a third-party fintech finances the purchase, charges the merchant, takes repayment risk or repeatedly advances funds, the legal character can change. There is no safe exemption merely because the product is described as BNPL.
2.2 Payment institution categories and minimum capital
The minimum capital is determined by the services covered by the application and BAM’s implementing rules. Publicly available summaries of the framework have commonly identified thresholds of approximately MAD 6 million for institutions limited to money-transfer activity and MAD 10 million where broader payment-account services are provided. These figures must be confirmed against the circular in force on the filing date and during the pre-filing meeting with BAM.
The frequently repeated figure of MAD 3 million for a Moroccan payment institution should not be used as a budgeting assumption without an official, current legal source. Regulatory capital is also not the same thing as ordinary company-law capital. Under Article 6 of Law No. 17-95 on sociétés anonymes, the general minimum capital of a non-publicly offered SA is MAD 300,000, while the minimum rises to MAD 3 million where the company makes a public offering. A regulated entity must satisfy the higher sector-specific capital applicable to its licence.
2.3 Ownership, directors and governance
BAM examines more than the amount deposited in a bank account. It assesses the identity and financial standing of shareholders, the transparency of the ownership chain, the reputation and competence of managers, governance arrangements, conflicts of interest and the applicant’s capacity to remain financially viable.
Foreign investors are permitted in principle. They should nevertheless expect enhanced documentation: corporate registers, audited accounts, beneficial-owner declarations, criminal-record or equivalent certificates, proof of origin of funds and legalised documents from the country of incorporation. Foreign investment must also be structured consistently with the foreign-exchange rules administered by the Office des Changes, especially if investors expect later dividend or disposal-proceeds repatriation.
In one recurring type of file, a startup presents an impressive technical team but no shareholder capable of supporting the company through two years of regulatory and operating losses. BAM’s concern is predictable: minimum capital is not a substitute for a sustainable funding plan. We have also seen projects forced to simplify offshore holding arrangements because the ultimate beneficial ownership could not be demonstrated quickly enough.
2.4 The application process and the four-month rule
Articles 19 to 21 of Law No. 103-12 organise the approval process. The application is submitted to the Governor of Bank Al-Maghrib, the legally prescribed opinion is obtained from the Credit Institutions Committee, and the decision is notified within the statutory period calculated from receipt of a complete file. The commonly cited period is four months after the application is deemed complete.
The practical trap lies in the words “complete file”. The clock does not protect an applicant while essential governance, capital, AML, technology or outsourcing documents remain outstanding.
In practice, preparation may take three to six months, while exchanges with the regulator can extend the overall project to 12, 18 or even 24 months. A founder may feel that the application has been pending for a year, whereas the administration still regards it as being completed. This distinction explains much of the frustration surrounding the payment institution licence in Morocco.
A serious application normally includes constitutional documents, shareholder information, a three-year business plan, financial projections, a detailed description of payment flows, governance policies, an organisation chart, managers’ CVs, criminal-record documents, an internal-control framework, an AML/CFT manual, outsourcing contracts, a cybersecurity architecture, incident-response and business-continuity plans, customer agreements, complaints procedures and evidence concerning the protection of customer funds.
External legal, audit and compliance preparation often costs between MAD 100,000 and MAD 350,000, depending on complexity. Technology audits, penetration testing and security certification can add substantially more. These are market estimates, not administrative fees charged by BAM.
2.5 Errors that delay applications
The most common mistake is a generic AML manual copied from a conventional business. It does not explain onboarding thresholds, remote identity checks, sanctions screening, transaction-monitoring scenarios, suspicious-transaction escalation or the risks created by agents and cross-border flows.
A Marrakech payment project once presented a manual that addressed domestic cash transfers but said nothing about transactions initiated abroad, although remittances were central to its business plan. Whether BAM formally “rejects” such a file or simply requires extensive remediation, the commercial result is the same: months are lost.
Other recurring problems include inconsistent financial projections, unsigned bank-partner agreements, vague cloud-hosting arrangements, no exit plan for a critical outsourcer, and customer terms that allow the startup to use safeguarded balances for its own expenses. A review by an banking lawyer in Casablanca before filing can be cheaper than rebuilding the file after the first regulatory questions.
3. Mobile wallets and electronic value
3.1 Do not assume that Morocco has an EU-style EMI licence
European law distinguishes payment institutions from electronic-money institutions under PSD2 and the Electronic Money Directive. Morocco has developed its own architecture. A wallet must be classified by examining whether it is attached to a payment account, who records the balance, whether funds are repayable, how cash-in and cash-out work, and whether the startup or a licensed partner is the regulated provider.
Consequently, there is no reliable shortcut under which every rechargeable wallet automatically obtains a separate “electronic-money issuer licence”. The product may require payment-institution approval, may need to be issued by a bank, or may operate as a technical layer under a licensed institution’s responsibility.
3.2 Protecting customer funds
A payment institution must keep customer funds separate from its own operating resources in accordance with the applicable BAM rules and the licence conditions. In practice, this requires a properly drafted account-holding and safeguarding arrangement with a Moroccan credit institution. Customer money cannot become startup working capital.
This banking relationship is often the hidden bottleneck. Founders spend months on the application interface but approach the safeguarding bank too late. Moroccan banks conduct their own due diligence and may request detailed information on ownership, AML controls, expected transaction volumes and technical connectivity before signing.
3.3 Wallet limits and agents
BAM has historically used tiered payment-account arrangements, with limits linked to customer-identification levels and risk. Figures such as MAD 200, MAD 5,000 and MAD 20,000 have appeared in earlier market documentation for different account categories. They should not be presented as permanent universal limits: the current circular, the account type and BAM’s latest instructions must be checked before product launch.
Payment institutions may also rely on agent networks subject to regulatory conditions and the principal institution’s responsibility. This is commercially valuable in rural areas, where grocery shops, transfer agencies and other local outlets can support cash-in and cash-out. The institution remains responsible for agent selection, training, monitoring, customer information and AML controls.
4. Can a fintech test without a full licence?
4.1 BAM’s fintech support should not be confused with a legal exemption
Bank Al-Maghrib has developed fintech engagement mechanisms, including a fintech desk or one-stop-shop approach and dialogue with innovators. This is a positive development. It allows startups to present their model, identify regulatory concerns and discuss possible partnerships before making a formal application.
Attention, however: publicly accessible Moroccan law does not support a general proposition that every selected startup may conduct regulated payment activity for 12 months without approval, or that a supposed Circular No. 5/G/2021 creates an automatic sandbox exemption. Unless BAM grants a specific, written and legally grounded testing framework, a startup should not accept customer funds or execute regulated payments merely because the service is labelled a pilot.
A demonstration using fictitious data is not regulated payment activity. A live test involving real customers and real money may be.
4.2 Safer testing structures
Three structures are generally safer. The first is a closed technical proof of concept with no real funds. The second is a pilot conducted by a licensed bank or payment institution, with the regulated partner remaining the contractual service provider. The third is a narrowly framed test expressly approved in writing by the competent regulator.
The Banking-as-a-Service model can accelerate market entry, but it is not regulatory invisibility. Contracts must identify who onboards customers, who performs KYC, who holds funds, who executes transactions, who handles complaints and who reports incidents. BAM’s outsourcing expectations also prevent a licensed institution from becoming an empty shell while the unlicensed startup performs every regulated function.
Morocco’s experimentation framework remains timid compared with the United Kingdom’s FCA sandbox or the structured regimes of the United Arab Emirates. Dialogue supported by international partners, including GIZ programmes concerning financial-sector development and inclusion, is therefore useful. Yet no conference, accelerator or innovation label replaces a licence.
5. Insurtech: when ACAPS, rather than BAM, is the main regulator
5.1 Digital distribution remains insurance distribution
An insurtech that underwrites insurance or presents itself as the insurer falls within ACAPS supervision. A platform that solicits customers, compares contracts in a manner amounting to intermediation, collects proposals or concludes policies may require approval as an insurance intermediary under Law No. 17-99 establishing the Insurance Code, promulgated by Dahir No. 1-02-238 of 3 October 2002.
The fact that the journey is entirely digital does not create an exemption. The Insurance Code was adopted in 2002 and, frankly, it shows its age when applied to embedded insurance, algorithmic pricing and app-based microinsurance. ACAPS has nevertheless developed rules and guidance for electronic distribution, meaning that consent, pre-contractual information, authentication, record retention and complaint handling must be built into the platform.
Insurance comparison sites occupy a sensitive position. A site that merely publishes neutral information is not necessarily a broker. If it recommends products, collects underwriting information, receives commissions or guides the customer to contract formation, ACAPS may view the activity differently.
5.2 Hybrid products may involve two regulators
A wallet offering accident cover, premium collection or embedded microinsurance may involve both BAM and ACAPS. The payment component does not eliminate insurance-distribution requirements, and insurance approval does not authorise payment services. The safest approach is a joint regulatory map prepared before contracts and interfaces are finalised, ideally with an insurance lawyer in Casablanca.
6. The legal compliance checklist for a Moroccan fintech
6.1 Corporate form and incorporation
A regulated applicant will commonly be structured as a Moroccan société anonyme with fixed capital, subject to the requirements of Law No. 17-95 and sector-specific banking rules. A SARL may be suitable during an early technology-development phase, but conversion can become necessary before regulated approval. Founders should not lock intellectual property, investor rights and preference arrangements into a structure that cannot support the future licence.
Ordinary incorporation through the Regional Investment Centre and OMPIC can be completed relatively quickly when the documents are ready. Regulated structuring takes longer because articles of association, shareholder agreements and governance provisions must remain compatible with BAM’s powers and prudential expectations. An corporate lawyer in Marrakech or another Moroccan city can coordinate incorporation, but banking-regulatory input is still required.
6.2 AML/CFT obligations
Morocco’s principal AML statute is Law No. 43-05 relating to the fight against money laundering, as substantially amended by Law No. 12-18. It would be inaccurate to describe Law No. 12-18 as a completely separate AML code. Payment and credit institutions are subject to customer due diligence, beneficial-owner identification, ongoing monitoring, record retention and suspicious-transaction reporting obligations.
The competent financial-intelligence authority is the Autorité Nationale du Renseignement Financier, formerly known as the UTRF. A fintech must calibrate customer risk, politically exposed person controls, sanctions screening and transaction-monitoring scenarios to its actual channels. Remote onboarding, agents, rapid wallet circulation and remittances require stronger controls than an ordinary online shop.
Morocco left the Financial Action Task Force increased-monitoring list in February 2023. That positive result did not reduce compliance expectations. On the contrary, regulators remain focused on demonstrating the effectiveness of supervision. A specialist AML/CFT compliance lawyer in Morocco should test the manual against real user journeys rather than merely review its wording.
6.3 Personal data and CNDP formalities
Every fintech processing personal data in Morocco must comply with Law No. 09-08, promulgated by Dahir No. 1-09-15 of 18 February 2009, and Decree No. 2-09-165 implementing that law. The CNDP is the competent authority.
Under Article 12 of Law No. 09-08, processing is generally subject to prior declaration unless it falls under another prescribed regime. Processing involving particular categories, national identity numbers or other legally specified circumstances may require prior authorisation under Article 21. Cross-border transfers must be analysed under Articles 43 and 44.
Financial data are highly confidential and commercially sensitive, but they should not automatically be labelled “sensitive data” in the technical statutory sense without checking the definition in Law No. 09-08. The fintech must have a valid legal basis, provide a clear privacy notice, limit collection, define retention periods, secure access and manage user rights. Hosting data abroad or using foreign cloud analytics can trigger cross-border-transfer formalities.
There is no universal CNDP shortcut exempting startups or SMEs from these obligations. Forms and procedures may be streamlined administratively, but the applicable declaration or authorisation must still match the processing. An Moroccan personal-data lawyer should review the data map before the application goes live.
6.4 Cybersecurity, outsourcing and operational resilience
BAM expects regulated institutions to identify information-system risks, control privileged access, encrypt sensitive data, monitor incidents, test backups and maintain business-continuity and disaster-recovery arrangements. Cloud hosting does not transfer regulatory responsibility to the cloud provider.
Critical outsourcing contracts should include audit rights, confidentiality, incident notification, continuity commitments, data-location information, subcontracting restrictions and an exit plan. Penetration tests and independent security reviews should be performed before launch and periodically thereafter.
Annual compliance costs for a medium-sized fintech can readily reach MAD 400,000 to MAD 1.2 million when compliance staff, internal control, external audits, cybersecurity tools, screening databases and legal support are included. A founder who budgets only for minimum capital has not budgeted for a regulated business.
6.5 Customer contracts and complaints
Terms and conditions must clearly identify the licensed provider, fees, execution times, account limits, authentication rules, unauthorised-transaction procedures, suspension rights, complaints channels and termination consequences. Promotional screens must be consistent with the legal contract. A disclaimer hidden at the bottom of a website cannot cure a misleading claim that the startup is a “bank”.
Complaint management should have assigned staff, traceable deadlines and escalation rules. Where a bank or licensed payment institution powers the product, the customer journey must explain the respective roles of the startup and regulated partner. This is central to the legal compliance of a Moroccan fintech startup, not a cosmetic drafting exercise.
7. A realistic route from incorporation to legal launch
7.1 Typical stages, costs and timing
Regulatory classification: four to eight weeks. Map the product, payment flows, credit exposure, customer contracts and data processing. Obtain preliminary legal advice and, where appropriate, engage with BAM’s fintech contact point.
Corporate and investment structuring: one to three months. Incorporate or convert the company, document beneficial ownership, protect intellectual property and align shareholder rights with regulatory governance.
Bank and technology partnerships: two to six months. Negotiate safeguarding, settlement, card, KYC, cloud and outsourcing arrangements. These discussions often overlap with the licensing work.
Application preparation: three to six months. Build the business plan, compliance manuals, financial model, risk framework, customer documents and technical evidence.
BAM review: formally tied to completeness, but often six to eighteen months overall. Respond to questions, revise documents, demonstrate capital and complete governance appointments.
Controlled launch and post-authorisation supervision. Approval is the beginning of ongoing reporting, audit and inspection obligations, not the end.
A realistic pre-launch budget ranges from MAD 800,000 to more than MAD 3 million, excluding regulatory capital. The range depends on whether the company builds infrastructure itself, partners with a bank, uses agents, processes cards or handles cross-border flows. The total journey commonly lasts 12 to 30 months.
7.2 The BaaS alternative
Operating under a licensed partner can be faster and less capital-intensive. A bank or payment institution remains the provider of the regulated service, while the startup supplies the interface, customer-acquisition channel or technology. CIH Bank, Attijariwafa bank, Bank of Africa and other Moroccan institutions have engaged with fintech ecosystems, although partnership appetite varies by product and risk profile.
The agreement must go far beyond an ordinary software contract. It should regulate customer ownership, KYC allocation, transaction approval, safeguarding, settlement, data access, fraud losses, complaints, regulatory reporting, audit rights and exit assistance. Before signing, founders may consult an business lawyer in Rabat together with financial-regulatory counsel.
8. Open banking, crypto-assets and the changing regulatory agenda
8.1 Open banking remains contract-led
Morocco has not adopted a direct equivalent of the European Union’s PSD2 open-banking regime creating standardised rights for account-information and payment-initiation providers. API access is therefore largely shaped by bilateral bank contracts, banking secrecy, Law No. 09-08, cybersecurity requirements and the general banking framework.
A customer’s consent does not by itself force a bank to open its API. Nor does screen scraping become safe merely because the user shares credentials. Account aggregators should anticipate strong customer authentication, explicit and traceable consent, data-minimisation, API-security and liability requirements as the Moroccan framework develops.
8.2 Crypto-assets and tokenised payments
Moroccan authorities have worked on a dedicated crypto-asset framework, while Bank Al-Maghrib, the Ministry of Economy and Finance, the AMMC and the Office des Changes have repeatedly warned about risks associated with virtual assets. The legislative status can change quickly. A founder should verify the latest adopted text in the Official Bulletin rather than rely on announcements that a bill is merely “ready” or “under discussion”.
Calling a token a loyalty point does not resolve its legal status if it is transferable, redeemable, used for payment or marketed as an investment. Crypto projects may simultaneously raise banking, capital-markets, foreign-exchange, AML, consumer and data-protection issues.
8.3 Morocco’s regional position
Morocco has a sophisticated banking sector and stronger financial infrastructure than many regional peers. It is ahead of Algeria in several areas of payment innovation, but its proportional licensing and experimentation mechanisms remain less mature than Kenya’s mobile-money ecosystem or South Africa’s broader fintech market. Compared with some Gulf jurisdictions, regulatory testing remains cautious.
That caution is not entirely negative. Once obtained, a BAM authorisation creates credibility with banks, investors and corporate customers. The challenge is to make supervision more predictable, publish clearer classification guidance and shorten the period during which applicants do not know whether their files are legally complete.
Conclusion: five legal reflexes for Moroccan fintech founders
A fintech founder should adopt five reflexes. First, map the real flow of funds before naming the product. Second, determine whether BAM, ACAPS, the AMMC or several regulators have jurisdiction. Third, secure the bank and outsourcing architecture early. Fourth, budget for ongoing AML, data and cybersecurity compliance, not merely share capital. Fifth, do not test a regulated activity with real customer money unless a licensed partner or written regulatory framework clearly permits it.
The Moroccan regime is complex, but compliance can become a competitive advantage. A startup that holds a robust licence, protects customer funds and passes bank due diligence is much harder to displace than an operator relying on a supposed legal grey zone.
Legal advice should therefore begin during product design, not two weeks before launch. Founders can find a banking lawyer in Morocco or consult an experienced financial-law lawyer in Casablanca to classify the model, prepare the BAM application and negotiate with licensed partners. In Moroccan fintech regulation, anticipation is almost always cheaper than remediation.

