---
guosmmDocumentId: GUOSMM-A-2026-002
title: "SHOSJJ Licensing Authority — Requirements Hierarchy"
language: en
publishedAt: 2026-06-30T12:00:00Z
effectiveAt: 2026-07-02T00:00:00Z
signingAuthority: Sovereign Military Order of Malta
---

# GAZZETTA UFFICIALE DELL'ORDINE SOVRANO MILITARE DI MALTA
# OFFICIAL GAZETTE OF THE SOVEREIGN MILITARY ORDER OF MALTA (GUOSMM)

| Field | Value |
|-------|-------|
| Document ID | `GUOSMM-A-2026-002` |
| Series | A |
| Document type | Licensing Regulation — SHOSJJ Licensing Authority |
| Published | 2026-06-30T12:00:00Z |
| Effective | 2026-07-02T00:00:00Z |
| Republication | v2 |

---

# SHOSJJ Licensing Authority

## Requirements Hierarchy for Issuance of Licenses to Natural Persons and Legal Entities

**Document Version:** 1.1  
**Authority:** Sovereign Hospitallers Order of St. John of Jerusalem (SHOSJJ)  
**Purpose:** Establish the governance, operational, legal, technical, and compliance requirements for a unified licensing framework applicable to both individuals and organizations.

**Legal basis:** Bull *Pie Postulatio Voluntatis* (1113); Constitutional Charter 2022 Art. 15 and Art. 6(5). This Licensing Regulation is subordinate Order law — not a Carta Costituzionale amendment.

Legal effectiveness originates from publication in the Gazzetta Ufficiale dell'Ordine Sovrano Militare di Malta (GUOSMM). External notice serves transparency and interoperability — not creation.

---

## Section 0 — Monetary and licensing role separation

0.1 **SHOSJJ Licensing Authority** is the **sole institutional license issuer** under this Regulation (`GUOSMM-A-2026-002`).  
0.2 **Treasury** issues **SCUDO** under `GUOSMM-A-2026-001`. **GRU** is **monetary policy** for the tokenized reserve basket — **not** a license issuer.  
0.3 **OMNL** is the Order **EMCB** under `GUOSMM-B-2026-001` — prudential supervisor; **not** the licensor.  
0.4 **DBIS** is the **Tripartite Sovereign Body** for EMCB/CB settlement under `GUOSMM-C-2026-001` — **not** the licensor and **not** a monetary or license issuing delegate.

---

# I. Governance Layer (Highest Authority)

## 1. Licensing Authority

The SHOSJJ Licensing Authority shall:

* Establish licensing policies.
* Approve licensing categories.
* Issue, suspend, revoke, and renew licenses.
* Maintain the official Licensing Register.
* Delegate administrative functions where appropriate.

---

## 2. Legal Framework

The licensing system shall define:

* Jurisdiction
* Authority
* Applicable regulations
* Administrative procedures
* Appeals process
* Enforcement authority

Every issued license shall reference:

* Licensing Act
* Administrative Rules
* Applicable Standards
* Licensing Conditions

---

## 3. Licensing Governance Board

Responsible for:

* Policy
* Standards
* Appeals
* Audits
* Oversight
* Accreditation

---

# II. Licensing Classes

The framework shall support unlimited licensing categories.

Example hierarchy:

```
License

    Person

        Professional
        Diplomatic
        Medical
        Financial
        Technical
        Security
        Judicial
        Academic

    Entity

        Bank
        Financial Institution
        Exchange
        Trust Company
        Insurance
        Technology Provider
        Educational Institution
        NGO
        Government
        Diplomatic Mission
        Medical Facility
        Defense Contractor
        Commercial Enterprise
```

---

# III. License Levels

Each license may include multiple authority levels.

Example:

```
Provisional

Associate

Licensed

Senior

Master

Chartered

Fellow

Honorary
```

Each level defines:

* privileges
* limitations
* supervision requirements
* signing authority
* delegation authority

---

# IV. Subject Types

The licensing system must distinguish between:

## Natural Person

Includes:

* Identity
* Citizenship
* Nationality
* Diplomatic Status
* Professional Qualifications
* Background Verification

---

## Legal Entity

Legal entity verification uses the **two-axis model** established under `GUOSMM-A-2026-004`:

* **`legalFormCode`** — canonical commercial registry form (103+ international and SHOSJJ-chartered forms)
* **`licenseClass`** — SHOSJJ authorization scope (see Section II)

Legacy KYB subject types remain valid aliases; the authoritative enumeration is [`shosjj-commercial-registry-legal-forms.v1.json`](../../config/governance/shosjj-commercial-registry-legal-forms.v1.json).

Includes (non-exhaustive):

* Corporation, LLC, Series LLC, PLLC, Foundation, Association
* Bank, Trust, EMI, VASP, DAO
* Government, Ministry, Embassy, Diplomatic Mission
* SHOSJJ chartered forms (SCC, SBI, SFI, DCM, INTL-CO, LPBC, …)
* University and other institutional forms

Verification shall include:

* Legal existence
* Registration
* Charter
* Authorized representatives
* Ownership
* Beneficial ownership (where applicable)
* Regulatory standing

---

# V. Core Licensing Requirements

Every application shall include:

## Identity Verification

**Person**

* Passport
* National ID
* Biometric verification
* Photo

**Entity**

* Articles
* Charter
* Certificate
* Registry verification
* Authorized officer verification

---

## Eligibility

Requirements defined per license.

Examples:

* Education
* Experience
* Certification
* Professional memberships
* Training
* Insurance
* Good standing
* Continuing education

---

## Background Investigation

Configurable by license.

May include:

* Identity
* Criminal history (where legally appropriate)
* Professional discipline
* Financial standing
* Sanctions screening
* PEP screening
* Reference verification
* Employment verification

---

# VI. Licensing Workflow

```
Application

↓

Document Collection

↓

Identity Verification

↓

Eligibility Review

↓

Compliance Review

↓

Background Investigation

↓

Technical Review

↓

Committee Recommendation

↓

Licensing Decision

↓

License Generation

↓

Digital Signing

↓

Publication

↓

Renewal Monitoring
```

---

# VII. Decision Authority

Possible outcomes:

* Approved
* Approved with Conditions
* Deferred
* Additional Information Required
* Denied
* Revoked
* Suspended
* Expired
* Cancelled
* Appealed

---

# VIII. License Record

Each issued license shall contain:

* License Number
* UUID
* License Class
* License Level
* License Status
* Issue Date
* Effective Date
* Expiration Date
* Renewal Date
* Authority
* Digital Signature
* Public Key
* QR Code
* Verification URL
* Cryptographic Hash
* Blockchain Registration (optional)

---

# IX. Digital Credentials

Every issued license shall support:

* Digital License
* PDF Certificate
* Printable Certificate
* Mobile Wallet
* Digital Badge
* NFC
* Smart Card
* PKI Certificate
* Verifiable Credential (W3C)
* DID Integration

---

# X. Entity Licensing Requirements

Entity licenses additionally require:

* Registered Name
* Trading Names
* Registration Number
* Jurisdiction
* Registered Address
* Operating Address
* Tax Identification
* Regulatory Numbers
* Directors
* Officers
* Beneficial Owners
* Authorized Representatives
* Risk Rating
* License Scope
* Insurance
* Capital Requirements (if applicable)

---

# XI. Person Licensing Requirements

Natural persons require:

* Full Legal Name
* Aliases
* Date of Birth
* Nationality
* Citizenship
* Residential Address
* Professional Address
* Email
* Telephone
* Emergency Contact
* Professional History
* Education
* Certifications
* Training
* Languages
* Professional Memberships
* Photograph
* Signature
* Biometrics (optional)

---

# XII. Compliance Layer

The licensing engine shall integrate:

* AML
* KYC
* KYB
* Sanctions
* PEP
* OFAC (configurable)
* EU Sanctions
* UN Sanctions
* Internal Watch Lists
* Risk Scoring
* Continuous Monitoring

---

# XIII. Renewal Management

The system shall support:

* Automatic reminders
* Online renewals
* Continuing education tracking
* Insurance verification
* Annual declarations
* Fee management (if applicable)
* Grace periods
* Reinstatement

---

# XIV. Enforcement

Authorized actions:

* Suspend
* Restrict
* Revoke
* Fine (if authorized)
* Probation
* Public Notice
* Administrative Hearing
* Appeals

---

# XV. Public Verification

Public verification portal shall expose:

* License Number
* License Holder
* Status
* Issue Date
* Expiration Date
* Scope
* Restrictions
* Issuing Authority
* Verification QR
* Digital Signature Validation

---

# XVI. Audit Requirements

Complete audit trail including:

* Application received
* Documents uploaded
* Verification performed
* Approvals
* Committee votes
* License issuance
* Renewals
* Suspensions
* Revocations
* Appeals
* Digital signatures
* Blockchain events

---

# XVII. Technical Architecture

The licensing platform should be implemented as modular services:

```
Licensing Authority
│
├── Person Licensing Service
├── Entity Licensing Service
├── Identity Service
├── Document Management
├── Verification Engine
├── Workflow Engine
├── Compliance Engine
├── Credential Issuance
├── PKI / Certificate Authority
├── Digital Wallet Integration
├── Registry Service
├── Public Verification Portal
├── Appeals & Enforcement
├── Audit Service
└── Reporting & Analytics
```

Complete Credential implements this architecture through `cc-workflow-orchestrator`, `cc-credential-registry`, `cc-entity-portal`, and related platform services.

---

# XVIII. Extensibility

The framework shall allow authorized administrators to define, without code changes:

* New license classes and subclasses.
* Custom eligibility criteria.
* Jurisdiction-specific requirements.
* Required document sets.
* Approval workflows.
* Renewal periods.
* Continuing education requirements.
* Risk models.
* Digital credential formats.
* Fee schedules (where applicable).
* Integration with external registries, identity providers, and regulatory systems.

This architecture provides a scalable foundation capable of supporting licensing across professional, financial, diplomatic, judicial, educational, healthcare, security, and commercial domains while maintaining consistent governance, verification, and lifecycle management for both natural persons and legal entities.

---

---

*Signing authority: Sovereign Military Order of Malta*
