The Board Question Nobody Asks Early Enough
An Electronic Money Institution (EMI) licence – an authorisation to issue electronic money and provide payment services – has become one of the most sought-after regulatory instruments in the digital-asset industry. Crypto exchanges, custodians and stablecoin platforms all reach for it at some point, usually because a banking partner demands it, a regulator flags its absence, or a payment rail simply closes. Boards that encounter the question for the first time after one of those events face the hardest version of it.
An EMI licence is not a universal crypto permit. It authorises the issuance of electronic money and the provision of regulated payment services; it does not, on its own, authorise the operation of a crypto exchange, the custody of digital assets, or the public offering of tokens. A crypto firm that holds an EMI licence may still require a separate VASP registration (virtual asset service provider registration under applicable AML frameworks), a CASP authorisation under MiCA (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities), or activity-specific permissions under the regime of each jurisdiction in which its users sit. Understanding this layering is the first practical lesson a board must absorb.
This analysis maps the EMI licensing path for crypto businesses, contrasts the leading jurisdictions, and sets out the structural lessons that separate successful applications from withdrawn ones.
What Does an EMI Licence Actually Authorise?
An EMI licence authorises a regulated entity to issue electronic money – a digital store of monetary value redeemable at par – and to provide a defined list of payment services, which commonly include the execution of payment transactions, account information services, and money remittance. It does not authorise the business to provide investment services, operate a trading venue, or offer leveraged products.
For a crypto firm, the EMI licence typically serves three purposes. First, it allows the firm to hold client fiat balances in a compliant structure, replacing the fragile correspondent-banking relationships that many crypto businesses rely on informally. Second, it provides a payment-service permission that allows the firm to move fiat into and out of digital-asset positions – the on-ramp and off-ramp problem that kills more crypto businesses than regulatory enforcement. Third, in several EU member states, an EMI authorisation granted under the EU's Second Payment Services Directive framework has historically provided a form of passportable credential, allowing the firm to offer payment services across the EU/EEA once authorised in its home state.
The important boundary: an EMI licence under the PSD2 framework and a CASP authorisation under MiCA are distinct regulatory instruments. A business that issues an e-money token – a token that stores monetary value and is redeemable against fiat – will, under MiCA, require authorisation as an EMT issuer, which sits within the MiCA regime and carries its own capital, reserve and governance requirements. That authorisation is separate from, though often layered with, a legacy EMI licence.
MiCA's EMT framework introduces a meaningful compliance lift for any crypto firm that issues a fiat-pegged stablecoin or e-money token to EU-resident users. The issuer must be authorised as a credit institution or as an EMI under the applicable domestic EMI transposition, and it must comply with MiCA's additional reserve, redemption and disclosure obligations. Boards should treat the two regimes as related but distinct tracks, not as one path with a shortcut.
Which Jurisdictions Grant EMI Licences to Crypto Firms?
The most practical EMI licensing jurisdictions for crypto-adjacent businesses are found across the EU/EEA, with Lithuania and Malta representing the two most commonly discussed entry points, alongside the United Kingdom under the FCA's e-money institution registration.
Lithuania built its reputation as a rapid EU entry point for fintech and crypto businesses seeking EMI authorisation. The Bank of Lithuania supervises both EMI authorisations and VASP registrations. Under the pre-MiCA regime, Lithuania was a popular choice precisely because the single-regulator relationship simplified the combined licensing stack. The MiCA transition has changed the calculus: a Lithuanian CASP authorisation under MiCA now carries EU-wide passporting rights, but the application standards are materially higher than the historic VASP registration process. Businesses that hold a legacy Lithuanian VASP registration and now wish to add EMI permissions – or vice versa – face a sequencing decision about which authorisation to pursue first.
In our practice, we have seen applicants miscalculate by filing an EMI application before their AML/KYC programme reaches the standard the Bank of Lithuania expects. The regulator reviews the entire compliance architecture, not just the payment services components. A crypto firm with a complex transaction-monitoring challenge – because its product mixes fiat payments and digital-asset transfers – must demonstrate that its monitoring covers both rails before the application advances.
Malta's MFSA supervises both the transitioning VFA (Virtual Financial Assets) framework and EMI authorisations. The VFA framework is in transition to MiCA's CASP regime, and the MFSA has been explicit that legacy-licensed entities must comply with MiCA timelines. An EMI licence from the MFSA carries EU passporting, but the MFSA's application process is detailed and the regulator applies a close-assessment approach to governance and AML.
The FCA in the United Kingdom operates an e-money institution authorisation separate from its cryptoasset MLR (Money Laundering Regulations) registration regime. Post-Brexit, FCA EMI authorisation no longer carries EU passporting rights, but for businesses serving UK users or operating UK-facing payment rails, the FCA authorisation is the required instrument. The FCA has also applied its financial promotion rules to crypto marketing, meaning that a UK-authorised EMI operating in the crypto space must manage promotion compliance as a concurrent obligation.
Beyond the EU/EEA and UK, crypto firms operating in the DIFC or the ADGM in Abu Dhabi will encounter payment-related permissions within those frameworks – the FSRA within the ADGM regulates payment services for virtual assets as part of its broader virtual asset regime. These are not "EMI licences" in the European sense, but they perform analogous functions within their jurisdictions.
Your entity structure, your user base and your banking relationships each change the licensing analysis materially. The standard path described here applies to the median applicant. A business that mixes stablecoin issuance, fiat payments and exchange services across multiple jurisdictions will face a multi-layer application strategy, not a single filing. For a scoped assessment of your specific position, contact OBOLUS at info@oboluslaw.com.
What Makes a Crypto EMI Application Fail?
Most EMI applications from crypto-sector businesses fail – or are withdrawn before a formal decision – for one of four structural reasons, and none of them is the complexity of the technology.
The first reason is AML/CFT programme immaturity. Regulators applying the FATF Recommendations – including Recommendation 15 on virtual assets and the Travel Rule (the obligation to transmit originator and beneficiary data with a transfer) – expect a crypto firm's AML programme to address the specific risks of digital-asset transfers, not just the generic risks of a payment institution. An applicant that submits a compliance manual designed for a traditional remittance business, without addressing on-chain transaction monitoring, VASP counterparty due diligence and Travel Rule compliance, will face a fundamental objection at the application stage.
The second reason is governance fragility. EMI regulators across the EU/EEA require the applicant to demonstrate fit-and-proper leadership with documented experience in financial services compliance. A founding team built entirely from technology and trading backgrounds – without a credentialed compliance or regulatory function at board or senior management level – creates an immediate weakness. Several regulators now require the appointment of a qualified Money Laundering Reporting Officer and a Compliance Officer before the application is filed, not as conditions of approval.
The third reason is the absence of a credible business plan. An EMI application in the crypto context must explain precisely which activities will generate fiat flows, what the expected transaction volumes are, how the firm will manage settlement risk, and why the licence is necessary for the stated business model. Applications that present overly optimistic projections without stress-testing, or that describe the product in vague terms to avoid difficult questions, attract prolonged information requests.
The fourth reason – the one boards most often miss – is the failure to address the regulatory perimeter of the crypto activity alongside the EMI application. A regulator reviewing an EMI application from a crypto exchange will ask whether the exchange activity itself is licensed or registered. If the answer is "not yet" or "we believe it falls outside the regime", the EMI application effectively funds a regulatory inquiry into the entire business. In our practice, we consistently advise that the full activity map must be settled before any single-licence application is filed.
The Cross-Border Reality: Entity, Users, Banking
A crypto firm's regulatory position is defined by three co-ordinates: where the regulated entity sits, where its users are located, and where its banking and payment infrastructure is domiciled. These three co-ordinates rarely align perfectly, and the gap between them is where enforcement risk concentrates.
Consider a business that holds a Lithuanian EMI authorisation, operates a crypto exchange from the same entity, and serves users across the EU/EEA. That business benefits from EU passporting for its EMI activities, but under MiCA it will require a CASP authorisation for the exchange activity. The MiCA passporting right for CASP authorisation operates separately from the PSD2 passporting right for EMI activity. The board cannot assume that a single authorisation covers both rails.
The banking dimension adds a further layer. An EMI authorisation allows the firm to hold client funds in segregated accounts, but it does not guarantee access to a correspondent banking relationship, access to SEPA settlement, or the ability to maintain a payment account with a systemically important bank. Many crypto firms discover that their EMI authorisation, while genuine, fails to unlock the banking relationships they expected because the correspondent banks apply their own risk appetite to crypto-sector clients independently of regulatory status.
In cross-border structures we regularly advise on, the firm holds an EMI authorisation in one EU member state for fiat-payment and client-funds purposes, a VASP registration or CASP authorisation in the same or a different member state for crypto-asset services, and – for operations in the Gulf or Asia – separate local permissions in those jurisdictions. Allied counsel in each relevant jurisdiction support the local filings, but the architecture of the group is designed at the outset to minimise regulatory friction between layers.
For businesses entering the VARA environment in Dubai, the equivalent of EMI-type payment permissions sits within the VARA activity-based licence framework. A firm operating a crypto exchange under VARA's exchange licence and also providing fiat payment services must ensure the correct activity licence covers the payment component; VARA's rulebooks address transfer and settlement services as a distinct licensed activity.
Decision Matrix: Which Profile Needs Which Instrument?
Different operator profiles require different primary instruments, and the right sequencing varies materially by the firm's activity mix, user base and growth horizon.
Profile A – Crypto exchange with fiat on/off ramp: The primary regulatory need is usually a crypto-activity permission first (CASP under MiCA, or VASP registration under the applicable regime), with an EMI authorisation layered on top to enable direct fiat account management. Pursuing the EMI licence first can expose the full crypto activity to regulatory scrutiny before the crypto permissions are in place. Indicative sequencing: VASP/CASP first, then EMI; total elapsed time varies by jurisdiction and application quality but is typically measured in multiple months rather than weeks.
Profile B – Stablecoin or e-money token issuer targeting EU users: MiCA's EMT issuer regime requires authorisation as an EMI (or as a credit institution) under applicable domestic law. The MiCA authorisation and the domestic EMI authorisation are, in practice, co-filed or sequenced very closely. The compliance lift is significant: reserve management, redemption rights, disclosure and governance requirements apply from the date of authorisation. The key risk here is underestimating the reserve and liquidity management obligations that sit alongside the issuance permission.
Profile C – Payment service provider moving into crypto custody: This firm typically already holds an EMI authorisation and is adding a custody function. The custody of digital assets is a regulated activity in most flagship regimes. In the EU, MiCA creates a specific custody and administration service that requires CASP authorisation, separate from the existing EMI permissions. The firm should not assume that its existing compliance infrastructure is adequate for the crypto custody layer without a specific gap analysis.
Profile D – Early-stage crypto startup seeking a "licence-ready" structure: The most common mistake here is filing for an EMI licence without a clear view of whether the business model actually requires one. Many early-stage crypto businesses do not issue electronic money; they facilitate digital-asset transfers. A VASP registration or a limited payment service permission may be the more appropriate and faster instrument. Filing the wrong application wastes time and capital and may alert a regulator to activities that a better-prepared applicant would address in a structured programme.
A Micro-Matter: Sequencing That Prevented Enforcement
In a recent licensing matter, an early-stage exchange operator with an existing EU VASP registration approached us after its primary banking partner suspended its account without notice. The exchange was processing fiat settlement through the banking relationship without an EMI authorisation, relying on a payment aggregator that had quietly withdrawn its sub-licence arrangement. We mapped the full activity perimeter, identified that the exchange's fiat operations had migrated from the aggregator model into direct client-fund holding – a regulated EMI activity – and advised an immediate restructure ahead of any application filing. A parallel VASP-to-CASP transition plan was developed to address the incoming MiCA requirements. The EMI application was filed with a governance remediation package, and the banking relationship was restored through an alternative EU-authorised partner during the application period. The business avoided an enforcement inquiry by addressing the regulatory gap before it was externally identified.
A Common Assumption: "A Single Offshore Licence Covers Our Global User Base"
One of the most persistent misconceptions we encounter in the early stages of a board engagement is the belief that a single licence – often an offshore VASP registration in a jurisdiction with a favourable regulatory environment – is sufficient to service users globally. It is not.
Regulatory reach follows the user, not the entity. A business that holds a Cayman VASP registration under CIMA's Virtual Asset (Service Providers) Act and actively markets to EU-resident users is subject to MiCA's CASP requirements for those users, irrespective of where the operating entity is incorporated. A business that solicits US users into a crypto exchange, regardless of entity domicile, faces the risk of SEC, CFTC and FinCEN scrutiny under US federal frameworks, as well as state money-transmitter licensing obligations in the states where users reside. The NYDFS BitLicense regime applies to activity with New York residents, not to entities physically located in New York.
The offshore licence is not worthless. A BVI FSC registration under the VASP Act 2022 or a Cayman CIMA registration serves a real function: it establishes a regulated baseline, satisfies banking diligence for institutional counterparties, and provides a credible regulatory footprint for operations genuinely focused on the relevant jurisdiction. The error is treating it as a substitute for the jurisdictional permissions that the firm's actual user distribution requires.
Boards that receive advice to the effect that "one licence is enough" should ask a single follow-up question: in which specific jurisdictions are your users located, and is that licence recognised in each of those jurisdictions as authorising the specific activity you are conducting? The answer almost always reveals a gap.
The AML and Travel Rule Layer Across EMI and Crypto Perimeters
Any business that holds both an EMI authorisation and a crypto-activity permission must manage a dual AML/CFT perimeter, and the two layers carry different technical requirements that must be integrated into a single programme.
The EMI AML layer requires transaction monitoring for payment flows, customer due diligence, and suspicious-transaction reporting under the applicable domestic AML transposition of the FATF Recommendations. The crypto layer adds on-chain transaction monitoring, counterparty VASP due diligence, and – critically – Travel Rule compliance for virtual-asset transfers. The Travel Rule requires that originator and beneficiary information travels with a virtual-asset transfer above the applicable threshold, which varies by jurisdiction. Regulators increasingly assess whether the firm's Travel Rule solution covers both fiat-side and crypto-side flows, and whether the two monitoring systems share data sufficiently to identify suspicious patterns that span both rails.
In our practice, we have seen combined EMI and VASP-licensed businesses pass initial AML assessments on each licence in isolation, then face material findings in a combined supervisory review because the monitoring systems were not integrated. The regulator's concern was not that either system was inadequate in isolation; it was that a customer could move value between the fiat and crypto rails in a way that fragmented the suspicious-pattern signal. Building an integrated monitoring architecture from the outset is materially less expensive than retrofitting it under supervisory pressure.
When to Engage Counsel and What That Engagement Looks Like
The right moment to engage counsel on an EMI licensing question is before the business plan is finalised, not after the bank account is closed. The activity map – a precise specification of which regulated activities the firm conducts, in which jurisdictions, and for which user categories – determines both the correct licensing instruments and the sequencing of applications. That map cannot be built retrospectively without accepting the risk that the current structure is already operating in a gap.
A licensing engagement at OBOLUS begins with a structured activity and jurisdiction analysis. We identify the full perimeter of regulated activity across the entity's operating model, match each activity to the applicable regulatory instrument in each relevant jurisdiction, and produce a licensing roadmap that sequences applications to minimise the period during which any regulated activity is uncovered. We map the licence, banking and tax stack together, because the banking relationship is usually the critical path – an EMI application filed without a confirmed banking partner for the segregated client-funds account is an application that cannot complete.
We also address the cross-border interaction between the EMI licensing layer and the concurrent VASP or CASP obligations. Where a client's structure requires local filings in jurisdictions outside our direct practice, we work with allied counsel in the relevant jurisdiction, coordinating the position across the group to prevent gaps or contradictions between local applications.
If a prior application stalled, an account was closed, or a regulatory inquiry has already begun, a second read of the structure often surfaces the root cause. The process of correction – whether through regulatory engagement, restructuring or a fresh application – is almost always faster when the structural reason for the problem is properly identified first. To map your position, contact OBOLUS at info@oboluslaw.com.
Related at OBOLUS
- Licensing and Registration for Digital Asset Businesses – the full scope of OBOLUS licensing practice across 70+ jurisdictions
- VASP Licensing in the Czech Republic – a practical jurisdiction guide for operators entering the Central European market
- EMI Licence for Crypto Firms: Early-Stage Founders – a targeted guide for founders at the pre-application stage
FAQ
How long does a crypto licence take to obtain?
Timelines vary materially by jurisdiction and licence type. In leading EU member states, a CASP authorisation under MiCA or an EMI authorisation typically takes several months from a complete filing; some regulators have statutory timelines, but pre-application preparation – governance, AML programme, business plan – often takes longer than the formal review. Offshore registrations in BVI or the Cayman Islands can be faster for registration-track processes, but they do not substitute for the jurisdictional permissions required where users are located.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The right choice turns on the activity mix, the user base, the banking strategy and the growth horizon. Lithuania and Malta offer EU passporting under MiCA for CASP activities; Dubai's VARA regime suits firms focused on the Gulf and emerging markets; Singapore's MAS Payment Services Act regime serves Asia-Pacific-focused operators. A business serving a genuinely global user base will typically require multiple jurisdictional permissions, not one licence. We map the full stack before advising on sequencing.
Do I need a separate custody licence?
In most flagship regimes, yes. Custody of digital assets is a regulated activity in its own right, distinct from exchange, payment or advisory services. Under MiCA, the custody and administration of crypto-assets for third parties is a specific CASP service category requiring authorisation. An EMI licence does not cover crypto custody. An exchange licence does not automatically cover custody either, though some regime structures bundle them. Any firm holding client digital assets should conduct a specific perimeter analysis to confirm the required authorisation.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – preventing the structural gaps that lead to enforcement, frozen rails and lost banking. We also work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where recovery matters intersect with licensing failures. To discuss your situation, contact info@oboluslaw.com.
By Glen Sorensen, Disputes & Recovery Analyst – specialist in regulatory licensing strategy, enforcement risk and cross-border asset recovery for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.