EST · MMXXVI
Home/Insights/Disputes/EMI licence for crypto firms: The Compliance Burden in Practice
Licensing & Registration

EMI licence for crypto firms: The Compliance Burden in Practice

Emi licence for crypto firms: The Compliance Burden in Practice. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Ta

An electronic money institution (EMI) licence – the authorisation that permits a firm to issue e-money and execute payment transactions – has become one of the most sought-after entry points for crypto businesses seeking regulated rails in the European Union and beyond. The appeal is clear: an EMI authorisation under the EU's e-money and payment-services directives, combined with the passporting architecture now feeding into MiCA (the Markets in Crypto-Assets Regulation), gives a crypto firm a credible, bank-ready legal wrapper and access to SEPA infrastructure. Yet the compliance burden that arrives with the licence is frequently underestimated at the structuring stage – and underestimating it is costly.

Operating without the right licence exposes a digital-asset business to enforcement action, abrupt debanking and the loss of payment rails at the moment they matter most. This analysis maps the EMI compliance reality for crypto firms: what the regime demands in practice, where it intersects with VASP registration (the separate obligation applying to virtual-asset service providers), how the cross-border dimension changes the calculus, and where firms typically lose ground. We draw on our cross-border practice to identify the structural traps and the decision points that matter before an application is filed.

What an EMI licence actually covers – and what it does not

An EMI licence authorises the issuance of e-money and the provision of payment services; it does not, of itself, authorise the exchange or custody of crypto-assets. That distinction is more consequential than most founders appreciate. A firm holding an EMI authorisation in an EU member state can issue fiat-denominated stored value, process payments and, under the passporting regime, offer those services across the EEA. It cannot rely on the same authorisation to operate a crypto trading desk, provide custody of private keys, or offer staking services – each of which may require a separate regulatory authorisation under MiCA's CASP (Crypto-Asset Service Provider) framework or an equivalent national regime.

The practical consequence is that most serious crypto businesses need a layered authorisation stack. The EMI licence covers the fiat-side of the operation. VASP or CASP registration covers the crypto-side. Where the two intersect – for example, when a firm converts fiat to crypto on behalf of a user – both regimes apply simultaneously. Regulators across the EU, and increasingly in jurisdictions such as the United Kingdom under the FCA's crypto-registration regime, are alert to firms that use an EMI licence as a proxy for broader crypto authorisation. We have seen firms receive supervisory enquiries specifically because the scope of their marketed services exceeded the perimeter of their licence.

For a scoped assessment of your authorisation stack before you file an application, contact OBOLUS at info@oboluslaw.com. The process above describes the standard position. Your facts – the entity structure, the user base geography and the banking arrangements – change the analysis materially. Map your options

What does the compliance programme actually need to cover?

An EMI compliance programme for a crypto firm must address a wider set of obligations than a comparable programme for a pure payments business, because the underlying transaction flows carry a higher financial-crime risk profile in regulators' view. The FATF Recommendations – and specifically Recommendation 15 on virtual assets – sit behind the AML expectations of every EU national competent authority supervising an EMI that touches crypto. That means the programme must cover customer due diligence, transaction monitoring calibrated for on-chain as well as off-chain flows, sanctions screening and, critically, the Travel Rule (the obligation to pass originator and beneficiary data with virtual-asset transfers above the applicable threshold).

The Travel Rule is the single compliance obligation that most consistently catches EMI-licensed crypto firms off guard. A firm operating under an EMI authorisation that also moves virtual assets is within scope of the Travel Rule in every jurisdiction that has implemented the FATF standard. The data-transmission infrastructure required to comply – counterparty identification, message-format compatibility, handling of unhosted wallets – is materially more complex than the standard correspondent-banking message flows the EMI framework was designed around. In our practice, firms that treat the Travel Rule as an IT project rather than a legal and compliance design question routinely produce solutions that satisfy neither the letter nor the spirit of the applicable VASP provisions.

Beyond AML, the compliance programme must address safeguarding. An EMI is required to segregate e-money funds from its own capital, either through ring-fenced accounts at an approved credit institution or through an insurance or guarantee arrangement. For crypto firms operating mixed fiat-and-crypto balance sheets, the boundary between safeguarded e-money funds and own-account crypto holdings is a recurring audit finding. The operational controls that maintain that boundary – daily reconciliation, independent verification, breach escalation – require dedicated resource that is not always budgeted at the licence-application stage.

Cross-border realities: where the EMI passport reaches and where it stops

The EEA passport means that an EMI authorised in one member state – Lithuania and Malta are both active licensing hubs under the Bank of Lithuania and the MFSA respectively – can provide payment services across the EU without a fresh authorisation in each country. That passporting right is valuable. It is also routinely overstated as a solution to the full cross-border challenge facing a crypto business.

First, the passport covers payment services only. MiCA's CASP authorisation, also a passportable licence, covers crypto-asset services. A firm needs both, and the passport for each runs on different regulatory tracks. A CASP authorisation notification to a host-state regulator under MiCA is not the same process as an EMI passport notification under the Payment Services Directive. Running both simultaneously, with different home-state contact points and different notification timelines, is administratively intensive.

Second, the passport does not reach outside the EEA. A crypto firm with EU users and non-EU users – the majority of growth-stage digital-asset businesses – faces a split regulatory obligation. Serving UK users requires separate engagement with the FCA's crypto-registration regime. Serving UAE users may engage VARA's activity-based licensing requirements for Dubai mainland operations. Serving Singapore users may require engagement with MAS under the Payment Services Act. In our cross-border practice, we regularly advise firms that assume their EU licence is effectively a global pass; it is not, and the gap between assumption and reality is where enforcement risk sits.

Third, banking – the practical infrastructure on which an EMI licence depends – does not follow the passport automatically. An EMI licence authorises the business to issue e-money. It does not compel any bank to provide a settlement or safeguarding account. In practice, finding a bank willing to onboard a crypto-facing EMI is a distinct workstream that runs in parallel to the regulatory application, often with a longer lead time. We have seen applications that cleared the regulatory track in reasonable time stall at the banking stage for a material additional period, with significant operational and capital cost consequences for the applicant.

Contrasting positions: EMI vs. CASP vs. VASP – which authorisation fits which business?

The choice between an EMI authorisation, a CASP authorisation under MiCA and a national VASP registration turns on the firm's core business activity, and the answer is rarely a single instrument. Understanding the distinctions in practice is the first step in building a licensing strategy that survives regulatory scrutiny.

An EMI authorisation fits a crypto firm whose primary regulated activity is the movement of fiat value – a crypto on-ramp/off-ramp business, a stablecoin distribution model, or a crypto exchange that settles trades in fiat and needs SEPA access. The crypto-side of those activities will still require CASP or national VASP authorisation in parallel.

A CASP authorisation under MiCA fits an exchange, a custodian, a portfolio manager of crypto-assets or an operator of a trading platform where the core regulated activity is the crypto-asset service itself. Where the firm also issues e-money, it will need the EMI layer in addition.

A national VASP registration – available in jurisdictions such as the BVI under the VASP Act 2022 or the Cayman Islands under CIMA's virtual-asset regime – fits a firm that wants a more lightweight compliance posture, typically for a holding-company or fund-structure layer rather than a client-facing exchange. The trade-off is that a BVI or Cayman VASP registration does not give EU passporting rights and will not satisfy the onboarding requirements of most European institutional counterparties.

For a firm sitting between an EU operating entity and an offshore holding structure, the legal question turns on where the regulated activity actually occurs and where the clients are. In our practice, the most resilient structures allocate the EMI authorisation to the EU payment-facing entity, the CASP authorisation to the EU crypto-services entity (which may be the same entity), and the offshore VASP registration to the group treasury or fund layer. The compliance programme is then designed to cover all three simultaneously, with clear governance lines between the layers.

The application process in practice: where firms lose ground

An EMI application is not a form-filling exercise. The national competent authority – whether that is the Bank of Lithuania, the MFSA, or the FCA for a UK registration – is evaluating the substance of the compliance programme, the fitness and propriety of the management team, the adequacy of the capital plan and the credibility of the business model. For a crypto-facing EMI, the regulator is also evaluating whether the applicant understands the specific risks that crypto transaction flows introduce into a payments business.

The most common failure point in the applications we have reviewed is the AML/CFT framework. Regulators routinely reject or suspend review of applications where the AML programme is drafted at a generic level without demonstrating how it addresses crypto-specific risks: on-chain transaction monitoring, blockchain analytics integration, handling of peer-to-peer wallet transfers, and the Travel Rule data pipeline. A programme that mirrors a standard payments-firm template without adaptation to crypto is identified at the document-review stage and generates a remediation request that can add significant time to the process.

The second common failure point is the management information systems (MIS) and record-keeping architecture. An EMI is required to produce regulatory reports to its home-state authority on a defined schedule. For a crypto-facing EMI, those reports must integrate data from on-chain and off-chain sources. Firms that have not built the reporting infrastructure before the application is reviewed – or that describe it as future-state in their application – encounter additional scrutiny.

Timeline is, per the Verified Facts Registry, a figure that varies by jurisdiction and licence category; we write it qualitatively. Authorisation timelines at leading EU hubs range from a matter of weeks at the fast end of a straightforward application to well over a year for complex or remediated files. In our cross-border practice, the firms that move fastest share a common characteristic: they resolve the banking question in parallel, not sequentially.

If a prior EMI application stalled or a banking account was closed, a structural review can surface the reason and the route forward. Write to info@oboluslaw.com or map your options here.

Micro-matter: the stablecoin payments firm that needed more than one licence

In a recent cross-border structuring matter, a payments company holding an EMI authorisation in an EU member state began distributing a third-party stablecoin to corporate clients across the EEA. The firm had correctly identified that its fiat payment flows were covered by its existing authorisation. It had not assessed whether distributing the stablecoin – an asset-referenced token (ART) or e-money token (EMT) under MiCA's categorisation – required separate CASP authorisation as a crypto-asset service. When a counterparty bank conducted its own regulatory due-diligence review, the gap was identified. We were instructed to map the correct authorisation perimeter, engage with the home-state authority on the scope question and restructure the distribution model to sit within the firm's existing permissions while a CASP application was prepared. The matter was resolved in a single quarter, without enforcement action, because the firm acted on the issue before the regulator raised it formally.

Decision matrix: which licensing profile fits your business?

Profile A – A crypto on-ramp/off-ramp operator with EU retail users, SEPA settlement requirement and no proprietary trading. Primary instrument: EMI authorisation (covering fiat issuance and payment services) plus CASP authorisation for the crypto conversion activity. Indicative timeline: varies materially by member state; the banking track typically runs longer than the regulatory track. Key risk: scope creep beyond the licensed perimeter as the product evolves.

Profile B – A crypto exchange serving both EU and non-EU institutional clients, holding custody of client assets. Primary instruments: CASP authorisation in the EU for exchange and custody services; EMI authorisation if the firm also issues stored value; VASP registration in the relevant offshore holding-company jurisdiction. Indicative timeline: longer than Profile A; the custody element of the CASP application adds compliance documentation. Key risk: the cross-border user base triggers multiple regulatory regimes simultaneously.

Profile C – A DeFi protocol operator seeking a light-touch regulated wrapper for a treasury entity. Primary instrument: VASP registration in the BVI or Cayman Islands. Caution: this does not satisfy EU or UK licensing requirements if the protocol has EU or UK users. Key risk: assuming the offshore registration is a sufficient answer to the full regulatory exposure.

Profile D – A stablecoin issuer targeting EU institutional distribution. Primary instrument: CASP authorisation plus, if the stablecoin qualifies as an EMT under MiCA, an EMT issuer authorisation in addition. This is the most demanding profile: it combines payments regulation, e-money regulation and MiCA's asset-token regime. Key risk: the reserve and redemption requirements are operationally intensive; failing to budget for the ongoing compliance cost before launch.

A common assumption: the offshore licence covers everything

A common assumption among early-stage crypto founders is that a single offshore VASP registration – whether in the BVI, Cayman Islands or another established jurisdiction – is sufficient to operate a global crypto business without further regulatory engagement. That assumption is incorrect, and acting on it is one of the primary drivers of the enforcement cases and banking closures we see in practice.

An offshore VASP registration addresses the licensing requirement of the offshore jurisdiction. It does not address the licensing requirements of the jurisdictions where the firm's clients are located, where its staff operate, or where its servers process transactions. Under the regulatory approach adopted by the EU under MiCA, by the FCA in the UK, by MAS in Singapore and by the SFC in Hong Kong, a firm offering crypto-asset services to users in those jurisdictions is subject to the local regime regardless of where the operating entity is incorporated. The concept of regulatory nexus – the set of connections that bring a firm within a regulator's scope – is defined by client location, marketing activity and, in some regimes, technical access, not by corporate seat alone.

In our cross-border practice, we regularly encounter firms that have incurred material legal exposure by marketing to EU or UK clients under the assumption that their offshore structure insulated them from EU or UK regulation. The corrective workstream – restructuring the entity, applying for the correct authorisations and addressing the historic compliance gap – is significantly more expensive than building the right structure from the outset.

Self-assessment: before you file an EMI application

Before committing to an EMI application for a crypto-facing business, a general counsel or founder should be able to answer the following questions with documented, substantiated answers. A gap in any of them is likely to surface during regulatory review.

First: what regulated activities does the firm intend to carry out, and does the EMI authorisation cover all of them? If crypto-asset services are in scope, is a parallel CASP or national VASP registration identified and in preparation?

Second: has the AML/CFT programme been designed specifically for crypto transaction flows, including on-chain monitoring, Travel Rule compliance and blockchain analytics integration? A generic payments-firm programme will not pass regulatory review for a crypto-facing EMI.

Third: is the safeguarding architecture documented, with clear operational controls distinguishing e-money funds from own-account crypto holdings? Has the daily reconciliation process been built and tested?

Fourth: is the banking track running in parallel? Has the firm identified a prospective settlement bank and safeguarding bank, engaged in preliminary conversations, and received at least an expression of interest? A regulatory authorisation without a bank willing to provide services has limited practical value.

Fifth: does the compliance programme address the firm's cross-border user base? If clients are located outside the EEA, has the firm identified the regulatory obligations in each material user jurisdiction and either obtained the relevant authorisation or restricted access in a documented, defensible way?

Sixth: is the management team's regulatory experience documented in a way that satisfies the home-state regulator's fit-and-proper assessment? For crypto-facing businesses, regulators increasingly scrutinise whether senior managers have experience of the specific compliance risks that on-chain transaction flows introduce.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Authorisation timelines vary significantly by jurisdiction, licence category and the completeness of the application. At well-resourced EU hubs, a straightforward application from a well-prepared firm can move through review in a matter of weeks. Complex applications, those requiring remediation or those involving novel business models can take considerably longer – in some cases well over a year. The banking track, which runs in parallel, often determines the practical go-live date more than the regulatory clock. Preparing a complete, regulator-ready file before submission is the single most effective way to compress the timeline.

Which jurisdiction is best for licensing my crypto business?

There is no universally correct answer. The right jurisdiction depends on the firm's target user base, its banking arrangements, its operational footprint and the specific services it intends to offer. An EU hub with passporting rights suits a firm targeting European clients. A jurisdiction such as the ADGM or AIFC suits a firm whose primary market is the Gulf or Central Asia. Singapore under the MAS Payment Services Act suits a firm focused on South-East Asian institutional clients. The starting point is always the services offered and the clients served – not the jurisdiction that appears simplest or cheapest on the surface.

Do I need a separate custody licence?

In most flagship regimes, custody of digital assets is a regulated activity requiring its own authorisation or a specific permission within a broader licence. Under MiCA, custody and administration of crypto-assets is one of the named CASP services requiring authorisation. Under the SFC regime in Hong Kong and the MAS regime in Singapore, custody activities carry distinct licensing conditions. An EMI licence does not cover crypto custody. A firm that holds client private keys or controls client assets on behalf of users must assess whether its existing authorisations extend to that activity before it commences custody operations.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence, banking and tax stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Glen Sorensen, Disputes & Recovery Analyst – specialist in cross-border enforcement risk, licensing compliance gaps and the intersection of payment regulation with digital-asset service obligations.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours