An electronic money institution (EMI) is a regulated entity authorised to issue electronic money – stored monetary value represented as a claim on the issuer – and to provide payment services within the scope of its licence. For digital-asset businesses, the EMI is not a peripheral concept. It is the legal gateway to fiat rails: the mechanism by which a crypto exchange, custodian or token-issuing platform holds client funds, moves money across borders and connects to the banking system at all. Without access to an EMI relationship – whether held in-house or through a third-party provider – a digital-asset operation is commercially stranded. This guide explains what an EMI is, how the regulated perimeter works across the leading regimes, why banks close crypto accounts and how to build a payment architecture that holds.
What Is an Electronic Money Institution, and Why Does It Matter for Crypto?
An EMI is a non-bank payment institution licensed to issue e-money (a digital store of fiat value) and to execute payment transactions on behalf of clients. The EMI sits between a commercial bank and an unregulated fintech: it can hold client funds as e-money balances, execute transfers and provide IBAN-like account structures, but it cannot lend money or take deposits in the traditional banking sense. For a digital-asset business, the EMI is the legal vehicle that converts fiat into the exchange and back again – the on-ramp and off-ramp infrastructure that underpins every crypto-to-fiat trade.
The regulated basis for EMIs in the European Union derives from the Electronic Money Directive (EMD2) and the Payment Services Directive (PSD2), implemented by national competent authorities across member states. The UK maintains a parallel regime administered by the FCA (Financial Conduct Authority) under the Electronic Money Regulations. Other jurisdictions – Singapore under MAS, the UAE under VARA and the ADGM/FSRA, and offshore centres including the Cayman Islands under CIMA – each have analogous frameworks that permit the issuance of fiat-denominated stored value or the provision of payment services to digital-asset clients. The precise licence category varies by jurisdiction; the commercial need is the same everywhere.
In our practice, the question is rarely whether a digital-asset business needs access to an EMI. The question is whether it needs its own EMI licence, whether it can rely on a third-party EMI relationship, and how to structure that arrangement to survive regulatory scrutiny in multiple markets simultaneously.
The process above describes the standard path. Your facts – the entity structure, the user base, the banking counterparty – change the analysis. For a scoped assessment of your payment architecture, contact OBOLUS at info@oboluslaw.com.
How Does EMI Licensing Work Across the Major Regimes?
EMI authorisation is a formal licensing process administered by the national regulator, requiring the applicant to demonstrate adequate capital, governance, AML/CFT controls and a credible business plan. The capital requirement is not uniform – it varies by licence class, by jurisdiction and by the scope of activities the applicant intends to carry out – and no specific figure can be stated without reference to current legislation. What is consistent across the leading regimes is the structure of the analysis.
In the EU under the EMD2/PSD2 framework, an authorised EMI benefits from passporting rights: a licence granted in one member state allows the institution to provide services across the entire EU and EEA without a separate local authorisation in each country. This makes EU EMI licences strategically valuable for digital-asset businesses with a pan-European client base. Lithuania and Malta have historically been entry points within the EU for crypto-adjacent payment businesses, though both are now transitioning their VASP-layer regulation to align with MiCA (Markets in Crypto-Assets Regulation) under ESMA oversight. An EU-authorised EMI operating alongside a MiCA CASP (Crypto-Asset Service Provider) authorisation is the emerging standard architecture for a compliant European digital-asset business.
In the UK under the FCA, EMI authorisation sits alongside cryptoasset registration under the Money Laundering Regulations. A business seeking to provide both payment services and crypto exchange functionality in the UK will often need to satisfy two separate regulatory tracks. The FCA's published data on cryptoasset registration refusals has been widely reported, and the practical difficulty of obtaining clean banking for a crypto business in the UK market is a recurring problem we see in our practice.
In Singapore under MAS, the Payment Services Act creates a tiered structure of payment institution licences. A digital-asset business providing digital payment token (DPT) services alongside fiat money services will typically need to address multiple activity categories within a single application or through a group structure. The MAS framework is explicit that DPT services and e-money issuance are distinct regulated activities.
In the UAE, the VARA regime in Dubai and the FSRA regime within ADGM each address payment and money-transmission activities within their respective perimeters. A business operating in both zones – or structured with a holding entity in one free zone and operations in another – needs a clear analysis of which regulatory perimeter captures which activity.
Why Do Banks and EMIs Refuse or Close Crypto Accounts?
Banks and EMIs refuse or terminate accounts for digital-asset businesses primarily because of unresolved AML/CFT risk, correspondent bank pressure, and the cost of monitoring obligations relative to revenue. This is the most common operational crisis we see: a business that has built its product, obtained a VASP registration or crypto licence, and then cannot open or maintain a bank or EMI account. Without fiat rails, the product is commercially inoperable.
The mechanics of de-banking in this sector follow a recognisable pattern. The account-holding institution receives a compliance flag – either from its own transaction monitoring, from a correspondent bank declining to settle transactions, or from an internal risk-appetite review. The flag triggers an enhanced due-diligence request. The business fails to satisfy the request, either because its documentation is insufficient or because the institution has a blanket risk policy. The account is closed with little explanation.
Several structural factors drive this pattern. First, the FATF Travel Rule (the obligation, under FATF Recommendation 15, to pass originator and beneficiary information with virtual asset transfers) imposes monitoring obligations on both the VASP and its banking counterparty. If the VASP cannot demonstrate compliant Travel Rule implementation, the bank's own exposure grows. Second, correspondent banking risk cascades downward: a global correspondent that refuses to settle crypto-related transactions forces its downstream respondent banks to mirror that policy, regardless of the respondent's own assessment. Third, many digital-asset businesses present to banks with incomplete or structurally opaque documentation – mixed personal and business flows, unclear source-of-funds, or a complex group structure that the bank cannot quickly map.
In a recent EMI onboarding matter, a token-issuing company with a valid EU VASP registration had its account closed following a correspondent-bank policy change at its EMI. We assisted in restructuring the entity's compliance documentation and introducing the client to allied counsel in the relevant jurisdiction for a fresh application with an EMI that had pre-cleared the asset class. The account was opened within a matter of weeks, and the business resumed operations without a licence-level change.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. To discuss the specific facts, write to OBOLUS at info@oboluslaw.com.
How Does a VASP Successfully Onboard with an EMI?
Successful EMI onboarding for a digital-asset business requires the VASP to present itself as a regulated, documentable and low-effort client from the first outreach. EMIs assess crypto clients against the same risk-appetite criteria they apply to any other high-risk category: AML programme quality, source-of-funds clarity, transaction volume predictability and the robustness of the VASP's own regulatory status. Businesses that approach EMIs with a deck and a bank introduction letter, without a structured compliance package, are turned away at a high rate.
The documentation package that consistently succeeds includes: a current VASP registration or licence certificate with its full scope; a written AML/CFT policy that addresses Travel Rule compliance specifically; a description of the transaction monitoring system in use, with vendor identification where applicable; a corporate structure chart showing all entities, beneficial owners to the required threshold, and the jurisdictional basis for each; a source-of-funds narrative for the initial deposit and ongoing flow; and projected transaction volumes by currency, jurisdiction and counterparty type.
Beyond documentation, counterparty selection matters as much as preparation. Not all EMIs accept crypto clients, and among those that do, the accepted asset classes, transaction structures and jurisdictions vary significantly. Presenting a compliant package to an EMI that has a blanket policy against stablecoin flows, for example, wastes time and generates a rejection that may affect subsequent applications. Mapping EMI counterparties to the specific profile of the business before outreach is the single most time-saving step in the process.
The cross-border dimension adds a further layer. A digital-asset business serving users in multiple jurisdictions may find that a single EU-passported EMI relationship is insufficient – either because certain jurisdictions require local payment institution presence, or because the EMI's own correspondent-bank coverage does not extend to the required currency corridors. In our practice, we have seen businesses that assumed a single EU EMI relationship would cover their entire operating perimeter, only to discover that transfers to or from certain markets were being blocked by the EMI's correspondent network. The architecture needs to be built jurisdiction by jurisdiction, not assumed from the top down.
What Does Client-Money Safeguarding Actually Require?
Client-money safeguarding is the regulatory obligation requiring an EMI to hold client funds in a protected pool – separate from the institution's own funds – such that those funds are available to clients in the event of the EMI's insolvency. For a digital-asset business relying on an EMI for its fiat operations, the safeguarding regime is not a formality. It is the structural protection that determines whether client fiat is recoverable if the EMI fails.
Under the EU EMD2 framework, an authorised EMI must safeguard client funds either by holding them in a segregated account at a credit institution or through an eligible insurance policy or bank guarantee. The specific safeguarding methods and the conditions for their use are set by the implementing national competent authority. National competent authorities within the EU/EEA have discretion over certain implementation details, which means that safeguarding standards are not entirely uniform across member states even within a passported EMI structure.
For a VASP that holds client fiat through an EMI relationship, the key due-diligence question is: where are those funds actually held, and under what safeguarding arrangement? A VASP that relies on an EMI without understanding the safeguarding structure is exposed to a risk that does not appear on its own balance sheet. We have seen situations where a VASP's client fiat was technically held as an unsegregated commingled balance at the EMI – not because of bad faith, but because the contractual arrangement had not been reviewed against the applicable safeguarding regime.
The position in the UK under the FCA's EMI regime is broadly analogous, with specific rules on the eligible accounts and custodians that may hold safeguarded funds. In offshore jurisdictions such as the Cayman Islands under CIMA and the BVI under the FSC, the safeguarding expectations are set by the applicable VASP or payment-services legislation and should be verified against current law before any reliance is placed on them.
How Should a Digital-Asset Business Structure Its Cross-Border Payment Architecture?
A multi-jurisdiction digital-asset business typically needs a layered payment architecture – not a single EMI relationship – to cover its full operating perimeter. The structure consists of a primary EMI or payment institution licence in the home or hub jurisdiction, combined with secondary relationships or local registrations in markets where the primary licence does not passport or where local currency settlement requires a domestic counterparty.
The decision matrix follows a consistent pattern. A business operating primarily within the EU or EEA, with a EUR-dominated transaction flow and a user base concentrated in Western Europe, can often operate effectively from a single EU-authorised EMI, relying on the passporting mechanism. A business with significant USD flows, US-facing operations or US-domiciled beneficial owners will need to consider the federal and state money-transmitter licensing (MTL) regime in the United States, the NYDFS BitLicense for New York activity, and the FinCEN registration requirement – none of which are covered by an EU EMI licence. A business with operations in the UAE, Singapore or Hong Kong will need to address the local VARA, MAS or SFC requirements in addition to any EU or UK payment licence.
The tax interaction is a further structural consideration that is frequently underweighted at the architecture stage. The jurisdiction in which the EMI licence sits determines the VAT/GST treatment of payment services fees and, in some cases, the withholding tax exposure on interest earned on safeguarded funds. Structuring the EMI layer without reference to the group's tax position can create avoidable costs that compound over time.
In a recent cross-border structuring matter, a custody and exchange group operating in three jurisdictions had built its payment architecture around a single offshore EMI relationship that was not licensed in any of its primary markets. When the group sought a banking relationship with a Tier 1 institution, the absence of a recognisable regulated payment layer was the primary obstacle. We assisted in identifying the appropriate EU and Gulf-region licence categories, mapping the application process and coordinating with allied counsel in each relevant jurisdiction. The result was a compliant, bankable structure that the group's institutional banking target could underwrite.
Does a Single Offshore Licence Cover Global Operations?
A single offshore licence does not cover global digital-asset operations – and the assumption that it does is the most common structural error we see in early-stage and growth-stage crypto businesses. The position is worth stating plainly, because the cost of acting on this assumption is severe: enforcement action, frozen payment rails, and the need to rebuild the entire regulatory stack under time pressure.
The offshore VASP registration – in the BVI under the VASP Act 2022, in the Cayman Islands under CIMA's VASP Act, or in a comparable offshore centre – addresses the VASP's regulated status within that jurisdiction. It does not confer any right to provide services to users in the EU (where MiCA CASP authorisation applies), the UK (where FCA registration and financial-promotion rules apply), Singapore (where the MAS Payment Services Act applies), or the US (where SEC, CFTC, FinCEN and state MTL requirements apply). Each of those regimes operates extraterritorially: it is the location of the user, not just the location of the entity, that determines which regulatory requirements are triggered.
The practical consequence is that a business with an offshore VASP registration serving EU users without MiCA CASP authorisation is operating unlawfully in those users' home jurisdictions, regardless of the apparent propriety of its offshore status. The same analysis applies to UK users under the FCA regime, to Singapore users under MAS, and to US users under the applicable federal and state frameworks. Regulators in all of these jurisdictions have taken enforcement action against businesses operating on the assumption of offshore immunity.
The myth also collides with the banking reality. An EMI or bank that is itself regulated in the EU, UK or Singapore will apply its home regulator's expectations to all clients it onboards, including offshore-registered VASPs. If the VASP cannot demonstrate compliant status in the markets it serves, the EMI's own AML exposure grows – and the account relationship becomes untenable.
Self-Assessment: Is Your EMI and Payment Architecture Fit for Purpose?
A fit-for-purpose payment architecture for a digital-asset business satisfies four tests simultaneously: regulatory compliance in every operating market; bankability with at least one Tier 1 or Tier 2 institution; operational resilience if a primary EMI relationship is terminated; and client-money protection that holds under the applicable safeguarding regime. Most businesses that come to us with an EMI problem fail at least one of these tests.
The self-assessment framework runs as follows. First, map every jurisdiction in which the business has users, employees, servers or beneficial owners, and identify the regulated activities triggered in each. Do not rely on the corporate structure alone – a Cayman entity serving EU users triggers EU law. Second, identify the payment licence or registration required in each triggered jurisdiction, and verify that the current structure holds the required permission or a defensible exemption. Third, review the contractual arrangements with all current EMI relationships to confirm that client funds are held under a compliant safeguarding arrangement, not commingled with the EMI's own funds. Fourth, assess whether the current banking infrastructure can survive the loss of any single EMI relationship – and if it cannot, build the backup before the primary relationship is at risk.
Operators who complete this assessment honestly will frequently identify gaps that require remediation. The earlier those gaps are identified, the lower the cost of fixing them. A gap identified during a licensing application or a banking due-diligence process is far more expensive to address than a gap identified during a structured legal review.
Related at OBOLUS:
- Banking, Payments and EMI Onboarding – how we structure and execute EMI and banking access for digital-asset businesses across 70+ jurisdictions
- Correspondent Banking Access: A Cross-Jurisdiction Comparison – a comparative analysis of banking access for crypto businesses in the leading hubs
- Digital-Asset Licensing in Gibraltar – what businesses need to know about the Gibraltar regulatory regime and its payment infrastructure
FAQ
Why do banks close crypto company accounts?
Banks close crypto accounts primarily because of AML/CFT risk exposure, correspondent-bank pressure and monitoring cost. A crypto business that cannot demonstrate compliant Travel Rule implementation, a clean source-of-funds narrative and a documented AML programme presents an unquantifiable risk. When correspondent banks restrict settlement for crypto-related transactions, downstream respondent institutions mirror that policy regardless of their own assessment – and the account is closed. Structural transparency and proactive compliance documentation are the most effective countermeasures.
How can a VASP onboard with an EMI?
A VASP can onboard with an EMI by presenting a structured compliance package before the first formal outreach: a current licence or registration certificate, a written AML/CFT policy that specifically addresses the Travel Rule, a transaction monitoring description, a full corporate structure chart to beneficial-owner level, a source-of-funds narrative, and projected transaction volumes by currency and jurisdiction. Equally important is selecting an EMI whose risk appetite and correspondent-bank coverage matches the VASP's asset class, geographic scope and transaction profile.
What does client-money safeguarding require?
Client-money safeguarding requires an authorised EMI to hold client funds separately from its own funds, in an eligible account at a credit institution or through an approved insurance or guarantee mechanism, so those funds remain available to clients in the event of the EMI's insolvency. The specific eligible methods are set by the applicable regime – EMD2 in the EU, the FCA's EMI regulations in the UK, and equivalent rules in offshore centres. A VASP relying on an EMI for fiat custody should review the contractual arrangement against the current safeguarding standard in the EMI's home jurisdiction.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence, banking and payment stack across operating, custody and payment layers before you commit – so structural gaps are identified before they become enforcement events. Digital assets are the entirety of our practice, and we act only for businesses. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in EMI licensing, VASP registration and cross-border payment architecture for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.