EST · MMXXVI
Home/Insights/Regulatory/EMI licence for crypto firms: A Cross-jurisdiction Comparison
Licensing & Registration

EMI licence for crypto firms: A Cross-jurisdiction Comparison

Emi licence for crypto firms: A Cross-jurisdiction Comparison. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk

An electronic money institution (EMI) – a firm authorised to issue electronic money and provide payment services – has become a critical operating layer for crypto businesses that need to hold fiat balances, settle user withdrawals and maintain correspondent banking. As regulators across the major hubs tighten the rules on which entities may touch customer funds, crypto firms without the right authorisation find themselves frozen out of banking rails, blocked from processing payments and exposed to enforcement action. The stakes are high, and the choice of jurisdiction determines both the speed of market entry and the long-term defensibility of the structure.

This analysis maps the EMI licensing environment across the jurisdictions most relevant to crypto operators: the European Union under MiCA and the Electronic Money Directive, the United Kingdom under FCA supervision, and a selection of offshore common-law regimes that have developed their own payment authorisation tracks. It contrasts the strategic positions of each, offers a decision matrix by operator profile and closes with a cross-border checklist. The goal is not a verdict – the best jurisdiction depends on the specific business – but a working framework for the decision.

Why do crypto firms need an EMI licence?

Most crypto exchanges, custodians and on-ramp providers hold customer fiat at some point in the transaction cycle. That activity – receiving, holding and transmitting funds on behalf of clients – typically constitutes a regulated payment service or electronic money issuance in every major jurisdiction. Operating without authorisation exposes the business to criminal enforcement, civil liability, account termination by correspondent banks and, increasingly, mandatory wind-down orders issued by regulators.

The convergence of crypto and payments regulation is accelerating. ESMA and national competent authorities under MiCA now treat the fiat-custody and settlement functions of a crypto-asset service provider (CASP) as inseparable from the payment services regime. A CASP that also wants to issue e-money or provide payment account services must hold a separate EMI authorisation – or partner with a licensed institution – in each relevant jurisdiction. The assumption that a VASP registration alone covers the payment layer is the most common and most expensive mistake we see in early-stage mandates.

There is also a banking dependency problem. Correspondent banks conduct their own due diligence on the regulatory status of crypto clients. A firm with only a VASP registration, but no EMI or payment institution licence, will find the pool of willing banking partners sharply contracted. In our cross-border practice, we regularly see businesses that completed a VASP registration and then discovered their banking options were limited to a small number of high-fee providers – because the banking counterparties wanted to see a full payment services authorisation, not just an AML-compliance registration.

The practical consequence: before a crypto firm commits capital to a jurisdiction, it must map the full authorisation stack – the VASP or CASP layer, the EMI or payment institution layer, and the custody layer if the business holds private keys. Those three layers rarely collapse into a single licence, and each has its own capital, governance and prudential requirements.

The process above describes the standard regulatory path. Your specific facts – the entity structure, the user base, the fiat-flow architecture and the banking relationships – change the analysis materially. For a scoped assessment of your authorisation stack, contact OBOLUS at info@oboluslaw.com.

EMI licensing in the European Union: passporting and MiCA interaction

The EU remains the highest-volume EMI market for crypto firms because a single authorisation by one national competent authority activates passporting rights across all member states and the wider EEA. A firm authorised as an EMI in Lithuania, Malta or any other member state may passport payment services into France, Germany, the Netherlands and the rest of the bloc without separate country applications – a structural advantage that no offshore jurisdiction replicates.

Lithuania built its reputation as an accessible EU EMI entry point, with the Bank of Lithuania developing a recognised track for payment institution and EMI applications. Under MiCA, that same regulator now supervises the transition from the prior VASP registration regime to CASP authorisation. A crypto firm that holds both an EMI licence from the Bank of Lithuania and a MiCA CASP authorisation can operate a fully integrated fiat-and-crypto service across the EU from a single regulated entity. The capital requirements and governance standards are not light – but the passporting benefit makes the cost proportionate for a business that genuinely serves a European user base.

Malta's MFSA offers a comparable combined-licence structure. The VFA (Virtual Financial Assets) framework is transitioning to MiCA CASP authorisation, and the MFSA has signalled a constructive posture toward applicants that already hold, or are applying for, EMI or payment institution status in parallel. The VFA agent concept, which historically required crypto firms to appoint a licensed intermediary for supervisory purposes, is being wound into the broader CASP authorisation track as MiCA takes effect.

The EU's CASP whitepaper regime adds a disclosure layer that EMI-only structures do not face. Crypto-asset issuers and service providers must publish and notify a whitepaper meeting ESMA standards before marketing to EU clients. A combined EMI-CASP applicant therefore carries a heavier documentation burden than a payment-only applicant, but it also presents a cleaner, more defensible structure to banking counterparties and institutional clients.

One cross-border nuance that operators frequently miss: the passporting right covers the payment services and EMI activities, not the crypto-asset services. A firm passporting EMI services from Lithuania into Germany may still need to address Germany's national competent authority requirements for the CASP activities separately, until MiCA passporting for CASPs is fully operational. The two regimes are running in parallel during the transition window, and the interaction between them requires careful navigation at the jurisdictional level.

How does the UK EMI regime compare after Brexit?

The United Kingdom operates its own EMI and payment institution regime under FCA supervision, entirely separate from the EU framework following Brexit. An FCA-authorised EMI has no passporting rights into the EU – and an EU-authorised EMI has no passporting rights into the UK. Businesses that serve both markets must therefore hold two separate authorisations, or structure through two separate entities, adding governance and capital cost.

The FCA's cryptoasset registration under the Money Laundering Regulations operates independently of EMI authorisation. A UK-based crypto firm must be registered with the FCA for AML purposes, and separately authorised as an EMI or payment institution if it issues e-money or provides payment services. The FCA has been explicit that the AML registration does not confer payment services permissions. The financial-promotion rules that apply to crypto marketing in the UK add a third compliance layer, separate from both.

In our practice, we advise clients that the UK remains a strategically important market for crypto payment services – the FCA's supervisory framework is well-developed, correspondent banking options for FCA-regulated entities are comparatively broad, and institutional clients treat FCA authorisation as a credibility marker. The application process is demanding, and the FCA's published rejection and withdrawal rates for cryptoasset registrations are among the highest of any major regulator. Applicants must expect a detailed review of governance, AML systems and, for EMI applications, prudential arrangements.

The cross-border interaction between UK and EU structures is one of the most complex planning decisions a crypto firm faces today. A firm with a UK EMI and an EU CASP must manage two sets of regulatory capital, two supervisory relationships, two AML regimes and potentially two sets of financial-promotion compliance. For some businesses the dual-jurisdiction structure is unavoidable. For others, selecting one market as the primary jurisdiction and accessing the other through licensed partnerships is the more efficient model.

Do offshore EMI structures provide viable alternatives?

Offshore common-law regimes – principally the BVI, the Cayman Islands and the Isle of Man – offer regulatory registration or licensing tracks for VASPs and, in some cases, payment service providers, but the EMI label in its EU/UK sense does not generally apply. These jurisdictions do not issue electronic money licences in the EU/PSD2 sense. What they offer is a VASP registration or a money services business authorisation that covers some of the activity a crypto firm would otherwise conduct under an EMI licence.

The BVI FSC administers the VASP Act 2022, which requires registration for virtual asset service providers operating in or from the BVI. The Cayman CIMA administers its own Virtual Asset (Service Providers) Act with registration and licensing tracks. Neither creates an EMI in the EU sense, and neither activates passporting rights into any other major market. The practical consequence is that a BVI- or Cayman-registered VASP that wants to hold fiat balances for EU or UK clients must either partner with an FCA- or EU-authorised payment institution, or hold a separate EMI authorisation in the relevant jurisdiction.

The Isle of Man offers a more developed payment services framework for crypto firms, with the Isle of Man FSA supervising a licensed payment institution track alongside its VASP authorisation regime. In certain operator profiles – particularly funds and custodians with a lower volume of retail fiat flows – the Isle of Man structure provides a cost-efficient regulated base with genuine supervisory substance, while the EU or UK EMI is held by a separate group entity.

The myth that a single offshore registration is sufficient to serve clients globally is among the most persistent and costly misconceptions in crypto business structuring. Regulators in the EU, UK, Singapore and Hong Kong all apply a market-access test: if the firm is actively marketing to, or serving, residents of a regulated jurisdiction, the local regulatory regime applies regardless of where the firm is incorporated or registered. An offshore VASP registration is not a shield against enforcement action in the jurisdiction where the clients are located.

What are the Asia-Pacific equivalents for crypto payment licensing?

In the Asia-Pacific region, payment service licensing rather than EMI authorisation is the operative concept – but the functional requirements are closely analogous, and the strategic stakes for crypto firms are equally high.

MAS (the Monetary Authority of Singapore) licenses digital payment token service providers under the Payment Services Act. The Act creates three licence tiers – money-changing, standard payment institution and major payment institution – with capital and transaction volume thresholds distinguishing the tiers. A crypto exchange or on-ramp that processes fiat above the relevant thresholds must hold a major payment institution licence from MAS, not merely a standard licence or an exemption. The MAS application process is thorough and deliberate; MAS has stated publicly that it applies a high-quality bar and expects applicants to demonstrate robust AML systems, governance and technology risk management. Timelines have historically extended well beyond initial estimates.

SFC (the Securities and Futures Commission of Hong Kong) administers the VASP licensing regime for virtual-asset trading platforms. The SFC regime addresses the securities and trading functions of a crypto exchange but does not directly confer payment services permissions. A firm operating in Hong Kong that also processes fiat must engage with the banking system through licensed remittance agents or licensed banks – and the SFC has been clear that VATP licensees must maintain segregated client accounts through properly licensed custodial and banking arrangements. The interaction between the VATP licence and the payment services layer is an active area of regulatory development in Hong Kong.

In our cross-border practice, we advise operators expanding into Asia-Pacific that the Singapore and Hong Kong regimes require early engagement – both with the regulator and with prospective banking partners. A crypto firm that arrives in Singapore with a completed application but no banking relationship in place will face a materially longer path to live operations than one that has pre-qualified its banking options alongside the licensing process.

Which EMI or payment licence structure suits which operator profile?

The right licensing structure depends on the firm's user base, fiat-flow architecture, capital position and strategic time horizon. The following profiles represent the decision branches we work through most regularly with clients.

Profile A – EU-focused crypto exchange with retail fiat on-ramp. This firm needs both a MiCA CASP authorisation and an EU EMI or payment institution licence. Lithuania or Malta are the most common entry points, for reasons of supervisory accessibility and passporting efficiency. The combined application adds time and capital – but a firm that compromises on either layer will face banking rejection and enforcement risk in the markets it is trying to serve. Indicative timeline to live operation is typically measured in months rather than weeks. Key risk: the parallel MiCA/PSD2 transition requires the application to address both regimes simultaneously, and the interaction is not yet fully settled in regulatory guidance.

Profile B – Global crypto custodian with institutional clients in multiple jurisdictions. This firm typically holds a CASP or VASP authorisation in one or more EU/UK/APAC jurisdictions, a custody-specific authorisation where required (MFSA, FSRA, SFC or MAS), and uses a licensed payment institution for fiat settlement rather than holding its own EMI. The EMI layer is outsourced; the licensing focus is on custody permissions and AML compliance. Indicative timeline depends on the primary jurisdiction; Singapore MAS timelines have been lengthier than EU equivalents for custody-plus-payment structures. Key risk: relying on a third-party payment institution creates a banking dependency that can be withdrawn.

Profile C – Early-stage founder building a crypto payments product for a specific regional market. This firm may not need a full EU EMI from day one if it operates below the relevant thresholds or uses a white-label banking-as-a-service provider as a licensed EMI partner. The Isle of Man or BVI VASP registration, combined with a licensed EMI partner for fiat, can provide a cost-efficient entry structure while the business scales. Key risk: the partner EMI structure is operationally simpler but strategically vulnerable – the partner can withdraw, reprice or restrict the service, and the firm has no licensed payment permissions of its own.

Profile D – DeFi or non-custodial protocol with fiat access points. The regulatory position depends on whether the protocol touches fiat or acts as an unhosted-wallet interface only. If fiat conversion or fiat-denominated settlement is a feature, the fiat-access points – typically centralised on-ramps – require payment or EMI authorisation in the jurisdictions where users are located. The protocol itself may not require a licence in every jurisdiction, but the business entity that operates the on-ramp does. Key risk: misidentifying the regulated perimeter and treating a custody or payment function as decentralised when it is operationally centralised.

How do AML and the Travel Rule apply across EMI and VASP structures?

Every EMI and VASP operating in a FATF member jurisdiction is subject to the Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data with virtual asset transfers above the applicable threshold. The threshold and the technical implementation standard vary by jurisdiction, but the obligation exists in every major regulated market the OBOLUS practice covers.

The interaction between the EMI layer and the VASP layer creates a double Travel Rule exposure. When a crypto firm processes a fiat-to-crypto conversion, the fiat leg is subject to payment services AML rules, and the crypto leg is subject to VASP Travel Rule requirements. Both sets of obligations must be satisfied at the point of transaction. Compliance systems that address one layer but not the other are a known failure mode and a consistent enforcement target.

ESMA and national competent authorities under MiCA have signalled that combined CASP-EMI entities will be scrutinised for the consistency of their AML controls across both the payment and crypto-asset functions. A firm that applies different customer-due-diligence standards to the fiat and crypto legs of the same transaction is at regulatory risk. The practical response is to build a unified AML/KYC system that applies consistent controls regardless of whether the underlying instrument is fiat or crypto.

In a recent licensing mandate, a payments firm seeking an EU EMI authorisation alongside a CASP application discovered mid-process that its proposed transaction-monitoring system addressed crypto movements but used a legacy rule-set for fiat. The remediation – updating the monitoring system to cover both legs uniformly – added time to the authorisation process but was essential. We see this structural gap regularly; it is one of the most predictable causes of application delay.

The cross-border AML dimension is further complicated by the variation in Travel Rule thresholds and technical standards across jurisdictions. A firm operating under MiCA, the FCA regime and the MAS Payment Services Act simultaneously must manage three sets of transfer-data obligations that are directionally aligned but operationally distinct. Centralising compliance architecture around the most demanding applicable standard – and documenting the jurisdiction-specific departures from that standard – is the approach we recommend to clients managing multi-jurisdiction AML obligations.

Is a single offshore licence sufficient for global operations?

A common assumption among early-stage founders is that a single well-chosen offshore registration – a BVI VASP, a Cayman VASP, or a similar instrument – is sufficient to serve a global client base, provided the firm's terms of service include appropriate geographic disclaimers. This assumption is commercially attractive and legally incorrect.

Every major regulated jurisdiction applies a market-access standard that turns on the substance of the firm's activity in that market, not on the location of its incorporation or registration. A firm incorporated in the BVI but actively marketing to EU residents, processing their fiat, and providing them with custody of their crypto assets is conducting regulated activities in the EU. The geographic disclaimer in the terms of service does not alter that analysis. The relevant test is what the firm does and for whom – not where its registered office sits.

The enforcement consequences of this structural error range from regulatory warnings and mandatory wind-down orders to criminal prosecution of officers and directors in the most serious cases. More immediately, it prevents the firm from opening correspondent bank accounts at tier-one institutions, which routinely require evidence of authorisation in the markets the firm serves. The banking rejection is often the first practical signal that the licence structure is insufficient – but by that point the firm has typically already incurred operating costs and user obligations that make a rapid structural reset painful.

We map the licence stack across the operating, custody and payment layers before a client commits to an entry structure. That early-stage mapping – addressing where the entity sits, where the users are, where the fiat flows and where the keys are held – is the foundation of a defensible multi-jurisdiction structure.

If a prior application stalled, an account was closed or a regulatory query arrived, a second read of the structure often surfaces the gap and the route back to compliance. Contact OBOLUS at info@oboluslaw.com to assess your current position.

Self-assessment checklist before committing to a licensing jurisdiction

Before selecting a jurisdiction for an EMI or payment services authorisation, a crypto firm's legal and compliance team should be able to answer the following questions clearly. A gap in any answer is a signal to engage specialist counsel before the application is filed.

  • Has the firm mapped every jurisdiction where it actively serves clients or processes transactions – not merely where it is incorporated?
  • Has the firm identified every regulated activity it conducts: VASP or CASP services, payment services, e-money issuance, custody, lending?
  • Does the proposed jurisdiction's licence cover all identified regulated activities, or does the firm need parallel authorisations?
  • Has the firm confirmed – with a prospective banking partner, not merely assumed – that the proposed licence satisfies the banking partner's own regulatory requirements?
  • Has the firm identified the Travel Rule obligations applicable to each jurisdiction where it operates and confirmed that its compliance system addresses both the fiat and crypto legs?
  • Does the firm have a credible governance structure, including independent compliance and AML/KYC oversight, that satisfies the applicable regulatory standard – not merely a compliance policy document?
  • Has the firm stress-tested the time and capital required to obtain the licence against its operational funding runway?
  • Does the proposed structure account for the cross-border regulatory interaction between the chosen jurisdiction and the markets where users are located?

These are not academic questions. Regulators in every major hub have increased the depth and duration of authorisation reviews in recent years. A firm that arrives at an application without clear answers to each of these questions will face delay, requests for information and, in some cases, rejection.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary substantially by jurisdiction, licence type and the quality of the application. EU EMI and CASP authorisations typically run from several months to over a year, depending on the national competent authority and the completeness of the submission. MAS applications in Singapore have historically taken longer than initial estimates. BVI and Cayman VASP registrations are generally faster but confer narrower permissions. The most reliable predictor of timeline is the quality of the governance, AML and prudential documentation submitted at the outset.

Which jurisdiction is best for licensing my crypto business?

There is no universally optimal jurisdiction. The right choice depends on where the firm's clients are located, what regulated activities the business conducts, the firm's capital position, its banking needs and its time horizon. EU passporting makes a MiCA CASP plus EMI structure attractive for Europe-facing businesses. Singapore and Hong Kong are the primary APAC entry points. Offshore structures are efficient for certain fund and custody profiles but do not substitute for authorisation in the markets where clients are served. We map the full stack before recommending a primary jurisdiction.

Do I need a separate custody licence?

In most major jurisdictions, custody of virtual assets – holding private keys on behalf of clients – is a regulated activity distinct from payment services or VASP/CASP authorisation. MiCA treats custody as a standalone CASP service. FSRA in Abu Dhabi, SFC in Hong Kong and MAS in Singapore each have explicit custody-authorisation requirements. A firm that holds client keys and assumes it is covered by its exchange or payment licence alone should review that assumption carefully. The regulatory perimeter for custody is expanding, not contracting.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before a client commits – so structural gaps surface before they become enforcement events, not after. To discuss your licensing structure, contact info@oboluslaw.com or reach us via t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in EMI, CASP and VASP authorisation strategies across the EU, UK and common-law offshore hubs.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours