An electronic money institution (EMI) licence – the regulatory authorisation allowing a business to issue electronic money and execute payment transactions – has become one of the most contested instruments in the digital-asset space. Crypto firms pursuing EMI status discover quickly that the licence is not simply an operational credential. It is a legal position that shapes enforcement exposure, banking access and, critically, the outcome of disputes. As supervisors across the EU, the United Kingdom and connected financial centres tighten conduct expectations under MiCA and aligned regimes, the gap between holding the right authorisation and holding the wrong one has never been wider.
The core question this analysis addresses is pointed: when a crypto firm's licensing structure is tested in a dispute – whether a regulatory enforcement action, a civil claim by a counterparty, or a cross-border asset-recovery matter – how does the EMI licence interact with that process? The answer turns on three variables: which regime issued the licence, how the firm's actual activities mapped to the licensed perimeter at the time of the dispute, and where the dispute is heard. This page works through each of those variables and draws out the practical implications for operators and their counsel.
What makes an EMI licence different for crypto firms?
An EMI licence is categorically distinct from a VASP registration (virtual asset service provider registration) or a CASP authorisation under MiCA: it is a payments instrument, not a crypto-specific one, and its regulated perimeter covers the issuance of electronic money and the execution of payment services rather than crypto-asset exchange or custody. For many crypto businesses, that distinction is precisely the point. A firm that settles transactions in fiat, issues stored-value accounts or provides wallet infrastructure denominated in e-money sits inside the EMI regulatory perimeter regardless of the blockchain rails underneath.
The disputes angle arises because the EMI framework creates a set of enforceable obligations – capital adequacy, safeguarding of client funds, AML/CFT compliance, conduct of business requirements – that become the measuring stick in any subsequent enforcement or litigation. In our cross-border practice, we consistently see disputes in which the central question is not whether the firm held a licence, but whether the licensed activities matched what the firm actually did. A firm operating a crypto exchange that also issues stored-value balances to customers may be conducting EMI-regulated activity whether or not it applied for that authorisation. That gap is where enforcement originates.
How does MiCA reshape the EMI-crypto boundary?
MiCA has drawn a new boundary between e-money token (EMT) issuance and traditional EMI activity that every operator holding or considering an EMI licence must understand. Under the MiCA regime, an EMT – a crypto-asset that purports to maintain a stable value by referencing one official currency – is subject to EMI authorisation requirements where the issuer is established in the EU. The ESMA and national competent authorities have made clear that an entity issuing a fiat-pegged token without the relevant EMI authorisation is simultaneously in breach of two regulatory regimes: the e-money framework and MiCA's whitepaper and issuer obligations.
That dual exposure is a material disputes risk. When a regulator investigates, it investigates both legs. When a counterparty sues for losses connected to an EMT that depegged or was frozen, both the EMI supervisory file and the MiCA compliance record are discoverable. In our practice, we advise operators to treat their EMI authorisation scope and their MiCA CASP authorisation scope as a single compliance map rather than parallel tracks – because in a dispute proceeding, courts and regulators will read them together.
The practical implication for cross-border operators is acute. A firm with an EMI licence in one EU member state that passports across the EU under the MiCA CASP regime must ensure that its passporting notification covers every service it actually delivers in each member state. A mismatch between the passport scope and the actual service delivery is both a supervisory breach and a litigation point for any claimant seeking to establish that the firm operated outside its licensed perimeter.
To map the licensed perimeter before a dispute arises, contact OBOLUS at Map your options. The process above describes the standard path. Your facts – the entity structure, the user base geography, the banking and settlement rails – change the analysis materially.
Which jurisdictions issue EMI licences used by crypto firms?
EMI authorisations used by crypto-active businesses are concentrated in jurisdictions that combine a credible regulatory regime with practical access to correspondent banking. Within the EU, the most frequently used issuance jurisdictions include Lithuania (under the Bank of Lithuania's supervision and transitioning to MiCA), Malta (MFSA, with its VFA framework now converging on MiCA CASP standards), and Ireland. In the United Kingdom, the FCA administers EMI authorisation separately from cryptoasset registration under the Money Laundering Regulations – a firm may need both.
Outside the EU and UK, the ADGM's FSRA in Abu Dhabi recognises payment-service activities that functionally overlap with EMI-type services, while Singapore's MAS administers payment institution licensing under the Payment Services Act for digital payment token service providers. None of these regimes is interchangeable. An EMI authorisation from the Bank of Lithuania does not extend to activities in the ADGM; a Singaporean Major Payment Institution licence does not passport into the EU. That geographic specificity of licensing is the single most common source of the disputes we see involving operators who assumed a single authorisation would cover a multi-jurisdictional service.
A common assumption is that an offshore or single-jurisdiction EMI licence creates a global operating right. It does not. Each jurisdiction in which the firm has customers, conducts marketing, routes payments or holds client funds is a potential enforcement vector. Regulators in the UK, EU and Singapore have each taken action against firms that served local customers under foreign licences that carried no local recognition. The cost of that assumption – in enforcement fines, remediation, and litigation – typically exceeds the cost of building the right structure at the outset.
What are the principal disputes risks attached to an EMI licence?
The disputes risks that attach to EMI licensing fall into four distinct categories, each with a different procedural character and a different forum. Understanding all four is essential before a crypto firm commits to a licensing structure.
The first is regulatory enforcement. An EMI supervisor may suspend or revoke a licence, impose conditions, or refer a matter to criminal authorities where it finds that a firm operated outside its authorised perimeter, failed to meet safeguarding obligations, or breached AML/CFT requirements. In EU member states, the relevant NCA under ESMA's oversight is the primary enforcement authority; in the UK, the FCA acts. The procedural consequence of an enforcement action is that the firm's banking relationships – typically held under EMI correspondent agreements – are simultaneously at risk.
The second is civil claims by customers or counterparties. A firm that issues e-money and then freezes balances – whether in response to an AML alert, a court order or insolvency – faces claims from account holders asserting that their funds were client money held on trust, not unsecured credit. English and Welsh courts have addressed analogous issues in crypto-asset insolvency proceedings; the characterisation of the asset as property held on trust is an active jurisprudential question with direct relevance to EMI-structured crypto businesses.
The third category is cross-border asset recovery. Where a firm is the victim – not the defendant – of fraud, the EMI structure can be an asset or a liability. An EMI that holds client money in segregated accounts may have a cleaner path to tracing and freezing than an unregulated entity, because the regulatory framework creates an auditable paper trail. In our recovery practice, we have used the safeguarding and record-keeping obligations of EMI-licensed intermediaries as the basis for disclosure applications in common-law forums.
The fourth is contractual disputes with banking counterparties. An EMI licence is, operationally, a gateway to correspondent banking. When a bank terminates an EMI's account – a debanking event that has affected a significant number of crypto-active EMIs across the EU and UK – the EMI faces both a practical crisis and a potential cause of action. The legal merits of that action turn in part on whether the EMI was operating within its licensed scope at the point of termination.
How does the disputes record reflect on EMI application strategy?
The procedural history of disputes in the crypto-EMI space reveals a consistent pattern: firms that designed their licensing structure reactively – obtaining an EMI licence to solve a banking problem rather than to reflect their actual regulatory perimeter – face disproportionate disputes exposure later. In our cross-border practice, we regularly advise on licensing matters where the presenting issue is a dispute that, on analysis, traces directly to an original licensing decision made without a full assessment of the firm's activities.
A firm preparing an EMI application should treat the licence scope as a legal commitment, not a commercial credential. The application document sets out the activities the firm is authorised to conduct. In a subsequent dispute – whether regulatory, civil or recovery-related – that document is the baseline against which actual conduct is measured. If the firm's activities expanded after authorisation without a corresponding licence variation, the gap is the exposure.
In a recent matter, we advised a payments business that held an EU-member-state EMI licence and had expanded into crypto-asset custody services over the course of two years following initial authorisation. When a customer dispute arose over the return of assets, the firm's counsel realised that the custody activity was not covered by the EMI perimeter and had not been notified to the supervising NCA. That gap required simultaneous regulatory remediation and litigation strategy. We structured the remediation filing and the civil defence in parallel, ensuring that the regulatory record did not prejudice the litigation position. The matter was resolved without a formal enforcement referral.
Decision matrix: which licensing profile fits your crypto business?
There is no universal licensing stack for a crypto business with payment-layer activity. The right instrument depends on the business model, the user geography, the asset types involved and the acceptable timeline to market. The following analysis maps four operator profiles to their most appropriate licensing path, with the disputes risk at each point.
A crypto exchange that settles trades in fiat and holds fiat balances for customers is conducting both VASP/CASP activity and, in most leading jurisdictions, EMI-regulated activity. The correct structure is a CASP authorisation under MiCA for the trading layer and an EMI authorisation for the fiat-holding layer. Operating with only the CASP authorisation creates a regulatory gap in the fiat layer; operating with only the EMI authorisation leaves the crypto trading perimeter unregulated. Timeline for both, in the EU, is a function of the relevant NCA's processing pace – qualitatively, a matter of months rather than weeks. The disputes risk of an incomplete structure is enforcement by both the NCA and the relevant AML supervisor.
A stablecoin issuer domiciled in the EU that pegs its token to a single fiat currency is issuing an EMT under MiCA. It requires EMI authorisation as a threshold matter. Attempting to structure around that requirement – for example by characterising the token as a utility token – creates a classification disputes risk that regulators and courts will resolve against the issuer where the economic substance is plainly a fiat peg. The timeline for EMI authorisation in a member state with a developed process is, qualitatively, longer than a simple VASP registration, and the capital requirements are correspondingly more demanding.
A DeFi protocol front-end operator that does not hold customer funds and does not issue stored-value instruments is unlikely to require an EMI licence. The disputes risk is different: it lies in being characterised as operating an unregistered exchange or providing unregistered investment services. The licensing question is whether the front-end operator's control over the protocol is sufficient to bring it within the CASP perimeter. That is a classification question best resolved before a dispute arises.
A crypto fund that uses a third-party EMI for payment rails and a separate custodian for asset holding has outsourced both EMI and custody risks to regulated counterparties. Its disputes exposure is then counterparty risk: what happens when the EMI or the custodian is itself subject to enforcement or insolvency? The structure requires contractual protections – representations, audit rights, change-of-control notifications – that reduce that exposure.
If a prior application stalled or a debanking event has disrupted your payment rails, contact OBOLUS now at Map your options. If an application stalled or an account was closed, a second read of the original structure can surface the gap and map the route forward.
How do EMI obligations interact with AML and the Travel Rule in disputes?
EMI-licensed crypto firms carry a layered AML/CFT compliance obligation that has significant procedural consequences when a dispute arises. The FATF Recommendations, including Recommendation 15 on virtual assets and the Travel Rule obligation requiring originator and beneficiary information to accompany transfers, apply to EMIs that process crypto-linked payment flows. Where a firm is investigated for AML failures, the Travel Rule compliance record – or its absence – becomes a central exhibit.
In civil disputes, AML obligations interact with the disputes process in a less obvious but equally important way. A counterparty seeking to recover assets from an EMI may apply for a court order requiring disclosure of transaction records, AML files and beneficial ownership information. In England and Wales, a Norwich Pharmacal order or a Bankers Trust order can compel an EMI to produce records held in its regulatory compliance function. The dual character of those records – simultaneously a regulatory compliance asset and a litigation disclosure risk – means that EMI-licensed firms should treat their AML files with the same care as privileged legal documents, to the extent that privilege applies.
The cross-border dimension compounds this. An EMI authorised in the EU that holds AML files in a cloud environment accessible from multiple jurisdictions may find itself subject to disclosure orders from courts in England, Singapore or Hong Kong, as well as from its home-state NCA. In our practice, we advise operators to build AML data architecture with litigation geography in mind from the outset, not as a retrofit.
What happens when an EMI licence is suspended or revoked?
Suspension or revocation of an EMI licence is, operationally, one of the most acute crises a crypto firm can face. The consequences cascade: correspondent banking agreements typically contain licence-validity representations that trigger default or termination on revocation; client funds in segregated safeguarding accounts become the subject of a supervised wind-down or insolvency; contractual counterparties have termination rights; and the firm's directors may face personal regulatory scrutiny.
The legal procedure for challenging a suspension or revocation varies by jurisdiction, but the common thread across EU member states, the UK and Singapore is that the firm has a right to make representations, and the timing of that right matters. In the EU, the relevant NCA must follow procedural requirements before finalising a revocation. In the UK, the FCA's decision-making process includes a warning notice and decision notice stage at which the firm can refer the matter to the Upper Tribunal. Understanding the procedural window – and engaging counsel before the warning notice is issued, not after – is the single most important step in an EMI enforcement response.
Operators we advise on licensing matters are counselled to maintain a regulatory-liaison protocol that ensures any NCA communication – a thematic review letter, a s166 equivalent skilled-person appointment, or an informal supervisory concern – is reviewed by qualified counsel within a defined period. That protocol has prevented a number of matters from escalating to formal enforcement proceedings.
A common assumption about offshore EMI structures
A persistent belief in the crypto-business community holds that a single offshore or mid-tier EMI licence – whether from a jurisdiction outside the EU and UK mainstream, or from a smaller EU member state with historically lighter supervision – is sufficient to operate a multi-jurisdictional payments and crypto service. That belief is wrong on two levels, and the second level is the disputes angle.
At the first level, a licence from jurisdiction A does not authorise services in jurisdiction B. Each jurisdiction applies its own perimeter tests. A firm with a single EMI authorisation that onboards customers in unrecognised jurisdictions, routes payments through correspondent banks in those jurisdictions, or conducts marketing directed at residents of those jurisdictions has created multiple unregulated-activity exposures.
At the second level – the disputes level – the offshore structure undermines the firm's position in every forum. Courts in England and Wales, the DIFC Courts in Dubai, and the courts of Singapore are all sophisticated forums that have addressed the relevance of a claimant's regulatory status to the enforceability of its rights. A firm that cannot demonstrate that it held the appropriate authorisation for the activity giving rise to the dispute is in a weaker position than one that can. In some jurisdictions, operating outside the licensed perimeter may be an ex turpi causa or illegality defence available to the counterparty.
Regulators in the leading hubs increasingly expect operators to demonstrate that their licensing structure reflects their actual business model, not a minimum-viable credential obtained for banking-access purposes. Where that expectation is not met, the regulatory relationship deteriorates – and a deteriorated regulatory relationship is the precursor to the enforcement actions that become disputes.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – the full practice overview covering all major licensing regimes and jurisdictions
- Licence Renewal and Variation Under Heightened Scrutiny – how to manage a variation application when the supervisor has open concerns
- EMI Licence for Crypto Firms: Early-Stage Founders Guide – the application process mapped step by step for first-time applicants
FAQ
How long does a crypto licence take to obtain?
Timeline varies substantially by jurisdiction and licence type. Within the EU, a CASP authorisation under MiCA or an EMI authorisation in a member state with a developed process typically takes several months from submission of a complete application. In Singapore, MAS processing for a payment institution licence is similarly a multi-month process. Jurisdictions with lighter initial supervision may process registrations faster, but the compliance build required to sustain that registration is not materially shorter. A realistic planning horizon, accounting for pre-application preparation, is generally measured in quarters rather than weeks.
Which jurisdiction is best for licensing my crypto business?
There is no universally best jurisdiction. The right choice depends on the business model, the user base, the banking infrastructure required, the tax position and the acceptable compliance cost. An EU CASP authorisation from a member state with a credible NCA offers the broadest passporting reach. Singapore's MAS licence is suited to operators serving Asian markets. VARA in Dubai is relevant for operators with a Middle East and global hub profile. ADGM's FSRA serves institutional-facing businesses. The disputes angle adds another variable: the forum in which you are most likely to litigate should be part of the jurisdiction decision.
Do I need a separate custody licence?
In most leading regimes, custody of crypto-assets is a separately regulated activity. Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct CASP service requiring specific authorisation. In Hong Kong, the SFC's VASP licensing regime covers custodial services for virtual-asset trading platforms. In Singapore, custody may fall within the payment institution framework or require separate MAS engagement depending on the asset type. An EMI licence alone does not authorise custody. Operating custodial services under an EMI authorisation that does not cover that activity is a regulated-perimeter breach.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack as a single mandate – not three disconnected workstreams – so that the structure we design for you holds under supervisory scrutiny and in any dispute that follows. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in EMI and CASP authorisation strategy, cross-border licensing perimeter analysis and regulatory enforcement response for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.