EST · MMXXVI
Home/Insights/Regulatory/EMI licence for crypto firms: The Structuring Angle
Licensing & Registration

EMI licence for crypto firms: The Structuring Angle

Emi licence for crypto firms: The Structuring Angle. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS

A crypto-payments business scaling from a single market into five discovers the same hard truth: the licence that works in its home jurisdiction does not automatically follow it across borders. For firms that hold, move or exchange fiat alongside digital assets, the electronic money institution (EMI) licence – a regulatory authorisation permitting the issuance of electronic money and the provision of payment services – often sits at the center of the structuring question. Getting the analysis wrong exposes the business to enforcement action, severed banking relationships and frozen payment rails. Getting it right is an exercise in layering: operating entity, custody wrapper, payment layer and the jurisdictions that govern each.

An EMI licence is not a substitute for a VASP registration (virtual asset service provider registration) or a crypto-asset service provider authorisation, and it is not sufficient standing alone for a business that also trades, custodies or issues tokens. The two regimes intersect, but they are legally distinct. Understanding where one ends and the other begins – and when a firm needs both – is the structuring angle that most early-stage operators miss.

This analysis sets out the EMI licensing regime as it interacts with digital-asset business, maps the decision matrix by operator profile, addresses the cross-border reality and identifies the points at which the analysis turns on structural choices rather than jurisdictional preference alone.

What an EMI licence covers – and what it does not

An EMI licence authorises the issuance of electronic money and the provision of regulated payment services, but it does not, by itself, authorise the exchange, custody or brokerage of crypto-assets. This distinction matters enormously for firms that sit at the intersection of fiat rails and digital-asset activity. A business that receives fiat from a customer, converts it to a stablecoin and routes it to a third-party wallet is doing something that may engage at least two separate regulatory regimes simultaneously: the payment services regime for the fiat leg and the crypto-asset services regime for the conversion and routing leg.

Under MiCA (the Markets in Crypto-Assets Regulation), the issuance of e-money tokens (EMTs) – stablecoins denominated in and redeemable for fiat currency – is expressly reserved to licensed credit institutions and authorised EMIs. That is a deliberate design choice by European legislators. It means an EMI authorisation under EU payment services law is a prerequisite for issuing a euro-pegged or sterling-pegged stablecoin to European users, regardless of where the issuing entity is domiciled. A firm that issues an EMT without the requisite EMI status is operating outside the regime from day one.

What the EMI licence does not cover is equally important. It does not authorise the custody of third-party crypto-assets, the operation of a trading platform or the provision of portfolio management over digital assets. Those activities require a separate CASP authorisation (crypto-asset service provider authorisation) under MiCA or an equivalent VASP registration under the applicable regime in the relevant jurisdiction. The practical consequence is that a full-service crypto firm – one that onboards fiat, converts to crypto, custodies assets and executes trades – will need to map each activity layer to its own regulatory permission.

In our cross-border practice, we consistently find that founders conflate the EMI layer with the broader licensing stack. The error is understandable: the EMI licence is often the most accessible regulated status for a fintech-adjacent business, and it provides genuine banking access. But it is not a master licence.

For a scoped assessment of where your activities fall across the EMI and crypto-asset services regimes, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options

Why do crypto firms pursue EMI status at all?

The EMI licence is attractive to crypto firms because it solves the banking problem – at least partially. A firm with an EMI authorisation can hold client funds in segregated accounts, issue payment instruments and access payment schemes in a way that an unlicensed entity cannot. For a crypto exchange or custodian that needs to onboard fiat from customers and off-ramp proceeds, the absence of a regulated payment layer is often the single largest operational constraint.

Beyond banking access, EMI status carries a legitimacy signal that matters in B2B and institutional contexts. Counterparties in the traditional financial system – correspondent banks, liquidity providers, institutional clients – assess their crypto-firm counterparts on regulatory status. An EMI authorisation in a credible jurisdiction communicates that the firm has passed AML/KYC scrutiny, maintains segregated client funds and operates under ongoing supervisory oversight. That signal is commercially material.

There is also a specific EU-law reason. Under MiCA, an EMI authorised in any EU member state may issue EMTs across the entire EU/EEA without requiring separate national authorisation in each member state. The passporting mechanism – the ability to carry a single authorisation into other member states through a notification process – is a genuine structural advantage for firms targeting the EU market. A crypto firm that needs to issue a euro stablecoin or process fiat payments for EU users can use a single EMI authorisation, passported across the bloc, rather than maintaining entity structures in multiple member states.

The EMI route also intersects with the Travel Rule (the obligation to pass originator and beneficiary identification data alongside a transfer) in an important way. EMIs are already subject to robust payment-law AML obligations, and regulators in leading hubs increasingly expect crypto firms to demonstrate equivalent controls on the crypto-asset side. A firm that has built compliant fiat payment infrastructure under an EMI authorisation is often better positioned to satisfy VASP-level Travel Rule requirements because the compliance architecture is already present.

The cross-border reality: where does the licence actually work?

A single EMI authorisation provides no automatic rights outside the jurisdiction – or the trading bloc – in which it was granted. This is the structural gap that the single-offshore-licence myth ignores. A firm holding an EMI licence in a single EU member state may passport payment services across the EU/EEA; it has no equivalent right in the United Kingdom, Singapore, the UAE or any other major digital-asset hub. Each of those jurisdictions maintains its own regulated-activity perimeter, and the fiat-handling and payment activities that the EMI licence covers in the EU may constitute a separately regulated activity requiring local authorisation in each additional jurisdiction.

In the United Kingdom, for example, the FCA (Financial Conduct Authority) maintains its own regime under the Electronic Money Regulations and the Payment Services Regulations, as well as the Money Laundering Regulations for cryptoasset activities. A firm that held an FCA-approved EMI status before the UK left the EU cannot rely on its EU-derived authorisation after the passporting rights ceased. It requires a separate FCA registration or authorisation for each activity it conducts with UK users or through UK-incorporated entities.

In Singapore, the MAS (Monetary Authority of Singapore) regulates payment services under the Payment Services Act, which encompasses major payment institution licences for entities handling significant volumes. A crypto firm that processes fiat for Singapore-based clients will need to assess whether its activities fall within the MAS-regulated perimeter, irrespective of what EMI authorisation it holds elsewhere.

In Dubai, VARA (Virtual Assets Regulatory Authority) regulates virtual-asset activities on the Dubai mainland under its own activity-based licence framework. VARA's rulebooks cover advisory, broker-dealer, custody, exchange, lending, management and transfer/settlement activities. An EMI authorisation granted by an EU regulator does not extend into the VARA perimeter. A firm that structures its EU operations around an EMI and then expands to Dubai will need a separate VARA licence for its Dubai-facing activities.

Operators we advise routinely underestimate the compliance cost of multi-jurisdictional expansion precisely because they build their initial structure around a single licence in one jurisdiction and then try to stretch it to cover activity in others. The structure needs to be designed for the target footprint from the outset, not retrofitted.

The EMI and VASP intersection: how do the regimes interact?

The interaction between the EMI regime and the VASP registration framework is one of the more technically demanding aspects of digital-asset structuring, and it is where most multi-product crypto firms encounter their most serious compliance gaps. The two regimes were designed by different legislative workstreams, apply to different activities and impose different obligations – but they increasingly apply to the same underlying business.

Under MiCA, a CASP authorisation covers services such as custody of crypto-assets, operation of a trading platform, exchange between crypto-assets and fiat, and execution of orders. The EMI authorisation covers the issuance of e-money and the provision of payment services. Where a firm both issues EMTs and provides exchange services, it requires both authorisations. ESMA and the national competent authorities have made clear that MiCA's CASP authorisation does not exempt a firm from EMI obligations for the EMT issuance leg, and an EMI authorisation does not exempt a firm from CASP obligations for the crypto-asset services leg.

Outside the EU, the picture is more varied. In the AIFC (Astana International Financial Centre) in Kazakhstan, the AFSA (Astana Financial Services Authority) regulates digital-asset trading facilities and custody as distinct activities. A firm that also provides payment-related services may need to satisfy both a digital-asset regulatory permission and any applicable payment-services requirement under the AIFC framework. The AIFC operates under a common-law framework, which provides structural predictability for cross-border operators familiar with English-law concepts.

In Hong Kong, the SFC (Securities and Futures Commission) operates a VASP licensing regime for virtual-asset trading platforms, while payment-related activities are regulated separately. A multi-product firm operating in Hong Kong needs to disaggregate its activities and map each one to the relevant regulatory permission.

The structural lesson is consistent across jurisdictions: the EMI layer and the VASP or CASP layer are not interchangeable. They solve different regulatory problems, require different compliance architectures and are issued by different competent authorities. A firm that conflates them will be unlicensed for at least some of its activities, regardless of the quality of the licence it holds.

In a recent structuring matter, a payments-adjacent crypto firm had obtained EMI authorisation in an EU member state and was operating fiat-to-crypto conversion services for clients across several European markets. The firm had not obtained CASP authorisation for the exchange activity. Following a supervisory inquiry, the firm needed to restructure its entity model to separate the EMT issuance layer from the crypto-exchange activity and pursue the appropriate authorisation for the latter. We worked with the firm on the entity separation and the authorisation application, and the business continued operating during the transition period under a structured compliance remediation plan agreed with the relevant competent authority.

Which jurisdiction should host the EMI licence?

The choice of EMI jurisdiction is not a decision about prestige – it is a decision about operating fit, timeline and the specific user base the firm intends to serve. Different jurisdictions offer different combinations of authorisation speed, capital requirements, supervisory approach and passporting scope, and the right answer depends on the firm's specific circumstances.

For EU-facing businesses, the passporting advantage of an EMI authorisation in a member state is the decisive factor. Lithuania has historically offered a relatively accessible EU VASP and EMI entry point, with the Bank of Lithuania serving as the competent authority. Under MiCA's transition provisions, existing registered entities in EU member states are moving toward CASP authorisation, and the EMI authorisation track runs in parallel for the e-money activities. Malta's MFSA administers both the transitioning VFA framework and the EMI/payment-services regime, and firms that have established in Malta for the VFA route may be well-positioned to add EMI authorisation within the same jurisdiction.

For businesses primarily targeting markets outside the EU, the EMI-specific question becomes whether the fiat-payment activity is sufficiently significant to justify a dedicated EMI entity, or whether the relevant jurisdictions have payment-services frameworks that can be accessed through a different route. Singapore's MAS-regulated payment institution tracks, for example, are calibrated to volume thresholds rather than the EU's activity-based categorisation, and a firm with modest fiat throughput may qualify for a lower-tier payment institution status rather than the full major payment institution licence.

A decision matrix by operator profile:

Profile A – EU stablecoin issuer or fiat-gateway operator: EMI authorisation in an EU member state is the required instrument. The passporting mechanism enables EU-wide reach from a single authorisation. The key risk is the parallel requirement for CASP authorisation if the firm also provides crypto-asset services. Timeline to authorisation varies by member state and by the completeness of the application; expect a process measured in months rather than weeks for a full authorisation.

Profile B – Multi-jurisdiction exchange with fiat on-ramp and off-ramp: An EMI in the EU for the EU fiat layer, combined with jurisdiction-specific payment or money-transmission licensing in each additional market (UK, Singapore, UAE, US). The compliance cost is proportional to the number of markets. The structural risk is gaps in coverage where activity is occurring without the corresponding permission. Timeline and capital vary materially by jurisdiction and activity category; consult current legislation for each target market.

Profile C – Early-stage crypto firm seeking banking access: EMI status is frequently the most direct route to a segregated client-funds account and access to payment schemes. However, where the firm's primary activity is crypto-asset exchange or custody rather than e-money issuance, the EMI may be a supporting structure rather than the primary regulatory instrument. The firm may need the VASP or CASP authorisation first, with the EMI added to enable the fiat layer.

Profile D – Token issuer with EMT characteristics: If the token being issued is redeemable for fiat currency at par on demand, it is likely an EMT under MiCA. Issuance without EMI status in the EU is a regulatory breach from day one. The authorisation path for an EMT issuer is the EMI track, not the CASP track. Significant-EMT status carries additional obligations around reserve management, reporting and redemption rights.

If a prior EMI application stalled or a banking relationship was terminated, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com – or message us via t.me/oboluslaw. Map your options

AML, the Travel Rule and the compliance architecture

AML and Travel Rule obligations attach to both EMI and VASP activities, but the precise scope differs in ways that have material operational consequences for firms running both licensing tracks. Getting the compliance architecture right from the outset is significantly cheaper than retrofitting it after a supervisory inquiry.

Under the FATF Recommendations – specifically Recommendation 15 (virtual assets and virtual asset service providers) – VASPs are required to implement the Travel Rule, transmitting originator and beneficiary information with virtual-asset transfers above the applicable de-minimis threshold. That threshold varies by jurisdiction and is subject to current legislation in each market; consult the applicable regime for the precise figure. What does not vary is the underlying obligation: a VASP that moves assets between wallets without implementing Travel Rule controls is operating outside the FATF-aligned standard that most major regulators have now incorporated into national law.

An EMI, in parallel, is subject to the funds-transfer regulation applicable in its jurisdiction – in the EU, that means the Transfer of Funds Regulation, which imposes its own originator/beneficiary data obligations on payment transactions. The operational challenge for a firm holding both an EMI authorisation and a VASP or CASP authorisation is ensuring that the Travel Rule controls on the crypto-asset side are integrated with the payment-data controls on the fiat side into a coherent end-to-end compliance programme.

Regulators in the leading hubs increasingly expect to see this integration demonstrated at the point of application and through ongoing supervisory reporting. A firm that runs its fiat compliance infrastructure separately from its crypto compliance infrastructure – with no data bridge between the two – will struggle to satisfy the AML/CTF expectations of a sophisticated supervisor. In our practice, we advise firms to design the compliance architecture as a single system from the outset, with the regulatory permissions sitting above a unified transaction-monitoring and customer-due-diligence layer.

What are the most common structural mistakes in EMI licensing for crypto firms?

The most damaging structural mistakes in EMI licensing for crypto firms are not failures of intent – they are failures of sequencing and scope. A firm that applies for an EMI licence before resolving its corporate structure, its banking relationship and its crypto-asset regulatory status is building on an unstable foundation.

The first and most common error is treating the EMI licence as the licensing strategy rather than one component of a layered stack. A general counsel or founder who believes that an EMI authorisation covers all fiat and crypto activity has misread the regulatory perimeter. The error surfaces when a competent authority inquiry or a banking partner's due-diligence process asks for evidence of the crypto-asset regulatory permission – and there is none.

The second error is choosing the EMI jurisdiction on the basis of speed or cost alone, without assessing whether the resulting authorisation can support the firm's banking and operational needs. An EMI authorisation in a credible EU member state is worth more to a firm that needs EU banking access than an authorisation in a jurisdiction whose banking system is inaccessible to crypto firms. The licensing choice and the banking strategy need to be designed together.

The third error is failing to plan for the passporting notification process. Passporting within the EU is not automatic: it requires a notification to the home regulator and, in some cases, a notification to the host-state regulator. The timeline for that process varies, and a firm that assumes it can commence passported activity on the day of authorisation may be operating unlicensed in host states for a period while the notification process completes.

A common assumption is that an offshore EMI – in a jurisdiction outside the major regulatory hubs – provides a low-cost equivalent to an EU or UK EMI that is sufficient to serve clients globally. It does not. The offshore structure may be valid for the activities conducted in that jurisdiction, but it provides no regulated status for EU, UK, Singapore, UAE or US-facing activity. The compliance gap created by relying on an offshore EMI for global operations is often larger than the cost of the additional licensing that proper structuring would require.

Self-assessment checklist: do you need an EMI licence?

The following questions help identify whether an EMI authorisation is likely to be required as part of a crypto firm's licensing stack. They are not a substitute for tailored legal advice, but they identify the pressure points that counsel needs to assess.

  • Does the firm issue tokens that are redeemable for fiat currency at par on demand? If yes, those tokens are likely EMTs under MiCA and EMI authorisation is required for EU issuance.
  • Does the firm hold fiat funds on behalf of users prior to conversion or withdrawal? If yes, the firm is likely providing a payment service that requires a regulated permission in each jurisdiction where users are located.
  • Does the firm process payments between users in fiat currency? If yes, a payment-services licence or EMI authorisation is likely required in each relevant jurisdiction.
  • Is the firm's primary activity crypto-asset exchange, custody or brokerage rather than e-money issuance? If yes, the VASP or CASP authorisation is the primary requirement, and the EMI question is secondary – though it may still arise for the fiat-handling layer.
  • Does the firm intend to operate across multiple EU member states? If yes, an EMI authorisation in a single EU member state with passporting rights is structurally more efficient than separate registrations in each state.
  • Has the firm been declined banking services on the basis of its regulatory status? If yes, the banking problem may be solvable through EMI authorisation – but only if the underlying crypto-asset activities are themselves properly licensed.

Operators we advise regularly discover through this checklist that they need at minimum a VASP or CASP authorisation alongside any EMI, and in some cases they need both before a credible bank will accept the business as a customer.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline varies materially by jurisdiction, licence category and the completeness of the application at submission. In leading EU member states, a CASP authorisation under MiCA is a process measured in months; a pre-MiCA VASP registration in the same jurisdiction may have been faster. In Singapore, MAS applies a rigorous review process for Payment Services Act licences; timelines are typically measured in several months to over a year depending on the licence tier and the complexity of the business. Applications submitted with incomplete documentation or unresolved AML/KYC gaps take significantly longer. In our experience, the single most effective way to reduce timeline is to resolve corporate structure, beneficial ownership and compliance programme questions before the application is filed.

Which jurisdiction is best for licensing my crypto business?

There is no universally correct answer. The right jurisdiction depends on the firm's specific activity mix, its target user base, its banking needs and its capital position. A firm issuing EMTs for EU users needs an EU EMI authorisation. A firm operating a trading platform for professional clients in the Gulf may prefer VARA in Dubai or FSRA in Abu Dhabi. A firm targeting institutional clients in Asia may prioritise MAS in Singapore or the SFC in Hong Kong. The licensing choice and the banking strategy need to be designed together. A licence in a jurisdiction whose banking system does not serve crypto firms produces limited operational benefit. We map the full stack – licence, banking and tax – before a client commits to a domicile.

Do I need a separate custody licence?

In most leading jurisdictions, yes – custody of third-party crypto-assets is a separately regulated activity that requires its own regulatory permission. Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct CASP activity. It is not covered by an EMI authorisation and is not bundled automatically into an exchange or trading-platform authorisation. In Singapore, custody of digital payment tokens engages the Payment Services Act framework as a separate regulated activity. In the UAE, VARA addresses custody as a distinct activity under its rulebook. A firm that custodies client assets without the relevant permission is operating outside the regulatory perimeter in most flagship regimes. The practical answer is to map each activity against the applicable regime before committing to a structure.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and where a recovery matter is live, we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in EMI and VASP licensing structuring for multi-jurisdictional digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours