An electronic money institution (EMI) licence — an authorisation to issue electronic money and provide payment services — has become one of the most contested instruments in digital-asset business structuring. Crypto exchanges, stablecoin operators and wallet providers ask whether an EMI licence covers their activities, supplements a VASP (virtual asset service provider) authorisation, or creates a second regulatory obligation they did not anticipate. The answer turns on what the business actually does, where it does it, and where its users sit — not on the label it applies to itself.
With VASP supervision tightening across the major hubs and the EU's MiCA (Markets in Crypto-Assets Regulation) drawing a sharper boundary between crypto-asset service provision and e-money issuance, the EMI question has become urgent for any operator holding fiat balances on behalf of users, issuing a stablecoin pegged to a single currency, or settling transactions through a payment account. Operating in the wrong category — or in no category at all — risks enforcement action, the loss of banking relationships and the kind of platform shutdown that is very difficult to reverse.
This analysis maps the legal lines between EMI authorisation and VASP registration, identifies the scenarios where both are required, and examines how the cross-border reality of digital-asset business reshapes the analysis for operators sitting between multiple regimes.
What EMI Licensing Actually Covers for a Crypto Firm
An EMI licence authorises its holder to issue electronic money and, in most regimes, to provide a defined list of payment services — it does not, of itself, authorise the firm to deal in, exchange or custody crypto-assets. The distinction matters immediately. A crypto exchange that holds user fiat balances in a pooled account and allows those balances to be used for buying and selling digital assets is performing a function that, in virtually every leading EU jurisdiction under the applicable payment services rules, resembles e-money issuance or at minimum payment account management. Whether it triggers a formal EMI authorisation requirement depends on the structure of the liability — specifically, whether users have a claim against the firm for redemption of their fiat balance at par.
Under MiCA, the line is drawn with new precision. An asset-referenced token (ART) that references a basket of assets is authorised under MiCA. An e-money token (EMT) — a stablecoin pegged to a single official currency — must be issued either by an authorised credit institution or by a licensed EMI. That classification alone means that any operator planning to issue a euro-pegged or dollar-pegged stablecoin inside the EU/EEA cannot rely on a CASP (Crypto-Asset Service Provider) authorisation alone; the EMI regime sits alongside it as a mandatory layer.
In our practice, the first question we ask when a client describes its fiat handling is whether the business model creates a stored-value liability. If it does, the EMI analysis begins immediately — regardless of the crypto wrapper around it.
For a scoped assessment of whether your fiat-handling model triggers EMI authorisation requirements, contact OBOLUS at Map your options. The process above describes the standard analytical path. Your facts — the entity's home jurisdiction, the nature of your user balances, the currency peg if any — change the analysis materially.
Where Do the VASP and EMI Regimes Overlap?
The VASP and EMI regimes overlap wherever a crypto firm accepts fiat, holds it on account and converts it into or out of digital assets on user instruction — which describes the core mechanics of most centralised exchanges. The VASP authorisation governs the crypto-side of that transaction; the EMI authorisation (or an exemption from it) governs the fiat-side. Both can apply simultaneously, and the failure to hold the second is not excused by holding the first.
Regulators in the leading hubs increasingly apply an activity-based analysis rather than a name-based one. VARA in Dubai structures its licensing precisely around defined activities — exchange, transfer, custody, lending, advisory — and an operator needs a separate authorisation for each activity it conducts. The FSRA within ADGM takes a comparable approach: an operator seeking to handle both crypto and fiat payment flows may need to satisfy requirements under both the virtual-asset framework and the payment-services regime. The FCA in the United Kingdom applies a similar duality: a firm may hold cryptoasset registration under the Money Laundering Regulations while simultaneously requiring FCA authorisation under the Payment Services Regulations for its fiat-side business.
Three scenarios in our cross-border practice consistently generate dual-licensing risk:
- A centralised exchange with a crypto/fiat order book that credits user fiat balances between trades.
- A wallet provider that allows users to top up via bank transfer, hold a fiat balance and spend it through a card programme.
- A stablecoin issuer targeting EU retail users with a single-currency peg.
In each case, a single VASP or CASP authorisation is structurally insufficient. The operator must map both the crypto-side and the fiat-side activity, identify the applicable regimes in each jurisdiction where it operates or has users, and determine whether exemptions or de-minimis thresholds apply — before it goes live, not after.
EMI Licence Categories — and Which Operator Profile Needs Which
Most EMI regimes distinguish between a full EMI authorisation and a lighter registration track, often called a "small EMI" or "limited-activity" tier, which applies below a defined transaction-volume threshold. The MiCA-era EU regime sits alongside existing payment-services frameworks; an operator authorised as a CASP that also issues EMTs must hold the EMI authorisation that meets the requirements set out in the applicable e-money rules — the CASP licence does not substitute for it.
A useful decision matrix for operators runs as follows:
Profile A — Crypto exchange, fiat on-ramp, no stablecoin issuance. This operator needs a VASP or CASP authorisation for its crypto activities. If it holds user fiat balances — even briefly between trades — it should obtain legal advice on whether those balances constitute e-money under the applicable payment-services rules. In many EU member states, the answer is yes. The timeline for a full EMI authorisation in the EU varies by member state and is typically measured in months; a "small EMI" registration can be faster but carries volume caps that may constrain growth.
Profile B — Stablecoin issuer, single-currency peg, EU retail distribution. Under MiCA, this operator is issuing an EMT and must hold an EMI authorisation as a precondition to issuance. No amount of CASP licensing covers this requirement. The authorisation must be in place before the token is issued to the public. The capital and reserve requirements are set by the applicable EMT provisions of MiCA and the underlying e-money rules.
Profile C — Crypto-native wallet with a card-spending feature. This operator sits squarely in dual-licensing territory. The wallet's crypto custody function may require a CASP/VASP authorisation; the card programme, the fiat top-up facility and the payment-account management function almost certainly require payment-institution or EMI authorisation. In this profile, the sequencing of licence applications matters — banking relationships for the EMT reserve account may depend on the CASP authorisation already being in place, and vice versa.
Profile D — Offshore exchange serving EU users from outside the EU. MiCA's passporting regime requires a CASP authorisation from a member state to serve EU clients legally at scale. An offshore EMI licence does not substitute for that authorisation. The operator must decide whether to obtain EU CASP authorisation, restrict EU users or accept the enforcement risk — the last option is not a legal strategy.
The Cross-Border Reality: Why One Licence Is Never Enough
A common assumption among early-stage founders is that a single offshore VASP registration or EMI licence in a permissive jurisdiction covers their global user base. It does not. The cross-border reality of digital-asset business is that the legal obligation follows the user — and in most cases, the obligation to hold a local authorisation is triggered by servicing residents of that jurisdiction, not by being incorporated there.
MiCA's passporting mechanism illustrates the point well. A CASP authorised in, say, Lithuania by the Bank of Lithuania may passport its services across the EU/EEA. That is a genuine and commercially valuable right. But MiCA's passporting covers CASP activities only; it does not extend an EMI authorisation granted elsewhere, and it does not substitute for local payment-services registration where that is separately required. An operator that uses its Lithuanian CASP passport to serve German retail users while also holding their fiat balances must separately satisfy the EMI or payment-institution requirements applicable to those balances.
Outside the EU, the fragmentation is more acute. MAS in Singapore requires a Digital Payment Token (DPT) service licence under the Payment Services Act; that framework is distinct from any EMI-equivalent authorisation and must be assessed separately for operators with Singaporean users or a Singapore-incorporated entity. The SFC in Hong Kong operates a VASP licensing regime for virtual-asset trading platforms; a separate analysis applies to any stablecoin issuance or payment-account activity. VARA in Dubai requires activity-specific authorisation; operating a transfer/settlement activity requires a separate licence from operating an exchange. In each case, the operative question is not "where is the company incorporated?" but "what activities does it perform, and where are the people affected by those activities?"
Operators we advise routinely underestimate the jurisdictional reach of their user base at launch. A mobile-first exchange that goes live with 100,000 users in its first month will have users in dozens of jurisdictions — several of which may require local registration before day one.
AML and Travel Rule Obligations Straddle Both Regimes
Both the EMI regime and the VASP regime carry AML/CFT obligations, and for a firm holding both authorisations, those obligations interact. The Travel Rule — the obligation, drawn from FATF Recommendation 15, to pass originator and beneficiary data with a virtual-asset transfer — applies to the VASP activity. The payment-services AML rules apply to the EMI activity. For an operator sitting across both frameworks, the compliance architecture must address both.
In practice, this creates a systems and policy challenge. The Travel Rule data requirements for crypto transfers sit in a different part of the transaction flow from the payment-services KYC requirements for fiat account opening. A firm that holds both authorisations must ensure its compliance infrastructure captures both — and that its policies, training and monitoring cover the full activity set, not just the primary business line.
We have seen enforcement action proceed under the AML framework in cases where a firm held a VASP registration but treated its fiat-account side as an unregulated adjunct. Regulators do not accept that characterisation. Where the fiat activity meets the definition of e-money issuance or payment-account management, the AML rules applicable to that activity apply in full — regardless of whether the firm holds the EMI authorisation it should.
Allied counsel in the relevant jurisdiction can advise on the specific AML programme requirements that apply to an operator's full activity set, including the interaction of Travel Rule obligations with payment-services customer due-diligence rules.
Where EMI Licence Applications Stall — and Why
EMI licence applications for crypto firms stall at two consistent points: the business-model analysis and the safeguarding/reserve documentation. Both reflect the same underlying issue — the applicant has not mapped its activity with sufficient precision before approaching the regulator.
On the business-model side, regulators require a clear articulation of what the firm does with user fiat from the moment of receipt to the moment of conversion or withdrawal. A crypto firm that describes its fiat handling in generic terms — "we hold funds on behalf of users" — will face follow-up requests that can extend the review process by months. The regulator wants to know whether the fiat balance represents e-money, a payment account, a client money arrangement or something else entirely. Each characterisation has different capital, safeguarding and conduct-of-business implications.
On the safeguarding side, an EMI authorisation requires the holder to segregate or insure the electronic money it issues. For a crypto firm whose primary banking relationship is a crypto-friendly neobank or an offshore correspondent, demonstrating that the safeguarding arrangement meets regulatory expectations is often the hardest part of the application. The regulator will want to see the bank account structure, the account agreement and evidence that the safeguarding bank itself meets the applicable standards. This is where the banking and licensing workstreams converge — and why we structure them as a single mandate rather than two separate projects.
A practical note on sequencing: in several EU member states, the regulator will not begin substantive review of an EMI application until the applicant has a confirmed banking arrangement for its safeguarding account. The bank, in turn, often wants to see progress on the licence application before it will open the account. Breaking that circular dependency is a project management challenge as much as a legal one.
If a prior EMI or VASP application has stalled at the business-model or safeguarding stage, a second read can surface the structural reason and the route through. Write to OBOLUS at Map your options.
Micro-Matter: Dual Licensing for a Fiat-Enabled Wallet
In a recent licensing matter, a payments company sought to launch a crypto wallet with a built-in euro fiat balance and a card-spending feature across several EU member states. The company held a preliminary CASP authorisation from a Baltic member-state regulator but had not assessed its EMI exposure. On review, the fiat-balance and card-spending functions clearly constituted e-money issuance and payment-account management — both requiring EMI authorisation. We restructured the entity architecture to separate the EMI activity into a purpose-built entity, coordinated the CASP and EMI applications in parallel with the regulator, and identified a safeguarding bank willing to open accounts on the basis of the combined application. The client went live within the projected timeline, with both authorisations in place before its first fiat deposit was received.
How the Decision to Hold an EMI Licence Affects Tax and Banking
An EMI authorisation is not just a regulatory instrument — it has material consequences for the firm's tax position and banking access that must be assessed at the structuring stage, not after the licence is granted.
On banking, an EMI licence typically improves access to correspondent banking relationships because the firm is a regulated entity with defined safeguarding obligations. That is a genuine commercial advantage for a crypto firm that has struggled to maintain fiat rails. However, the EMI entity must maintain its safeguarding account with an institution that meets the applicable standards, and those institutions may themselves apply enhanced due-diligence requirements to an EMI whose underlying business is crypto. The banking stack must be stress-tested before the licence application is filed, not after it is granted.
On tax, an EMI authorisation can affect the VAT treatment of the firm's services. In the EU, payment services supplied by an EMI are generally exempt from VAT under the applicable exemption provisions; crypto-exchange services may be treated differently depending on the jurisdiction and the nature of the service. Where a firm holds both a CASP and EMI authorisation, the VAT treatment of its income streams may need to be allocated between the two, with implications for input-tax recovery and pricing. Lydia Brennan, OBOLUS's Tax and Structuring Analyst, regularly works through this interaction for clients structuring their licence and entity stack.
The cross-border tax picture adds further complexity. An operator authorised in Lithuania that passports into Germany and France may face different VAT characterisations in each member state for nominally identical services. The safeguarding account may sit in a third jurisdiction. Transfer-pricing rules apply to intra-group service fees. These are not hypothetical issues — they are live questions that arise in virtually every EU-passport structure we advise on.
Does a Single Offshore Licence Really Cover Global Operations?
A common assumption in early-stage digital-asset businesses is that a well-chosen offshore registration — a BVI VASP registration, a Cayman VASP Act filing or a Seychelles equivalent — constitutes a sufficient licence stack for a global operation. That assumption is incorrect, and acting on it carries serious consequences.
The BVI FSC's VASP Act and CIMA's Virtual Asset regime are legitimate regulatory frameworks with real compliance requirements. Neither is designed to, nor legally capable of, substituting for a local authorisation in a jurisdiction where a firm actively solicits or services residents. MiCA's reverse solicitation exemption — which allows EU residents to approach a third-country firm on their own initiative — is narrow, fact-specific and not a general licence substitute. The FCA's position on unregistered firms marketing to UK consumers is unambiguous. MAS has taken enforcement action against firms operating DPT services without the requisite Singapore authorisation.
An offshore structure can play a legitimate role in the licence stack — as the holding entity, as the entity serving users in non-regulated or lower-risk jurisdictions, or as the fund-management entity above the operating companies. But an offshore entity cannot be the operator for a business that materially serves residents of regulated markets without also holding the authorisations those markets require.
In our practice, we map the user geography, the entity structure and the activity set simultaneously. Where the map reveals a gap — an activity performed in a jurisdiction without the required authorisation — we identify whether the fix is a new licence, a structural separation, or a restriction on user onboarding. All three options have cost and time implications. The earlier that mapping is done, the lower the cost of the correction.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – an overview of the full licensing practice, including VASP, CASP and payment-services authorisations across 70+ jurisdictions.
- Crypto Exchange Licensing: A Cross-Border Perspective – analysis of exchange-specific licensing across the EU, UAE, Singapore, Hong Kong and the UK.
- EMI Licence for Crypto Firms: A Guide for Early-Stage Founders – practical guidance on the EMI application process for founders at the pre-authorisation stage.
FAQ
How long does a crypto licence take to obtain?
Timelines vary significantly by jurisdiction and licence type. A VASP registration in an offshore centre may be completed in a matter of weeks. A full CASP authorisation in an EU member state under MiCA, or an EMI authorisation in a major EU jurisdiction, is typically measured in months and depends heavily on the completeness of the application, the regulator's current workload and whether a pre-application engagement process is available. Banking and safeguarding documentation is often the longest-lead item. Early engagement with the regulator, a complete application file and a confirmed banking arrangement are the most reliable ways to compress the timeline.
Which jurisdiction is best for licensing my crypto business?
There is no single answer. The right jurisdiction depends on your activity set, your target user geography, your banking requirements, your investors' expectations and your tax position. An EU CASP authorisation with passporting rights suits operators targeting European retail or institutional clients. VARA in Dubai suits operators seeking an onshore UAE presence with clear activity-based rules. MAS in Singapore suits operators targeting Southeast Asian institutional flows. For most businesses, the optimal structure involves more than one jurisdiction — typically an operating entity in a primary licensed hub and a holding structure that reflects the firm's tax and investor requirements.
Do I need a separate custody licence?
In most leading regimes, custody of digital assets on behalf of third parties is a regulated activity requiring its own authorisation or a specific inclusion within an existing licence. Under MiCA, custody and administration of crypto-assets is a defined CASP activity; a CASP that provides custody services must be expressly authorised to do so. VARA treats custody as a separate licence activity. MAS and the SFC in Hong Kong take comparable positions. An exchange licence or a VASP registration does not automatically cover custody services. Where a business intends to hold client assets — particularly for institutional clients — the custody question must be addressed at the application stage.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit — and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Lydia Brennan, Tax & Structuring Analyst — specialising in the tax and regulatory interaction of EMI and VASP licensing for cross-border digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.