A token-issuer preparing to serve European retail customers, or a digital-asset exchange routing fiat settlements across the eurozone, faces the same immediate legal question: which payment authorization does the business need, in which member state, and what does that mean for its banking relationships the day the licence lands? Operating without the right authorization exposes the business to enforcement action, frozen settlement rails and the loss of the correspondent accounts that keep revenues moving. That risk is not theoretical. Regulators in the European Union are accelerating their supervision of payment institutions that touch crypto flows, and the MiCA (Markets in Crypto-Assets Regulation), administered by ESMA and the national competent authorities, has sharpened every jurisdiction's appetite to act.
Payment institution licensing in the EU under MiCA sits at the intersection of two overlapping regimes: the long-established payment-services framework and the newer CASP (Crypto-Asset Service Provider) authorization that MiCA introduces. A business handling fiat legs of crypto transactions typically needs both. This page sets out the regulated basis, the practical process for an inbound operator, the cross-border interaction with banking and tax, and the moment at which specialist counsel should be engaged.
What the EU payment regime covers for digital-asset businesses
The EU's payment services regime and the MiCA CASP authorization are distinct instruments that frequently apply to the same business simultaneously. A crypto exchange settling in euros is a payment institution for its fiat leg and, once MiCA applies, a CASP for its crypto activities. ESMA and the relevant national competent authority each have supervisory reach, and both expect the operator to hold the correct authorization for every regulated activity it performs.
The payment-services side covers execution of payment transactions, money remittance, account information and payment initiation. For a digital-asset operator, the most common trigger is the receipt, holding and transmission of client funds in fiat. That activity requires either a payment institution licence or, where the volumes and product scope justify it, a full electronic money institution authorization. The difference matters for safeguarding obligations, capital requirements and the products the entity may offer.
MiCA adds a second layer. Any business offering crypto-asset services in the EU – exchange, custody, transfer, advisory, portfolio management – requires a CASP authorization. The two authorizations travel together for most exchanges and crypto payment processors. In our practice, we regularly advise operators who discover mid-build that their structure requires three separate regulatory touchpoints: a payment institution licence in the chosen member state, a CASP authorization with a ESMA-coordinated NCA, and an AML registration or approval tied to both.
Who needs a payment institution licence in the EU?
Any business that receives, holds or transmits client funds as part of a digital-asset service – without being a credit institution – needs a payment institution authorization if it operates in the EU or directs services to EU-resident customers. The test is functional, not formal: the name on the entity or the marketing language is irrelevant. What matters is whether the activity, viewed objectively, constitutes a regulated payment service.
Common trigger scenarios we see include: a stablecoin issuer that holds euro reserves and processes redemptions; a crypto exchange that maintains euro wallets for clients; a payments processor converting fiat to crypto on behalf of merchants; and a DeFi protocol that operates a fiat on-ramp through a legal entity. In each case, the fiat-handling element independently triggers payment institution obligations, regardless of how the crypto activity is characterized.
The AUDIENCE_MYTH we encounter consistently is that a single offshore licence – in a jurisdiction with light-touch supervision – is sufficient to serve EU customers at scale. It is not. MiCA's passporting regime operates from EU authorizations only. A BVI or Cayman registration carries no recognition inside the single market. An operator directing services to EU residents without the correct authorization faces enforcement in the member states where those residents are located.
How does the MiCA CASP authorization interact with payment institution licensing?
MiCA's CASP authorization covers crypto-asset services but does not replace or subsume payment institution obligations for fiat activity. The two regimes run in parallel. ESMA, through its coordination role, has been explicit that a CASP authorization does not grant payment-services permissions, and national competent authorities have confirmed that a payment institution licence does not extend to crypto-asset activities.
This parallel structure creates a sequencing question. In our cross-border practice, we have seen operators attempt to obtain the CASP authorization first, on the assumption that the payment licence would follow quickly. In several cases, the chosen member state's NCA required evidence of a parallel payment authorization – or at minimum a credible timeline to obtain one – before it would progress the CASP application. The safest approach is to map both authorization timelines together and, where possible, run the applications in parallel from day one.
Passporting under MiCA is a significant commercial benefit. A CASP authorized in one member state may notify other EEA states and begin offering services there without a fresh authorization. The same principle applies to payment institutions under the payment services framework. A business that structures its EU entry around a single well-chosen member state can reach the entire single market through a pair of notifications rather than 27 separate applications.
The choice of home member state is the single most consequential decision in EU market entry for a digital-asset operator. It determines the regulatory culture the business lives with, the timeline to authorization, the capital treatment, the depth of NCA engagement during supervision, and the practicality of banking. Operators we advise routinely spend more time on member-state selection than on any other single element of the structure.
What is the application process for EU payment institution licensing?
The application process for a payment institution licence in an EU member state follows a broadly common structure, though the administrative process, the depth of review and the timeline vary by jurisdiction. Every application involves an initial completeness check, a substantive review period, and a decision by the national competent authority. In parallel, AML fitness is assessed, often by the same authority or a dedicated financial intelligence unit.
A well-prepared application package for a payment institution will typically include: a detailed business plan with financial projections; a description of the payment services to be provided and the technical architecture supporting them; governance documentation including organizational charts and board composition; individual fitness-and-propriety documentation for all key function holders; a program of operations; and a safeguarding methodology demonstrating compliance with client-money obligations.
For a digital-asset operator, the business plan must explicitly address the crypto-related activities and explain how the regulated and unregulated elements are operationally separated. NCAs in the major EU financial centers – particularly those experienced with fintech applications – will scrutinize the technology stack, the AML controls and the safeguarding arrangements with greater depth than a standard payments applicant faces. The review timeline varies. In our experience advising businesses through EU applications, a professionally prepared application typically moves from submission to decision in a matter of months, though more complex structures or under-resourced NCAs can extend that materially.
A common mistake at this stage is submitting an application before the governance structure is complete. Some operators believe they can finalize director appointments, shareholder structures and local substance requirements after submission. NCAs treat an incomplete governance picture as a fundamental deficiency, and applications stall as a result. The governance must be real and fully documented before the file goes in.
CTA #1The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis substantially. A payment institution application embedded in a broader MiCA CASP structure requires a coordinated approach from day one. To map the authorization sequence for your EU build, contact OBOLUS at info@oboluslaw.com.
What does client-money safeguarding require for payment institutions?
Client-money safeguarding is a hard requirement for payment institutions holding customer funds, and it is an area where digital-asset operators frequently underestimate the operational burden. The payment services framework requires that client funds received be segregated from the institution's own funds and protected in the event of insolvency. This is not a disclosure requirement – it is a structural and operational obligation.
The two main methods are segregation in a dedicated account with a credit institution, or coverage by an insurance policy or guarantee from a credit institution or insurer. For a digital-asset payment institution, the challenge is practical: many credit institutions are unwilling to open safeguarding accounts for entities with significant crypto exposure. The account-opening problem and the safeguarding requirement interact in a way that can block the entire EU entry plan if not addressed early.
In our practice, we regularly see operators who obtained a payment institution licence but could not operationalize it because no bank would open the required safeguarding account. The licence and the bank account must be planned together, not sequentially. This is the reason our engagement on EU payment licensing always includes a parallel review of the banking strategy before the application is submitted.
How does EU payment licensing interact with banking and tax across borders?
For a business operating across the EU payment institution and MiCA CASP regimes, the cross-border tax and banking picture is complex. A payment institution in member state A, passporting into member states B through Z, will typically be subject to corporate tax in state A on its EU-wide profits, but may face withholding tax, VAT registration obligations or permanent establishment risk in states where it has staff, servers or material commercial activity.
The interaction between the payment institution and its banking relationships is particularly sensitive. Correspondent banks and e-money institution partners perform their own due diligence on the payment institution's client base. A payment institution serving crypto exchanges will face heightened KYC requirements from its banking partners, and in some cases a refusal to provide settlement accounts. This is not a compliance failure by the payment institution – it reflects the risk appetite of the correspondent bank – but it is a practical constraint that must be addressed in the business model.
Transfer-pricing considerations apply where the payment institution is part of a group. If the group operates a custody entity, a CASP entity and a payment institution in different member states or third countries, the intra-group arrangements need to reflect arm's-length pricing. Regulators and tax authorities in the major EU centers have become sophisticated at identifying structures where service fees or intercompany arrangements erode the tax base of the licensed entity.
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer, derived from the FATF Recommendation 15) applies to VASPs operating alongside or within the EU payment structure. A crypto-asset transfer from the CASP entity that settles via the payment institution triggers Travel Rule obligations on the VASP side and standard payment-message obligations on the payment side. The two data flows must be reconciled in the compliance architecture.
CTA #2If a prior EU application stalled, an account was closed or a passporting notification was rejected, a second read of the structure often surfaces the underlying reason. In many cases the fix is architectural rather than regulatory. To discuss the route back, write to OBOLUS at info@oboluslaw.com.
Decision point: which operator profile should choose which EU path?
Not every digital-asset operator needs a payment institution licence as its primary EU authorization. The right entry path depends on the business model, the client base, the product and the timeline.
Profile A – a crypto exchange with a significant fiat settlement volume and retail EU clients – should seek a payment institution licence in a member state with fintech depth and NCA familiarity with crypto applications, run in parallel with a CASP notification. The timeline to full EU-wide operability will span months from a clean starting position. The key risk is safeguarding-account access.
Profile B – a pure crypto-asset service provider that does not hold client fiat – needs a CASP authorization only. It should select the home member state based on NCA quality, timeline and local substance requirements. The payment institution question may not arise unless the business model evolves.
Profile C – an e-money or stablecoin issuer whose token constitutes an EMT (e-money token) under MiCA – requires an EMI authorization (not just a payment institution licence) as well as the relevant MiCA issuer authorization. The capital and governance requirements for an EMI are higher than for a payment institution. The timeline is correspondingly longer.
Profile D – a business already licensed in a third country, such as a Singapore MAS-licensed DPT service provider or a VARA-licensed Dubai exchange – needs fresh EU authorizations before it can serve EU clients. Third-country licenses carry no recognition in the EU market. Allied counsel in the relevant jurisdiction can coordinate the outbound documentation, but the EU applications must be driven by EU-admitted counsel.
In a recent matter, a payments technology company operating under a Southeast Asian regulatory authorization sought to expand into the EU. The company had assumed its home-country licensing would accelerate the EU process. We established that the EU required a fresh payment institution application and a parallel CASP notification in the chosen member state, with local substance requirements including a resident compliance officer. The structure was reorganized before submission, the applications were filed simultaneously, and the business reached EU-wide operability within the projected window. No figures are attributed to this matter.
What is the AML and Travel Rule posture under MiCA?
AML obligations for EU payment institutions and MiCA CASPs are strict and have been reinforced by successive EU anti-money-laundering directives and, now, the EU's dedicated AML authority – the AMLA (Anti-Money Laundering Authority), whose direct supervisory reach is expected to extend to certain crypto-asset service providers designated as high-risk. The applicable VASP provisions under the EU's transfer-of-funds regulation extend the Travel Rule to crypto-asset transfers, requiring that originator and beneficiary information travel with every transaction above the applicable threshold.
For a payment institution that is also a CASP, the AML architecture must address two regulatory populations simultaneously: the payment-services supervisor focused on fiat flows, and the crypto-asset supervisor focused on on-chain activity. A single integrated AML policy is possible, but the risk appetite, the transaction monitoring parameters and the reporting obligations differ enough that the policy must be drafted with both supervisors in mind.
Regulators in the leading EU hubs increasingly expect evidence of a tested transaction-monitoring system before authorization is granted, not a statement of intent to implement one. A business that presents an AML policy without a functioning monitoring tool – or that relies on a third-party provider without a demonstrated integration – will face questions that extend the review timeline.
Related at OBOLUS
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital-Asset Businesses – full practice overview covering payment institution, EMI and CASP authorization across the EU and beyond.
- Corporate Bank Account Opening for Established Operators – how to open and maintain banking for a licensed digital-asset business when standard routes are closed.
- Crypto Holding Structure for Institutional Clients – tax-efficient holding and treasury structures for institutions with significant digital-asset positions.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of risk-appetite misalignment, not legal prohibition. Most major credit institutions apply correspondent-banking restrictions that treat crypto-exposed clients as high-risk by default. The practical triggers include: the nature of the counterparties (exchanges, custodians, unhosted wallets), AML compliance gaps visible in the account history, and pressure from the bank's own regulators to reduce crypto exposure. A licensed and well-documented payment institution is better positioned than an unlicensed operator, but licensing alone does not guarantee account retention. The structure, the client base and the compliance evidence all factor into the bank's decision.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) seeking to onboard with an EMI must present a regulatory and compliance picture that meets the EMI's own AML obligations. In practice, this means providing its regulatory authorization, a clear description of its business model, its AML policy and the identity of its beneficial owners. EMIs subject to MiCA and EU AML requirements must conduct their own risk assessment of VASP clients and may apply enhanced due diligence. A VASP that holds a recognized authorization – a MiCA CASP, a MAS licence or a comparable credential – is materially easier to onboard than an unregistered operator. The documentation package should be prepared before approaching the EMI.
What does client-money safeguarding require?
Client-money safeguarding for an EU payment institution requires that funds received from customers be held separately from the institution's own funds and protected against insolvency claims. The two principal methods are a segregated account with an authorized credit institution, or an insurance policy or bank guarantee of equivalent coverage. The institution must reconcile the safeguarded amount against client liabilities on a regular basis. For digital-asset operators, the practical challenge is finding a credit institution willing to open a safeguarding account for a crypto-exposed entity. This must be resolved before or in parallel with the licence application, not after it.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the entirety of our practice. We map the licence, banking and compliance stack across operating, custody and payment layers before you commit – not after a problem surfaces. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specializes in EU regulatory authorization strategy for digital-asset operators, including MiCA CASP and payment institution licensing across multiple member states.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.