For a virtual asset service provider (VASP) building fiat rails into the EU, Lithuania has long been the jurisdiction of first call. The Bank of Lithuania's supervisory posture, the country's position inside the EU single market, and the relative speed of the electronic money institution (EMI) onboarding process made it a practical gateway for crypto businesses that needed euro accounts, SEPA access, and a regulated counterpart willing to bank them. With the Markets in Crypto-Assets Regulation (MiCA) now in force across the EU, the requirements have sharpened – and operating without the right licence risks enforcement action, frozen payment rails, and the loss of the banking relationship the whole structure depends on.
This page sets out the legal basis for EMI onboarding in Lithuania, the process a VASP follows to qualify, the cross-border interactions that alter the analysis, and the decision point at which outside counsel becomes essential.
Why Does Lithuania Remain a Preferred EMI Onboarding Gateway for VASPs?
Lithuania provides one of the most developed EMI ecosystems in the EU, and that makes it a practical first port of call for VASPs that need compliant fiat infrastructure before their own CASP authorisation is complete. The Bank of Lithuania supervises both the VASP/CASP licensing regime and the EMI sector, which means a single regulator holds visibility over both sides of the relationship. That structural coherence matters: an EMI operating under the Bank of Lithuania's framework has clear guidance on what a VASP customer looks like, how to assess it, and what ongoing monitoring is expected.
The EU passporting principle compounds the value. An EMI authorised in Lithuania can provide payment services across all EU and EEA member states without requiring a separate licence in each. For a VASP with a pan-European user base, that reach is commercially significant. The alternative – building banking relationships in multiple jurisdictions simultaneously – is slower, costlier, and harder to manage from a compliance perspective.
In our cross-border practice, we regularly advise VASPs that treat the Lithuanian EMI relationship as the cornerstone of their EU payment stack. The onboarding process is more demanding than it was before MiCA, but it remains achievable for well-prepared operators. The question is what "well-prepared" actually requires.
MiCA introduces a CASP authorisation requirement for entities providing crypto-asset services in the EU. For a VASP seeking EMI onboarding in Lithuania, that creates a sequencing question: does the EMI relationship come before or after the CASP authorisation? Most Lithuanian EMIs will require at minimum a credible MiCA application in progress, and many require authorisation or a near-final file before they will proceed to full account opening.
What Does a Lithuanian EMI Actually Assess When Onboarding a VASP?
A Lithuanian EMI assesses a VASP applicant across four broad dimensions: regulatory standing, AML/CFT infrastructure, business model risk, and ultimate beneficial ownership. Each dimension carries its own documentary burden, and gaps in any one of them will stall the process.
On regulatory standing, the EMI will want to see the VASP's current licence status – whether that is an existing registration under the pre-MiCA VASP regime, a pending CASP application, or authorisation already in hand. An entity with no regulatory footprint in any recognised jurisdiction faces the highest friction. An entity with a CASP authorisation in an EU member state, or an equivalent from a regime the EMI recognises (such as the Financial Conduct Authority in the UK, the Monetary Authority of Singapore, or the VARA regime in Dubai), will typically move faster through initial screening.
On AML/CFT infrastructure, the EMI is effectively stress-testing the VASP's compliance programme. This means reviewing the AML policy, the transaction monitoring approach, the Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer) implementation plan, and the sanctions screening procedures. Lithuanian EMIs operate under the Bank of Lithuania's AML supervision and are directly accountable for the quality of their customer base. A VASP that cannot demonstrate a functional Travel Rule solution will not complete onboarding.
Business model risk is assessed through the product description, the projected transaction flows, the jurisdiction from which clients are sourced, and the mix of fiat and on-chain activity. Retail-facing exchanges with high transaction volumes attract more scrutiny than institutional or B2B operators. The EMI will want to understand the highest-risk elements of the business – custody of customer funds, OTC operations, DeFi-adjacent activity – and will price that risk into the scope of ongoing monitoring.
Ultimate beneficial ownership documentation follows standard CDD requirements: certified corporate documents, a full ownership chain to the natural-person UBOs, source of funds, and in most cases a management interview.
For a scoped assessment of your EMI readiness ahead of the application, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the existing regulatory position, the banking history – change the analysis materially.
How Does the Cross-Border Structure Affect EMI Onboarding Prospects?
The majority of VASPs seeking Lithuanian EMI onboarding are not purely Lithuanian businesses. The typical structure involves an operating entity incorporated in Lithuania or another EU member state, a parent or holding company in an offshore or third-country jurisdiction, and a user base that spans multiple regions. That multi-layer structure is legitimate, but it creates friction at the EMI's due diligence stage unless it is documented with care.
The first cross-border issue is the jurisdictional reach of the EMI account. A Lithuanian EMI account is designed for EU-regulated activity. Using it to settle transactions with customers in jurisdictions that require local licensing – the United States, for example, where state money-transmitter licensing and potential FinCEN registration apply, or in markets where the VASP has no regulatory standing – can expose both the VASP and the EMI to regulatory risk. The EMI will typically require a geographic scope confirmation as part of onboarding, and it will restrict the account accordingly.
The second issue is the tax interaction. A Lithuanian entity holding an EMI account will have substance requirements under Lithuanian corporate law and EU state-aid and transfer-pricing principles. A VASP that incorporates in Lithuania purely for the EMI relationship, with no genuine management or operational presence, risks challenge on substance grounds. The Bank of Lithuania has become more attentive to shell structures, and EMIs are under pressure to satisfy themselves that their customers are genuinely operating from the jurisdiction they claim.
The third issue is the banking-stack interaction across jurisdictions. Many VASPs operate with a primary EU account (typically the Lithuanian EMI) and a secondary account in a non-EU hub – Dubai, Singapore, or the Cayman Islands – for non-EU flows. Building that dual-rail structure requires careful attention to which entity holds which account, how funds move between them, and how the compliance obligations in each jurisdiction interact. In our cross-border practice, we have seen structures where the cross-jurisdictional fund flows triggered de-risking events with the primary EMI, because the documentation of the offshore leg was insufficient. The solution is to document the full structure before opening any account, not after a closure notice arrives.
What Does MiCA Mean for the VASP-to-EMI Onboarding Sequence?
Under MiCA, entities providing crypto-asset services in the EU require CASP authorisation from the relevant national competent authority – in Lithuania, the Bank of Lithuania. The transition period for entities that operated under the prior national VASP registration regime has a defined end date, after which pre-MiCA registrations cease to confer operating permission. VASPs that have not progressed to CASP authorisation by that deadline face a gap in their regulatory standing that will affect EMI onboarding.
For an inbound business – a VASP incorporated outside the EU that wants to establish a Lithuanian presence to access the EU market – the sequencing typically runs: entity incorporation → CASP pre-application engagement with the Bank of Lithuania → parallel EMI outreach with the regulatory application in evidence → CASP authorisation → full EMI account activation. Each stage has its own timeline, and the stages are partially concurrent. A well-managed process can run the entity setup and the CASP pre-application in parallel, reducing elapsed time. But the CASP application is substantive: it requires a detailed business plan, governance documentation, an AML policy meeting the Bank of Lithuania's standards, and senior management who pass fit-and-proper assessment.
The MiCA passporting mechanism is important here. A CASP authorised in Lithuania can provide services across the EU without re-authorising in each member state. That makes Lithuania not just an EMI gateway but a potential CASP hub for pan-European operations. For a VASP that is deciding where to anchor its EU regulatory presence, the combination of a CASP authorisation and an EMI relationship in the same jurisdiction is administratively efficient and reduces the number of regulatory relationships the business needs to manage.
However, MiCA also introduces a whitepaper obligation for certain token types, and the ART (asset-referenced token) and EMT (e-money token) categories carry additional issuer-level requirements. A VASP that issues a stablecoin or a multi-collateral token must assess whether it falls within those categories before proceeding with a Lithuanian EMI onboarding, because the regulatory profile of an ART or EMT issuer is materially different from that of a trading platform or custody operator.
What Are the Most Common Mistakes VASPs Make in Lithuanian EMI Applications?
The most common mistake is approaching EMI onboarding as a banking problem rather than a regulatory problem. The VASP that sends a standard account-opening form to a Lithuanian EMI without a complete AML policy, a defined Travel Rule solution, and clear evidence of its regulatory standing will receive a rejection or an extended information request that delays the process by months. EMIs are not banks in the retail sense; they are regulated institutions with their own compliance obligations, and they expect their VASP customers to meet a high standard of regulatory readiness before they commit to the relationship.
The second mistake is under-investing in the AML/CFT documentation. A generic AML policy downloaded from a compliance template repository does not satisfy the Bank of Lithuania's expectations. The policy needs to reflect the specific business model, the specific risk categories the VASP faces (retail vs institutional, DeFi-adjacent vs centralised, custody vs non-custody), and the specific jurisdictions from which clients are sourced. The Bank of Lithuania has issued detailed AML supervisory guidelines, and EMIs are expected to assess their customers against that standard.
The third mistake is misrepresenting the structure of the business. A VASP that presents a Lithuanian entity as its primary operating entity while the actual management and control sits offshore will encounter problems during the management interview and the corporate due diligence review. The EMI has an obligation to understand where the business is genuinely managed. If the answer is "not in Lithuania," the EMI will assess whether the Lithuanian entity has sufficient substance to justify the account.
In a recent engagement, a payments technology company approached a Lithuanian EMI after a prior EMI relationship in another EU member state was terminated following a periodic review. The termination had triggered a negative event reference that the company had not disclosed to the new EMI. We advised on the disclosure obligations, restructured the AML documentation to address the specific deficiencies that had caused the prior termination, and supported the company through a second application. The application was accepted, and the account was activated within a commercially reasonable timeframe. The key to the outcome was transparency about the prior history and a materially stronger compliance file the second time around.
A Common Assumption: One Offshore Licence Is Enough
A common assumption among early-stage VASP founders is that a single offshore registration – in the BVI, the Cayman Islands, or a similar jurisdiction – is sufficient to operate an exchange or custody business with a global client base and a Lithuanian EMI account. That assumption is incorrect on multiple fronts.
First, a BVI or Cayman VASP registration does not confer the right to provide crypto-asset services to EU residents. MiCA applies to entities providing services to clients in the EU, regardless of where the entity is incorporated. An offshore entity without a CASP authorisation that services EU clients is in breach of MiCA, and a Lithuanian EMI that knowingly banks such an entity is exposed to supervisory risk from the Bank of Lithuania. The EMI will require a clear regulatory analysis of the geographic scope of the VASP's business before proceeding.
Second, the Travel Rule applies in Lithuania and across the EU irrespective of the VASP's incorporation jurisdiction. If a VASP uses a Lithuanian EMI account to receive or send funds associated with transfers that lack the required originator/beneficiary data, both the VASP and the EMI face AML compliance exposure. The EMI will assess whether the VASP has a Travel Rule solution in place before onboarding and will monitor compliance on an ongoing basis.
Third, the banking relationship itself depends on the VASP maintaining regulatory standing in the jurisdictions where it operates. If the VASP's primary licence is revoked, suspended, or downgraded in its home jurisdiction, the EMI has grounds – and in many cases an obligation – to review and potentially close the account. A single point of regulatory failure in an offshore jurisdiction cascades into the EMI relationship. Diversifying the regulatory stack across the operating, custody, and payment layers is the correct structural approach.
If a prior EMI application stalled or an existing account is under review, contact OBOLUS at info@oboluslaw.com. A second read of the file can identify the structural reason and map the route back.
Which Profile of VASP Is Best Positioned for Lithuanian EMI Onboarding?
The answer depends on the regulatory position, the business model, and the state of the AML/CFT infrastructure at the point of application.
Profile A is the EU-authorised or near-authorised CASP. This entity has either completed its MiCA CASP authorisation in Lithuania or another EU member state, or is in the final stages of the application process with a complete file before the Bank of Lithuania. Its AML policy is current, its Travel Rule solution is implemented or contractually committed, and its ownership structure is clean and documented. This profile has the highest onboarding success rate and the shortest EMI process timeline. The EMI can satisfy itself on regulatory standing quickly, and the ongoing monitoring relationship is well-defined.
Profile B is the third-country VASP with a recognised equivalent licence. This entity holds a licence from a jurisdiction whose regulatory standards the EMI regards as equivalent – MAS in Singapore, SFC in Hong Kong, VARA in Dubai, or FCA in the UK. It is not yet EU-authorised but has a credible regulatory history, a functioning compliance programme, and a defined plan for obtaining CASP authorisation. This profile can achieve EMI onboarding, but the process takes longer and the EMI will typically apply more restrictive initial transaction parameters. The geographic scope of the account will be limited, and the VASP will need to demonstrate a concrete EU regulatory pathway.
Profile C is the early-stage VASP with a pre-MiCA Lithuanian registration and a CASP application in progress. This entity has a historical Bank of Lithuania relationship, which is an advantage, but the pre-MiCA registration does not by itself satisfy the EMI's current requirements. The VASP needs to demonstrate that its compliance infrastructure has been upgraded to meet MiCA standards and that the CASP application is substantively complete. EMIs will typically grant a conditional relationship pending CASP authorisation, with clear milestones for upgrading to a full account.
Profile D is the unregistered or early-stage entity with no EU regulatory standing. This profile will not achieve Lithuanian EMI onboarding in the near term. The correct approach is to initiate the CASP application process, build the compliance infrastructure to the required standard, and return to the EMI conversation once regulatory standing is established. Attempting to circumvent this sequence by using an intermediary or a nominee structure creates regulatory and reputational risk for the VASP and the EMI.
Self-Assessment: Is Your VASP Ready for Lithuanian EMI Onboarding?
Before approaching a Lithuanian EMI, a VASP should be able to answer yes to each of the following questions. A no – or an uncertain – indicates a gap that needs to be closed before the application.
Do you hold a current CASP authorisation under MiCA, a pre-MiCA registration that is being actively upgraded, or a recognised equivalent licence from a major jurisdiction? Can you produce a complete AML policy that reflects your specific business model, client base, and risk profile? Do you have a Travel Rule solution in place or contractually committed, with documentation of how you will comply with the originator/beneficiary data obligations for virtual asset transfers? Is your ultimate beneficial ownership structure documented to the level required by the Bank of Lithuania's AML guidelines? Can you demonstrate genuine substance in the Lithuanian entity – management presence, operational activity, and decision-making capacity in Lithuania? Have you mapped the geographic scope of your client base and confirmed that the Lithuanian EMI account will be used only for activity that falls within your regulatory permissions?
If the answer to any of these questions is uncertain, the time to resolve it is before the application, not during the EMI's due diligence review. We map the licence stack across operating, custody, and payment layers before you commit, which is the most efficient way to avoid the delays and reputational costs of a rejected or stalled application.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital Asset Businesses – the full practice overview for VASP banking and payment-rail structuring.
- De-Risking and Account Closure Defence – legal strategy for founders facing EMI de-risking or account termination.
- Travel Rule Compliance in Bermuda – cross-jurisdictional Travel Rule obligations and programme design.
FAQ
Why do banks close crypto company accounts?
Banks and EMIs close crypto company accounts primarily because of AML/CFT risk that the institution cannot adequately monitor, incomplete or inconsistent compliance documentation, or a regulatory change that alters the risk profile of the customer category. In Lithuania, the Bank of Lithuania has issued supervisory guidance that EMIs must apply when assessing VASP customers. A VASP that cannot demonstrate a functioning compliance programme, a clear Travel Rule solution, and transparent beneficial ownership will be assessed as high-risk and is likely to face account closure or refusal of onboarding.
How can a VASP onboard with an EMI?
A VASP seeking to onboard with a Lithuanian EMI should begin by confirming its regulatory standing – ideally a CASP authorisation under MiCA or a recognised equivalent licence. It must then prepare a complete AML policy aligned to the Bank of Lithuania's standards, implement or contractually commit to a Travel Rule solution, and document its ownership structure and source of funds. The application should be approached as a regulatory submission, not a standard account-opening request. Engaging counsel familiar with the Bank of Lithuania's expectations materially reduces the risk of rejection.
What does client-money safeguarding require?
Under the applicable EU payment services rules, an EMI is required to safeguard funds received from or for the benefit of payment service users. This means segregating those funds from the EMI's own assets and holding them in a designated account with a credit institution or investing them in secure, liquid, low-risk assets. For a VASP customer, the practical consequence is that the fiat balance held by the EMI on the VASP's behalf is protected in the event of EMI insolvency. The VASP's own obligations to its end clients regarding custody and safeguarding of client assets are a separate matter governed by the VASP's own regulatory permissions.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody, and payment layers before clients commit – a process that consistently surfaces structural issues before they become enforcement or banking problems. To discuss your EMI onboarding situation or broader VASP structuring needs, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in EU VASP licensing, MiCA transition strategy, and Bank of Lithuania regulatory engagement for inbound digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.