A fiat on/off-ramp (a facility that converts between national currency and digital assets) in Lithuania sits at the intersection of Bank of Lithuania payment-services supervision, the evolving CASP (crypto-asset service provider) authorisation under MiCA, and the practical reality of correspondent-banking access. Getting the legal stack right before you sign a banking or EMI (electronic money institution) agreement is not optional – it determines whether your rails stay open. This page sets out the regulated basis, the inbound-business process, the cross-border interactions, and the single most important decision point for operators seeking Lithuanian fiat infrastructure.
What is the regulated basis for fiat on/off-ramp banking in Lithuania?
Running a fiat on/off-ramp in Lithuania requires at minimum a registered or authorised payment-services presence under the regime supervised by the Bank of Lithuania. Under the prior national VASP regime and now under MiCA's transition provisions, any business exchanging crypto assets for fiat – or vice versa – engages both the payment-services perimeter and the virtual-asset-service perimeter simultaneously. Operators who treat these as separate questions invariably find one side of the equation unresolved when a banking partner requests documentation.
The Bank of Lithuania supervises payment institutions (PIs), electronic money institutions (EMIs) and, since MiCA's phased implementation, CASP authorisation for crypto-asset service providers. Lithuania built its reputation as a fast EU entry point precisely because the Bank of Lithuania established a clear, documented onboarding track for payment-sector applicants. That track remains available – but the supervisory standard has risen materially since the early VASP-registration era.
A business operating a fiat on/off-ramp without the correct authorisation faces immediate enforcement risk. The Bank of Lithuania holds powers to issue prohibition orders, impose administrative sanctions and refer to criminal-law authorities. More practically, any Lithuanian-domiciled bank or EMI that detects an unlicensed counterparty in its transaction flow will exit the relationship. Operating without the right licence risks enforcement, frozen rails and the loss of banking access that took months to build.
Under MiCA, the exchange of crypto assets for fiat constitutes a core CASP activity. The regulation applies directly across EU and EEA member states. A Lithuanian authorisation carries EU passport rights – a CASP or PI authorised by the Bank of Lithuania may notify into other member states without a separate licence. That passportability is the structural reason why Lithuania remains a competitive domicile for businesses whose user base spans the EU.
For a scoped assessment of your licensing exposure in Lithuania, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking counterparties – change the analysis materially.
Who needs a licence to operate fiat rails in Lithuania?
Any business that accepts fiat from customers and delivers crypto assets – or accepts crypto and delivers fiat – to customers in Lithuania or to EU-based customers through a Lithuanian entity needs both a payment-services authorisation and a CASP authorisation under MiCA. The test is functional, not nominal: labelling a service a "wallet" or a "conversion desk" does not change the regulated character of the activity.
Four operator profiles commonly engage with Lithuanian fiat infrastructure:
- Retail exchange operators offering euro-denominated buy/sell functionality require a PI or EMI licence at the payment layer and a CASP authorisation at the crypto-asset layer.
- OTC desks settling large-volume fiat-to-crypto trades for institutional counterparties may qualify for a narrower payment-services permission, but the CASP perimeter still applies to the crypto side of the trade.
- Custodians accepting fiat subscriptions and distributing fiat redemptions engage the payment-services regime even if the primary regulated activity is custody.
- Issuers of asset-referenced tokens (ARTs) or e-money tokens (EMTs) under MiCA must satisfy issuer authorisation requirements that are distinct from – and additional to – the PI/EMI layer.
The FATF Recommendation 15 framework obliges Lithuania, as an EU member state, to apply Travel Rule obligations (the requirement to pass originator and beneficiary data alongside a virtual-asset transfer) to qualifying transactions. Any operator processing fiat-to-crypto conversions and transmitting the resulting assets must have a Travel Rule compliance programme in place before a reputable Lithuanian bank or EMI will complete onboarding.
What does the Lithuanian authorisation process look like in practice?
The Bank of Lithuania's authorisation process for a payment institution or EMI follows a documented sequence: pre-submission engagement, formal application, completeness check, substantive review, and conditional authorisation with an AML/compliance sign-off. Each stage has a defined scope, though elapsed time varies with the complexity of the application and the quality of the submitted documentation.
In our practice, the applications that move fastest share three characteristics. First, the corporate structure is clean and the beneficial ownership chain is fully documented before submission. Second, the AML/CFT programme – including the Travel Rule module – is finished and stress-tested, not in draft. Third, the applicant has identified and engaged its banking or EMI partner in parallel, so that account-opening documentation moves simultaneously with the regulatory file.
The substantive review by the Bank of Lithuania covers governance, management fitness, IT and operational resilience, AML policy and the proposed safeguarding arrangement for client funds. For a PI or EMI intending to handle fiat on/off-ramp volumes, the safeguarding question is particularly scrutinised: the regulator expects a clear, documented method – either insurance-backed or segregated-account-based – before it will issue a licence.
For a crypto-specific operator adding the CASP layer under MiCA's transition provisions, the parallel track is an application to the Bank of Lithuania as the national competent authority. The MiCA CASP authorisation requires a whitepaper for any token that meets the threshold criteria, a conflicts-of-interest policy, cyber-resilience documentation and a client-asset protection framework. Operators who submit the PI/EMI file and the CASP file separately – rather than as a coordinated package – typically experience review delays while the Bank of Lithuania resolves questions that span both files.
A cross-border note: the entity in Lithuania is rarely the whole structure. In our cross-border practice we regularly advise on the interaction between the Lithuanian operating entity and an offshore parent, a BVI or Cayman holding company, or a second licensed entity in another jurisdiction handling non-EU users. The Bank of Lithuania will examine group structure and will expect clear delineation of which entity bears which regulated activity. Structures that appear designed to shift regulated activity offshore while retaining EU users attract close scrutiny.
How does EMI onboarding work for a Lithuanian crypto business?
EMI onboarding for a Lithuanian crypto business is a two-stage process: first, selecting the right EMI partner; second, satisfying that partner's own compliance programme, which in the crypto sector is typically more demanding than the Bank of Lithuania's own authorisation checklist.
Lithuanian-licensed EMIs occupy a distinctive position. They operate under Bank of Lithuania supervision and hold EU passport rights, meaning they can issue IBANs and process SEPA transfers across the eurozone. For a VASP or CASP that needs euro settlement rails, a Lithuanian EMI is often the most accessible route – but "accessible" does not mean automatic. EMIs that service crypto businesses carry elevated AML risk ratings and the corresponding supervisory scrutiny. They manage that risk by imposing detailed onboarding requirements on their crypto clients.
Typical EMI onboarding requirements for a crypto counterparty include: a current regulatory licence or registration (or confirmed pending status), a full AML/KYC policy aligned to the Bank of Lithuania's AML guidelines, a Travel Rule implementation plan with named technology vendor, source-of-funds documentation for the first expected transactions, and a transaction-monitoring framework with defined escalation thresholds. Some EMIs also require a third-party AML audit before they will open an account for a new crypto client.
We have seen operators spend months on EMI outreach without success because they approached the process as a banking relationship rather than as a regulated-entity-to-regulated-entity compliance engagement. The EMI's compliance team, not its commercial team, makes the ultimate onboarding decision. Presenting the full legal and compliance package on first contact – licence, AML manual, Travel Rule solution, UBO chain, transaction-flow projections – compresses the process materially.
If a prior application to an EMI or bank stalled or an account was closed, a second read can surface the structural reason and the route back. Contact OBOLUS at info@oboluslaw.com.
What are the cross-border tax and banking interactions?
A Lithuanian operating entity creates tax exposure in Lithuania on its trading income and, depending on the treaty network and the substance of the entity, potentially in other jurisdictions where its principals or users are located. Lithuania's corporate income tax rate, a substance requirement for treaty-protection purposes, and transfer-pricing obligations on intra-group transactions all affect the economic logic of the structure. These questions must be resolved in parallel with the licensing track – not after authorisation is obtained.
The cross-border banking question is equally significant. Lithuanian-licensed PIs and EMIs settle primarily in euros through SEPA. A business with material transaction volume in currencies outside the eurozone – US dollars, British pounds, Swiss francs – needs correspondent-banking access in those currency zones, which typically requires either a second licensed entity in the relevant jurisdiction or a banking relationship with a global correspondent willing to service a crypto-sector client. The latter category is smaller than it was, and most global correspondents will expect to see a MiCA-compliant or equivalent licensed entity before engaging.
Operators expanding from Lithuania into non-EU markets routinely ask whether the Lithuanian CASP authorisation – with its EU passport – is sufficient to serve users in jurisdictions such as the UAE, Singapore or the UK. The answer is jurisdiction-specific. MiCA passporting operates within the EU/EEA perimeter; it does not substitute for a VARA, MAS or FCA authorisation in the relevant third-country market. A business that operates under a Lithuanian licence and onboards users from a market where a local licence is required is exposed in that market regardless of its EU status.
In a recent structuring matter, a digital-asset payments business sought to consolidate its EU and Gulf operations through a single Lithuanian entity. We identified that the Gulf-facing activity fell squarely within the VARA activity-based licensing regime and that the proposed structure would create a regulatory gap the operator had not anticipated. We mapped the licence stack across the operating, custody and payment layers before the client committed capital to the structure, avoiding a costly reorganisation at a later stage.
What are the most common legal mistakes in Lithuanian fiat-ramp setups?
The most common mistake is treating the payment-services authorisation as the complete solution and overlooking the CASP perimeter. Operators who hold a PI or EMI licence but have not obtained CASP authorisation – or who rely on a transitional exemption they have not verified – are operating on borrowed time. The Bank of Lithuania is the national competent authority for MiCA in Lithuania; it will enforce the CASP perimeter independently of payment-services supervision.
A second common mistake is an incomplete AML/CFT programme at the point of EMI onboarding. Many operators treat the AML manual as a compliance formality rather than as the primary risk document that banking partners and regulators examine first. An AML manual that does not address crypto-specific typologies – chain-hopping, mixer usage, NFT wash trading, cross-chain bridge exploitation – will not satisfy a Lithuanian EMI's compliance team in the current supervisory environment.
A third mistake is the single-entity assumption: the belief that a single offshore licence is enough to serve clients globally. In practice, each material market where an operator has users creates a separate regulatory exposure. A Lithuanian-licensed entity serving UAE users without a VARA authorisation, or serving Singapore users without a MAS DPT service licence, is exposed in those markets to enforcement even if its primary licence is in good standing.
A fourth mistake is underestimating the importance of substance. The Bank of Lithuania, like other EU regulators, expects the licensed entity to have genuine local substance: a qualified management team with real decision-making authority, operational infrastructure in Lithuania, and a compliance function that is demonstrably independent of the group's commercial interest. Shell structures with a local director and no other Lithuanian presence do not satisfy this expectation and are at material risk of supervisory challenge.
Which operator profile should choose Lithuania and why?
Lithuania remains well-suited to certain operator profiles and less suited to others. Understanding which profile fits the Lithuanian model before committing to incorporation and application saves material cost and time.
Profile A – EU-focused retail exchange: An operator whose primary market is EU retail users, who needs euro SEPA rails, and who can establish genuine Lithuanian substance benefits most directly from Lithuanian authorisation. The Bank of Lithuania offers a documented authorisation track, and the MiCA CASP passport covers the entire EU/EEA user base from a single licence. The key risk is the rising compliance cost of maintaining the CASP authorisation as MiCA implementation matures; operators should budget for ongoing supervisory engagement, not merely one-time authorisation.
Profile B – Global exchange with EU as one region: An operator whose primary volume is outside the EU and who views Lithuania as a regional access point faces a more complex stack. The Lithuanian entity services EU users; parallel licences in the UAE, Singapore or another hub service non-EU users; and the group's banking programme must span multiple currency zones. This is a structurally viable model – we regularly advise on it – but it requires coordinated legal and compliance work across the jurisdictions, not sequential applications.
Profile C – OTC desk or institutional settlement facility: An operator settling large-volume, counterparty-specific trades rather than serving retail users may find that the payment-services perimeter is narrower for its activity, and the CASP authorisation is the primary regulatory question. The Bank of Lithuania's treatment of institutional-facing activities under MiCA is an active question in the current supervisory cycle; operators in this profile should take specific advice before structuring.
Profile D – ART or EMT issuer: A business issuing an asset-referenced token or e-money token under MiCA must satisfy the MiCA issuer authorisation requirements, which are distinct from and more demanding than a standard CASP authorisation. The Bank of Lithuania is the competent authority for issuers domiciled in Lithuania. Reserve management, redemption rights and the interaction with payment-services regulation require specialist analysis before the issuance structure is finalised.
Self-assessment: are your Lithuanian fiat rails legally sound?
Before committing to a Lithuanian fiat on/off-ramp structure, operators should be able to answer affirmatively to each of the following questions. A negative or uncertain answer identifies a legal gap that requires resolution before, not after, the banking relationship is established.
- Does the entity hold, or have a confirmed path to, a Bank of Lithuania PI or EMI authorisation and a MiCA CASP authorisation covering the planned fiat conversion activity?
- Is the AML/CFT programme documented, crypto-specific and aligned to current Bank of Lithuania AML guidelines, including a Travel Rule module with a named technology solution?
- Has the beneficial ownership chain been fully disclosed and documented to the standard expected by both the Bank of Lithuania and prospective EMI or banking partners?
- Has the group structure been reviewed to confirm that non-EU user activity is covered by the correct licence in the relevant third-country jurisdiction?
- Does the Lithuanian entity have genuine local substance – qualified management, real operational infrastructure and an independent compliance function?
- Has the safeguarding method for client funds been determined and documented, and has it been reviewed against the Bank of Lithuania's current expectations?
- Has the cross-border tax position of the Lithuanian entity been reviewed against Lithuania's corporate income tax regime and any applicable transfer-pricing obligations?
We map the licence stack across operating, custody and payment layers before you commit. If the answer to any item above is uncertain, that is the starting point for a scoped legal engagement.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital Asset Businesses – the full practice overview: PI, EMI and CASP licensing strategy across jurisdictions.
- Correspondent Banking Access in Turkey – navigating banking access for crypto businesses in a high-scrutiny emerging market.
- GP/LP Structuring for Digital Assets for Regulated Entities – fund structure options for operators whose Lithuanian entity interacts with an offshore investment vehicle.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because the account-holder fails to satisfy the bank's AML risk-assessment threshold. Common triggers include an incomplete or generic AML manual, no Travel Rule solution, an unclear beneficial ownership chain, or transaction patterns inconsistent with the declared business model. A licensed entity with a crypto-specific AML programme, documented source-of-funds procedures and a clear regulatory status is materially less likely to face account closure than an unlicensed or poorly documented one.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) onboards with a Lithuanian or EU-licensed EMI by presenting its full regulatory and compliance package at the first point of contact: current authorisation or confirmed pending status, an AML/CFT policy aligned to the Bank of Lithuania's guidelines, a Travel Rule implementation plan, source-of-funds documentation and transaction-monitoring procedures. The EMI's compliance team makes the decision; treating the onboarding as a compliance-to-compliance engagement rather than a commercial one accelerates the process.
What does client-money safeguarding require?
Client-money safeguarding under the Bank of Lithuania's payment-services regime requires a licensed PI or EMI to hold client funds either in a segregated account at a credit institution or covered by an eligible insurance or guarantee arrangement. The method must be documented, operationally implemented and verifiable by the regulator. For crypto-sector operators, the Bank of Lithuania expects the safeguarding arrangement to be in place – not merely planned – before it will finalise authorisation.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise crypto exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We advise on the full licence stack – from Bank of Lithuania PI and EMI authorisation through MiCA CASP to cross-border tax and banking structuring – before you commit capital. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in EU payment-services and crypto-asset licensing, with a focus on Bank of Lithuania authorisation and MiCA CASP implementation for inbound operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.