EST · MMXXVI
Home/Services/Banking Payments Emi/Payment institution licensing for Established Operators
Banking, Payments & EMI Onboarding

Payment institution licensing for Established Operators

Payment institution licensing for Established Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OB

Operating a digital-asset business without properly structured payment institution licensing is one of the fastest routes to a frozen rail, a closed account, or an enforcement notice from a national competent authority. For established operators – exchanges, custodians, token issuers and payment aggregators already processing volume – the risk is not theoretical. Banks conduct periodic de-risking reviews, and a licence gap discovered during that review typically produces an account closure letter, not a remediation plan.

A payment institution (PI) is an entity authorised under the applicable payments regime to execute payment transactions, issue payment instruments, or acquire payment transactions on behalf of merchants or users. For digital-asset businesses, PI authorisation – or an equivalent electronic money institution (EMI) authorisation – is often the missing layer between a VASP licence and a functioning fiat rail. This page sets out the regulated basis, the application process, the cross-border interaction, and the structural decisions that determine whether PI licensing solves the banking problem or merely shifts it.

The sections below move from the regulatory perimeter through the practical application process to the decision points most relevant to an established operator re-engineering its payment stack.

What does the payment institution regulatory perimeter actually cover?

PI and EMI authorisation regimes regulate the execution of payment transactions and the issuance of electronic money – not the trading or custody of crypto assets. The distinction matters. A VASP licence permits an operator to exchange, transfer or custody virtual assets under the applicable crypto regime. It does not, by itself, permit the operator to receive fiat deposits, hold client funds in a segregated payment account, or process card transactions on behalf of users. That activity requires separate authorisation under the applicable payments framework.

Across the EU and EEA, the relevant framework is the Payment Services Directive regime as implemented in each member state, now in the process of transition to its successor rules. Under that regime, a PI may hold client funds in safeguarded accounts and execute payment orders. An EMI may additionally issue electronic money – a stored monetary value redeemable at par – which is the instrument underpinning most prepaid wallet structures used in crypto-fiat conversion. ESMA and national competent authorities (NCAs) apply increasing scrutiny to entities that combine VASP and EMI activity in a single legal entity, and several NCAs have required operational separation.

Outside the EU, the regimes are structurally similar but vary in scope. The FCA in the United Kingdom maintains its own PI and EMI registration and authorisation tracks under the applicable electronic money and payment services regulations. MAS in Singapore applies a tiered licensing model under the Payment Services Act that covers DPT services and payment execution within the same instrument. VARA in Dubai governs transfer and settlement activity for virtual assets but does not itself authorise fiat payment execution – fiat rails in Dubai still require coordination with the UAE Central Bank's licensing regime. For any operator with users or banking relationships in multiple jurisdictions, the consequence is a multi-layer licence stack, not a single authorisation.

For a scoped assessment of your payment and banking licence gaps, contact OBOLUS at info@oboluslaw.com. The structure above describes the standard perimeter. Your entity, user base, and banking relationships change the analysis materially. Map your options.

Which established operators actually need PI or EMI authorisation?

An established operator needs PI or EMI authorisation – or a direct contractual relationship with an authorised institution as a registered agent or distributor – when its activity falls within the regulated payment services perimeter of the jurisdictions where it operates. The test is functional, not definitional: it turns on what the entity does, not what it calls itself.

The most common trigger points for established digital-asset operators are these. First, holding fiat balances on behalf of users between the point of deposit and the point of crypto purchase constitutes receiving funds for payment services in most EU member states, regardless of whether those funds are labelled "float," "settlement balance," or "prefunding." Second, operating a peer-to-peer fiat escrow – common in OTC and marketplace structures – typically engages the money transmission or payment execution perimeter. Third, issuing a wallet that allows users to store fiat pending conversion, and redeem that balance on demand at par, falls squarely within the EMI definition in most major regimes.

Operators that process all fiat through a fully authorised third-party EMI or PI under a properly documented agency or distribution agreement may be able to avoid direct authorisation – but the risk of that model is the counterparty relationship. If the EMI loses its licence, imposes transactional limits, or terminates the agreement for de-risking reasons, the operator loses its rail. In our practice, the operators most exposed to rail disruption are those that treated their EMI relationship as a long-term solution rather than a bridging arrangement while they built their own authorisation.

How does the PI or EMI application process work for a crypto operator?

The PI or EMI application process follows a common architecture across the major authorising jurisdictions, even where the specific requirements differ in detail. The core elements are a legal-entity structure capable of meeting capital and governance requirements; a compliance programme that satisfies AML/CFT obligations under the applicable FATF-aligned framework including the Travel Rule (the obligation to pass originator and beneficiary data with a transfer); a business plan demonstrating the viability of the payment business; and a safeguarding arrangement for client funds.

For a crypto-native operator, the application diverges from a conventional fintech submission in several important respects. Regulators now routinely ask for a detailed account of the crypto activities conducted by the group – including the jurisdictions in which the VASP operates, the token categories handled, the on-chain and off-chain flows, and the way in which crypto risk is managed within the AML programme. An application that presents the payment business in isolation from the crypto context will not typically survive the assessment phase. NCAs under MiCA and the FCA under its current regime have both indicated, through supervisory communications and published Q&As, that combined VASP/PI operations require explicit treatment in the risk assessment submitted with the application.

Timeline expectations vary by jurisdiction and by the completeness of the submission. In jurisdictions operating under the EU payments framework, the statutory assessment window runs from the point at which the NCA confirms the application is complete – and that completeness confirmation itself can take several weeks if the initial submission is deficient. In our experience advising operators through this process, the most common cause of delay is not the regulator's review speed but the operator's inability to produce a complete AML/CFT programme documentation set at the point of initial submission.

The safeguarding requirement deserves particular attention. Under EU payment services rules, a PI must either hold client funds in a designated safeguarded account with a regulated credit institution, or cover those funds with an insurance policy or guarantee meeting the applicable requirements. Identifying a credit institution willing to open that safeguarded account for a crypto-adjacent PI is, in practice, the hardest operational step in the process. Banks conducting due diligence on a prospective PI safeguarding relationship will look through the PI to the underlying business – and if that business includes crypto exchange or custody activity, the bank's AML and reputational risk functions will apply the same scrutiny they would to a VASP applicant.

How does PI licensing interact with a multi-jurisdiction crypto operation?

For an established operator with users or infrastructure in more than one jurisdiction, the PI or EMI licence in a single member state does not resolve the full payment regulation picture – it opens the passporting question. A PI authorised in an EU member state may passport its services to other EEA member states by notifying its home NCA, which coordinates with the host state regulator. That passporting right is a significant operational advantage for an operator serving users across Europe from a single legal entity.

The jurisdictions most commonly chosen as home-state authorising regimes for EU PI and EMI passporting include Lithuania, Ireland, and Malta, each of which has developed administrative capacity and an established relationship with the digital-asset sector. Lithuania, supervised by the Bank of Lithuania, historically processed VASP registrations at volume and maintains NCA capacity relevant to MiCA CASP and payment services applications. The MFSA in Malta operates a VFA framework in MiCA transition and maintains a payment services authorisation track. Ireland offers access to the EU single market and an English-language regulatory environment, with the Central Bank of Ireland as the relevant NCA.

The cross-border complexity multiplies when the operator also has users in the UK, Singapore, or the UAE. The FCA in the UK does not recognise EU passporting post-Brexit; a separate MLR registration and, for most PI activity, a separate FCA authorisation is required. MAS in Singapore applies its own Payment Services Act regime, with its own capital, AML and technology risk requirements. VARA in Dubai governs virtual-asset transfer and settlement but does not substitute for UAE Central Bank payment licensing for fiat activity. An operator managing a global user base will typically need two to four distinct payment-layer authorisations, each anchored to a distinct legal entity and banking relationship.

In our cross-border practice, the operators who handle this most efficiently are those that map the full licence stack – VASP layer, payment layer, custody layer – before committing to an entity structure, rather than retrofitting authorisations onto a structure optimised for a different purpose. Retrofitting is possible, but it typically costs more in time and in regulatory friction than a purpose-designed structure.

If a prior application stalled or a banking relationship was closed, a second read of your structure can surface the reason and the route forward. Contact OBOLUS at info@oboluslaw.com or message us at t.me/oboluslaw. Map your options.

What are the most common structural mistakes crypto operators make in PI licensing?

The most damaging mistakes in PI licensing for crypto operators are not errors of omission in the application pack – they are structural decisions made earlier, before any application is filed, that create problems the application cannot solve.

The first and most frequent is locating the payment activity in an entity that also holds the VASP licence for the crypto trading business. Regulators increasingly prefer, and in some cases require, that payment services be conducted by a legally separate entity, even where the two entities are in the same corporate group. A group structure that separates VASP activity (exchange, custody, token issuance) from payment activity (fiat receipt, safeguarding, instruction execution) reduces regulatory interference risk, simplifies the AML programme documentation, and makes the safeguarding bank relationship easier to establish. It also preserves operational continuity: if the VASP licence comes under supervisory review, the payment rail is not simultaneously at risk.

The second common mistake is treating the safeguarding account requirement as an administrative formality. Banks that provide PI safeguarding accounts are taking on the regulatory and reputational risk of the PI's underlying business. A crypto operator applying to open a safeguarded account must approach that bank relationship the same way it approaches a regulatory application: with a full CDD pack, a clear description of the crypto activity, and a documented AML programme. Arriving without that documentation results in a prolonged onboarding process or an outright decline.

The third mistake – addressed more fully in the objection-handler section below – is the assumption that a well-structured offshore licence is a substitute for PI authorisation in the jurisdictions where users are actually located. It is not. The regulatory perimeter in EU member states, the UK, and Singapore is triggered by the location of the user and the nature of the service, not by the location of the entity providing it. An operator whose payment services are consumed by EU residents is within the EU payments perimeter regardless of where its legal entity sits.

In a recent payment structure matter, a crypto exchange that had grown from a predominantly offshore user base to a significant EU user population found its existing EMI relationships unable to scale with the business. The operator had no EU PI authorisation of its own, and the third-party EMI had begun to impose volume limits as part of its own de-risking exercise. We advised on a group restructuring that separated the EU-facing payment activity into a dedicated Irish-domiciled entity, mapped the Bank of Lithuania passporting option for the broader EEA book, and prepared the safeguarding bank approach. The application was filed within a commercially workable timeframe, and the volume constraint was resolved operationally while the authorisation process ran.

A common assumption about offshore licensing and global reach

A common assumption among operators scaling across borders is that a single well-chosen offshore licence – a BVI VASP registration, a Cayman VASP licence, or a licence from a jurisdiction outside the EU and UK regulatory perimeter – provides adequate legal cover for payment services directed at users globally. That assumption is incorrect, and it is one of the leading structural reasons that established operators lose banking relationships.

The BVI Financial Services Commission under the VASP Act 2022 and CIMA under the Cayman VASP Act both provide regulated frameworks for virtual-asset service providers operating in those jurisdictions. Those frameworks are legitimate and serve genuine purposes in fund domiciliation, custody structuring and certain asset-management activities. They do not, however, confer any right to provide payment services to residents of the EU, the UK, Singapore, or other jurisdictions with active payment services perimeters. An operator with BVI registration providing fiat receipt and payment instruction services to German retail users is not licensed for that activity under German law or under MiCA.

Banks understand this. Correspondent banks and EMI providers conducting due diligence on a crypto operator look at where the users are, not only where the entity is registered. An operator that cannot demonstrate payment-service authorisation in the jurisdictions generating its user volumes will be assessed as a de-risking candidate by any correspondent bank applying standard AML and regulatory compliance criteria. The practical consequence is a termination letter, usually with no right of appeal and a short notice period.

The solution is not to abandon offshore structures – they serve real purposes in the overall entity map. It is to treat the offshore structure as one layer of a multi-layer stack and to add the payment-layer authorisation appropriate to the jurisdictions where regulated payment services are actually being provided.

Which PI or EMI structure fits which operator profile?

The right PI or EMI structure depends on the operator's user geography, its transaction volume profile, the nature of its crypto activity, and the timeline within which it needs a functioning rail. The following decision matrix describes the most common operator profiles and the instruments that typically fit each.

An established exchange with a predominantly EU user base and existing VASP activity in one or more EEA member states will typically benefit from a PI or EMI authorisation in a home EU member state with active passporting to the remaining EEA markets. Lithuania offers administrative efficiency and an established supervisory relationship with crypto operators. Ireland offers English-language regulation and strong correspondent banking access. Malta provides the VFA-to-MiCA transition path for operators already inside the MFSA framework. The application timeline in each of these jurisdictions varies by the completeness of the submission, but a well-prepared application should not expect the statutory assessment window to be the binding constraint.

An operator with a significant UK user base and an existing EU PI requires a separate FCA authorisation or registered-agent relationship with an FCA-authorised institution. The FCA's current AML registration track for crypto assets does not substitute for payment services authorisation. A combined UK and EU payment operation will almost always require two separate entities and two separate safeguarding arrangements.

An operator building primarily for the Asia-Pacific market, with users in Singapore and Hong Kong, should structure its payment layer around the MAS Payment Services Act framework in Singapore and, where virtual-asset trading platform activity is involved, the SFC's VATP regime in Hong Kong. The MAS framework offers tiered licensing with graduated capital and compliance obligations depending on payment volume and business model. The key risk for a crypto operator in that structure is demonstrating to MAS that the AML controls applied to the DPT business meet the standard required for a payment services licensee.

An operator serving users in multiple regions – EU, UK and Asia-Pacific simultaneously – will need a group structure with a minimum of three payment-layer authorisations and a coordination framework for cross-border AML data sharing and Travel Rule compliance. That structure is achievable, but it requires design from the entity level upward, not retrofitting of payment authorisations onto an existing single-entity structure.

Pre-application self-assessment for PI licensing

Before filing a PI or EMI application, an established operator should be able to answer affirmatively to each of the following structural questions. If any answer is negative or uncertain, that is the item to resolve first.

Is the payment-activity entity legally separate from the VASP-activity entity in the same group? Does the proposed entity meet the minimum capital requirement applicable to its intended licence category? Is there an identified credit institution willing in principle to provide a safeguarded account for client funds? Does the AML programme documentation explicitly address the crypto-specific money-laundering risks identified by FATF Recommendation 15? Is a qualified MLRO or equivalent responsible officer identified, with documented knowledge of both payment services and virtual-asset AML risk? Has the business plan mapped the specific payment services to be provided, the user jurisdictions, and the regulatory perimeter engaged in each? Has the group structure been disclosed to the proposed safeguarding bank?

An application that cannot answer all of these questions affirmatively before submission will almost certainly generate a completeness query from the NCA, which restarts the statutory clock and extends the overall timeline. In our practice, the operators who achieve the shortest application-to-authorisation timelines are those who treat the pre-application preparation phase as the substantive work and the formal submission as the final step.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily for three reasons: the operator lacks demonstrable regulatory authorisation appropriate to its activities, the AML programme documentation does not meet the bank's correspondent compliance standard, or the bank's own de-risking policy excludes the crypto sector entirely. In our experience, the first two causes are addressable with proper preparation. The third – a policy-level exclusion – requires identifying a different banking counterparty rather than attempting to remediate for one that has made a sector-level decision.

How can a VASP onboard with an EMI?

A VASP (virtual asset service provider) seeking to onboard with an authorised EMI must present the same documentation the EMI would require from any regulated financial institution: a current VASP licence, a full AML/CFT programme including Travel Rule procedures, audited or management accounts, and a clear description of the transaction flows the EMI will be asked to process. EMIs applying appropriate due diligence will conduct a risk assessment of the VASP's underlying business. A VASP that cannot produce a complete compliance pack in advance of that assessment will generally not be onboarded.

What does client-money safeguarding require?

Client-money safeguarding under EU payment services rules requires a PI or EMI to hold funds received from clients either in a designated safeguarded account with a regulated credit institution or covered by an eligible insurance policy or guarantee. The funds must be kept separate from the institution's own funds at all times. The credit institution providing the safeguarded account must be identified in the authorisation application. In practice, securing a safeguarding bank relationship is the most operationally complex step in PI or EMI authorisation for crypto-adjacent operators.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence, banking and payment stack across operating, custody and payment layers before you commit to a structure – so that the analysis informs the design, not the remediation. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in payment institution authorisation, VASP licensing and cross-border regulatory compliance for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours