For an institutional operator building fiat rails around a digital-asset business, the question is not whether to hold a payment institution licence – it is which licence, in which jurisdiction, structured around which entity, before the first client transfer clears. Operating without the right authorisation exposes the business to enforcement action, frozen correspondent accounts and the permanent reputational damage that follows a regulatory suspension. The payment institution licensing regime sits at the intersection of e-money regulation (the rules governing the issuance of electronic money and the provision of payment services), VASP licensing (virtual asset service provider authorisation), and banking-access policy – a combination that demands cross-border coordination from the first day of planning. This page maps the regulated basis, the application process, the common structural mistakes, and the decision logic that determines which profile suits which operator.
Why Institutional Clients Need Payment Institution Licensing
Payment institution licensing is the gateway to operating fiat rails legally – and for institutional digital-asset operators, missing this step is a structural risk, not a procedural oversight. A firm that routes client funds through an account it does not control, or through a payment arrangement it does not hold, creates regulatory exposure that no contractual workaround can eliminate. Regulators across the major hubs – from the Financial Conduct Authority (FCA) in the United Kingdom to ESMA and national competent authorities under MiCA – treat unauthorised payment activity as a serious enforcement matter. The stakes for an institutional operator are correspondingly high: a single enforcement notice can freeze operations across all jurisdictions in which the firm's banking counterparties are regulated.
The institutional context adds a further dimension. Retail-facing businesses must hold the right licence. Institutional operators must also demonstrate to counterparty banks that their regulatory status is coherent with the volume, velocity and cross-border nature of the flows they run. A custody business settling trades in multiple currencies, a token-issuance platform processing subscription payments, or a crypto exchange offering OTC desks – each requires a payment authorisation calibrated to its actual activity profile. We regularly advise operators who discover this mismatch only after an account is closed or a correspondent relationship is withdrawn.
The applicable regime matters as much as the fact of licensing. An EMI authorisation in one EU member state, passported under MiCA's CASP framework, carries different capital and safeguarding obligations than a Singapore Major Payment Institution licence issued under the Payment Services Act, or a VARA transfer-and-settlement authorisation in Dubai. Each carries distinct client-money rules, Travel Rule obligations, and restrictions on the categories of institutional counterparty the licensee may serve.
For a scoped assessment of your payment authorisation needs, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking – change the analysis. Map your options.
The Regulatory Perimeter: Which Activities Trigger Authorisation?
A payment institution licence is required whenever a firm provides payment services as a regulated activity – a threshold that turns on the nature of the funds flow, not on the firm's self-description. Across the leading regimes, the regulated perimeter captures account issuance, fund transfers, payment initiation, currency exchange and, increasingly, digital-asset settlement against fiat. The precise boundary differs by jurisdiction, but the analytic approach is consistent: if the firm touches client money on the way between payer and payee, it is in the perimeter.
For institutional digital-asset operators, three activity types most frequently trigger the requirement. First, exchange operations that settle trades in fiat – whether directly to client bank accounts or to pooled wallets – require payment service authorisation in most major regimes. Second, custodians that hold fiat collateral, margin or proceeds on behalf of clients are typically providing a payment account or safeguarding service that falls within the regulated scope. Third, OTC desks, prime brokers and liquidity providers that intermediate fiat settlement are conducting money transmission under applicable law.
The critical analytical step is distinguishing activities that require full payment institution authorisation from those that require only e-money institution (EMI) authorisation or, in some jurisdictions, registration rather than full licensing. In the EU under MiCA, an operator providing payment services in connection with a CASP authorisation must ensure its payment service activities are separately covered – either through a standalone PI/EMI licence, a credit institution licence, or a passporting arrangement with an authorised partner. The FCA in the United Kingdom draws the same line under the Money Laundering Regulations and the Payment Services Regulations.
How Does Payment Institution Licensing Interact with VASP and EMI Authorisation?
Payment institution licensing does not exist in isolation – for any institutional digital-asset operator, it sits alongside VASP authorisation and, where applicable, EMI authorisation as part of a three-layer regulatory stack. Understanding how these layers interact is essential before committing to a domicile or an entity structure. The wrong layering creates gaps that regulators identify quickly and banking partners identify even faster.
The VASP layer covers the digital-asset-specific activity: trading, custody, exchange, transfer. The EMI layer covers the issuance of electronic money – prepaid balances, stored-value instruments, tokenised fiat representations. The payment institution layer covers the movement of funds between accounts – transfers, settlements, remittances. In many institutional business models, all three activities are present simultaneously. A single entity may not hold all three authorisations in every jurisdiction; the structural question is how to apportion activities across entities and geographies in a way that is both compliant and commercially coherent.
In our practice, we see two recurring structural failures. The first is the assumption that a VASP licence in one jurisdiction implicitly covers payment service activity across the firm's broader operation. It does not. The second is the belief that an EMI authorisation covers all payment service activity. It does not – EMI and PI are distinct authorisations covering distinct activity sets, and a firm that issues stored-value instruments while also executing fund transfers between client accounts may need both. The interaction between these regimes, across multiple operating jurisdictions, is where the analysis becomes most consequential for an institutional operator.
What Does the Payment Institution Application Process Require?
A payment institution application is a compliance-intensive process with material document and governance demands – operators who approach it as a form-filing exercise consistently face delays, remedial requests and, in some cases, refusals that might have been avoided with better preparation. The application process across major regimes follows a common logic, even where procedural specifics differ.
The first stage is the regulatory mapping exercise. This means identifying the activities that require authorisation, the categories under which those activities fall in each relevant jurisdiction, and the regulatory capital, safeguarding and AML obligations that attach to each category. This stage also determines the domicile strategy – whether the operator should hold the PI licence directly, through a dedicated entity, or through a passporting arrangement under an authorised partner. In the EU, passporting under MiCA provides one route; standalone national authorisation under a legacy PI regime is another. In the UAE, VARA's transfer-and-settlement authorisation requires a separate application from an exchange or advisory licence.
The second stage is governance and policy build. Regulators require a fit-and-proper assessment of directors and controllers, a documented business model that maps activities to regulated categories, AML/CFT policies aligned to FATF Recommendation 15 standards, and a client-money safeguarding framework. For institutional operators, the safeguarding requirements are particularly demanding: client funds must be held in designated accounts, insulated from the firm's own resources, and reconciled on a schedule the regulator expects to see evidenced in policy and practice.
The third stage is the application itself – submission, regulator engagement, and the management of any information requests during the review period. Timeline varies materially by jurisdiction. Some regimes process applications within a matter of weeks; others take several months for a complete institutional application. The applicant's ability to respond promptly and accurately to supplemental requests is the single largest variable determining outcome and timeline.
The final stage is pre-authorisation banking. The practical reality is that a payment institution licence is of limited value without a banking relationship to activate it. Many banks will not open an account for a payment institution until the licence is granted; many regulators expect evidence of a banking arrangement as part of the application. Managing this sequencing – and having a credible answer to both questions simultaneously – is one of the most common structural challenges we work through with clients.
The Cross-Border Reality: Where the Entity Sits Versus Where Clients Are
The most significant structural risk for an institutional operator is the mismatch between where the licensed entity sits and where the regulated activity actually occurs. A payment institution authorised in an EU member state may passport into other member states under MiCA's framework – but passporting does not extend to jurisdictions outside the EU/EEA, and it does not resolve the question of whether the firm's activities in those jurisdictions independently trigger local authorisation. An operator serving institutional clients in the UAE, Singapore and the United Kingdom simultaneously is potentially in the perimeter of VARA, the MAS Payment Services Act regime, and the FCA's Payment Services Regulations – all at once.
Banking access amplifies this complexity. Correspondent banking relationships are governed by the policies of the correspondent bank's home regulator, not just the PI licensee's home regulator. A payment institution authorised in Malta under the MFSA regime may find that its correspondent bank in a major financial centre applies additional due-diligence requirements based on the destination of the funds, the nature of the counterparties, or the jurisdictions through which the flows transit. These requirements are commercially real, and they are separate from the regulatory authorisation question.
In a recent matter, a mid-stage institutional operator held a payment institution authorisation in one EU jurisdiction but routed settlement flows through entities in two further jurisdictions, neither of which held standalone authorisation. When the correspondent bank reviewed the account as part of a scheduled relationship assessment, the structural gap was identified and the account was suspended pending remediation. We mapped the cross-jurisdictional activity against each regime's perimeter, identified the minimal additional authorisations required, and coordinated the regulatory engagement with allied counsel in the relevant jurisdictions. The banking relationship was restored within a matter of months, but the disruption to institutional client relationships in the interim was significant – a cost that earlier structural planning would have avoided.
The Travel Rule adds a further cross-border obligation for operators that combine payment services with digital-asset transfers. Under FATF Recommendation 15, the obligation to pass originator and beneficiary data with a virtual asset transfer applies alongside, and independently of, the payment institution's own data-transmission obligations under payment service law. Managing both compliance frameworks simultaneously, across multiple jurisdictions with different de-minimis thresholds, requires a policy architecture that treats them as connected, not parallel.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Contact OBOLUS at info@oboluslaw.com or reach us via t.me/oboluslaw. Map your options.
Common Mistakes That Delay or Derail PI Authorisation
Payment institution applications fail or stall for identifiable, avoidable reasons. The most common is scope mischaracterisation – the applicant describes its activities in terms designed to minimise the licence category required, without understanding that regulators are trained to identify the economic substance of an activity regardless of how it is labelled. A firm that processes client-to-client transfers but calls them "treasury management" is still running a regulated payment service. Regulators see this pattern regularly and it triggers enhanced scrutiny of the entire application.
The second common mistake is inadequate safeguarding architecture. Institutional PI applicants are expected to demonstrate, not merely assert, that client money is held separately, reconciled regularly and insulated from insolvency risk. Where an applicant proposes a safeguarding arrangement that relies on a single account with a single bank, without a documented reconciliation process and an independent audit trail, the regulator will typically require remediation before proceeding. This is a structural fix, not a document fix, and it takes time.
The third mistake is the governance gap. Fit-and-proper requirements for directors and controllers at institutional PI applicants are more demanding than many operators expect. A controlling shareholder or director with a complex cross-jurisdictional ownership structure – common in digital-asset businesses – must be able to demonstrate the full ownership chain, the source of funds at the shareholder level, and the absence of disqualifying regulatory history. Assembling this documentation retrospectively, under regulator time pressure, is significantly harder than building it into the application from the outset.
Finally, the timing of the banking conversation is consistently mismanaged. Operators often delay the banking approach until after licensing, treating it as a downstream question. In practice, the banking due-diligence process runs in parallel with the regulatory application, and the operator that arrives at authorisation without a credible banking partner in place faces a second, equally demanding approval process immediately. We build the banking and regulatory timelines as a single integrated plan from the first day of mandate.
Decision Matrix: Which PI Structure Suits Which Institutional Profile?
Not every institutional operator requires the same PI structure. The right approach turns on activity profile, geographic footprint, regulatory capital position, and the firm's existing licensing stack.
An institutional exchange or OTC desk with a primarily EU-facing client base and an existing or planned CASP authorisation under MiCA is best served by an EU PI or EMI licence in a jurisdiction with a developed supervisory track record – one that allows passporting across the EU/EEA and that integrates cleanly with CASP obligations. The primary risk in this profile is capital adequacy: PI and EMI authorisations carry own-funds requirements that scale with the volume of payment services provided, and an institutional operator processing high volumes will face capital demands that require advance planning.
An operator with a UAE-centred institutional client base, seeking to run fiat rails alongside a VARA exchange or custody licence, needs the VARA transfer-and-settlement authorisation as the primary payment layer – alongside a banking relationship with a UAE-regulated institution that can accommodate the correspondent flow. The cross-border dimension here is acute: institutional clients in this profile frequently settle in currencies that flow through correspondent banks outside the UAE, and each correspondent leg carries its own due-diligence requirements.
An operator building for a global institutional client base – spanning EU, UAE, Singapore and potentially the United Kingdom – will almost always require a multi-entity structure. A single PI licence in a single jurisdiction does not provide the authorisation perimeter, the banking optionality, or the regulatory credibility required to serve institutional counterparties across all four of these markets simultaneously. We map this stack at the outset, identifying the minimum number of entities and licences required to cover the actual activity, and designing the intercompany arrangements that make the structure operationally coherent.
A crypto-native operator entering the payment services space for the first time – perhaps a token issuer adding subscription-payment functionality or a DeFi protocol building a fiat on-ramp – occupies a different position. Here, the question is often whether a full PI authorisation is required immediately or whether an arrangement with an authorised partner (an EMI or PI that provides payment services on a white-label basis) is the appropriate interim structure while the operator's own application is in progress. Both routes carry regulatory and commercial trade-offs that require careful analysis before commitment.
The Myth That a Single Offshore Licence Is Enough
A common assumption in institutional digital-asset circles is that a single PI or EMI licence in a favourable offshore jurisdiction provides adequate regulatory cover for a globally operating business. This assumption is incorrect – and acting on it is one of the fastest routes to enforcement exposure and banking loss.
The reason is jurisdictional nexus. Most payment service regulatory regimes assert jurisdiction based on where the activity occurs, where the clients are located, or where the funds are received – not only where the licensed entity is incorporated. An operator incorporated in the Cayman Islands with a CIMA registration, serving institutional clients who are resident in the EU, is potentially in the perimeter of MiCA and the EU Payment Services Directive regardless of the offshore domicile. The EU does not recognise offshore PI licences as equivalent to CASP or PI authorisation under MiCA; neither does the FCA recognise offshore registration as equivalent to FCA authorisation for the purposes of UK financial-promotion rules or payment service regulation.
Offshore licensing has its place in a well-designed institutional structure – the BVI VASP Act, the Cayman VASP Act, and comparable regimes offer genuine regulatory legitimacy for specific activity profiles and specific client bases. The error is treating the offshore licence as a substitute for, rather than a complement to, authorisation in the jurisdictions where the regulated activity actually occurs. We see this structural gap in the majority of remediation engagements we take on, and it is consistently more expensive to fix after the fact than to design correctly from the outset.
Related to this is the assumption that an operator can rely indefinitely on a transitional or grandfathered status under a regime that is in the process of tightening its rules. MiCA's transition provisions, the VARA regime's evolving activity categories, and the FCA's extended registration deadlines have all created windows of apparent tolerance that operators have, in some cases, treated as permanent. They are not. The enforcement risk does not begin when the transition period ends; it begins when the regulator forms a view that the operator is not progressing toward compliant status.
Related at OBOLUS
- Banking, Payments & EMI Onboarding practice overview – the full regulatory and banking landscape for digital-asset operators seeking fiat rails
- De-risking and account closure defence – legal options when a bank terminates a payment or custody account
- Payment institution licensing for established operators – the process and strategy for operators with an existing regulatory footprint
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of de-risking policies that treat digital-asset businesses as high-risk categories, regardless of the individual firm's compliance profile. The proximate causes include AML/CFT policy concerns, correspondent-bank pressure, regulatory uncertainty in the bank's home jurisdiction, and inadequate documentation from the crypto firm at onboarding. A firm that holds a recognised payment institution or EMI authorisation, demonstrates a well-documented AML framework, and presents a clear business model with institutional counterparties is materially better positioned to sustain banking relationships than one relying on informal or unregulated arrangements.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) seeking to onboard with an EMI (e-money institution) must satisfy the EMI's own compliance requirements, which typically mirror those of the EMI's regulator. This means presenting a VASP authorisation, a documented AML/KYC framework aligned to FATF standards, a clear description of the intended fund flows, and evidence of the VASP's own regulatory status in each jurisdiction where it operates. EMIs that serve digital-asset clients are themselves subject to enhanced supervisory scrutiny, so the quality of the VASP's compliance documentation directly determines the EMI's willingness and speed to onboard.
What does client-money safeguarding require?
Client-money safeguarding under payment institution and EMI regimes requires that funds received from clients be held separately from the firm's own funds, in designated accounts at authorised credit institutions, and reconciled on a documented and regular schedule. In most leading regimes, the safeguarding obligation is supplemented by a requirement for an insurance or comparable arrangement to cover any shortfall in the event of the institution's insolvency. For institutional operators handling large-value or multi-currency flows, the practical demands of building and evidencing a compliant safeguarding architecture are significant and should be addressed before the application is filed.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance frameworks that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence, banking and payment-institution stack across operating, custody and payment layers before you commit – so the structure you build is the structure that holds. To discuss your payment institution licensing needs, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in payment institution and VASP authorisation across EU, UAE, UK and Asia-Pacific regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.