A payment institution (PI) licence – the regulated authorisation that permits a business to execute payment transactions, issue e-money or provide account-information services on behalf of third parties – is no longer a secondary consideration for a digital-asset company. It is increasingly the admission ticket to fiat rails, institutional banking relationships and compliant customer onboarding. Operating without one, or operating on a licence that does not match the activity profile, exposes the business to supervisory enforcement, abrupt account closures and, in the worst cases, cessation of client flows. The pages that follow lay out exactly what a regulated entity must understand before it applies.
Payment institution licensing for regulated entities sits at the intersection of payments law, VASP (virtual asset service provider) regulation and banking access policy. The precise requirements – the scope of the regulated activity, the capital and safeguarding obligations, the AML framework – turn on which jurisdiction issues the licence and where the entity's clients are located. A UK fintech authorised under FCA rules cannot automatically offer services across the EU; a CASP authorised under MiCA still needs a payment layer if it handles client fiat. Those distinctions drive the entire structuring exercise.
This page covers the regulated basis for PI licensing, the application process and common failure points, the cross-border layer that crypto companies consistently underweight, and a decision matrix for matching business profile to licence structure.
What is the regulated basis for payment institution licensing?
The legal trigger for PI authorisation is the act of executing, initiating or acquiring a payment transaction on behalf of a third party – or issuing instruments that represent stored monetary value. That definition, applied consistently across the major regulated hubs, captures a broader set of crypto-business activities than most founders expect. Custodians that receive and transmit fiat on behalf of clients, exchanges that aggregate client funds before settlement, and token issuers that offer redemption in fiat all land inside the regulated perimeter.
In the EU and EEA, the applicable regime is the Payment Services Directive framework, supervised by national competent authorities and, for the e-money dimension, the EMI (electronic money institution) authorisation regime. Under MiCA, a CASP that also issues e-money tokens is required to hold an EMI authorisation – the two regulatory frameworks do not collapse into one. In the United Kingdom, the FCA supervises payment institutions and EMIs under the Payment Services Regulations and the Electronic Money Regulations respectively; a company with an FCA cryptoasset registration still requires separate authorisation for payment activity. In Singapore, MAS licenses payment businesses under the Payment Services Act, with tiered categories that cover digital payment token services alongside e-money issuance and account issuance.
The cross-border dimension is critical from day one. A payment licence issued in one jurisdiction does not, as a rule, extend the right to serve clients or onboard banking counterparties in another. EU passporting – the right of an authorised payment institution or EMI to notify into other member states without a fresh authorisation – applies within the EU/EEA, but not beyond it. A Cayman-registered entity holding a CIMA registration cannot rely on that status to access European payment infrastructure. Operators we advise regularly discover this gap only after a banking partner declines to extend services to a new market.
The jurisdictions that matter most for the businesses we advise – the EU (including Lithuania and Malta as fast-entry member states), the UK, Singapore and the UAE – all require a locally authorised entity or a passported branch for payment activity directed at their residents. That geographic principle is the starting point for every licensing architecture we build.
To map which regulated activities your current structure is missing, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis.
How does the PI licence application process work?
A well-prepared payment institution application typically moves through four stages: pre-application engagement with the regulator, preparation of the application package, formal review and a fit-and-proper assessment of senior management, and post-authorisation conditions. The elapsed time at each stage varies by jurisdiction, category of authorisation and the completeness of the submission – regulators in the major hubs are explicit that incomplete applications reset the review clock.
The application package is the stage where most first-time applicants underperform. At a minimum it requires a detailed business plan (including projected transaction volumes, client types and revenue model), a wind-down plan, an organisational chart with mapped reporting lines, documented AML/CFT policies calibrated to the FATF Recommendations (including the Travel Rule – the obligation to pass originator and beneficiary data with a transfer), outsourcing agreements and IT security documentation. Regulators increasingly expect a narrative that explains the payment flow end to end, from client onboarding to settlement, rather than a compliance checklist.
The fit-and-proper assessment of directors, senior managers and qualifying shareholders adds a parallel track. Regulators require disclosure of prior regulatory history, criminal record checks and, in some hubs, evidence of relevant professional experience. Where a founder or director has a prior adverse regulatory finding – even in a different jurisdiction – that needs to be addressed proactively in the submission, not discovered by the regulator mid-review.
In our practice, the most common delay at this stage is the banking-and-safeguarding loop. Most PI regimes require the applicant to demonstrate, before or very shortly after authorisation, that it holds a safeguarding account at a credit institution – meaning a bank or a licensed EMI – that will segregate client funds. Getting that account opened before the licence is granted, while the regulator expects confirmation of the account for the application, is the chicken-and-egg problem that stalls many competent applicants. We have worked through this sequencing challenge for clients across several EU member states and the UK.
What are the most common mistakes regulated entities make in PI licensing?
The failure mode we see most often is misclassification of the regulated activity – structuring a business around a lighter-touch registration when the actual flows require full authorisation. A company that processes client fiat on behalf of counterparties, even temporarily, is executing a payment service. Treating that as an incidental treasury function rather than a regulated payment activity creates a gap that regulators, banks and institutional clients will all identify eventually.
The second failure mode is geographic overreach. A regulated entity that holds a PI licence in one EU member state and passports into two others may then onboard clients in a third member state without completing the requisite passport notification. The notification process is administrative but mandatory. Skipping it – on the reasonable but incorrect assumption that authorisation implies general EU coverage – produces an unlicensed-activity exposure in the third state. We regularly advise clients on regularising exactly this situation.
Third is the treatment of crypto-to-fiat flows as outside the payment perimeter. An exchange that converts digital assets to fiat and then transmits that fiat to a client's bank account is, in most regulated environments, providing a payment service for that final leg. The crypto leg may be covered by a VASP or CASP licence; the payment leg usually is not. Operating without a PI or EMI licence for that transmission exposes the entity to enforcement by the payments supervisor – a different authority, in some jurisdictions, from the crypto regulator.
Fourth is inadequate capital and own-funds planning. PI regimes set minimum capital by activity category and may also require an own-funds buffer calculated on a percentage of payment volume. Operators that model only the minimum capital at incorporation, without stress-testing it against growth projections and own-funds calculations, can find themselves below the regulatory threshold within twelve months of launch without having anticipated the shortfall.
How does PI licensing interact with cross-border crypto operations?
For a digital-asset business operating across more than one jurisdiction – which in our experience describes the overwhelming majority of clients – the payment institution layer cannot be planned in isolation. It sits above a VASP or CASP licence, alongside a custody regime and, for token issuers, a securities or ART/EMT framework. Each layer has its own regulator, its own capital expectation and its own AML posture. They do not automatically cohere.
The EU presents the clearest illustration. A CASP authorised under MiCA in Lithuania, passporting across the EEA, still requires an EMI or PI authorisation for the fiat legs of its operations. The Bank of Lithuania supervises both tracks, but they are distinct applications, distinct ongoing supervisory relationships and distinct compliance programmes. Building them in parallel – rather than sequentially – saves months and avoids the operational gap that arises when the CASP is live but the EMI is still in review.
In the UAE, the interaction is different but equally layered. A VARA-licensed exchange in Dubai may need to engage with the UAE Central Bank on the payment side if fiat transmission is within scope. VARA's rulebooks and the Central Bank's payment-services framework operate in distinct regulatory perimeters; a business that spans both must manage two supervisory relationships. In our cross-border practice, we map those interactions before the first application is filed, not after the second regulator raises a query.
Banking access is the practical expression of the cross-border challenge. Banks in the major financial centres assess incoming PI applicants against the licensed entity's activity profile, the jurisdictions where it operates and the quality of its AML programme. A Cayman-registered holding company referring its fiat flows through an EU subsidiary with a PI licence is a structure banks understand – but only if the intercompany arrangements, the flow-of-funds documentation and the AML controls are coherently documented from the outset. Banks that have reviewed a client's structure once, found gaps and declined, are materially harder to re-approach without an independently structured remediation narrative.
In a matter handled earlier this year, a cross-border payments company with operations across two jurisdictions approached us after its primary banking relationship was terminated. The bank had not raised AML concerns directly; the closure was prompted by a mismatch between the client's stated business profile in the account-opening documentation and the actual transaction patterns – a higher proportion of crypto-related inflows than the bank's internal risk appetite accommodated. We restructured the entity's payment flow documentation, identified an EMI partner with explicit digital-asset onboarding policies and introduced the client through a structured submission. The company was onboarded within a commercially acceptable timeline and the original banking gap was closed through a secondary relationship established in parallel.
If you are managing a banking gap or a cross-border licensing mismatch, write to OBOLUS at info@oboluslaw.com for a scoped assessment. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back.
How can a VASP or crypto business onboard with an EMI?
Onboarding a digital-asset business with an EMI (electronic money institution) – a licensed issuer of electronic money that typically provides IBAN accounts, payment processing and fiat settlement – requires a different approach from standard corporate account opening. EMIs operate under regulatory capital and own-funds obligations that incentivise them to manage risk exposure per client type; crypto businesses land in a risk category that receives enhanced scrutiny in virtually every regulated EMI's onboarding matrix.
The practical requirements vary by EMI. Most require a clean regulatory status – the VASP or CASP licence in good standing, with no open supervisory inquiries. They require AML documentation at least as detailed as a banking submission: the AML/KYC policy, the transaction monitoring framework, the PEP and sanctions screening process, the governance structure and the ultimate beneficial owner (UBO) chain. Some EMIs additionally require a forensic or compliance-technology partner confirmation – for example, a report from a recognised blockchain analytics provider confirming the entity's transaction monitoring capability.
In our practice, we have seen EMI onboardings move significantly faster when the client presents a structured submission package rather than responding reactively to a due-diligence questionnaire. The difference between a two-week onboarding and a three-month review cycle is almost always the quality and completeness of documentation provided at the outset. We prepare that package as a standard part of the licensing mandate, rather than treating banking access as a downstream problem.
Which PI or EMI structure fits your business profile?
The right licensing structure depends on three variables: the activity scope, the geographic footprint and the pace of growth. No single structure fits all profiles, and the analysis changes as a business scales.
Profile A – Early-stage VASP or exchange, primarily EU-focused, seeking fiat on-ramp: A CASP authorisation in a fast-entry EU member state such as Lithuania or Malta, combined with an EMI onboarding engagement (rather than a standalone PI licence at this stage), is typically the most capital-efficient entry path. The EMI relationship provides fiat rails immediately; the PI licence is built out as volume grows and the business case for holding the payment infrastructure directly becomes clear. The primary risk at this profile is the EMI's ongoing risk-appetite review – a relationship that works at launch may not survive a material increase in crypto-related volumes without a proactive communication strategy.
Profile B – Established exchange or custodian with multi-jurisdictional user base: A standalone PI or EMI authorisation in the EU (for the European user base) combined with a MAS-licensed payment entity in Singapore (for the Asian corridor) and a VARA-licensed entity in Dubai (for the MENA market) represents a three-entity structure that matches regulatory perimeter to client geography. The complexity and capital commitment are higher, but the resilience – against any single regulator's risk-appetite shift – is substantially greater. Timeline to full operability across all three hubs is, qualitatively, a matter of quarters rather than weeks, and requires integrated project management across the licensing, banking and compliance workstreams.
Profile C – Token issuer with ART or EMT classification under MiCA: An entity issuing an asset-referenced token or e-money token under the MiCA regime must obtain the relevant authorisation (ART issuer or EMI for EMTs) from an EU national competent authority. The payment institution layer is embedded in the EMT issuer authorisation; what the issuer additionally needs is a distribution and redemption infrastructure that does not itself constitute an unauthorised payment service. That line – between issuing an instrument and providing payment services using it – requires specific analysis at the product design stage, before the whitepaper is finalised.
Is a single offshore licence sufficient for global operations?
A common assumption among early-stage operators is that a single offshore registration – typically from a jurisdiction with a lighter-touch regime and lower capital requirements – is sufficient to serve a global user base, provided that users access the platform through a terms-of-service click. That assumption is incorrect in virtually every major market.
Regulators in the EU, UK, Singapore, Hong Kong and the UAE all apply some variant of a nexus test: if a business actively solicits, markets to or provides services to residents of the jurisdiction, the activity falls within the supervisory perimeter regardless of where the corporate entity is registered. The FCA's financial-promotion rules apply to crypto marketing directed at UK persons irrespective of the promoter's location. MiCA's regime applies to CASPs offering services to EU clients, not merely to EU-incorporated entities. VARA's activity-based licensing structure captures entities that operate "in or from" Dubai.
The offshore single-entity model may be appropriate as a holding or treasury vehicle in certain structures – the Cayman Islands and BVI serve that function well under the CIMA and BVI FSC frameworks respectively. But the operating entity – the one that touches client funds, executes transactions and runs the user-facing platform – requires authorisation in the jurisdictions where those clients sit. Building the structure that way from the outset is materially less expensive than regularising it after a regulator's inquiry or a banking partner's due-diligence question surfaces the gap.
What does client-money safeguarding require in practice?
Client-money safeguarding – the obligation to hold funds received from payment-service users in a designated safeguarding account at a credit institution, separate from the firm's own funds – is a capital-equivalent protection mechanism that most PI and EMI regimes impose as a condition of authorisation. It is also, in practice, one of the most operationally demanding ongoing obligations that a newly authorised payment institution must manage.
The mechanics differ by jurisdiction, but the core principle is consistent: client funds received for the purpose of executing a payment transaction must not be mixed with the firm's proprietary funds, must be held at an institution (a bank or authorised EMI) that acknowledges the safeguarding obligation, and must be reconciled daily. Regulators expect a documented reconciliation process, an acknowledgment letter from the bank confirming the safeguarding status of the account, and a clear audit trail connecting client liabilities to the safeguarding account balance.
For digital-asset businesses, the additional complexity is that client positions may move rapidly between fiat and crypto. A company that holds fiat on behalf of clients and also holds digital assets on their behalf must segregate both categories of asset correctly and maintain the fiat safeguarding requirement even during periods when the majority of client value is held in crypto form. Regulators in the major hubs are explicit that the obligation does not disappear because the fiat balance is temporarily low.
In our practice, we structure safeguarding documentation as part of the initial licence application and then build the ongoing compliance calendar around the reconciliation obligation. A safeguarding deficiency – identified in a supervisory review or an audit – is among the most serious post-authorisation compliance failures a payment institution can face. Addressing it proactively, before the first supervisory visit, is materially less disruptive than responding to a notice of supervisory concern.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital-Asset Businesses – our full practice overview covering the licence, bank and compliance stack for crypto operators
- Corporate bank account opening in Turkey – jurisdiction-specific guidance on establishing fiat banking access in Turkey for regulated entities
- Payment institution licensing for established operators – a deeper dive for companies with existing licensed structures seeking to expand or restructure
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of a mismatch between the client's documented risk profile and the bank's internal risk-appetite policy. The most common triggers are: transaction patterns that deviate from the stated business model; an AML programme that does not meet the bank's enhanced due-diligence standard for virtual-asset businesses; and insufficient regulatory licensing relative to the scope of activity. A bank that declines or closes an account rarely explains the precise reason, which makes pre-submission structuring of the account-opening package – with explicit AML and licensing documentation – the most reliable mitigation.
How can a VASP onboard with an EMI?
A VASP seeking to onboard with an EMI should approach the process as a regulatory submission rather than a standard commercial application. The EMI will conduct enhanced due diligence, requiring at minimum the VASP licence, a detailed AML/KYC policy, the UBO structure, and transaction monitoring documentation. Many EMIs additionally require confirmation of a blockchain analytics or compliance-technology integration. Presenting a complete, structured package at the outset – rather than building it reactively across a due-diligence questionnaire – is the factor that most consistently reduces onboarding timelines from months to weeks.
What does client-money safeguarding require?
Client-money safeguarding under PI and EMI regimes requires that funds received for payment purposes be held in a designated account at a credit institution or authorised EMI, kept strictly separate from the firm's own funds. The firm must maintain daily reconciliations, hold a written acknowledgment from the bank confirming the safeguarding designation, and ensure the balance at all times covers aggregate client liabilities. Regulators treat safeguarding deficiencies as serious compliance failures; the obligation applies continuously, regardless of whether client funds are predominantly in fiat or digital-asset form at any given time.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack across operating, custody and payment layers before you commit – structuring licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in payment institution authorisation, VASP licensing and cross-border regulatory structuring for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.