EST · MMXXVI
Home/Services/Banking Payments Emi/Payment institution licensing from a Cross-border Perspective
Banking, Payments & EMI Onboarding

Payment institution licensing from a Cross-border Perspective

Payment institution licensing from a Cross-border Perspective. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk

Payment Institution Licensing from a Cross-border Perspective

Operating a digital-asset business without the right payment institution licence is not a compliance gap — it is an existential risk. Regulators across the EU, the UK, the UAE and Singapore have moved, in recent cycles, to treat unlicensed payment activity as a priority enforcement matter. Rails get frozen. Accounts get closed. And the window to remediate, once a bank or regulator flags the structure, is measured in days rather than months. For any business that touches fiat — on-ramps, off-ramps, client-fund settlement, or custody float — the question of payment institution licensing (the authorisation that permits a legal entity to provide payment services to third parties) sits at the centre of the regulatory stack. This page sets out the regulated basis, the cross-border dynamics that shape it, the common structural mistakes we see, and a practical decision matrix for operators at the build or re-structure stage.

Why Does Payment Institution Licensing Matter for Crypto Businesses?

Payment institution licensing matters for crypto businesses because virtually every fiat-touching function in the digital-asset stack — client on-ramp, settlement, custody float, card issuing — qualifies as a regulated payment service in the major jurisdictions. The failure to hold the correct authorisation does not produce a licensing gap that can be quietly corrected; it produces a position that banks, correspondent banks and payment-network members can and do use as grounds to terminate or refuse accounts.

We regularly advise businesses that built their initial structure around a single crypto-asset registration — a VASP notification, for example, or a crypto-asset service provider (CASP) authorisation under MiCA — and discovered only later that their fiat-handling activities required a separate payment institution or electronic money institution (EMI, an entity authorised to issue electronic money and provide payment services) licence. The two regimes do not automatically overlap. A MiCA CASP authorisation does not permit the entity to hold client funds as electronic money. A VASP registration under the UK's Money Laundering Regulations does not authorise payment services. These are distinct authorisations, and in cross-border structures they are required in layered combination.

The commercial consequence is direct. A business that routes client fiat through an entity that is not authorised for payment services in the relevant jurisdiction faces de-risking pressure from its banking partners, potential enforcement action from the payment-services regulator, and the reputational cost of a public finding. In our practice, we have seen enforcement actions lead to multi-month interruptions in fiat-settlement capacity — an outcome that, for an exchange or a custodian, is close to a full operational shutdown.

MiCA and the EU Payment Services Directive regime both operate on the principle that the substance of the activity — not its label — determines which authorisation applies. Operators who structure around that principle from the start avoid the most damaging remediation scenarios.

OBOLUS maps the full licence, banking and compliance stack before you commit to a structure. The process above describes the standard path. Your facts — the entity type, the user base geography, the fiat-flow architecture — change the analysis substantially. For a scoped assessment, contact OBOLUS at info@oboluslaw.com.

The Regulated Perimeter: What Triggers a Payment Licence?

The regulated perimeter for payment institution licensing is defined by the nature of the service performed, not by the technology used to perform it. Across the major regulatory regimes — the EU payment-services framework, the UK's Payment Services Regulations, MAS's Payment Services Act in Singapore, and the UAE's CBUAE payment-services regime — the common trigger is the execution, initiation or facilitation of a payment transaction involving funds held on behalf of a third party.

For a digital-asset business, the activities most commonly caught within that perimeter include: receiving fiat from clients and holding it pending a crypto purchase; executing fiat withdrawals upon redemption of crypto holdings; issuing prepaid instruments or stored-value products denominated in fiat; and operating as an intermediary in a fiat-to-fiat transfer that accompanies a crypto settlement. Each of these maps, in the relevant jurisdictions, to a defined payment-service category.

The EU's payment-services regime — implemented through MiCA's parallel regime and the underlying payment-services legislative framework — distinguishes between a payment institution (a PI, authorised to provide payment services but not to issue e-money) and an EMI. An EMI may both issue e-money and provide payment services; a PI may only provide services from a defined list without issuing e-money. The distinction matters operationally. A crypto exchange that issues a stored-value account to clients, crediting fiat proceeds of a sale, is likely issuing e-money — not merely providing a payment service. That distinction determines which authorisation is required and, in turn, which capital and safeguarding obligations apply.

Singapore's MAS regime under the Payment Services Act uses a different taxonomy — money-changing, standard payment institution and major payment institution tiers — but the underlying logic is the same: the nature of the service and the volume of transactions determine the licence tier. Hong Kong's SFC VATP regime and the VARA regime in Dubai similarly require separate authorisations for payment and settlement services that sit outside the core crypto-asset activity licence.

The Cross-border Reality: Where the Entity Sits vs. Where the Money Flows

The most common structural error in cross-border digital-asset businesses is a mismatch between the jurisdiction of the licensed entity and the jurisdictions in which the payment services are actually provided. An EU passportable PI or EMI authorisation addresses the EU perimeter — but it does not cover UK users following the end of passporting, does not cover UAE-based clients, and does not satisfy Singapore's MAS licensing requirements for services provided from or to Singapore-resident users.

In our cross-border practice, we map three distinct axes for every structure: (1) where the legal entity is incorporated and licensed; (2) where the users or counterparties are located and receive the service; and (3) where the fiat funds physically flow — the banking jurisdiction, the correspondent-bank chain, and the settlement layer. These three axes frequently point to different jurisdictions, each with its own licensing and safeguarding requirements.

The EU's passporting mechanism under the payment-services regime is a genuine efficiency for operators targeting the EEA. A PI or EMI authorised in one member state may notify its home-state regulator and passport the service across the EU/EEA without requiring separate authorisations in each host state. This makes the choice of home-state NCA — and the speed and cost of the authorisation process — a material business decision. In our practice, we regularly advise on the relative positioning of different EU member states for PI and EMI authorisation, weighing regulator responsiveness, capital expectations and the practical speed of the process.

Outside the EU, passporting does not exist. A UK FCA-registered payment institution provides services in the UK. A MAS-licensed DPT service provider operates in Singapore. These are separate authorisations requiring separate capital, separate compliance infrastructure and, typically, separate local management. A structure that relies on a single EU or offshore EMI to serve a globally distributed user base is, in legal terms, almost certainly providing unlicensed payment services in the jurisdictions where the unlicensed perimeter applies.

The banking layer compounds this. A payment institution that holds client funds must hold them with a credit institution in an account that meets the safeguarding requirements of the relevant regime. In practice, this means the EMI or PI must maintain a banking relationship in a jurisdiction where it is authorised — and that banking relationship is the first casualty when a bank's correspondent review identifies that the entity's licence does not cover the activities it is performing.

How Does the Payment Institution Application Process Work?

A payment institution or EMI application is a structured regulatory process that requires a detailed business model submission, a programme of operations, a governance pack, a capital assessment and, in most jurisdictions, an AML/CFT policy framework before the application is formally accepted as complete by the relevant regulator.

The broad steps are consistent across the major EU member-state NCAs, the FCA and MAS, even if the specific requirements and timelines vary materially:

  • Pre-application engagement: most regulators permit or expect a pre-application meeting or written query to clarify the scope of the proposed activities and the applicable licence category. This step is not optional in practice — it saves significant rework at the full-application stage.
  • Business model and programme of operations: a detailed description of the payment services to be provided, the client base, the projected transaction volumes and the operational model, including the technology stack and outsourcing arrangements.
  • Governance and fit-and-proper assessment: directors and senior managers must satisfy the regulator's fit-and-proper requirements. In most jurisdictions this requires criminal records checks, financial soundness verification and a demonstration of relevant experience.
  • Capital and financial projections: each licence category carries a minimum capital requirement (the specific figure varies by regime and category and should be confirmed against current legislation). The application must demonstrate that the entity meets the requirement on authorisation and will maintain it thereafter.
  • AML/CFT framework: a compliant AML/CFT policy, including a risk assessment, a compliance officer designation and, where the Travel Rule applies, a documented approach to the obligation to pass originator and beneficiary data with qualifying transfers.
  • Safeguarding mechanism: a documented approach to client-fund safeguarding — either segregation in a dedicated account with a credit institution or an insurance/guarantee arrangement.

Timelines from submission of a complete application to authorisation vary materially by jurisdiction, regime and the complexity of the business model. In the EU, the process at most NCAs is measured in months rather than weeks; certain member states have historically processed applications more quickly than others. The FCA's payment-services authorisation process has historically taken longer than EU counterparts. MAS timelines similarly vary by application complexity. These are qualitative benchmarks — the specific timeline for any given application depends on the completeness of the submission and the regulator's current caseload.

A recurring practical point: a formally incomplete application resets the clock. The most common cause of delay in the processes we support is a business model submission that does not address the cross-border dimension — it describes the service as if it will be provided only in the home jurisdiction, when the commercial reality involves users or flows in multiple markets. Regulators increasingly ask direct questions about cross-border activity early in the review. An application that cannot answer them credibly does not progress.

Common Structural Mistakes in Cross-border Payment Licensing

The most damaging structural mistakes in cross-border payment licensing share a common origin: they were built around what the operator wanted the structure to be, rather than what the regulated perimeter requires it to be.

The first and most frequent mistake is the single-licence fallacy — the assumption that one PI or EMI authorisation, typically in an EU member state or a smaller offshore jurisdiction, is sufficient to cover all payment activity regardless of where clients are located or where funds flow. That assumption is a myth. A single EU EMI authorisation covers the EEA; it does not cover the UK, the UAE, Singapore or the United States. An offshore VASP registration covering crypto-asset services does not substitute for a payment institution authorisation in any jurisdiction. The licensing stack for a business with a global user base is, by design, multi-jurisdictional — and the cost of ignoring that is enforcement exposure in every jurisdiction where the unlicensed perimeter applies.

The second mistake is treating the AML/CFT compliance function as a documentation exercise rather than an operational one. Regulators conducting supervisory visits — and banks conducting their own due diligence on a new EMI customer — both examine whether the AML/CFT framework is embedded in the operation, not merely written down. A policy that does not reflect the actual client base, transaction types or jurisdictions served will fail both tests. The Travel Rule (the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary information with qualifying virtual-asset transfers) is a particular area of scrutiny: many EMIs and PIs processing crypto-related fiat flows have Travel Rule exposure that their initial compliance programmes did not anticipate.

The third mistake is inadequate safeguarding. Client-fund safeguarding requires either segregation in a dedicated account with an authorised credit institution or a qualifying insurance or guarantee arrangement. In practice, the segregation route requires a banking relationship that most conventional banks are unwilling to provide to a crypto-adjacent business without a track record and a complete compliance framework already in place. Businesses that have not resolved their banking strategy before applying for their payment licence frequently discover that the licence is granted before the safeguarding mechanism is operational — at which point the authorisation cannot be used.

In a recent engagement, a payments company with an EU EMI authorisation and a growing base of VASP clients sought to expand its services into the UK market. The structure assumed that the existing EU authorisation, combined with a contractual pass-through to a UK banking partner, would cover the regulated perimeter. It did not. We identified that the UK-facing activity required separate FCA authorisation and that the existing banking arrangement did not meet the FCA's safeguarding requirements. We structured a remediation path — a UK branch application combined with a revised safeguarding agreement — and the business resumed UK activity on a compliant footing before the regulatory review that had already been initiated was concluded.

If a prior application stalled or an account was closed, a second-read analysis can surface the structural reason and the route back. To map the licence, banking and compliance stack for your build, write to info@oboluslaw.com.

Decision Matrix: Which Payment Licence for Which Operator Profile?

The right payment institution structure depends on the operator's business model, user base and fiat-flow architecture. No single structure fits all profiles — and the advice that a particular jurisdiction or licence type is "standard" for crypto businesses is rarely accurate in any specific situation.

Profile A — EU-focused crypto exchange or custodian seeking full fiat-rail control: An EMI authorisation from an EU NCA, passported across the EEA, is the appropriate instrument. The EMI structure permits client e-money issuance, fiat settlement and custody float. The capital requirement is higher than a PI, and the safeguarding obligations are more prescriptive — but the commercial flexibility is materially greater. The timeline is measured in months; the pre-application engagement with the NCA is essential. The key risk is banking: the EMI must establish a safeguarding account with a credit institution that accepts crypto-adjacent payment businesses as clients. We advise on both the NCA selection and the banking strategy in parallel.

Profile B — Non-EU digital-asset business seeking EU market access without a full subsidiary: A PI authorisation in an EU member state with a defined, limited list of payment services is a faster route to market than a full EMI. The PI structure is appropriate where the business does not need to issue e-money — for example, where the fiat settlement function is limited to receiving and transmitting client funds in connection with crypto transactions. The capital requirement is lower; the authorisation timeline is generally shorter. The cross-border limitation is the same: the EU authorisation covers the EEA only. For UK or Singapore activity, separate local authorisation is required.

Profile C — Global multi-product operator (exchange, custody, lending, payments): The structure requires a layered authorisation approach. An EU EMI or PI for the EEA perimeter; FCA authorisation for UK activity; a MAS Payment Services Act licence for Singapore; and, where the business targets UAE clients, engagement with the CBUAE and VARA frameworks for the respective payment and crypto-asset activities. Each authorisation requires its own governance, capital and compliance infrastructure — in practice, this means a multi-entity group with local management and independent compliance functions in each regulated jurisdiction. The coordination of these structures — so that intra-group flows do not themselves create unlicensed payment activity — is a material legal-structuring exercise.

Profile D — Early-stage or single-jurisdiction operator seeking to onboard with an established EMI rather than self-licence: For businesses that are not yet at the scale to justify the cost and governance burden of a direct payment institution authorisation, the practical route is EMI onboarding — a contractual arrangement with an authorised EMI or banking-as-a-service provider that provides the fiat-rail access under the EMI's own authorisation. This route is faster and cheaper in the short term, but it transfers control of the fiat rail to a third party that may itself be subject to de-risking pressure. In our practice, we regularly advise on the contractual protections that a business in this position should seek — termination notice periods, data portability, reserved capacity — and on the migration path to a direct authorisation as the business scales.

AML/CFT and the Travel Rule in Payment Institution Structures

AML/CFT compliance for a licensed payment institution is not a one-time documentation exercise — it is a living operational framework that regulators and banking partners both assess on a continuing basis. For payment institutions that serve digital-asset businesses or that process fiat flows connected to crypto transactions, the compliance exposure is heightened.

The Travel Rule, derived from FATF Recommendation 15 and implemented with jurisdiction-specific thresholds across the EU, UK, Singapore and other major regimes, requires that originator and beneficiary information travel with a qualifying virtual-asset transfer. For a payment institution processing the fiat leg of a crypto transaction, this creates a specific compliance question: at what point does the PI's obligation to collect and transmit payment-chain data intersect with the VASP's Travel Rule obligation on the crypto leg? The answer depends on the structure of the transaction and the roles of the entities involved — but the general principle is that a PI that is part of the settlement chain for a VASP transaction cannot isolate itself from the Travel Rule data obligations that attach to that transaction.

In practice, this means that a payment institution's AML/CFT framework must explicitly address the crypto-adjacent nature of its client base, the transaction monitoring parameters appropriate for crypto-connected fiat flows, and the escalation procedures when a transaction pattern presents heightened risk. Banks that serve PIs and EMIs as safeguarding-account providers routinely conduct their own AML reviews of the PI's client base — and a PI that cannot demonstrate a credible, operational compliance framework for its crypto-business clients will lose its safeguarding account, which in turn means losing its authorisation in functional terms.

Self-Assessment Checklist for Payment Institution Readiness

Before committing to a payment institution application — or to an EMI onboarding arrangement — a digital-asset business should work through the following questions. These do not substitute for legal advice, but they frame the issues that determine the correct instrument and the realistic timeline.

  • Is the business's fiat-handling activity limited to crypto-connected settlement, or does it include standalone payment services that require their own authorisation in the jurisdictions where clients are located?
  • Does the business need to issue e-money (credit a stored-value balance in fiat to a client account) — or only to receive, hold and transmit fiat in connection with crypto transactions? The answer determines whether an EMI or a PI is the correct authorisation.
  • Where are the clients located? The answer maps the jurisdictions whose regulated perimeters the activity potentially engages — and therefore the combination of licences the group structure requires.
  • Has the business identified a banking partner willing to provide a safeguarding account before — not after — the application is submitted?
  • Does the governance structure include a resident compliance officer with AML/CFT experience appropriate to the crypto-adjacent client base?
  • Has the AML/CFT framework been reviewed specifically for Travel Rule compliance in each jurisdiction where the business operates?
  • Is the business model submission for the application — the programme of operations — accurate as to the cross-border dimension of the activity?

A "no" or "not yet" to any of these is not necessarily a blocker — but it is a material risk factor that needs to be resolved before or during the application process, not discovered after the regulator has asked the question.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because the account-holding business does not hold — or cannot demonstrate that it holds — the regulatory authorisations that the bank's compliance team requires for the account purpose. De-risking pressure from correspondent banks amplifies this: a bank that itself relies on correspondent relationships cannot afford a client whose activities draw adverse correspondent-bank scrutiny. A demonstrably licensed, well-documented crypto business is materially more bankable than one relying on a narrow registration that does not cover the fiat-touching activities it actually performs.

How can a VASP onboard with an EMI?

A VASP (virtual asset service provider) seeking to onboard with an EMI for fiat-rail access must demonstrate to the EMI's compliance function that its own AML/CFT framework, its licensing status and its transaction-monitoring capabilities meet the EMI's risk appetite. In practice this means providing a current regulatory status certificate, an AML policy tailored to the VASP's activity, evidence of Travel Rule compliance capability, and a clear description of the client base and transaction types. EMIs that accept VASP clients typically impose ongoing reporting obligations and reserve the right to exit the relationship on short notice — contractual protections on that point are important.

What does client-money safeguarding require?

Client-money safeguarding under most payment-institution regimes requires that funds held on behalf of clients are either held in a dedicated segregated account with an authorised credit institution — separate from the firm's own funds and protected in the event of the firm's insolvency — or covered by a qualifying insurance policy or guarantee. The specific requirements, including the timing of segregation, the eligible account types and the reporting obligations, vary by regime. In the EU and UK frameworks, the safeguarding obligation attaches from the moment client funds are received, not from the end of a business day.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice, and we act only for businesses — which means our analysis is always calibrated to the operator's perspective, not the retail investor's. We map the full licence stack across operating, custody and payment layers before you commit to a structure. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst — specialises in payment institution and CASP licensing strategy for cross-border digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours