Operating a digital-asset business without the correct payment institution licence is not a grey-area risk. It is an enforcement event waiting to happen – frozen rails, blocked accounts, and in some regimes, criminal exposure for the individuals who signed the applications. As supervisors across the EU, the UAE, Singapore and the UK tighten oversight of payment institution (PI) authorisation, the cost of getting the structure wrong has never been higher.
Payment institution licensing for digital-asset firms sits at the intersection of two demanding regulatory regimes: the payment-services framework and the virtual-asset service-provider (VASP) regime. A firm that holds a VASP licence but lacks the PI authorisation needed to move fiat cannot operate its business end-to-end. The gap is frequently overlooked – and it is the gap that banks, correspondents and card schemes examine first.
This page explains what payment institution licensing involves for crypto-native businesses, where the common failures arise, and how OBOLUS structures the engagement from initial gap analysis through to authorisation and live rails.
What payment institution licensing covers for digital-asset businesses
A payment institution authorisation permits a firm to provide regulated payment services – account issuance, fund transfers, payment initiation, acquiring – to customers in exchange for a fee. For a digital-asset business, the PI licence is the legal instrument that ties the fiat side of the operation to the crypto side. Without it, the business is dependent entirely on third-party EMI (electronic money institution) or PI access, which is revocable at short notice.
The regulated perimeter matters. Most flagship regimes distinguish between PI authorisation (full) and registration (light-touch, with lower volume thresholds). Under MiCA and the underlying EU payment-services regime, a firm providing payment services above the applicable threshold must hold full PI authorisation from a national competent authority and can passport that authorisation across the EU/EEA. In the UAE, the activity falls under VARA's transfer-and-settlement activity class if it is crypto-to-crypto, but fiat settlement requires separate engagement with the Central Bank of the UAE for PI coverage. In Singapore, the Payment Services Act administered by MAS creates distinct licence tiers – standard payment institution and major payment institution – with the applicable tier determined by transaction volumes and float thresholds, both of which are [VERIFY] and must be checked against current MAS guidance before any application.
In our practice, we see firms assume that holding a VASP registration automatically permits them to collect and transmit client fiat. It does not. The two frameworks are legally distinct, and the banking community treats them as such.
What is the regulated basis, and why does cross-border structure matter?
The regulated basis for a payment institution licence is determined by where the firm is incorporated, where its customers are located, and where the funds flow. A firm incorporated in one EU member state but serving customers in another is subject to both the home-state authorisation process and the host-state notification obligations under the EU payment-services passporting mechanism. A firm that incorporates offshore to avoid EU supervision but processes euro payments for EU residents is not outside the regime – it is inside it, without the authorisation that would make the activity lawful.
Cross-border structuring is therefore not optional. It is the central question. We regularly advise clients who have built a product first and asked the licensing question second. The discovery is almost always the same: the entity structure that made sense for tax or operational reasons has created a payment-services nexus in a jurisdiction where the firm has no authorisation and no banking.
The cross-border interaction between PI authorisation and VASP licensing creates a specific structural problem. A VASP authorised under VARA in Dubai and serving EU customers may need either a MiCA CASP authorisation for the crypto layer or an EU PI authorisation for the fiat layer – or both. The ADGM FSRA regime in Abu Dhabi handles virtual assets and payment services within a single common-law perimeter, but that coverage does not extend beyond the ADGM itself. Allied counsel in the relevant jurisdiction is engaged wherever local statutory presence or local-counsel sign-off is required.
For a scoped assessment of your payment-institution licensing position, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis.
How does a payment institution application typically proceed?
A payment institution application proceeds through four operational phases: gap analysis and entity design, documentation build, regulator engagement, and post-authorisation banking onboarding. Each phase has a distinct risk of failure, and the preparation for each determines the timeline of the next.
The gap analysis maps the firm's existing regulatory footprint against the licence categories available in each candidate jurisdiction. For a crypto-native business, this includes the VASP layer, the PI layer, and the AML/CFT posture that will be scrutinised by both the regulator and the banking counterparty. Under the FATF Recommendations – and specifically the Travel Rule obligation – the firm must be able to demonstrate that it passes originator and beneficiary data with every qualifying transfer. Regulators and banks alike treat a weak Travel Rule programme as a disqualifying factor.
The documentation build for a PI application is more intensive than most founders expect. A regulator will expect a detailed business plan, a financial model, a safeguarding analysis, an AML/KYC policy, a governance structure with identified controllers and fit-and-proper persons, IT security documentation, and – in most regimes – evidence of the firm's banking arrangements before authorisation is granted. That last point is a structural difficulty: banks want to see a licence, and the regulator wants to see a bank. We manage that sequence through pre-application engagement with both sides simultaneously.
Timeline is a function of regulator capacity, application quality, and the completeness of the initial submission. In the EU, timelines vary by national competent authority and are not published as a uniform figure; Lithuania and Malta have historically processed applications within a range of months, but MiCA alignment has extended review periods across several NCAs. In Singapore, MAS targets a decision window that is measured in months for a well-prepared application. Any figure beyond that is [VERIFY] against current regulator guidance and should not be relied upon without checking.
What are the most common licensing mistakes for crypto-native firms?
The most common mistake is treating the PI licence as a standalone instrument rather than as one layer in a stack that includes VASP authorisation, AML registration, and banking access. A firm that obtains a PI authorisation but cannot open a correspondent account has spent time and legal fees on a document it cannot use.
The second most common mistake is under-investing in the governance and compliance documentation. Regulators in the leading hubs – MAS, the FCA, ESMA's network of NCAs – have moved toward qualitative review of the AML/KYC programme, not just checkbox compliance. A policy that was drafted from a template and never tested operationally will fail the regulator's assessment. We have seen applications rejected at the documentation stage for this reason alone.
A third failure mode is mis-categorisation. A firm that applies for a standard payment institution registration when its projected volumes place it in the major PI or full authorisation bracket will face a forced re-application, losing months. The reverse is rarer but also costly: a firm that applies for full authorisation when a lighter instrument would suffice carries ongoing compliance obligations it cannot sustain.
Finally, and specific to digital-asset businesses: some operators assume that an existing e-money institution relationship – where the crypto business is a programme manager or distributor under an EMI's authorisation – provides the same regulatory standing as their own PI licence. It does not. Programme-manager arrangements are operationally useful but create dependency risk. A single EMI decision to offboard the crypto client terminates the fiat rails entirely. We see this frequently in our cross-border practice, and it is one of the cleaner arguments for pursuing own-account authorisation.
How does EMI onboarding work for a VASP that needs fiat rails now?
EMI onboarding is the faster path to live fiat rails while a firm's own PI application is in progress, but it requires as much legal preparation as the licence application itself – just directed at a private counterparty rather than a regulator.
An EMI or PI that onboards a crypto business as a client is taking on the risk profile of that business's entire user base. Accordingly, EMI compliance teams apply a due-diligence standard that is equivalent in intensity to a regulatory application. The firm must produce corporate documentation, AML/KYC policies, a description of its product and user base, details of its own regulatory status, and – increasingly – a forensic-quality explanation of how it manages blockchain analytics and transaction monitoring.
In our practice, we prepare the EMI onboarding pack as a parallel workstream to the PI application itself. The materials largely overlap. A strong onboarding pack produced for EMI outreach will serve the PI application with minimal rework, and the EMI relationship provides live rails and a banking reference during the application period – both of which strengthen the regulatory file.
The cross-border dimension is acute here. EMIs authorised in one EU member state can passport services across the EEA. However, some EMIs decline to onboard VASPs that have EU customers but no EU VASP or CASP authorisation, regardless of the offshore entity's own regulatory status. The EMI's compliance team is managing its own correspondent-banking relationships, and an unregulated-in-Europe crypto business creates correspondent-banking risk for the EMI. This is the practical consequence of the regulatory gap, and it is why the two applications – PI and VASP – are best run as a single mandate.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com.
What does client-money safeguarding require under a payment institution licence?
Safeguarding is the operational obligation that most frequently surprises newly authorised PIs. Under the EU payment-services regime, and equivalently under MAS and the FCA's rules, a PI must either segregate client funds in a designated account at a credit institution or cover them with an insurance policy or guarantee. The safeguarding account must be ring-fenced from the firm's own funds, must be held at a bank that accepts the PI as a client, and must be reconciled daily.
For a digital-asset business, this creates an immediate question: when a customer deposits fiat to purchase crypto, is that fiat covered by the safeguarding obligation before the conversion occurs? The answer depends on the jurisdiction and the specific product design, and it is not uniform. Regulators in the EU have issued guidance on the point, but the guidance requires careful application to each fact pattern. We work through the safeguarding analysis as part of the product design review, before the application is filed, because regulators treat a deficient safeguarding model as grounds for refusal.
The safeguarding account also creates a banking dependency. A PI cannot operate without a credit institution willing to hold the ring-fenced funds. Banks that onboard PIs as safeguarding-account clients apply their own internal crypto-business policies. Some will hold the account but decline to provide operational banking. Others will decline entirely. Mapping the banking options in the target jurisdiction is part of the pre-application work, not an afterthought.
Which licensing structure fits your business profile?
The right instrument depends on the firm's transaction volumes, user base, geographic spread, and appetite for ongoing compliance cost. The following decision logic reflects the patterns we see most frequently.
Profile A – Early-stage crypto business, sub-threshold volumes, EU customers: The practical path is EMI onboarding as a programme manager or direct client, combined with CASP authorisation under MiCA for the crypto layer. Own-account PI authorisation is the medium-term goal once volumes and governance infrastructure support it. The risk at this stage is EMI dependency; the mitigation is a strong contractual framework and an active PI application on the horizon.
Profile B – Established exchange or custodian, multi-jurisdictional users, significant fiat volume: Own-account PI or EMI authorisation is structurally necessary. The jurisdiction selection turns on the entity's existing regulatory footprint, the user-base geography, and the availability of correspondent banking in the chosen hub. An EU PI with passporting, combined with a VARA or ADGM authorisation for the MENA user base, is a common dual-hub structure in our practice.
Profile C – Non-EU business seeking EU market access: The firm needs either to establish an EU-incorporated subsidiary for CASP and PI authorisation, or to rely on cross-border service rules that, under MiCA, are materially more restrictive than the prior patchwork. The cost of a subsidiary is an investment in market access; the alternative is exclusion from the EU retail and institutional market as MiCA enforcement matures.
Profile D – Business with existing PI or EMI authorisation seeking to add crypto services: The addition of crypto services to an existing PI/EMI may require notification to the authorising regulator, amendment of the authorisation, or a separate VASP/CASP application. The answer depends on the jurisdiction and the scope of the current authorisation. A quiet product launch without regulatory notification is a compliance failure, not a competitive advantage.
A common assumption: one licence covers everything
A common assumption among early-stage crypto businesses is that a single offshore PI or EMI registration – obtained quickly and cheaply from a lightly regulated jurisdiction – is sufficient to operate a global payments product. This is incorrect, and the consequences of acting on it are serious.
Jurisdictional reach is determined by where the customers are and where the funds flow, not by where the entity is incorporated. A BVI-incorporated firm providing payment services to EU residents without MiCA CASP or EU PI authorisation is operating in breach of the EU regime. The FSC's VASP registration in the BVI covers the BVI perimeter; it does not provide a passport into the EU, Singapore, or the UK. Banks and card schemes have grown sufficiently sophisticated to make this distinction, and correspondent banks increasingly require sight of jurisdiction-specific authorisation before opening accounts for crypto businesses.
The offshore-first approach also creates a travel-rule gap. FATF Recommendation 15 applies to VASPs globally, but enforcement is jurisdiction-specific. A firm that is not authorised in the jurisdictions where its customers are located may be outside the direct supervisory perimeter of those regulators, but it is not outside the perimeter of its banking counterparties. Banks apply FATF standards to their business-customer base regardless of the customer's regulatory status, and a customer with no provable Travel Rule compliance will be offboarded.
In our cross-border practice, we map the licence stack – operating, custody and payment layers – across each jurisdiction before the client commits to an entity structure. The cost of that analysis is a fraction of the cost of restructuring after the banking relationships have been refused.
A recent matter illustrates the point. A payments business with an existing offshore registration sought to expand into the EU market. On review, we identified that the firm's fiat-settlement activity, routed through a European payment processor, had already created a regulated-activity nexus under the EU payment-services regime. We structured a parallel CASP notification and PI pre-application process, engaged with the relevant national competent authority on a voluntary disclosure basis, and the firm entered the authorisation process from a position of regulatory cooperation rather than enforcement. The rails remained live throughout.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – full practice overview covering account access, onboarding strategy and banking relations
- PSP and Acquiring Agreements in Abu Dhabi Global Market (ADGM) – jurisdiction-specific guide to payment and acquiring arrangements under the FSRA regime
- Exchange Disclosure Orders under MiCA in the European Union – analysis of disclosure mechanisms available to digital-asset firms and claimants under the EU regime
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of correspondent-banking risk. A bank that holds accounts for a crypto business absorbs that business's AML/CFT risk into its own risk profile. Where the crypto business cannot demonstrate a documented Travel Rule programme, a clean transaction-monitoring framework, and clear regulatory status in its operating jurisdictions, the bank's compliance team will treat the relationship as unacceptable – regardless of the firm's commercial standing. Regulatory pressure on banks from their own supervisors amplifies this dynamic. The practical solution is to resolve the licensing and compliance gaps before approaching banking counterparties, not after accounts have been closed.
How can a VASP onboard with an EMI?
A VASP seeking EMI onboarding should prepare a full due-diligence pack before making outreach: corporate structure, regulatory licences held, AML/KYC policies, blockchain analytics and transaction-monitoring procedures, a description of the user base and product, and evidence of Travel Rule compliance. EMIs assess VASPs as they would any high-risk financial-services client. The quality of the pack determines the outcome; a weak or incomplete submission will be declined. Where the VASP operates across multiple jurisdictions, the pack should address each jurisdiction's regulatory status specifically – EMI compliance teams check each one.
What does client-money safeguarding require?
Under most PI and EMI regimes, client-money safeguarding requires the firm to hold customer funds in a segregated account at a credit institution, entirely separate from the firm's own funds, reconciled daily against customer balances. Some regimes permit an insurance or guarantee alternative. The safeguarding account must be held at a bank willing to accept the PI as a client in that capacity – which is itself a banking-access challenge for crypto-native firms. Failure to implement an adequate safeguarding model is a ground for refusal of authorisation and, post-authorisation, for regulatory action.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and compliance stack as one mandate – not three disconnected workstreams – so that clients commit to a structure that holds under scrutiny from both regulators and banks. To discuss your situation, contact info@oboluslaw.com or reach us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in payment institution authorisation, VASP licensing, and cross-border compliance architecture for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.