EST · MMXXVI
Home/Services/Banking Payments Emi/Payment institution licensing under Heightened Scrutiny
Banking, Payments & EMI Onboarding

Payment institution licensing under Heightened Scrutiny

Payment institution licensing under Heightened Scrutiny. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OB

Securing fiat rails for a crypto business is one of the hardest operational problems in digital assets today. Payment institutions operate under increasing pressure from their own regulators to apply enhanced due diligence to virtual asset service provider (VASP) clients, and many simply decline the category entirely. A crypto exchange, custodian or token-issuance platform that cannot move fiat cannot serve institutional clients, cannot settle, and cannot grow. The legal question is not merely "which licence do we need?" – it is "how do we structure the entity, the compliance posture and the regulatory relationships so that a payment institution will accept us and a regulator will authorise us?"

Payment institution licensing under heightened scrutiny requires a business to demonstrate that its AML/CFT controls, its ownership transparency and its operational boundaries satisfy not just its own regulator but also the correspondent banking and EMI partners it depends on. Jurisdictions operating within the MiCA regime (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities) now link CASP authorisation to payment access in ways that earlier offshore registration models did not anticipate. That linkage makes the licence stack – operating licence, payment licence, custody permissions – a single connected question, not three separate ones.

This page sets out the regulated basis, the practical process and the cross-border considerations for digital-asset businesses pursuing payment institution licensing under conditions of heightened regulatory scrutiny.

Why Heightened Scrutiny Exists – and Why It Has Intensified

Payment institutions face a de-banking incentive that is structural, not arbitrary. A licensed payment institution (PI) or e-money institution (EMI) that onboards a VASP inherits exposure to that VASP's AML/CFT risk profile. If the VASP's controls fail, the PI's own authorisation is at risk. That asymmetry explains why, across the EU, the UK, Singapore and the Gulf, PI and EMI operators apply heightened due diligence to crypto clients – or exclude them as a category.

FATF Recommendation 15, which brought virtual assets within the standard inter-governmental AML/CFT framework, placed VASPs alongside banks and broker-dealers in the risk universe. The Travel Rule – the obligation to pass originator and beneficiary data with a qualifying transfer – extended that framework to the transaction layer. A PI onboarding a VASP that cannot demonstrate Travel Rule compliance is accepting a client that may be in breach of the same rules the PI is subject to. Regulators in the major licensing hubs have made that point explicitly in supervisory guidance.

In our cross-border practice, we have seen the consequences of underestimating this dynamic. A business that secures a VASP registration in a lighter-touch jurisdiction and then attempts to open accounts at a PI in a stricter hub will face the PI's own risk appetite, not the registration country's standard. The two are rarely aligned.

What the Regulated Perimeter Covers for a Crypto-Adjacent PI or EMI

The regulated perimeter for payment institution licensing in the context of a digital-asset business is wider than many operators expect. A business needs a payment licence – or an EMI authorisation – when it receives, holds or moves fiat currency on behalf of clients, issues electronic money, or executes payment transactions. That description catches most crypto exchanges, OTC desks, crypto-to-fiat ramps and stablecoin issuance vehicles.

Under MiCA, a CASP that also wishes to issue an e-money token (EMT) – a stablecoin pegged to a single fiat currency – must hold an EMI authorisation in an EU/EEA member state. The two licences are complementary; obtaining only the CASP authorisation does not permit EMT issuance. Operators building a stablecoin product on top of an exchange or custody service therefore need to plan a dual-licence structure from the outset.

Outside the EU, the position varies sharply by jurisdiction. The MAS Payment Services Act in Singapore establishes a tiered licensing model for digital payment token service providers. The FCA in the UK requires cryptoasset registration under the Money Laundering Regulations and imposes financial promotion restrictions; a separate payment licence or EMI authorisation is needed for fiat services. The VARA regime in Dubai and the FSRA in Abu Dhabi's ADGM each address transfer and settlement as a distinct activity class. A business with users in multiple regions cannot rely on a single licence to cover the full service set.

For a practical scoped assessment of your licence and payment-rail requirements, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis.

How Does the PI/EMI Application Process Work Under Heightened Scrutiny?

The application process for a payment institution or EMI authorisation follows a structured regulatory submission, but its success in a heightened-scrutiny environment depends heavily on pre-application preparation that most applicants underestimate.

The standard stages are: regulatory scoping and entity design; pre-application engagement with the target regulator; preparation of the programme of operations and business plan; AML/CFT policy documentation; fit-and-proper assessment of controllers and key managers; capital and safeguarding demonstration; and formal submission. The regulator will review the file, raise questions and, if satisfied, issue authorisation subject to conditions.

Where a VASP or crypto-adjacent business is the applicant, each stage carries additional weight. The programme of operations must address how crypto assets interact with the fiat payment flows. The AML/CFT documentation must demonstrate Travel Rule compliance – either through a purpose-built solution or a credible implementation roadmap. Controllers will be assessed not only for general financial fitness but for their history in the digital-asset space. Any prior regulatory action, licence refusal or enforcement event anywhere in the world will be examined.

Regulators in the leading hubs increasingly expect the applicant to have engaged specialist counsel before submission. A first-time submission from a crypto entity without that foundation rarely succeeds without substantive resubmission. In our practice, we work through the pre-application stage with clients precisely to avoid that cycle – identifying the structural issues before the file reaches the regulator.

Cross-Border Complications: Entity, User Base and Banking in Different Places

For a digital-asset business, the entity, the users and the banking will often sit in three different places – and that gap is the most common source of regulatory friction in payment institution licensing.

A business incorporated in the BVI or Cayman Islands for holding purposes, with an operational subsidiary applying for a PI licence in an EU member state, must demonstrate to the EU regulator that the group structure does not impede supervision. The parent's jurisdiction must not prevent the regulator from obtaining information, and the group's beneficial ownership must be transparent to a level that satisfies the licensing NCA. If the BVI FSC's VASP Act registration is the only upstream regulatory touchpoint, that will typically not be sufficient on its own.

The banking problem is separate but related. A PI or EMI authorisation enables the business to hold client funds in safeguarded accounts. But it does not automatically produce a bank account. The authorised entity still needs a credit institution to hold those safeguarded funds, and that credit institution will apply its own VASP due diligence. We have seen businesses secure their PI authorisation and then spend months unable to find a willing bank – effectively making the licence commercially useless.

In a recent matter, a payments company that had obtained a EU PI licence found that its target banking partners declined because the ultimate beneficial owner held a significant stake in a separately operating crypto exchange in a jurisdiction with lower AML standards. We worked with the client to restructure the ownership disclosures, prepare a consolidated group AML narrative and reapproach two banking counterparties with a targeted submission. The banking relationship was established within a single quarter. That kind of sequencing – licence, then banking, with the right preparation at each stage – is where legal and commercial advisory work meet.

Decision Matrix: Which Structure Fits Your Operator Profile?

Different operator types face materially different licensing paths, and the right structure depends on the service scope, the user base and the intended payment rails.

A crypto exchange with a global retail and institutional user base, seeking to offer fiat on/off ramps across the EU and UK, will generally need a CASP authorisation under MiCA for the crypto side and either an EMI or PI authorisation (depending on whether it holds e-money) for the fiat layer. The timeline for dual authorisation in a larger EU jurisdiction is typically measured in months rather than weeks; in a smaller member state with a more accessible NCA, the process can be shorter, though passporting then carries its own notification steps. The key risk for this profile is that the exchange's trading volume and user jurisdiction mix generate AML risk categories that require explicit treatment in the programme of operations.

A custody and OTC desk operator with institutional clients and no retail exposure has a narrower regulated perimeter but faces sharper banking scrutiny. Institutional clients move larger fiat amounts; banking counterparties apply higher due diligence thresholds. The licence needed is typically narrower – a PI authorisation covering payment execution rather than e-money issuance – but the banking onboarding is more complex. This profile benefits from engaging a banking partner in parallel with the licence application, not after it.

A stablecoin issuer targeting the EU market needs both a CASP authorisation (for the trading and distribution activities) and an EMI authorisation (for the EMT itself under MiCA). The reserve management and redemption obligations attached to the EMI authorisation are substantial. This is the highest-complexity licensing path for a crypto business in Europe at present.

A Web3 infrastructure or payments API provider may not require a payment licence at all if it operates purely at the technical layer without acquiring funds or making payment decisions. That analysis, however, turns on jurisdiction-specific application of the payment services definitions, and the wrong answer exposes the business to unlicensed activity enforcement. The safer course is a formal regulatory perimeter opinion before building out the commercial relationships.

If your structure has moved beyond the planning stage, a second read can surface issues before they reach the regulator. Write to OBOLUS at info@oboluslaw.com. If a prior application stalled or an account was closed, we can identify the structural reason and map the route back.

Common Mistakes in PI/EMI Applications by Crypto Entities

The most damaging mistakes in payment institution licensing for crypto businesses are not technical – they are structural, and they are typically made before the application is filed.

The first is treating the payment licence as standalone. A crypto business that applies for a PI authorisation without first aligning its VASP registration, its group structure and its AML documentation to the PI regulator's expectations will produce an application that raises more questions than it answers. Payment regulators and VASP regulators talk to each other in the major hubs. An inconsistency between the VASP registration documents and the PI application – in the description of the business model, the beneficial ownership disclosures or the AML risk appetite – will produce a request for information that adds months to the timeline.

The second common mistake is underinvesting in the programme of operations. This document is the regulator's primary lens on the business. A generic document transplanted from a non-crypto PI application and supplemented with a brief crypto annex is not adequate. The programme must address the specific intersection of fiat and crypto flows, the on-chain and off-chain risk indicators, and the operational controls that bridge the two.

The third mistake is waiting until after authorisation to approach banking partners. The authorisation and the banking relationship must be pursued in parallel. Banks that service regulated PIs will often need to be engaged during the application stage, so that when authorisation is granted the account can be activated quickly. A gap of several months between authorisation and a live bank account is a commercial and compliance problem – the PI is authorised but cannot operate.

Operators we advise routinely underestimate the time required for fit-and-proper vetting of controllers. In a group where an individual holds stakes in multiple crypto entities across several jurisdictions, the regulatory biography that the PI application must present is complex. Compiling it accurately and presenting it clearly is a significant piece of work that should begin well before the submission date.

AML, Travel Rule and What PI Regulators Actually Check

AML/CFT compliance is the pivot on which most crypto PI applications turn, and the Travel Rule is the specific standard that distinguishes a prepared applicant from an unprepared one.

The Travel Rule – rooted in FATF Recommendation 15 and implemented through national AML legislation in each major licensing jurisdiction – requires that originator and beneficiary information travel with a virtual asset transfer above the applicable threshold. A VASP or crypto-adjacent PI that cannot demonstrate a working Travel Rule solution, or a credible plan for one, will face serious challenge from a PI regulator that is itself subject to AML supervision.

Beyond the Travel Rule, PI regulators conducting a VASP onboarding assessment will typically examine: the customer risk categorisation model (how the business identifies higher-risk users and applies enhanced due diligence); the transaction monitoring logic (what triggers a review, how alerts are escalated); the sanctions screening coverage (which lists, how frequently updated, how matches are handled); and the SAR/STR filing process. For a crypto business, each of these has an on-chain dimension that a conventional PI policy does not address by default.

In our practice, we have seen PI regulators request detailed technical evidence of the transaction monitoring system's ability to flag on-chain risk indicators – not just fiat transaction patterns. That expectation, which would have been exceptional three years ago, is now routine in the leading EU member states and in Singapore. Building the documentation to meet it is a pre-application task.

Self-Assessment: Is Your Business Ready for PI/EMI Licensing Under Heightened Scrutiny?

The following markers indicate that a crypto business is in a position to pursue PI or EMI authorisation with a reasonable prospect of success.

On structure: the entity seeking authorisation is clearly identifiable as the regulated operator; its beneficial ownership is transparent and documented; there are no upstream holding structures in jurisdictions that the target regulator considers high-risk for group supervision purposes; and any existing VASP registrations or licences in other jurisdictions are consistent with the narrative in the PI application.

On compliance: a written AML/CFT policy exists that specifically addresses virtual assets; a Travel Rule solution is in place or in documented implementation; the business has a named MLRO with relevant experience and the time to discharge the function; and transaction monitoring covers both fiat and on-chain activity.

On banking: the business has identified at least two potential banking partners for safeguarding accounts; it has prepared a due diligence pack for those banks, not just for the regulator; and it understands that the banking onboarding will run in parallel with, not after, the licence application.

On management: controllers and key function holders have been assessed for fit and proper against the target regulator's published criteria; their regulatory biographies are compiled and accurate; and no individual holds a position that creates an undisclosed conflict between the PI applicant and a related crypto entity.

If any of these markers is absent, addressing it before submission is materially more efficient than addressing it in response to a regulator's question.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because of AML/CFT risk management. A VASP client requires the bank to apply enhanced due diligence to the VASP's own customer activity, not just the VASP as a corporate client. If the bank cannot obtain sufficient transparency over the VASP's user base, transaction flows and compliance controls, the risk-reward calculus for the relationship is unfavorable. In some cases, correspondent banking pressure from upstream banks removes the option entirely, regardless of the individual bank's appetite.

How can a VASP onboard with an EMI?

A VASP seeking to onboard with an EMI must demonstrate, at minimum, a complete regulatory identity – the licences held, the jurisdictions covered and the services in scope – along with a documented AML/CFT framework that addresses virtual-asset-specific risks, including Travel Rule compliance. EMIs operating in the EU, UK and Singapore increasingly require a pre-onboarding disclosure pack. Engaging the EMI during the VASP's own licensing process, rather than after it, materially improves the likelihood of a successful onboarding within an acceptable timeframe.

What does client-money safeguarding require?

Client-money safeguarding for an authorised payment institution or EMI requires that funds received from clients are held separately from the institution's own funds, typically in a designated account at a credit institution or in eligible low-risk assets. The safeguarding obligation is ongoing – not just at authorisation. A crypto-adjacent PI must ensure that its safeguarding methodology covers fiat receipts that interact with crypto settlement flows, and that its banking partner understands and supports the safeguarding structure. Specific reserve composition and reconciliation standards vary by jurisdiction and licence class.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so that structural problems are identified before they become regulatory ones. Our disputes team also coordinates freezing relief and on-chain tracing across leading common-law forums when recovery is needed. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in payment institution and VASP licensing across EU, Gulf and Asia-Pacific regulatory regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours