EST · MMXXVI
Home/Services/Licensing Registration/EMI licence for crypto firms for Established Operators
Licensing & Registration

EMI licence for crypto firms for Established Operators

Emi licence for crypto firms for Established Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBO

For an established crypto firm, the question is rarely whether to hold an Electronic Money Institution (EMI) licence – a regulatory authorisation allowing a business to issue electronic money and provide payment services. The question is whether the licence you have is the right one for the business you are now running. Banking rails, institutional counterparties and card-network access all turn on the answer. A gap between your current authorisation and your current activity profile is not an abstract compliance risk: it is an enforcement exposure that compounds every quarter you carry it.

This page sets out the regulated basis for EMI licensing as it applies to established crypto operators, the process for obtaining or upgrading authorisation, the structural mistakes that most frequently surface in our practice, and the cross-border realities that determine whether a single licence is sufficient or whether a stack of authorisations is required.

What EMI authorisation means for an established crypto operator

An EMI licence lets a crypto firm issue e-money, hold client funds against that issuance and provide a defined set of payment services without relying on a third-party payment institution. For operators who have moved beyond pure exchange or custody services into card programmes, settlement rails, stablecoin issuance or embedded finance, EMI authorisation is typically the enabling layer. Under MiCA, the EU regulatory regime administered by ESMA and national competent authorities, an EMT (e-money token) issuer must itself hold an EMI licence or a banking licence in the issuing member state. That requirement sits alongside, not instead of, any CASP (Crypto-Asset Service Provider) authorisation the firm holds.

The regulatory architecture matters because established operators often carry legacy licences that were appropriate at formation but do not cover the activities they now conduct. We regularly advise firms that onboarded under a simple VASP registration and have since added card issuing, cross-border remittance or fiat on-ramp infrastructure – all of which may require EMI authorisation or a layered payment institution licence depending on the jurisdiction. The cost of that mismatch, measured in debanking events and regulatory censure, is material.

The cross-border dimension compounds the problem. An EMI licence granted by the FCA in the United Kingdom passports to no EU jurisdiction after the MiCA transition. A CASP passport in one EU member state does not, by itself, authorise payment services across the EEA under the EMI regime. Operators with users in multiple jurisdictions need to map the activity against the regime in each relevant venue – and in our practice, that mapping consistently reveals authorisation gaps that the founding team did not anticipate.

For a scoped assessment of your current authorisation stack, the process above describes the standard path. Your facts – the entity structure, the user base geography, the banking and the stablecoin issuance model – change the analysis materially. To map your specific position, contact OBOLUS at info@oboluslaw.com or Map your options.

Which regime governs EMI licensing for crypto firms?

EMI authorisation sits at the intersection of payments law and digital-asset regulation, and the governing regime varies by where the entity is incorporated, where it operates and what it does with client funds. The principal frameworks an established operator will encounter are as follows.

In the European Union, EMI licensing is governed at the member-state level, with the requirement set by EU payments directives as transposed. MiCA overlays crypto-specific obligations for EMT issuers. The practical effect is that a firm issuing a stablecoin pegged to the euro, for example, must hold EMI or banking authorisation in a member state and comply with MiCA's reserve, redemption and supervisory requirements for e-money tokens. Passporting then extends that authorisation across the EEA, but CASP authorisation for exchange or custody services must be obtained separately. ESMA and the relevant national competent authority – the Bank of Lithuania, the MFSA in Malta or another NCA – administer the process.

In the United Kingdom, the FCA supervises EMI authorisation under the relevant payments regulations. The FCA's cryptoasset registration under the Money Laundering Regulations is a separate, parallel process, and firms frequently need both. The financial promotion rules also apply to crypto marketing, adding a third compliance layer for established operators with retail-facing products.

In the UAE, the payment services regime and VARA's virtual-asset licence categories operate in parallel. A firm offering transfer or settlement services in Dubai must hold the relevant VARA activity licence; payment services may require a separate Central Bank authorisation depending on the activity profile. In Abu Dhabi, the FSRA within ADGM regulates financial services for virtual assets under its own framework. Neither UAE venue provides an automatic bridge to EU or UK payment services authorisation.

In Singapore, the Monetary Authority of Singapore licenses payment services under the Payment Services Act. A firm operating a digital payment token service alongside an e-money issuance function may require authorisation at the Major Payment Institution tier, with its associated capital and compliance obligations.

The practical upshot is that established crypto operators almost never need a single licence. They need a licence stack, mapped to where the entity sits, where the users are and where the funds flow.

What does the EMI application process look like for established operators?

For an established business, the EMI application process differs from an early-stage application in one critical respect: the regulator reviews the business you are already running, not the business you plan to build. That means the application must reconcile your current activity profile with the scope of the authorisation you are seeking – and any gap between the two will be interrogated.

The process typically moves through four stages. First, a regulatory mapping exercise confirms which activities require EMI authorisation, which require a separate VASP or CASP authorisation and which are covered by existing licences. For a firm that has been operating for several years, this exercise frequently surfaces activities that migrated out of scope without a formal authorisation amendment.

Second, the legal and operational preparation phase assembles the application pack. For an EMI application this typically includes governance documentation, an AML/CFT programme that satisfies the FATF (Financial Action Task Force) Recommendations including the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer), a detailed business plan with financial projections, a safeguarding analysis, an IT and operational risk framework, and the personal questionnaires for approved persons and beneficial owners. Regulators increasingly apply scrutiny to the technology infrastructure behind the payment flows, not only to the legal documentation.

Third, the application is submitted and the regulator conducts its review. Timelines vary by jurisdiction and by the completeness of the submission. Regulators in the leading hubs increasingly expect a single, clean submission with no material deficiencies; an application that triggers repeated rounds of requisitions extends the timeline substantially and signals governance weaknesses the regulator will remember.

Fourth, post-authorisation: the firm must build and maintain the ongoing compliance infrastructure – capital adequacy monitoring, safeguarding audits, regulatory reporting and, in the EU, MiCA-aligned token documentation if EMT issuance is in scope. Established operators sometimes underestimate this phase, treating the licence grant as the endpoint rather than the starting line.

In our cross-border practice, we manage the application as a project with defined milestones and a single point of contact for regulator correspondence. Where allied counsel in the relevant jurisdiction are required, we coordinate the engagement from the outset.

What are the most common structural mistakes established crypto firms make?

The structural errors we see most frequently in established-operator mandates are not the ones the founders anticipated. They are the ones that accumulated quietly as the business grew.

The first is activity creep without authorisation review. A firm that began as a pure exchange adds an e-money wallet, then a card programme, then a cross-border settlement function. Each addition felt incremental. Cumulatively, the firm is now conducting regulated payment services without EMI authorisation. The risk is not theoretical: regulators in the major hubs have taken enforcement action against operators who characterised payment services as ancillary to an existing licence when the volumes told a different story.

The second is reliance on a partner institution's licence. Many established operators built their initial product on top of a bank or payment institution's infrastructure, relying on that partner for the regulated layer. When the partner terminates the relationship – as we have seen happen at short notice in multiple jurisdictions – the operator has no independent payment authorisation and loses its rails immediately. An EMI licence is, among other things, an insurance policy against that concentration risk.

The third is the single-jurisdiction assumption. A common assumption is that a single offshore licence is enough to serve clients globally. It is not. The determination of whether your activities require local authorisation turns on where your users are, where the funds are processed and whether your token issuance is denominated in a fiat currency that triggers a specific regulatory requirement. A VASP registration in the BVI, for example, does not authorise e-money issuance to EU users. MiCA's reach is territorial, and ESMA has been explicit about the consequences for unregistered token issuers accessing EU retail markets.

The fourth is deferring the approved-persons process. EMI authorisation requires that key individuals – directors, compliance officers, AML officers and, in many jurisdictions, beneficial owners above defined thresholds – pass a fitness and propriety assessment. For established firms whose ownership or management has changed since formation, the historical vetting of incoming individuals is often incomplete. Regulators discover this during the authorisation process. The result is a delay, a remediation requirement or, in serious cases, a refused application.

How does EMI licensing interact with custody and CASP authorisation?

EMI licensing, CASP authorisation and custody licensing address different regulated activities. An established operator typically needs more than one of them, and the interactions between regimes create obligations that each licence, read in isolation, does not reveal.

Under MiCA, custody of crypto-assets is a regulated CASP activity requiring separate authorisation. An EMI licence does not cover custody, even if the firm holds client crypto-assets incidentally to its payment services. Where an operator holds both client e-money balances and client crypto-asset balances, it needs both EMI authorisation and CASP custody authorisation – with separate safeguarding regimes applying to each pool of assets.

In Singapore, the MAS framework distinguishes between the digital payment token service (exchange and transfer) and the custody of digital payment tokens. An operator active in both areas must hold authorisation for both activities at the appropriate payment institution tier. The same layering logic applies in Hong Kong under the SFC's VASP licensing regime for virtual-asset trading platforms.

The FATF Travel Rule applies across these regimes. A firm that conducts both EMI-regulated payment transfers and virtual-asset transfers must implement Travel Rule compliance for both sets of transactions, with the applicable thresholds and data requirements determined by each relevant jurisdiction's implementation. In our practice, we see firms that have implemented Travel Rule compliance for their virtual-asset flows but overlooked it for their e-money payment flows – an oversight that regulators are increasingly identifying on supervisory visits.

The cross-border interaction also affects banking. A firm that holds an EMI licence and a CASP authorisation in different jurisdictions faces correspondent banking due diligence from two directions: the EMI's safeguarding bank must understand the crypto-asset exposure, and the crypto-custodian's banking counterparty must understand the e-money obligations. We regularly advise on structuring the entity architecture to separate these exposure profiles where that segregation materially improves bankability.

Decision matrix: which EMI and authorisation profile fits your business?

The right authorisation architecture for an established operator depends on the activity profile, the user geography and the entity structure. The following profiles illustrate the principal decision branches.

Profile A – EU-focused EMT issuer with exchange and custody services. An operator issuing a euro-pegged stablecoin and providing exchange and custody services to EU retail users requires, at minimum, EMI authorisation in an EU member state (for the EMT issuance), CASP authorisation in the same or a passportable member state (for exchange and custody), and Travel Rule compliance across both service lines. The authorisation timeline depends on the NCA and the completeness of the submission; regulators in the leading EU licensing hubs are receiving increased application volumes under MiCA, and clean, complete submissions are processed materially faster. Key risk: the EMT reserve and redemption requirements under MiCA are more demanding than a simple e-money safeguarding obligation, and the whitepaper obligations add a public disclosure dimension.

Profile B – UK-regulated payment business with a crypto on-ramp. A firm holding FCA EMI authorisation that is adding a crypto exchange or on-ramp function needs FCA cryptoasset registration under the Money Laundering Regulations and must comply with the financial promotion regime for any crypto marketing. The EMI licence does not extend to crypto-asset services. The two authorisations run in parallel, and the compliance programmes must address both regimes. Key risk: the FCA's MLR cryptoasset registration process has a high refusal rate; established operators with prior enforcement history in any jurisdiction face an elevated due diligence burden.

Profile C – Multi-jurisdiction operator with a hub-and-spoke structure. An operator licensed in a single hub (VARA in Dubai, AFSA in the AIFC, or FSRA in ADGM) and serving users in EU, UK and Asian markets cannot rely on that single licence for the full activity scope. Each additional market requires either local authorisation or a defensible analysis of why the activity falls outside the local regulatory perimeter. For payment services, the territorial reach of the EU and UK regimes means that serving EU and UK users with e-money products typically requires authorisation in those jurisdictions, not merely a disclosure in a terms-of-service document. Key risk: the failure-mode is not a formal enforcement action in the hub jurisdiction; it is debanking and correspondent relationship termination by counterparties who have identified the jurisdictional gap in their own due diligence.

Profile D – Established exchange adding institutional settlement rails. A crypto exchange adding institutional-grade settlement infrastructure – acting as a settlement agent, providing nostro/vostro structures, or clearing fiat legs of crypto trades – is likely entering regulated payment services territory in the jurisdictions where the fiat flows are settled. EMI authorisation or a payment institution licence, depending on the jurisdiction, is required before those services go live. The application process for an established exchange benefits from demonstrated compliance history but is complicated by the complexity of the settlement architecture. Key risk: regulators expect the applicant's governance to be commensurate with the institutional risk profile of the proposed activity; an exchange compliance programme built for retail KYC is not automatically fit for institutional settlement oversight.

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. To pressure-test your structure before you commit, message us via t.me/oboluslaw or Map your options.

A note on the banking layer

An EMI licence without a banking relationship is a regulatory credential with no operational utility. Established crypto operators understand this problem abstractly; they tend to underestimate how significantly the licence structure affects the bankability of the entity.

Banks conducting due diligence on an EMI applicant in the crypto sector will review the regulatory authorisation, the AML/CFT programme, the Travel Rule implementation, the beneficial ownership chain and the jurisdictional exposure of the customer base. A firm that holds a clean EMI authorisation from a recognised regulator – the FCA, ESMA's NCAs, MAS or the FSRA – is materially more bankable than one that holds only a VASP registration from an offshore registry, even if the underlying business activity is identical.

In our practice, we structure the entity and the authorisation sequence with the banking application in mind from the outset. The regulatory application and the banking application are not sequential processes; the strongest positions present both simultaneously, using the regulatory submission to anchor the banking due diligence. We have seen firms complete a full EMI authorisation process only to discover that their chosen banking counterparty requires a different entity domicile or a different licence category – a result that is avoidable with early coordination.

The banking layer also interacts with safeguarding. EMI authorisations require that client funds are safeguarded either by segregation in a dedicated account at a credit institution or by investment in eligible low-risk assets. In practice, the safeguarding obligation requires an explicit contractual arrangement with a bank that is willing to designate the account as a safeguarding account and to carry the associated regulatory relationship. Not all banks active in the crypto sector offer this arrangement. The selection of a safeguarding partner is a legal and commercial decision that deserves as much attention as the authorisation application itself.

How we approach EMI licensing for established operators

In our practice, EMI licensing engagements for established operators begin with a regulatory gap analysis. Before any application is drafted, we map the firm's current activity profile against the authorisation it holds, identify the gaps and prioritise the remediation sequence. That exercise typically takes a matter of weeks and delivers a written memorandum that the management team can take to the board.

The application phase is managed as a structured project. We prepare the full application pack, manage the correspondence with the regulator and coordinate with allied counsel in the relevant jurisdiction where local authorisation or a local compliance officer is required. Our experience is that clean, complete applications – where every required document is present on day one and every regulatory question is anticipated and answered in the accompanying narrative – move through review substantially faster than submissions that arrive in instalments.

Post-authorisation, we advise on the ongoing compliance obligations: capital monitoring, safeguarding audit cycles, Travel Rule programme maintenance and the periodic regulatory reporting that EMI authorisation requires. For operators with a MiCA EMT issuance in scope, we coordinate the whitepaper documentation and the reserve attestation process.

In a recent licensing matter, an established payments firm with a legacy VASP registration sought to add an EMT issuance capability for a euro-pegged settlement token. The firm had assumed its existing registration covered the new activity. Our gap analysis identified that the EMT issuance required EMI authorisation in an EU member state, a separate CASP authorisation for the distribution function and a revised safeguarding structure. We managed the dual authorisation process in parallel, with the banking application coordinated alongside, and the firm received both authorisations ahead of its planned product launch. The outcome was a clean go-live with no regulatory interruption to the existing business.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary by jurisdiction, licence type and the completeness of the submission. In the major EU licensing hubs, CASP authorisation under MiCA and EMI authorisation under the payments regime each typically take a matter of months from a clean, complete application. The FCA's MLR cryptoasset registration has historically taken longer, particularly for applicants with complex ownership structures. Regulators in all leading jurisdictions process incomplete applications more slowly; a well-prepared submission with no material deficiencies is the single greatest driver of a shorter timeline.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction; the right venue depends on the activity profile, the user base, the banking requirements and the operator's long-term growth plans. EU member-state CASP authorisation provides EEA passporting under MiCA. VARA in Dubai and FSRA in Abu Dhabi suit operators building institutional or asset-management products in the Gulf. MAS in Singapore is the benchmark for Asia-Pacific VASP operations. For an established operator, the determining factor is usually where the regulated activity occurs, not where the operator prefers to be domiciled.

Do I need a separate custody licence?

In most flagship jurisdictions, yes. Under MiCA, custody of crypto-assets is a distinct CASP activity requiring its own authorisation, separate from an EMI licence or an exchange authorisation. In Singapore, custody of digital payment tokens is similarly distinguished from exchange and transfer services under the Payment Services Act. An operator holding client crypto-asset balances alongside e-money balances should assume that separate custody authorisation is required and seek specific advice before combining those activities under a single licence.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so that the authorisation architecture matches the business you are building, not the one you started with. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-jurisdiction EMI and CASP authorisation strategy for established digital-asset operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours