Operating a crypto firm that moves institutional money without the right authorisation is not a grey area. It is an enforcement trigger. Regulators across the EU, the UAE, the UK and Singapore are actively scrutinising whether electronic money institutions (EMIs) – entities authorised to issue electronic money and provide payment services – are being used to move digital assets under a framework that was not designed for the activity. For institutional clients, the stakes are compounded: counterparties conduct licensing due diligence before they onboard, and a gap in your regulatory stack is a deal-stopper, not a footnote.
An EMI licence (electronic money institution authorisation) is a payment-layer credential that sits alongside – not instead of – a VASP (virtual asset service provider) registration or crypto-asset service provider authorisation. The relevant regime in any given jurisdiction determines whether your firm needs one, both, or a separate payment institution authorisation. This page maps that structure, the application process and the cross-border realities that institutional operators routinely underestimate.
Why an EMI Licence Is the Critical Infrastructure Layer for Institutional Crypto Firms
The EMI licence is the instrument that allows a crypto firm to hold client funds, issue stored value and execute payment transactions under a regulated mandate – functions that institutional clients now treat as non-negotiable prerequisites for engaging a counterparty. Without it, even a fully licensed VASP is exposed at the payment rail. In our practice, we regularly advise firms that built their VASP stack correctly but left the payment layer on an unregulated correspondent, only to find banking partners withdrawing once institutional due diligence surfaced the gap.
Under MiCA (Markets in Crypto-Assets Regulation), the EU's primary crypto-asset regime, e-money tokens – stablecoins referenced to a single fiat currency – must be issued by an entity authorised under the applicable e-money directive or a credit institution. The same logic applies in the UK under FCA oversight. Firms serving institutional clients who use or issue EMTs (e-money tokens) therefore need both the CASP authorisation for crypto-asset services and an EMI authorisation for the payment and stored-value functions.
The cross-border dimension is immediate. An institutional client may sit in Frankfurt, with custody in Singapore and liquidity bridged through a UAE entity. Each of those nodes carries its own payment-service perimeter. A single EMI authorisation in one EU member state can passport payment services across the EEA – but it does not reach the UAE, Singapore or the UK. We see this structural mismatch regularly, and it is one of the first things we audit when a new institutional client engages us.
Regulators in the leading hubs increasingly expect institutional-facing crypto firms to demonstrate a coherent regulatory stack that covers the crypto layer, the payment layer and the custody layer as an integrated whole – not as three separate registrations assembled after the fact.
What Activity Triggers the EMI Requirement for a Crypto Firm?
The EMI perimeter is triggered by the issuance of electronic money or the provision of regulated payment services – and most institutional crypto workflows touch that perimeter. Holding client fiat balances pending settlement, issuing prepaid instruments, executing on-behalf-of payment transactions or operating a stored-value account structure will typically bring a crypto firm inside the EMI regulated perimeter in any jurisdiction that has implemented the standard FATF and e-money regulatory architecture.
The analysis is fact-sensitive. A firm that merely connects buyers and sellers on a pure exchange model – with no fiat custody and no payment execution – may fall outside the EMI perimeter in some regimes. But institutional workflows rarely stay that clean. Prime brokerage services, OTC settlement, stablecoin issuance and custody-linked payment rails all expand the perimeter. In our cross-border practice, we map each activity against the regulatory perimeter in every jurisdiction where the firm has users, counterparties or infrastructure – not just where the entity is incorporated.
A common mistake at this stage is equating "where we are registered" with "where we are regulated." A Cayman-incorporated entity with EU institutional clients is not outside EU regulatory reach simply because the corporate seat is offshore. The activities-based approach that MiCA and most major regimes now apply means the question is where the services are provided and to whom – not where the company is domiciled.
CTA #1
If you are building or scaling an institutional book, the time to map your payment-layer perimeter is before your banking partner or a regulator does it for you. The analysis differs materially depending on your activity set, your user base and the jurisdictions in play. Map your options with us before you commit.
How Does the EMI Licence Application Process Work?
An EMI application is a detailed regulatory submission that requires a complete business plan, governance documentation, AML/CFT programme, safeguarding policy, risk management framework and – in most major regimes – a proof of minimum own funds. The process has several sequential dependencies that compress the timeline if they are built in from the start and extend it significantly if they are not.
The standard process in a leading EU jurisdiction under the applicable e-money regime runs broadly as follows. First, the firm selects a jurisdiction and confirms that the intended activity scope maps cleanly to the EMI licence category rather than to a payment institution or a bank licence. Second, pre-application engagement with the relevant national competent authority – required in some regimes, strongly recommended in all – helps identify any activity-specific concerns before the formal file is submitted. Third, the application file is assembled: constitutional documents, shareholder and management vetting packs, the business plan with a three-year financial projection, the AML/CFT manual and a safeguarding attestation.
Fourth, the authority conducts its review, which may include requests for further information. Timeline varies by regime: some national competent authorities under the e-money framework operate within a defined statutory window; others are governed by a broader administrative-discretion standard. A well-prepared file with no RFI cycle typically moves faster than a file that triggers multiple rounds of supplementary questions. We build the application file to front-load the likely RFI topics, which is the most effective way to compress elapsed time without overpromising on outcomes.
For the crypto-specific overlay, the application must also demonstrate that the safeguarding and AML controls address the digital-asset dimension – blockchain-based transaction monitoring, wallet-level due diligence and Travel Rule (the obligation to pass originator and beneficiary data with each transfer) compliance. Regulators in the EU, UK and Singapore are increasingly granular about this requirement for institutional-facing entities.
How Does the Cross-Border Reality Change the EMI Licensing Strategy?
For an institutional crypto firm with a multi-jurisdiction footprint, an EMI licence is never a standalone decision. It sits within a licensing stack that typically combines a CASP authorisation under MiCA for EU crypto-asset services, an EMI or payment institution authorisation for the payment layer, a VASP registration or VARA licence if the firm operates in the UAE, and – if custody is a regulated activity in the relevant regime – a separate custody authorisation under MAS in Singapore, ADGM's FSRA framework in Abu Dhabi or the SFC's VASP regime in Hong Kong.
The EU passporting mechanism under the applicable e-money regime is one of the most valuable structural tools available to an institutional firm. A single EMI authorisation obtained in a member state with a responsive NCA can passport payment services across the entire EEA, allowing the firm to serve EU institutional clients without entity proliferation. The CASP authorisation under MiCA operates on the same passporting logic. This is a meaningful structural advantage over building entity-by-entity, and it is one of the primary reasons we regularly advise institutional clients to anchor their EU structure in a jurisdiction with a clear MiCA transition pathway and an established NCA process.
Outside the EU, the picture fragments. The UK operates its own payment-service registration under FCA oversight, with its own AML registration for crypto activities. VARA in Dubai and the FSRA in ADGM each operate regime-specific authorisation tracks that do not recognise EU passporting. Singapore's MAS runs a tiered payment services regime under the Payment Services Act, with a major payment institution licence required for digital payment token services above defined thresholds. None of these regimes give credit to each other's authorisations. A firm that services institutional clients across these hubs needs a considered entity and licence architecture – not a collection of individual applications made in sequence.
In our cross-border practice, we map the full licence, banking and tax stack before a single application is filed. We work with allied counsel in the relevant jurisdictions where local counsel engagement is required. The objective is a structure that the firm can operate, that counterparties accept and that does not create a compliance cliff as the business scales.
What Are the Most Costly EMI Licensing Mistakes Institutional Crypto Firms Make?
The most common and costly mistake is filing an EMI application in isolation – treating it as a box-ticking exercise rather than as an opportunity to structure the whole regulatory perimeter correctly from the start. A firm that obtains an EMI authorisation but leaves its crypto-asset services operating on an unregistered basis, or that structures custody outside a regulated wrapper, is not compliant: it has a partial licence stack with visible gaps that institutional due diligence will surface.
The second mistake is jurisdiction-shopping without a use-case analysis. Choosing a jurisdiction because the authorisation timeline is shorter or the minimum own funds appear lower without analysing whether that authorisation will be accepted by target counterparties, whether the regime supports the intended passporting scope and whether the banking environment is workable for the firm's operational currency mix – is a decision that typically results in a second application eighteen months later.
A third mistake is underestimating the personal accountability dimension. In virtually every major EMI regime, the controllers and senior managers of the applicant entity are vetted individually. Fit and proper requirements – the regulator's assessment of good repute and professional competence for key individuals – are applied rigorously, particularly for institutional-facing entities. A controller with prior regulatory censure, or a management team that cannot demonstrate relevant experience, will delay or prevent authorisation regardless of the quality of the application file.
Finally, firms regularly underestimate the post-authorisation compliance cost. An EMI licence carries ongoing safeguarding, capital adequacy, reporting and audit obligations. For a crypto firm, the digital-asset dimension adds Travel Rule implementation, enhanced blockchain transaction monitoring and, under MiCA, specific own-funds calculation rules that differ by activity type. Building the compliance infrastructure in parallel with the application – rather than after authorisation – is structurally more efficient and avoids the enforcement risk of operating in the window between authorisation and full operational readiness.
A Matter From Our Practice
In a recent licensing engagement, an institutional prime brokerage firm with operations structured through a non-EU holding company sought to expand into EU institutional clients. The firm held a VASP registration in an offshore jurisdiction but had no EU-regulated entity. Institutional counterparties were requiring MiCA-compatible authorisation before they would onboard. We reviewed the existing entity structure, identified the activity set that required both CASP authorisation and an EMI authorisation for the payment settlement function, and designed a two-entity EU structure anchored in a member state with a clear MiCA transition pathway. The pre-application engagement with the national competent authority was completed within the first two months of the mandate. The application was submitted on an expedited basis and the firm was able to demonstrate a compliant regulatory posture to counterparties during the application period under the transitional provisions available in that regime.
Which Licensing Profile Fits Your Institutional Crypto Business?
Institutional crypto firms fall into broadly recognisable profiles, each of which maps to a different licensing strategy. Understanding which profile fits your business is the starting point for any licensing mandate.
Profile A – EU-anchored institutional exchange or OTC desk: The firm primarily serves EU institutional counterparties, holds client fiat during settlement and may issue or transact in EMTs. The indicated structure is a CASP authorisation under MiCA (for crypto-asset services) plus an EMI or payment institution authorisation (for the payment and stored-value functions), both anchored in the same EU member state to leverage the passporting mechanism. Timeline is driven by the NCA review process in the selected jurisdiction – typically a matter of months for a well-prepared file, though this varies by regime and authority workload.
Profile B – UAE-based institutional custody and brokerage: The firm serves GCC institutional clients and international family offices, holds crypto assets under custody and executes payments in fiat and stablecoins. The indicated structure is a VARA activity-based licence for the Dubai mainland perimeter or an FSRA authorisation within ADGM for Abu Dhabi-based activity, combined with a payment-layer authorisation where fiat settlement is a material function. EU passporting does not apply; any EU clients require separate EU-regulated capacity.
Profile C – Singapore-based DPT service provider with regional institutional reach: The firm provides digital payment token services to institutional clients across the Asia-Pacific region. The indicated structure is a major payment institution licence under MAS's Payment Services Act, with potential engagement with the SFC in Hong Kong if the firm also services Hong Kong institutional clients. Capital thresholds and activity-specific conditions apply and vary by licence tier – consult current MAS guidance for the applicable requirements.
Profile D – Multi-hub institutional operator: The firm has institutional clients and infrastructure in two or more of the EU, UAE, Singapore and UK. The indicated structure requires a jurisdictional stack with individual authorisations in each regime – there is no mutual-recognition shortcut – combined with a group entity structure that manages capital, compliance and governance efficiently across the stack. This is the most complex and the most common profile among the institutional operators we advise.
Addressing the Offshore Licence Assumption
A common assumption among institutional crypto firms building their first regulatory stack is that a single offshore authorisation – a Cayman VASP registration, a BVI FSC registration under the VASP Act 2022, or a registration in a similarly permissive regime – is sufficient to operate globally as long as clients are sophisticated or institutional. This assumption is incorrect and has become more costly as the major regulated hubs have tightened their reach.
The activities-based test that MiCA, VARA, MAS and the FCA each apply means that a firm serving EU, UAE, Singapore or UK institutional clients from an offshore base is conducting regulated activities in those jurisdictions regardless of where it is incorporated. "Reverse solicitation" carve-outs – the principle that a client who approaches a firm on their own initiative may be served without local authorisation – are narrow, heavily conditioned and not available for systematic business. Regulators and institutional counterparties both scrutinise reliance on these carve-outs, and the reputational consequence of an enforcement action based on incorrect reliance is disproportionate to the short-term cost saving.
Offshore registrations remain useful – as holding structures, as part of a multi-entity architecture, or in regimes where the offshore jurisdiction's regime is genuinely recognised by target counterparties. The BVI VASP Act 2022 and the Cayman VASP registration each serve legitimate structural functions. The error is treating them as a substitute for regulated authorisation in the jurisdiction where institutional business is actually conducted.
CTA #2
If a prior application stalled, a counterparty rejected your licence stack, or a banking relationship was withdrawn after a compliance review, the structural reason is usually identifiable and addressable. We carry out a second-read analysis of the existing structure and the application history, identify the gap and map the route back. Map your options to request a scoped review.
Self-Assessment Checklist: Are You Ready to File an EMI Application?
Before filing an EMI application in any jurisdiction, institutional crypto firms should be able to answer the following questions affirmatively. Each item represents a category where an incomplete answer will generate a regulator RFI or a material delay.
First: is the activity perimeter clearly defined – specifically, which of the firm's functions constitute electronic money issuance or regulated payment services in the target jurisdiction, and which are covered by a separate VASP or CASP authorisation? Second: does the firm have a compliant AML/CFT programme that explicitly addresses digital-asset transaction monitoring, Travel Rule obligations and the enhanced due diligence requirements for institutional counterparties? Third: has the firm identified its shareholder and management structure, confirmed that all individuals who will face fit-and-proper scrutiny can satisfy the required criteria, and assembled the supporting documentation? Fourth: does the firm have or can it demonstrate access to the minimum own funds required by the target regime, in a form the regulator will accept? Fifth: is the firm's safeguarding policy – the mechanism by which client funds are protected in the event of the firm's insolvency – designed to meet the specific requirements of the target regime, including any digital-asset-specific adaptations required? Sixth: has the firm engaged with the banking landscape in the target jurisdiction to confirm that a business account is achievable post-authorisation, given that many payment-service banking partners conduct their own financial crime reviews of EMI applicants?
A negative answer to any of these questions identifies a workstream that should be completed before the file is submitted, not after.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – the full practice area overview for crypto licensing across 70+ jurisdictions
- EMI Licence for Crypto Firms in South Africa – jurisdiction-specific analysis of the South African regulatory regime for crypto EMIs
- EMI Licence for Crypto Firms for Early-Stage Founders – the licensing roadmap for pre-revenue and seed-stage crypto businesses
FAQ
How long does a crypto licence take to obtain?
Timeline varies materially by jurisdiction, licence type and the completeness of the application file. In a well-prepared EU CASP or EMI application with pre-application NCA engagement, the process is typically a matter of months. Applications that trigger multiple rounds of supplementary questions, or that are filed in jurisdictions with higher regulatory backlogs, can take considerably longer. We structure application files to front-load the most common RFI categories, which is the most reliable way to compress elapsed time within the limits of any given regime.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction depends on where your clients are, what activities you conduct, what passporting or mutual-recognition benefits you need and whether the local banking environment supports your operational currency mix. EU jurisdictions with clear MiCA transition pathways offer passporting across the EEA. VARA in Dubai and MAS in Singapore each serve specific regional client bases. We assess the full licence, banking and tax stack together before recommending a jurisdictional anchor – not the authorisation in isolation.
Do I need a separate custody licence?
In most major regulated regimes, custody of client crypto assets is a separately regulated activity. Under MiCA, providing custody and administration of crypto-assets is a defined CASP service requiring specific authorisation. Under MAS and the SFC, safeguarding client assets has its own regulatory treatment. An EMI licence covers the payment and stored-value perimeter; it does not authorise crypto custody. Firms that both hold crypto assets for clients and provide payment services will typically need authorisations covering both functions – the exact combination varies by regime and activity scope.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack as one mandate – not three disconnected workstreams – so institutional operators build a structure that counterparties accept and regulators recognise. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialises in multi-hub EMI and VASP authorisation strategies for institutional digital-asset firms across the EU, UAE, Singapore and offshore financial centres.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.