EST · MMXXVI
Home/Services/Licensing Registration/EMI licence for crypto firms for Regulated Entities
Licensing & Registration

EMI licence for crypto firms for Regulated Entities

Emi licence for crypto firms for Regulated Entities. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS

EMI Licence for Crypto Firms for Regulated Entities

A crypto firm that processes fiat flows, issues stored-value instruments or provides payment services to users sits squarely within the perimeter of electronic money regulation in most major jurisdictions – alongside, not instead of, any VASP (virtual asset service provider) or CASP (crypto-asset service provider) licence it may already hold. Operating without the right authorisation exposes the business to enforcement action, the sudden withdrawal of banking rails and, in some regimes, criminal liability for directors. The risk is not theoretical: regulators across the EU, the UK and the Gulf have intensified scrutiny of firms that process user fiat flows under an umbrella crypto registration while believing that registration covers payment activity. It does not.

This page explains when a crypto firm needs an EMI licence (electronic money institution authorisation), how that requirement interacts with MiCA CASP authorisation and VASP registration frameworks, what the application process demands, and how to build a licence stack that holds up across the jurisdictions where your users actually live. It is written for general counsel, compliance leads and founders who have already passed the question "do we need a licence?" and are now asking "which ones, where, in what order."

What is an EMI licence and why does it matter for crypto firms?

An EMI licence authorises a firm to issue electronic money – a digital claim on funds that can be used for payment transactions – and to provide payment services to users and merchants. For a crypto firm, the trigger is not the crypto activity itself. It is the fiat side: receiving user funds, holding them in accounts, issuing instruments redeemable at par, processing payment orders or enabling settlement between users in fiat. Any of those activities, in most regulated jurisdictions, requires either an EMI licence or a payment institution licence, depending on the scope of services.

Under MiCA, e-money tokens (EMTs) – stablecoins pegged to a single fiat currency – may only be issued by an entity that is already an authorised credit institution or holds an EMI licence. This single provision brings a large category of stablecoin projects, fiat-backed settlement layers and embedded-payment products directly into the EMI regime, regardless of whether the firm also seeks CASP authorisation for exchange or custody activity. The two licences operate in parallel; one does not substitute for the other.

In the United Kingdom, the FCA's MLR registration covers the crypto side of the business, but fiat flows require separate authorisation under the Electronic Money Regulations or the Payment Services Regulations. A firm with FCA crypto registration that processes fiat on behalf of users without that additional authorisation is operating outside its permissions – a position the FCA has consistently enforced.

We regularly advise firms that have structured an exchange or custodian under a VASP registration and then add a fiat off-ramp or a card-linked wallet. That addition changes the regulatory perimeter materially, and the firms that do not update their licence stack in advance are the ones who receive the call from their banking partner first.

Which crypto firms actually need an EMI licence?

The trigger for EMI authorisation is functional, not definitional: the question is what the firm does with user fiat, not what it calls itself. The following activities consistently bring a crypto firm into the EMI or payment-institution perimeter across the leading regulated jurisdictions.

  • Receiving fiat from users and holding it pending conversion to or from crypto – even briefly.
  • Issuing a fiat-denominated stored-value balance that users can redeem, spend or transfer.
  • Issuing or managing an EMT under MiCA.
  • Providing payment initiation services or account information services to users.
  • Running a settlement layer between counterparties in fiat terms, even where the underlying instrument is a stablecoin or wrapped asset.
  • Offering a debit or prepaid card linked to a crypto balance, where fiat conversion occurs at point of use.

Conversely, a pure crypto-to-crypto exchange that never touches fiat, holds no fiat balances and does not issue any fiat-denominated instrument may operate under a VASP or CASP authorisation alone – provided it genuinely does not step outside that perimeter. In practice, most scaling crypto businesses add at least one fiat-adjacent feature within the first two years. Building the EMI analysis into the initial structuring decision is considerably cheaper than retrofitting it later.

The process above describes the standard trigger analysis. Your facts – the entity, the product roadmap, the user geography – change the conclusion. For a scoped assessment of whether your current or planned activities require EMI authorisation, contact OBOLUS at info@oboluslaw.com.

What does the EMI licence application process require?

EMI authorisation is a full regulatory application, not a notification or a registration. The competent authority – whether ESMA's network of national authorities under the EU Payment Services Directive framework, the FCA in the UK, the Central Bank of Ireland, or the relevant authority in a chosen EU member state – conducts a substantive assessment of the firm's governance, capital adequacy, business plan, safeguarding arrangements and AML/CFT controls before granting authorisation.

The core application package typically requires the following elements, regardless of jurisdiction:

  • A programme of operations describing the specific payment services to be provided, the intended markets and the projected volume and value of transactions.
  • A detailed business plan with financial projections demonstrating that the firm will maintain the required minimum own funds on an ongoing basis.
  • Evidence of the firm's initial capital, held in a form acceptable to the regulator.
  • A governance and management structure document, naming proposed directors, senior managers and the head of compliance; each individual is subject to a fitness-and-propriety assessment.
  • An AML/CFT programme, including policies on customer due diligence, transaction monitoring, the Travel Rule (the obligation to pass originator and beneficiary data with a transfer), and suspicious-activity reporting.
  • Safeguarding arrangements: the methodology by which user funds will be segregated from own funds, whether through a dedicated safeguarding account at a credit institution or through an insurance/guarantee approach where permitted.
  • An ICT and operational resilience framework, covering business continuity, outsourcing controls and incident-reporting procedures.
  • For crypto-integrated EMIs: a clear description of the interface between the EMI activity and the crypto activity, including how fiat-to-crypto and crypto-to-fiat flows are handled, what on-chain activity the entity participates in, and how the crypto-specific AML/CFT risks are managed.

Timeline varies by jurisdiction and by the quality of the initial submission. In our practice, well-prepared applications to established EU regulators proceed to a first substantive review within a matter of weeks; full authorisation typically follows after several months of back-and-forth on governance details, safeguarding mechanics and AML documentation. Underprepared submissions – incomplete governance packs, generic business plans, inadequate Travel Rule procedures – draw requests for information that extend timelines materially.

What are the most common mistakes crypto firms make in EMI applications?

In our cross-border practice, four failure modes appear consistently across EMI applications for crypto firms, and each is avoidable with proper pre-application structuring.

Conflating VASP registration with EMI authorisation. A VASP registration under a national AML regime, or a CASP authorisation under MiCA, covers crypto-asset services. It does not extend to the issuance of electronic money or the provision of payment services to users. Firms that begin processing fiat flows before obtaining EMI authorisation are, in every relevant jurisdiction, operating without permission.

Inadequate safeguarding design is the second failure mode. Regulators increasingly require a clear, documented safeguarding methodology at the point of application, not a general statement of intent. For a crypto firm, the challenge is that safeguarding accounts must be at regulated credit institutions, and many banks remain cautious about opening institutional accounts for crypto-adjacent EMIs. The banking and licence workstreams must run in parallel, not sequentially.

Third: governance mismatches. Regulators apply a substantive fitness-and-propriety test to every proposed director and senior manager. A founding team drawn entirely from a crypto background, without at least one member who has held a regulated financial-services role, will typically face additional questions. Identifying and onboarding the right compliance lead before the application is submitted – not after the regulator requests it – removes a common delay.

Finally, underestimating the crypto-specific AML annexe. Standard payment-institution AML templates were not designed for entities whose customers transact on public blockchains. Regulators expect to see Travel Rule implementation detail, blockchain analytics controls and a clear articulation of how the firm will handle transactions involving privacy-enhanced protocols or unhosted wallets. A generic AML policy lifted from a payments template is the quickest way to receive a request for fundamental revision.

How does the EMI licence interact with the broader cross-border licence stack?

For a crypto firm operating across multiple jurisdictions, the EMI licence is one layer in a stack that may also include a CASP authorisation under MiCA, one or more national VASP registrations, a custody authorisation, and in some cases a securities or investment-firm licence if the crypto assets in question are classified as financial instruments. Managing these layers in sequence – or in the wrong order – is one of the more expensive mistakes a scaling digital-asset business can make.

The EU's MiCA passporting regime for CASPs does not extend to payment services. An EMI authorised in one EU member state may, however, passport its EMI permissions across the EEA under the Payment Services Directive framework. This means the entity structure can be engineered to give a single regulated entity both CASP authorisation and EMI authorisation in the same jurisdiction, with passporting carrying both sets of permissions into other EU markets. The jurisdiction selection decision – which member state to anchor the primary authorisation – therefore has consequences that extend well beyond local regulatory cost.

Outside the EU, the picture is more fragmented. In the UAE, VARA licences cover virtual-asset activity; payment-service activity in dirhams sits within a separate Central Bank of the UAE regime. A firm operating a crypto exchange and a dirham wallet in Dubai requires both. In Singapore, MAS licenses digital payment token services under the Payment Services Act; the same statute covers payment services more broadly, so a single major payment institution licence can encompass both crypto and fiat services – a structuring advantage that the EU and UK do not offer in the same way.

We map the licence, banking and regulatory-capital stack before our clients commit to a jurisdiction. The cost of selecting the wrong anchor jurisdiction – or the wrong licence sequence – is measured in months of delay and in capital locked into a structure that then has to be rebuilt. To map the licence and banking stack for your build, write to info@oboluslaw.com.

Which licence profile fits your operator profile?

Not every crypto firm faces the same EMI analysis. The relevant question is what your product does today and what it will do within the next operating cycle. The following decision framework maps common operator profiles to the typical licence requirement.

Profile A – Pure crypto exchange, no fiat balances, no fiat instruments. If the exchange converts crypto to crypto only, holds no user fiat, and all onboarding and offboarding happens through a licensed third-party PSP, the EMI trigger may not be present. The primary authorisation needed is a CASP licence under MiCA for EU activity or the applicable VASP regime in the target jurisdiction. The risk here is product scope creep: adding a fiat wallet or a card product later, without reassessing the licence position, is where enforcement exposure arises.

Profile B – Exchange with fiat wallets or on-ramp/off-ramp capability. As soon as user fiat is received and held – even briefly, even in a segregated account in the user's name – the EMI or payment institution analysis applies. The firm needs CASP authorisation for the crypto side and EMI or PI authorisation for the fiat side. The combined licence is entirely achievable in multiple EU member states; the application process is more demanding, but the result is a single regulated entity with full product capability and passporting rights across the EEA.

Profile C – Stablecoin issuer or EMT issuer. Under MiCA, issuing a stablecoin pegged to a fiat currency requires EMI authorisation as a prerequisite. There is no standalone MiCA route for EMT issuance without first being an authorised EMI or credit institution. The timeline implication is significant: EMI authorisation must come first, then the EMT whitepaper and notification regime follows. Founders who begin token design before the EMI application is in process regularly find themselves six to twelve months behind their roadmap.

Profile D – Custodian with settlement services. A custodian that settles fiat obligations between counterparties – for instance, a prime-brokerage or OTC desk – is likely providing payment services in addition to custody. The custody licence (required under most flagship regimes as a regulated activity) does not cover the payment leg. A separate EMI or PI authorisation is needed for the settlement function, unless the custody regime in the chosen jurisdiction explicitly encompasses it.

The single-offshore-licence assumption is the most expensive myth in crypto licensing

A common assumption among founders scaling a crypto business is that a single offshore registration – a BVI FSC VASP registration, a Cayman CIMA licence, or a similar instrument – is sufficient to serve users across the EU, UK, Gulf and Asia. It is not, and acting on that assumption exposes the business to enforcement risk in every jurisdiction where it has users.

Offshore registrations serve an important function. They are appropriate for entities that genuinely operate within the offshore jurisdiction, whose users are limited to investors in that jurisdiction, or whose activity is entirely institutional and cross-border in a way that does not constitute retail service provision in any regulated market. That is a narrow set of facts. Most consumer-facing exchanges, wallet providers and stablecoin issuers do not meet it.

Regulators in the EU, UK, UAE and Singapore have each issued guidance – and in several cases enforcement notices – addressing the position of offshore-registered entities that actively market to or serve residents in their jurisdiction. The principle is consistent: an offshore registration provides no immunity from the local licensing requirement if the firm is, on a functional analysis, conducting regulated activity within that jurisdiction.

The implication for an EMI licence is direct. Even if a firm holds a VASP or CASP authorisation in a recognised jurisdiction, if it processes fiat flows for EU residents, UK users or Singapore-based customers, the relevant payment-services regime applies. The only question is whether the regulator identifies the exposure before the firm's banking partner does.

Operators we advise who built on a single offshore instrument have, in several cases, needed to restructure rapidly when a banking partner or an acquiring bank required sight of EU- or UK-regulated permissions before continuing to process. Rebuilding under enforcement pressure is considerably more expensive than building correctly from the start.

Self-assessment: does your business need to act now?

The following questions are designed to surface whether an EMI or payment-institution analysis is overdue. A yes answer to any of them warrants immediate legal review.

  • Does your platform receive fiat from users and hold it, even briefly, before converting to crypto or returning it?
  • Do users hold a fiat-denominated balance in your system that they can transfer to other users or redeem on demand?
  • Are you issuing or planning to issue a stablecoin or EMT pegged to a fiat currency?
  • Does your product include a debit card, prepaid card or any payment instrument linked to a crypto or fiat balance?
  • Do you settle fiat obligations between trading counterparties or provide a fiat settlement layer for OTC or institutional activity?
  • Do you have users in EU member states, the UK, the UAE or Singapore, and have you assessed whether your current authorisation covers the payment-service dimension of what you provide to them?
  • Has a banking partner or acquirer asked to see a payment-services authorisation that you do not currently hold?

If a prior application stalled, a banking relationship was withdrawn, or a regulatory query arrived that you were not expecting, a second read of your current authorisation profile may surface the structural gap and the route to addressing it. Write to info@oboluslaw.com or message us via t.me/oboluslaw.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline varies significantly by jurisdiction and licence type. A MiCA CASP authorisation in an EU member state with a well-resourced regulator typically takes several months from the submission of a complete application. An EMI authorisation in the same jurisdiction runs on a broadly comparable timeline, though the safeguarding and capital evidence requirements add preparation time. Underprepared applications attract requests for information that can double the effective timeline. Building the full application pack – governance, AML, business plan, safeguarding – before submission is the most reliable way to keep the process on track.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right anchor jurisdiction depends on where your users are, what your product does, what banking infrastructure you need and how the local regulatory capital requirements interact with your funding position. For EU market access, MiCA passporting makes the choice of member state a consequential structuring decision. For Gulf activity, VARA in Dubai and the FSRA in ADGM serve different product and client profiles. For Asia-Pacific access, MAS in Singapore and the SFC in Hong Kong each have distinct requirements. We work through the decision matrix with clients before they commit resources to any single path.

Do I need a separate custody licence?

In most flagship jurisdictions, custody of crypto assets on behalf of third parties is a regulated activity that requires its own authorisation – separate from an exchange licence, an EMI licence or a general CASP authorisation. Under MiCA, providing crypto-asset custody and administration is one of the defined CASP services and must be specified in the authorisation. In VARA-regulated Dubai and under MAS in Singapore, custody similarly requires explicit regulatory permission. Operating a custody function under a registration that does not cover it is a common compliance gap, particularly for exchanges that begin safeguarding user assets as a product feature before the licence scope has been formally extended.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. We map the full licence stack – operating, custody, payment and EMI layers – before our clients commit capital to a structure. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-jurisdictional CASP and EMI authorisation strategies for digital-asset businesses entering regulated markets.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours