EMI licence for crypto firms from a Cross-border Perspective
A crypto exchange, custodian or payments platform that issues e-money, holds client funds or processes fiat on-ramps is, in most serious jurisdictions, operating under the direct reach of electronic money institution rules — not merely VASP registration. The question is not whether an EMI licence (an authorization permitting a firm to issue electronic money and provide related payment services) is needed. The question is which EMI regime, in which jurisdiction, layered with which VASP or CASP (Crypto-Asset Service Provider) authorization, matches the firm's operating footprint. Getting that stack wrong invites enforcement, frozen payment rails and the loss of banking relationships that took years to build. This page maps the regulated basis, the application path, the cross-border interaction and the structural decisions that separate firms that scale from those that stall.
Why an EMI licence is not optional for most crypto firms
Most crypto firms that touch fiat are already conducting EMI-regulated activities, whether they know it or not. Issuing stored-value balances, processing fiat settlements, holding user funds in transit — each of these triggers the electronic money or payment institution perimeter in the EU under MiCA and the parallel payment services directives, in the UK under FCA supervision, and in analogous regimes across Singapore under MAS, the UAE under VARA and ADGM's FSRA, and in the BVI and Cayman Islands under their respective VASP frameworks.
The legal boundary is drawn by function, not by label. A firm that calls its fiat wallet a "treasury account" and its balance top-up a "deposit" is nonetheless issuing electronic money if the economic reality fits the statutory definition. Regulators in every major hub have become progressively less tolerant of definitional ambiguity. In our practice, we regularly advise firms that self-classified as pure crypto platforms, only to discover mid-due-diligence that their fiat settlement flow required EMI authorization before they could onboard institutional banking.
The stakes are concrete. Operating in the EMI perimeter without the right authorization exposes the business to enforcement action, civil penalties, mandatory cessation of the regulated activity and — critically — termination by the correspondent banking network that underpins fiat settlement. Those outcomes are reversible in theory. In practice, losing a banking relationship at scale takes months or years to repair, and some operators never recover it.
For a scoped assessment of whether your fiat flows trigger EMI or payment institution authorization, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts — the entity, the user base, the banking — change the analysis.
Which EMI regime applies to your structure?
The applicable EMI regime is determined by where the issuing entity is incorporated, where it passports or branches, and where its users are located — three questions that frequently point to three different answers. A firm incorporated in an EU member state under MiCA and the applicable payment directives can passport its CASP and EMI authorizations across the EU and EEA from a single competent authority. That passporting right does not extend to the UK, the UAE, Singapore or Hong Kong. Each of those jurisdictions requires a separate local authorization or a recognized branch structure.
The cross-border reality for most mid-size crypto firms is a layered stack. Consider the architecture: the trading and custody layer may sit under a VASP authorization in the BVI or Cayman Islands; the fiat settlement layer requires an EMI or payment institution license in an EU jurisdiction or the UK; the institutional client layer in the Gulf may require a VARA or ADGM/FSRA authorization; and the Asia-Pacific onboarding layer triggers MAS or SFC obligations. Each layer is regulated independently, and a deficiency in any one of them can freeze the entire operation.
Lithuania has historically attracted EU EMI applications from crypto firms because its Bank of Lithuania processes applications on a timeline that, while no longer uniquely fast under the MiCA transition, remains competitive within the EU. Malta's MFSA, transitioning from its VFA framework to the MiCA CASP regime, offers an established supervisory relationship for firms already operating there. Neither jurisdiction should be chosen on timeline alone. Supervisory culture, local substance requirements, AML posture and banking access all vary materially between EU member states.
What does the EMI application process actually involve?
The EMI application process runs across several distinct workstreams, and a firm that underestimates the documentary burden is the firm that receives a request for further information at week eight and loses three months of clock. The core workstreams are entity and governance, business plan, financial projections, AML/CFT program, IT security and business continuity, and safeguarding arrangements.
Governance is the most commonly underestimated workstream. Regulators expect fit-and-proper assessments of every significant shareholder, director and senior manager. For a crypto firm with a complex cap table — token holders, DAO participants, nominee arrangements — mapping the ultimate beneficial ownership to the regulator's satisfaction often takes longer than drafting the business plan itself. In our cross-border practice, we have seen applications stall for weeks because a beneficial owner in a third-country jurisdiction could not produce documentation in the form required by the EU competent authority.
Safeguarding is the second area where crypto firms consistently underperform. EMI rules require that client funds held in e-money are segregated and protected against the insolvency of the issuer. For a firm that also holds crypto assets, demonstrating clean separation between the e-money float and the trading treasury — including across omnibus wallets — requires careful accounting architecture and a legal opinion in most cases.
The AML/CFT program must address the Travel Rule (the FATF obligation to pass originator and beneficiary identification data with each qualifying transfer). This is non-negotiable in every leading jurisdiction, and a program that cannot demonstrate technical Travel Rule compliance will not receive authorization. Timeline, absent complications, is typically measured in months rather than weeks — and that figure rises if the competent authority raises substantive questions on the AML program or governance documentation.
What are the most common mistakes crypto firms make in EMI applications?
Applying in the wrong jurisdiction is the single most expensive mistake, because the cost is not just the abortive application — it is the delay while the firm re-files elsewhere, during which competitors advance and banking relationships remain unavailable. We have seen firms choose a jurisdiction based on a single factor (perceived speed, perceived regulator leniency, a referral from a non-specialist advisor) and then discover that local substance requirements, capital expectations or banking access in that jurisdiction were incompatible with their business model.
A second persistent mistake is treating the EMI application as separate from the VASP or CASP application. In most operating structures, the two authorizations are interdependent. A CASP authorization under MiCA does not cover the issuance of electronic money — a firm that issues stored-value fiat balances needs both. Filing the CASP application first and the EMI application six months later doubles the regulatory exposure window and may require the firm to restructure governance to satisfy two separate sets of fit-and-proper requirements concurrently.
The third mistake is banking. An EMI license without a banking partner that will open a safeguarding account is a license that cannot operate. Banking access for crypto-adjacent EMIs remains constrained across the EU. A firm that completes a twelve-month authorization process and then discovers it cannot open a compliant safeguarding account faces a choice between a further delay and a structural workaround — neither of which was in the business plan. Firms that address banking concurrently with authorization, rather than sequentially after it, consistently reach operational readiness faster.
How does an EMI licence interact with VASP and CASP regimes across borders?
The interaction between an EMI authorization and a parallel VASP or CASP license is the defining cross-border question for any crypto firm operating at scale. The MiCA regime requires a CASP authorization for crypto-asset services and separately addresses electronic money tokens under the EMT sub-regime — a stablecoin pegged to a single fiat currency issued by an EMI must comply with both the EMI regime and the MiCA EMT provisions. This dual-layer obligation is not a technicality. It affects reserve composition, redemption obligations, marketing restrictions and the applicable capital requirements.
Outside the EU, the interaction is governed by local regimes that do not share MiCA's integrated architecture. In Singapore, the MAS Payment Services Act licenses digital payment token services and payment institution activities under separate licence classes; a firm operating both must hold both, and the capital and compliance obligations of each run independently. In the UAE, VARA's activity-based licensing model requires a separate authorization for each regulated activity — exchange, custody, transfer — and none of those VARA authorizations covers the issuance of electronic money, which may require engagement with the UAE Central Bank regime separately.
A micro-matter from our recent practice illustrates the complexity. In a matter handled earlier this year, a payments firm expanding from an EU EMI base into the Gulf discovered that its MAS-registered DPT subsidiary was generating fiat settlement flows that required a VARA transfer/settlement authorization before it could onboard Gulf institutional clients. We mapped the authorization gap, advised on the phased application sequence and coordinated the AML program update to satisfy both VARA and the MAS expectations simultaneously — without requiring the firm to reincorporate or restructure its EMI entity. The outcome was a compliant, cross-border operating structure achieved on a timeline shorter than the firm's original estimate for a single-jurisdiction application.
If your current structure spans more than one jurisdiction and you are uncertain whether each layer is properly authorized, a structural audit before the next funding round or banking review is the right moment. Write to info@oboluslaw.com or message us at t.me/oboluslaw.
Decision matrix: which EMI and VASP structure fits which operator profile?
Different operator profiles lead to materially different authorization stacks. The following decision branches describe the logic we apply in scoping advice for cross-border crypto firms — not a universal prescription, because every structure depends on facts that vary.
Profile A — EU-centric exchange with fiat on/off ramps: A firm serving retail or institutional clients primarily across the EU and EEA needs a CASP authorization under MiCA from one EU member state, passportable across the bloc, combined with an EMI or payment institution license in the same or a compatible member state to cover fiat settlement. Lithuania and Malta are the established entry points, though supervisory culture and local substance expectations differ between them. The indicative authorization timeline for a well-prepared application, absent substantive regulatory queries, is measured in several months for each authorization, running concurrently where possible. The principal risk is banking: safeguarding account access must be secured early.
Profile B — Global platform with UAE, Asia and EU exposure: A firm operating across VARA's Dubai perimeter, the MAS Payment Services Act in Singapore and the EU MiCA regime needs at minimum three separate authorizations — VARA for Dubai-based activities, a MAS license for Singapore DPT services, and an EU CASP plus EMI for the European fiat layer. Each runs on its own timeline and satisfies its own AML program requirements. The cross-border AML program must be designed to satisfy the most demanding of the three regulators simultaneously, which in practice means designing to VARA and MAS standards and verifying that the EU AML expectations are also met. Allied counsel in each relevant jurisdiction are engaged for local law opinions.
Profile C — Early-stage firm seeking a single offshore entry point: The VASP Act regime in the BVI or the Cayman Islands offers a lighter registration path for certain activities, but neither jurisdiction provides a passporting right into the EU, the UK or the Gulf, and neither covers EMI issuance. A BVI or Cayman VASP registration is a viable first step for a firm that is not yet serving EU or UAE retail clients and does not issue e-money. It is not a substitute for EU CASP, UK FCA registration or VARA authorization when the firm reaches those markets. The cost of treating an offshore registration as a permanent global solution is deferred enforcement rather than avoided enforcement.
A common assumption: one offshore licence is sufficient for global operations
A common assumption among early-stage crypto founders is that a single offshore VASP registration — BVI, Cayman or a similarly light regime — is sufficient to serve clients globally while the firm builds scale. That assumption is incorrect in every leading jurisdiction, and acting on it carries serious regulatory risk.
The FCA, ESMA and VARA each apply their regulatory perimeter based on where clients are located and where the service is marketed, not only where the firm is incorporated. A BVI-registered firm that actively markets to UK retail investors is within the FCA's financial-promotion perimeter. A firm that offers exchange services to UAE residents is within VARA's jurisdiction regardless of its domicile. Neither regulator has been reluctant to act against offshore firms that serve local clients without local authorization.
The pragmatic path is not to avoid offshore structures — they serve a legitimate purpose in the early stage and in the institutional layer. The pragmatic path is to map the authorization requirement against the actual client and marketing footprint before launch, and to build a compliance calendar that sequences the authorizations correctly as the business expands into each regulated market. That mapping is the work we do with clients before commitment, not after enforcement.
Self-assessment: is your EMI and VASP structure fit for cross-border scale?
Before engaging with a regulator or a banking partner, the following questions identify the structural gaps most commonly found in cross-border crypto firm structures. These are the diagnostic questions we apply at the outset of every licensing mandate.
- Does your firm issue, hold or process fiat-denominated balances for clients? If yes, EMI or payment institution authorization is likely required in each jurisdiction where those clients are located.
- Have you mapped your beneficial ownership chain to the satisfaction of a fit-and-proper assessment under the most stringent of your target regulators?
- Does your AML/CFT program address the Travel Rule across all token transfers, including stablecoin transfers that cross jurisdictional lines?
- Have you confirmed that a compliant safeguarding account is available in your target EMI jurisdiction before you file the application?
- Does each regulated layer of your structure — exchange, custody, payment — hold the specific authorization required by the relevant regime, rather than relying on a single license to cover multiple activities?
- For EU operations: does your CASP authorization cover the specific crypto-asset services you intend to offer, and does a separate EMI authorization cover your fiat issuance?
- For cross-border operations: have you confirmed that your AML program meets the standards of the most demanding jurisdiction in your footprint?
If any of these questions produces an uncertain answer, that uncertainty is the starting point for the legal work — not something to resolve in parallel with a live application.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – our full-practice overview across 70+ jurisdictions
- UAE (VARA/Dubai) vs United Kingdom – where to license a crypto firm – a direct jurisdiction comparison for operators choosing between two leading hubs
- EMI licence for crypto firms: guidance for early-stage founders – practical steps for founders at the pre-application stage
FAQ
How long does a crypto licence take to obtain?
Authorization timelines vary significantly by jurisdiction and licence type. An EU CASP or EMI authorization under a well-developed national competent authority typically runs over several months for a well-prepared application, and longer if the regulator raises substantive queries on governance, AML or safeguarding. VARA in Dubai and MAS in Singapore operate on their own timelines, each reflecting the regulator's review capacity and the complexity of the application. No jurisdiction currently offers a timeline shorter than a matter of weeks for a complete authorization, and most serious regimes are measured in months.
Which jurisdiction is best for licensing my crypto business?
There is no universally best jurisdiction. The right licensing jurisdiction depends on where your clients are located, which regulated activities you conduct, your capital structure, your AML posture and your banking access. EU CASP authorization with EMI passporting suits a firm serving EU retail and institutional clients. VARA suits a firm operating in or from Dubai. MAS suits a firm with a Singapore operating base. An offshore VASP registration in the BVI or Cayman Islands may be appropriate at the early stage but does not substitute for authorization in the markets where you actively serve clients.
Do I need a separate custody licence?
In most leading regimes, custody of crypto assets is a regulated activity distinct from exchange, payment and EMI services. Under MiCA, custody and administration of crypto-assets for third parties is a specific CASP service requiring explicit authorization. Under VARA in Dubai, custody is an activity-based licence separate from exchange and transfer authorizations. Under the MAS Payment Services Act in Singapore, safeguarding of digital payment tokens engages specific regulatory conditions. A firm that holds client assets without the applicable custody authorization is typically operating outside its licensed perimeter, regardless of what other authorizations it holds.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit — because discovering a structural gap at the point of banking review or regulatory examination costs far more than building the structure correctly at the outset. To discuss your cross-border authorization needs, contact info@oboluslaw.com.
By Aisha Tan, Licensing and Jurisdictions Analyst — specialist in cross-border EMI, CASP and VASP authorization strategy for crypto exchanges, custodians and payments platforms across the EU, UAE, Asia-Pacific and offshore jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.