An EMI licence (electronic money institution authorisation) is the regulated instrument a digital-asset firm must hold when it issues electronic money, operates client wallets with fiat balances, or facilitates payment flows that cross the boundary between crypto rails and the banking system. Without it, a firm operating in any of the major regulated markets exposes itself to enforcement action, the immediate closure of correspondent banking accounts, and the kind of reputational damage that stops a product launch cold. As digital-asset firms scale across jurisdictions, the EMI licence question is rarely optional – and the cost of answering it late is far higher than the cost of answering it correctly at the outset.
This page sets out what an EMI authorisation covers, how it interacts with the VASP (virtual asset service provider) registration that most crypto businesses also need, and what a structured legal process looks like across the most relevant jurisdictions.
What does an EMI licence cover for a crypto firm?
An EMI authorisation permits a firm to issue electronic money – digital representations of fiat currency – and to provide associated payment services. For a crypto firm, this is the regulated basis on which it may hold client funds in a fiat-denominated wallet, issue prepaid cards or stablecoins backed by fiat reserves, and receive and send payments on behalf of users. The licence sits alongside, not inside, a VASP registration: the two authorisations operate on different regulated perimeters. A VASP registration covers virtual-asset activities; an EMI licence covers the fiat-side payment flows that typically accompany them.
The distinction matters operationally. A crypto exchange that settles user withdrawals in euros, pounds or dollars is touching a regulated payment service at that point in the flow. Regulators under MiCA (the EU's Markets in Crypto-Assets Regulation), under the FCA's payment-services regime in the UK, and under equivalent frameworks in Singapore and elsewhere have consistently taken the position that performing those activities without authorisation is a criminal offence, not a civil irregularity. In our practice, we regularly advise firms that built out their product assuming the VASP registration covered everything – only to discover the fiat leg was unregulated.
The cross-border reality compounds this. A firm incorporated in Lithuania, serving users across the EU, processing euro withdrawals and holding fiat balances, will need to satisfy both the CASP authorisation requirements under MiCA and the payment institution or EMI authorisation requirements under the applicable EU Payment Services Directive regime. Neither authorisation substitutes for the other.
To discuss where your firm sits on this spectrum, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options
Which regulators issue EMI authorisations relevant to digital-asset firms?
The principal EMI-issuing regulators a digital-asset business will encounter depend on where it incorporates, where its users are located, and where its banking relationships sit. The following regulators are the most commonly relevant in our cross-border practice.
In the EU, electronic money institution authorisations are issued by national competent authorities – in practice, the regulators of Lithuania, Malta (the MFSA) and Ireland attract significant digital-asset applications. Lithuania's Bank of Lithuania built a reputation as an accessible EU entry point under the prior VASP regime and continues to process payment and EMI applications under the MiCA transition. An EMI authorised in any EU member state may passport its payment services across the EEA without separate authorisation in each host state – this is one of the most commercially significant features of the EU regime and a primary driver of where digital-asset firms choose to incorporate their European entity.
In the UK, the FCA authorises electronic money institutions under the Electronic Money Regulations. The FCA's authorisation process is known for rigorous review of governance, safeguarding arrangements and AML controls. Firms that treat it as a formality consistently encounter delays or refusals. UK EMI authorisation does not carry EU passporting rights following the UK's departure from the EU, which means firms with both EU and UK user bases often need separate authorisations in each market.
In Singapore, the MAS (Monetary Authority of Singapore) issues Major Payment Institution licences under the Payment Services Act, which cover e-money issuance alongside digital payment token services. In Hong Kong, the SFC governs virtual asset trading platforms, but payment-related activities may additionally engage the remittance or money-service operator registration requirements. In the UAE, VARA governs virtual-asset activities in Dubai proper, while payment-services authorisation falls under a separate regulatory track.
The pattern across all major hubs is consistent: the digital-asset regulator and the payments regulator are not always the same authority, and the activities they regulate do not always align neatly with a single product flow.
What does the EMI application process look like for a digital-asset firm?
An EMI application is a documentation-intensive process that rewards preparation far more than speed. The application package typically comprises a detailed business plan, a programme of operations, evidence of the corporate structure and ownership chain (including ultimate beneficial owner disclosures), audited financial statements or a forecast where the firm is new, a capital adequacy demonstration, and a comprehensive set of policies covering AML/CFT, safeguarding of client funds, operational resilience and IT security. For digital-asset firms, regulators will additionally expect to see how the firm manages the interface between its crypto activities and the fiat payment flows that require EMI authorisation.
The governance documentation is frequently the point at which applications stall. Regulators expect to assess the fitness and propriety of each director, significant shareholder and senior manager individually. In the EU framework, the management body must meet collective and individual competence standards that the regulator assesses substantively – not as a checkbox exercise. We have seen well-capitalised firms lose months because a director's background check was incomplete or a governance document did not reflect the actual decision-making structure of the business.
Timeline varies by jurisdiction and application quality. In our cross-border practice, well-prepared applications in EU member states with active digital-asset pipelines typically progress through a pre-application phase, formal submission, a question-and-answer cycle, and decision within a matter of months – though the overall window varies considerably depending on the regulator's current caseload and the completeness of the submission. The FCA process in the UK is generally longer. Singapore's MAS has implemented a tiered licensing regime that allows firms to operate under an exemption while a full application is pending, though the exemption itself carries conditions.
The critical process discipline is pre-application engagement. Most major regulators operate a pre-application or pre-notification process. Using it correctly – presenting the business model, identifying the relevant authorisation category and getting early regulatory feedback – substantially reduces the risk of a formal application being returned or stalled at the quality-review stage.
What mistakes do crypto firms most often make in EMI applications?
The most consequential mistake is mischaracterising the business model. Regulators do not authorise activities in the abstract; they authorise a specific programme of operations as described in the application. If the programme does not accurately reflect what the firm intends to do – or if the firm's product evolves after authorisation without a variation request – the authorisation does not cover the new activity. Digital-asset firms that launch a stablecoin product, add fiat off-ramps or white-label payment functionality after their initial authorisation are a consistent example of this problem.
A second common error is treating the capital requirement as a one-time hurdle rather than an ongoing obligation. EMI regimes typically impose minimum initial capital plus ongoing own-funds requirements calibrated to the volume of electronic money in issue. A firm that meets the minimum at authorisation but does not build the internal systems to monitor and maintain capital adequacy through growth will find itself in breach at precisely the moment its business is scaling fastest.
Third: inadequate safeguarding arrangements. The obligation to segregate client funds and hold them in qualifying assets – or to cover them with a guarantee or insurance policy – is a core EMI requirement across EU, UK and comparable regimes. Firms that commingle client fiat with operational funds, or that use a single banking account for both, are creating both a regulatory breach and a significant insolvency risk for their users.
A fourth failure mode is underestimating the AML and Travel Rule obligations that attach to EMI authorisation. An authorised EMI is a supervised entity for anti-money laundering purposes. The Travel Rule (the FATF obligation to pass originator and beneficiary data with a transfer) applies to the payment flows the EMI processes. Compliance infrastructure – transaction monitoring, sanctions screening, customer due diligence – must be operational before the licence is used, not built in parallel with the first live transactions.
How does an EMI licence interact with the broader cross-border structure of a digital-asset business?
For most digital-asset businesses of scale, the EMI licence is one layer in a multi-licence, multi-jurisdiction structure. The typical stack includes an operating entity holding the VASP or CASP authorisation, an entity holding the EMI or payment institution authorisation, potentially a separate custody entity (since custody of digital assets is a separately regulated activity in most flagship regimes), and a holding or IP entity in a tax-efficient jurisdiction. These entities interact – the EMI entity may process payments on behalf of the operating entity under an intra-group agreement – and each interaction is a potential regulatory or tax event.
Banking is the variable that most frequently destabilises a carefully designed structure. An EMI authorisation does not guarantee access to correspondent banking. Banks will independently assess the business model, the AML controls, the jurisdictional risk profile and the nature of the underlying digital-asset activities before opening accounts. In our practice, we regularly advise clients that securing the banking relationship in parallel with, or even before, the regulatory application is the correct sequencing – because an authorised EMI without a banking account cannot operate its programme of operations, and a failed banking application after authorisation represents a serious commercial failure.
The cross-border tax dimension is equally material. The jurisdiction of EMI incorporation determines where payment processing income arises and where it is taxed. Payments to affiliated entities – for technology services, distribution or IP licensing – attract transfer pricing scrutiny. VAT treatment of payment services varies across the EU (generally exempt) and UK, but the treatment of crypto-related fees within an EMI structure can generate uncertainty that should be resolved at the structuring stage, not at the first tax audit.
In a recent licensing matter, a payments firm expanding into the EU from a non-EU hub had built its product on the assumption that a single offshore authorisation would cover its European operations through a service contract. When its primary EU banking partner flagged the arrangement as unacceptable and required a locally authorised entity, the firm faced a choice between a rapid EU authorisation or the loss of the banking relationship. We structured and submitted the EU EMI application, managed the pre-application engagement with the relevant national competent authority, and the firm received its authorisation in a position to maintain its banking relationship and its product timeline.
If a prior application stalled or a banking account was closed, a second read can surface the structural reason and the route back. Contact OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw. Map your options
Decision matrix: which operator profile needs an EMI licence?
Profile A – Crypto exchange with fiat on/off ramps: A platform that receives fiat deposits from users, holds those balances pending crypto purchases, and processes fiat withdrawals is performing payment services and potentially issuing e-money. It requires both a VASP or CASP authorisation (for the crypto activities) and an EMI or payment institution authorisation (for the fiat flows). The risk of operating without the payment authorisation is enforcement by the payments regulator – a distinct authority from the VASP supervisor in most jurisdictions – and the loss of banking.
Profile B – Stablecoin issuer: A firm issuing a fiat-referenced stablecoin within the EU is subject to the ART (asset-referenced token) or EMT (electronic money token) regime under MiCA, depending on the reserve structure. An EMT issuer must hold an EMI authorisation. This is a hard requirement under the MiCA framework, not a matter of structuring preference. Firms that have issued stablecoins under a prior regime and have not yet obtained the requisite MiCA authorisation face a defined transition window and enforcement exposure after it closes.
Profile C – Crypto custody or brokerage firm with fiat settlement: A firm that settles trades in fiat on behalf of clients – even if it does not itself hold the fiat balances for any extended period – may be providing payment execution services that require payment institution authorisation short of a full EMI licence, depending on the activity and the jurisdiction. The threshold for requiring full EMI authorisation versus a more limited payment institution registration turns on the nature and duration of the client funds held.
Profile D – DeFi protocol or non-custodial platform: A protocol that never holds fiat or issues fiat-denominated instruments is less likely to require an EMI licence in most jurisdictions. However, if the protocol operates a front-end that processes fiat payments – subscription fees, on-ramp services, treasury management – those specific activities may trigger payment services regulation independently of the protocol's underlying architecture. The on-chain/off-chain distinction is not a reliable guide to regulatory perimeter; the economic substance of the activity is.
Self-assessment checklist: are you ready to apply for an EMI licence?
Before submitting an EMI application, a digital-asset firm should be able to confirm the following at a minimum. First, the corporate structure is finalised: the applicant entity is incorporated in the target jurisdiction, the ownership chain is documented to ultimate beneficial owner level, and any group entities are identified and their roles in the programme of operations described. Second, the management body meets the fit-and-proper requirements of the target regime: each director and senior manager can demonstrate relevant experience and has no disqualifying regulatory or criminal history. Third, the business plan accurately reflects the intended activities for the first three years, including the fiat payment flows that require EMI authorisation, with a financial model that demonstrates capital adequacy at authorisation and on a forward-looking basis. Fourth, the policy suite – AML, safeguarding, operational resilience, IT security, complaints handling, outsourcing – is drafted and consistent with the applicable regulatory requirements. Fifth, banking relationships are identified and, ideally, conditionally confirmed: the firm knows where client funds will be safeguarded and which bank will hold the safeguarding account.
A common assumption in our practice is that the policy documentation can be drafted concurrently with the application process. In reality, regulators in the most demanding jurisdictions – the FCA, MAS, and the major EU competent authorities – review the policies as part of the application and will raise detailed questions about their content. Applications submitted with placeholder or generic policies consistently receive extended review periods or formal requests for significant revision.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – the complete guide to VASP, CASP and payment authorisations across 70+ jurisdictions
- EMI and money transmitter licensing for crypto firms in the United States – federal and state MTL requirements for digital-asset payment businesses
- Sanctions screening for regulated crypto entities – AML and OFAC compliance for authorised digital-asset businesses
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction, regulator caseload and the quality of the application submitted. In EU member states with active digital-asset pipelines, a well-prepared application can progress through pre-application engagement, formal review and decision within a matter of months. The FCA process in the UK is generally more extended. Singapore's MAS operates a tiered system with an interim exemption available for qualifying applicants while a full application is pending. In every case, inadequate preparation – incomplete documentation, weak governance evidence, or an inaccurate description of the business model – is the primary cause of delay.
Which jurisdiction is best for licensing my crypto business?
There is no single answer. The optimal jurisdiction depends on where your users are, where your banking relationships can be maintained, the nature of your product, the activities you intend to offer, and your tax and structural objectives. A firm primarily serving EU users should generally hold an EU authorisation to benefit from passporting. A firm with US activities will need to address federal and state-level requirements separately. We map the licence, banking and tax stack across all relevant operating jurisdictions before recommending a structure – and the correct answer often involves more than one jurisdiction simultaneously.
Do I need a separate custody licence?
In most flagship jurisdictions, yes. Custody of digital assets – holding private keys or controlling access to virtual assets on behalf of clients – is a regulated activity distinct from both the VASP or CASP operating authorisation and the EMI or payment institution licence. Under MiCA, custody and administration of crypto-assets on behalf of clients is a specific CASP service requiring authorisation. Under VARA in Dubai, custody is a separately licensed activity. An EMI licence does not substitute for a custody authorisation, and firms that hold client crypto assets without the appropriate licence are operating in a gap that regulators in the major hubs are actively examining.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so that the structure you build at launch is the structure that can scale. Digital assets are the entirety of our practice, and we act only for businesses. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialist in multi-jurisdiction EMI, payment institution and VASP authorisation processes for digital-asset businesses.
To pressure-test your structure before you commit, message us via t.me/oboluslaw or write to info@oboluslaw.com. Map your options
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.