EST · MMXXVI
Home/Services/Licensing Registration/EMI licence for crypto firms under Heightened Scrutiny
Licensing & Registration

EMI licence for crypto firms under Heightened Scrutiny

Emi licence for crypto firms under Heightened Scrutiny. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBO

An electronic money institution (EMI) licence – the regulatory authorisation that permits a firm to issue e-money and, in most major regimes, to hold client funds in payment accounts – has become the default plumbing layer beneath every serious crypto business. Exchanges need it to hold fiat. Stablecoin issuers need it to redeem. On-ramp and off-ramp providers need it to move value across rails. Yet when regulators see the words "crypto" or "virtual assets" on an application, the review gets harder, the information requests multiply and the timelines stretch. Operating without the right authorisation exposes the business to enforcement action, loss of banking relationships and, in the worst cases, frozen payment rails at the moment they are most needed.

This page sets out what heightened regulatory scrutiny means in practice for a crypto firm seeking an EMI licence, how the application process differs from a standard payment-institution filing, and where a cross-border business is most likely to encounter structural problems before they become existential ones.

What "heightened scrutiny" means for a crypto EMI application

Regulators across the major licensing hubs now apply a distinct review standard to applications from firms with virtual-asset activities. This is not a formal category in most rulebooks; it is a supervisory posture. A firm whose revenue model involves crypto exchange, stablecoin issuance, custody or DeFi-adjacent services will face questions that a pure-payments applicant does not. The FCA in the United Kingdom has been explicit that crypto firms must demonstrate not only AML/KYC compliance but also a credible and tested technical control environment. The Bank of Lithuania, operating within the MiCA transitional period, applies equivalent scrutiny to applicants who also hold or intend to hold a CASP authorisation (Crypto-Asset Service Provider authorisation under MiCA) in parallel. The MFSA in Malta and competent authorities across the EU/EEA have signalled similar expectations.

In our licensing practice, we regularly see regulators requesting detailed flow-of-funds analysis showing how fiat and virtual assets move separately through the firm's infrastructure. Examiners want to see that e-money float is never co-mingled with crypto assets held for clients. They want independent evidence – not management assertions – that the separation is enforced at the technical layer. A well-prepared application addresses these questions before they are asked.

The cross-border dimension sharpens the problem. A firm incorporated in one EU member state, banking through a correspondent in a second, and serving users in a third will face parallel scrutiny from multiple national competent authorities. MiCA passporting narrows but does not eliminate this complexity, because passporting applies to CASP activities, not to the EMI licence itself. The EMI authorisation remains a national matter in the EU: each member state's regulator assesses the application against the applicable European e-money directive provisions, translated into local law.

For a crypto firm, the EMI application is a stress test of the entire operating model, not merely a compliance filing.

Early preparation – before a draft application exists – reduces the risk of a material information request (MIR) that restarts the review clock. In our practice, MIRs are the single most common cause of avoidable delay in crypto-firm EMI applications.

The regulated basis: EMI, payment institution or CASP?

The EMI licence and the payment institution (PI) licence are related but distinct instruments, and choosing the wrong one at the start of the process has downstream consequences that are difficult to correct. An EMI may issue e-money – a claim on the issuer, held in a payment account – and may provide payment services. A PI may only provide payment services; it cannot issue e-money. A crypto firm that plans to hold fiat balances for users, or that plans to issue a fiat-backed stablecoin that qualifies as an EMT (e-money token) under MiCA, needs the EMI licence, not the PI licence.

The CASP authorisation under MiCA covers crypto-asset services – exchange, custody, advice, portfolio management – but does not itself permit the firm to hold e-money or operate payment accounts. A firm that needs to do both requires both authorisations. In our advisory work, the single most common structural mistake we see is a firm that has secured a VASP registration or a CASP authorisation but has not secured the EMI licence it needs to hold fiat on behalf of users. When the banking relationship then requires evidence of EMI authorisation, the firm is operating without one, often unknowingly.

Outside the EU, the picture varies. Under the Singapore Payment Services Act, administered by MAS, a major payment institution licence covers a range of payment services including e-money issuance; there is no separate EMI category as there is in Europe. In the United Kingdom, the FCA registers e-money institutions under the Electronic Money Regulations, which sit alongside the Money Laundering Regulations crypto registration – a firm that holds both crypto and fiat functions needs to satisfy both regimes. In the UAE, VARA activity licences cover crypto services; payment services in Dubai are regulated by the UAE Central Bank, which operates a separate licensing track.

How does the EMI application process work for a crypto firm?

The EMI application process for a crypto-adjacent firm has more moving parts than the standard timeline suggests. In most EU member states, the formal review period runs to a defined statutory window after a complete application is submitted – but the clock does not start until the regulator formally accepts the application as complete. For a crypto firm, that acceptance can take materially longer than for a pure-payments firm, because the initial submission invariably generates pre-acceptance queries.

The application package itself typically includes: the business plan (which must address the crypto and fiat revenue streams separately); the AML/CFT policy (which must account for the Travel Rule – the obligation to pass originator and beneficiary data with a virtual-asset transfer – as well as standard payment-chain requirements); the internal audit and governance documents; the safeguarding analysis (showing how e-money float is held and by which credit institution); and the IT/security documentation. For a crypto firm, the IT/security section is often the most heavily interrogated, because regulators are assessing not just payment infrastructure but the interface between the payment layer and the on-chain layer.

Key process steps for a crypto firm seeking an EMI licence:

  • Pre-application structuring: confirm the correct licence category (EMI vs PI vs combined with CASP), the jurisdiction of incorporation, and the banking partner that will hold safeguarded funds.
  • Flow-of-funds mapping: produce a technical and legal diagram showing how fiat and virtual assets are separated at every stage of the user journey.
  • Draft application preparation: business plan, AML/CFT framework, governance and control documentation, and the safeguarding analysis.
  • Pre-submission engagement with the regulator: in several jurisdictions, a pre-application meeting or written pre-filing inquiry can surface regulator concerns before the formal clock starts.
  • Formal submission and completeness review: the regulator reviews for completeness; queries at this stage are common and must be answered promptly.
  • Substantive review and material information requests: the regulator assesses the application on its merits; MIRs may pause the statutory clock.
  • Decision and, where applicable, passporting notification to other member-state regulators.

In our experience, a well-prepared crypto firm can move through this process in a timeframe broadly comparable to a standard EMI application. A firm that arrives with an incomplete AML framework, unclear safeguarding arrangements or unresolved corporate structure questions will spend that time answering information requests rather than progressing toward a decision.

The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped assessment of where your application stands or where it should start, contact OBOLUS at info@oboluslaw.com or map your options here.

What are the most common mistakes crypto firms make in EMI applications?

The most consequential mistake is submitting before the corporate structure is clean. Regulators examine the full ownership chain, including any holding companies, parallel trading entities and wallets that hold operational or client assets. A crypto firm that has run a trading operation under a different entity, or that has a token treasury sitting in a foundation, will face questions about those structures. Addressing them after submission creates delay; addressing them before submission is straightforward.

The second most common mistake is the safeguarding gap. EMI regulations require that e-money float be held in segregated accounts with an approved credit institution or covered by appropriate insurance. For a crypto firm, the approved credit institution question is acute: many banks remain reluctant to hold safeguarded funds for a crypto-adjacent business. An application that names a banking partner that subsequently declines the relationship will stall. The banking relationship must be confirmed – at least in principle – before or contemporaneously with the application submission.

A third recurring issue is AML/CFT documentation that covers traditional payment chains but does not address virtual-asset-specific risks: the Travel Rule, on-chain transaction monitoring, wallet screening, and the handling of privacy coins or mixing-service outputs. Regulators in the major hubs increasingly expect crypto firms to demonstrate that their AML framework is written by people who understand blockchain mechanics, not merely adapted from a generic payments template.

Finally, we regularly see firms underestimate the governance requirements. An EMI must have a qualified management body with appropriate experience. For a crypto firm, at least some of that experience must be demonstrably crypto-relevant. A management team composed entirely of traditional finance professionals, with no documented understanding of virtual-asset operations, raises questions at the fit-and-proper assessment stage.

How does a cross-border crypto business manage the EMI and VASP licensing stack?

For a business sitting between multiple jurisdictions, the licensing question is rarely about a single instrument. A crypto exchange that holds fiat for users, provides custody, and serves clients across the EU and UK faces a matrix of requirements: a CASP authorisation in one EU member state (with passporting to others), an EMI licence for the fiat-holding function, FCA registration under the Money Laundering Regulations for UK-facing activity, and potentially MAS or SFC licensing if the firm serves Asia-Pacific users.

The cross-border reality is that each of these authorisations has its own timeline, its own capital expectations and its own AML regime. MiCA passporting is a significant benefit, but it applies only after the home-state CASP authorisation is granted. The EMI licence does not passport in the same way that a CASP authorisation does within the EU; a firm serving users in multiple EU member states through an EMI must consider whether its e-money activities require notification or registration in each host member state.

We map the licence, banking and tax stack for our clients before they commit to a jurisdiction. In our cross-border practice, the sequencing decision – which authorisation to pursue first – is often more consequential than the choice of jurisdiction. A firm that secures a CASP authorisation but defers the EMI application will find that its payment rails are limited until the EMI licence is in place. A firm that secures the EMI first, in a jurisdiction that then requires a full CASP authorisation before the firm can offer trading services, faces a gap period of operational restriction.

Allied counsel in the relevant jurisdiction support our work on the ground: local regulatory filings, pre-submission meetings with the competent authority, and ongoing supervisory communication require local presence and relationships that a purely desk-based practice cannot replicate.

If a prior application stalled or a banking relationship collapsed mid-process, a structural review can surface the reason and map the route forward. Write to info@oboluslaw.com or start the conversation here.

Which EMI licensing profile fits your crypto business?

Not every crypto firm has the same licensing needs, and the correct instrument depends on the business model, the user base and the banking architecture. The following profiles cover the most common scenarios we advise on.

Profile A – Crypto exchange with fiat on/off ramp serving EU users. This firm needs a CASP authorisation under MiCA for the trading and custody services, and an EMI licence in the home member state for the fiat-holding function. The sequencing question is material: in our practice, we generally recommend running both applications in parallel where the jurisdiction allows, to avoid a gap between CASP authorisation and EMI authorisation. The key risk is the banking relationship for safeguarded funds. Timeline for the combined stack is typically measured in many months and varies by member state and application quality.

Profile B – Stablecoin issuer targeting the EU market. A stablecoin that qualifies as an EMT under MiCA requires the issuer to hold an EMI authorisation in an EU member state. This is a hard requirement, not a choice. The application must address MiCA's reserve composition and redemption obligations in addition to the standard EMI requirements. The issuer must also comply with MiCA's whitepaper obligations for the token itself. This is the most technically complex licensing path in the EU crypto space.

Profile C – Payments firm expanding into crypto services. A firm that already holds an EMI or PI licence and wishes to add crypto services faces a different challenge: the existing licence does not automatically cover VASP or CASP activities. The firm must apply for the applicable crypto authorisation in addition to the existing payment licence. Regulators will assess whether the addition of crypto services changes the firm's risk profile in a way that requires changes to the existing licence conditions. In our practice, this assessment is often underestimated by firms that assume their existing regulatory relationship smooths the path.

Profile D – Non-EU crypto firm seeking EU market access. A firm incorporated outside the EU that wishes to serve EU users with fiat-holding services must establish an EU entity and obtain the EMI licence in the relevant member state. There is no third-country EMI passporting into the EU. The choice of member state involves a range of factors – regulatory timeline, local banking availability, the cost of ongoing supervision, and the firm's existing operational presence in the EU. Lithuania has historically been a faster-entry jurisdiction for EMI authorisation; Malta and other member states offer different trade-offs.

A common assumption about offshore licensing

A common assumption among early-stage and scaling crypto firms is that a single offshore licence – a BVI VASP registration, a Cayman VASP Act registration, or a registration in a jurisdiction with lighter-touch oversight – is sufficient to serve clients globally, including in regulated markets such as the EU or UK. That assumption is incorrect, and it is increasingly dangerous to rely on it.

Regulators in the EU, UK, Singapore and Hong Kong apply a territorial analysis based on where services are actually provided to users, not where the entity is incorporated. A firm incorporated in the BVI but actively soliciting EU retail users for fiat-holding payment accounts is providing regulated payment services in the EU without authorisation. The FCA applies the same analysis to UK users. MAS applies an equivalent framework to Singapore users. The practical consequence is that the offshore structure provides no shelter from enforcement in the jurisdictions where the users sit.

The BVI VASP Act 2022 and the Cayman VASP Act are genuine and useful regulatory instruments for entities with genuine offshore operations – funds, holding companies, entities with no direct retail-user relationships. They are not substitutes for EMI or CASP authorisation in the jurisdictions where regulated services are provided to regulated-market users.

In our licensing practice, we have seen firms build significant user bases on the basis of an offshore structure, only to discover – at the point of a banking review, a regulatory inquiry or a market-entry step – that the structure does not support the activity it is being used for. Rebuilding a compliant structure under time pressure is materially harder and more expensive than building it correctly at the outset.

Self-assessment checklist before applying for an EMI licence

Before a crypto firm submits an EMI application – or instructs counsel to prepare one – the following questions should be answered with documentary evidence, not management assertions.

  • Is the corporate structure clean, with a documented ownership chain and no unresolved token treasury or foundation issues?
  • Has the firm confirmed, at least in principle, a banking partner that will hold safeguarded e-money float?
  • Does the AML/CFT framework address virtual-asset-specific risks, including Travel Rule compliance, on-chain transaction monitoring and wallet screening?
  • Is the flow-of-funds separation between fiat and crypto assets documented at the technical and legal level?
  • Does the management body include individuals with documented experience in virtual-asset operations, sufficient to satisfy the fit-and-proper requirements of the target regulator?
  • Has the firm mapped which services require which licence – and in which jurisdiction – before settling on the application sequence?
  • Does the business plan address the cross-border user base in a way that is consistent with the territorial scope of the authorisation being sought?

A firm that can answer all seven questions with documentary evidence is in a materially stronger position than one that cannot. In our practice, we work through this checklist with clients before any application is drafted, because identifying a gap at the checklist stage costs days; identifying it at the MIR stage costs months.

A cross-border EMI application under pressure

In a recent licensing matter, a crypto payments firm incorporated in an EU member state had been operating under a PI licence but discovered, during a banking-partner due diligence process, that its fiat-holding function required an EMI licence rather than a PI licence. The banking partner's own compliance team flagged the gap. The firm had active operations and a live user base. We conducted a structural review across the entity's licensing, banking and AML framework, identified the specific activities that crossed the EMI threshold, and prepared a revised application with a corrected safeguarding analysis and a supplementary AML annex addressing Travel Rule compliance. The application was submitted with a pre-submission meeting arranged with the competent authority. The firm maintained its banking relationship and its PI licence during the review period while the EMI application was assessed. The matter resolved without enforcement action and without interruption to payment services.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

The timeline varies by jurisdiction, licence category and application quality. In most EU member states, the formal statutory review period for an EMI authorisation runs to several months after the application is accepted as complete. For crypto firms, the pre-acceptance phase – during which the regulator reviews for completeness – frequently extends the overall timeline. A well-prepared application with a confirmed banking partner and a complete AML framework materially reduces delay. We advise clients to plan for a timeline measured in many months rather than weeks for the full EMI authorisation process.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction. The right choice depends on the firm's user base, revenue model, banking options, operational presence and long-term market-access goals. For EU market access, the CASP and EMI regime under MiCA applies across all member states; the choice of home-state regulator involves timeline, cost and practical considerations. For Asia-Pacific access, MAS in Singapore and SFC in Hong Kong apply distinct regimes. A firm seeking global coverage typically needs a stack of authorisations, not a single licence. We map that stack before the client commits to a structure.

Do I need a separate custody licence?

In most major regimes, custody of virtual assets – holding client assets on behalf of users, with the ability to transfer them – is a regulated activity separate from the EMI licence. Under MiCA, custody is a CASP activity requiring its own authorisation. Under the Singapore Payment Services Act, custody is a distinct regulated activity. An EMI licence permits the firm to hold e-money; it does not, by itself, authorise crypto-asset custody. A firm that holds both fiat and virtual assets for users needs to confirm the applicable custody authorisation in each jurisdiction where it operates. This is a common gap we identify in licensing reviews.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ dispute forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your EMI licensing situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EMI and CASP authorisation strategy for crypto firms across EU, UK and Asia-Pacific licensing regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours