Home/Services/Application for Authorisation/EU Electronic Money Institution
European Union

European Union · Authorisation

EU EMI Authorisation under EMD2 & PSD2

Authorisation under EMD2 and PSD2 from the National Competent Authority of your chosen member state, with passporting across all 30 EEA states by notification.

At a glance

RegulatorNational Competent Authority
LegislationEMD2 + PSD2
Initial capital€350,000
Passporting30 EEA states
Realistic end to end6–18 months
40+
Engagements delivered
3
Core jurisdictions — UK, EU & Canada
10+
Licences secured
30+
Years combined experience

Is this the right permission?

Three tests. All three must be true.

There is no single EU application and no single regulator. The decision that shapes cost, timeline and long-term substance obligations is which member state you apply in — and it is made before anything else.

01

You need EEA market access

Authorisation in one member state passports into all 30 EEA states by notification. If your customers are EU-based, this is the route — a UK EMI licence has carried no EEA passporting rights since Brexit, and no amount of UK permission substitutes for it.

02

You can build genuine local substance

There is no branch route. PSD2 requires authorisation to go to a legal person established in a member state, and national regulators read the head-office test as real decision-making in country — Ireland's Central Bank, for example, expects Financial Control, Legal & Compliance and Risk Management physically present.

03

You will exceed the waiver threshold

EMD2 Article 9 allows member states to offer a lighter waiver below €5 million average outstanding e-money — Ireland runs it as Small EMI, Lithuania as a restricted licence. The trade-off is real: Lithuania's restricted licence is valid domestically only, with no passporting at all.

Jurisdiction choice is not a cost comparison. Ireland is slower but carries weight with banking partners; Lithuania is fastest but under materially tighter substance scrutiny since 2022; Malta sits between them. We scope this against your actual model before recommending one.

PSD3 will repeal EMD2 — but not yet

PSD3 and a new Payment Services Regulation have been provisionally agreed and are approaching publication. When they apply — not expected before late 2027 — EMD2 is repealed and e-money institutions become a sub-category of a single merged Payment Institution licence, with a 24-month transition for existing authorisations, extendable to 30 at the national regulator's discretion. It changes long-term planning, not the application you file today.

Overview

There's no single EU regulator — choosing your hub matters.

EU EMI authorisation runs through whichever National Competent Authority (NCA) you choose as your base — there's no single EU-wide regulator, and no single application. Once authorised, you passport across all 30 EEA states, but the notification isn't automatic and the choice of hub jurisdiction is itself a strategic decision, not a formality.

The €350,000 capital figure is the same number the UK inherited from the same original directive, but this is now a fully separate legal regime post-Brexit, assessed entirely on its own terms by your chosen NCA.

One thing worth knowing before you commit to a hub: PSD3 and a new EU Payment Services Regulation have been provisionally agreed by the European Parliament and Council and are approaching formal publication. When they take effect — not expected before late 2027 — EMD2 is repealed outright, and e-money institutions become a sub-category of a single merged Payment Institution licence rather than a separate authorisation type. Existing EMI authorisations get a genuine transition window, 24 months extendable to 30, so this is a real, dated development to factor into long-term planning, not an immediate concern.

Requirements in detail

What you actually need.

Incorporation

Unlike the UK, there's no branch option — PSD2 requires authorisation to go to “a legal person established in a Member State,” so you need a real local entity, not a subsidiary of convenience. Neither PSD2 nor EMD2 actually defines “head office” — that's left to each NCA's own judgment, and in practice they read it as genuine substance: Ireland's Central Bank, for example, expects your Financial Control, Legal & Compliance and Risk Management functions physically in-country, with real board decisions taken there, not just a registered address.

Capital

€350,000 initial capital, the same figure the UK inherited from the same original directive — but the EU version is now a fully separate legal regime post-Brexit, assessed by whichever National Competent Authority (NCA) you apply to. EMD2 Article 9 provides a genuine lighter-touch route too: firms whose average outstanding e-money stays under €5,000,000 (averaged over the preceding six months) can apply for a waiver instead of full authorisation — Ireland runs this as a distinct "Small Electronic Money Institution" registration, Lithuania as a "restricted EMI" licence with no minimum capital and a lower fee, though the trade-off is real: a restricted EMI in Lithuania is valid only within Lithuania, with no EEA passporting. Exceed the threshold and you have 30 days to apply for full authorisation.

Directors & MLRO

Board composition specifics vary by member state — see the jurisdiction comparison below — but a dedicated AML/CFT compliance officer with demonstrable expertise is a universal requirement at authorisation stage, regardless of which NCA you choose.

Governance & people

Your directors and senior managers go through a fit-and-proper assessment covering reputation, integrity, knowledge, skills and time to do the job properly, and your qualifying shareholders are assessed separately to confirm the ownership structure won't compromise sound management. Worth being precise about one commonly-repeated claim: EMD2 and PSD2 don't literally write in a numeric “at least two directors” rule — that specific phrasing comes from banking legislation (CRD IV), not the e-money directive. In practice, though, most NCAs apply an equivalent standard to EMIs anyway; Malta's MFSA explicitly expects at least two executive directors genuinely directing the business, so budget for it regardless of what the directive technically says.

Ongoing obligations

Authorisation isn't the finish line. Safeguarding runs on the same two-method structure the UK inherited from the same directive — segregate relevant funds in a separate account or secure, liquid, low-risk assets, or cover them with an insurance policy or comparable guarantee from a provider outside your own corporate group. A statutory auditor is required, and — where you provide payment initiation or account information services alongside e-money issuance — Professional Indemnity Insurance meeting EBA minimum-amount guidelines. Budget for your chosen NCA's own ongoing supervisory levy too: Ireland runs an industry-wide tiered levy, Malta charges a fixed annual fee from €25,000 plus a formula-based component, and every NCA differs.

Not sure this is the right permission?

A scoping call maps your regulatory perimeter and confirms which regime actually applies — before any documentation work starts.

Book a Scoping Call

Time & cost

What actually drives both.

The three-month statutory period is the same across the EU. Almost nothing else is — which is why the honest answer to "how long" starts with "in which member state".

Jurisdiction sets the baseline

Ireland runs a 90 working-day statutory assessment that commonly extends well beyond it; Lithuania historically the fastest at six to twelve months; Malta around eight months indicative, closer to twelve with preparation. See the comparison below before committing.

Substance cannot be assembled quickly

Local premises, resident senior management and in-country control functions are conditions of authorisation, not things to arrange afterwards. This is the item that most often turns a nine-month plan into an eighteen-month one.

The EBA guidelines set a fixed evidence list

Every NCA works from EBA/GL/2017/09, which specifies eighteen categories of information — programme of operations, business plan, structural organisation, safeguarding, governance, security policy, AML controls, qualifying-holding and management suitability, and more. The list does not vary; the depth expected does.

Fit-and-proper assessments run per person

Directors and senior managers are assessed on reputation, knowledge, skills and time commitment; qualifying shareholders are assessed separately on source of funds, PEP exposure and strategic intent. Each is an individual process with its own timetable.

Initial capital

€350,000

The same figure the UK inherited from the same directive, but assessed independently by your chosen NCA. Article 9 waiver routes carry no minimum capital below €5 million outstanding e-money, at the cost of passporting.

Application fee

Varies by regulator

Ireland charges no application fee and recovers cost through a tiered supervisory levy after authorisation. Lithuania is approximately €1,463 for a full EMI licence. Malta is €10,000 for a single category and €15,000 for both, effective January 2025.

Ongoing supervision

Varies by regulator

Ireland levies through the Central Bank Industry Funding Levy; Malta charges a fixed annual supervisory fee from €25,000 plus a formula-based component. Substance costs — local staff and premises — usually exceed the regulatory fees.

Our fee

Scoped and fixed once the jurisdiction decision is made, since that determines the shape of the pack, the substance requirements and the NCA's specific expectations. The jurisdiction analysis itself is part of the first engagement, not an afterthought.

Choosing your hub

Ireland, Lithuania or Malta.

Ireland
Lithuania
Malta
Timeline
~9–12 months practical (90 working-day statutory assessment, often longer)
6–12 months practical (3 months statutory, 2 for restricted licence)
~8 months indicative, ~12 months total with preparation
Notable requirements
Irish-incorporated; Financial Control, Legal & Compliance and Risk functions physically in-country; Fitness & Probity vetting
No statutory residency rule, but Bank of Lithuania substance expectations in practice favour EU/EEA-resident senior management; management board of 3+ plus a separately appointed CEO
At least two executive directors genuinely directing from Malta, at least one resident; dedicated Compliance Officer plus separate MLRO
Fee
No application fee — tiered supervisory levy after authorisation
Approx. €1,463 full EMI / €1,235 restricted (indicative)
€10,000 single category / €15,000 dual (effective Jan 2025), plus annual supervisory fee from €25,000
Reputation
Thorough and conservative — valued for banking-partner trust, slower in practice
Historically the fastest, most fintech-friendly EU hub — substance scrutiny has tightened materially since 2022 (the Bank of Lithuania revoked EMI UAB PayrNet's licence in 2023 for systemic AML failures)
Established, dialogue-oriented regulator; safeguarding and AML expectations have tightened through 2025–26, and DORA (ICT resilience) applies from January 2025

Indicative — fees and timelines shift with each regulator’s own notices. We confirm current figures directly before you commit to a jurisdiction.

Process & timeline

From scoping to authorisation.

3 months statutory · 6–18 months practical

01

Document preparation & jurisdiction choice

Choose your NCA and build the full documentation suite around that jurisdiction's specific expectations — the biggest driver of both speed and long-term substance costs.

02

Review & query management

Submission to your chosen NCA and its review. Statutory minimums run three months, but real-world timelines vary sharply by jurisdiction — see the comparison below.

03

Pre-commencement & authorisation

Final conditions — capital injection, safeguarding account, local substance confirmed — then formal authorisation and, once live, passporting notifications to any other EEA states you plan to serve.

What we prepare

The documentation suite.

53 documents, illustrative — safeguarding and governance documentation is tailored to your chosen NCA's specific expectations, not a single EU-wide template.

01

AML/CFT Programme

The firm's approach to customer due diligence, monitoring, screening and suspicious activity reporting.

13 documents
AML/CFT Policy
Business-Wide Risk Assessment Procedure
BWRA Matrix & Controls
Customer Due Diligence Procedure
Customer Risk Assessment Matrix
Transaction Monitoring Procedure
Ongoing Monitoring Procedure
Sanctions Policy
Suspicious Activity Reporting Procedure
Anti-Bribery & Corruption Policy
Anti-Tax Evasion Policy
Anti-Fraud Policy
Countries & Territories Risk Matrix

+ supporting forms and registers

02

Safeguarding Programme

Your funds-protection method — segregation or insurance/comparable guarantee — under EMD2 Article 7, the same two-method structure the UK inherited from the same directive.

5 documents
Safeguarding Method Assessment (Segregation vs Insurance/Guarantee)
Safeguarding Policy
Client Funds Reconciliation Procedure
Investment Policy (Liquid, Secure, Low-Risk Assets)
Safeguarding Training & Awareness Programme

EBA/GL/2017/09, Guideline 7. + supporting forms

03

Governance Framework

The firm's structure, reporting lines, responsibilities and internal control environment.

11 documents
Governance Policy
Outsourcing Policy
Internal Audit Programme
Whistleblowing Policy
Complaints Procedure
Complaints Register
Consumer Duty Policy
Wind-Down Plan
Risk & Compliance Committee Charter
Safeguarding Committee Charter
Internal Audit Committee Charter

+ fit-and-proper files for management and qualifying shareholders

04

IT & Cybersecurity Programme

The firm's approach to systems, security controls, access management, incident response and mandatory fraud reporting.

15 documents
Information Security Policy
IT Governance & Strategy
IT Architecture & Funds Flow Overview
IT & Security Risk Assessment & Methodology
Operational & Tech Risk Management Framework
Business Continuity & Disaster Recovery Plan
Incident Management Policy & Procedure
Regulatory & Internal Incident Reporting Standard
Fraud & Transaction Statistics Reporting Procedure
IT Operations & Service Management Procedures
Change & Release Management Policy
Access Control & User Management Policy
Logging, Monitoring & SIEM Standard
Outsourcing & Third-Party Risk Management Policy
Vulnerability Management & Security Testing Policy

+ supporting standards and registers

05

Business & Operational Documentation

The commercial and operational backbone of the application — how the business runs and is governed.

9 documents
Business Plan
Programme of Operations
Financial Projections (incl. stress scenarios)
Funds Flow Diagrams
Draft E-Money Holder Contract
Organisational Structure Chart
Governance Structure Chart
Client Journey Chart
Three Lines of Defence Model Chart

+ supporting documentation and charts

We build this pack, not a template of it.

Every document is written against your actual services, customers and jurisdictions — which is what makes it survive a regulator’s review and a bank’s due diligence alike.

Talk to Us

Who does the work

Senior people, start to finish.

Every application is scoped, built and submitted by senior team members who understand fintech and this specific regime — never delegated to a junior bench.

Sam Kyazymov
Founder & CEO
Sachin Popat
Managing Director
Viktoriia Nikitina
Senior Regulatory Advisory & Strategy Consultant
Theodora Tserni
Senior Regulatory Advisor

FAQ

Questions worth asking up front.

It depends on your risk tolerance and timeline pressure, not just cost. Lithuania is historically the fastest route but under more substance scrutiny than a few years ago; Ireland is slower and more conservative but carries real weight with banking partners; Malta sits in between, with an established, dialogue-oriented regulator. We scope this against your actual business model before recommending one.

Secure your EU EMI,
secure your future.

Book a scoping call and we’ll map your fastest, most defensible path to authorisation.