European payments legal guide · 2026
An EMI or PI application rarely fails because a founder cannot complete a form. It fails because the business model, governance, safeguarding, technology, financial forecasts and AML controls do not describe the same business. The fastest route is therefore not more paperwork; it is better preparation.
1. EMI and PI licenses: the legal difference
A Payment Institution (PI) is authorised under the EU payment-services framework to provide specified payment services such as execution of payment transactions, payment accounts, acquiring, money remittance or payment initiation. An Electronic Money Institution (EMI) can provide payment services and issue electronic money, subject to the additional legal and prudential framework for e-money. Neither authorisation is a universal banking licence.
The correct category depends on what the business actually does. A wallet that stores fiat balances and allows users to spend or redeem them may raise e-money and safeguarding questions. A platform that only routes payments may need a PI analysis. A business that wants to hold deposits, lend from deposits or access the full range of bank activities needs separate advice on whether a credit institution licence is required.
| Question | PI route | EMI route |
|---|---|---|
| Core permission | Specified payment services within the approved scope. | Payment services plus issuing, distributing or redeeming electronic money within the approved model. |
| Initial capital | Depends on the service: PSD2 categories commonly use €20,000, €50,000 or €125,000 thresholds. | Generally €350,000 initial capital, subject to the applicable rules and supervisory assessment. |
| Safeguarding | Customer funds received for payment services must be protected using the applicable safeguarding method. | Safeguarding is central to both e-money and payment activity, with redemption and float-management obligations. |
| Typical use case | Payment processing, remittance, acquiring, initiation or account-information models. | Wallets, stored-value products, prepaid instruments and broader payment ecosystems using e-money. |
| Passporting | EU/EEA cross-border activity is possible after authorisation and the relevant notification process. | The same principle applies, but the passported activity must match the approved permissions and operating model. |
Legal source note: Capital figures are high-level statutory reference points, not a quote for a particular application. The final requirement can be affected by the service category, projected fixed overheads, own-funds calculation and national supervisory practice. Review PSD2, the E-Money Directive and the competent authority's current guidance.
2. Why applications lose time
Regulators commonly request clarification where the application is internally inconsistent. The customer journey says one thing, the financial forecast assumes another, and the AML policy describes a third risk profile. A regulator then has to reconstruct the business before it can assess authorisation.
Perimeter first
Map the exact payment flows, customer funds, currencies, merchants, agents, partners and countries before selecting PI or EMI.
People named early
Identify directors, key function holders, MLRO, compliance lead, risk owner and technology responsibility before drafting the organisation chart.
Evidence, not promises
Convert policies into procedures, sample reports, reconciliation logic, training records and tested escalation paths.
3. A realistic timeline for a serious application
There is no universal approval deadline. A prepared, proportionate application may move through the formal review process within several months, but the full project from perimeter assessment to authorisation often takes longer. Complex ownership, cross-border outsourcing, incomplete local substance, a new technology stack or repeated information requests can materially extend the timetable.
Where the calendar is usually spent
The largest avoidable delay is often the period before filing, when the applicant discovers that its policies, forecasts, contracts and systems do not match.
4. Step-by-step application sequence
- Define the service perimeter: describe each payment, wallet, merchant, card, remittance, initiation, account-information and e-money function in plain language.
- Choose the authorisation route: compare PI and EMI scope, capital, safeguarding, passporting, local substance and long-term product plans. See our FinTech licensing overview.
- Build the ownership and governance file: verify ultimate owners, source of wealth, director experience, fit-and-proper evidence, conflicts and reporting lines.
- Design the financial model: link revenue, transaction volumes, staffing, capital, liquidity, safeguarding, reconciliation and three-year stress assumptions.
- Translate AML into workflows: create risk scoring, KYB, sanctions, PEP handling, transaction monitoring, suspicious-activity escalation and record-retention procedures.
- Evidence technology and outsourcing: document access control, incident response, business continuity, vendor due diligence, data protection and service-level oversight.
- Run a challenge review: ask whether a regulator can trace one customer payment from onboarding through settlement, reconciliation, monitoring and complaints.
5. The readiness test before filing
| Workstream | Regulator-ready evidence | Warning sign |
|---|---|---|
| Business plan | Products, countries, customers, pricing, volumes, partners and risks agree with the financial forecast. | Round numbers with no acquisition logic or payment-flow assumptions. |
| Safeguarding | Named account structure, daily reconciliation, segregation logic, exceptions and customer-funds controls. | “Funds will be safeguarded” with no process or responsible owner. |
| AML/KYC | Risk assessment tied to customer types, jurisdictions, products, channels and transaction monitoring rules. | Generic template copied from a bank or crypto business. |
| Management | Experienced local and group-level roles with time commitment, independence and escalation authority. | One director is expected to perform every control with no backup. |
| Technology | Architecture, access rights, incident log, continuity testing, vendor register and data map. | Critical functions outsourced without oversight or exit planning. |
6. Jurisdiction and practical preparation
Applicants should compare competent-authority expectations, not only incorporation speed. Lithuania, France and Malta are frequently considered for European payment structures, but the right choice depends on management, customer base, languages, banking, cost and the ability to maintain substance after authorisation. Read the dedicated Lithuania EMI guide, Malta guide and the broader FinTech comparison before committing.
Banking and payment-partner onboarding should run in parallel. A bank will test source of funds, customer geographies, expected flows, safeguarding, merchants, chargebacks and AML controls. Our banking and payment setup service and AML/KYC compliance service address the two workstreams together.
“The quickest application is the one that gives the regulator fewer reasons to reconstruct the business.”
Licensium payments-market observation
Conclusion: prepare the operating model, not a paperwork bundle
An EMI or PI authorisation can provide a powerful European platform, but approval depends on a credible business that can protect customer funds, manage risk and operate under continuing supervision. Start with the perimeter, appoint accountable people, test the money flows and make every document tell the same story.
Licensium can compare the relevant EMI and PI routes, review the business plan, build a regulator-ready AML framework and coordinate a confidential licensing discussion.
Research and legal sources
- Directive (EU) 2015/2366 — PSD2
- Directive 2009/110/EC — Electronic Money Directive
- EBA — Payment services and electronic money
- EBA — AML/CFT framework
This article is general information, not legal advice or a guarantee of authorisation. Capital, timing and substance requirements must be confirmed against the current rules and the chosen competent authority.