Paris 22:53
New York 16:53
London 21:53
Blog

EMI, payment institution and CASP licences: what regulators check on AML

Louise Toulemonde

Louise Toulemonde

October 1, 2026

EMI, payment institution and CASP licences: what regulators check on AML

Every EMI, payment institution (PI) and crypto-asset service provider (CASP) licence application must describe the internal controls the applicant has built to meet its anti-money laundering obligations, and the regulator assesses them before it grants anything. In practice that means seven things on paper: a written ML/TF risk assessment, customer due diligence and suspicious activity procedures, controls over agents, a training plan, a named person responsible with evidence of their expertise, a review process and a staff manual.

The law gives a regulator three months. The EBA measured a median of seven to nine, and almost every authority blamed the same thing: incomplete files.

The legal hook is short. For a PI, Article 5(1)(k), Directive (EU) 2015/2366 (PSD2) requires "a description of the internal control mechanisms which the applicant has established" to comply with the AML directive. An e-money institution gets the same article through Article 3(1), Directive 2009/110/EC. A CASP answers Article 62(2)(i), Regulation (EU) 2023/1114 (MiCA), which asks for the procedures "to identify, assess and manage risks, including money laundering and terrorist financing risks".

What are EMI, PI and CASP licences?

A payment institution licence authorises a firm to provide payment services under PSD2. An electronic money institution (EMI) licence authorises it to issue e-money as well, under the second E-Money Directive. A CASP authorisation under MiCA covers crypto-asset services such as custody, exchange or running a trading platform, and since the end of the transitional period on 1 July 2026 at the latest (Article 143(3), MiCA) it is the only way to provide those services in the EU.

LicenceLegal basisMinimum initial capitalStatutory decision timeAML item in the file
Payment institutionPSD2EUR 20,000 (money remittance), 50,000 (payment initiation), 125,000 (other services), Article 73 months from a complete file, Article 12Article 5(1)(k)
E-money institutionEMD2EUR 350,000, Article 43 months, PSD2 Article 12 applied by EMD2 Article 3(1)PSD2 Article 5(1)(k)
CASPMiCAEUR 50,000, 125,000 or 150,000 by class, Article 67 and Annex IV25 working days to check completeness, then 40 working days, Article 63Article 62(2)(i)

All three are obliged entities under today's national AML laws and, from 10 July 2027, under the AML Regulation (Articles 2(1)(6), 3 and 90, Regulation (EU) 2024/1624). The licence is where a regulator first checks you can carry that weight.

What does the regulator check on AML and KYC?

The checklist is written down. For PIs and EMIs it is Guideline 14 of the EBA Guidelines on authorisation (EBA/GL/2017/09), in force since 13 January 2018. For CASPs it is Article 6 of Commission Delegated Regulation (EU) 2025/305, which follows the same logic and adds a copy of the policies themselves.

What the file must showEBA GL 14.1 (PI, EMI)Reg. 2025/305 Art. 6 (CASP)
ML/TF risk assessment: customer base, products, channels, geographies(a)(a)
CDD policies and procedures, and suspicious transaction reporting(b)(b)
Controls over branches and agents(c), (g)
Staff and agent training(d)(e)
The person in charge of AML compliance, with evidence of expertise(e)(d)
Controls that keep policies up to date and effective(f)(g)
The AML manual for staff, or a copy of the policies(h)(f)

Two items sink files more than the others. The risk assessment, because a generic one that could describe any fintech tells the regulator you have not looked at your own customers. And the person in charge: the EBA expects the AML/CFT compliance officer to be "appointed at management level" and "normally" to work in the country where the firm is established (EBA/GL/2022/05, paragraphs 25 and 28). For CASPs, ESMA adds that "the outsourcing of AML functions is restricted" and that responsibility "should always remain with the CASP" (ESMA supervisory briefing, 31 January 2025).

How long does a licence take?

The law says three months for a PI or EMI, counted from a complete file. The practice says longer. The EBA's peer review of PSD2 authorisation found that "the median duration of the authorisation process is 7-9 months from the submission of an application", and 28 of 29 national authorities named the same cause of delay: applications "often incomplete upon submission" (EBA/REP/2023/01, paragraphs 28 and 30).

The clock only starts when the regulator considers the file complete, so an AML section written as a placeholder costs months, not days.

What do national regulators add?

  • France, ACPR. PI and EMI licences are granted "dans un délai de 3 mois à compter de la réception d'un dossier complet", and the applicant needs an AML framework "adapté" (ACPR, payment institutions). Its fintech charter asks for a summary of the LCB-FT framework and the key function holders at the pre-application meeting, and notes that silence after three months means refusal. CASPs are authorised by the AMF, with an ACPR opinion. In 2025, 11 CASPs were authorised in France, and only 30% of the 90 firms still registered under the old PSAN regime had applied for MiCA authorisation (AMF annual report 2025).
  • Germany, BaFin. The application must describe the internal controls that meet the duties of sections 27 and 53 (section 10(2) no. 11 ZAG), and BaFin's application overview maps its money laundering row straight to EBA Guideline 14.
  • Netherlands, DNB. A systematic integrity risk analysis (SIRA) covering money laundering, terrorist financing, sanctions and fraud is "a precondition", owned by the management board (DNB EMI application notes). The statutory period is three months, and DNB says processing "tends to be longer".
  • United Kingdom, FCA. Three months from a complete application and 12 months at most (regulation 9, Payment Services Regulations 2017; regulation 9, Electronic Money Regulations 2011), plus a nominated officer under regulation 21, Money Laundering Regulations 2017. The crypto register shows how hard the AML bar is: of 393 applications determined since January 2020, 17% were registered and 67% withdrawn (FCA, as at 1 October 2026).

A worked example: an EMI that onboards businesses

Fernhill Pay, a fictional start-up, applies to the ACPR for an EMI licence to issue business accounts to European SMEs. Capital: EUR 350,000. Its AML section, built on Guideline 14:

  1. Risk assessment. Customers are companies in 12 EU countries, onboarded online, with cross-border payments. Higher-risk segments named: cash-intensive sectors, holding companies with foreign parents, customers outside the EU.
  2. CDD procedures. Registry check, ownership to the natural persons, identity verification of owners and representatives, sanctions and PEP screening, a risk score that sets the review depth.
  3. Reporting. Alert handling, escalation, filing to Tracfin.
  4. AML compliance officer. A named senior manager based in France, with a CV that shows AML experience, and a deputy.
  5. Training. At hiring, then yearly.
  6. Review. An annual effectiveness review reported to the board.
  7. The manual. The procedures above, written for the analyst who will apply them.

What makes this file credible is item 1 with numbers in it: the expected share of high-risk customers, and what the firm does with them.

How many of your customers will be high risk?

Across the KYB files that Dotfile customers rated with a risk engine over the past year, about 1 in 5 landed at high risk or above, and 1 in 25 was prohibited outright. A quarter sat at low risk, just over half at medium. A business plan that assumes every customer is standard risk will not survive the first question from the regulator, and an onboarding team sized for it will not survive its first quarter.

Based on KYB files with a defined risk level, built on Dotfile over the past year; aggregates only.

What changes with the AMLR in 2027?

From 10 July 2027, the AML Regulation writes the governance model into law for every obliged entity: a member of the management body responsible for compliance, the "compliance manager", and a compliance officer "with sufficiently high hierarchical standing" (Article 11(1) and (2), Regulation (EU) 2024/1624). Until then, the national transpositions of the AML directive and the EBA guidelines apply. A file built today should already name both people. Euro area PIs and EMIs also owe Verification of Payee on every credit transfer, and must send and receive instant transfers from 9 April 2027. The full sequence of dates is in our AML regulatory calendar, and the new EU supervisor is covered in our guide to AMLA.

FAQ

What is the difference between an EMI and a payment institution? An EMI can issue electronic money, stored value it holds for the customer, as well as provide payment services; a payment institution provides payment services only and holds funds just to execute transactions. The capital follows: EUR 350,000 for an EMI, EUR 20,000 to 125,000 for a PI.

What is the minimum capital for an EMI licence? EUR 350,000 under Article 4 of Directive 2009/110/EC. A payment institution needs EUR 20,000, 50,000 or 125,000 depending on the services, and a CASP EUR 50,000, 125,000 or 150,000 depending on its class.

How long does a payment institution licence take? Three months from a complete file by law. The EBA measured a median of seven to nine months from submission, mostly because files arrive incomplete.

Do I need an MLRO before I apply? You need to name the person in charge of AML compliance and prove their expertise in the file (EBA Guideline 14.1(e); Article 6(d) of Regulation 2025/305 for CASPs). In the UK, a nominated officer is a legal requirement under regulation 21 of the MLRs.

Can a CASP outsource its AML function? Only in part. ESMA says responsibility for AML compliance always stays with the CASP.

What Dotfile does

Dotfile is the KYB and KYC platform regulated firms use to run the CDD procedures their licence file describes: registry checks, ownership structures and UBO verification, identity verification, AML screening and a configurable risk engine, with every decision recorded in the case. See the risk engine documentation.

Ready for Anywhere?

Verify any business, enter any market, defend every decision. Every signal orchestrated, every decision traceable, from one platform.

Book a demo