How an EU e-money institution is structured
Holding company, licensed EMI, safeguarding accounts and passporting — where client money actually sits, what capital is required, and what PSD3 will change.
The licensed entity is deliberately thin and clean: the regulator authorises it, so nothing unrelated is allowed to sit inside it.
- Customer funds in
- Received against issued e-money and placed in the safeguarding account by the end of the following business day.
- Revenue
- Fees and interchange are the EMI's own income and sit outside safeguarded funds — the reconciliation boundary regulators test first.
- Insolvency
- Safeguarded funds are protected for e-money holders ahead of general creditors, which is the reason for the whole arrangement.
- Expansion
- Host-state markets are opened by passport notification via the home regulator, not by a new licence.
Why the licensed entity is kept thin
Regulators authorise a specific legal entity with a specific business plan. Anything else the group does — software development, marketing, unrelated ventures, intra-group lending — belongs above or beside the EMI, never inside it. A licensed entity carrying unrelated activity attracts supervisory attention and complicates own-funds calculations.
The holding company therefore employs group staff, owns the platform IP and consolidates investment, while licensing the technology to the EMI on arm's-length terms.
Safeguarding is the heart of the file
Safeguarding is not a labelled bank account. It is a daily discipline: funds received against issued e-money placed with a credit institution by the end of the following business day, kept apart from the institution's own funds, reconciled every day, with the reconciliation evidenced and the boundary between customer money and revenue clearly drawn.
Failures here are what closes payment institutions. Supervisors ask for reconciliations before they ask for anything else.
Passporting, and what it does not give you
Once authorised, an EMI notifies its home regulator of an intention to provide services into other EEA states, either cross-border or through a branch. That opens the market without a second licence.
It does not remove host-state conduct rules, local AML expectations or, crucially, the need for banking and scheme relationships in that market. Groups that treat the passport as a commercial solution rather than a legal one usually discover this at the acquiring stage.
What is changing
The PSD3 and Payment Services Regulation package will replace PSD2 and EMD2, moving much of the regime into directly applicable EU regulation and merging the payment and e-money frameworks. Adoption and transposition timing was still moving through 2025 and 2026, so any application should be built to current rules with the transition mapped, not assumed.
Separately, instant payments obligations are now live, and Lithuania imposed new requirements on institutions participating in payment systems with effect from 9 April 2025.
- Safeguarding treated as an account name rather than a daily reconciliation process.
- Business plan and financial model inconsistent with the licence applied for — the most common reason for a stalled application.
- Opaque ownership above the EMI, which delays or defeats the qualifying-holding assessment.
- Nominal local management with real decisions taken elsewhere.
- Own funds calculated under the wrong method, leaving a capital shortfall at the first supervisory review.
- Assuming the passport delivers banking, acquiring and scheme access in the host market.
Seen in practice
How a SOPARFI sits between an operating group and its shareholders, why the participation exemption is the whole point, and the conditions that decide whether a European exit is taxed or not.
How DIFC, ADGM and DMCC entities sit under a UAE holding or foundation, what the 0% Qualifying Free Zone Person status actually requires, and how groups lose it.
Why there are two feeders, what the master actually does, where the manager sits, and which entity in the chart carries the economic substance obligation.