An EMI application is not a form you complete. It is a file in which you demonstrate, in advance and on paper, that you can run a regulated business that holds other people's money. Regulators read it as a business case with a compliance framework attached, and they reject far more applications for being thin than for being wrong.

The mechanics vary by country. What regulators are looking for does not.

Start with the business model, because everything follows from it

Before capital, before people, before systems, the regulator wants to understand what you actually do. Who your customers are, how they are onboarded, where the money comes from, where it goes, which countries it touches, and how you make a margin.

This matters more than founders expect. Almost every subsequent requirement is calibrated to the model. A firm serving domestic salaried consumers and a firm serving high-turnover merchants in higher-risk corridors are held to very different standards on the same licence. Describe the model imprecisely and every downstream section of the application will be judged against the wrong benchmark.

Capital, and the difference between having it and evidencing it

An EMI carries an initial capital requirement, and an ongoing own funds requirement that scales with the average outstanding e-money you hold. Meeting the number on day one is the easy part. The application has to show that the capital is genuinely yours, that it will remain unencumbered, and that the shareholders behind it can support the firm as volumes grow.

Regulators trace funding to source. Capital arriving from an opaque structure, or from an investor who cannot evidence how they came by it, is one of the more common reasons a file stops moving.

Safeguarding, examined before you launch

Every EMI must safeguard customer funds, either by segregating them at a credit institution or investing them in secure liquid assets, or by covering them with an insurance policy or comparable guarantee. The regulator will want the specific arrangement, the specific bank, the reconciliation process, and the evidence that the account is legally insulated from your own creditors.

This is the section that most often exposes a firm that has not done the work, because it cannot be written in the abstract. You need a real banking relationship in place. Safeguarding deserves its own treatment, and it is worth reading before drafting anything.

The people

Regulators authorise firms, but they assess individuals. Directors, the money laundering reporting officer, the compliance officer, and significant shareholders all go through fitness and propriety assessment: experience relevant to the business, a clean regulatory history, and enough seniority to say no to the commercial side.

A common and avoidable failure is a compliance function that exists only on the organisation chart. If your MLRO is a part-time contractor with four other mandates, expect that to be noticed and challenged.

Governance and financial crime controls

Regulators want to see that risk is owned by someone senior, that the compliance function can act independently of the commercial side, and that the firm's financial crime controls are built around its own exposure rather than around a template.

That last point is where applications are separated. Controls calibrated to the corridors you actually serve, the customer types you actually onboard, and the products you actually offer read very differently from generic material, and the difference is visible from a distance. Regulators also expect a firm to be able to close in an orderly way without customers losing balances, and to have thought about that before it is needed rather than after.

Substance in the country of authorisation

Regulators expect the firm to be genuinely run from the country that licensed it. That means real premises, decision makers who are actually there, and the core functions performed locally rather than exported to a group entity elsewhere. Letterbox arrangements have been a supervisory priority across the EEA for years and are treated as a reason to refuse rather than a detail to fix later.

Why applications slip

Regulators work to a statutory clock, and that clock stops every time they ask a question. The duration of an application is therefore set less by the authority than by the quality of the file it receives, which is the part you control.

Applications stall for predictable reasons: no banking partner secured, a model the applicant cannot explain consistently across sections, capital of unclear provenance, or a compliance function that does not convince. None of those are discovered late by accident. They are visible in the first draft to anyone who has read a rejected file.

The other route

If the timeline is the binding constraint, acquiring an authorised EMI is the alternative. It trades application risk for diligence risk, and it comes with a change-of-control approval that is its own regulatory process.

BrokLicense prepares and runs EMI applications, and the change-of-control approvals when clients acquire instead, in the jurisdictions we cover. The work starts with the business model, so that is where the conversation starts too.