Markets

Licensing a Money Transfer Business in the EU: Payment Institution Licence and Passporting

How to choose an authorisation route and a home member state, passport into other markets, safeguard customer money and show regulators the platform behind it

An EU payment institution licence is two things at once: permission to send money in one member state, and a passport to offer the same service in the others. Founders tend to focus on the first and underestimate the second. The home state you choose decides who supervises you, in what language, and how much of your business must sit in that country. The host states you passport into still apply their own anti-money laundering rules to what you do there.

This guide is for founders, compliance heads and operations leads planning to send money from the EU. It covers the authorisation routes, how to choose a home state, how passporting works, safeguarding, local AML supervision and the platform evidence regulators ask for. It is general guidance, not legal advice: confirm every obligation with the regulator in each country, or with an adviser who works in that market, before you apply or launch.

01 · ROUTES

Choose the authorisation route that fits your model

Money remittance is one of the payment services listed in the second Payment Services Directive (PSD2). Each member state has written PSD2 into its own law, and its own anti-money laundering law follows the EU AML directives. The routes below exist in every member state, though the detail varies from country to country.

  • Payment institution (PI). The standard route for a money transfer business. You are authorised by your home regulator, hold initial capital (PSD2 sets €20,000 for a firm offering only money remittance), safeguard customer money and can passport. This is the route most of this guide assumes.
  • Electronic money institution (EMI). Needed if customers will hold stored value with you, such as a wallet balance they keep and spend later. Capital requirements are higher (€350,000 initial capital) and safeguarding covers the e-money you issue. An EMI can also provide payment services, money remittance included.
  • Registered or small payment institution. PSD2 lets member states exempt smaller businesses from full authorisation where their monthly payment volume, averaged over the previous 12 months, stays under a national limit of no more than €3 million. Requirements are lighter, but there is no passport, so the route suits a single-country business. Not every state offers it for money remittance (France's simplified licence excludes it), so check the national rule.
  • Agent of an authorised institution. You provide the service on behalf of a licensed PI or EMI, which registers you as its agent and remains responsible for your compliance. It is the quickest way to start trading, but your corridors, limits and risk appetite are the principal's decisions.
EU authorisation routes for a money transfer business compared
RouteWho answers to the regulatorPassportFits
Payment institutionYouYesA remittance business planning to serve more than one country
E-money institutionYouYesA business offering customer wallets that hold value
Registered or small PIYou, under lighter rulesNoA one-country business below the threshold
Agent of a PI or EMIThe principalThrough the principal onlyTesting a market before applying yourself

Decide the wallet question early. If you plan to let customers keep a balance, get advice on whether your model needs e-money authorisation before you choose the PI route, because changing route later means a new application.

02 · HOME STATE

Choose a home member state on more than speed

Your home state is where you are authorised and where your head office is. Its regulator supervises your prudential position for the whole EU, so you will live with that choice for years. In France authorisation comes from the ACPR, in the Netherlands from De Nederlandsche Bank (with the AFM overseeing conduct), and in Spain from the Banco de España (with SEPBLAC as the AML supervisor and financial intelligence unit). Speak to firms each regulator already supervises, and to local advisers, before deciding.

What to weigh when choosing a home member state
FactorWhat to find outWhy it matters
Regulator approachHow the regulator engages before and during an application; whether it offers pre-application meetings; how it treats outsourced technologyA regulator that engages early catches gaps before they become rejection reasons
LanguageWhether the application, policies and correspondence must be in the national languageYour compliance documents must be written and maintained in that language, for every update
TimelinesHow long recent applicants waited, in their own words; how complete an application must be before the clock startsPublished targets and lived experience often differ; plan funding for the longer case
SubstanceWhich managers and functions must sit in the country; whether real decision-making must happen thereA licence held by a shell entity will not survive supervision
Your customersWhether your largest customer base lives in that countryBeing supervised where most of your customers are keeps supervision and conduct rules aligned
BankingWhether local banks will open safeguarding and operating accounts for a payment institutionWithout a safeguarding account you cannot trade, however good the licence
AML supervisionWho supervises AML and how the financial intelligence unit receives reportsYou will deal with them every week

Watch for: choosing a home state only because applications there are said to be quick. Regulators expect a firm's management and control to sit where it is authorised. If your team, customers and decisions are elsewhere, expect hard questions at application and more after it.

03 · APPLICATION

Build an application the regulator can approve

Applications follow a common pattern across member states, based on PSD2 and the European Banking Authority's guidelines on authorisation. Expect to provide:

  1. Programme of operations and business plan, including the corridors, payout methods and customer types you will serve, and a forecast for the first years.
  2. Governance: directors and managers who meet the fit and proper test, a named compliance function and clear reporting lines.
  3. Capital and own funds, with evidence of where the money came from.
  4. Safeguarding arrangements for customer money (see section 05).
  5. AML and counter-terrorist financing programme: business-wide risk assessment, customer due diligence, monitoring, reporting, sanctions screening and training.
  6. Security and operational resilience: incident handling, business continuity, outsourcing and security policies, and how your technology supports them.
  7. Agents and outsourcing: who does what on your behalf, and how you oversee them.

Write the policies to describe how your platform actually behaves. Regulators read the AML programme next to the system description, and a mismatch prompts follow-up questions.

04 · PASSPORTING

Passport into other member states, one notification at a time

Once authorised, you can offer your services in another member state by notifying your home regulator, which forwards the notification to the host state's regulator. There are two forms:

  • Freedom to provide services, where you serve customers in the host state remotely, for example through your app, without a physical presence there.
  • Right of establishment, where you open a branch or appoint agents in the host state.

The host regulator can raise concerns, particularly about agents and AML, and the home regulator decides whether the passport goes ahead. PSD2 gives the home regulator one month to forward a complete notification, the host one month to respond, and the home regulator three months in all to decide, so allow up to three months and do not market to customers in the host state until the passport is in place.

A passport does not take local rules with it. Each host state applies its own AML law to activity on its territory, and agents in a host state fall under its AML supervision. Host states can require a payment institution operating there through agents to appoint a central contact point, a local person who answers the host regulator on AML matters. Consumer protection, data protection and language expectations also follow the customer.

A UK or other non-EEA licence gives no passporting rights.

05 · SAFEGUARDING

Safeguard customer money from the first transfer

Under PSD2, money a customer gives you for a transfer must be protected until it is paid out. The usual methods are keeping it in a separate account at a credit institution, apart from your own money, or covering it with an insurance policy or comparable guarantee. Your home regulator will want to know which method you use, at which bank, and how you prove every day that the safeguarded balance matches what you owe customers.

That daily proof is an accounting job: for every transfer, when customer money arrived, when it left, and which fees and FX gains are yours to move out. A ledger that records every movement automatically makes the answer routine.

Before you apply: open the conversation with banks about a safeguarding account early. Many applicants find that banking, not the licence, is the slowest step, and regulators will expect your arrangements to be in place before you trade.

06 · AML

Meet AML and sanctions duties in every country you serve

Your AML programme has to work in each member state you serve, not only at home. In practice that means:

  • Customer due diligence before a business relationship or an occasional transfer of funds above €1,000 (some member states set stricter national thresholds), with enhanced due diligence for higher-risk customers, politically exposed persons and high-risk third countries.
  • Information with every transfer. The EU Transfer of Funds Regulation requires payer and payee information to accompany transfers.
  • Suspicious transaction reports to the financial intelligence unit of the member state where you are established, such as Tracfin in France, FIU-Nederland in the Netherlands and SEPBLAC in Spain. Where you operate in a host state through a branch or agents, expect to report to that state's unit for the activity there.
  • Sanctions. EU sanctions apply directly in every member state, and national authorities enforce them. Screen senders and recipients, act on matches, and keep a record of every decision.
  • Training and records, kept in a form a host supervisor can review.

The rules are changing. The EU has adopted a new AML package, including a directly applicable AML Regulation (Regulation (EU) 2024/1624, which applies from 10 July 2027) and a new EU Anti-Money Laundering Authority (AMLA). Parliament and Council negotiators also reached a provisional agreement in November 2025 on PSD3 and a Payment Services Regulation to replace PSD2; check the Official Journal for their final text and dates. Track them with your adviser, and confirm dates against official sources before you plan around them. For the wider programme, see compliance and risk management for money transfer businesses and sanctions screening for remittance companies.

07 · EVIDENCE

Prepare the platform evidence regulators ask for

At application, and again at inspection, expect to show:

  • How identity checks, screening and limits are applied, and that they cannot be skipped.
  • Where customer data is hosted and who can reach it.
  • Who on your team can change rules, rates and fees, and how changes are recorded.
  • How suspicious activity is detected, investigated and reported.
  • How the safeguarded balance is reconciled.
  • What software the platform is built from, and how your provider manages security and quality.

Build a review pack before the first questionnaire arrives. Our guide to passing a security review covers what to put in it.

08 · SCENARIO

Scenario: one home state, two passported markets

The details are illustrative, not drawn from any real operator. A founding team of five plans a remittance app for West and North African communities, with customers in France, Spain and Belgium.

Choosing the route. Customers will not hold balances, so they apply as a payment institution rather than an EMI. They rule out the registered route because they need a passport.

Choosing the home state. They score three candidates against the table in section 02. France wins: most expected customers live there, the founders and compliance lead work in French, and the head office and decision-making can genuinely sit in Paris. Another state was described to them as quicker, but their team and customers would have been elsewhere.

Applying. The French policies are written to match the platform: AML rules per corridor, the documents asked for as a customer's totals grow, screening lists and who rules on matches. The safeguarding bank is agreed before the application is filed.

Passporting. After authorisation they notify Belgium under the freedom to provide services: customers there use the app, and there are no agents. For Spain they want 12 agent locations, so they notify the right of establishment, appoint a central contact point if the host regulator requires one, and add Spanish AML procedures for agent oversight. Spanish customers get the app and emails in Spanish.

Running it. Each quarter the compliance lead samples screening decisions and agent onboarding records in all three countries.

What the scenario shows: the home state was chosen where the business really is, which made substance easy to prove. Passporting was quick for remote services and heavier where agents were involved, because agents bring the host state's AML supervision with them.

09 · REMITSO

Doing it with RemitSo

RemitSo is a white label remittance platform. It gives an EU payment institution the controls and records its policies describe. See the admin features.

  • Sanctions screening against 8 lists reloaded every night, including EU financial sanctions and Swiss SECO alongside the UN, UK, OFAC, Canada SEMA and Australian DFAT lists. Each list shows its version and load history, the people a change could affect are re-screened, and every officer decision is recorded. A "Sanction lists out of date" alert tells your team if a load falls behind.
  • AML rules per currency, paying country and payout country, with corridor exceptions, windows from a single transaction to a year, and document tiers as totals grow. Set EUR rules for each passported market, with a history of who changed what.
  • 46 risk indicators combined into your own risk rules: risky transfers wait for a person, everything else flows.
  • Suspicious Activity Reports generated, managed and submitted from the console, so the case and its evidence sit together. Filing with each national FIU follows your own procedure.
  • ID check and selfie inside the first transfer, so customers are verified at the moment it matters.
  • Apps in English, French or Spanish, with emails in each customer's own language, suited to customers in France, Spain and Belgium.
  • Double-entry accounting and deposits matched to the cent: every payment, payout, fee and FX movement is recorded, which supports your daily safeguarding reconciliation.
  • A dedicated AWS account in your region, a software bill of materials, and ISO 27001:2022 and ISO 9001:2015 certification for the technology section of your application and later reviews.

RemitSo does not generate EU regulator or FIU reports today; its only built-in regulator report is Australia's IFTI-E. Your team still writes and owns the AML programme, rules on matches, decides what to report and deals with each regulator.

Book a demo to walk through the controls with your application in mind.

SOURCES

Sources

Checked October 2026. Regulations change; confirm current requirements with the regulator or your adviser.

FAQ

Frequently asked questions

Do I need a payment institution or an e-money licence to send money in the EU?

For money remittance alone, a payment institution licence is the usual route. If customers will hold a balance with you and spend it later, ask an adviser whether you need e-money authorisation instead, before you apply.

Can one EU licence cover every member state?

An authorised payment institution can passport into other EU and EEA states by notification. Each host state still applies its own AML law, consumer rules and supervision of agents on its territory.

Which EU country is best for a payment institution licence?

There is no single answer. Weigh the regulator's approach, the working language, realistic timelines, the substance you must hold locally, banking access and where your customers live. Speak to firms already supervised there.

Where do we file suspicious transaction reports if we operate in several countries?

The EU AML directive requires reports to go to the financial intelligence unit of the member state where the reporting firm is established. That is your home state, and also a host state where you operate through a branch or agents. Confirm the arrangement for each country with its regulator or your adviser, especially where you use agents.

Does RemitSo produce EU regulatory reports?

Not today. RemitSo generates and manages Suspicious Activity Reports in the console and keeps the transaction record your reports draw on, but its only built-in regulator report is Australia's IFTI-E.

Built by people who have helped MSBs for years.

The risk checks on every online transfer come from what they see every day.

  • The person paying isn't the customer
  • One bank account, several customers
  • A disposable email address
  • Sign-in from a high-risk location
  • The same person signing up twice
  • A name close to a sanctions list
Book a demo

See RemitSo running with your corridors.

  • 30 minutes with our team, on video
  • The real admin panel and customer apps
  • White label or source code, explained with pricing
  • Your compliance and launch questions answered
Loading the form…

Video