CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Bybit's Austrian EMI License: Dual-Entity EU Structure and What Accounting Firms Must Assess Now

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING Bybit's Austrian EMI License: Dual-Entity EUStructure and What Accounting Firms Must AssessNow

Bybit's European payments subsidiary has received an electronic money institution (EMI) license from Austria's Financial Market Authority (FMA), giving the exchange a direct regulatory footing for payment services across the European Economic Area. The move matters well beyond one exchange: it establishes a dual-entity model, one entity authorized under the EU's Markets in Crypto-Assets Regulation (MiCA) and a separate one licensed as an electronic money institution, that will increasingly appear on the books of clients served by accounting firms, auditors, and CFOs working in the digital asset space. Firms relying on robust crypto accounting software need to understand how this structure affects engagement scoping, financial reporting, and AML obligations today.

Bybit's Austrian EMI License: Dual-Entity EU Structure and What Accounting Firms Must Assess Now

What the FMA Authorization Actually Covers

The scope of Bybit Payments GmbH

The entity that received the FMA authorization is Bybit Payments GmbH. Under Austrian and EU payment services law, an EMI license authorizes the issuance of electronic money and the provision of payment services, which in this case may include person-to-person transfers, merchant payment solutions, open banking features, and card products. These services will be offered through the Bybit.eu platform.

Critically, the license does not authorize crypto-asset services. Those remain the domain of a separate Austrian entity, Bybit EU GmbH, which has held a MiCA crypto-asset service provider (CASP) authorization since May 2025. That entity is authorized to provide crypto custody, exchange, placement, and transfer services.

What is explicitly excluded

Bybit has stated that Bybit.eu serves users across the EEA with Malta excluded. The exchange has noted on its website that services are available only in jurisdictions where applicable MiCA passporting requirements have been met, though it has not specified the precise regulatory reason for the Malta exclusion. Accounting professionals advising clients on EEA reach should note this carve-out when assessing service availability and user onboarding scope.

The Dual-Entity Structure: Why It Is Significant

Two licenses, two regulatory perimeters

Bybit has been explicit that the two entities will maintain distinct regulatory permissions and responsibilities. Bybit EU GmbH handles the crypto layer; Bybit Payments GmbH handles the e-money and payments layer. This is not a novelty in financial services, but it is a relatively new configuration in the crypto exchange context within the EU, and it carries direct consequences for how the combined operation is audited and reported.

From a regulatory standpoint, an EMI operating under the EU's Payment Services Directive framework and a CASP operating under MiCA are subject to different supervisory regimes, different capital adequacy rules, different AML/CFT program requirements, and different reporting obligations. When both entities sit under the same ultimate beneficial ownership and operate on the same customer-facing platform, the boundaries between them require careful management, both operationally and on the balance sheet.

The strategic rationale Bybit has articulated

Bybit has stated that the EMI authorization could help strengthen its relationships with banks, payment providers, and enterprises, and reduce reliance on third-party payment infrastructure. This is a familiar motivation for crypto businesses seeking to internalize payment rails rather than depending on banking partners who may apply heightened due diligence or restrict services. For accounting firms serving similar clients, this strategic shift is worth tracking: it signals a maturation of the exchange's EU compliance posture and a potential reduction in the counterparty risk associated with third-party payment intermediaries.

Accounting Implications for Firms and CFOs

Intercompany transactions and consolidation

Where a crypto exchange operates two regulated subsidiaries in the same jurisdiction, intercompany transactions between the MiCA CASP and the EMI entity will need careful documentation. Under IFRS 10, consolidated financial statements must eliminate intercompany balances and transactions; under IAS 24, related-party disclosures will apply to any flows between Bybit EU GmbH and Bybit Payments GmbH. For accounting firms auditing or preparing accounts for similar dual-entity structures, the key questions are: what services does each entity provide to the other, at what transfer price, and how are settlement flows recorded across the two legal perimeters?

Regulatory capital and safeguarding requirements

An EMI operating under the EU's Payment Services Directive 2 (PSD2) framework is subject to initial capital requirements and ongoing own funds requirements calculated by reference to payment volumes. It is also required to safeguard client funds held as electronic money, either through segregation in a dedicated account with a credit institution or through an insurance or guarantee product. These safeguarding obligations are distinct from the prudential requirements that apply to the MiCA CASP entity. Firms using digital asset accounting software to manage client ledgers for exchange businesses will need to ensure that safeguarded e-money balances are classified and presented correctly, not commingled with proprietary crypto holdings on the balance sheet.

Revenue recognition across the two entities

Payment services revenue and crypto-asset services revenue are economically and contractually different. EMI revenue typically arises from interchange, account fees, and transaction charges; CASP revenue arises from trading spreads, custody fees, and transfer commissions. Under IFRS 15, both revenue streams require identification of the performance obligation and the transaction price, but the timing of recognition and the principal versus agent analysis may differ materially between the two. Firms advising on or auditing the consolidated accounts need clear visibility into which entity is acting as principal for each service type.

AML and KYC Obligations Under the Dual-Entity Model

Two regulatory regimes, one customer base

The EU's Anti-Money Laundering directives apply to both payment institutions and crypto-asset service providers, but the specific guidance, risk factors, and supervisory expectations differ. CASPs are explicitly listed as obliged entities under the EU AML framework, with sector-specific guidance covering the anonymity risks of crypto transactions, travel rule compliance, and blockchain analytics. EMIs are obliged entities under the same framework but with guidance calibrated to traditional payment risks such as card fraud, money mule networks, and cross-border remittance abuse.

When a single customer interacts with both a CASP and an EMI that share a platform, the AML program design must address the risk that the two touchpoints create a combined exposure that neither entity's standalone program fully captures. Accounting firms conducting AML audits or gap analyses for similar structures should check that the client maintains a group-wide AML policy that maps risk across both regulated entities, not just entity-level programs in isolation.

The travel rule dimension

The EU's Transfer of Funds Regulation, which extends travel rule requirements to crypto-asset transfers handled by CASPs, applies to Bybit EU GmbH in its CASP capacity. Payment transfers handled by Bybit Payments GmbH fall under the existing payment-side transfer-of-funds rules. Firms should confirm that their clients operating in similar dual-entity structures have clear internal protocols for routing transfers through the correct entity and applying the correct travel rule regime, since misrouting a crypto transfer through the EMI entity, or vice versa, could create a compliance gap that supervisors would treat seriously.

What Accounting Firms Should Do Now

Engagement scoping and representation letters

If your firm currently serves a client that operates, or is moving toward, a dual-entity structure combining a MiCA CASP and an EMI, your engagement letter and representation letter should explicitly identify which legal entities are in scope. A common risk in multi-entity engagements is that the audit or accounting scope drifts to cover the consolidated group without adequately addressing the distinct regulatory obligations of each entity. This is particularly relevant given that MiCA supervision and PSD2 supervision may sit with different national competent authorities, even within the same member state.

Chart of accounts and crypto bookkeeping software configuration

The dual-entity structure will require a chart of accounts that separates e-money liabilities from crypto custody liabilities, and payment services revenue from crypto services revenue. Firms configuring crypto bookkeeping software or digital asset accounting software for such clients need to ensure that sub-ledgers are set up at the entity level, not just at the group level, so that regulatory capital calculations and safeguarding compliance can be demonstrated to the FMA and to any other competent authority conducting a review.

Monitoring the rollout of payment products

The FMA authorization provides the legal basis for future payment capabilities; Bybit has not confirmed a specific launch timeline for card products, open banking features, or P2P transfer services. Accounting firms and CFOs should track the actual product rollout, since each new payment product category may trigger additional notification requirements to the FMA, additional own funds calculations, and potentially additional safeguarding arrangements. Building a monitoring cadence into the client relationship now is more efficient than reactive adjustments once products go live.

For broader context on how the EU is shaping its supervisory expectations for CASPs and the interplay with other reporting obligations, see our coverage of MiCA CASP supervision and what it means for accounting firms. For a comparison of how other exchanges have navigated MiCA authorization at the national level, the analysis of how Hungary's MiCA licensing precedent developed is also instructive.

Bybit's Austrian EMI License: Dual-Entity EU Structure and What Accounting Firms Must Assess Now

Frequently Asked Questions

What is the difference between Bybit EU GmbH and Bybit Payments GmbH?

Bybit EU GmbH is the MiCA-authorized CASP entity, licensed to provide crypto custody, exchange, placement, and transfer services. Bybit Payments GmbH is the newly licensed EMI entity, authorized to issue electronic money and provide payment services such as P2P transfers, merchant payments, open banking, and card products. The two entities hold separate licenses, have separate regulatory obligations, and maintain distinct permissions under Austrian and EU law.

Which regulator issued the EMI license and what authority does it have?

The license was issued by Austria's Financial Market Authority (FMA). The FMA is Austria's integrated financial regulator and supervises banks, payment institutions, and electronic money institutions under Austrian law implementing EU directives including PSD2. An EMI license issued by the FMA carries EEA passporting rights, allowing Bybit Payments GmbH to offer payment services across EEA member states subject to the passporting notification process.

Why does the dual-entity structure matter for AML compliance?

Each entity is an obliged entity under the EU AML framework, but the specific risk factors and supervisory guidance differ between CASPs and EMIs. When both entities share a customer base and a platform, firms must ensure that the group-level AML policy addresses the combined risk exposure, including the risk that a customer uses the crypto entity and the payment entity in a coordinated way that neither standalone program would fully flag.

How should safeguarded e-money balances be presented on the balance sheet?

Under PSD2 safeguarding requirements, client funds held as electronic money must be segregated and cannot be commingled with the EMI's own funds. On the consolidated balance sheet of a group that also holds crypto assets, it is essential that safeguarded e-money balances are classified separately from crypto custody liabilities and from proprietary crypto holdings. Misclassification could lead to a misleading picture of own funds adequacy for both entities.

What should accounting firms do if a client is building a similar dual-entity structure?

Start with engagement scoping: confirm in writing which entities are in scope for audit, accounts preparation, or advisory work. Then review the chart of accounts to ensure sub-ledgers exist at the entity level. Assess whether the client's AML program covers both the CASP and EMI perimeters. Finally, build a monitoring plan for new payment product launches, since each may trigger additional regulatory notifications or capital calculations that affect the financial statements.

Source: Cointelegraph

EUATGeneralAdoptedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
ESMA MiCA Register Reaches 309 CASPs as BNY Mellon Unit and 14 Others Join in Third Update
AML/KYC & Licensing
FATF's PPP Report: Crypto AML Gaps Firms Must Close Now
AML/KYC & Licensing
ESMA Q&A on CASP Custody: What Accounting Firms and CFOs Must Act On Now
AML/KYC & Licensing
ESMA Launches Supervisory Action on CASP Custody Resilience