You have been assuming an open banking license sits somewhere above an EMI on the cost ladder — more regulated, more capital, more scrutiny, because that is how every other high-risk licensing conversation you have had has gone. It is worth checking that assumption before you scope a budget around it, because on capital requirements specifically, it runs the other way.
An AISP or PISP license costs a fraction of an EMI's minimum capital. That is a genuine, commonly misunderstood fact, and it changes how a payments business should sequence its own licensing strategy — but it is not the whole story, because the license that is cheaper to obtain is not automatically cheaper to run.
This guide walks through what an AISP and PISP license actually require, why the capital bar is lower than an EMI's while the ongoing technical burden is often heavier, and why Lithuania has become a commonly used fast-track jurisdiction for exactly this authorization. For the underlying capability each license unlocks, see our guide to open banking for high-risk businesses.
Direct Answer
An AISP license needs no minimum capital, only professional indemnity insurance. A PISP needs 50,000 EUR, and a full Payment Institution needs 125,000 EUR — all well below an EMI's 350,000 EUR. The tradeoff is technical, not financial: PI and PISP authorization carries a heavier ongoing compliance and API-integration burden than an EMI's.
Step 1: Decide Which License You Actually Need
An AISP license covers read-only account access alone: no payment initiation, no fund custody. A PISP license adds payment initiation on top. A full Payment Institution (PI) license extends further, into money remittance, acquiring, and in some cases card issuing. None of these can issue electronic money — that scope belongs to an EMI license alone.
Getting this scoping decision right first matters more than it looks, because each category has a different capital floor, a different application form, and a different ongoing supervisory relationship with your regulator. If the product you are licensing is a pay-by-bank checkout option, our comparison of pay by bank vs. cards is worth reading before you finalize scope, since the fee and dispute tradeoffs it covers shape what a PISP license actually needs to support.
What to Consider:
- Match the license to the actual service: do not apply for full PI authorization if your product only ever reads account data — AISP alone is faster and cheaper.
- Combined applications are common: many applicants seek AISP and PISP authorization together under one PI license rather than as two separate registrations.
- E-money issuance requires a separate license: none of AISP, PISP, or PI authorization allows you to issue e-money — that is EMI territory only.
- Scope creep costs time later: expanding your authorized services after licensing means a variation application, not a quick form update.
Example
A fintech planning both account-verification tooling and a pay-by-bank checkout product applied for combined AISP and PISP authorization under a single PI license from the outset, rather than launching with AISP-only and filing a variation six months later once the payment-initiation product was ready.
Final Takeaway: Scope your application to the services you will actually launch within the next 12-18 months — applying for more than you need adds cost and review time for capabilities you will not use yet.
Step 2: Understand the Real Capital Requirements
This is where the common assumption breaks down. Under PSD2, an AISP needs no minimum initial capital at all — only professional indemnity insurance covering its liability. A PISP needs 50,000 EUR. A full PI authorization, covering money remittance and acquiring, needs 125,000 EUR. An EMI license, under the separate Electronic Money Directive, needs 350,000 EUR — roughly 3 to 17 times the PI-family figures depending on exactly which services you scope in.
That is a real, substantial difference, and it is the opposite of what most operators assume walking in. The reason it does not translate into an easier license overall is capital requirement is only one axis of licensing cost — the next section covers where PI and PISP authorization actually gets harder than an EMI's.
What to Consider:
- AISP capital floor: none — professional indemnity insurance is the only financial-strength requirement.
- PISP capital floor: 50,000 EUR, a fraction of what most applicants assume before checking.
- Full PI capital floor: 125,000 EUR for the broader service scope, still well under an EMI.
- Do not confuse capital with total setup cost: legal, technical, and compliance-build spend can exceed the capital requirement itself, especially for PI and PISP.
Example
A payments startup budgeted 350,000 EUR in reserve capital assuming it needed an EMI-equivalent license for its planned pay-by-bank product. Once it confirmed PISP authorization was sufficient for its actual service scope, the capital requirement dropped to 50,000 EUR — freeing the difference for the technical build the license category actually demands.
Final Takeaway: Confirm the specific capital floor for your exact service scope before budgeting — do not assume open banking licensing costs scale the same way EMI licensing does.
| License category | Minimum initial capital | Core capability |
|---|---|---|
| AISP | None — professional indemnity insurance only | Read account data with consent |
| PISP | 50,000 EUR | Initiate payments from an account with consent |
| Full Payment Institution (PI) | 125,000 EUR | Remittance, acquiring, in some cases card issuing |
| EMI | 350,000 EUR | Issue electronic money, broadest scope |
Step 3: Choose Your Jurisdiction
Lithuania has become a commonly used fast-track hub for AISP, PISP, and PI authorization inside the EU. The Bank of Lithuania runs an established, well-documented application process, and licensing activity has stayed consistent through 2025 and into 2026 — including a payment institution license issued to AB Lietuvos paštas in April 2026, one of a steady stream of authorizations the regulator has processed.
A license granted in Lithuania, like any EU/EEA member state authorization, passports across the bloc — the value of choosing a specific jurisdiction lies in the regulator's responsiveness and track record with applicants like you, not in the geographic reach of the resulting license.
What to Consider:
- Passporting is EU-wide regardless of jurisdiction: the license itself carries the same cross-border rights no matter which member state issues it.
- Regulator track record matters more than location: Lithuania's appeal is a documented, ongoing pattern of PI and EMI authorizations, not a legal advantage over other member states.
- Confirm the regulator's current review capacity: application queues shift with the volume of applicants a given national regulator is processing at any point.
- Local counsel still matters: a fast-track reputation does not remove the need for jurisdiction-specific legal and compliance guidance.
Example
A fintech comparing three EU jurisdictions for PISP authorization chose Lithuania after finding a consistent recent record of payment institution licenses granted by the Bank of Lithuania, rather than choosing based on where its founders happened to be incorporated.
Final Takeaway: Choose a jurisdiction on the regulator's documented track record with your license category, not on assumptions about which EU country is generically "easiest."
Step 4: Build the Technical and Compliance Infrastructure the License Actually Demands
This is where PI and PISP authorization gets operationally heavier than an EMI's, and it is not a capital-cost burden — it is a technical and ongoing-compliance one. Strong Customer Authentication (SCA), governed by the EBA's regulatory technical standards, has to be built and maintained. Dedicated API integration and testing with every partner bank is an ongoing engineering commitment, not a one-time build. eIDAS QWAC and QSEAL certificates are required for secure communication with account-servicing banks, and incident reporting obligations run continuously once you are authorized.
Reality Check
A lower capital requirement is not the same thing as a cheaper business to run. AISP and PISP authorization needs a fraction of an EMI's minimum capital, but the ongoing technical burden — Strong Customer Authentication, dedicated API integration and testing with every partner bank, eIDAS certificates, continuous incident reporting — often costs more in sustained engineering and compliance spend than an EMI's extra capital would have required. Choosing the license with the lowest capital bar is not the same decision as choosing the cheapest path to actually operate.
What to Consider:
- Budget for engineering, not just capital: API integration with every partner bank is an ongoing line item, not a one-time setup cost.
- eIDAS certificates need renewal and management: QWAC and QSEAL certificates are a recurring operational requirement, not a one-time certificate you file away.
- Incident reporting is continuous: build the reporting process before launch, not after your first qualifying incident forces you to build it under pressure.
- Appoint accountability early: a designated MLRO and a compliance lead who understands the specific technical standards should be in place before you submit, not hired after approval.
Example
A newly authorized PISP budgeted for the 50,000 EUR capital requirement but underestimated the ongoing cost of API testing cycles with each new partner bank it wanted to connect to. By its second year of operation, cumulative integration and certificate-management spend had exceeded the capital difference it had saved by choosing PISP over EMI authorization in the first place.
Final Takeaway: Budget the ongoing technical and compliance cost of PI or PISP authorization as a real operating expense, separate from and potentially larger than the capital requirement itself.
Step 5: Prepare and Submit Your Application
Once the license category, jurisdiction, and technical build plan are settled, the application itself follows a fairly standard PI-family pattern: corporate structure and UBO documentation, a detailed business plan, safeguarding arrangements for any client funds you will hold, governance and fit-and-proper documentation for management, and evidence of the technical infrastructure from Step 4.
Timelines commonly cited for PI authorization run 9 to 18 months overall, with the statutory review period itself often closer to 3 months once a complete file is submitted — the gap between those two figures is almost always pre-submission preparation, not regulator delay.
What to Consider:
- Arrive with a complete file: the 3-month statutory review clock only starts once the regulator considers the application complete, not on the day you submit a partial one.
- Treat 9-18 months as the realistic total: budget your launch timeline around the full range, not the shorter statutory review figure alone.
- Governance documentation is not a formality: fit-and-proper assessments of management are a substantive part of the review, not a checkbox.
- Sector-specific applicants face more questions: a business model tied to a high-risk vertical should expect deeper source-of-funds and business-model scrutiny than a generic fintech application.
Example
An applicant that assembled its full documentation package — UBO structure, business plan, safeguarding arrangement, and technical evidence — before first contact with the regulator cleared its statutory review in roughly 3 months. A comparable applicant that submitted an incomplete file spent 5 additional months in a back-and-forth clarification cycle before the statutory clock even started.
Final Takeaway: Assemble every document Step 5 requires before your first submission — an incomplete file costs months, not days, because the statutory review clock does not start until the file is complete.
| Phase | Typical duration | What determines the length |
|---|---|---|
| Pre-submission preparation | 6-15 months | Documentation completeness, technical build readiness |
| Statutory regulatory review | ~3 months (once file is complete) | Regulator queue and file quality |
| Total realistic timeline | 9-18 months | Sourced to licensing-industry aggregates, not independently audited |
Step 6: Plan for Ongoing Supervision After Authorization
Authorization is the start of a supervisory relationship, not the end of one. AISP and PISP license holders remain subject to continuous oversight: incident reporting, periodic prudential and compliance returns, and — for PISPs specifically — ongoing scrutiny of the safeguarding arrangement protecting any funds in transit.
The businesses that stay licensed treat this as a recurring operating function with its own calendar from day one, the same discipline that separates a durable EMI or payment agent relationship from one that collapses at its first supervisory review. A licensed PISP planning to serve iGaming merchants specifically should also read our guide on open banking payments for iGaming — vertical-specific onboarding friction is a business decision the license itself does not resolve.
What to Consider:
- Build a compliance calendar before launch: reporting deadlines do not pause while you get operationally settled.
- Budget ongoing technical maintenance: SCA, API integrations, and certificate renewals are recurring costs, not launch-year expenses.
- Expect periodic reauthorization checks: regulators revisit fit-and-proper and safeguarding arrangements well after initial licensing.
- Treat compliance as infrastructure: the same principle that applies to any EMI or payment agent relationship applies here — ongoing, not one-time.
Example
A licensed PISP built its first-year compliance calendar — quarterly incident-reporting reviews, an annual SCA infrastructure audit, and a certificate-renewal schedule — three months before going live, and cleared its first supervisory review with no material findings.
Final Takeaway: Build your ongoing compliance and technical-maintenance calendar before your license is even granted — the supervisory relationship starts the day you are authorized, not once you feel settled.
Getting the AISP/PISP Licensing Decision Right
The insight worth sitting with is the one that reverses the usual assumption: AISP and PISP licensing costs a fraction of an EMI's in minimum capital, and that is not a marketing simplification — it is a real, verifiable feature of the regulatory framework.
What does not reverse is the total cost of operating the license. Strong Customer Authentication, per-bank API integration, eIDAS certificate management, and continuous incident reporting make PI and PISP authorization a genuinely technical, engineering-heavy undertaking that a lower capital floor does not offset.
Scope the license to the service you will actually launch, choose a jurisdiction like Lithuania on its documented track record rather than reputation alone, budget the technical build as a real and possibly larger cost than the capital requirement, and build your compliance calendar before you are authorized rather than after.
How BankMyCapital Helps
Getting AISP or PISP authorization right means scoping the license to your real service plan, matching capital and technical investment to what the regulator will actually review, and sequencing jurisdiction choice around documented regulatory track record rather than reputation. BankMyCapital structures that sequencing across licensing and the payment infrastructure it supports.
See our payment processing services for how licensing decisions connect to the payment rails your business will actually run on.
Frequently Asked Questions
How much capital do I need for an AISP or PISP license?
An AISP needs no minimum capital, only professional indemnity insurance. A PISP needs 50,000 EUR. A full Payment Institution license needs 125,000 EUR. All three sit well below an EMI's 350,000 EUR requirement.
Is a PISP license cheaper to run than an EMI license overall?
Not necessarily. The capital requirement is lower, but PISP authorization carries a heavier ongoing technical burden — Strong Customer Authentication, per-bank API integration and testing, eIDAS certificate management, and continuous incident reporting — that can exceed the capital saving over time.
Why is Lithuania a common choice for AISP/PISP licensing?
The Bank of Lithuania has a well-documented, consistent record of authorizing payment institutions, including recent licenses granted through 2025 and 2026. The license itself passports EU-wide regardless of jurisdiction — the appeal is the regulator's track record and responsiveness, not a legal advantage unique to Lithuania.
How long does AISP or PISP authorization actually take?
Commonly cited timelines run 9 to 18 months overall, though the statutory review period itself is often closer to 3 months once a complete application file is submitted. Most of the gap between those figures is pre-submission preparation time, not regulator delay.
What does BankMyCapital charge to help structure an AISP/PISP licensing project?
Engagements are scoped individually because jurisdiction, service scope, and technical readiness all change the workload, but structured licensing support starts from a fixed floor rather than a percentage of turnover. Ask for a scoped quote once you can describe your target service scope and jurisdiction preference.