Skip to content
Banco de España · Spain

EMI licence in Spain — the Banco de España application file

Fintech Passport
June 21, 2026 · 9-min read
EMI licence in Spain — the Banco de España application file

Spain is one of the few EU markets where the e-money authorisation file is set out letter by letter in a royal decree — which means the checklist is the law, not a supervisory preference. The framework is Ley 21/2011 de dinero electrónico, transposing EMD2, developed by Real Decreto 778/2012 (BOE of 5 May 2012) as amended by Real Decreto 736/2019. Banco de España decides, and it decides within three months — a deadline that runs from a complete file and expires, by statute, in a refusal. This piece walks through what Article 2 of the royal decree actually demands, the procedural traps in Article 1, and what switches on at grant.

1. Who decides, and who else is in the room

Article 1.1 of RD 778/2012 gives the decision to Banco de España — but only previo informe del Servicio Ejecutivo, that is, after a report from SEPBLAC on matters within its competence. This is the detail most applicants underestimate. The AML programme is not a section that a prudential reviewer glances at; it is read by the financial intelligence unit, and its report is a precondition of the decision.

Two further consultations can be triggered by the shareholding. Where control of the applicant — in the sense of Article 42 of the Commercial Code — will be exercised by an e-money institution, credit institution, payment institution, investment firm or insurer authorised in another Member State, or by the persons who control one of those, Banco de España must consult the responsible supervisors before granting. Where control will be exercised from outside the EU, whether or not by a regulated entity, the authority may require the controllers to provide a guarantee covering the whole of the authorised activity.

The authorisation itself is not generic: it specifies the activities the institution may carry out, in line with the programa de actividades submitted. Authorisation is granted only to legal persons established in a Member State.

2. The three-month clock, and how it ends

Article 1.2 is short and consequential. The application must be resolved within three months of its receipt at Banco de España, or of the moment the required documentation is completed. If no express decision is notified within that period, the application is deemed refused by administrative silence — without prejudice to the authority’s duty to issue and notify a decision anyway. A refusal must be reasoned.

There is also a reporting flow the applicant never sees. Under Article 1.3, Banco de España reports quarterly to the Treasury on each file, including the applicant’s identity, the dates of application and decision, the programme of activities — and, where the authority considers it high, the degree of technology-based financial innovation in the proposed business model, with a description. A genuinely novel model is visible at national level from the moment it is filed.

3. The application file, letter by letter

Article 2.1 lists the documents. The lettering matters, because Banco de España reads the file against it.

LetterWhat it requires
a)–b)Programme of activities naming e-money issuance, the payment services sought, ancillary or closely related services and any other Article 8 activity; business plan with budget projections for the first three financial years demonstrating adequate and proportionate systems, resources and procedures
c)Evidence of the initial capital under Article 6 of Ley 21/2011, held at the moment of authorisation
d)The measures safeguarding funds received in exchange for e-money issued, or from payment services, under Article 9 of Ley 21/2011 and Article 16 of the royal decree
e)Corporate governance and internal control mechanisms, including administrative, risk-management and accounting procedures, shown to be proportionate, appropriate, sound and adequate
f)–g)The procedure for supervising, handling and following up security incidents and user complaints about them, including the incident notification mechanism under Article 67 of RDL 19/2018; and the procedure to record, control, trace and restrict access to sensitive payment data
h)Business continuity arrangements, with a clear delimitation of critical operational functions, effective contingency plans and a procedure to test and periodically review them
i)The principles and definitions used to collect statistical data on performance, transactions and fraud
j)A security policy document with a detailed risk assessment, referencing Chapter V of RDL 19/2018 on operational and security risk, and covering software and systems used by the applicant or by firms it outsources to — expressly including the GDPR obligations to carry out impact assessments and appoint a data protection officer (Articles 35 and 37)
k)The internal control and communication procedures to prevent money laundering and terrorist financing
l)Structural organisation, including branches, e-money distribution and redemption structures or agents, outsourcing arrangements, and participation in a national or international payment system
m)Significant shareholders with the size of their effective holding and evidence of suitability. Corporate shareholders other than credit institutions supervised by Banco de España must file three years of annual accounts and management reports, with audit reports where they exist
n)Directors and general managers, with proof of honourability, experience and knowledge, assessed under Articles 29, 30 and 31(1)–(2) of RD 84/2015 — the banking suitability standard
o)–q)Draft by-laws with a negative name-availability certificate from the commercial register (shares must be nominative); registered office and central administration in Spanish territory; and the customer-complaints machinery under Article 69 of RDL 19/2018 including the Reglamento para la defensa del cliente under Orden ECO/734/2004

One definitional point sits inside letter m) and catches group structures: for the purposes of a significant holding, notable influence means the possibility of appointing or removing a member of the institution’s highest governing body. A minority stake with a board-appointment right is a significant holding.

4. Three worked cases

Case A — the applicant controlled by an EU credit institution

Facts. A group whose parent is a bank authorised in another Member State incorporates a Spanish vehicle and files for an EMI licence.

Which rule applies. Article 1.5, first paragraph: Banco de España must consult the parent’s home supervisor before granting.

What the practitioner does. Treats that consultation as a dependency with its own lead time and prepares the parent side for it — a current supervisory standing summary, the group governance documents in a form the home authority will recognise, and a named contact. Groups that discover the consultation at month two lose weeks that the three-month clock does not give back.

Case B — the non-EU controller

Facts. The ultimate controller is an individual resident outside the EU; the Spanish entity is otherwise conventionally structured.

Which rule applies. Article 1.5, second paragraph: a guarantee covering the entire authorised activity may be demanded of those who control the applicant, whether or not they are regulated.

What the practitioner does. Raises it in pre-application rather than waiting to be asked, and models the capital consequence. A guarantee scoped to “the totality of the authorised activities” is sized against the programme of activities, so a broad programme filed for optionality has a cost here that a narrow one does not.

Case C — the file that is submitted “to start the clock”

Facts. An applicant files with the safeguarding model described conceptually and the security policy document still in draft, intending to complete during review.

Which rule applies. Article 1.2 — three months from receipt or from completion of the required documentation — together with the negative-silence rule.

What the practitioner does. Does not file. Letters d) and j) are the two most commonly incomplete blocks and both are evidential rather than descriptive: d) needs the contractual flow of funds into the safeguarding arrangement, and j) needs a risk assessment that reaches outsourced systems and states the GDPR impact-assessment and data-protection-officer position. Filing without them does not start a clock; it starts a requirement.

5. Authorisation is not the last step

Article 1.4 sequences what happens after the decision. Once authorised, and after registration in the Registro Mercantil, the institution must be entered in the Registro Especial de entidades de dinero electrónico del Banco de España — under Article 4.3 of Ley 21/2011 and Article 5 of the royal decree — before beginning its activities. Three registrations, in order, and the commercial one sits in the middle.

6. What switches on at grant

  • FTF — the monthly account-holder feed to SEPBLAC
  • DMO — monthly systematic AML reporting
  • DTE and the balance-of-payments returns to Banco de España
  • CESOP once cross-border payment volumes reach the EU threshold
  • The DORA register of information, which the Article 2.1 j) security file should already anticipate
  • Passport notifications to host Member States, under the PSD2 and EMD2 notification routes

The pattern worth planning for: several of these draw on the same customer and transaction data the application file describes. An applicant that builds the reporting data model while drafting letters i) and l) does the work once.

7. FAQ

How long does a Spanish EMI authorisation take?

Article 1.2 of RD 778/2012 requires a decision within three months of receipt or of the completion of the required documentation. Because information requests reset practical completeness, end-to-end timelines are usually longer than three months.

What happens if Banco de España does not decide in time?

The application is deemed refused by administrative silence, without prejudice to the authority’s duty to issue and notify an express, reasoned decision.

Does SEPBLAC see the application?

Yes. Article 1.1 requires a report from the Servicio Ejecutivo on matters within its competence before Banco de España authorises.

Must the entity be Spanish?

Authorisation is granted only to legal persons established in a Member State, and Article 2.1 p) requires the registered office and central administration — and the effective conduct of the payment-services part of the business — to be in Spanish territory. Shares must be nominative.

What suitability standard applies to directors?

Article 2.1 n) applies the criteria and control procedures in Articles 29, 30 and 31(1)–(2) of RD 84/2015, the regulation developing the banking law — the same honourability, knowledge and experience test used for credit institutions.

8. What to do, today

  • Build the file against the letters of Article 2.1 rather than a generic EU template, and name each annex after its letter.
  • Treat letters d) and j) as evidence exercises: contractual safeguarding flow, and a risk assessment that reaches outsourced systems and states the GDPR impact-assessment and DPO position.
  • Check the shareholding for a board-appointment right — that alone makes a holding significant, and pulls in three years of accounts for corporate holders.
  • If control sits outside the EU, model the Article 1.5 guarantee before fixing the scope of the programme of activities.
  • Sequence the three registrations — authorisation, Registro Mercantil, Registro Especial — and remember that activity may not start before the third.
  • Draft the Reglamento para la defensa del cliente early; it is a filed document under letter q), not a post-grant policy.

Related: PI licence in Spain · What is SEPBLAC? · The Spanish reporting calendar · Safeguarding compared across the EU · Own funds and initial capital · Qualifying holdings and change of control · Direct access to Spanish payment systems · Where to base your EMI

Related reads.