Mirela Ciobanu
18 Aug 2026 / 5 Min Read
Daniele Tagliarini explains why passporting alone is not enough for PSPs, EMIs, and CASPs entering Italy, and how a strong local AML and compliance framework can become a competitive advantage.
Italy offers international PSPs, EMIs, and CASPs an attractive combination of digital growth, cash-to-digital demand, extensive distribution infrastructure, and regulated sectors with sophisticated payment needs. Yet passporting is only the first layer of market entry: the local operating model determines whether growth will be compliant, scalable, and credible.
Italy should not be approached as a market that is simply moving from cash to digital. Its real opportunity lies in the coexistence of both.
Consumers and businesses increasingly expect digital wallets, instant payments, ecommerce solutions, and seamless account funding. At the same time, physical touchpoints, cash-based habits, and local distribution networks continue to influence how many services are accessed and funded. Regulated gaming adds another dimension, while MiCAR is pushing crypto businesses towards more structured and supervised operating models.
For international payment firms, this creates room for propositions that connect digital services with local customer journeys. It also means that product design, distribution, AML, and regulatory accountability cannot be developed as separate workstreams.
For an EU payment institution or electronic money institution, passporting can provide access to Italy through cross-border services, a branch, or a notified network of agents or distributors. That is an important legal advantage of the single market.
However, passporting answers only one question: whether the institution may provide its regulated services in Italy. It does not, by itself, determine how the institution should govern local distribution, apply Italian AML requirements, respond to authorities, retain information, supervise customer-facing arrangements, or allocate responsibility between headquarters and local partners.
This distinction is often underestimated. Commercial discussions may advance quickly because the licence is already in place, while the local control model remains incomplete. The result can be delayed launches, repeated partner due diligence, unclear accountability, and costly redesign after contracts have been signed.
A Central Contact Point, or CCP, is a locally established point of reference that connects a foreign institution’s Italian activity with the host country’s AML and supervisory framework. It becomes particularly relevant when the institution relies on agents, distributors, affiliates, ATMs, retail points, or other stable local infrastructure.
Not every cross-border business requires a CCP. The need depends on the legal and operational structure, the nature and scale of the local establishments, the services provided, and the applicable national and European rules. Nevertheless, the assessment should take place before the commercial model becomes difficult to change.
For PSPs and EMIs, the European framework considers indicators such as the number of local establishments, the value of the activity carried out through them, and whether the host authority can obtain complete and timely information. In Italy, where the relevant conditions are met, the CCP becomes a central element of the AML architecture for an institution operating without a full branch but through local establishments.
A Central Contact Point should not be viewed as a mailbox, a name on a form, or a substitute for the institution’s own compliance function. Nor does it transfer responsibility away from the authorised entity.
Properly designed, it creates a local accountability layer between the foreign institution, its Italian operating footprint, and the host-country AML and supervisory framework. Its role can include supporting the implementation of local AML procedures, overseeing compliance by relevant establishments, facilitating information flows, coordinating responses to authority requests, and representing the appointing institution in communications with the competent authority and the Financial Intelligence Unit.
This makes the CCP both a control mechanism and an operating interface. It helps headquarters understand what must happen locally, while giving Italian authorities a clear and accessible local point of responsibility.
For CASPs, MiCAR creates a European authorisation and passporting framework, but it does not eliminate the importance of local AML execution.
EU legislation allows host Member States to require a Central Contact Point where a CASP from another Member State is established locally in a form other than a branch. The European Banking Authority has also submitted final draft technical standards designed to extend the existing CCP framework to CASPs, adapting the criteria to crypto-asset services and to business models that may have a limited traditional physical presence.
The practical message is that crypto firms should not treat MiCAR authorisation as the final step. Where local partners, customer-facing infrastructure, payment rails, cash-to-crypto journeys, or stable Italian arrangements are involved, the operating model should be tested against the host-country AML framework from the outset.
A strong local compliance model does more than reduce regulatory risk.
It can accelerate onboarding by banks, acquirers, gaming operators, distributors, and other commercial partners. It can give the board a clearer view of launch risk and accountability. It can reduce uncertainty during inspections or information requests. Most importantly, it can prevent a business from building growth on an operating model that later proves difficult to scale.
For a new entrant, this can also become a market signal. Italian partners are more likely to commit resources when regulatory duties are clearly allocated, customer journeys have been mapped, and escalation channels are already in place. A well-structured local model reduces the perception that compliance will be addressed only after volumes grow. In negotiations, that credibility can be as important as pricing, product functionality, or integration speed.
This is why compliance in Italy should not be treated only as a cost line. When designed early, it becomes part of the value proposition: evidence that the institution understands the market, has invested in governance, and intends to build a sustainable presence.
Before entering or expanding in Italy, boards and management teams should ask:
Italy remains a compelling market for international payment and crypto firms, precisely because it rewards businesses that can manage complexity well. The decisive question is therefore not only, ‘Can we enter Italy?’ It is, ‘Can we enter with an operating model that regulators, partners, and customers can understand and trust?’
About the author

Daniele Tagliarini is a strategic payments and regulatory advisor with over 25 years of experience across payment services, electronic money, fintech, crypto, and regulated gaming. Through DTC Advisory, he supports international PSPs, EMIs, and CASPs on licensing, Italian, Swiss, and other EU markets entry, distribution models, and regulatory execution. His work includes assessing Central Contact Point requirements and helping firms design and establish effective local AML and supervisory arrangements in Italy and selected European markets. You can connect with Daniele on LinkedIn or email address - daniele@dtcadvisory.it.
The Paypers is a global hub for market insights, real-time news, expert interviews, and in-depth analyses and resources across payments, fintech, and the digital economy. We deliver reports, webinars, and commentary on key topics, including regulation, real-time payments, cross-border payments and ecommerce, digital identity, payment innovation and infrastructure, Open Banking, Embedded Finance, crypto, fraud and financial crime prevention, and more – all developed in collaboration with industry experts and leaders.
Current themes
No part of this site can be reproduced without explicit permission of The Paypers (v2.7).
Privacy Policy / Cookie Statement
Copyright