Client funds safeguarding is the point where regulatory theory meets operational reality for every board running a digital-asset business. When the payment rails freeze, the banking correspondent exits, or a regulator demands evidence that client money is ring-fenced, a weakness in the safeguarding architecture can halt the entire business within days. The analysis below maps the legal obligation, the common structural failures, and the cross-border decisions that matter most to boards making these choices now.
Boards governing crypto-asset service providers (CASPs) and virtual asset service providers (VASPs) face a structural tension: the regimes that require client-funds safeguarding – MiCA at the EU level, the FCA's payment-institution rules in the United Kingdom, the MAS Payment Services Act in Singapore, and activity-based rulebooks under VARA in Dubai – each define the obligation differently, while the banking and e-money institution (EMI) infrastructure that executes safeguarding sits in yet another regulatory layer. Getting all three layers aligned before launch is the practical problem. This analysis addresses it directly, section by section.
What does client-funds safeguarding actually mean for a digital-asset business?
Client-funds safeguarding is the legal obligation to hold money received from clients in a way that keeps it separate from the business's own assets and accessible for return if the business fails or is suspended. The obligation exists in every mature regime: MiCA requires CASPs that hold client funds to maintain segregation and to apply safeguarding methods drawn from the EU Payment Services framework; the FCA's client-money rules impose equivalent expectations on UK-authorised payment institutions; MAS under the Payment Services Act requires major payment institutions handling float to safeguard daily; and the VARA regime in Dubai mandates that client assets – whether fiat or digital – be held in a manner that insulates them from the firm's insolvency estate.
The common thread across all of these is segregation and identifiability. Client money must sit in an account that is legally distinguishable from proprietary funds. It must be reconciled – typically on a daily or end-of-day basis – and the firm must be able to produce that reconciliation on short notice to the regulator. In our practice, the most frequent point of failure is not the intent to segregate but the plumbing: correspondent banking relationships that commingle currencies, EMI sub-accounts that are shared across multiple product lines, or treasury sweeps that temporarily cross the client-money boundary.
For a business holding both fiat and digital assets, the obligation bifurcates. Fiat safeguarding is governed by the payment-institution or EMI licence that the business holds – or by the licensed entity it routes through. Digital-asset safeguarding is governed by the applicable VASP or CASP regime. A board that treats the two as one undifferentiated obligation will, almost certainly, be non-compliant under at least one of them.
Why is the banking layer the weakest link in a crypto firm's safeguarding structure?
The banking layer is the weakest link because no VASP or CASP controls it directly: the firm depends on a licensed deposit-taker or EMI to hold the safeguarded pool, and that counterparty applies its own risk appetite to the client. When that appetite shifts – as it has repeatedly across correspondent banking – the safeguarding structure collapses regardless of how well the internal compliance was maintained. Boards consistently underestimate this counterparty risk at the point of design.
In practice, banks and EMIs close crypto company accounts for three recurring reasons. First, they cannot complete their own AML/CDD obligations to a standard that satisfies their regulator – typically because the VASP does not produce granular transaction-level data in a format the bank can process. Second, the bank's internal risk committee recalibrates its exposure to the digital-asset sector as a whole, triggering a class-level exit rather than a firm-specific one. Third, the crypto firm has not structured the account relationship with the bank's onboarding requirements in mind: the legal entity, the jurisdiction of incorporation, and the product description presented at onboarding do not align with the firm's actual operating footprint.
The cross-border dimension compounds each of these. A firm incorporated in the BVI operating under a Cayman Islands Monetary Authority (CIMA) registration, paying staff in euros, and serving European retail users is presenting a multi-jurisdictional profile to every banking counterparty. Each institution will evaluate the weakest link in that chain. One institution may decline on the BVI domicile alone. Another may require a European-licensed entity as the account holder. A third may accept the structure only if the EMI onboarding is supported by a CASP authorisation from an EU national competent authority under MiCA.
CTA #1 — The analysis above describes the most common structural exposure. Your entity, your user base, and your banking relationships change the analysis materially. Map your options with our team before the next banking review cycle begins: contact OBOLUS at info@oboluslaw.com.
How does MiCA change the EU safeguarding standard for CASPs?
MiCA brings the EU's CASP authorisation regime into direct interaction with payment-institution-level safeguarding obligations for the first time, creating a single rulebook that replaces the patchwork of national VASP registrations that preceded it. Under the MiCA regime, a CASP that holds client funds – whether in fiat or in crypto-assets – must maintain those assets under a safeguarding method that satisfies the requirements set by ESMA and the relevant national competent authority. The passporting mechanism means that a CASP authorised in one EU member state can carry those obligations across the entire EU/EEA perimeter.
For boards, the practical implication is that the choice of home-member state for CASP authorisation is also a choice about which national competent authority will supervise your safeguarding arrangements day to day. Authorities differ in their supervisory intensity, their appetite for novel product types, and their timelines for granting authorisation. A business that optimised for speed by choosing a jurisdiction with a historically lighter-touch VASP regime – Lithuania's Bank of Lithuania, for example – now operates under a MiCA-aligned framework with substantially more granular safeguarding expectations than the prior AML-registration model required.
The ART (asset-referenced token) and EMT (e-money token) categories under MiCA carry additional obligations: reserve composition, custody of reserve assets, and redemption mechanisms that interact directly with the safeguarding architecture. A stablecoin issuer that is also operating a trading venue faces layered obligations – as an ART or EMT issuer and as a CASP – that must be reconciled in the treasury and legal entity design before authorisation is sought.
How does a VASP successfully onboard with an EMI for fiat rails?
A VASP successfully onboards with an e-money institution (EMI) by presenting a structured compliance package that resolves the EMI's principal concern: that accepting the VASP as a client will create regulatory or reputational exposure the EMI cannot manage. The EMI is not simply a bank substitute; it is a licensed payment institution with its own safeguarding and AML obligations, and it will evaluate the VASP's AML/CFT framework, transaction monitoring capability, and jurisdictional licensing footprint before issuing an IBAN or processing fiat flows.
The practical onboarding process, across the EMIs that accept digital-asset clients, involves several identifiable steps. The VASP must produce its own AML/CFT policies and procedures, its Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) compliance evidence, a clear legal-entity structure showing where the regulated activities are licensed, and a product description that maps to the EMI's product risk categorization. Where the VASP holds a recognised CASP or VASP licence – from ESMA-supervised authorities under MiCA, from the FCA, from MAS, or from VARA – the EMI onboarding risk score typically falls, because the regulator has already conducted a fit-and-proper and AML baseline assessment.
Operators we advise routinely underestimate the time the EMI's own compliance committee requires to approve a digital-asset client. This is not a documentation problem; it is a committee-calendar and risk-appetite problem. Building the relationship with the right EMI – one that has already approved similar client profiles – is a pre-condition that must be worked in parallel with the licensing process, not after it.
A further cross-border complication: many EMIs licensed under PSD2 in one EU member state restrict their IBAN issuance to EU-incorporated entities or require that the account holder hold a payment-institution or CASP registration in the same jurisdiction. A BVI or Cayman-incorporated VASP may need a European operating subsidiary or a co-arrangement with a European licensed entity before EMI onboarding becomes possible.
Decision matrix: which safeguarding structure fits which operator profile?
The appropriate safeguarding structure depends on the operator's licence layer, its user base, and the fiat rails it needs – and no single architecture is optimal for every profile. The analysis below maps four common situations to the structure that the relevant regimes and banking market support in practice.
Profile A – EU-licensed CASP with a retail user base. This operator holds or is seeking MiCA CASP authorisation from a national competent authority. The safeguarding obligation falls squarely within the MiCA rulebook. The right structure is a dedicated client-funds account with a licensed credit institution or qualifying money-market fund, fully segregated from proprietary treasury, reconciled daily, and reported to the supervising NCA. The key risk is choosing a home-member state where the NCA's supervisory guidance on segregation methodology is still developing. Timeline to compliant structure: typically several months from authorisation, depending on the banking relationship.
Profile B – Singapore MAS-licensed DPT service provider serving Asian markets. MAS under the Payment Services Act requires daily safeguarding of client float above the applicable threshold for major payment institution licensees. The structural answer is a local safeguarding account with a Singapore-licensed bank, supported by a daily reconciliation policy that satisfies MAS's audit expectations. The cross-border issue for this profile is that many operators also have an EU or UK user base, requiring a parallel safeguarding structure under MiCA or FCA rules for that perimeter.
Profile C – VARA-licensed firm in Dubai serving MENA and global institutional clients. VARA's activity-based licence regime requires safeguarding of client assets – both fiat and digital – in accordance with the applicable VARA rulebooks. Institutional clients typically require a custody arrangement that is legally ring-fenced. The fiat safeguarding vehicle is usually a UAE-licensed bank account, with the asset-custody layer held separately. The risk here is the interaction with non-UAE banking counterparties; correspondent banking for UAE-licensed VASPs can be difficult to arrange without a well-documented compliance package.
Profile D – Early-stage operator with offshore incorporation and no active licence. This is the highest-risk profile for safeguarding failure. Without a licence in a recognised regime, no bank or EMI can satisfy its own AML/CDD obligations simply by reference to a regulator's due diligence. The practical result is that this operator either cannot access institutional banking at all or accesses it via intermediaries whose own compliance posture creates secondary risk. The structural recommendation for this profile is always to resolve the licensing question first; the safeguarding architecture follows from the licence.
Micro-matter: when the fiat rails and the stablecoin freeze at the same time
In a recent matter, a payments company operating under a CASP-equivalent registration experienced simultaneous disruption to both its fiat safeguarding account – following a correspondent bank exit – and its stablecoin settlement layer, when the issuer's compliance team placed a review hold pending a law-enforcement inquiry. The company had structured its safeguarding in a single jurisdiction and had not maintained a secondary banking relationship. We were engaged to advise on the legal options in parallel: coordinating with the issuer to resolve the compliance hold, identifying an alternative fiat safeguarding vehicle in a second jurisdiction, and reviewing the client-money trust documentation to confirm that the segregation could be demonstrated to the regulator during the interruption period. The rails were restored within weeks; the regulator's inquiry did not result in enforcement action because the segregation documentation was clean. The lesson the board took from the matter was structural: a single-rail safeguarding design is a concentration risk, not a compliance solution.
What are the most common structural failures in client-funds safeguarding?
The most common structural failure is the absence of a formal client-money trust or equivalent legal mechanism that survives the insolvency of the operating entity – meaning that if the firm fails, client funds are recoverable as a separate pool rather than distributed pro rata with general creditors. This is not a documentation formality; it is the legal distinction between safeguarding and simple segregation, and regulators across the major hubs now expect evidence of a properly constituted trust or statutory equivalent at authorisation stage.
The second major failure is reconciliation discipline. A daily reconciliation that is run but not reviewed – or reviewed only quarterly by an external auditor – does not satisfy the supervisory expectation. Regulators increasingly expect a named compliance officer to certify the reconciliation, with escalation procedures documented in writing for any shortfall. We have seen firms with structurally sound trust arrangements fail supervisory reviews because the operational reconciliation process was informal.
The third failure is product scope drift. A firm that begins as an exchange and adds a lending product, a staking yield product, or a custody service changes its safeguarding obligation in each case. Lending deployed from a client-funds pool may breach the segregation requirement. Staking rewards that are credited to a pooled account before allocation may create a commingling issue. Each new product should trigger a legal review of whether the safeguarding architecture remains adequate – a review that, in our experience, is frequently deferred until an examiner raises the question.
A fourth, less-discussed failure is the jurisdiction mismatch between the legal entity that holds the safeguarding account and the entity that holds the licence. Where a group operates a licensed entity in one jurisdiction and routes client funds through a treasury entity in another, the question of which regime's safeguarding rules apply – and which regulator can compel return of the funds in a wind-down – can become contested. In a cross-border insolvency, that contest takes time the clients may not have.
CTA #2 — If a prior licence application stalled, a banking account was closed, or your safeguarding structure has not been reviewed since the firm added a new product line, a second read can surface the structural reason and the route forward. Map your options with our disputes and regulatory team: contact OBOLUS at info@oboluslaw.com or message us at t.me/oboluslaw.
How do cross-border operators manage safeguarding across multiple regulatory perimeters?
Cross-border operators manage safeguarding across multiple regulatory perimeters by building a jurisdictional map of their client base, their licensed entities, and their banking relationships, and then assigning each client-funds pool to the safeguarding regime that governs the relevant entity – not the regime that is most convenient. The multi-jurisdiction reality of digital-asset business means that the same pool of client money may be subject to concurrent safeguarding obligations in more than one regime, particularly where the operating entity passports services across borders.
Under MiCA's passporting mechanism, a CASP authorised in one EU member state may serve clients across the EU/EEA. But the safeguarding obligation follows the licence, not the client's location. The firm must maintain a safeguarding structure that satisfies the home-state NCA – and that structure must be capable of ring-fencing the client pool for the benefit of clients across all member states served. Where the firm also has UK users, the FCA's client-money rules may impose a separate and non-equivalent obligation on the UK-facing entity. Running a single pooled account across both perimeters creates regulatory exposure in both.
The Singapore-Hong Kong corridor illustrates a second variant of this problem. A firm licensed by MAS as a major payment institution and also seeking a VATP licence from the SFC in Hong Kong faces two daily safeguarding reconciliation obligations, likely in two different currencies, with two different banking counterparties, and with two regulators that may have different views on whether a shared treasury function is acceptable. In our cross-border practice, we build the entity map and the banking stack in parallel from the first planning session, precisely because the choices made at that stage constrain every subsequent safeguarding design.
One practical point boards frequently miss: the AIFC in Kazakhstan, governed by the AFSA, offers a common-law framework for digital-asset businesses with structural proximity to English trust law. For a multi-hub operator that needs a Central Asian trading presence alongside a European or Gulf licence, the AIFC's safeguarding regime – designed on recognisable common-law principles – can simplify the legal analysis of the client-money trust relative to some civil-law alternatives.
A common assumption: "One offshore licence is enough to cover all our clients"
A single offshore VASP or CASP registration – from the BVI, the Cayman Islands, or a jurisdiction with a light-touch regime – does not satisfy the safeguarding obligation in the jurisdictions where clients are located. The VASP Act in the BVI, or the registration regime under CIMA in the Cayman Islands, creates a compliance baseline for operating within those jurisdictions' regulatory perimeters. It does not create a passport into the EU, the UK, Singapore, or Hong Kong. Serving clients in those jurisdictions without the applicable local licence means operating outside the regulated perimeter for safeguarding purposes – which in turn means that the EMI or bank serving those clients may itself be in breach of its obligations by processing the flows.
The practical consequence of this assumption is that the firm's banking relationships are built on a licence that the banking counterparty's own compliance team rates as insufficient. When that assessment is made – at the annual review rather than at onboarding, because the initial review was superficial – the account is closed. The safeguarding structure built on that banking relationship collapses with it.
Regulators in the leading hubs increasingly expect a demonstrated nexus between the licence, the entity holding the safeguarding account, and the jurisdiction of the clients served. ESMA's supervisory convergence work under MiCA, the FCA's financial-promotion and client-money supervisory posture, and MAS's enhanced due diligence expectations for DPT service providers all point in the same direction: the offshore single-licence model is structurally inadequate for any firm with a material retail or institutional user base in a regulated jurisdiction.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for digital-asset businesses – structuring the fiat rails, EMI relationships and payment-institution licensing for VASPs and CASPs
- Client-funds safeguarding in Luxembourg – the Luxembourg framework for payment institutions, EMIs and MiCA CASPs holding client money
- Airdrop legal structuring in the Cayman Islands – token distribution, CIMA registration and the interaction with Cayman entity design
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily for three reasons. First, the bank cannot complete its own AML and customer due diligence obligations because the VASP does not provide granular transaction-level data in a usable format. Second, the bank's internal risk committee recategorises the digital-asset sector as above its risk appetite, triggering a sector-level exit. Third, the legal entity structure, jurisdiction, and product description presented at onboarding do not match the firm's actual operating footprint, and the discrepancy surfaces at the annual review. Resolving these requires addressing the underlying structural cause, not just the documentation.
How can a VASP onboard with an EMI?
A VASP onboards with an e-money institution by presenting a structured compliance package: AML/CFT policies, Travel Rule compliance evidence, a clean legal-entity map, and a product description that maps to the EMI's risk categories. A recognised VASP or CASP licence from a supervised regulator – under MiCA, the FCA, MAS, or VARA – materially reduces the EMI's compliance risk score. The process typically takes longer than anticipated because the EMI's own risk committee must approve the relationship; firms that begin this process in parallel with the licensing application are better positioned than those that sequence it after authorisation.
What does client-money safeguarding require?
Client-money safeguarding requires, at minimum, three elements across the major regimes: segregation of client funds from the firm's own assets in legally distinct accounts; daily reconciliation between the safeguarding account and client-liability records, certified by a named compliance officer; and a legal mechanism – typically a statutory trust, a contractual trust, or a qualifying money-market fund arrangement – that ensures the client pool survives the firm's insolvency and is returned to clients before general creditors. The precise requirements vary by jurisdiction and licence type; a CASP under MiCA, a major payment institution under MAS, and a VARA-licensed firm each operate under distinct but structurally similar obligations.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and payment firms on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the banking, EMI onboarding and compliance architecture that surrounds them. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – because the safeguarding failure almost always sits at the intersection of those layers. We map the licence stack across operating, custody and payment layers before you commit, so the architecture holds when the regulator or the banking counterparty looks closely. To discuss your safeguarding structure, contact info@oboluslaw.com.
By Glen Sorensen, Disputes & Recovery Analyst – specialist in cross-border asset recovery, client-money disputes and the regulatory frameworks governing fiat and digital-asset safeguarding for licensed payment firms and VASPs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.