EST · MMXXVI
Home/Insights/Disputes/De-risking and account closure defence: A Cross-jurisdiction Comparison
Banking, Payments & EMI Onboarding

De-risking and account closure defence: A Cross-jurisdiction Comparison

De-risking and account closure defence: A Cross-jurisdiction Comparison. Cross-border digital-asset legal counsel for business – licensing, disputes and structu

Banks and electronic money institutions (EMIs – regulated payment firms that hold client funds and execute transfers) have spent the past several years quietly exiting the digital-asset sector. For an exchange, custodian or token issuer, the consequences are immediate: frozen rails, stranded client balances and a compliance posture that looks broken to the next potential banking partner. The question is not merely why de-risking happens – it is what a business can do about it, jurisdiction by jurisdiction, before the notice letter arrives.

De-risking – the practice by which a bank or EMI terminates or refuses a business relationship on the basis of perceived regulatory risk rather than individualized customer assessment – affects virtually every VASP (virtual asset service provider) operating at scale. The legal response available to a VASP depends on where the account is held, what licence the VASP carries, and whether the relevant jurisdiction imposes an obligation on payment firms to provide services on objectively justified terms. This comparison maps those variables across the leading hubs where digital-asset businesses bank and operate.

The sections below move from the structural causes of de-risking to the jurisdiction-by-jurisdiction legal levers, the decision matrix a VASP should run before committing to a banking structure, and the recovery path when an account is already under notice. As regulatory regimes converge on the MiCA model and VASP supervision tightens globally, the gap between a well-structured banking stack and an ad-hoc approach is widening.

Why de-risking targets digital-asset businesses

De-risking is a rational, if blunt, response to asymmetric compliance cost. Banks and EMIs face examination risk, anti-money laundering enforcement and correspondent-banking pressure when they hold accounts for VASPs – and the revenue rarely justifies the overhead of individualized due diligence. The result is categorical exit: entire sectors removed from the book rather than assessed client by client.

For a digital-asset business, the immediate trigger is almost always one of three things. First, the VASP's own jurisdiction of incorporation carries a poor FATF (Financial Action Task Force) rating or appears on a grey or black list. Second, the VASP's licence is ambiguous – it might cover custody but not exchange, or it might be a legacy registration that has not yet transitioned to the current regime. Third, the VASP's transaction profile includes high-velocity transfers, frequent large round-number withdrawals or counterparty exposure to addresses flagged in blockchain forensic databases.

None of those factors necessarily makes the business a bad actor. But a bank's compliance team works from policies, not individual assessments. The FATF Recommendations, and in particular Recommendation 15 on virtual assets, have reshaped what correspondent banks demand from institutions that hold VASP accounts. That pressure cascades down to the VASP's own bank. Understanding this cascade is the first step toward defending against it.

In our cross-border practice, we see a fourth factor that clients frequently underestimate: the travel rule. The Travel Rule (the obligation to pass originator and beneficiary identification data alongside a virtual-asset transfer) creates an audit trail that a bank can examine on demand. A VASP that cannot demonstrate a compliant Travel Rule implementation gives its bank an easy reason to exit.

To discuss a current de-risking notice or a banking structure that is under pressure, contact OBOLUS at Map your options. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis.

Legal protection against de-risking exists in most major jurisdictions, but the strength of that protection varies enormously by regime. The key variable is whether the jurisdiction imposes a duty to provide payment services on objectively justified terms – and whether a VASP has standing to enforce that duty.

In the European Union, under MiCA and the supporting Payment Services Directive regime, a payment institution or EMI that denies or terminates access to payment services must give reasons in writing, and those reasons must be objectively justified. A VASP holding a CASP (Crypto-Asset Service Provider) authorisation under MiCA is, in principle, a regulated entity entitled to access payment infrastructure on non-discriminatory terms. The European Banking Authority has addressed access-to-account obligations in published guidance. The practical enforceability of that guidance varies by member state, but it creates a formal compliance lever that a well-advised VASP can pull.

In the United Kingdom, the FCA's approach to the Payment Accounts Regulations creates a comparable structure for basic accounts, though the protections for business accounts held by VASPs are less developed. The FCA has acknowledged de-risking as a systemic concern. A VASP that is FCA-registered under the Money Laundering Regulations occupies a stronger position than an unregistered entity, but registration alone does not guarantee a bank will maintain the relationship.

In Singapore, the MAS Payment Services Act licensing regime creates a regulated VASP category. A Digital Payment Token (DPT) licensee under the MAS framework carries a status that most major Singapore banks recognize. In our experience, a licensed DPT service provider has a materially stronger negotiating position with a Singapore bank than an unlicensed foreign entity – though no statutory right to an account exists in absolute terms.

In Dubai, the VARA (Virtual Assets Regulatory Authority) licensing regime is still relatively young, but VARA-licensed entities operate in a jurisdiction where the regulatory posture toward digital assets is explicitly supportive. Banking access for VARA-licensed businesses has improved as local and regional banks become more familiar with the regime's requirements.

How does EMI onboarding change the picture for crypto businesses?

EMI onboarding – the process by which a VASP establishes a payment account with a regulated electronic money institution rather than a full commercial bank – is often the practical alternative when banks decline to engage. EMIs are typically faster to onboard, more familiar with digital-asset transaction patterns, and more willing to price risk explicitly rather than exit categorically.

The trade-off is exposure concentration. A VASP that processes client funds through a single EMI has no redundancy. EMIs themselves face de-risking: their own banking partners (the so-called "bank behind the EMI") may exit the relationship if the EMI's VASP client base grows too large or too concentrated. This creates a second-order de-risking risk that a structural analysis must address.

The relevant legal question is whether the EMI operates under a licence that covers the VASP's transaction types and jurisdictions. Under the MiCA regime and the EU Payment Services framework, an EMI passporting from one member state may serve clients across the EU/EEA – but that passport does not solve the onboarding problem if the EMI's risk appetite excludes the VASP's business model. In Lithuania, which has historically been a fast-entry EU VASP jurisdiction under the Bank of Lithuania's supervision, the transition to MiCA's CASP authorisation is reshaping which EMIs will onboard which VASPs.

In Malta, where the MFSA oversees the transitioning VFA framework, EMI relationships have historically been structured through a combination of local and European passporting institutions. The transition to MiCA creates both risk (legacy registrations lapsing) and opportunity (a clean CASP authorisation that a mainstream EMI will recognize).

Operators we advise routinely underestimate how much the legal form of the VASP entity – not just the licence it holds – affects EMI onboarding. A Malta-incorporated CASP applying to a Lithuanian EMI faces different due diligence expectations than a Singapore DPT licensee applying to a Hong Kong bank. Both are regulated. Both may still be declined. The distinction lies in the specific compliance matrix the EMI's AML team is running.

How does de-risking defence compare across the leading hubs?

Across the major hubs, the legal defence available to a de-risked VASP follows three broad patterns: statutory access rights, regulatory soft-pressure, and contractual challenge.

European Union (MiCA/ESMA). The strongest statutory framework. A CASP authorisation creates a regulated status that, in principle, triggers non-discriminatory access obligations under EU payment law. The leverage is real but slow: an enforcement complaint to a national competent authority takes time, and a bank facing examination pressure from its own regulator may not be moved by a formal complaint. The better tactic is often pre-emptive: establishing the CASP's AML and Travel Rule compliance posture in writing before the bank's annual review cycle, rather than after the termination notice.

United Kingdom (FCA). The FCA MLR registration creates a public compliance signal, but the statutory access rights for business accounts are weaker than in the EU. The stronger lever in the UK is contractual: banks operating under standard terms may give inadequate notice of closure, triggering a claim for damages. We have seen cases where the notice period under a business account contract was insufficient on its face, giving the VASP grounds to challenge the timeline and negotiate a structured exit – buying time to move fiat rails rather than losing them overnight.

Singapore (MAS/PSA). The MAS Payment Services Act creates a well-recognized licence status. Singapore banks are sophisticated in their VASP due diligence. The practical defence is proactive compliance disclosure: a VASP that delivers a structured AML/KYC package, a Travel Rule compliance attestation and a clear business model description to its banking relationship manager before the bank's risk review substantially reduces the de-risking probability. The MAS has been explicit in its expectation that banks conduct individualized assessments rather than categorical exits.

UAE – Dubai (VARA). The VARA licensing regime creates a strong regulatory endorsement, and the local banking environment has become more receptive to digital-asset businesses than was the case in earlier years. The challenge is that banking access in Dubai for VASPs is still concentrated among a small number of institutions. A VARA-licensed exchange with strong AML governance is well positioned but should structure its fiat rails across at least two institutions to avoid single-point failure.

Hong Kong (SFC). The SFC's VASP licensing regime for virtual-asset trading platforms creates a formal recognition that major Hong Kong banks are beginning to factor into their onboarding decisions. The regime is still maturing, and banking relationships for VATPs remain difficult to establish. Allied counsel in the relevant jurisdiction report that the practical path involves direct engagement with the SFC's guidance on the bank-VASP relationship – a process that takes months, not weeks.

Switzerland (FINMA). Switzerland's FINMA framework, including the possible fintech licence and SRO affiliation routes, creates a range of regulated statuses. Swiss banking access for VASPs has historically been among the most challenging globally, despite Switzerland's reputation as a crypto-friendly jurisdiction. FINMA's token taxonomy – payment, utility and asset tokens – is well developed, but the gap between a clean FINMA classification and a confirmed banking relationship remains significant. Several Swiss cantonal banks have developed VASP-specific onboarding programmes, but capacity is limited.

A micro-matter from our practice illustrates the cross-border dimension. In a recent matter, a payments business operating under an EU CASP authorisation received a 60-day account closure notice from its primary EMI. The stated reason was "elevated risk profile" – a category exit, not a specific AML finding. We mapped the entity's Travel Rule compliance documentation, prepared a formal objection under the applicable EU payment services framework, and simultaneously initiated the onboarding process with two alternative EMIs in a second EU member state. The bank withdrew the notice before the 60-day period expired. The VASP retained its rails and added a second EMI relationship as structural redundancy – the outcome it needed rather than a legal victory in isolation.

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Contact OBOLUS for a scoped assessment: Map your options.

Which banking structure should a VASP choose?

The right banking structure for a VASP depends on its licence profile, its user geography, its transaction volume and its risk tolerance for rail disruption. No single structure is universally optimal. The following matrix describes four common profiles and the structural response each calls for.

Profile A: EU-licensed CASP (MiCA), serving EU/EEA retail and institutional clients. The primary banking layer should be at least two EMIs operating under EU passports, in different member states. The VASP should maintain formal AML and Travel Rule documentation packages ready for annual review by each institution. If one EMI exits, the second carries operations while a replacement is onboarded. The CASP authorisation is the anchor; the Travel Rule compliance programme is the day-to-day defence. Timeline to establish a second EMI relationship: typically several weeks to a few months, depending on the institution.

Profile B: Singapore DPT licensee, serving Asia-Pacific clients. Banking access is most sustainable through a combination of a Singapore-regulated bank (familiar with MAS PSA requirements) and an offshore EMI for settlement functions. The MAS expects licensees to maintain adequate financial resources; the banking structure must support that expectation. A Singapore DPT licensee that cannot demonstrate a stable banking relationship during its licence renewal process faces a materially higher renewal risk. Timeline for banking establishment alongside a new DPT licence: concurrent, not sequential.

Profile C: VARA-licensed exchange in Dubai, serving MENA and international clients. The primary risk is concentration in a small number of UAE-headquartered banking institutions. A VARA-licensed exchange should actively pursue a secondary banking relationship outside the UAE – most commonly in a European jurisdiction or Singapore – to provide a fiat buffer if the primary UAE relationship comes under pressure. VARA's own rulebooks on financial resource requirements will inform the minimum banking structure needed.

Profile D: Unlicensed or registration-only entity (e.g., legacy UK MLR registration), serving mixed global clients. This profile carries the highest de-risking risk. The legal protections available on account closure are weakest where the entity's regulatory status is ambiguous or transitional. The structural prescription is to prioritize the licensing decision above the banking decision. Operating on an MLR registration alone, without a clear path to a fuller authorization, makes every banking relationship conditional and fragile. The cost of a licence application is almost always less than the cost of a banking crisis.

How does the Travel Rule affect banking access for VASPs?

The Travel Rule is a direct factor in whether a VASP retains its banking relationships – and many operators underestimate how visible their Travel Rule posture is to their bank's compliance team. A bank that holds a VASP account is, in effect, assessing whether the VASP's own AML infrastructure is robust enough to prevent the bank from becoming a vehicle for layering or integration of illicit funds.

The FATF Travel Rule, incorporated into national law across the MiCA regime, the MAS Payment Services Act, and the VARA rulebooks, requires that VASPs pass originator and beneficiary identification data with virtual-asset transfers above the applicable threshold. Where a VASP cannot demonstrate a compliant Travel Rule solution – either a recognized travel-rule protocol or a manual compliance process with documented counterparty verification – a bank examining its relationship faces an obvious gap.

The Travel Rule interacts with de-risking in a specific way. Banks do not assess Travel Rule compliance directly; they assess whether the VASP has a credible, auditable process. A VASP that can produce a dated Travel Rule compliance assessment, an enumeration of the protocols it uses, and evidence of counterparty VASP screening has materially reduced the bank's compliance concern. This is a legal and documentation exercise as much as a technical one.

In our cross-border practice, we regularly advise VASPs on structuring their Travel Rule documentation package as a banking-retention tool. The package typically includes the legal basis for the VASP's compliance approach in each operating jurisdiction, the technical solution in use, and a summary of how unhosted wallet transactions are handled. Banks that have received this package have, in a number of instances, reversed a de-risking decision that was initially categorical.

What does client-money safeguarding require across jurisdictions?

Client-money safeguarding – the obligation to hold client funds separate from the VASP's own assets, typically in a designated account at a credit institution or through an insurance or guarantee arrangement – is a licensed obligation in most major regimes and a de-risking factor in its own right. A VASP that cannot demonstrate proper safeguarding of client funds gives a bank a compliance concern that goes beyond AML.

Under the EU MiCA regime, CASPs that hold client funds are subject to explicit safeguarding requirements. The applicable provisions require segregation of client assets and impose duties that mirror, in many respects, the safeguarding rules applicable to EMIs under the payment services framework. A CASP that holds client e-money balances through an EMI relationship must ensure that the EMI's own safeguarding arrangements are compliant – meaning the VASP's banking due diligence runs in both directions.

In Singapore, the MAS Payment Services Act imposes safeguarding requirements on DPT service providers above specified thresholds. The specifics of those thresholds and the permissible safeguarding methods are set out in the applicable MAS regulations and notices, which a VASP must review against its current business model and balance sheet. Operators we advise frequently find that their safeguarding structure was designed for a smaller balance than they currently hold, creating a silent compliance gap.

In Guernsey, a jurisdiction with a well-developed client-funds safeguarding regime, the protection of client money is a foundational pillar of the financial services framework. Guernsey's approach to safeguarding is directly relevant to crypto custodians and fund structures that use the jurisdiction as a holding layer. The legal structure required there differs in important respects from MiCA's approach, and a cross-border operator must account for both.

The common thread across jurisdictions is that safeguarding compliance is not a one-time exercise. It requires periodic review as the VASP's balance sheet grows, as new asset classes are added, and as the regulatory expectations in each operating jurisdiction evolve. A bank conducting an annual review of a VASP relationship will examine the safeguarding structure as part of that review. A gap found during a bank review is a de-risking trigger.

What are the most common structural mistakes that lead to account closure?

The most common mistake is sequencing: building the product, acquiring clients, and then attempting to establish banking. By the time a VASP reaches the banking conversation with a meaningful transaction volume, its risk profile is visible and its negotiating position is weak. Banking relationships should be established concurrently with or before the first client transaction.

A second persistent mistake is entity proliferation without a coherent legal map. A VASP group with a holding company in the BVI, an operating entity in Lithuania, an exchange in Dubai and a custody entity in the Cayman Islands may find that each banking relationship is stressed by the group's overall structure. A bank examining one entity in the group will conduct enhanced due diligence on the group as a whole. If the group structure is not documented – with clear explanations of why each entity exists, what it does and how funds flow between them – the bank's compliance team will fill the gaps with assumptions. Those assumptions are rarely favourable.

Third: treating AML compliance as a back-office function rather than a banking-relationship asset. The compliance programme that satisfies a regulator may not be the document a bank's relationship manager needs. VASPs that translate their regulatory AML documentation into a banking-facing disclosure package – a concise summary of the risk framework, the monitoring tools in use, the Travel Rule solution and the governance structure – consistently report better banking retention outcomes than those that produce compliance documentation only on demand.

A common assumption among operators new to the digital-asset space is that a single offshore licence is sufficient to serve clients globally and maintain banking relationships across multiple jurisdictions. This is incorrect. A BVI VASP Act registration, for example, creates a local compliance standing but does not, by itself, satisfy the regulatory expectations of a Singapore or European bank onboarding the entity. Each banking jurisdiction applies its own due diligence standard. A licence in one jurisdiction is evidence of compliance there; it is not a universal passport for banking access elsewhere.

When should a VASP engage legal counsel on de-risking?

Engaging counsel before a de-risking event – rather than after – is the single highest-return step a VASP can take. A legal and structural review conducted before a bank's annual relationship review gives counsel time to identify and close compliance gaps, prepare the banking-facing disclosure package, and, if necessary, initiate a parallel onboarding process with alternative institutions. After a closure notice has been issued, the window is shorter, the leverage is weaker, and the options cost more.

The trigger for engaging counsel should be any of the following: a request by the bank for enhanced due diligence documentation; a change in the VASP's own licence status (transition, renewal, or new activity); a significant change in transaction volume or asset mix; an expansion into a new user jurisdiction; or any news of banking exits from the sector in the VASP's home jurisdiction.

We regularly advise on the full stack – the licence, the banking and the compliance documentation – as a single integrated mandate. The banking problem and the licensing problem are not separate. A VASP that holds the right licence in the right jurisdiction, with the right AML programme and a documented Travel Rule solution, is a different banking client than one that holds a legacy registration and relies on informal compliance practices. We structure the licensing, banking and tax as one mandate rather than three disconnected workstreams, because the bank sees all three simultaneously.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because the compliance cost of maintaining them – enhanced due diligence, monitoring, correspondent-banking pressure and examination risk – exceeds the revenue the relationship generates. The exit is usually categorical rather than client-specific: entire business categories are removed from the bank's risk appetite. A VASP that holds a recognized licence, maintains a documented AML programme and can demonstrate Travel Rule compliance is materially less likely to be exited than one that cannot.

How can a VASP onboard with an EMI?

A VASP seeking to onboard with an EMI should prepare a structured disclosure package: its licence documentation, a summary of its AML and KYC framework, its Travel Rule compliance solution, a description of its client base and transaction profile, and its group structure. EMIs familiar with digital-asset businesses will conduct their own due diligence, but a proactive package reduces the review timeline and signals operational maturity. Where an EMI operates under an EU passport, the applicable payment services regime governs the terms on which the EMI may accept or decline the application.

What does client-money safeguarding require?

Client-money safeguarding requires a VASP to hold client funds separate from its own assets – typically in a designated account at a credit institution, or through an insurance or guarantee arrangement meeting the applicable regulatory standard. The specific requirements vary by jurisdiction and licence type. Under MiCA, CASPs holding client funds face explicit segregation and safeguarding obligations. Under the MAS Payment Services Act, DPT licensees above specified thresholds must maintain compliant safeguarding arrangements. Both regimes require periodic review as the business scales.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Glen Sorensen, Disputes and Recovery Analyst – specialising in cross-border banking access disputes, account closure defence and on-chain asset recovery for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours