EST · MMXXVI
Home/Insights/Disputes/De-risking and account closure defence: What Recent Enforcement Tells Operators
Banking, Payments & EMI Onboarding

De-risking and account closure defence: What Recent Enforcement Tells Operators

De-risking and account closure defence: What Recent Enforcement Tells Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and

Banks and electronic money institutions are exiting crypto relationships at an accelerating pace. A de-risking event – the closure or refusal of a fiat account because an institution has decided the compliance cost of a customer class outweighs the commercial return – is no longer an edge case. For a virtual asset service provider (VASP), losing its primary settlement account can freeze payroll, halt withdrawals and, in extreme cases, trigger a regulatory solvency notice. The legal question is concrete: what rights does a VASP hold when its bank or electronic money institution (EMI) terminates unilaterally, and how has enforcement practice shaped those rights?

Enforcement action across the major hubs tells a consistent story. Regulators and courts in leading common-law forums have begun to distinguish legitimate commercial decisions to exit a client from discriminatory or procedurally defective closures. Recent practice shows that operators who understood their contractual position, held the right licence stack and documented their compliance posture were materially better placed to challenge closure, compel disclosure, or at minimum secure an orderly wind-down period. The sections below map that environment for operators making real decisions now.

Why de-risking happens – and why it matters to your business model

De-risking is a rational institutional response to asymmetric compliance economics. A regulated bank or EMI bears the direct cost of AML/CFT monitoring for every customer, while the penalty exposure for a single AML failure can run into the hundreds of millions of dollars across major jurisdictions. When the expected compliance cost of servicing a class of customers exceeds the expected revenue, exit is the commercially defensible choice. For crypto operators, that calculus is rarely in their favour at the institutional level.

The practical consequence is severe. A VASP that loses its fiat rail – the banking or payment-account infrastructure that converts digital assets to and from local currency – loses its operating model. Customers cannot deposit or withdraw. Institutional counterparties disengage. The regulator notices a liquidity stress before the business does. In our cross-border practice, we have seen businesses operating under a validly issued licence collapse operationally within weeks of an unannounced account closure, because no secondary banking relationship existed.

The FATF Recommendations explicitly address the collateral damage of wholesale de-risking, noting that blanket exit from entire customer sectors undermines financial inclusion and pushes activity to unmonitored channels. ESMA and national competent authorities across the EU have separately flagged that EMI onboarding obstacles for licensed CASPs under MiCA are inconsistent with the regime's passporting logic. The signals are there. They have not yet produced a right to an account – but they have produced procedural obligations that operators can use.

The cross-border dimension compounds the risk. A VASP licensed in one jurisdiction but banking in another faces a layered exposure. The bank's home regulator may apply different risk appetite rules. The VASP's licence may not be recognised by the banking counterparty's compliance team. AML documentation prepared for one regime may be inadequate for another. Operators who treat banking as a routine operational matter, rather than a legal and structural one, find out the hard way that it is neither routine nor operational once the closure notice arrives.

To map your fiat-rail exposure before a closure notice arrives, contact OBOLUS at info@oboluslaw.com. The process above describes the standard risk pattern. Your facts – entity structure, licence category, user geography and banking counterparty domicile – change the legal analysis materially.

What recent enforcement tells operators about their rights

Enforcement practice in the leading jurisdictions has produced a clearer, if still unsettled, picture of the rights a VASP holds on account closure. The core point from recent practice is this: a closure is not automatically lawful simply because the bank's terms and conditions include a general termination right. Courts and regulators have scrutinised whether the termination right was exercised in a manner consistent with procedural fairness, anti-discrimination obligations and, where applicable, sector-specific access-to-payment rules.

In England and Wales, the Payment Accounts Regulations and the Payment Services Regulations impose obligations on payment service providers to give adequate notice before exit and to give reasons in defined circumstances. While these provisions stop short of creating an absolute right to maintain an account, they have been used in litigation and regulatory complaints to challenge summary closures. A bank that terminates a licensed VASP account on 30 days' notice, citing only "risk appetite", faces a more credible challenge than a business would have faced five years ago.

In the EU under MiCA, the logic extends further. A CASP authorised by a national competent authority and exercising passporting rights across the EU/EEA has an argument – one that ESMA has begun to examine – that an EMI's refusal to service it on solely categorical grounds (i.e., "you are a crypto company") may be inconsistent with the principle of fair access to payment services. That argument has not yet been definitively resolved by enforcement, but it is live, and it is strengthening.

In the UAE, VARA has signalled an expectation that banks operating in the mainland Dubai environment will apply proportionate risk assessment to VARA-licensed entities rather than categorical exclusion. The DIFC Courts represent a credible forum for a licensed entity that suffers economic harm from an unjustified closure by a counterparty inside the DIFC financial free zone. Trafigura v Gupta, a 2025 DIFC decision, reinforced that the DIFC Courts will grant worldwide freezing relief in support of foreign proceedings – a data point relevant to the recoverable-harm question even outside the strict de-risking context.

The consistent enforcement lesson is this: the strength of a closure challenge is almost entirely determined before the closure happens. An operator with complete compliance documentation, a clear licence stack, and a well-structured contractual relationship with its banking counterparty has significantly more leverage than one without those elements. Enforcement does not create rights retroactively. It validates preparation.

What is the licence stack problem, and why does it produce banking failures?

A single licence in a single jurisdiction is almost never sufficient for a VASP operating across borders, and banking failures are frequently traceable to gaps in the licence stack rather than to the compliance failures that banks cite. When a bank's compliance team reviews a crypto client, it looks at the licence held in each jurisdiction where the business is active, the regulatory category of each service offered and the AML regime applicable in each market. A licence gap – an activity that is licensed in one place but unregulated in the country where the user sits – is treated as an AML risk. The account exits.

The architecture of a complete licence stack for a mid-sized VASP typically involves at minimum a VASP or CASP authorisation in the jurisdiction of primary operation, a payments or EMI licence (or a relationship with a licensed EMI) for fiat settlement, and in some cases a separate custody licence or registered structure for the asset-holding layer. Each component has a different regulatory counterparty. Each creates a different ongoing compliance obligation. Banks underwrite the combined structure, not the headline licence.

Operators we advise routinely underestimate the importance of the payment layer. A VASP licence, whether issued under VARA in Dubai, under the MAS Payment Services Act in Singapore, or under the Bank of Lithuania's MiCA transitional framework, does not on its own authorise the holding of client fiat money. Where the VASP does not hold an EMI or payment institution licence itself, it is dependent on a regulated payment partner. That dependency is an exposure point. If the partner exits, operations halt unless a secondary relationship exists.

The cross-border dimension of this problem is acute in the AIFC. The Astana Financial Services Authority (AFSA) licenses digital asset trading and custody activity within the AIFC's common-law framework. An operator licensed by AFSA conducting business with users in multiple time zones will need banking relationships that span Kazakh tenge settlement, US dollar correspondent rails and potentially euro clearing. Each rail involves a different regulatory gateway. The AIFC's common-law framework and its proximity to the developing CIS markets make it attractive, but the banking stack must be built with the same care as the regulatory one.

What are the most common mistakes in EMI onboarding that lead to later account closures?

EMI onboarding failures for VASPs almost always trace to one of four structural mistakes, each of which surfaces during the EMI's periodic review rather than at initial onboarding. The first and most common is inadequate AML programme documentation. The EMI's compliance team needs to see a complete AML/CFT policy, a risk assessment, transaction monitoring parameters and evidence of staff training. A policy document that meets the minimum threshold of the VASP's home regulator may fall significantly short of what the EMI's own FCA or Bank of Lithuania compliance team requires.

The second common mistake is failure to align the business description at onboarding with the actual product. A VASP that describes itself as a "digital asset custodian" at account opening and then begins operating exchange-like services will trigger a material change review. The EMI's right to terminate for failure to notify a material change is typically broad and well-drafted. Courts have generally upheld terminations in those circumstances.

The third mistake is neglecting the Travel Rule – the obligation, arising under FATF Recommendation 15 and implemented across the major VASP regimes, to pass originator and beneficiary data with a transfer above the relevant de minimis threshold. An EMI that discovers its VASP client is not compliant with the Travel Rule in the markets where it operates will treat that as a material AML risk. The account review that follows is rarely resolved in the VASP's favour without significant remediation.

The fourth, and most structurally important, mistake is the failure to negotiate adequate contractual protections at the outset. Standard EMI terms of service include broad termination rights that can be exercised on short notice without cause. A properly negotiated banking or EMI agreement for a licensed VASP should include, at minimum, a meaningful notice period before termination, a requirement for specific grounds (or at least a statement of grounds) and a dispute-escalation mechanism. We have seen operators decline to negotiate these terms at onboarding – typically because they were simply relieved to have obtained an account – and then find themselves with no leverage when closure came.

For a scoped assessment of your EMI or banking agreement before you sign or before a review is triggered, contact OBOLUS at info@oboluslaw.com. If a prior application stalled or an existing account is under review, a second read of the underlying contractual framework frequently surfaces the structural issue and the route to resolution.

Contrasting positions: how operators and banks see the same closure

The same account closure looks entirely different depending on which side of the relationship you are on, and understanding both views is necessary for effective defence. Banks and EMIs characterise de-risking as a forward-looking risk management decision. The exit is not, in their framing, a finding that the customer did anything wrong. It is a business decision that the category of customer generates compliance cost and regulatory exposure that exceeds acceptable levels. That framing is deliberate: it forecloses the AML-related reputational damage that would follow if the exit were characterised as a finding of wrongdoing.

Operators experience the same event as a finding of wrongdoing, because it functions as one operationally. A crypto exchange whose primary settlement bank exits cannot credibly market itself as a regulated, compliant business while its settlement infrastructure is absent. Institutional counterparties, prospective banking replacements and the VASP's own regulator all draw inferences from the closure that the bank carefully avoids making explicit.

The legal asymmetry is significant. The bank has broad contractual rights to exit. It has no duty to provide an account. It faces regulatory liability if it retains a customer it later determines was a money laundering risk. Its incentives strongly favour exit. The operator, by contrast, needs the account to function. Its rights are procedural and, in some regimes, statutory – not rights to retain the account, but rights to an orderly and reasoned process. That asymmetry does not mean the challenge is hopeless. It means the challenge must be precisely framed: procedural defect, inadequate notice, categorical rather than individual risk assessment, or discrimination on grounds not permitted by applicable access-to-payment rules.

A common assumption among operators is that regulatory approval of their licence means banks must accept them. This is incorrect. A VASP licence authorises the conduct of virtual asset services. It does not require any regulated bank to open or maintain an account with the licensee. Where statutory access rights exist – and they are limited – they are found in payment-accounts regulation, not in the licensing regime. The two legal regimes operate in parallel, not in sequence.

Which profile fits which approach – a cross-border decision framework

Not every de-risking event calls for the same response, and the right approach depends on the operator's profile, the nature of the closure and the forum available. The following analysis describes the principal response profiles we see in practice.

Profile A: EU-licensed CASP, EMI termination, short notice. The most actionable response combines a formal regulatory complaint to the relevant national competent authority (citing MiCA's passporting logic and ESMA's signalling on fair access) with a contractual review for procedural defects in the termination. If the EMI is licensed in a jurisdiction with statutory notice requirements – the FCA's framework being the most developed – a regulatory referral runs concurrently with a negotiated extension of the notice period. The goal is an orderly transition window, not reinstatement, which is rarely achievable. Indicative timeline from notice to transition completion: typically several weeks to a few months, depending on the availability of a replacement EMI and the willingness of the terminating institution to cooperate. Key risk: regulatory complaint delays are long; the faster lever is contractual.

Profile B: VARA-licensed operator in Dubai, mainland bank exit. VARA's expectation of proportionate risk assessment by banks creates a supervisory lever. A formal communication to VARA, documented in writing, that the operator holds a valid licence and has been exited on categorical grounds (not individual compliance failure) is a meaningful step that most operators do not take. VARA's response is not guaranteed, but its supervisory authority over its licensees creates an indirect incentive for banks operating in the same regulatory environment to cooperate with an orderly wind-down. Cross-border banking in this profile typically involves a UAE-licensed bank, a correspondent in a Gulf Cooperation Council state and a secondary relationship in a jurisdiction with an established VASP banking market.

Profile C: Offshore-licensed VASP, no secondary banking, primary EMI exit. This profile has the weakest defence. An operator holding only an offshore registration (BVI, Cayman or similar) and banking through a single EMI has minimal contractual leverage and no regulatory complaint channel with real teeth. The response in practice is accelerated replacement banking outreach, which we support through our knowledge of jurisdictions with more accommodating banking environments for licensed operators. The lesson is structural: the offshore licence profile was the wrong architecture for a business with material fiat-rail dependency, and the de-risking event is an opportunity to rebuild correctly.

Profile D: Operator with documented Travel Rule compliance and auditable transaction monitoring, bank exit citing general "crypto risk". This is the strongest factual basis for a challenge. Where the operator can demonstrate Travel Rule compliance, a risk-rated AML framework and a clean supervisory history, a bank that cites only categorical risk is in a more exposed position if the closure is challenged. This does not guarantee reinstatement. It creates negotiating leverage for an extended transition period, for a letter of reference (which assists replacement banking outreach) and, in some cases, for a commercial settlement of the losses caused by the abrupt exit.

In practice: how a licence gap produced an account exit

In a recent matter, a payments company operating a digital asset exchange under a CASP authorisation in an EU member state lost its primary EMI relationship after the EMI's periodic review identified a discrepancy between the activities disclosed at onboarding and the scope of transactions flowing through the account. The company had expanded into a lending service that was regulated separately from the exchange activity under its home jurisdiction's MiCA implementation. The EMI characterised the unlicensed lending activity as a material change in the customer's risk profile and served notice of closure on commercially standard terms.

We were engaged shortly after the notice was served. The analysis identified two issues. First, the lending activity was arguable within the existing licence scope on a close reading of the national implementation. Second, the EMI had not followed the dispute escalation process specified in its own terms, which required a compliance-to-compliance conversation before termination for business-reason changes. We used both points: a formal dispute notice citing the procedural defect, accompanied by a legal opinion on the licence scope question, extended the notice period by several weeks and gave the client time to onboard a secondary EMI. The primary relationship was not reinstated, but the orderly transition avoided the liquidity event that would have followed an abrupt closure.

What does client-money safeguarding require, and how does it interact with banking access?

Client-money safeguarding is the regulatory obligation, common to EMI, payment institution and custodial regimes, to hold client funds separately from the firm's own assets and in a manner that would survive the firm's insolvency. Its interaction with banking access is direct and often overlooked: safeguarding requires a designated safeguarding account with a regulated credit institution. If the credit institution exits, the safeguarding obligation does not suspend. The firm is immediately in breach if it cannot place client funds in a compliant safeguarding account within the required period.

Under the FCA's regime in the UK, EMIs and payment institutions holding client funds must safeguard those funds from receipt. The Bank of Lithuania and MiCA's national implementations replicate substantially the same logic for EU CASPs holding client fiat. The consequence of a safeguarding breach is regulatory – a breach reportable to the home supervisor, potentially triggering supervisory intervention – and civil, because affected clients have a direct claim against safeguarded funds ahead of general creditors.

The safeguarding account dependency means that de-risking events have a secondary effect beyond operational disruption. A bank exit that eliminates the only safeguarding account puts the operator in technical breach of its licence conditions within hours, not days. Regulators have used safeguarding breaches as the trigger for more intrusive supervisory engagement – account freezes, requirement to appoint a skilled person, and in some cases licence suspension proceedings.

Operators we advise are increasingly building a secondary safeguarding account structure as a licence condition compliance matter, not merely an operational resilience one. Two safeguarding accounts in different banking counterparties, ideally in different jurisdictions, is the baseline we recommend. The cost of maintaining both is small relative to the regulatory exposure of relying on a single relationship. In our practice, this structure has twice prevented a safeguarding breach from materialising when a primary banking relationship exited on short notice.

Addressing the common assumption: does one licence cover all markets?

A common assumption among operators entering the market is that a single licence – typically an offshore registration in the BVI, Cayman Islands, or a single EU member state – is sufficient to serve clients globally and to maintain global banking relationships. This assumption is incorrect, and enforcement across all major hubs has consistently confirmed its incorrectness.

The licence granted in one jurisdiction authorises the conduct of specified activities within, or to residents of, that jurisdiction, and in some cases with the benefit of a passporting mechanism to adjacent jurisdictions. It does not create a right to conduct regulated activities in third countries without additional authorisation. A BVI VASP registration does not authorise the provision of exchange services to UK or EU retail users without FCA registration and MiCA CASP authorisation respectively. A MiCA CASP authorisation does not extend to Singapore users without MAS licensing. The global reach of digital assets does not carry the licence with it.

The banking consequences of this misunderstanding are immediate. A bank's compliance team conducting customer due diligence on a VASP will map the actual user geography against the licences held. Where users are present in jurisdictions where the VASP is unlicensed, the bank's assessment is that the business is conducting unregulated activity. That is a de-risking trigger, and it is one that the operator has, in a formal sense, created for itself.

The practical implication is that the licence stack must be mapped to the user geography. For an operator with global ambitions, that means identifying the three to five jurisdictions that represent the dominant share of users or transaction volume, licensing in each or implementing a jurisdictional restriction that banking counterparties can verify, and building the compliance documentation to demonstrate the mapping. We map the licence stack across operating, custody and payment layers before operators commit to a market-entry architecture – because the architecture, once built, is expensive and slow to change.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because the expected compliance cost of AML/CFT monitoring for the customer exceeds expected revenue. This is a risk-appetite decision, not a finding of wrongdoing. Contributing factors include inadequate AML documentation, an unlicensed activity in one or more user markets, Travel Rule non-compliance, or a change in the bank's internal sector-risk classification. A licensed, well-documented operator with a complete licence stack presents materially lower closure risk than one relying on a single offshore registration.

How can a VASP onboard with an EMI?

Onboarding with an EMI requires preparing a complete AML/CFT programme, a current risk assessment, a clear description of all regulated activities and the licences covering them, evidence of Travel Rule compliance, and transaction monitoring documentation. The application should accurately describe the business as it will actually operate, not as it operates at the point of application. Negotiating adequate contractual protections – a meaningful notice period, a stated-grounds termination right and a dispute-escalation process – is as important as the initial AML documentation package.

What does client-money safeguarding require?

Client-money safeguarding requires that funds received from clients be held in a designated account, separate from the firm's own funds, with a regulated credit institution, from the moment of receipt. The obligation applies under the FCA's regime in the UK, under equivalent payment institution and EMI rules in EU jurisdictions, and under custodial licence conditions in most major VASP regimes. A safeguarding breach is reportable to the home regulator and gives clients a direct proprietary claim ahead of general creditors. Maintaining at least two safeguarding accounts at separate institutions is the practical minimum for resilience.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and payment stack across operating, custody and settlement layers before operators commit to a structure. Our disputes team coordinates freezing relief and on-chain tracing across the leading common-law forums. To discuss your situation, contact info@oboluslaw.com.

By Glen Sorensen, Disputes & Recovery Analyst – specialising in cross-border account closure defence, on-chain asset tracing and enforcement proceedings across common-law forums for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours