Fiat banking for crypto businesses sits at the intersection of payments law, AML compliance and correspondent-bank risk appetite. A virtual asset service provider (VASP) that converts customer funds between digital assets and fiat currency is not simply moving money – it is touching the regulated perimeter of payment services, electronic money issuance and, in most jurisdictions, money-transmission licensing. Get that wrong and the rails close overnight, often without the warning a bank would give a conventional payments client.
The legal question is precise: which party in the on/off-ramp chain bears the regulated obligation, under which regime, and across which jurisdictions? The answer determines whether your business can maintain a bank account, process payouts to customers and survive a compliance audit. This analysis works through the regulated perimeter, the pressure points where banks terminate accounts, the cross-border tension between the jurisdiction of the VASP licence and the jurisdiction of the bank, and the practical steps that experienced operators use to keep fiat rails open.
What Is a Fiat On/Off-Ramp, and Why Does It Attract Regulatory Scrutiny?
A fiat on/off-ramp is any process that converts government-issued currency into a digital asset – or the reverse – and the regulated scrutiny flows directly from that conversion step. From a payment-law perspective, receiving fiat funds from a customer and holding them pending conversion is functionally identical to accepting a payment or issuing e-money. Regulators in every major jurisdiction treat that activity as requiring authorisation, registration or at minimum a licence passported from another recognised regime.
The risk is asymmetric. A VASP that operates a fiat conversion service without the correct payment or e-money authorisation is simultaneously exposed to enforcement by the payments regulator and at risk of losing its banking relationship, because the bank's own compliance team will identify the mismatch between the VASP's stated activity and its regulated permissions. In our cross-border practice, we see this misalignment most often in businesses that obtained a VASP registration in one jurisdiction and assumed it covered payment services in another.
The regulated perimeter has three layers. First, the VASP licence itself – which in the EU now takes the form of a CASP authorisation (Crypto-Asset Service Provider) under MiCA, administered by ESMA and the relevant national competent authority. Second, a separate payment institution or e-money institution authorisation for the fiat leg of the transaction. Third, AML registration or equivalent, which runs in parallel and is required even where an entity is exempt from full licensing.
Operators who conflate these layers face an immediate structural problem: the VASP or CASP authorisation does not, by itself, license the receipt of fiat funds from retail customers. The moment the business touches client money in a currency form, the payment-services regime activates – and that regime has its own capital requirements, safeguarding obligations and passporting rules.
For a scoped legal assessment of your on/off-ramp structure and which licences apply to your specific activity, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.
Which Licences Govern the Fiat Leg?
The fiat leg of a crypto on/off-ramp is governed by the payment-services or e-money regime of the jurisdiction where funds are received from customers – not the jurisdiction where the VASP is domiciled. This distinction is operationally critical and is the single most common source of account terminations in businesses we advise.
In the European Union, the applicable regime for fiat handling sits under the payment-services directive framework, which MiCA does not displace. A CASP authorised under MiCA may need a separate Payment Institution (PI) or Electronic Money Institution (EMI) authorisation to receive and hold client fiat funds, depending on how the conversion service is structured. ESMA has made clear that MiCA authorisation and payment-services authorisation are not interchangeable.
In the United Arab Emirates, VARA's activity-based licensing model covers exchange and transfer/settlement services, but the fiat payment infrastructure sits within the CBUAE's payment-services framework. A business licensed by VARA for virtual-asset exchange that also processes fiat deposits through a UAE bank account will typically need to confirm with its banking partner that the fiat-handling activity falls within its permitted scope – or obtain a separate payment-services permission.
In Singapore, the Monetary Authority of Singapore (MAS) administers the Payment Services Act, which provides three licence tiers. A Digital Payment Token (DPT) service licence covers the virtual-asset side; fiat handling may engage the e-money or domestic money-transfer service categories depending on volume and structure. The distinction between a standard payment institution and a major payment institution turns on transaction thresholds that vary by category – businesses near those thresholds face meaningful regulatory exposure if they grow into a higher tier without upgrading their licence.
In the United Kingdom, the FCA requires cryptoasset businesses to register under the Money Laundering Regulations (MLR) – but that registration does not authorise payment services. A VASP operating an on/off-ramp with UK customers will typically need to hold, or partner with, an FCA-authorised payment institution or EMI.
The pattern repeats across jurisdictions. The VASP licence covers the crypto side. The payment licence – or an EMI relationship – covers the fiat side. Operating both under one roof is possible, but it requires two separate regulatory conversations.
Why Do Banks Terminate Crypto Company Accounts?
Banks close crypto accounts for identifiable, legal reasons – not arbitrary aversion – and understanding those reasons is the first step to building a banking structure that survives compliance review. The primary trigger is a mismatch between the account's transaction profile and the bank's documented understanding of the account holder's business and regulatory status.
A correspondent bank running de-risking programmes scrutinises its downstream clients' customer bases with the same lens it applies to its own AML obligations. For a VASP, that means the bank will ask: does this entity hold the licences that are required for the activity its transactions reflect? If the VASP is processing fiat conversions at volume and holds only a VASP registration – not a payment institution authorisation – the bank faces a binary choice: obtain a legal opinion confirming compliance or close the account.
Several recurring patterns arise in practice. The first is the unlicensed payment activity trigger: the bank's transaction-monitoring system identifies incoming retail fiat deposits followed by outgoing crypto purchases, which is the signature of unlicensed payment-services activity. The second is the Travel Rule gap: where the VASP cannot demonstrate that it is transmitting originator and beneficiary information with virtual-asset transfers under the Travel Rule (the obligation under FATF Recommendation 15 to pass identifying data with every qualifying transfer), the bank treats the account as a financial-crime risk. The third is licence-jurisdiction mismatch: the VASP holds a licence from a jurisdiction the bank's AML policy does not recognise as equivalent, making the entire relationship a red-flag item.
In our cross-border practice, we regularly advise clients who lost a banking relationship after the bank's annual KYC review – not because the business was doing anything illegal, but because the documentation on file did not keep pace with the business's growth. A company that started as a crypto-wallet provider and expanded into fiat conversion without updating its bank's understanding of the activity profile is the archetype of this problem.
The remediation process is almost always slower than operators expect. Most banks require not just a revised KYC pack but a legal opinion on the entity's regulatory permissions, a revised compliance policy that maps the business activity to the licence held, and often a demonstration that the Travel Rule is being implemented. That process is measured in weeks, not days.
EMI Onboarding: The Practical Path for VASPs Without Their Own Fiat Licence
Onboarding with an Electronic Money Institution (EMI) is the most common path a VASP takes to access fiat rails without holding its own payment-services licence. An EMI can issue electronic money, hold client funds in safeguarded accounts and process payments across SEPA and other payment schemes – functions that a VASP needs for the fiat leg of its conversion service.
The relationship is legally a B2B services arrangement: the EMI acts as a regulated intermediary and the VASP is the EMI's business customer. From the EMI's perspective, onboarding a VASP is one of the higher-risk account relationships it can take on. The EMI must apply its own AML due-diligence standards to the VASP as a business, conduct enhanced due diligence on the VASP's underlying customer base if the VASP is serving retail clients, and satisfy itself that the VASP's licence is valid and sufficient for the activity.
In practice, EMIs assess VASPs on several criteria. First, the VASP must hold a demonstrably valid licence or authorisation in a jurisdiction the EMI treats as equivalent or acceptable. An offshore registration from a jurisdiction without a recognised AML framework is typically insufficient. Second, the VASP's AML programme must be documented and auditable – the EMI will request policies, transaction-monitoring procedures and the name of a responsible compliance officer. Third, the VASP must demonstrate Travel Rule compliance or a credible implementation plan, because the EMI's own obligations extend to the VASP's transfer activity on the EMI's rails.
Operators we advise routinely underestimate the time the EMI onboarding process takes. A well-prepared application – one that presents the licence, the AML framework and the Travel Rule compliance architecture as a complete package – will typically be processed materially faster than an application that arrives in stages as the EMI requests additional documents. The difference is preparation, not negotiation.
The cross-border angle matters here too. A VASP incorporated in the BVI or Cayman Islands, holding a VASP Act registration, onboarding with an EMI authorised in Lithuania or Malta will face a detailed question about which jurisdiction's requirements govern the relationship. The EMI's own regulator – the Bank of Lithuania or the MFSA – will require the EMI to document why it is comfortable that the VASP's offshore licence provides equivalent protection. That analysis is not automatic.
Cross-Border Tension: Licence Jurisdiction vs. Bank Jurisdiction
The most complex legal situations in fiat on/off-ramp banking arise when the jurisdiction of the VASP's licence is different from the jurisdiction of the bank, the jurisdiction of the VASP's customers and the jurisdiction where the fiat funds are processed. Each of those differences creates a potential compliance gap, and a compliance gap is a banking-relationship risk.
Consider the common structure: a holding company in the BVI, an operating entity licensed by the Cayman Islands Monetary Authority (CIMA) under the Virtual Asset (Service Providers) Act, banking through a European bank, and serving customers in the EU and the Gulf. The Cayman VASP licence is recognised as credible in many correspondent-banking networks. But it does not grant the right to offer payment services to EU-resident customers under the EU payment-services framework, and it does not carry a MiCA CASP authorisation, which EU customers' deposits might require once the full MiCA regime is operative.
The bank, for its part, must manage its own regulatory exposure to EU AML requirements, which extend to its business customers' operations. If the VASP's customer base includes EU residents and the VASP does not hold a MiCA-compatible authorisation, the bank faces a question about whether maintaining the account exposes it to regulatory criticism. Depending on the bank's own supervisory context, the answer may lead to account closure.
We have seen this scenario play out repeatedly with businesses that expanded into new customer geographies without reassessing the licence stack. The solution is rarely a single licence: it is typically a combination of a CASP authorisation in the EU (or a passported MiCA licence from one member state), a VARA or ADGM licence for Gulf customers, and either a direct payment-institution licence or a documented EMI relationship for the fiat processing in each region.
Regulators in the leading hubs increasingly expect VASPs to demonstrate a geographic match between the customers they serve and the licences they hold. A well-structured operator today maps its user base by jurisdiction and stress-tests the licence stack against that geography before it applies for a bank account – not after the account is closed.
If a prior banking application stalled or an existing account was closed, a structural re-read can surface the root cause and the route back. Write to OBOLUS at info@oboluslaw.com. A second read can surface the structural reason and the route back. Map your options.
Client Money Safeguarding: The Non-Negotiable Floor
Client-money safeguarding – the obligation to hold customer funds separately from the firm's own assets, in a way that makes them recoverable on insolvency – is the non-negotiable floor of any fiat on/off-ramp operation, and it is enforced as a hard legal requirement by every serious regulatory regime.
Under payment-services and e-money frameworks across the EU, UK and Singapore, a licensed payment institution or EMI must safeguard client funds either by holding them in a segregated account at a credit institution or by covering them with an insurance policy or bank guarantee. The precise method permitted and the operational requirements attached to it vary by category of licence, but the principle – client money is not the firm's money – is universal.
For a VASP operating a fiat on/off-ramp through an EMI partner, the safeguarding obligation sits primarily with the EMI. The VASP, however, is not insulated from safeguarding risk. If the VASP is holding fiat funds in transit – even for a short period between customer receipt and transfer to the EMI's safeguarded account – it may be performing an unlicensed safeguarding function. That exposure is small in time but real in legal terms.
The practical implication is that the commercial and legal agreement between the VASP and its EMI partner must define, precisely, the moment at which custody of fiat funds transfers and the safeguarding obligation activates. A poorly drafted service agreement that leaves a gap – funds received by the VASP but not yet transferred to the EMI – is a compliance gap that a regulator or a bank's auditor will identify.
The cross-border dimension adds further complexity. A VASP serving customers in multiple jurisdictions, with fiat processed through an EMI in one jurisdiction, must confirm that the EMI's safeguarding architecture covers customers in each jurisdiction where fiat is received. Some payment-services regimes have specific rules about where client funds for residents of that jurisdiction must be held.
The Travel Rule and Fiat Rails: A Compliance Dependency
The Travel Rule is, in practical terms, a condition of access to fiat rails – not merely a standalone AML obligation. Banks and EMIs increasingly treat a VASP's Travel Rule compliance as a prerequisite for account onboarding and a basis for ongoing account review.
The Travel Rule, derived from FATF Recommendation 15, requires that a VASP transmit originator and beneficiary information alongside virtual-asset transfers above a defined threshold. The threshold varies by jurisdiction; the underlying obligation does not. A VASP that cannot demonstrate a documented Travel Rule implementation – including the technology that transmits the data, the counterparty-identification procedure for unhosted wallets and the policy for transfers where the receiving VASP cannot be identified – will face onboarding refusal from most credible EMI partners.
The operational challenge is that Travel Rule compliance for cross-border transfers requires the receiving VASP also to be compliant and reachable on a Travel Rule messaging network. Where the counterparty VASP is in a jurisdiction without an implemented Travel Rule requirement, the sending VASP must apply a risk-based approach that is documented and auditable. Banks and EMIs ask for this documentation precisely because their own AML obligations extend to the adequacy of their customers' compliance programmes.
In our cross-border practice, we have seen account terminations triggered specifically by Travel Rule gaps discovered during a bank's annual AML review. The bank's finding was not that the VASP was engaged in financial crime – it was that the VASP's documented compliance programme did not satisfy the bank's own standards for what a credible Travel Rule implementation looks like. The distinction matters: the remedy is a compliance-architecture exercise, not a legal defence.
Decision Matrix: Which Structure for Which Operator?
The right fiat on/off-ramp structure depends on the operator's transaction volume, customer geography, existing licences and risk tolerance. There is no single answer, but the choice narrows quickly when the facts are mapped.
Profile A – Early-stage exchange or broker, primarily EU customers, CASP authorisation sought or held. The most efficient path is to pair the CASP authorisation with a documented EMI onboarding arrangement in the same jurisdiction or a passportable EU jurisdiction. The EMI handles safeguarding; the CASP covers the virtual-asset service side. The licence cost and timeline for a standalone payment-institution licence at this stage typically exceeds the business benefit. Key risk: the EMI partner's own risk appetite may change, terminating fiat access at short notice.
Profile B – Established exchange, global customer base, operating from a Gulf hub. A VARA or ADGM licence covers the Gulf virtual-asset layer. The fiat leg requires either a UAE-licensed payment institution or a banking relationship that explicitly covers payment-services-equivalent activity. For EU and UK customers, the business typically needs a second entity with appropriate authorisation or a clearly documented restricted-customer-access policy. Key risk: the licence-jurisdiction mismatch between the Gulf entity and the EU customer base is the most common source of European bank terminations for this profile.
Profile C – Custodian or fund administrator with institutional clients, operating from Singapore or Hong Kong. MAS or SFC regulation covers the virtual-asset layer. The fiat leg is typically managed through institutional banking relationships where the counterparty is another regulated financial institution, not retail. Safeguarding and segregation requirements are still active but the compliance conversation with a correspondent bank is materially different. Key risk: AML documentation requirements for institutional virtual-asset flows remain high, and correspondent banks will expect detailed evidence of source-of-funds procedures.
In each profile, the answer to "which structure?" is reached by mapping the activity to the licensed permission, confirming the fiat-handling method against the payment-services regime of each customer jurisdiction and documenting Travel Rule compliance before the banking conversation begins – not during it.
Micro-Matter: A Structural Misalignment That Cost Fiat Access
In a recent matter, a digital-asset brokerage had operated successfully with a single VASP registration obtained in an offshore jurisdiction and a banking relationship with a European correspondent bank. The business expanded its customer base into EU member states and processed materially larger fiat volumes as a result. During the bank's annual review of the account in late 2024, the bank's compliance team identified that the VASP's registration did not carry MiCA CASP authorisation – which was in transition – and that no payment-institution permission was on file for the EU fiat-handling activity. The bank suspended outgoing payments pending a legal opinion and, two weeks later, issued a 30-day account-closure notice.
We were engaged shortly after suspension. The immediate steps were: a legal opinion mapping the VASP's licensed permissions against the EU payment-services regime; a gap analysis identifying which activities required separate authorisation; and a transitional compliance memo for presentation to the bank. Simultaneously, we identified an EMI in a MiCA-ready EU member state prepared to onboard the VASP on an expedited basis, subject to a compliant AML and Travel Rule submission. The fiat rails were restored through the EMI before the bank's closure notice expired. The underlying licensing gap remains the subject of a CASP authorisation application.
The lesson is not that offshore registrations are ineffective – they serve a legitimate structural purpose. The lesson is that the fiat banking relationship requires a licence-to-activity match that the VASP regime alone does not always provide, and that match must be documented before the bank asks for it.
A Common Assumption: One Offshore Licence Is Enough to Serve Clients Globally
A common assumption among early-stage crypto businesses is that a single offshore VASP licence – BVI, Cayman, or a similarly recognised offshore jurisdiction – provides sufficient regulatory cover to operate a fiat on/off-ramp for customers anywhere in the world. This assumption is incorrect and, when acted on, is one of the more reliable routes to banking disruption.
The offshore VASP licence does several things well. It establishes the entity within a recognised regulatory framework. It demonstrates to counterparties that the business is not operating in a completely unregulated environment. It may be sufficient for certain institutional-to-institutional transactions where both parties are themselves regulated financial institutions.
What it does not do is authorise the entity to provide payment services in any jurisdiction outside the one where the licence was issued. It does not create the legal right to receive fiat deposits from retail customers in the EU, UK, Singapore or the United States. And it does not satisfy the equivalence requirements that EU, UK and Singapore banks apply when deciding whether to maintain accounts for crypto businesses.
The practical consequence is that a business operating on an offshore licence alone – serving EU retail customers with fiat on/off-ramp services – is providing unregistered payment services in every EU member state where its customers reside, regardless of what its offshore licence says. MiCA and the national payment-services frameworks of EU member states apply based on where the customer is, not where the VASP is incorporated.
The correct response is not to abandon offshore structures – they remain useful for holding companies, treasury entities and structures where the customer-facing activity sits in a separately licensed entity. The correct response is to map the customer base, identify the jurisdictions of regulated activity and build the licence stack to match. We map that stack before clients commit capital to a banking or licensing structure they may not be able to use.
Related at OBOLUS
- Banking, Payments & EMI Onboarding – Legal strategy for crypto businesses building fiat access across multiple jurisdictions.
- Client Funds Safeguarding for Established Operators – Structuring segregation and safeguarding obligations to meet regulator and banking-partner expectations.
- Staking and Rewards Taxation in France (AMF/PSAN) – Tax and regulatory treatment of staking income under the French digital-asset regime.
FAQ
Why do banks close crypto company accounts?
Banks close crypto accounts most commonly because of a mismatch between the entity's licensed permissions and its transaction profile, gaps in AML documentation or Travel Rule compliance, or a licence from a jurisdiction the bank's policy does not recognise as equivalent. The trigger is usually the bank's annual KYC review, not active misconduct. Remediation requires updated legal opinions, a revised compliance framework and, often, a new or supplementary licence for the relevant fiat-handling activity.
How can a VASP onboard with an EMI?
A VASP seeking EMI onboarding must present a valid VASP or CASP authorisation from a jurisdiction the EMI treats as acceptable, a documented AML programme, a Travel Rule compliance architecture and evidence of an identified compliance officer. EMIs will conduct enhanced due diligence on the VASP's underlying customer base. A complete, well-prepared submission typically moves faster than one assembled in response to sequential requests for additional documents.
What does client-money safeguarding require?
Client-money safeguarding requires that fiat funds received from customers be held separately from the firm's own assets in a segregated account at a credit institution – or covered by an equivalent insurance or guarantee mechanism. The obligation sits with the payment institution or EMI handling the fiat leg. The VASP and its EMI partner must define contractually the exact moment at which safeguarding obligations transfer, to avoid gaps during the period between customer receipt and EMI custody.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit capital to a structure you may not be able to use. To discuss your fiat on/off-ramp structure, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Glen Sorensen, Disputes & Recovery Analyst – specialising in cross-border enforcement, banking-relationship disputes and recovery strategy for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.