Operating a digital-asset business on fiat rails is, in practice, a three-layer legal problem. The first layer is the payment or electronic money licence your entity holds. The second is the banking relationship that activates it. The third is the cross-border reality of serving users, moving funds and holding reserves across jurisdictions that apply different rules to the same activity. Miss any one layer and the rails stop.
This analysis examines where payment institution (PI) licensing obligations begin and end for crypto-adjacent businesses, how those obligations interact with virtual asset service provider (VASP) regimes, and what happens when a structure designed for one market is tested in another. The cross-border dimension is not optional background – it is the central legal question every operator with a multi-currency book must answer before it launches, not after its first account closure.
What activity actually triggers a payment institution licence?
A payment institution licence is required when an entity executes payment transactions, issues payment instruments or acquires payment transactions on behalf of third parties – and when that activity falls within the perimeter of the relevant payments regime. The precise perimeter differs by jurisdiction, but the underlying logic is consistent: if you are moving value on behalf of someone else, you are likely regulated.
For crypto businesses, the question sharpens quickly. An exchange that holds fiat on behalf of users before converting it into digital assets may be executing payment transactions. A custodian that moves stablecoins backed by fiat reserves may be issuing an instrument that a regulator classifies as an e-money token (an EMT, a digital representation of fiat value). A DeFi protocol with a fiat on-ramp embedded in its interface may be operating an acquiring service without having recognised it as such.
The analytical starting point is always substance over label. Whether an instrument is marketed as a "utility token," a "payment voucher" or a "settlement stablecoin" is legally irrelevant. What matters is the rights it confers and the flows it enables. Under MiCA – the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities – EMTs and asset-referenced tokens carry explicit authorisation requirements regardless of how they are described in a whitepaper. The FCA in the United Kingdom applies a parallel logic under its electronic money and payment services regimes, requiring firms to map their activity against the regulated categories before determining which registration or authorisation applies.
In our practice, the most common structural error is an operator that correctly identifies its VASP obligations but fails to identify the separate payment services obligation that sits underneath them. A VASP licence in Dubai under VARA, for instance, does not automatically authorise the receipt of fiat funds from retail customers in the European Economic Area. Those flows may trigger a separate EU CASP authorisation and, depending on the instrument, an EMT licence as well.
EMI or PI: does the distinction still matter for crypto businesses?
The distinction between an electronic money institution (EMI) and a payment institution remains legally significant and operationally consequential for any crypto business managing fiat balances on behalf of clients. An EMI is authorised to issue electronic money – a claim redeemable at par against the issuer – and is subject to stricter safeguarding, capital and redemption obligations than a PI. A PI processes payments but does not issue a monetary claim.
For most stablecoin-adjacent businesses, the EMI route is the relevant one. Under MiCA, an EMT issuer must either hold an EMI authorisation in an EU member state or obtain the new CASP authorisation where EMTs are involved. The MFSA in Malta and the Bank of Lithuania both supervise entities making this transition from legacy VFA or VASP registrations to the MiCA framework. The practical difference for the business is material: an EMI must safeguard client funds in a segregated account or insure them, must redeem at par on demand and must meet own-funds requirements that scale with its outstanding e-money.
A PI operating without e-money issuance authority is a narrower instrument. It can process, route and settle payments but cannot create the monetary instrument that a stablecoin effectively is. Operators that have structured around a PI and then layered a token product on top have, in several cases we are aware of, found themselves in a grey zone where the PI licence is insufficient and the EMI authorisation has not been sought.
The cross-border dimension compounds the issue. A PI authorised in one EU member state can passport its activities across the EEA under MiCA's passporting mechanism for CASPs. But that passport covers regulated crypto-asset services – it does not automatically extend the underlying payment services licence to jurisdictions outside the EU. A business serving UK users from a Malta EMI still needs to assess whether its UK-facing activity requires separate FCA registration under the UK's own payments regime.
For a scoped assessment of your payment services obligations across your operating and user-base jurisdictions, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analytical path. Your entity structure, your token design and your banking arrangements change the analysis significantly.
Why do banks refuse or terminate relationships with crypto businesses?
Banks close or refuse crypto company accounts primarily because of unresolved compliance risk at the intersection of AML/CFT obligations and the perceived opacity of on-chain flows. This is not a single legal rule – it is the accumulated effect of how financial crime frameworks apply to digital-asset counterparties.
Under the FATF Recommendations, specifically Recommendation 15 on virtual assets, banks that provide correspondent or account services to VASPs are expected to treat those VASPs as high-risk counterparties and to apply enhanced due diligence. In practice, this means a bank must understand who the VASP's own customers are, what AML controls they apply, and whether those controls meet the bank's own risk appetite. Most retail and mid-market banks conclude that they cannot efficiently perform that analysis at scale and exit the sector entirely.
The Travel Rule – the obligation, derived from FATF and implemented across the major licensing regimes, to pass originator and beneficiary data with every virtual asset transfer above the applicable threshold – adds a second layer of concern. A crypto business that cannot demonstrate Travel Rule compliance exposes its banking partner to indirect regulatory risk. Banks in Singapore under MAS supervision, firms in the EEA subject to the Transfer of Funds Regulation under MiCA's adjacent framework, and businesses operating under the FCA's MLR registration all face Travel Rule obligations that their banks are now explicitly asking about during onboarding.
A third factor is the quality of the VASP's own licence. A bank performing due diligence on a prospective crypto client will distinguish between an entity holding a full CASP authorisation under MiCA and one relying on a legacy registration from a jurisdiction that has not yet aligned to the post-MiCA standard. The latter carries a higher AML risk premium in the bank's own compliance model – and a higher probability of account refusal or termination.
In a recent matter, a payments company with a valid EU registration found its primary fiat account closed following the bank's internal AML review. The review flagged incomplete Travel Rule data on outbound transfers and the absence of a documented counterparty risk policy covering VASP relationships. We worked with the client to build the required compliance architecture and re-approached the bank with a structured due diligence package. The account relationship was reinstated on revised terms. The timeline was a matter of weeks, not months, but only because the underlying licensing position was already clean.
How do VASP and payment institution obligations interact in practice?
VASP and payment institution obligations interact through overlapping activity triggers, not through a clean division of regulatory labour. An operator conducting both virtual asset exchange and fiat payment services is typically subject to both regimes simultaneously – and the compliance obligations of each do not satisfy those of the other.
Under VARA in Dubai, activity licences cover advisory, broker-dealer, custody, exchange, lending, management and transfer/settlement of virtual assets. None of those licences, on their own, authorises the receipt or transmission of fiat funds from retail customers in the EU. A Dubai-licensed exchange serving European clients still needs to assess MiCA CASP authorisation requirements, and if it holds fiat balances on behalf of those clients, potentially an EMI authorisation in an EU member state.
The ADGM's FSRA in Abu Dhabi applies a parallel structure. The FSRA's regime for regulated activities in virtual assets operates within the ADGM financial free zone and addresses the virtual asset service. The fiat payment flows that accompany those services may, depending on their structure, require separate authorisation under the FSRA's payment services framework or, for cross-border flows into regulated markets, under the rules of the destination jurisdiction.
Singapore's Payment Services Act under MAS adds a further dimension. Digital payment token services and e-money issuance are regulated activities under the Act, each with separate licence tiers and capital expectations. A Singapore-licensed exchange that also issues a stablecoin pegged to a fiat currency may require both a Digital Payment Token service licence and a separate e-money licence, depending on the stablecoin's design. In our cross-border practice, we have seen operators in this region assume that a single MAS licence tier covers their full activity set – and find that the second licence is required only after launch, creating a period of unlicensed activity.
What structural risks arise when the entity, the licence and the user base sit in different jurisdictions?
The most acute structural risk in cross-border payment services is jurisdictional misalignment: an entity licensed in one jurisdiction actively serving users in another where a separate licence is required. This is not a technical gap – it is an enforcement exposure that can result in account closure, regulatory action and, in some cases, personal liability for directors.
The analysis turns on three questions. First, where are the users? A business licensed in Lithuania under the Bank of Lithuania's VASP regime may be passportable across the EU under MiCA once its CASP authorisation is in place, but that passport does not extend to the United Kingdom, Switzerland, Singapore or the UAE. Serving users in those jurisdictions from a single EU entity requires either a local licence in each market or a genuine substance and activity analysis that places the regulated service within the licensed perimeter.
Second, where is the fiat held? Client funds held in a segregated account at a Polish bank are subject to Polish banking supervision and EU deposit protection rules. The same funds held at an offshore banking partner may not carry equivalent protections, and the EMI's safeguarding obligation – to hold client funds in a credit institution or insured equivalent – may not be satisfied. This matters not only for regulatory compliance but for the business's own exposure if the banking partner fails.
Third, where is the payment decision made? Some regulators apply a "place of business" test; others apply an "active marketing" test; others look at where the transaction is executed. A crypto firm with a nominal registered address in a jurisdiction where it holds a licence but whose actual operations – servers, staff, customer-facing decisions – are located elsewhere may find that its licence does not cover the activity as it is actually conducted.
A common assumption is that a single offshore licence is sufficient to serve clients globally. That assumption is the most reliable predictor of account closure and enforcement attention we encounter in practice. The correct analysis identifies each jurisdiction where the business has users, holds funds or makes payment decisions, and maps each against the applicable licensing requirement. That mapping is the foundation of a compliant multi-jurisdictional payments structure.
Which licence structure fits which operator profile?
The right payment institution structure depends on the operator's activity profile, its user geography and the fiat flows it needs to support. There is no single correct answer, but there are identifiable profiles with identifiable optimal paths.
Profile A – EU-focused exchange with fiat on-ramp. An operator whose primary users are in the EEA and whose business model includes receiving fiat from retail customers, converting to digital assets and holding balances between transactions, needs both a MiCA CASP authorisation and, if it holds fiat balances on behalf of users beyond the incidental payment processing window, an EMI authorisation in a member state. Lithuania and Malta both offer established pathways for this profile. The MFSA's transition framework and the Bank of Lithuania's CASP authorisation process are the two most active routes. Timeline varies by application quality and the competent authority's current processing load, and should be confirmed against current practice before commitment.
Profile B – Gulf-based operator seeking EU fiat access. A VARA-licensed Dubai entity that wants to accept fiat from European clients cannot rely on its VARA licence for that purpose. The structural answer is typically a parallel EU CASP entity, either through a new authorisation in a member state or through a compliant operating arrangement with an EU-licensed EMI. Allied counsel in the EU jurisdiction confirm the local specifics; OBOLUS manages the cross-border structural layer. The principal risk for this profile is the gap period – when the Dubai entity is live and the EU authorisation is pending – during which EEA-facing fiat activity must be paused or routed through a licenced partner under a compliant arrangement.
Profile C – Asia-Pacific exchange with global ambitions. An operator licensed under MAS's Payment Services Act in Singapore faces a different matrix. Singapore's licence covers Digital Payment Token services within MAS's jurisdiction; it does not authorise payment services in the EU, UK or UAE. A business expanding from Singapore into those markets must obtain the relevant local licence or structure a compliant cross-border model. The AIFC in Kazakhstan offers an additional option for Central Asian and CIS market access, with AFSA supervision and a common-law framework, but again does not substitute for EU or UK licensing.
Profile D – Fintechs and payment businesses entering crypto. A licensed PI or EMI seeking to add digital-asset services faces the reverse problem. Its existing licence may not cover VASP activities, even if the underlying payment flows look similar. Under MiCA, a regulated entity offering crypto-asset services must obtain CASP authorisation separately, even if it is already an authorised payment institution. The transitional provisions under MiCA provide limited grandfathering for existing licensed entities, but the scope of that grandfathering is narrow and jurisdiction-specific. Acting on the assumption that a PI licence extends to crypto services without legal confirmation is a documented source of enforcement action in several EU member states.
What does client-money safeguarding require for payment institutions holding fiat?
Client-money safeguarding requires a payment institution to ring-fence funds received from customers so that they cannot be used for the institution's own purposes and are available for return if the institution fails. The obligation is not aspirational – it is a licence condition, and failure to maintain it is a ground for authorisation withdrawal.
Under MiCA's EMT framework and under equivalent rules in the UK, Singapore and the major Gulf hubs, the safeguarding obligation requires the institution to hold client funds in one of two ways: in a segregated account with a credit institution, or covered by an insurance policy or bank guarantee from a regulated provider. The credit institution must itself be regulated in a jurisdiction that meets the home regulator's standards. A PI that attempts to satisfy this requirement by holding funds with an unregulated payment partner, a crypto exchange or a non-bank entity will typically fail the safeguarding test.
The interaction with crypto business models is direct. Many crypto operators receive fiat from customers into an operational account, convert it to stablecoins, and maintain the stablecoin balance as the "fiat equivalent" on their books. This approach does not satisfy safeguarding obligations under any major payments regime unless the stablecoin itself qualifies as a permissible safeguarding instrument – which, under current frameworks, it generally does not for fiat obligations. The fiat received from the customer must be safeguarded in fiat form until converted to a regulated instrument or returned.
In practice, this creates a timing risk at the point of conversion. The window between receipt of client fiat and its conversion must be managed within the safeguarding framework, including by maintaining a documented policy that addresses how long fiat is held, in what account and under whose custody. Regulators conducting supervisory reviews – a routine step in both MAS and ESMA-supervised markets – focus specifically on this gap.
A common assumption: getting the licence solves the banking problem
A persistent operational assumption among crypto operators is that holding the right payment institution licence will, on its own, resolve the banking problem. The experience of operators across multiple jurisdictions tells a different story.
A payment institution licence establishes regulatory permission to conduct payment services. It does not compel any bank to provide a correspondent account, an IBAN or settlement infrastructure. Banks perform their own due diligence on payment institution applicants and apply their own risk appetite frameworks independently of the regulator's decision to grant the licence. An EMI that is fully authorised under MiCA may still find that every Tier 1 and Tier 2 bank in its home jurisdiction declines to open an account on AML or reputational risk grounds.
The resolution requires a parallel banking strategy. In our practice, we advise clients to treat the licence application and the banking approach as concurrent workstreams, not sequential steps. The elements that improve banking outcomes are known: a documented AML/CFT framework that addresses VASP counterparty risk; Travel Rule compliance that is demonstrable in the due diligence package, not merely asserted; a clear articulation of the customer base and the expected transaction volumes; and, where relevant, an audited safeguarding account structure that the prospective banking partner can verify independently.
The geography of banking access also shifts regularly. Banking partners that were active in the crypto sector in one jurisdiction may exit that market following a regulatory development elsewhere. OBOLUS maintains active insight across the major EU, Gulf and Asia-Pacific banking corridors and can identify the current landscape of available partners for a specific licence and activity profile. For a mapping of the licence, banking and compliance stack for your business, write to info@oboluslaw.com.
When should a payment institution candidate engage legal counsel?
Legal counsel should be engaged before the structure is committed – not after the first account closure or regulatory query. The point at which the corporate structure, the licence jurisdiction and the banking strategy are chosen is the point at which the legal exposure is created or avoided. Restructuring after the fact is materially more expensive than building the right structure from the beginning.
The specific triggers for early engagement include: selecting the jurisdiction for the PI or EMI authorisation; designing the token or stablecoin product and assessing whether it triggers an EMT authorisation; determining whether the business needs a VASP licence, a payment services licence or both; assessing whether its user base creates multi-jurisdictional licensing obligations; and negotiating the terms of its banking relationship in light of the regulator's expectations.
Later triggers – where the cost of legal support is higher but the alternative is worse – include: responding to a regulatory inquiry or supervisory review; managing an account closure and rebuilding banking access; addressing a period of unlicensed activity; and restructuring a holding or operating company to resolve a compliance deficiency identified by the regulator or by a banking partner.
OBOLUS maps the licence, banking and compliance stack across operating, custody and payment layers before clients commit to a structure. That scoping work draws on current practice across more than seventy licensing jurisdictions and identifies the intersections between payment services obligations and VASP requirements that are most frequently missed. If a prior application stalled or a banking relationship ended, a second read of the structure typically surfaces the cause and the route to resolution.
To map the licence, banking and tax stack for your build, write to OBOLUS at info@oboluslaw.com. If a regulatory clock is already running, contact the team via t.me/oboluslaw directly.
Related at OBOLUS
- Banking, Payments & EMI Onboarding – structuring fiat access and payment licences for digital-asset businesses across jurisdictions
- Client Funds Safeguarding in Liechtenstein – how Liechtenstein's framework addresses payment institution safeguarding obligations
- Legal Structuring for DeFi Protocols – the available legal models for protocol operators managing fiat and on-chain flows
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of AML and compliance risk. Under FATF Recommendation 15, banks must treat VASPs as high-risk counterparties and apply enhanced due diligence. Most banks conclude they cannot efficiently verify a crypto client's own AML controls. Additional triggers include incomplete Travel Rule compliance, weak licence quality relative to current CASP standards, and insufficient documentation of the client's counterparty risk framework. A well-structured AML package and a clean licence significantly improve retention outcomes.
How can a VASP onboard with an EMI?
A VASP onboards with an EMI by presenting a documented AML/CFT framework that addresses the specific risks of virtual asset flows, Travel Rule compliance evidence, a clear description of the VASP's own licensing position, and expected transaction volumes. EMIs performing due diligence on VASP clients apply their own risk appetite independently of the VASP's regulatory status. Operators that approach EMI onboarding with a structured due diligence package – rather than treating it as a standard account-opening process – consistently achieve better outcomes.
What does client-money safeguarding require?
Client-money safeguarding requires a payment institution to hold funds received from customers either in a segregated account at a regulated credit institution or under an insurance policy or bank guarantee from a regulated provider. The obligation applies from the moment fiat is received and continues until it is transmitted or returned. Holding client fiat in stablecoin form or with an unregulated partner does not satisfy the safeguarding requirement under any major payments regime. Documented safeguarding policies and regular reconciliation are standard expectations in supervisory reviews.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around every payment and VASP structure. Digital assets are the whole of our practice. Operators we advise routinely span multiple licensing regimes simultaneously – EU CASP alongside Gulf VASP licences, payment institution authorisations alongside custody frameworks – and we map those interactions before commitment. To discuss your situation, contact info@oboluslaw.com.
By Glen Sorensen, Disputes & Recovery Analyst – specialising in cross-border payment institution enforcement, account recovery and VASP compliance disputes across the EU, UK and Gulf hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.