EST · MMXXVI
Home/Insights/Glossary/Client-money Safeguarding: A Legal Guide for Digital-Asset Businesses
Banking, Payments & EMI Onboarding

Client-money Safeguarding: A Legal Guide for Digital-Asset Businesses

Client-money Safeguarding: A Legal Guide for Digital-Asset Businesses. Cross-border digital-asset legal counsel for business – licensing, disputes and structuri

Client-money safeguarding is the legal obligation to hold client funds separately from a firm's own assets, ensuring those funds remain protected against the firm's insolvency. For digital-asset businesses, this obligation sits at the intersection of payment services law, virtual asset service provider (VASP) regulation and banking access – and in our practice, it is one of the most frequently misunderstood areas of cross-border compliance. Getting it wrong does not produce a warning letter; it produces frozen rails, enforcement action and, in the worst case, a regulatory wind-down that destroys client relationships built over years.

This guide maps the regulated basis for client-money safeguarding across the major regimes, traces how the obligation interacts with the cross-border reality of digital-asset operations, and identifies the practical decisions that turn a legal concept into a daily operational discipline. Where figures are required by regulation, we note that they vary by licence category and jurisdiction – we do not invent them.

What Is Client-Money Safeguarding and Who Does It Reach?

Client-money safeguarding is the requirement to ring-fence funds held on behalf of clients so those funds sit outside the general estate of the firm holding them. The principle is old in financial services law. Its application to digital-asset businesses is newer, contested in places and expanding rapidly as regulators align their VASP regimes with the standards they already impose on payment institutions.

The obligation reaches any business that holds client money in the course of providing a financial or payment service. Under MiCA (the Markets in Crypto-Assets Regulation administered by ESMA and national competent authorities across the EU/EEA), authorised crypto-asset service providers that hold client funds must maintain safeguarding arrangements equivalent to those applied under the Payment Services Directive. That means ring-fencing, secure placement and regular reconciliation – not merely good accounting.

Under the VARA regime in Dubai, the relevant rulebooks governing exchange, custody and transfer activities each contain client-asset protection provisions. The FSRA within ADGM applies analogous requirements. In Singapore, MAS under the Payment Services Act imposes explicit safeguarding obligations on major payment institutions holding customer moneys above defined thresholds. The FCA in the UK has applied its Client Assets Sourcebook (CASS) framework to certain cryptoasset-related businesses and has signalled an intent to extend custody rules further as its regime matures.

The common thread across all these regimes is the same: a firm holding client money that is not legally segregated is, from a regulatory standpoint, a firm using client money. That conclusion attracts enforcement regardless of intent.

Operators we advise routinely underestimate the reach of this obligation. A crypto exchange that sweeps client fiat balances into a single omnibus account for operational convenience – even briefly, even for settlement efficiency – may be treating those funds as its own under the applicable safeguarding rules. The reconciliation cadence, the trust or escrow structure used, and the documentation of client entitlements are all scrutinised on examination.

The Cross-Border Problem: Where Does the Obligation Apply?

A digital-asset business rarely holds client money in only one jurisdiction. The entity may be licensed in one location, bank in another, serve clients across multiple countries and hold stablecoin reserves in a third. Each layer can attract a different safeguarding regime – and the regimes do not always align.

Consider the common structure: a VASP licensed under MiCA in Lithuania, banking through a European EMI, serving institutional clients in the Gulf and holding USDT reserves on-chain. The MiCA-authorised entity must comply with the safeguarding requirements of the applicable CASP authorisation. The EMI through which it banks has its own safeguarding obligations under the E-Money Directive and its national transposition. The Gulf clients may be subject to rules under VARA or the FSRA depending on where they are domiciled. None of these regimes defers to the others.

In our cross-border practice, the most common structural failure is the assumption that licensing in one jurisdiction satisfies the safeguarding expectations of the regulators in every jurisdiction where the business operates or has counterparty exposure. That assumption is incorrect. MiCA passporting allows a CASP authorised in one EU member state to operate across the EEA – but the safeguarding obligation travels with the passport. A firm that is compliant in Lithuania is not automatically compliant when its German clients' fiat passes through a non-ring-fenced account held in a non-EU bank.

The cross-border angle sharpens further when a firm maintains banking relationships in jurisdictions with less developed VASP regulation. Banks in those jurisdictions may impose their own contractual requirements about how client funds are held, independent of any regulatory regime. Breach of those requirements can trigger account closure before any regulator has been notified of a problem.

To map the full safeguarding obligation across your entity, banking and user base, contact OBOLUS at info@oboluslaw.com. The analysis above describes the standard framework. Your facts – the entity structure, the licence category, the banking counterparty and the client profile – determine which rules actually apply and which gaps exist.

How Does Safeguarding Interact With an EMI or Payment Licence?

The practical home of client-money safeguarding for most digital-asset businesses is the EMI (electronic money institution) or payment institution layer, because that is where the fiat component of a crypto business typically lives. An EMI holds funds issued as electronic money on behalf of customers; those funds must be safeguarded from the moment of receipt, not when the settlement cycle closes.

Under the E-Money Directive framework as implemented across EU member states, an EMI must either place safeguarded funds in a segregated account at a credit institution, invest them in secure, liquid low-risk assets, or cover them with a suitable insurance policy or bank guarantee. These are not alternatives to be chosen purely on convenience; the EMI's regulator will assess whether the method chosen genuinely protects clients against insolvency risk.

For a VASP seeking to onboard with an EMI, this matters in both directions. The VASP needs to understand what the EMI will and will not do with client fiat on its behalf – because if the EMI is holding the VASP's clients' fiat as the VASP's own float, the safeguarding obligation may have moved to the VASP without the VASP being aware of it. The legal position turns on how the relationship is structured in the account agreement, the nature of the flows and the regulatory classification of the funds in transit.

In a recent matter we handled, a payments company had onboarded with an EMI on terms that treated incoming client fiat as a liability of the VASP rather than a held-on-trust balance. When the VASP's regulator conducted a review, the account structure did not satisfy the ring-fencing requirement of the applicable licence conditions. We restructured the account documentation and updated the reconciliation procedures to bring the arrangement into compliance before an enforcement step was taken. The timeline from identification of the issue to remediation was measured in weeks, not months – but only because the structural defect was caught early.

The lesson is not that EMI onboarding is dangerous. It is that the account documentation must be reviewed by counsel with both the VASP regime and the payment services regime in mind simultaneously. Those are different legal disciplines, and the intersection is where the risk lives.

What Does Safeguarding Require in Practice?

Client-money safeguarding is not a single act. It is a continuous operational discipline with four principal components: segregation, reconciliation, documentation and audit readiness.

Segregation means the funds are held in a legally distinct account – typically a statutory trust account or its equivalent under the applicable regime – that is identified as client money and not available to satisfy the firm's own creditors. The account title, the terms of the banking agreement and the internal ledger entries must all be consistent with this characterisation.

Reconciliation is the process by which the firm confirms, at defined intervals, that the aggregate balance in the segregated account equals the sum of all individual client entitlements as recorded on the internal ledger. Discrepancies must be investigated and resolved promptly. In our practice, we have seen regulators treat a failure to reconcile on schedule as equivalent in seriousness to a failure to segregate – because unreconciled discrepancies are the mechanism by which co-mingling goes undetected.

Documentation covers the internal policies, account agreements, terms of business with clients and any trust deeds or escrow agreements that establish and evidence the ring-fence. In a cross-border structure this documentation must be consistent across each layer of the entity stack. A conflict between the client-facing terms (which may say funds are held on trust) and the banking agreement (which may grant the bank set-off rights against the firm's own obligations) can destroy the ring-fence in practice even where it appears intact on the surface.

Audit readiness means the firm can produce, on short notice from a regulator, a reconciled record of every client balance, the identity of the account(s) in which those funds sit and the legal basis for the ring-fence. For a VASP operating across multiple currencies and on-chain positions, this requires systems investment as well as legal architecture. The regulatory expectation is not that this documentation can be assembled eventually; it is that it exists and is current at every moment.

When Does a Safeguarding Failure Trigger a Disputes Question?

A safeguarding failure becomes a disputes question at the moment a third party – a regulator, a creditor or a client – challenges the firm's right to hold or control the funds in question. At that point, the adequacy of the ring-fence is no longer a compliance matter; it is the central issue in litigation or an insolvency proceeding.

The leading common-law forums – England and Wales, the DIFC Courts, Singapore and Hong Kong – have each addressed questions about the status of client funds held by an insolvent digital-asset firm. The consistent position in those forums is that funds held on a properly constituted trust for clients do not form part of the firm's general estate. Funds that were not properly ring-fenced – because the documentation failed, because the reconciliation was not maintained, or because the operational practice co-mingled client and firm funds – may be treated as unsecured claims against the insolvent estate.

The practical consequence is severe. A client whose funds were not properly safeguarded, in a firm that subsequently became insolvent, is ranked as an unsecured creditor. Recovery from an insolvency estate in a digital-asset business failure, where assets may have been dissipated on-chain or across multiple jurisdictions, is uncertain at best. The legal instrument that changes that outcome is the proper construction of the ring-fence before the crisis occurs.

Where misappropriation rather than insolvency is the issue – where funds are taken by an insider or diverted through fraud – the speed of the legal response is measured in hours. Courts in England and Wales and in the DIFC have granted worldwide freezing orders and disclosure orders in crypto recovery matters on an urgent basis. The CFAAR (Crypto Fraud and Asset Recovery network, launched in London in September 2021) provides a coordination mechanism for cross-border recovery. But none of those tools operates retroactively on funds that were never properly ring-fenced, because it is much harder to demonstrate a proprietary claim to funds that were co-mingled before the fraud occurred.

If a safeguarding concern has already crystallised – a regulator has raised questions, a banking relationship has been suspended or funds are disputed – contact our disputes desk now at info@oboluslaw.com. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums, and time is the variable that matters most.

The Banking Access Dimension: Why Safeguarding Affects Fiat Rails

Client-money safeguarding and banking access are structurally linked, and the failure of one often precipitates the failure of the other. Banks that provide fiat rails to digital-asset businesses are themselves subject to regulatory scrutiny of the accounts they maintain. A bank that cannot satisfy its own regulator that the client funds held in a VASP's account are properly ring-fenced may close that account – not because the VASP has done anything wrong in terms of its own licence conditions, but because the bank's compliance team cannot document the arrangement to its regulator's satisfaction.

This is the mechanism behind the majority of what the industry calls "de-banking" events for crypto companies. The bank's problem is not the crypto activity per se; it is the inability to verify, from the account documentation and transaction flows, that the funds passing through are correctly characterised and safeguarded. A VASP that can produce clean documentation – a trust account designation, a reconciliation framework, an account agreement that does not create set-off rights against client balances – is materially better positioned to retain banking relationships than one that cannot.

In the EMI onboarding context, the same logic applies in reverse. An EMI that onboards a VASP as a corporate client must assess whether the VASP's underlying client-money handling is consistent with the EMI's own safeguarding obligations. An EMI that is indirectly holding client funds of a VASP's clients – because the VASP has not properly segregated those funds before passing the aggregate to the EMI – may find itself exposed to a claim that it is holding client money without the protections required by its own licence conditions.

Operators we advise on EMI onboarding routinely discover that the account documentation offered as standard by the EMI does not address the VASP's specific safeguarding obligations. The EMI's standard terms are drafted for corporate treasury flows, not for a firm that holds client money in a regulated capacity. Negotiating the account agreement to reflect the actual legal position – including the trust characterisation, the reconciliation cadence and the treatment of interest on safeguarded funds – is a step that is frequently skipped and frequently regretted.

A Common Assumption: Does an Offshore Licence Solve the Problem?

A common assumption among digital-asset operators is that an offshore licence – in the BVI, the Cayman Islands or a similarly flexible jurisdiction – resolves the safeguarding question by placing the firm outside the reach of the more demanding regimes. This assumption is incorrect in almost every material respect.

First, the safeguarding obligation follows the client, not the entity. A BVI-registered VASP serving clients who are resident in the EU is, under MiCA, offering crypto-asset services to EU persons. Depending on the nature of those services and the manner of offering, the MiCA authorisation requirement – and with it the MiCA safeguarding standards – may apply regardless of where the entity is incorporated.

Second, the BVI VASP Act 2022 and the Cayman VASP Act both impose conduct requirements on registered entities, including requirements about the handling of client assets. These are not the same as the EU or Singapore requirements, but they exist and they are enforced. An offshore licence is not a regulatory blank cheque; it is a licence within a regime that has its own conduct standards.

Third, and most immediately practical, banking. A VASP incorporated offshore that cannot demonstrate to a correspondent bank that client funds are properly safeguarded will not obtain the fiat rails that its business model requires. The correspondent bank's compliance requirements – driven by its own regulator, which is likely the FCA, the Federal Reserve or another major authority – apply irrespective of where the VASP is incorporated. The safeguarding documentation must satisfy those requirements even when the VASP's home jurisdiction does not mandate them.

In our cross-border practice, the right structure for a multi-jurisdictional digital-asset business is almost never a single entity in a single jurisdiction. It is a stack: a CASP or VASP entity in the appropriate licence jurisdiction, a payment or EMI entity for the fiat layer, a custody entity where required, and documentation that ties all three together in a way that satisfies each applicable regime. We map that stack before the client commits to a structure, not after the banking relationship has been closed.

Decision Matrix: Which Safeguarding Approach Fits Which Operator?

Different operator profiles face materially different safeguarding obligations, and the appropriate approach varies accordingly. The following analysis maps the principal profiles to the instruments and considerations relevant to each.

A crypto exchange holding client fiat balances pending execution faces the most demanding safeguarding requirement. Client fiat is received, held and returned in the course of a regulated service. Under MiCA, the VARA rulebooks and the MAS Payment Services Act, this activity requires either CASP/VASP authorisation with safeguarding conditions or, in some regimes, a separate payment institution licence. The exchange must maintain a segregated trust account, reconcile daily and document each client's entitlement. The key risk is the gap between receipt and placement: funds received but not yet placed in the segregated account are, in most regimes, already subject to the safeguarding obligation from the moment of receipt.

A crypto custodian holding client assets – whether fiat, digital assets or both – operates under a custody regime rather than a pure payment services regime, but the segregation principle is the same. FINMA in Switzerland, the SFC in Hong Kong and the FCA in the UK each apply custody-specific requirements to the ring-fencing of client assets. A custodian that also holds fiat pending reinvestment or withdrawal must satisfy both the custody and the payment safeguarding standards simultaneously.

A token issuer raising fiat proceeds against a token offering faces a different question. The proceeds of a token sale are not, in most regimes, client money in the payment services sense – they are capital raised by the issuer. But where the issuer holds back a portion for refund obligations (as the ART and EMT reserve requirements under MiCA contemplate), those reserved funds attract explicit safeguarding obligations. The issuer must ring-fence the reserve, invest it in approved instruments and maintain records demonstrating continuous compliance.

A Web3 business using third-party rails – relying on an EMI or payment processor to handle client fiat – may believe it has delegated the safeguarding obligation entirely. It has not. The firm's responsibility is to ensure that the arrangement with the third party genuinely produces a ring-fence for clients' benefit, not merely a contractual promise to that effect. If the EMI fails and the VASP's clients are unsecured creditors of the EMI rather than beneficiaries of a ring-fenced trust, the VASP may face claims from its own clients for failing to ensure their funds were protected.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts most often because they cannot satisfy their own regulator that the funds flowing through the account are properly characterised and safeguarded. The bank's compliance team needs to see clean documentation – segregated account structures, reconciliation records and an account agreement that does not create set-off rights against client balances. A VASP that cannot produce that documentation presents an unresolvable compliance risk from the bank's perspective, irrespective of the VASP's own licence status. The fix is structural, not merely conversational.

How can a VASP onboard with an EMI?

A VASP can onboard with an EMI by presenting a clear compliance profile: a current VASP or payment licence, documented AML/KYC procedures, an account structure proposal that reflects the VASP's safeguarding obligations, and transaction flow projections with source-of-funds analysis. The EMI's standard onboarding terms frequently do not address the VASP's specific safeguarding requirements, so the account agreement typically requires negotiation. Allied counsel in the relevant jurisdiction can assist with both the compliance presentation and the account documentation review.

What does client-money safeguarding require?

Client-money safeguarding requires four things: segregation of client funds into a legally distinct account held on trust or equivalent; reconciliation of that account against individual client entitlements at defined intervals; documentation establishing the ring-fence across the entity, banking and contractual layers; and audit readiness so the regulator can verify compliance on demand. The specific requirements vary by licence category and jurisdiction under MiCA, the VARA rulebooks, the MAS Payment Services Act and other applicable regimes. Failing any one of the four components can be treated as a breach of the whole obligation.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before clients commit to a structure, and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when a recovery clock is running. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory and Compliance Analyst – specialising in VASP licensing, client-asset protection obligations and cross-border regulatory compliance for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours