Obtaining fiat rails is the operational bottleneck most VASPs (virtual asset service providers) underestimate. An exchange, custodian or payments desk can hold a sound licence and a clean compliance programme and still find every EMI (electronic money institution) application rejected – because the documentation package, the corporate structure or the jurisdiction mix triggers a risk-appetite veto before a relationship manager reads past page two. With EMI onboarding for crypto businesses tightening across the major hubs, the cost of a failed application is not just the wasted fee. It is the operating quarter lost while competitors capture the market.
This guide sets out the onboarding process step by step. Each step names the legal basis, the cross-border complication and the mistake that kills applications at that stage. The goal is a durable fiat-rails relationship, not a provisional account that closes at the first annual review.
Step 1: Understand What an EMI Actually Assesses Before You Apply
An EMI's decision to onboard a VASP is a risk-appetite decision first and a compliance decision second. Before any document is submitted, the applicant needs to map exactly where the EMI sits on the crypto-risk spectrum – because the legal basis for rejection is rarely stated plainly. Most EMI refusals are not formal regulatory decisions; they are commercial declinations framed as compliance outcomes. The distinction matters for how a reapplication is structured.
EMIs operating under the Payment Services Directive framework in the EU, and institutions registered with the FCA (Financial Conduct Authority) in the UK, are required to manage financial-crime risk under the applicable anti-money laundering regime. For a VASP customer, that means the EMI must understand the VASP's own AML posture, its licence status and its customer base before it can price the relationship into its own risk model.
In our cross-border practice, we routinely see operators assume that a licence – a MiCA CASP authorisation, a VARA activity licence, a BVI VASP Act registration – is self-explanatory to a banking compliance team. It is not. The compliance analyst reviewing your application may be experienced in payments but not in the specific regime under which you are authorised. Your onboarding pack must translate your licence into terms a payments-sector risk officer understands without needing to research your regulator first.
The cross-border complication at this step is entity geography. An EMI regulated by ESMA's national competent authorities will view a VASP incorporated in the Cayman Islands differently from one authorised under MiCA in an EU member state. Neither is automatically disqualifying – but the compliance team's default question is whether they can verify the supervision at all. If the answer requires them to map an unfamiliar regime, the path of least resistance is a polite decline.
Common mistake: Submitting an application before conducting a structured risk-appetite pre-screen. A single call with the EMI's compliance or onboarding team – before a formal file is opened – can reveal whether the relationship is viable at all, saving weeks of preparation cost.
Step 2: Structure the Legal Entity Before Approaching an EMI
The entity you present to an EMI is the primary risk unit under assessment, and the wrong structure will defeat an otherwise strong application. EMIs onboard legal entities, not business models. The entity's jurisdiction of incorporation, its ownership chain, its directors' residency and its licence status must all cohere into a picture that the EMI's compliance team can verify and document for its own regulator.
A VASP operating out of a single offshore holding company – even one with a valid licence – will face scrutiny over beneficial-ownership transparency. FATF Recommendation 15 on virtual assets, and its application through each jurisdiction's national AML regime, requires the EMI to conduct customer due diligence on the VASP as a business customer. Complex, multi-layer holding structures with opaque beneficial ownership are the fastest route to a file being flagged for enhanced due diligence – or closed.
The entity design question is also a tax and banking question simultaneously. The jurisdiction that minimises regulatory friction for EMI onboarding may not be the same jurisdiction that minimises withholding tax on payment flows or that offers the strongest custody infrastructure. We map the licence, banking and tax stack as a single structure, because optimising each in isolation routinely produces conflicts that surface only when the first account application is reviewed.
Cross-border note: where a VASP has users across multiple jurisdictions – EU customers served from a Singapore entity, for example – the EMI will want to understand which regulatory regimes govern those users and how the VASP manages cross-border AML compliance. A structure that looks clean from a single-jurisdiction perspective may appear fragmented or unregulated from the EMI's vantage point.
Common mistake: Forming the operating entity in a low-cost offshore jurisdiction to reduce incorporation time, then approaching EU or UK EMIs. The absence of a local licence or substantive local presence will almost invariably trigger a risk-appetite veto, regardless of how strong the AML programme is.
To map the licence, banking and tax stack for your build, write to info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options
Step 3: Prepare the Compliance Documentation Pack
A complete, pre-assembled compliance documentation pack is the single factor most likely to accelerate an EMI onboarding process, because it removes the back-and-forth that stalls applications at the diligence stage. The pack is not a collection of corporate documents; it is a structured risk narrative built around the documents.
The core categories in a VASP onboarding pack for an EMI are: corporate structure and ownership documentation; licence certificates and regulatory correspondence; the AML/CFT policy and procedures (current version, dated); the KYC and transaction-monitoring framework; a business plan covering revenue model, customer segments and projected transaction volumes; and evidence of the beneficial owners' source of wealth.
The Travel Rule (the obligation under FATF standards to pass originator and beneficiary data with a virtual-asset transfer) deserves specific attention. EMIs are increasingly asking VASPs to demonstrate Travel Rule compliance as a condition of onboarding – not as a future obligation, but as an existing operational practice. A VASP that cannot name its Travel Rule solution, or that is still operating in a jurisdiction where the rule has not yet been implemented domestically, will struggle to satisfy an EMI whose own regulators require it to understand the counterpart's AML posture fully.
Cross-border note: the jurisdiction in which the EMI is regulated will determine the depth of documentation it can request. An EMI under the MiCA/ESMA framework or the FCA regime will operate under a detailed set of customer due-diligence expectations. An EMI regulated by a less prescriptive framework may be lighter on formal requirements but heavier on informal relationship-building. The pack must be calibrated to the specific EMI's regulatory context.
Common mistake: Submitting a generic AML policy downloaded from a template library. Compliance teams are experienced readers. A policy that does not name the VASP's specific customer risk categories, its transaction-monitoring thresholds or its escalation procedure for virtual-asset-specific red flags will signal operational immaturity – and an immediate request for supplementary information, or a rejection.
Step 4: Engage the EMI Through a Structured Pre-Application Process
The formal application is the final step in a relationship-building process, not the opening move. EMIs that serve VASPs have internal onboarding teams that operate under tight capacity constraints. A cold application with no prior contact is processed in queue order, with no advocate inside the institution. A structured pre-engagement – an introductory call, a brief summary deck, a direct line to an onboarding manager – changes the dynamic materially.
In our practice, we have seen operators approach EMIs through three routes: direct outreach by the VASP's legal or compliance team; introduction through a specialist intermediary; and formal application through an EMI's published onboarding portal. The third route – cold portal submission – produces the longest processing times and the highest rejection rates for crypto businesses. The first and second routes, properly managed, compress the timeline because the EMI's risk team has already formed a preliminary view before the formal file is opened.
The pre-engagement conversation should cover the VASP's licence status, its customer base by geography and type, its expected transaction volumes and its existing banking relationships. The last point matters. An EMI will want to understand whether it is the primary banking partner or one of several – because a VASP that is shopping widely after multiple closures presents a different risk profile from a VASP selectively building a banking stack for the first time.
Cross-border note: the pre-engagement strategy must account for the EMI's own regulatory position. An EMI licensed in Lithuania or Malta under the transitional MiCA framework may have different risk appetite from a Cayman-registered payment institution or a UK-FCA-registered EMI. Understanding the EMI's own supervisory context is part of the pre-engagement intelligence-gathering.
Common mistake: Treating the pre-engagement stage as optional. Operators who skip it and submit a cold application rarely receive substantive feedback when the application is declined. Without a relationship, there is no dialogue – and no route to understanding what would need to change for a reapplication to succeed.
Step 5: Respond to Due-Diligence Requests Promptly and Completely
Once a formal application is open, the EMI's compliance team will issue due-diligence requests. The speed and completeness of the VASP's responses is the primary variable within the VASP's control at this stage. Delays in responding – even by a few days – reset the reviewer's priority queue and can extend timelines materially.
Every due-diligence request should be answered in full, in a single response, with documents clearly labelled and cross-referenced to the question asked. Partial responses that require follow-up questions indicate disorganisation to the reviewer and consume capacity. The EMI's compliance analyst is assessing the VASP not just on its formal compliance posture but on its operational reliability as a future customer.
A common category of request at this stage is enhanced diligence on transaction patterns. The EMI may ask for historical transaction data, a breakdown of customer geography and a description of the highest-risk customer segments. VASPs that have operated without formal AML documentation of their transaction-monitoring decisions will find this stage difficult. Retroactively constructing transaction records is both legally precarious and practically unconvincing to an experienced compliance reviewer.
Cross-border note: where the VASP has operated under more than one licence – for example, holding both a VARA activity licence for UAE operations and a BVI VASP Act registration for broader offshore business – the EMI may ask for both regulatory histories, including any regulatory correspondence or supervisory findings. Inconsistencies between the two records need to be explained proactively, not defensively.
Common mistake: Treating the due-diligence stage as adversarial. The EMI's compliance team is trying to satisfy its own regulatory obligations, not defeat the applicant. A cooperative, transparent approach – including proactive disclosure of any regulatory findings or past account closures – builds confidence. Incomplete disclosure discovered later is grounds for immediate termination of the relationship.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Contact OBOLUS at info@oboluslaw.com. Map your options
Step 6: Negotiate Account Terms and Understand Safeguarding Obligations
Account terms with an EMI are not boilerplate. The commercial and legal provisions in an EMI agreement – transaction volume limits, permitted asset classes, acceptable customer geographies, the EMI's right to terminate on notice and the safeguarding structure for client funds – directly affect the VASP's operating model and its own regulatory compliance.
Safeguarding is the most legally consequential provision. EMIs holding client funds are required, under the applicable payment-services regime, to safeguard those funds through segregation or a comparable protection mechanism. For a VASP whose customers hold fiat balances while transacting in digital assets, the safeguarding structure at the EMI level has a direct impact on the VASP's own client-money obligations under its licence.
The right of the EMI to terminate the agreement on short notice – typically without stating a reason under commercial-contract principles – is a structural risk for any VASP that depends on a single EMI relationship. A termination without notice causes an immediate disruption to fiat settlement capacity. Operators we advise routinely build a minimum of two active EMI relationships to provide operational resilience, recognising that account closures in the crypto-banking segment remain common.
Cross-border note: where the VASP holds a licence in one jurisdiction and the EMI is regulated in another, the governing law of the account agreement – and the jurisdiction for dispute resolution – need to be assessed carefully. A VASP incorporated in the UAE holding an account with a Lithuanian EMI faces a different legal exposure on a contested termination than if both parties are in the same jurisdiction.
Common mistake: Signing EMI account terms without legal review on the basis that all EMIs use standard documentation. They do not. The termination clause, the permitted-use provisions and the restrictions on customer geography are negotiating points that have significant operational consequences. Review before signature, not after the first restriction notice.
Step 7: Maintain the Relationship After Onboarding
Onboarding approval is the beginning of an ongoing compliance relationship, not the resolution of a one-time problem. EMIs conduct periodic reviews of their VASP customers – typically aligned with annual AML cycles – and the quality of those reviews determines whether the relationship continues.
A VASP that obtained its account on the strength of a well-prepared initial pack but failed to maintain its compliance documentation, to update its licence status after a regulatory change or to notify the EMI of material changes to its business model will face the same risk-appetite scrutiny at annual review that it faced at onboarding. The difference is that a post-onboarding closure is operationally more disruptive than a pre-onboarding rejection.
In our practice, we have seen accounts closed at annual review following: a change in the VASP's beneficial ownership that was not proactively disclosed; a regulatory finding by the VASP's home supervisor that was not communicated to the EMI; and a material increase in transaction volumes in high-risk geographies without a corresponding update to the AML programme. Each of these is avoidable with a structured compliance-maintenance protocol.
Cross-border note: where the VASP's regulatory environment changes – a new MiCA CASP authorisation replacing a prior transitional registration, or a new VARA licence category applying to an activity the VASP already conducts – the EMI should be notified proactively. Regulators in the leading hubs increasingly expect EMIs to maintain current documentation on their VASP customers. An outdated file creates risk for the EMI and, transitively, for the account relationship.
Common mistake: Treating the account as permanent once established. No banking relationship in the crypto segment is permanent. A structured annual compliance-review protocol, covering licence status, ownership structure, transaction patterns and regulatory correspondence, is the operational minimum for maintaining access to fiat rails over the medium term.
In a recent matter involving a payments-focused VASP, we identified during an annual compliance audit that a change in the company's ownership structure had not been reflected in the EMI documentation for nearly two years. We prepared a proactive disclosure package and accompanied the VASP through the EMI's enhanced-review process. The account relationship was preserved, and the VASP updated its compliance protocol to ensure future changes are notified within a defined period.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – the full practice area overview covering account strategy, structure and retention.
- Client Funds Safeguarding in South Korea – how safeguarding obligations interact with VASP licensing in the Korean market.
- Staking and Rewards Taxation in Nigeria – tax treatment of digital-asset income where fiat settlement is a regulatory flashpoint.
FAQ
Why do banks close crypto company accounts?
Banks and EMIs close crypto company accounts primarily because the VASP's risk profile exceeds the institution's risk appetite or because the VASP's compliance documentation fails to satisfy the institution's AML obligations. Common triggers include undisclosed changes in ownership, transaction patterns inconsistent with the stated business model, a regulatory finding by the VASP's home supervisor or an inability to demonstrate Travel Rule compliance. The closure decision is almost always commercial rather than regulatory – the institution is managing its own exposure, not making a finding about the VASP's conduct.
How can a VASP onboard with an EMI?
A VASP onboards with an EMI by presenting a complete, correctly structured application that addresses the EMI's specific risk-appetite concerns. The process requires a properly licenced legal entity, a current and VASP-specific AML/CFT programme, demonstrable Travel Rule compliance, and a pre-engagement strategy that builds a relationship before the formal file is submitted. Matching the application to the EMI's regulatory context – whether that is the MiCA regime, the FCA's MLR framework or another applicable regime – materially improves the outcome.
What does client-money safeguarding require?
Client-money safeguarding requires that funds belonging to customers are held in a manner that protects them from the institution's own insolvency. For EMIs operating under the applicable payment-services regime, this means either segregating client funds in a dedicated account at a credit institution or covering them with an equivalent insurance or guarantee. For a VASP relying on an EMI for fiat settlement, the safeguarding structure at the EMI level directly affects the VASP's own obligations to its customers under its licence. The specific requirements vary by jurisdiction and licence category.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit – so the structure you build is the one your banking partners can work with. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP licensing, EMI onboarding strategy and cross-border AML compliance for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.