For a crypto firm, securing fiat rails is often harder than obtaining a licence. Banks and electronic money institutions (EMIs – regulated entities licensed to hold and move fiat on behalf of clients) apply enhanced due diligence to digital-asset businesses as a matter of policy, not exception. The result: a well-structured exchange or custodian with a valid VASP (virtual asset service provider) authorisation can still find itself without a working bank account months after launch. This guide sets out each practical step to open a corporate bank account as a crypto firm – the regulated basis at each stage, the cross-border considerations, and the mistake that kills most applications before they are assessed on their merits.
The process requires preparation that begins before the first outreach to a financial institution. Firms that treat banking as an afterthought – something to arrange after the licence is in hand – consistently face delays, rejections and the operational risk of having no functioning fiat corridor at all. Loss of banking is one of the most disruptive events a digital-asset business can face. It freezes client onboarding, halts revenue and triggers cascading compliance obligations. Structuring the approach correctly from the outset is not optional.
Why Crypto Firms Face Structural Banking Friction
Banks and EMIs decline crypto clients not because digital assets are inherently impermissible, but because the risk-management cost of on-boarding a VASP is perceived to exceed the commercial return. Regulators in every leading hub – the Financial Conduct Authority (FCA) in the UK, the European Banking Authority working alongside national competent authorities under MiCA, and VARA in Dubai – have acknowledged the problem without fully resolving it. The practical effect is that crypto firms operate in an environment where the supply of willing banking partners is structurally constrained.
Several specific factors drive the friction. First, AML/CFT exposure: a crypto firm's transaction flows involve pseudonymous counterparties, cross-border transfers and, in many cases, assets whose provenance requires forensic analysis. Banks apply the FATF Recommendations – including the Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual-asset transfer) – through their own risk frameworks, which are typically more conservative than regulatory minimums. Second, reputational risk: association with a firm later found to have facilitated illicit flows creates regulatory and press exposure that a bank's compliance committee is paid to avoid. Third, correspondent bank pressure: even a bank that is willing to hold a crypto client's account may face restrictions from its own correspondent banking relationships.
Understanding this structure tells you what a successful application must achieve: it must reduce the bank's perceived risk to a level below its internal threshold. Every step below is directed at that objective.
Step 1: Get the Licensing Layer Right Before You Approach a Bank
No bank or EMI will open an account for a crypto firm that lacks the relevant authorisation in its operating jurisdiction – and the right licence matters as much as having one at all. Under MiCA, a CASP (crypto-asset service provider) authorisation from one EU member-state national competent authority permits passporting across the EU/EEA. That single authorisation significantly improves the banking conversation in continental Europe because it signals regulatory oversight to the prospective bank's compliance function.
In the UAE, a VARA licence in Dubai covers mainland activities, while an FSRA authorisation under the ADGM regime applies within Abu Dhabi Global Market. A firm operating in both geographies needs to be clear about which entity holds which permission – and which banking relationship supports which entity. Conflating them in the application is a common and costly mistake.
The cross-border note here is critical. A firm incorporated in the BVI under the VASP Act 2022, licensed in Lithuania under the Bank of Lithuania's transitional regime, and serving EU retail clients is a different risk profile from a VARA-licensed Dubai entity with institutional counterparties. Banks assess the combination of domicile, licence and client base – not just the licence in isolation.
Common mistake at Step 1: Applying to banks before the licence is issued, on the assumption that a conditional or in-progress authorisation is sufficient. It is not. The application will be declined or shelved, and the firm will have consumed its best opportunity to make a first impression.
Step 2: Select the Right Type of Financial Institution
Corporate banking for crypto firms is available from three categories of institution, and the right choice depends on the firm's transaction profile, client base and jurisdiction of incorporation.
Traditional banks – including those licensed under national banking laws in the EU, the UK, Switzerland and Singapore – offer the widest payment network access and the most credible correspondent relationships. They are also the most conservative in their crypto on-boarding. A firm with a FINMA-registered Swiss entity, a clean compliance record and institutional clients has a reasonable prospect of a traditional bank relationship. A startup exchange with retail clients and high transaction volumes faces a much harder conversation.
EMIs – entities holding an electronic money licence under the EU's Electronic Money Directive or equivalent regimes – are the more accessible on-ramp. EMIs operate faster on-boarding processes and are generally more experienced with digital-asset clients. However, EMI accounts typically carry limitations: transaction volume caps, restricted payment corridors and, in some cases, absence from the SWIFT network. For a firm needing to move significant fiat volumes cross-border, an EMI may be a bridge rather than a permanent solution.
Payment institutions and fintech banks licensed under the UK Payment Services Regulations, the EU Payment Services Directive or equivalent regimes occupy a middle ground. Some have developed specific crypto on-boarding tracks, particularly in the Baltic states, Malta and certain Central European markets.
Cross-border note: A firm that needs fiat rails in multiple currencies across multiple jurisdictions will typically require more than one banking relationship. Planning for a primary account and at least one backup – ideally in a different jurisdiction – is standard risk management for any digital-asset business of meaningful scale.
Common mistake at Step 2: Targeting the largest, most prominent bank in a jurisdiction on the assumption that scale equals appetite for crypto clients. In practice, the largest institutions are often the most restrictive. Firms that have done the market research – identifying which institutions have an active crypto on-boarding track – move materially faster.
Step 3: Build the Compliance Package Before First Contact
Banks and EMIs conducting enhanced due diligence on a crypto firm will request a compliance package. Assembling this in advance – rather than responding to requests piecemeal – shortens the process and signals operational maturity. The package typically includes the following elements.
Corporate documentation: certificate of incorporation, register of directors, register of members, constitutional documents and any trust or nominee declarations. For a firm with a complex structure – a holding company in the Cayman Islands, an operating subsidiary in Malta and a technology entity in Singapore, for example – the bank will want to see the entire structure chart with ownership percentages and ultimate beneficial ownership confirmed at each level.
Regulatory standing: copies of all licences and authorisations, correspondence with the regulator confirming good standing, and any conditions attached to the licence. Under MiCA, the CASP authorisation from the relevant national competent authority is the primary document. A firm also supervised by ESMA-coordinated processes should include that correspondence.
The AML/CFT programme: the firm's written AML policy, the KYC/CDD procedures, the Travel Rule compliance methodology, the sanctions screening process and the suspicious activity reporting structure. Banks apply particular scrutiny to the Travel Rule compliance methodology – how the firm collects, verifies and transmits originator and beneficiary data under the FATF Recommendations. A policy document that does not address Travel Rule specifically will raise questions.
Business model description: a clear, plain-language description of what the firm does, who its clients are, what the expected transaction volumes and values are, and which jurisdictions it operates in. This document is read by the bank's compliance team, not its technical staff. It must be precise, accurate and free of marketing language.
Source of funds: evidence of how the business itself is funded – investor documentation, capital injection records, loan agreements. A crypto firm funded by token proceeds needs to be prepared to explain that in detail.
Common mistake at Step 3: Providing an AML policy that was drafted for the regulatory application and never updated. Banks are sophisticated enough to identify a policy that does not reflect the firm's actual operations. A Travel Rule methodology that covers the theory but omits the firm's specific technical implementation – whether via a VASP-to-VASP messaging protocol or a third-party Travel Rule solution – will draw scrutiny and likely requests for clarification that extend the process.
Step 4: Structure the First Contact and Manage the On-Boarding Process
The first contact with a bank or EMI sets the frame for the entire on-boarding process. A cold application submitted through an online portal, without prior relationship development or intermediary introduction, is the lowest-probability approach for a crypto firm. A structured introduction – through legal counsel, a known intermediary or a direct relationship with the bank's financial institutions or fintech desk – consistently produces better outcomes.
In our cross-border practice, we have seen applications from well-structured crypto firms declined at the initial screening stage because the submission arrived through the wrong channel and was assessed by a generalist compliance officer with no crypto-specific experience. The same firm, reintroduced through a financial institutions relationship, cleared enhanced due diligence in a fraction of the time.
The on-boarding process itself, once initiated, typically involves: an initial compliance review; a request for the compliance package described in Step 3; one or more calls with the bank's AML or financial crime team; a formal credit or commercial committee review; and, in some cases, a site visit or management interview. The sequence and depth vary by institution and by jurisdiction.
A worldwide freezing order (an injunction freezing a defendant's assets globally, issued by a court with relevant jurisdiction) is a risk that a crypto firm must disclose if one is in force against it. Any undisclosed litigation, regulatory investigation or enforcement action that surfaces during on-boarding will end the process immediately.
Common mistake at Step 4: Treating the on-boarding process as a one-way information request. The most effective applicants treat it as a dialogue – proactively flagging potential questions, offering additional documentation before it is requested and establishing a named point of contact at the bank for follow-up. Passive applicants wait for the bank to revert; active applicants manage the process.
Step 5: Address Client-Money Safeguarding Requirements
For a crypto firm that holds client fiat – an exchange, a custodian or an OTC desk – client-money safeguarding is a separate and regulated requirement that the banking structure must support. Under the EU's MiCA regime and its interaction with the Payment Services Directive, regulated entities holding client funds are required to maintain those funds in a designated safeguarding account, segregated from the firm's own assets.
The bank or EMI must therefore be willing to operate a segregated client-money account, not merely a corporate operating account. Not every institution that will bank a crypto firm is willing to provide a segregated client-money structure. Identifying this capability at the outset of the bank selection process avoids the common scenario where a firm secures an operating account but cannot open the client-money structure it needs to operate.
In jurisdictions such as Liechtenstein, where the Token and Trusted Technology Service Provider Act (TVTG) creates a specific legal framework, client-funds safeguarding interacts with both banking regulation and the token-law regime. The practical implication for a firm with Liechtenstein operations is that the banking structure must satisfy both the TVTG safeguarding expectations and the requirements of the applicable Liechtenstein bank.
Cross-border note: A firm operating across multiple jurisdictions may need separate safeguarding accounts in each jurisdiction where it holds client fiat, depending on the regulatory requirements that apply. Centralising client money in a single account in a single jurisdiction is structurally simpler but may not satisfy the requirements of regulators in each market the firm serves.
Common mistake at Step 5: Assuming that a general corporate account doubles as a client-money account. It does not, and operating on that basis creates regulatory exposure in virtually every jurisdiction that mandates safeguarding – which now includes the major EU markets under MiCA and the UK under the FCA's client assets regime.
A Recent Engagement: EMI On-Boarding for a Cross-Border Payments Firm
In a recent matter, a payments company holding a CASP authorisation in one EU member state sought to open EMI-supported fiat accounts in three jurisdictions simultaneously. The initial applications were declined at the AML screening stage, primarily because the firm's Travel Rule methodology did not address the treatment of transfers involving non-VASP counterparties. We reviewed the compliance package, identified the gap, and helped restructure the AML programme to address the specific concern. The firm then reapproached two of the three EMIs through a financial institutions introduction. Both accounts were opened within a matter of weeks of the reapproach. The third EMI was replaced with a payment institution in a different market that had an active crypto on-boarding track. The firm now operates fiat rails in all three target jurisdictions.
Step 6: Plan for Account Continuity and the De-Risking Scenario
Opening an account is not the end of the process. Banks and EMIs periodically re-underwrite their crypto clients. A change in the firm's business model, an adverse regulatory development, a change in the bank's own risk appetite or a correspondent banking restriction can trigger account closure with limited notice.
Firms that have planned for this – by maintaining relationships with two or more financial institutions, by structuring their operations so that no single banking relationship is a single point of failure, and by keeping their compliance documentation current – absorb the disruption of an account closure far more effectively than those that have not.
The de-risking scenario is particularly common when a crypto firm scales rapidly. A transaction volume that was acceptable at on-boarding may exceed the bank's risk appetite six months later. Proactive communication with the bank's financial institutions team about volume growth – rather than allowing a monitoring alert to trigger the review – is consistently more effective.
Cross-border note: A firm whose banking structure spans multiple jurisdictions should be aware that a regulatory development in one jurisdiction can create pressure on banking relationships in another. An enforcement action by the FCA, for example, may prompt an EMI in Lithuania or Malta to re-examine its relationship with a firm that has UK-facing operations. The jurisdictional interdependencies are real and must be managed actively.
Common mistake at Step 6: Treating banking as a solved problem once an account is open. In our experience advising crypto exchanges and custodians, account continuity requires ongoing relationship management, compliance updates and proactive communication – not a one-time application effort.
The process above describes the standard path. Your facts – the entity structure, the user base, the banking jurisdictions – change the analysis materially. For a scoped assessment of your banking structure and EMI on-boarding options, contact OBOLUS at info@oboluslaw.com.
When a Payment Licence Changes the Equation
Some crypto firms find that the most effective route to stable fiat rails is not to seek banking as a client, but to obtain a payment licence (an authorisation to provide payment services directly, without relying solely on a third-party bank or EMI). A payment institution licence under the EU's Payment Services Directive, or an equivalent authorisation under the UK's Payment Services Regulations, allows a firm to access payment infrastructure more directly and with greater operational control.
This is not the right solution for every firm. The authorisation process is distinct from a VASP or CASP authorisation and requires its own capital, compliance programme and regulatory engagement. For a firm already managing the demands of a VASP licence, adding a payment institution application is a material additional commitment. But for firms at sufficient scale – where the cost of maintaining multiple banking relationships and absorbing periodic de-risking events exceeds the cost of the licence – it is a structurally sound option.
In our practice, we regularly advise firms considering this route on whether the payment licence model fits their transaction profile and whether their existing compliance infrastructure can support the additional regulatory obligations. The answer is fact-specific. A firm running a custodian operation with limited payment flows is a different candidate from an exchange processing high-volume retail fiat-to-crypto conversions daily.
The interaction between a payment licence and the firm's existing CASP or VASP authorisation is also jurisdiction-specific. Under MiCA, the CASP regime and the payment services regime are distinct, and a firm may need both. Under VARA in Dubai, the licensing regime is activity-based and the interaction with payment services rules requires careful mapping.
A Common Assumption That Costs Firms Time and Money
A common assumption among founders and CFOs building a digital-asset business is that a single offshore licence – a BVI VASP registration or a Cayman CIMA authorisation, for example – is sufficient to serve clients globally and secure banking relationships in any jurisdiction. It is not. Banks and EMIs in the EU, the UK, Singapore and Switzerland apply their own analysis of whether the firm's licensing structure satisfies the regulatory expectations of the jurisdictions where its clients are located, where its fiat flows originate and where its operations are conducted.
An offshore registration that is not accompanied by the appropriate authorisation in the firm's primary operating markets will not satisfy a European bank's compliance team. The bank is not simply checking whether the firm has a licence somewhere – it is assessing whether the firm is regulated appropriately for the business it is actually conducting. A firm serving EU retail clients without a MiCA CASP authorisation, relying instead on a BVI registration, faces a materially harder banking conversation in Europe – regardless of the quality of its compliance programme.
We map the licence stack across operating, custody and payment layers before our clients commit to a structure. The banking conversation is not separate from the licensing decision – it is an integral part of it.
If a prior application stalled or a banking relationship was closed, a second read of the structure can surface the underlying reason and identify the route forward. Write to OBOLUS at info@oboluslaw.com or message via t.me/oboluslaw.
Related at OBOLUS
- Banking, Payments and EMI On-Boarding for Digital-Asset Businesses – how OBOLUS structures fiat-rail access for crypto firms across jurisdictions
- Client-Funds Safeguarding in Liechtenstein – TVTG safeguarding obligations and banking interaction for Liechtenstein-based digital-asset entities
- On-Chain Asset Tracing: The Structuring Angle – how corporate structure affects asset recovery and disclosure orders in disputes
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because the firm's risk profile has changed, transaction volumes have exceeded the bank's internal thresholds, or the bank's own correspondent banking relationships have been restricted. Regulatory developments – an enforcement action against a firm in the same sector, a change in the regulator's guidance – can also trigger a risk-appetite review that results in account closure. A crypto firm with multiple banking relationships and current compliance documentation is materially better positioned to absorb this than one reliant on a single account.
How can a VASP onboard with an EMI?
A VASP seeking EMI on-boarding must present a complete compliance package including its regulatory authorisation, AML/CFT programme, Travel Rule methodology, business model description and source-of-funds documentation. EMIs conduct enhanced due diligence on digital-asset clients and will assess the firm's compliance maturity, not merely its licence status. An introduction through legal counsel or a known intermediary – rather than a cold portal application – consistently improves the outcome. The process timeline varies by EMI and jurisdiction; firms should plan for a process measured in weeks, not days.
What does client-money safeguarding require?
Client-money safeguarding requires a crypto firm that holds client fiat to maintain those funds in a designated account that is legally and operationally segregated from the firm's own assets. Under MiCA and the applicable EU payment services rules, the safeguarding account must be held with an authorised credit institution or deposited in qualifying liquid assets. The bank or EMI must be specifically willing to operate a segregated structure – not merely a corporate account. The exact requirements vary by jurisdiction and by the regulatory regime under which the firm is authorised.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise crypto exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the banking, payment and compliance structures that sit around them. We map the licence stack across operating, custody and payment layers before clients commit to a structure. We have advised on crypto banking on-boarding challenges across EMI and payment institution relationships in multiple markets. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialises in VASP/CASP licensing and compliance programme design for digital-asset businesses seeking banking and payment access across multiple jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.