The De-risking Reality for Digital-Asset Businesses
A de-risking account closure is a bank's or electronic money institution's unilateral decision to exit a customer relationship – not because of proven wrongdoing, but because the institution judges that the category of business carries compliance costs or reputational exposure it is unwilling to absorb. For crypto exchanges, custodians, token issuers and payment firms, de-risking has become one of the most disruptive operational hazards in the market. Fiat rails go dark. Payroll, settlement and client-money flows freeze. The downstream licensing implications can accelerate faster than the legal response. The steps below give your team a structured path from receipt of the closure notice to a restored, diversified banking stack – without relying on guesswork or a single-institution fix.
Acting within the first 48 hours determines how much of your operating position you preserve. The regulated basis for the closure, the jurisdiction of the institution, and the structure of your existing licences together define which channels are open to you. A business that treats this as a pure banking problem will lose ground; one that treats it as a legal and structural problem will find solutions faster.
This guide walks through seven sequential steps. Each carries the applicable regime context, the cross-border considerations that most operators face, and the most common mistake at that stage.
Step 1: Secure the Notice and Diagnose the Legal Basis
The moment a de-risking closure notice arrives, preserve every document and identify the stated – and unstated – regulatory basis before you do anything else. Institutions generally cite one of three grounds: a policy-level exit from a defined category of business (sector de-risking), a finding arising from an AML review, or a licensing-gap concern triggered by the applicable anti-money-laundering regime in their jurisdiction. Understanding which applies determines your next move.
In practice, many notices are terse. They invoke broad contractual rights and name no specific finding. That terseness is itself significant: it signals a category exit rather than an individual finding, which means the path forward is a structural one rather than a remediation one. Demand, in writing, the specific reason code and the effective date of closure. Most institutions are obliged under their home regulatory regime – whether under the Money Laundering Regulations in the UK, or the applicable AML provisions in an EU member state under the anti-money-laundering directives – to respond to a reasonable request for information about the decision. The response (or its absence) becomes evidence.
Cross-border note: If the closing institution is domiciled in a jurisdiction different from your operating entity – a common configuration for crypto businesses that bank offshore – the notice may trigger obligations in multiple jurisdictions simultaneously. A UK-registered business banking with a Lithuanian or Maltese EMI faces overlapping MiCA transitional provisions and the FCA's own expectations for cryptoasset firms. Document both sides of that relationship from day one.
Common mistake at Step 1: Accepting the closure as final and immediately shopping for a replacement account without retaining the original notice and correspondence trail. That trail is your primary legal tool if you subsequently need to dispute the decision, demonstrate to regulators that you responded responsibly, or satisfy a new institution's due-diligence inquiry about why the prior relationship ended.
Step 2: Assess Your Current Licence and Regulatory Footprint
A de-risking event is frequently a symptom of a licensing-gap that the closing institution identified before you did. The first internal question to resolve is whether your current regulatory footprint – the combination of licences, registrations and passporting rights across every jurisdiction in which you operate – accurately covers the activities and the user base you are actually running.
Operators in the digital-asset sector routinely carry a primary VASP registration in one country while routing payment flows through entities in two or three others, serving users in markets where neither entity holds a local licence. Closing institutions, particularly those regulated under MiCA by ESMA or under the FCA's cryptoasset registration regime, increasingly run enhanced checks on exactly that configuration. A VASP (virtual asset service provider) operating under a BVI FSC registration or a Cayman CIMA registration while routing EUR settlements through a European EMI is precisely the profile that triggers an automated exit under many institutions' current de-risking matrices.
Conduct an honest audit: which activities are licensed, where, for which users, and under which regime? Identify every gap between the licence you hold and the activity you are conducting. That gap – not the banking relationship itself – is the underlying problem. Restoring banking without closing that gap will produce the same result with the next institution, often faster.
Common mistake at Step 2: Assuming that the licence held in the most permissive jurisdiction covers operations globally. A single offshore licence is not a substitute for the local or regional authorisations that an institution's AML compliance team expects to see. The myth that a single registration is enough to bank and serve clients worldwide is the single most expensive misconception in crypto business structuring.
For a scoped assessment of your licence footprint and the gaps a closing institution may have flagged, contact OBOLUS at info@oboluslaw.com. The process above describes the standard diagnostic. Your entity structure, user geography and product mix change the analysis materially.
Step 3: Map the Immediate Liquidity and Operational Exposure
Before engaging a replacement institution, map every cash flow that routes through the closing account within the notice period. This step is operational, but it has direct legal consequences. Funds held at the closing institution at the point of closure may be subject to a return process that varies by the institution's home regulatory regime – and delays in that process can create secondary liquidity problems that harm clients if your business holds client money.
If your business holds client money in the closing account, the applicable safeguarding regime (the obligation to hold client funds separate from own funds, as required under the relevant payment-services rules in the EU and UK) requires that those funds remain identifiable and returnable at all times. An abrupt account closure that intermingles safeguarded funds with corporate funds triggers a regulatory notification obligation in most major payment-services regimes. Identify the safeguarding status of every balance in the account immediately.
Cross-border note: For businesses that operate across the EU and the UK post-Brexit, the safeguarding rules apply differently depending on whether the relevant institution is authorized under the applicable EU payment-services regime or under UK rules. An operator banking in both environments simultaneously must satisfy both sets of requirements for client-money protection. MiCA's provisions on the safeguarding of client assets for CASPs (crypto-asset service providers) add a further layer that MiCA-authorized firms must reconcile with the payment-services safeguarding they are already running through their EMI partners.
Common mistake at Step 3: Moving all balances out of the closing account as rapidly as possible without first confirming the safeguarding classification of each balance. A panicked transfer of mixed funds – own funds and client funds commingled – may itself constitute a safeguarding breach, adding a regulatory problem to the banking problem.
How Do You Qualify for EMI Onboarding After a De-risking Event?
Electronic money institutions (EMIs) have emerged as the primary fiat-rails provider for the digital-asset sector, and their onboarding criteria are materially more detailed than a standard corporate bank account application. After a de-risking event, the application pack you present to a prospective EMI must proactively address the closure – because the EMI's compliance team will find it regardless.
A well-prepared EMI onboarding file after a de-risking event should contain, at minimum: the original closure notice with your written request for reasons and the institution's response; a current regulatory summary covering every licence and registration held; an AML/KYC policy summary that demonstrates alignment with the FATF Recommendations, including the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer); a source-of-funds and source-of-wealth narrative for the principal UBOs; a transaction-monitoring description; and – critically – a plain-English explanation of why the prior relationship ended and what has changed since.
EMIs subject to MiCA or to their national AML regime will assess whether your business holds, or is actively pursuing, a CASP authorisation or the applicable national equivalent. The period of MiCA transition has made this more nuanced: a business operating under a pre-MiCA national VASP registration that is still within the transitional window occupies a different compliance posture than one that is fully authorized. Make that distinction explicit in the application. Ambiguity is the primary reason EMI applications stall at the compliance-review stage.
In our cross-border practice, we regularly see onboarding applications fail not because the client's business is non-compliant, but because the application pack presents the compliance position in the internal language of the crypto firm rather than the external language of an AML compliance officer at a regulated payment institution. Translation matters.
Common mistake at Step 4: Applying to multiple EMIs simultaneously with an identical pack and no tailored explanation of the de-risking event. Compliance teams communicate. A poorly explained closure, applied to five institutions in the same fortnight, can produce five simultaneous rejections – and some institutions maintain informal records of declined applicants.
What Structural Changes Reduce Future De-risking Exposure?
A restored banking relationship built on the same structural foundations as the one that was closed will fail again. The de-risking event is an opportunity to rebuild the banking and licensing architecture in a way that distributes risk and satisfies the compliance expectations of the institutions you need.
The core principle is diversification across three axes: institution type, jurisdiction, and currency. A digital-asset business whose EUR settlement, USD correspondent banking and stablecoin-to-fiat off-ramp all run through a single EMI in a single jurisdiction has created a single point of failure. A resilient fiat-rails structure typically involves a primary EMI for operational settlement, a secondary relationship for client-money safeguarding, and at least one alternative corridor for cross-border payments – ideally in a jurisdiction where the applicable regulatory regime is well-aligned with your primary licence.
On the licensing axis, the structural fix usually involves closing the gap identified in Step 2. For operators who serve EU users, that means pursuing or accelerating a CASP authorisation under MiCA. For operators with significant Asia-Pacific user exposure, the MAS Payment Services Act regime or the SFC's VATP licensing in Hong Kong may be the right structural anchors for banking in those corridors. For businesses structured through the BVI or Cayman Islands – both of which carry the BVI FSC or CIMA registration as their regulatory foundation – layering a MiCA CASP or a UK FCA registration on top substantially improves banking access in European corridors.
Cross-border note: The jurisdictional combination of operating entity, banking entity and user-base geography is the primary variable in a banking institution's de-risking calculus. A Cayman-domiciled fund that primarily serves European investors and banks through a Maltese EMI carries a different risk profile than a Malta-authorized CASP that banks through the same institution. The legal structure of the first is treated as offshore; the second is treated as a regulated EU entity. The practical banking outcome often differs significantly.
Common mistake at Step 5: Treating the banking fix and the licensing fix as sequential rather than parallel work streams. Most EMIs will not advance onboarding for a business that is in active licence-application mode without a clear account of the timeline and the transitional compliance posture. Running the two workstreams simultaneously, with coordinated communications to the target EMI, is the efficient path.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com – we map the licence, banking and payment stack for your build before you commit to a structure that replicates the original problem.
How Does the Travel Rule and AML Posture Affect Bank Onboarding?
A digital-asset business's AML and Travel Rule posture is now the primary technical filter in any banking or EMI onboarding assessment – more determinative, in our experience, than the jurisdiction of the primary licence.
The Travel Rule requires VASPs to collect, verify and transmit originator and beneficiary information for virtual-asset transfers above applicable thresholds. FATF Recommendation 15 sets the international standard; its implementation varies by jurisdiction (both in the threshold applied and in the technical standards required). An institution onboarding a VASP will test whether that VASP has a Travel Rule solution in place, whether it is connected to one or more interoperability protocols, and whether it has a defined policy for unhosted wallets.
Banks and EMIs that are themselves regulated under MiCA or their national AML transposition will treat a VASP without a demonstrable Travel Rule programme as a high-risk customer by default. That default can be changed – but only by presenting a Travel Rule policy, a named technology solution, and evidence of operational compliance before the compliance assessment begins. In our cross-border practice, we advise VASP clients to prepare a Travel Rule summary sheet specifically for banking due diligence: a one-to-two page document that answers the standard AML questionnaire before it is asked.
The cross-border dimension here is acute. A VASP that operates a Travel Rule solution compliant with one jurisdiction's standards but has not mapped that solution to the standards of the jurisdiction in which it is seeking banking may find its application flagged. For EU-licensed CASPs banking in the UK, and for UK-registered cryptoasset firms banking within the EU, the differences in threshold and data-field requirements mean that a single Travel Rule policy is rarely sufficient without a jurisdiction-specific annex.
Common mistake at Step 6: Presenting a Travel Rule policy that was drafted for regulatory submission to the licensing authority and has not been adapted for a banking due-diligence audience. The regulatory submission version is written to satisfy the regulator; the banking version needs to satisfy a commercial compliance team that will have different questions, different risk tolerance, and a shorter attention span.
When Should You Engage Legal Counsel in a De-risking Dispute?
Legal counsel should be engaged at Step 1 – but the nature of the engagement changes as the process develops. In the first phase, the role is diagnostic and documentary: preserving correspondence, assessing the legal basis of the closure, identifying obligations triggered by the notice. In the middle phase, counsel supports the structural and licensing workstream and advises on the banking application narrative. In the later phase, if the closure was wrongful or the institution has failed to return funds promptly, the engagement shifts to enforcement.
A micro-matter from our recent practice illustrates the value of early engagement. A regulated payments company holding a VASP registration in an EU jurisdiction received a de-risking notice from its EMI with a 30-day wind-down period. The notice cited no specific finding. We were engaged within 72 hours. We identified that the closure notice had been issued after the company processed a single large stablecoin settlement through the account – a transaction that was within its licensed activity but that had triggered the EMI's automated de-risking threshold. We drafted a formal response setting out the regulatory basis for the transaction, the client's AML record, and a summary of its Travel Rule compliance. The EMI reversed the closure decision. In parallel, we had already begun mapping two alternative EMI relationships as contingency – a workstream that continued even after the reversal, because a business that has been de-risked once should never again be single-banked.
Not every de-risking notice is reversible. Where an institution has made a policy-level decision to exit a sector entirely, no individual response will change the outcome. In those cases, the legal role shifts immediately to the structural and replacement workstream. The decision tree matters: early engagement allows counsel to make that diagnosis correctly and avoid investing response effort in an institution that has already closed the door.
Common mistake at Step 7: Engaging counsel only after the account has closed and the replacement search has already generated multiple rejections. At that point, the documentary record is often incomplete, the licensing gaps have not been addressed, and the narrative presented to prospective EMIs has already created impressions that are difficult to correct.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital-Asset Businesses – how we structure fiat-rails access across the major banking corridors for licensed VASPs and CASPs
- EMI Onboarding for VASPs in Nigeria – the regulatory and practical environment for fiat-rails access in one of Africa's most active crypto markets
- Cayman Islands vs Singapore: Where to License a Crypto Business – a comparative analysis of two leading offshore and mid-shore licensing jurisdictions
Self-Assessment Checklist: Are You Ready for EMI Onboarding After a Closure?
Before approaching a prospective EMI or bank, work through the following questions. An honest "no" to any item signals a gap that the institution's compliance team will almost certainly surface – and that should be addressed before the application is submitted, not during it.
- Do you hold the original de-risking notice and all subsequent correspondence?
- Can you explain, in one paragraph, why the prior relationship ended and what has changed?
- Is every activity you conduct covered by a current licence or registration in the relevant jurisdiction?
- Is your Travel Rule solution documented, operational, and described in plain English for a compliance audience?
- Have you identified and documented your safeguarding arrangements for client money?
- Do your UBO disclosure documents reflect the current ownership and control structure?
- Have you mapped the jurisdictions in which your users are located against the licences you hold?
- Do you have a secondary banking or EMI relationship in place, or a live application in progress?
A common assumption among operators who have received a de-risking notice is that presenting a clean AML history is sufficient for EMI onboarding. It is not. An EMI subject to MiCA, the FCA registration regime, or the applicable MAS or SFC framework will assess the forward-looking compliance architecture – the licence, the Travel Rule posture, the safeguarding structure – not just the absence of prior findings. A clean past and a structurally weak present produce the same result as a problematic past: rejection or a short-tenured relationship.
FAQ
Why do banks close crypto company accounts?
Banks and EMIs close crypto accounts primarily through de-risking: a commercial decision to exit a category of business judged to carry disproportionate AML compliance costs or reputational exposure. The decision is typically based on the institution's own risk appetite rather than any specific finding against the individual business. Contributing factors include the absence of a recognized licence, a weak AML or Travel Rule posture, geographic exposure to high-risk user corridors, and the volume or nature of stablecoin or virtual-asset transaction flows through the account.
How can a VASP onboard with an EMI?
A VASP seeking EMI onboarding after a de-risking event should prepare a complete compliance pack covering its current licences and registrations, its AML and Travel Rule framework, its safeguarding arrangements for client money, and a clear account of any prior banking closures and the steps taken since. EMIs regulated under MiCA or equivalent regimes will assess the VASP's forward-looking compliance architecture – not only its prior record. Legal structuring of the application narrative, aligned with the EMI's own regulatory expectations, materially improves the outcome.
What does client-money safeguarding require?
Client-money safeguarding, as required under the applicable payment-services and e-money regimes in the EU and UK, requires that client funds be held separately from the firm's own funds, be identifiable at all times, and be returnable to clients without being subject to the firm's insolvency. For digital-asset businesses operating through EMI partners, satisfying safeguarding requirements typically means maintaining designated safeguarding accounts, conducting regular reconciliations, and holding adequate own funds to cover any shortfall. MiCA adds further asset-safeguarding expectations for authorized CASPs.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and payment companies on banking access and EMI onboarding across 70+ licensing jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, structuring and compliance that sit around them. Digital assets are the entirety of our practice. We map the licence stack – across operating, custody and payment layers – before you commit to a structure that replicates the original problem. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP and CASP licensing, AML compliance architecture, and banking access for digital-asset businesses across EU and offshore jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.