EST · MMXXVI
Home/Insights/Guides/How to Safeguard Client Funds Compliantly
Banking, Payments & EMI Onboarding

How to Safeguard Client Funds Compliantly

How to Safeguard Client Funds Compliantly. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a virtual asset service provider (VASP) or payments business without a properly structured client-funds regime is one of the fastest routes to a frozen account, a regulatory notice, or both. Safeguarding client funds compliantly means segregating those funds from the firm's own capital, holding them through a regulated vehicle, and maintaining the paper trail that regulators, correspondent banks, and auditors will demand. This guide works through each structural step — the regulatory basis, the cross-border note, and the mistake that derails operators at that stage.

Why Client-Funds Safeguarding Matters for Digital-Asset Businesses

Safeguarding is the legal and operational requirement to keep client money or client crypto assets separate from a firm's own property so that, on insolvency, those assets are returned to clients rather than distributed to general creditors. Under most leading payment and VASP regimes — including MiCA (the EU's Markets in Crypto-Assets Regulation), the Payment Services Act in Singapore, and FCA registration requirements in the UK — some form of segregation or safeguarding obligation is a threshold condition for operating legally.

The practical stakes are high. Banks that provide fiat rails to crypto businesses treat weak safeguarding as a risk indicator. A business that cannot demonstrate clean segregation is, in most banking conversations, unbanked before it starts. We see this pattern regularly: a company obtains a VASP registration, believes the hard work is done, then discovers that every prospective EMI or correspondent bank requires evidence of a documented safeguarding method before onboarding.

The loss-aversion framing matters here. Enforcement is not the only threat. A regulatory review that surfaces a commingled account can produce account closures, remediation costs, and reputational damage that outlasts the underlying error by years. Getting the structure right at the outset costs a fraction of unwinding it later.

Step 1 — Classify What You Hold and Under Which Regime

Before choosing a safeguarding method, you must classify the assets you hold and identify the regulatory regime that governs each category — because the obligations differ materially depending on whether you hold fiat, e-money, stablecoins, or unbacked crypto assets.

Fiat held on behalf of clients in most EU member states falls under the Payment Services Directive transitional rules and, going forward, under MiCA's requirements for electronic money tokens (EMTs). Stablecoins that qualify as asset-referenced tokens (ARTs) under MiCA attract their own reserve and safeguarding framework. Unbacked crypto assets held in custody trigger the custody-specific requirements of the applicable CASP (Crypto-Asset Service Provider) authorisation.

In Singapore, a business licensed under the Payment Services Act for digital payment token (DPT) services faces segregation requirements that apply specifically to DPT holdings — separate from the rules covering stored value or e-money. The MAS (Monetary Authority of Singapore) has tightened these expectations significantly following sector-wide reviews.

Cross-border note. An operator with users in multiple jurisdictions may hold assets governed simultaneously by MiCA, the MAS regime, and FCA rules. Each layer may impose different segregation mechanics — separate custodial wallets, ring-fenced bank accounts, or trust structures. Treating the most permissive regime as the floor is an error that creates exposure in every other market you serve.

Common mistake at this step: classifying the entire asset pool under the regime where the entity is licensed, rather than under the regime applicable to where the user is located or the service is provided. Regulators in the user's jurisdiction look at substance, not entity structure.

Step 2 — Choose the Right Safeguarding Method

Regulated payment and crypto-asset regimes generally permit two structural safeguarding methods: a segregated bank account at a credit institution, or a ring-fenced insurance or guarantee arrangement. For crypto assets, a third route — cold or warm storage under a regulated custodian — has become the operational standard in most leading hubs.

The segregated bank account method is the most common for fiat components. The account must be held with a credit institution, clearly designated as a client account, and entirely separate from the operating account. Commingling — even temporarily, even for operational convenience — is a regulatory breach in virtually every regime that uses this method. Under the FCA's rules for authorised payment institutions, the precise naming convention and notice requirements for those accounts are prescribed; similar specificity applies under MiCA's EMT rules and the MAS Payment Services Act framework.

For crypto-asset custody specifically, the regulated custodian route involves placing client assets with a separately licensed custodian that holds those assets on a trust or fiduciary basis. Under MiCA, a CASP providing custody services must maintain individual ledger records for each client and must not use client assets in proprietary trading or lending without explicit, documented client consent.

Cross-border note. If you custody crypto assets for clients in Hong Kong, the SFC (Securities and Futures Commission) requires that at least 98% of client assets be held in cold storage, with the warm/hot wallet percentage tightly capped. That standard is more prescriptive than many EU member state implementations. A dual-hub operator — licensed in both the EU and Hong Kong — must design its custody architecture to the stricter of the two standards across the entire client pool.

Common mistake at this step: selecting a safeguarding method that satisfies the licensing jurisdiction but fails the operational jurisdiction — for example, holding all client assets in an EU custodian account while serving Hong Kong clients subject to SFC cold-storage ratios.

To map the right safeguarding structure for your entity, your user base, and your banking stack, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts — the entity, the user base, the banking — change the analysis. A scoped structural review typically surfaces the mismatches before they reach a regulator.

Step 3 — Open and Maintain the Right Fiat Rails

Opening a client-funds account at a bank or EMI (electronic money institution) as a VASP or payments business is the step most operators underestimate, and the one most frequently delayed by structural errors upstream.

Banks and EMIs that service digital-asset businesses are concentrated in a limited set of jurisdictions. In practice, a VASP seeking fiat rails (the banking connections that allow receipt and payment of traditional currency) will approach institutions operating under the MiCA regime, under MAS supervision in Singapore, or under the FCA in the UK. Each institution applies its own risk appetite on top of the regulatory minimum. A clean regulatory licence is necessary but not sufficient. The bank will also examine the safeguarding method, the AML controls, the beneficial ownership structure, and the volume and source of expected client funds.

EMI onboarding — specifically, onboarding with a licensed EMI rather than a full credit institution — has become the most common first-step for smaller VASP operators. An EMI account does not carry the same deposit protection as a bank account, but it is faster to open and the EMI's own regulatory obligations create an alignment of interest: the EMI wants to see the same safeguarding documentation the regulator wants.

In our practice, the businesses that onboard with EMIs most cleanly are those that arrive with a documented safeguarding policy, a clear description of the client money flow, an AML/KYC framework that already meets the Travel Rule (the obligation to pass originator and beneficiary data with each transfer), and a legal opinion on the regulatory status of the assets they hold. Arriving without that documentation adds weeks and often months to an already protracted process.

Cross-border note. The FATF (Financial Action Task Force) Travel Rule — formally Recommendation 15 — applies to VASPs and financial institutions processing virtual asset transfers. The specific data threshold (the minimum transfer value at which the rule activates) varies by jurisdiction. An operator processing transfers across, say, the EU, Singapore, and the BVI must apply each jurisdiction's threshold to the relevant leg of the transfer — a detail that many multi-jurisdictional operators initially mishandle.

Common mistake at this step: applying for an EMI account before the VASP licence is confirmed, or before the safeguarding documentation is complete. Most serious EMIs will pause onboarding the moment a document gap is discovered; re-submitting a clean file typically restarts the queue rather than resuming from the prior position.

Step 4 — Build Operational Controls That Satisfy Auditors and Regulators

The documented safeguarding method is the baseline; the operational controls are what keep it intact. Regulators in every leading hub have moved from rules-on-paper reviews to operational-effectiveness assessments — they want evidence that the safeguarding regime functions as described, not merely that it was designed correctly.

For fiat client-money accounts, the minimum operational requirements across most regimes include: daily reconciliation of the client-money balance against the firm's internal ledger; a documented process for topping up any shortfall within a defined period; and a clear record of any permitted deductions (such as fees drawn from the account under disclosed terms). Under MiCA's CASP framework, these reconciliation records must be kept for a defined retention period and must be available to the competent authority on request.

For crypto-asset custody, the controls parallel the fiat model but add wallet-level specifics: segregation at the wallet address level (not merely at the aggregate balance level), documented key-management procedures, and third-party confirmation of the custody arrangement where a sub-custodian is used. The ADGM/FSRA (Abu Dhabi Global Market Financial Services Regulatory Authority) and VARA (Dubai's Virtual Assets Regulatory Authority) both examine key management as a substantive part of the custody licence review — a level of operational granularity that surprises applicants who approach it as a paperwork exercise.

Micro-matter. In a recent matter, a crypto-payments company structured across two jurisdictions presented a clean segregated account policy to its licensing regulator. The daily reconciliation process, however, ran at T+2 rather than T+1. An on-site review by the competent authority flagged the gap as a safeguarding breach. We worked with the operator to redesign the reconciliation workflow, update the documented policy, and submit a remediation plan within the regulator's required window. The licence was maintained without a public sanction. The lesson: the gap between the written policy and the operational reality is where enforcement actions originate.

Common mistake at this step: treating safeguarding as a legal/compliance function rather than an operational one. The people running the daily reconciliation process need to understand what it is for — not merely how to run a spreadsheet.

Step 5 — Manage Cross-Border Safeguarding Obligations

A single offshore licence is not enough to serve clients globally — and this is the assumption that most frequently produces enforcement risk in cross-border digital-asset businesses.

The reality is that the safeguarding obligation follows the user, not just the entity. A VASP licensed under the BVI FSC's Virtual Asset Service Providers Act 2022 and serving clients in the EU is, from the perspective of ESMA and the national competent authorities operating under MiCA, providing crypto-asset services to EU clients without authorisation. The BVI licence does not satisfy the MiCA passporting requirement. Safeguarding client funds under the BVI standard does not satisfy the MiCA requirement either. The two regimes are parallel obligations, not alternatives.

The practical consequence for a multi-hub operator is a layered licence stack. The operating entity, the custody vehicle, and the payment layer may each sit in a different jurisdiction, each with its own safeguarding requirement. Structuring that stack so that every client-facing activity has the right licence in the right jurisdiction — and that the safeguarding mechanics at each level satisfy the local requirement — is a design exercise, not an administrative one.

Allied counsel in the relevant jurisdictions work alongside our team on complex multi-hub structures. In practice, the jurisdictions that attract the most structuring attention for this kind of cross-border build are the EU (for the passport), Singapore (for the Asia-Pacific layer), and ADGM or VARA in the UAE (for the Middle East and emerging-market gateway). The AIFC/AFSA framework in Kazakhstan is increasingly considered for Central Asia-facing operations.

Cross-border note. Tax treatment of the safeguarding vehicle itself — whether it is a trust, a subsidiary, or a contractual arrangement — varies significantly by jurisdiction and can have VAT/GST implications on custodial fees that operators rarely model at the design stage. Structuring the safeguarding layer without factoring in the tax treatment of the fee flow is an error we regularly see corrected at significant cost downstream.

Common mistake at this step: assuming that a jurisdiction's VASP registration or licence automatically resolves the safeguarding obligation for clients in other markets. It does not. Each market's competent authority will assess the safeguarding treatment applicable to its own residents or users independently.

If a prior application stalled or a banking relationship was closed, a second read of the structure often surfaces the cause. Write to OBOLUS at info@oboluslaw.com — we map the licence, banking, and safeguarding stack as a single mandate.

Step 6 — Self-Assessment: Is Your Safeguarding Structure Compliant?

Before approaching a regulator, a bank, or an EMI, work through this structural checklist. Each item represents a question the counterparty will ask, and a gap will delay or block the process.

  • Have you classified every asset category you hold — fiat, e-money, stablecoins (ART/EMT), and unbacked crypto assets — under the specific regulatory regime applicable to each?
  • Is client money segregated at the account level (not merely the entity level), with the account clearly designated and the designation documented?
  • Is the safeguarding method — segregated bank account, insurance/guarantee, or regulated custodian — appropriate for each asset class under each applicable regime?
  • Does the daily reconciliation process match the policy document? Is there a documented shortfall-remediation procedure?
  • For crypto-asset custody: are client assets segregated at the wallet address level, with documented key-management procedures and sub-custodian confirmations where relevant?
  • Does your Travel Rule compliance policy address each jurisdiction in which you process transfers, including the applicable threshold for each?
  • Have you assessed whether the safeguarding structure satisfies the requirements of every jurisdiction in which you have users — not just the jurisdiction of incorporation or licensing?
  • Is the safeguarding documentation ready to produce to a regulator, an EMI, or a correspondent bank on request, without requiring revision?

A business that can answer each of these questions affirmatively, with documentary support, is in a position to approach most regulated counterparties with confidence. A business that cannot should resolve each gap before initiating any banking or licensing conversation — not during it.

Decision Matrix — Which Safeguarding Structure Fits Your Profile

The right safeguarding structure depends on what you hold, where you operate, and who your users are. The following matrix describes the most common operator profiles and the structural route each typically requires.

Profile A — EU-licensed CASP holding fiat and unbacked crypto assets: The primary safeguarding requirement is a MiCA-compliant segregated bank or EMI account for fiat, combined with wallet-level segregation for crypto. The indicative challenge is finding a credit institution or EMI willing to hold the client-money account for a CASP at early stage — expect a thorough due-diligence process and allow adequate lead time. Key risk: the bank account conversation happens before the licence is issued, but the bank requires the licence — sequence management is critical.

Profile B — VASP licensed in an offshore jurisdiction (BVI, Cayman, or ADGM) serving a global user base: The primary question is not whether the home-jurisdiction safeguarding requirement is met, but whether the requirements of every destination market are met. The likely structure involves a layered entity — a holding company in the offshore hub, an operating entity in each regulated market — with separate safeguarding arrangements at each operating level. Key risk: conflating entity-level compliance with user-level compliance.

Profile C — Singapore-licensed DPT service provider with APAC users: MAS has articulated detailed safeguarding expectations for DPT businesses. The structure requires DPT assets to be held in trust for clients in a segregated account with an approved financial institution, and the MAS expects documented reconciliation at defined intervals. For a regional operator also serving clients in Hong Kong, the SFC's 98%-cold-storage rule will apply to the HK-facing custody — a higher standard than most MAS-only operators design for initially. Key risk: under-designing the custody architecture for the HK layer.

A Common Assumption: "Our Offshore Licence Covers Global Operations"

A common assumption among digital-asset operators entering multi-market distribution is that a licence obtained in a permissive or strategically located jurisdiction provides a global operational perimeter. It does not.

The major regulated hubs — the EU under MiCA, Singapore under the Payment Services Act, Hong Kong under the SFC VASP regime, and the UK under FCA registration — each apply their rules based on where services are provided to users, not merely where the entity is incorporated or licensed. Serving EU residents from a non-MiCA entity is, for purposes of MiCA enforcement, providing crypto-asset services in the EU without authorisation. The safeguarding obligation is part of that authorisation requirement; it cannot be satisfied by a foreign standard.

This does not mean every digital-asset business needs ten licences. It means the licence and safeguarding architecture must be designed around the actual user base and service distribution — and that design should precede the banking and EMI onboarding conversation, not follow it.

In our cross-border practice, we structure licensing, banking, and safeguarding as a single integrated mandate. The operators who reach compliant operations fastest are those who treat the three workstreams as one design problem from the outset — not as three sequential administrative tasks.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because of perceived AML risk, unclear safeguarding arrangements, or failure to meet the bank's internal risk-appetite threshold for digital-asset businesses. Even a licensed VASP can lose banking access if it cannot demonstrate clean client-money segregation, a Travel-Rule-compliant transfer process, and a beneficial ownership structure that satisfies the bank's own KYC standards. Regulatory licence and banking access are separate questions — a licence does not guarantee a bank account.

How can a VASP onboard with an EMI?

A VASP seeking EMI onboarding should arrive with a complete compliance package: the regulatory licence or registration, a documented safeguarding policy, an AML/KYC framework that addresses the Travel Rule, a clear description of the client money flow, and a legal opinion on the regulatory status of the assets held. Gaps in any of these documents typically pause the process. The strongest applications also include a detailed description of the business model and the user base, framed in the risk language the EMI's compliance team uses.

What does client-money safeguarding require?

Client-money safeguarding requires, at minimum, segregating client funds from the firm's own capital in a clearly designated account or custody structure, reconciling the client-money balance against the firm's internal ledger at defined intervals, and maintaining records sufficient to return client assets promptly on insolvency. The specific mechanics — account type, reconciliation frequency, retention period for records — vary by jurisdiction and asset class. Under MiCA, MAS, and FCA rules, a safeguarding failure can trigger enforcement action independently of any other breach.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and payments companies on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the banking, safeguarding, and compliance that sit around them. We structure licensing, banking, and tax as one mandate rather than three disconnected workstreams — and we map the licence stack across operating, custody, and payment layers before you commit. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst — specialising in cross-border VASP licensing, AML compliance, and safeguarding structures for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours