EST · MMXXVI
Home/Insights/Regulatory/Correspondent banking access: A Cross-jurisdiction Comparison
Banking, Payments & EMI Onboarding

Correspondent banking access: A Cross-jurisdiction Comparison

Correspondent banking access: A Cross-jurisdiction Comparison. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk

Correspondent banking access for digital-asset businesses is one of the most consequential – and least predictable – legal variables in a cross-border build. A crypto-native firm (an exchange, custodian, or token issuer that processes fiat alongside digital assets) may hold licences in three jurisdictions and still find itself without a functioning bank account. The legal question is not whether your business is licensed. It is whether the correspondent banking system – the chain of relationships through which local payment institutions access global clearing – will accept your risk profile, your regulatory standing, and your transaction flows.

This analysis compares how the major licensing hubs approach correspondent banking access for virtual-asset service providers (VASPs), where the structural fault lines lie, and how a cross-border operator can reduce de-banking exposure before it becomes an operational crisis.

Why Correspondent Banking Access Determines Fiat Viability

Access to correspondent banking is the single most important infrastructure question for a VASP operating fiat rails. Without it, a licensed exchange cannot receive customer deposits in the currencies it trades. Without it, a regulated custodian cannot settle redemptions. A licence granted by VARA, the MFSA, or the Bank of Lithuania does not compel any bank to open or maintain an account. Regulators authorise; correspondent banks decide.

The mechanics matter. A correspondent bank is a financial institution that provides services – clearing, settlement, foreign-exchange, and custodial functions – to another institution that lacks direct access to a particular payment system. In practice, almost every EMI or payment institution serving a VASP depends on at least one correspondent for access to SWIFT, SEPA, or domestic real-time gross settlement. If that correspondent withdraws, the payment chain collapses – regardless of licence status.

In our cross-border practice, we have seen clients arrive with authorised CASP status under the MiCA regime and a functioning compliance programme, yet unable to retain a correspondent because their transaction profile included on-chain settlement. The licence was real. The banking was absent.

The problem is structural, not reputational. Correspondent banks apply their own risk appetite frameworks. FATF Recommendation 13 – the de-risking guidance – gives them discretion. Most major clearing banks operate globally and carry US dollar clearing exposure, which brings FinCEN, OFAC, and OCC expectations directly into their relationship decisions. A VASP incorporated in Malta and licensed under the transitioning VFA framework may clear fiat through a UK-based payment institution whose own USD correspondent sits in New York. Every step in that chain applies a fresh risk assessment.

How the Major Hubs Compare on Banking Access

The regulatory quality of a licence materially affects – but does not guarantee – access to correspondent banking, and the gap between the best and worst hubs is significant. What follows is a comparison across the leading digital-asset licensing environments.

UAE (VARA / ADGM-FSRA). The UAE has made deliberate regulatory investment in banking access for VASPs. VARA's activity-based licensing regime – covering exchange, custody, broker-dealer, and transfer services – signals to correspondent banks that a supervised framework exists. ADGM, operating under the FSRA within Abu Dhabi's financial free zone, provides a common-law framework that major international banks recognise. In practice, UAE-licensed VASPs report materially better access to Emirati domestic banks and to regional clearing networks than equivalently structured businesses in less-developed regimes. That said, USD clearing remains a constraint: the US dollar correspondent relationships that many UAE banks rely on are subject to the same US regulatory expectations as anywhere else.

EU (MiCA / CASP). MiCA's passporting mechanism – by which a CASP authorised in one member state may operate across the EU/EEA – was designed in part to rationalise the patchwork of national VASP registrations that characterised the pre-MiCA environment. For correspondent banking purposes, MiCA CASP status carries meaningful weight. It signals harmonised AML/CFT compliance, standardised whitepaper requirements, and national competent authority oversight. Lithuania and Malta, historically popular onboarding points, are transitioning their prior VASP populations into the CASP regime. EMIs in those jurisdictions that serve VASPs are doing the same. The practical result is that a MiCA-authorised CASP with a clean compliance structure has a credible narrative to bring to a correspondent bank – but the narrative must be backed by documented governance, and the correspondent will verify it.

UK (FCA / MLR). The UK Financial Conduct Authority's cryptoasset registration under the Money Laundering Regulations provides AML-focused oversight, not a full prudential licence. For correspondent banking, this matters: a payment institution using a UK-registered VASP client faces a thinner regulatory story to tell its own correspondent than it would with a MiCA CASP. Financial promotion rules in the UK add a further compliance layer. In our practice, we have observed that UK-regulated EMIs are often reluctant to onboard VASPs unless the VASP can demonstrate a licence in a jurisdiction with stronger prudential oversight – a dynamic that has pushed many operators toward a dual-licence structure.

Singapore (MAS / PSA). MAS's Payment Services Act licensing regime – with its three tiers for payment institutions handling Digital Payment Tokens (DPTs) – is widely respected by correspondent banks in the Asia-Pacific region. A major payment institution licence under the PSA provides a credible prudential baseline. Singapore-licensed VASPs generally access SGD rails with less friction than operators in many other hubs. Cross-border USD access remains tighter, and MAS-licensed businesses building toward US-facing flows still need to manage the US regulatory layer independently.

Switzerland (FINMA). FINMA's token taxonomy and its SRO/AML affiliation pathway are well understood by Swiss financial institutions. Swiss banks have historically been more willing than their US or UK counterparts to bank crypto-adjacent businesses when AML governance is demonstrably strong. The practical constraint is that Swiss banking relationships are bespoke and often expensive to establish. Operators who obtain a FINMA-supervised structure can find banking but should not expect it to be automatic or fast.

BVI and Cayman. The BVI FSC's VASP Act registration and the Cayman CIMA regime serve primarily fund and holding structures. Neither jurisdiction offers fiat clearing infrastructure of its own. A BVI-registered VASP seeking operational banking for client flows will rely entirely on correspondent relationships run through third-country EMIs or payment institutions. The correspondent banking problem is therefore downstream of the licensing gap: the BVI or Cayman registration is real, but it does not substitute for a prudential licence in a hub where banking infrastructure exists.

What Is Driving De-risking – and Where It Hits Hardest

De-risking – the practice of terminating or restricting banking relationships to reduce compliance cost and regulatory exposure – hits crypto businesses at three points in the correspondent chain: the local bank or EMI, that EMI's own correspondent, and the USD correspondent that clears the chain internationally.

Each level applies its own risk filter. A VASP that satisfies its local EMI's AML requirements may still be exited because the EMI's correspondent has a blanket policy against crypto-related flows. That policy may reflect its own US dollar clearing exposure, its own regulator's expectations, or simply risk appetite set at the group level in a jurisdiction the VASP has no presence in.

The sectors most exposed are: exchanges with retail-facing on-ramping (high transaction volumes, mixed customer profiles); OTC desks serving institutional clients (large ticket sizes trigger enhanced due diligence); and stablecoin issuers or operators who settle in USDT or USDC and then need to convert back to fiat (the on-chain/off-chain bridge is a primary friction point).

Operators we advise routinely underestimate the Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual asset transfer) as a banking factor. A correspondent bank reviewing an EMI's VASP client expects to see Travel Rule compliance operational – not planned, not in development. Non-compliance at this point is itself grounds for de-risking.

CTA #1

The correspondent banking problem is rarely solved by finding a new bank. It is solved by structuring the entity, the licence, and the compliance programme so that the risk narrative is credible at every step in the chain. For a scoped assessment of your current structure's banking risk, contact OBOLUS at info@oboluslaw.com.

How Does an EMI Actually Onboard a VASP?

EMI onboarding of a VASP is a structured due-diligence process, not a product sign-up, and the documentation burden is substantially higher than for a conventional payment business. Understanding the process is essential for any operator planning fiat rails.

The EMI's onboarding team will typically request: corporate structure documents (including UBO chain to natural persons); proof of VASP registration or licence in the relevant jurisdiction; the AML/CFT policy and risk-appetite statement; a sample of the customer onboarding (KYC/KYB) procedure; evidence of Travel Rule compliance – provider name, implementation date, and scope; transaction monitoring procedures; the last two cycles of internal audit or compliance review; and, in most cases, a sanctions screening policy referencing OFAC, EU consolidated list, and UN designations.

Regulators in the leading hubs increasingly expect this documentation to be current – within the last twelve months – and to reflect actual operational practice, not aspirational policy. An EMI that sees a gap between the written programme and the live operation will exit the relationship or decline to begin one.

The cross-border dimension compounds the process. A VASP that holds a MiCA CASP licence for EU clients, a PSA licence for Singapore-facing business, and a BVI registration for fund vehicles will need to demonstrate which entity handles which client flows and which licence covers each. EMIs in any one jurisdiction will probe the other entities in the group for risk exposure: a BVI entity with no AML programme is a liability for the whole group, even if the EU entity is impeccably compliant.

In a recent engagement, a payment services operator sought to onboard three group entities simultaneously with a single EMI. The EU entity carried a transitioning MiCA-pathway licence; the Singapore entity held a PSA payment institution licence; the BVI entity was registered but had a dormant compliance programme. The EMI declined the group onboarding on the basis of the BVI entity's profile, even though the BVI entity generated no client-facing flows. We restructured the group's AML programme to ring-fence the BVI entity from client-flow activities and documented the separation for the EMI's review. The onboarding proceeded for the licensed entities on the second submission.

Which Licensing Profile Reduces Banking Friction – A Decision Matrix

No single licensing profile eliminates correspondent banking friction. The relevant question is which profile minimises it for a given operator type, jurisdiction footprint, and currency mix.

Profile A – EU retail exchange, EUR-denominated, passporting ambition. The optimal instrument is MiCA CASP authorisation in a member state with an established CASP supervisory track. The EU passporting mechanism gives a single-regulator story to EMIs across the bloc. The timeline to authorisation is a matter that varies by member state and application quality; operators should plan on a multi-month process. The principal banking risk is the EUR clearing chain: EU-based EMIs serving VASPs are themselves subject to MiCA and AML supervision, which provides a degree of mutual assurance. The residual risk is a group-level policy at a major correspondent bank.

Profile B – Multi-currency exchange, Asia-Pacific and MENA focus. The optimal structure typically combines a MAS-licensed entity for SGD and regional Asian flows with a VARA or FSRA-licensed entity for AED and MENA flows. Each entity maintains its own EMI relationship and its own Travel Rule compliance programme. USD clearing for both entities runs through the US dollar correspondent of each EMI. The principal risk is that USD corridor policies change independently of either regulator's position. Operators should maintain contingency banking with at least two EMIs across the two jurisdictions.

Profile C – Institutional OTC desk, large-ticket, multi-currency. FINMA-supervised structures or MiCA CASP with a prudential licence track are the strongest correspondent banking credentials for institutional business. Swiss banking relationships are bespoke and slower to establish but tend to be more stable once running. The primary risk is enhanced due diligence at the transaction level rather than at the account level.

Profile D – Fund vehicle with digital-asset strategy, Cayman or BVI incorporated. The fund vehicle itself will not carry an operating banking relationship for client flows. The general partner or management entity – typically incorporated in a hub jurisdiction – needs its own payment infrastructure. The Cayman or BVI registration addresses fund structuring and investor protections; it does not provide banking. This distinction is frequently misunderstood, and we have seen it cause significant operational delays at launch.

The Five Structural Mistakes That Cause Banking Failure

Banking failure for a VASP almost always traces back to one of five structural mistakes, most of which are visible – and correctable – before a bank account is opened.

First: treating the licence as the banking solution. A VASP licence authorises an activity. It does not obligate any bank to provide services. The compliance programme that accompanies the licence is what the EMI actually evaluates.

Second: building a single-entity structure. An operator that processes all flows – exchange, custody, and payment – through a single licensed entity concentrates risk in a way that no EMI will find attractive. The licence perimeter and the activity perimeter should align: custody, exchange, and payment flows through appropriately licensed or ring-fenced entities.

Third: incomplete Travel Rule implementation. A VASP that has not operationalised Travel Rule compliance – with a named provider, documented workflows, and records – is presenting a material compliance gap to any correspondent that asks. Regulators in all leading hubs treat this as a baseline expectation.

Fourth: a group structure with an unsupervised entity. As the micro-matter above illustrates, a single non-compliant entity in a group creates group-wide banking exposure. EMIs perform group-level reviews, not entity-level reviews in isolation.

Fifth: no contingency banking plan. Operators who rely on a single EMI relationship have no operational resilience when that relationship is terminated. A sudden account closure – which may follow a policy change at the correspondent level with little warning – should not be a business-ending event. Building the second banking relationship before you need it is a structural decision, not a tactical one.

The Cross-border Reality: Tax and Banking as Interlocked Problems

The jurisdiction where an entity is licensed, the jurisdiction where its banking sits, and the jurisdiction where its revenues are taxed are three separate questions – but they interact in ways that create banking risk when they are misaligned.

An entity licensed in the EU but banking through a non-EU EMI with a US dollar clearing chain faces a multi-regulator story that each correspondent in the chain must understand and accept. If the entity's beneficial owners are resident in a jurisdiction that the FATF has placed on an enhanced monitoring list, every layer of that chain will apply additional scrutiny.

Tax posture adds a further dimension. An entity that books revenue offshore while operating staff and infrastructure onshore – a structure common in the early wave of crypto businesses – is the type of structure that flags enhanced due diligence at the EMI onboarding stage. Operators we advise are increasingly building licence, tax, and banking as a single integrated mandate rather than three sequential decisions. The reason is simple: a tax-efficient offshore booking entity is of limited value if it cannot access the payment rails it needs to operate.

Regulators in the leading hubs increasingly expect to see substance in the licensed entity: local staff, genuine governance, and operational decision-making that matches the jurisdiction on the licence. EMIs apply the same scrutiny. A shell entity licensed in a favourable jurisdiction but managed from a different one is a red flag at both the regulatory and the banking layer.

CTA #2

If a prior banking application stalled or an account was closed without a clear explanation, the structural reason is usually identifiable. A second-read engagement can surface it and map a route to resolution. To discuss your situation, write to OBOLUS at info@oboluslaw.com.

A Common Assumption: "We Can Solve Banking After Launch"

A common assumption among operators entering the digital-asset space is that banking is a commercial problem to be resolved post-launch, once the product is live and revenue is generating. This assumption is one of the most reliably expensive mistakes in the sector.

Banking relationships for VASPs require regulatory documentation that takes months to prepare and verify. An EMI onboarding a VASP will typically run a three-to-six-month due diligence process before a relationship goes live. If the application is declined – for a structural reason that was present from the outset – the operator has lost that window and faces the cost of restructuring before reapplying.

The further risk is that launching without banking in place creates a public record of an operating VASP without a compliant fiat processing path. That record is visible to subsequent correspondent banks and is treated as a further risk signal.

The practical answer is to begin the banking engagement at the same time as the licensing engagement, and to treat the two as a single workstream. In our practice, we structure licence, banking, and tax as one integrated mandate precisely because the decisions at each layer are not independent.

Self-Assessment: Is Your Business Banking-Ready?

Before initiating an EMI onboarding process, an operator should be able to answer all of the following affirmatively.

First: does the legal entity that will hold the bank account carry a relevant VASP licence or registration in a jurisdiction whose AML/CFT regime an EMI can map to FATF standards?

Second: is the AML/CFT policy current – reviewed within the last twelve months – and does it address virtual-asset-specific risks including on-chain settlement, stablecoin transactions, and DeFi exposure?

Third: is Travel Rule compliance operational, with a named technology provider, documented workflows, and a defined scope covering all transfers above the applicable threshold in each jurisdiction the business serves?

Fourth: are all entities in the corporate group either licensed, registered, or demonstrably ring-fenced from client-flow activities? No group entity should present an unresolved AML gap.

Fifth: is the licensing jurisdiction consistent with the substance of the operation – local staff, genuine governance, and decision-making that matches the licence address?

Sixth: does the operator have a contingency banking plan – a second EMI relationship or a documented process for initiating one – so that a single account closure does not halt operations?

If any of these questions draws a negative answer, the banking engagement should be deferred until the gap is closed. Proceeding without that foundation is structurally likely to produce a declined application or a later de-banking event.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because of risk appetite, not because of any specific regulatory prohibition. Correspondent banks apply their own compliance frameworks, which frequently treat virtual-asset transaction flows as high-risk due to AML/CFT complexity, Travel Rule compliance uncertainty, and US dollar clearing exposure. A VASP that cannot demonstrate a well-documented AML programme, operational Travel Rule compliance, and a clean UBO structure gives the bank no credible risk narrative to present to its own correspondent. The result is exit, often with minimal notice.

How can a VASP onboard with an EMI?

A VASP seeking EMI onboarding should prepare a complete due-diligence package before approaching any EMI: corporate documents with full UBO disclosure, the relevant VASP licence or registration, a current AML/CFT policy, evidence of operational Travel Rule compliance, transaction monitoring procedures, and a sanctions screening policy. The EMI will also conduct group-level due diligence, so every entity in the corporate structure must be either licensed or demonstrably ring-fenced. Expect a multi-month review process. Approaching two or more EMIs simultaneously reduces timeline risk.

What does client-money safeguarding require?

Client-money safeguarding requires that funds received from clients in the course of a payment or e-money service are held separately from the firm's own funds and protected against the firm's insolvency. Under EMI and payment institution regimes in the EU, UK, and most leading hubs, this typically means segregation in a designated account at a credit institution, coverage by an insurance product, or investment in low-risk liquid assets. The specific method and coverage threshold vary by regime; operators should confirm the applicable safeguarding rule with counsel before selecting a model.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance that sit around them. We map the licence stack across operating, custody, and payment layers before you commit – and we structure licensing, banking, and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in cross-border VASP licensing and banking access strategy for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours