For a digital-asset business, losing access to fiat rails is not a technical inconvenience. It is an existential event. Correspondent banking access – the compliance burden that sits behind it – has become the central operational risk for exchanges, custodians, EMIs (electronic money institutions), and payment service providers that touch crypto on either side of the transaction. As supervisory expectations tighten across the major hubs and correspondent banks apply their own layered due-diligence requirements on top of formal licensing, the gap between holding a valid regulatory authorisation and actually receiving a bank account has widened substantially. This analysis examines why that gap exists, how it operates in cross-border structures, and what a well-advised business can do to close it.
The core problem is structural. A VASP (virtual asset service provider) may satisfy every licensing condition imposed by its home regulator – VARA in Dubai, the Bank of Lithuania under the MiCA transition, the MFSA in Malta – and still fail the separate, informal risk-appetite assessment applied by a correspondent bank. These are two distinct gatekeeping exercises, and they run in sequence: the regulator decides whether you may operate; the bank decides whether it will serve you. Failing the second gate after clearing the first wastes capital, delays launch, and in some structures triggers regulatory reporting obligations of its own.
Why Correspondent Banks Refuse Crypto Clients
Correspondent banks decline crypto accounts primarily because of de-risking (the practice of terminating or refusing entire customer categories to reduce aggregate compliance exposure), not because individual applicants are demonstrably non-compliant. The correspondent sits upstream in the correspondent banking chain and applies its own jurisdiction's AML/CFT standards to every downstream institution it clears for. If a digital-asset business's regulatory status is uncertain, or if the correspondent's compliance team lacks the internal expertise to assess it, the default decision is refusal.
Several converging pressures drive that default. Global AML/CFT standards under the FATF Recommendations – including Recommendation 15, which addresses virtual assets and virtual asset service providers – require correspondent banks to understand the nature of their respondents' business and the underlying customer populations. That expectation is not confined to the VASP's home regulator; it flows upstream to every bank in the clearing chain. A correspondent clearing for a bank that clears for an EMI that clears for an exchange faces nested exposure it may simply be unwilling to price.
In our practice, the refusals we see most frequently are not categorical objections to crypto itself. They are objections to specific structural features: a holding company in a high-risk jurisdiction, a customer base that skews toward peer-to-peer transfers, a product mix that includes privacy coins, or an incomplete set of Travel Rule (the obligation to pass originator and beneficiary data with each qualifying transfer) procedures. Each of these features elevates the correspondent's own compliance cost. The business that can demonstrate it has addressed each one – not in a marketing document but in an operational compliance programme the bank can actually review – materially improves its position.
The process above describes the standard path. Your facts – the entity structure, the user base, the banking jurisdiction – change the analysis significantly. For a scoped assessment of your current structure and its banking implications, contact OBOLUS at info@oboluslaw.com.
What Regulators Require Versus What Banks Actually Require
The compliance burden that blocks correspondent banking access differs in kind, not merely in degree, from the compliance programme that secures a regulatory authorisation. Understanding where those two sets of requirements diverge is the first step toward satisfying both.
Regulatory authorisation focuses on the applicant's fitness and propriety, its governance structure, its AML/CFT policies, its capital adequacy, and its consumer-protection arrangements. The regulator's assessment is point-in-time and documentation-heavy. It produces a licence. Banks, by contrast, apply a continuous, relationship-based risk assessment that extends well beyond the licensing documentation. They want to see how the compliance programme actually runs: transaction monitoring output, Suspicious Activity Report filing rates, customer risk ratings in practice, and the staffing behind each function.
Under the MiCA regime administered by ESMA and national competent authorities, a CASP (crypto-asset service provider) authorisation requires detailed AML/CFT policies. Those policies satisfy the regulator. They do not automatically satisfy a correspondent bank's financial-crime compliance desk, which may ask for monthly transaction statistics, a breakdown of customer jurisdictions, and evidence of Travel Rule implementation on specific transfer corridors. These are operational questions. A business that answered them at authorisation stage but has not maintained live records to answer them again – at short notice, in a format a non-specialist banker can read – will lose the banking relationship even if its regulatory status is impeccable.
We regularly advise clients to treat the banking due-diligence pack as a standing document, not a one-time submission. The businesses that retain their fiat rails are the ones that can produce an updated compliance summary in response to a banker's query within forty-eight hours, not four weeks.
How Does the EMI Onboarding Process Work for Crypto Businesses?
For digital-asset businesses that cannot obtain a direct relationship with a clearing bank, an EMI (electronic money institution) or a licensed payment institution represents an intermediate layer that provides access to fiat rails without requiring the business to hold a full payment licence itself. EMI onboarding has its own compliance burden, and it is not markedly lighter than the direct correspondent bank path.
EMIs operating under regimes such as the FCA's UK payment services framework or the equivalents enforced by national competent authorities under EU payment services law are themselves subject to AML/CFT oversight. They in turn conduct customer due diligence on the businesses they onboard. An EMI serving a crypto exchange is required to understand the exchange's customer base, its compliance programme, and – crucially – its Travel Rule procedures, because transfers processed through the EMI's rails may carry virtual asset transfer data that triggers the EMI's own information-transmission obligations.
In practice, EMI onboarding involves three phases. The first is initial screening: the EMI reviews the VASP's licence status, jurisdiction of incorporation, beneficial ownership, and product description. Many applications fail here, not because the business is non-compliant, but because the EMI's risk appetite categorically excludes certain product types or user geographies. The second phase is compliance documentation: the EMI requests AML/CFT policies, a compliance officer CV, transaction monitoring system details, and evidence of Travel Rule capability. The third phase is commercial negotiation: the EMI sets reserve requirements, volume caps, and pricing that reflect its own cost of carrying the relationship.
Operators we advise routinely underestimate the time the third phase takes. Reserve requirements and volume caps set at onboarding can constrain a business's growth for a year or more if not negotiated carefully at the outset.
The Cross-Border Compliance Burden: Where the Entity Sits Versus Where the Bank Sits
A VASP licensed in one jurisdiction frequently needs banking access in a different jurisdiction. The entity may be authorised by VARA in Dubai but require EUR settlement through a European correspondent. It may hold a CASP authorisation issued by a Lithuanian regulator but need USD clearing through a US correspondent bank subject to FinCEN oversight. Each leg of that structure introduces a separate regulatory framework and a separate banking compliance assessment.
This is where the structural choices made at incorporation stage have their most consequential downstream effects. A holding company in a jurisdiction that appears on the FATF grey list – or that a correspondent bank treats as elevated-risk regardless of formal listing – will contaminate the banking application even if the operating entity sits in a clean jurisdiction. The correspondent bank looks through the structure. It maps the group, traces the ultimate beneficial ownership, and applies its highest risk-band to the whole relationship.
The cross-border reality also affects the Travel Rule compliance analysis. Different corridors have different data-transmission thresholds, different approved messaging formats, and different expectations regarding information about unhosted wallets. A business operating across multiple jurisdictions must maintain a Travel Rule programme that satisfies the most demanding applicable standard on each corridor, not merely the standard of its home regulator. In our cross-border practice, we have seen licensing applications that pass domestic scrutiny rejected at the banking stage because the applicant's Travel Rule procedures covered only its home jurisdiction's threshold and ignored the stricter requirements of its key settlement corridor.
The mid-point assessment matters here. If your current structure was designed for a single market and you are now expanding, the banking and compliance architecture needs to be rebuilt, not merely extended.
What De-Risking Actually Costs, and Who Bears It
De-risking is not a neutral regulatory outcome. It transfers compliance risk from the correspondent bank to the digital-asset business and, ultimately, to the end user. A VASP that loses its banking relationship must either find an alternative or suspend operations. Finding an alternative takes time – measured in weeks to months, not days – during which the business cannot settle obligations, cannot pay staff in fiat, and cannot honour withdrawal requests in the currencies its customers expect.
The cost is not only operational. A bank account closure may trigger notification obligations to the regulator, depending on the jurisdiction. Under certain licensing regimes, a material change in payment infrastructure is a notifiable event. A business that fails to notify faces the additional risk of a regulatory sanction layered on top of its banking problem.
We have seen this sequence in practice. In one recent matter, a payment services company operating across two jurisdictions had its primary EUR settlement account closed by the correspondent bank following a routine periodic review. The account closure triggered a notification obligation to one of its regulators. The regulator's inquiry focused not on the account closure itself, but on whether the business's safeguarding arrangements for client funds had remained continuously compliant during the period when alternative banking was being arranged. The business had assumed that once it secured a replacement account, the matter would close. It had not factored in the regulator's retrospective view of the gap period. We were brought in to manage the regulatory correspondence and to document the steps taken during the interruption. The outcome was satisfactory, but the process consumed several months and management resources that had been allocated elsewhere.
That pattern – a banking disruption producing a secondary regulatory inquiry – is increasingly common. Regulators in the major hubs are attentive to the indicators of financial instability in the businesses they supervise, and an unplanned bank account closure is one of those indicators.
Decision Matrix: Which Banking Path Fits Which Operator Profile?
There is no single answer to the question of how a digital-asset business should structure its fiat access. The right path depends on the business's regulatory status, its transaction profile, its user geography, and the jurisdictions in which it needs to settle. The following profiles reflect patterns we see regularly in practice.
Profile A: A CASP-authorised exchange with EU-resident users requiring EUR and GBP settlement. The optimal path is a direct relationship with an IBAN provider or payment institution within the EU/UK regulatory perimeter, supplemented by an EMI for jurisdictions where a direct relationship is not available. The compliance burden is highest here. The exchange must produce a full AML/CFT programme, a Travel Rule implementation plan, and evidence of ongoing transaction monitoring calibrated to its user geography. The timeline from a well-prepared application to account opening is typically a matter of months, varying by the specific institution.
Profile B: A custody-only operator with institutional clients and no retail payment volumes. The banking risk profile is materially lower because the transaction volume is lower, the client population is more easily verified, and the product does not involve retail payment processing. Some traditional private banks and family-office banking desks will consider custody operators that do not run an exchange. The compliance burden remains significant – beneficial ownership, governance, and AML/CFT documentation is still required – but the breadth of banking options is wider than for an exchange.
Profile C: A token issuer raising capital through a private placement with no ongoing payment processing activity. Banking access during the issuance period is a discrete problem: the issuer needs to receive subscription proceeds and return capital to investors if conditions are not met. A short-term account relationship with a bank familiar with structured issuance may be achievable, even where a long-term relationship would not be. The compliance burden is concentrated on the source-of-funds and investor-verification documentation rather than on ongoing AML/CFT monitoring of a customer population.
Profile D: A cross-border money-transfer business using stablecoins for settlement with retail end-users. This profile attracts the highest correspondent-bank scrutiny. The combination of retail exposure, stablecoin mechanics, and cross-border transfer activity triggers the full range of FATF Recommendation 15 expectations, including Travel Rule compliance on every qualifying transfer. Banking access for this profile often requires a dedicated regulatory strategy, a jurisdiction-by-jurisdiction licensing analysis, and a phased rollout that builds banking relationships in lower-scrutiny corridors before expanding to higher-scrutiny ones.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. To map the licence, banking and compliance stack for your specific profile, write to OBOLUS at info@oboluslaw.com.
Common Structural Mistakes That Block Banking
The most damaging structural mistakes are those made before the banking application is filed. Reversing them after the fact requires regulatory notifications, corporate restructuring and, in some cases, a new licensing application – all of which take time and capital that could have been avoided.
The first and most common mistake is locating the holding company in a jurisdiction that the target bank treats as elevated-risk, without a business rationale for that location that the bank can document. Banks are required to understand why a group structure looks the way it does. "Tax efficiency" is an answer that invites further scrutiny. "The operating entity is licensed here and the holding company is here because the founding shareholders are residents of this jurisdiction" is an answer that can be documented and closed.
The second mistake is treating the AML/CFT programme as a document rather than as a function. A compliance manual that was written by a consultant eighteen months ago and has not been updated since will fail a banking review. Banks ask for evidence that the programme is live: recent transaction monitoring alerts and their disposition, recent SAR filing records, evidence of ongoing staff training. A static document is not evidence of a live function.
The third mistake is underinvestment in Travel Rule infrastructure before approaching banks. The Travel Rule – derived from FATF standards and implemented at varying thresholds across the major VASP regimes – requires that originator and beneficiary information travel with qualifying virtual asset transfers. A business that cannot demonstrate Technical capability to transmit and receive that information on its key corridors will face a blocking question in any banking due-diligence process that extends to transaction-level review.
A fourth mistake, specific to the cross-border context, is failing to obtain allied counsel in the relevant jurisdiction before filing. Banking applications in Singapore under the MAS Payment Services Act regime, or in Hong Kong under the SFC VASP framework, are assessed against local regulatory expectations that diverge in important respects from EU or UAE practice. A compliance programme designed to satisfy one regime will not automatically satisfy another.
A Common Assumption That Experience Does Not Support
A common assumption among founders entering the digital-asset sector is that a single offshore licence – a BVI VASP Act registration, a Cayman Islands registration under the applicable CIMA regime, or a similar light-touch structure – is sufficient to support global operations, including fiat banking, across major markets. That assumption is incorrect, and acting on it is one of the most reliable ways to end up without banking.
Offshore structures serve legitimate purposes. They are appropriate for holding-company functions, for certain fund structures, and as part of a layered group architecture where the operational entity carries the substantive regulatory authorisation. They are not, in isolation, a basis for accessing correspondent banking in the EU, the UK, Singapore, or the United States. A correspondent bank in Frankfurt or New York will not substitute a BVI registration for the MiCA CASP authorisation or the FinCEN MSB registration that it expects to see in an institution it clears for.
The practical consequence is that businesses built on a single offshore licence that attempt to scale into regulated markets face a restructuring exercise at exactly the point when they can least afford one: after they have committed capital, hired staff, and signed commercial agreements on the assumption that banking access would follow. We have seen this pattern more than once. It is entirely avoidable with the right analysis at the design stage.
This does not mean every business needs a licence in every jurisdiction it serves. It means the licence stack – the combination of authorisations held across the operating, custody, and payment layers – needs to match the actual banking, user, and settlement geography of the business. Getting that match right requires a cross-border analysis that addresses each layer separately before the first banking application is filed.
Client Money Safeguarding and Its Banking Implications
Client-money safeguarding – the obligation to hold client funds in a manner that protects them in the event of the business's insolvency – intersects with correspondent banking access in ways that are frequently underestimated. The safeguarding obligation requires that client money be held in a designated account at an approved institution, segregated from the firm's own funds. That designated account is itself a banking relationship that must be established and maintained.
Under most regulated payment-services regimes, the list of approved institutions for safeguarding purposes is defined by the relevant regulator. Not every bank that agrees to open an account will qualify as an approved safeguarding institution. A business that opens a payment account with an EMI and then proposes to use that EMI account for safeguarding may find that its regulator's guidance disqualifies the arrangement. The business then has two banking problems: an operating account and a safeguarding account, each with its own due-diligence process.
Regulators increasingly expect safeguarding arrangements to be put in place before authorisation is granted, or immediately upon it. A business that delays the safeguarding banking application on the assumption that it can be resolved after launch may face a condition on its licence that prevents it from accepting client funds until the arrangement is in place. That condition can effectively delay launch by months.
In our cross-border practice, we have seen safeguarding requirements in one jurisdiction interact with banking-access restrictions in another in ways that required a creative structuring solution: for example, using an approved institution in a third jurisdiction to hold safeguarded funds for a business whose primary operating account was in a jurisdiction where no approved safeguarding institution would onboard it. These solutions are available, but they require advance planning and, typically, allied counsel in each relevant jurisdiction.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital-Asset Businesses – How OBOLUS structures fiat-rail access across licensing, compliance and banking layers.
- De-Risking and Account Closure Defence in Canada – Defending against account closures and correspondent de-risking in the Canadian market.
- Travel Rule Compliance Programme for Regulated Entities – Building a Travel Rule programme that satisfies regulators and correspondent banks alike.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily through de-risking: a decision to exit entire customer categories rather than assess individual compliance quality. The drivers include the AML/CFT compliance cost of monitoring high-transaction-volume clients, uncertainty about regulatory status in the VASP's home jurisdiction, inadequate Travel Rule documentation, and structural features – such as a holding company in an elevated-risk jurisdiction – that raise the correspondent's aggregate compliance burden. A well-documented compliance programme and a clear group structure materially reduce closure risk.
How can a VASP onboard with an EMI?
A VASP onboards with an EMI (electronic money institution) by satisfying the EMI's own customer due-diligence process, which typically requires a valid regulatory authorisation, a current AML/CFT policy, evidence of a live transaction-monitoring function, Travel Rule capability documentation, and beneficial-ownership disclosure. The EMI then sets commercial terms – reserve requirements, volume caps, pricing – that reflect its risk assessment of the VASP's business. Negotiating those terms at the outset, rather than accepting standard terms, is important for businesses with material transaction volumes.
What does client-money safeguarding require?
Client-money safeguarding requires that funds received from clients be held in a designated, segregated account at an institution approved by the relevant regulator, separate from the firm's own operating funds. The approved-institution list varies by regime. Most regulated payment-services frameworks require safeguarding arrangements to be in place at or before authorisation. A business that cannot establish a qualifying safeguarding account may face a licence condition preventing it from accepting client funds until the arrangement is confirmed with the regulator.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit – so the banking question is answered at the design stage, not after the first rejection. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP authorisation requirements and correspondent banking compliance across EU and Gulf hub jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.