Correspondent banking – the system by which banks hold accounts for one another to process cross-border payments – is the artery through which fiat currency flows into and out of the digital-asset economy. When that artery closes, the business model collapses. Token issuers, exchanges and VASPs (virtual asset service providers) that built their growth on an assumption of stable fiat access are discovering, often abruptly, that the legal and commercial lines governing correspondent access are more precise, and more easily crossed, than their original structuring anticipated.
The central legal question is not whether a crypto business deserves a bank account. It is whether the bank's own regulatory obligations – anti-money-laundering rules, risk-based correspondent due diligence, and in many jurisdictions explicit supervisory guidance on de-risking (the practice of wholesale exit from perceived-risk client categories) – permit continued access once a regulator, a compliance function or a global correspondent flags the relationship. Operating without a clear answer to that question exposes the business to frozen fiat rails (the payment infrastructure connecting crypto platforms to traditional banking) and, in the worst case, to enforcement action triggered by the account closure itself.
This analysis maps the legal architecture around correspondent banking access, explains the regulatory logic that drives bank decisions, and sets out the structural steps a digital-asset business can take to reduce the risk of losing the rails it depends on.
The Correspondent Banking Architecture and Why Crypto Triggers It
Correspondent banking access is not a single relationship – it is a chain. A local or regional bank that wants to clear US dollars, euros or sterling must itself maintain a correspondent account with a bank that has direct access to those payment systems. That upstream correspondent imposes its own compliance requirements on the downstream bank, which then flows those requirements to the downstream bank's customers, including any EMI (electronic money institution) or payment firm that a crypto business relies on for fiat settlement.
The critical legal exposure sits at two points in the chain. First, at the VASP-to-payment-firm interface: when a crypto exchange or custodian opens an account with an EMI or a smaller payment institution, that institution is itself subject to supervisory scrutiny from its national regulator – the FCA under the UK Money Laundering Regulations, a national competent authority under MiCA, or MAS under Singapore's Payment Services Act. The institution must satisfy itself that its own AML controls are not compromised by the crypto client's activity. Second, at the payment-firm-to-correspondent interface: the upstream correspondent bank applies a separate, often more conservative, risk appetite that may have nothing to do with the payment firm's individual compliance posture and everything to do with that bank's global policy toward entire customer categories.
In our cross-border practice, we have seen businesses onboarded by a well-regarded European EMI only to discover, months later, that the EMI's own correspondent had flagged the relationship and required the EMI to exit it. The business had done nothing wrong. The legal lines were drawn upstream.
Related at OBOLUS
- Banking, Payments & EMI Onboarding – how we structure fiat access for digital-asset businesses across jurisdictions
- Legal counsel for crypto payment firms – practice-specific guidance for payment firms in the digital-asset space
- Digital asset custody licensing – regulated custody structures that can support banking access
If your business is assessing a new banking structure or has recently lost a correspondent relationship, OBOLUS can map the regulatory and commercial options across the relevant jurisdictions. The analysis above describes the standard pressure points. Your entity structure, user base and transaction profile change the answer. Map your options.
What the Law Actually Requires of Banks in the Correspondent Chain
Banks are not legally prohibited from banking crypto businesses in most major jurisdictions – but the regulatory regime around correspondent due diligence creates a structural incentive to decline. Under the FATF Recommendations, including Recommendation 13 on correspondent banking and Recommendation 15 on virtual assets, a correspondent bank must apply enhanced due diligence to respondent institutions and must satisfy itself that the respondent has adequate AML/CFT controls. Where the respondent's customer base includes VASPs, that inquiry extends, in practice, to the VASP's own compliance posture.
ESMA and the European Banking Authority have both issued supervisory guidance cautioning against blanket de-risking while simultaneously requiring banks to apply risk-based due diligence to their payment-institution clients. The tension is real: a bank told it cannot de-risk entire categories must nonetheless demonstrate to its own supervisors that each retained relationship is individually assessed. For a large correspondent processing thousands of respondent relationships globally, that individual-assessment burden pushes commercially toward the exit anyway.
In the US, FinCEN's guidance on money services business banking makes clear that banks are expected to assess individual MSB customers rather than refuse the category wholesale. The New York Department of Financial Services – through its BitLicense regime – has a distinct supervisory overlay for crypto businesses operating in New York. Despite this guidance, the practical reality in our experience is that many US correspondent banks apply internal policies that treat crypto-adjacent business as an elevated-risk category requiring senior credit committee approval, a level of scrutiny that smaller payment firms cannot realistically satisfy.
The legal line, then, is this: a bank is not entitled to close an account arbitrarily, but it is entitled to exit a relationship that its own risk-based assessment determines creates a compliance burden it cannot manage. Challenging that assessment requires demonstrating, with specificity, that the bank's process was procedurally improper – a high bar in most jurisdictions.
Why Your Licence Category Determines Your Banking Access
The single most important structural variable in correspondent banking access for a digital-asset business is the regulatory category under which it operates – because that category determines what compliance representations the business can credibly make to a bank and to the bank's upstream correspondent.
A business operating under a payment licence (a full authorisation rather than a registration) in a recognised jurisdiction carries materially different weight than a business operating under a lighter-touch regime. Under MiCA, a CASP (crypto-asset service provider) authorisation granted by a national competent authority and passportable across the EU/EEA sits on one end of the spectrum. A registration in an offshore jurisdiction with minimal supervisory infrastructure sits at the other. Banks – and their correspondents – apply informal but consistent hierarchies: regulated entities in FATF-equivalent jurisdictions with ongoing supervisory reporting obligations are easier to onboard than entities whose primary licence is in a jurisdiction that a global correspondent has not independently assessed.
VARA in Dubai, the FSRA within ADGM in Abu Dhabi, MAS in Singapore, the SFC in Hong Kong and FINMA in Switzerland all sit in the upper tier of that informal hierarchy. Businesses holding authorisations from those regulators can make specific, verifiable claims about AML/CFT programme quality, capital adequacy and ongoing supervisory oversight. Those claims reduce the compliance burden on the correspondent bank and, in turn, reduce the incentive to exit the relationship.
The myth we hear regularly is that a single offshore registration is sufficient to serve clients globally. It is not. A business with a Cayman or BVI registration – both legitimate frameworks under CIMA and the BVI FSC respectively – that wishes to serve EU, UK or US customers will face questions about its AML/CFT programme that those registrations alone may not answer to a correspondent's satisfaction. The licence stack must match the customer and transaction profile.
How Do Banks Actually Assess a Crypto Business Account Application?
A crypto business applying for correspondent-capable banking typically faces a structured due diligence process that extends well beyond the standard KYB (know-your-business) pack. Understanding what the bank is actually assessing – and why – allows a well-advised business to position itself precisely rather than generically.
Banks assess four primary vectors. The first is jurisdictional coverage: where does the business operate, where are its customers, and where does transaction flow originate? A business onboarded in Lithuania for EU customers but also serving users in jurisdictions on a correspondent's high-risk country list creates a structural mismatch that the bank must resolve in its own risk committee. The second is the AML programme itself: the bank wants evidence of a functioning Travel Rule compliance framework, a transaction monitoring system appropriate to the volume and complexity of the business, and a senior compliance officer with documented authority. Third is the counterparty profile: who are the business's own customers, and what is the concentration risk? A crypto exchange with a diverse retail or institutional client base is assessed differently from one with a small number of high-value counterparties in volatile jurisdictions. Fourth is the business model: the bank distinguishes between an exchange settling spot transactions and a platform offering leveraged derivatives or complex structured products, because the AML risk profile differs materially.
We regularly advise clients preparing these packages. The most common failure we observe is a mismatch between what the business says its AML programme does and what the documentary evidence shows it actually does. A correspondent bank's compliance team will read the programme documentation and test it against the transaction data. Inconsistencies at that stage rarely result in a revised application – they result in a decline.
If a prior application stalled or a banking relationship was terminated, there is usually a recoverable structural reason. A second read of the compliance package, the entity structure and the correspondent's stated objections typically identifies the specific gap. Map your options.
The Cross-Border Reality: Multiple Entities, Multiple Rails
Digital-asset businesses that operate across more than one jurisdiction face a compounding problem: correspondent banking access is not portable. A euro account held through a Lithuanian EMI does not provide GBP clearing through a UK correspondent. A Singapore-regulated payment firm does not automatically access USD correspondent rails through that licence alone. Each currency corridor requires a separate correspondent relationship, and each carries its own diligence burden.
The practical implication is that a business serving clients in the EU, the UK and the US simultaneously must maintain separate regulated relationships – typically an EU EMI or CASP, a UK FCA-registered or authorised entity, and some form of US money-services-business registration or state money-transmitter licensing – and must ensure that each of those entities can independently satisfy the correspondent requirements of the relevant banking system. Where one entity fails that test, it does not just lose its own rail; it can create a reputational signal that affects the onboarding of the others.
Operators we advise routinely underestimate the banking implications of their entity structuring decisions. A holding company in a zero-tax jurisdiction may be appropriate for the group structure, but it will not be the entity that opens the correspondent-capable bank account. The licensed operating entity must be the account-holding entity, with its own capital, its own compliance function and its own regulatory relationship. Layering the bank account through the holding company, or through an intermediate entity that itself lacks regulatory standing, is a structure that sophisticated correspondents will identify and reject.
The cross-border dimension also activates the Travel Rule – the obligation under FATF Recommendation 16 to pass originator and beneficiary data with a virtual-asset transfer. A VASP that cannot demonstrate Travel Rule compliance cannot credibly represent to a correspondent bank that its transaction flow is fully traceable. In our experience, Travel Rule readiness has become a de-facto prerequisite for correspondent onboarding in leading jurisdictions, even where the domestic regulator has not yet made it a formal enforcement priority.
Decision Matrix: Which Structure for Which Operator Profile?
Correspondent banking access is not a single problem with a single solution. The appropriate structure depends on the operator's business model, customer base, revenue currency and regulatory appetite. The following profiles describe the principal decision branches we work through with clients.
Profile A – EU-focused exchange or custody provider. The primary instrument is a MiCA CASP authorisation from a national competent authority in a jurisdiction with an established supervisory track record. The CASP passport covers the EU/EEA, and the authorisation provides the compliance representation that EU correspondents require. Banking access is typically sought through a European systemic or regional bank with a demonstrated digital-asset client programme. The timeline from licence application to operational banking is measured in months, not weeks, because the CASP authorisation process itself has its own review period. The key risk is that the national competent authority's capacity to process applications varies, and delays in authorisation delay correspondent onboarding.
Profile B – Multi-jurisdictional platform targeting UAE, EU and Asia simultaneously. This profile requires a parallel-track licensing strategy: VARA or FSRA authorisation for the UAE corridor, a MiCA CASP or an established EU payment licence for euro rails, and a MAS Digital Payment Token licence for the Singapore leg. Each licensed entity holds its own banking relationship. The compliance infrastructure must be coordinated centrally but represented locally to each correspondent. The cost and operational complexity are material; the alternative – operating all corridors through a single lightly regulated entity – is the structure most likely to trigger correspondent exit.
Profile C – Token issuer seeking fiat settlement for token sales and redemptions. This profile typically requires EMI onboarding rather than a full banking relationship. The EMI must itself be authorised in a jurisdiction whose regulator the upstream correspondent respects, and the token issuer must be able to demonstrate that its activity falls within the scope of the EMI's own permissions. Token structures that blur the line between payment and investment activity create diligence complexity that EMIs – under pressure from their own correspondents – are increasingly unwilling to accept without external legal opinion on classification.
Micro-Matter: Correspondent Exit Mid-Operation
In a recent matter, a payments company holding a recognised EU payment authorisation received notice from its primary correspondent bank that the relationship would be terminated within a contractually specified period. The stated reason was a revision to the correspondent's global policy on digital-asset-adjacent businesses. No specific compliance failure was identified. The business's own authorisation was current and its AML programme had passed its most recent supervisory review.
We were engaged to assess the position and identify a remediation path. The analysis identified two parallel tracks. First, a legal review of the termination notice against the account terms and the applicable national consumer and commercial banking law, to assess whether there was a procedural ground for challenge or a right to a reasoned explanation. Second, a concurrent banking search across alternative correspondents in two EU jurisdictions and one offshore centre, using the client's existing regulatory status as the primary positioning document.
Within the notice period, an alternative correspondent relationship was established in a different EU member state, maintaining continuity of the euro rail. The legal challenge to the original termination served its purpose as a negotiating tool – it created the time window necessary for the alternative to be operational. The business continued without interruption to its clients. The episode illustrated a central principle: correspondent exit is rarely a legal emergency in isolation, but it becomes one if no alternative structure has been pre-positioned.
What Does Client-Money Safeguarding Require in This Context?
Client-money safeguarding – the regulatory obligation to hold client funds in segregated accounts, separate from the firm's own money – intersects with correspondent banking access in a way that many operators underestimate until it creates a practical crisis.
Under most regulated payment and EMI frameworks, client funds must be safeguarded by one of two methods: holding the funds in a segregated account at a credit institution, or covering the funds with an insurance policy or guarantee from an authorised third party. The first method – the one most operators use – requires a bank account specifically designated and structured for safeguarding purposes. That account must be held with a bank that understands and accepts the safeguarding purpose, and the account agreement must typically reflect specific legal terms about the segregation obligation.
When a correspondent relationship fails, the safeguarding account is at risk before the operational account. Banks sometimes hold the safeguarding account and the operational account at the same institution, and a termination of the correspondent relationship can affect both simultaneously. A business that loses its safeguarding account faces an immediate regulatory compliance failure – independent of anything else – because it can no longer demonstrate that client funds are properly protected.
Regulators under the MiCA regime, under the FCA's payment services framework, and under MAS's Payment Services Act all treat safeguarding failures seriously and, in some circumstances, as grounds for licence suspension or revocation. In our practice, we advise clients to treat the safeguarding account as a separate banking infrastructure decision – not as a by-product of the operational account – and to maintain at least one alternative safeguarding provider relationship that can be activated quickly.
Objection Handler: The Single-Licence Myth and What It Actually Costs
A common assumption among founders and CFOs entering the digital-asset space is that a single well-chosen offshore licence provides sufficient regulatory cover to access the banking and payment rails necessary to operate globally. This assumption is commercially understandable – licence applications are expensive, slow and operationally demanding – but it is legally and practically incorrect, and acting on it carries costs that exceed the savings.
The mechanism is straightforward. A correspondent bank in a major financial centre applies its own risk criteria to the respondent bank's customer base. Where a customer holds only an offshore registration in a jurisdiction that the correspondent has not independently assessed as equivalent to a FATF-compliant domestic regime, the correspondent's compliance team must either conduct that assessment itself – at material cost and with uncertain outcome – or decline the relationship. Almost all global correspondents choose the latter. The result is that the offshore-only structure, designed to reduce compliance burden, creates correspondent inaccessibility that is often permanent.
The practical cost of the single-licence approach typically includes: a period of operational disruption while banking alternatives are sought; the cost of restructuring – new entity formation, new licence applications, new compliance infrastructure – conducted under time pressure rather than on a planned basis; and, in some cases, a supervisory inquiry triggered by the account closure itself, which correspondents are in some jurisdictions obliged to report. We have seen businesses spend materially more remedying an inadequate original structure than they would have spent building the right one from the outset.
Related at OBOLUS
- Banking, Payments & EMI Onboarding – the full practice guide to structuring fiat access
- Legal counsel for crypto payment firms – sector-specific guidance for payment-adjacent operators
- Digital asset custody licensing – custody authorisations that support banking and safeguarding access
Self-Assessment: Can Your Current Structure Sustain Correspondent Access?
Before committing to a banking structure or accepting the terms of an EMI onboarding, a digital-asset business should be able to answer the following questions with documentary evidence – not assertions.
Does the licensed entity hold the bank account directly, or is the account held through an intermediate entity that lacks regulatory standing? Is the licence category in the operating jurisdiction one that the target correspondent bank and its own upstream correspondent have previously accepted? Does the AML programme documentation match the transaction monitoring system actually in use, and has that match been verified by an independent review? Is the Travel Rule compliance framework operational – not planned, not in deployment, but operational – for the transaction types the business processes? Is the safeguarding account held with a separate institution, or at least under a separately documented arrangement, from the operational account? Has the business mapped the currency corridors it needs and identified a regulated, correspondent-capable entity for each?
If any of these questions cannot be answered with a clear yes supported by documentation, the banking position is structurally vulnerable. Correspondent exit, where it comes, comes quickly – and the notice period in most account agreements is shorter than the time required to establish an alternative relationship from scratch.
FAQ
Why do banks close crypto company accounts?
Banks close digital-asset business accounts primarily because of their own correspondent banking obligations. A global correspondent bank may impose restrictions on respondent banks' exposure to crypto-adjacent customers, regardless of the individual business's compliance record. The legal basis is the bank's right to exit relationships that its own risk-based assessment identifies as creating a compliance burden it cannot manage. A regulatory authorisation in a well-supervised jurisdiction reduces – but does not eliminate – that risk.
How can a VASP onboard with an EMI?
A VASP seeking EMI onboarding must demonstrate that its AML/CFT programme meets the standard the EMI's own regulator requires. In practice, this means providing a current AML policy, evidence of a functioning transaction monitoring system, Travel Rule compliance documentation, and a description of the customer base with its risk profile. EMIs operating under MiCA or the FCA framework are themselves subject to supervisory scrutiny of their client lists, so the VASP's compliance quality directly affects the EMI's willingness to take on the relationship.
What does client-money safeguarding require?
Under most regulated payment and EMI frameworks, client funds must be held in a segregated account at a credit institution, separate from the firm's own assets, or covered by an insurance or guarantee arrangement. The safeguarding account must be specifically structured for that purpose, and the account agreement must reflect the segregation obligation. Losing the safeguarding bank relationship – not just the operational account – creates an immediate regulatory compliance failure that can trigger supervisory action independent of any other issue.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence, banking and compliance stack across operating, custody and payment layers before you commit – because the cost of rebuilding a failed structure under time pressure consistently exceeds the cost of building it correctly from the outset. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialist in cross-border VASP authorisation, correspondent banking access and AML programme structuring for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.