EST · MMXXVI
Home/Insights/Regulatory/De-risking and account closure defence: Where the Legal Lines Are Drawn
Banking, Payments & EMI Onboarding

De-risking and account closure defence: Where the Legal Lines Are Drawn

De-risking and account closure defence: Where the Legal Lines Are Drawn. Cross-border digital-asset legal counsel for business – licensing, disputes and structu

For a digital-asset business, losing a bank account is not an administrative inconvenience. It is an existential event. De-risking – the practice by which regulated financial institutions terminate or restrict services to entire categories of customer rather than conducting individual risk assessments – has closed fiat rails for exchanges, custodians, payment firms and token issuers across every major operating jurisdiction. The legal question is whether that closure is reviewable, reversible or avoidable in the first place.

The answer is fact-specific and jurisdiction-dependent, but the architecture of the problem is consistent. Banks exercise contractual termination rights that are broad on their face; regulators in many markets provide no express right of access to payment infrastructure; yet a growing body of administrative, competition and human-rights law places real constraints on what a financial institution can lawfully do when it exits a category rather than a customer. Operators who understand those constraints before closure – not after – are materially better positioned to preserve their fiat stack.

This analysis maps the legal terrain: where bank discretion ends, where supervisory leverage begins, how the cross-border reality of crypto banking intersects with EMI onboarding, and what a structured defence actually looks like.

What de-risking actually is – and why it keeps happening

De-risking is a systemic response to regulatory pressure, not a product of individual credit or compliance decisions. A financial institution that processes payments for virtual-asset service providers (VASPs) carries the AML/CFT exposure of those VASPs on its own books. Supervisors in the US, the UK and across the EU have made clear – through enforcement actions, guidance and examination priorities – that transaction monitoring for crypto-related flows is resource-intensive and the tail risk of a regulatory finding is high. The rational institutional response is category exit.

The result is a two-tier banking environment. Larger, established crypto businesses with strong compliance programmes and recognisable regulatory footprints can generally secure and maintain institutional relationships. Earlier-stage operators – particularly those licensed in non-G7 jurisdictions or still building their AML infrastructure – encounter a structural reluctance that no volume of due-diligence documents will reliably overcome. FATF Recommendation 15 and its interpretive note extended the FATF framework to virtual assets and VASPs, but that expansion has, in practice, intensified the scrutiny banks apply rather than reducing the de-risking incentive.

Understanding the incentive is important because the legal defence depends on it. If a bank exits a customer because of a genuine, documented compliance finding, the legal options are limited. If it exits a category reflexively – with no individual risk assessment and no opportunity for the customer to address the concern – the picture changes significantly.

What does the banking contract actually say?

Most correspondent banking agreements and business current account terms include a termination-for-convenience clause: the bank may close the account on notice, typically 30 to 90 days, without giving reasons. That clause is wide, but it is not unlimited.

The first constraint is procedural. Notice periods must be respected. An immediate freeze without notice – absent a mandatory hold imposed by law enforcement or a sanctions designation – may give rise to a breach of contract claim, particularly where the operator can show financial loss flowing from the abrupt closure. In our practice, we regularly advise operators to document loss in real time from the moment a freeze is applied, precisely because that contemporaneous record is the foundation of any damages claim.

The second constraint is implied terms. In several common-law jurisdictions, courts have held that contractual rights of termination are subject to an implied obligation of good faith or reasonable exercise. The extent of that obligation varies by jurisdiction and by the level of the relationship: a transactional clearing account is treated differently from a long-term correspondent arrangement on which a business has demonstrably relied. The practical argument for the operator is that the bank's exercise of a broad contractual right for a discriminatory categorical reason – rather than a customer-specific reason – engages those implied terms.

The third constraint is statutory. Some jurisdictions impose notice or reason obligations by regulation. The FCA's rules in the United Kingdom, for example, require payment service providers to give notice before terminating a payment account and, in some circumstances, to provide a reason. The MiCA regime in the EU creates a regulatory environment in which CASP authorisation is a credible signal of supervised compliance – one that banks are increasingly expected to recognise.

Where does regulatory leverage exist?

Pure contractual analysis rarely resolves a de-risking problem on its own. The more effective route – and the one we pursue first – is supervisory engagement: using the regulatory record of the VASP to put pressure on the bank at the supervisory level.

Several regulators have issued guidance that de-risking entire categories of customer without individual assessment is itself inconsistent with a well-calibrated compliance programme. The Financial Conduct Authority in the UK has stated explicitly that blanket de-risking is not an acceptable substitute for risk-based assessment. The European Banking Authority has issued guidance in the same direction, and ESMA's engagement with MiCA implementation adds institutional weight to the argument that authorised CASPs should have access to payment services proportionate to their supervised status.

The practical effect is this: a bank that exits an authorised VASP without conducting any individual assessment – and that fails to document the customer-specific basis for its decision – is potentially vulnerable to a supervisory finding of its own. In our cross-border practice, we have used that vulnerability as leverage in pre-litigation engagement, presenting the bank's compliance team with a documented account of the VASP's supervisory status, AML programme and transaction profile. The goal is not to litigate the bank's discretion but to give its compliance function a reason to re-examine the categorical decision.

In Dubai, the VARA (Virtual Assets Regulatory Authority) regulatory licence provides a credible institutional signal. VARA-licensed businesses operating under the full VARA rulebook carry a compliance infrastructure that many correspondent banks will, on proper examination, recognise as meeting or exceeding their own due-diligence threshold. A similar argument applies for ADGM/FSRA-licensed operators and, increasingly, for EU-authorised CASPs under MiCA.

To map the supervisory record that supports your account-retention argument, contact OBOLUS at info@oboluslaw.com. The process above describes the standard engagement path. Your facts – the licence held, the jurisdiction of the bank, the customer base – change the analysis materially.

How does EMI onboarding change the equation?

An e-money institution (EMI) – a firm authorised to issue electronic money and provide payment services – occupies a different position in the fiat-rail ecosystem than a correspondent bank. EMIs typically serve as the first point of access to regulated payment infrastructure for digital-asset businesses that cannot secure direct banking. Understanding how EMI onboarding works, and where it breaks down, is central to any account-closure defence strategy.

Most EMI onboarding processes are risk-appetite exercises. The EMI assesses the VASP's business model, jurisdiction, AML programme, transaction volumes and customer profile against its own risk framework. Authorisation in a recognised jurisdiction – Lithuania under the Bank of Lithuania, Malta under MFSA, or an EU CASP under MiCA – is a significant positive factor. A business operating under the VASP Act 2022 in the BVI or a VATP licence from the SFC in Hong Kong will generally receive more constructive engagement than one without any regulatory footprint.

Where EMI relationships break down most often is at the Travel Rule layer. The Travel Rule (the obligation, embedded in FATF Recommendation 16 and in the EU's Funds Transfer Regulation, to pass originator and beneficiary data with a virtual-asset transfer) creates a data-sharing obligation that many VASPs have not fully operationalised. An EMI conducting onboarding due diligence will inspect a VASP's Travel Rule compliance posture as closely as its AML policy. Gaps at that layer – inconsistent data collection, no VASP-to-VASP messaging solution in place – are a common ground for EMI rejection or exit, independent of any categorical de-risking decision.

The cross-border dimension matters here specifically. A VASP operating between, say, a Singapore-registered entity and a European user base must demonstrate Travel Rule compliance under both the Payment Services Act regime (MAS) and the applicable EU provisions. Two different data sets, two different procedural obligations – and any EMI onboarding that spans both will scrutinise both. We regularly advise on building the Travel Rule stack before approaching an EMI, precisely because a well-documented solution removes the most common rejection ground.

The cross-border reality: where the account sits versus where the risk lives

Digital-asset businesses are structurally cross-border. The operating entity may be licensed in Lithuania; the custodian may sit in the Cayman Islands; the exchange matching engine may be in a third jurisdiction; the users may be spread across twenty countries. A bank or EMI assessing the relationship is assessing all of that simultaneously, and its risk appetite for each layer is different.

The most common structural mistake we see is a mismatch between the entity that holds the licence and the entity that holds the account. A BVI or Cayman holding entity opening an account for operational purposes – without a corresponding regulated operating licence in a recognised jurisdiction – will face de-risking risk that a properly structured group would not. The fiat-rail architecture should mirror the regulatory architecture. The banking entity should be the same entity – or a directly supervised affiliate – that holds the licence the bank is being asked to recognise.

A second structural issue is correspondent-bank exposure. Many EMIs and smaller banks clear through a major correspondent that has its own crypto risk policy. An EMI that is willing to onboard a VASP may still be unable to process that VASP's transactions if its clearing correspondent applies a categorical block. Understanding the full correspondent chain before an onboarding application – and structuring the relationship to sit within the correspondent's tolerance – is part of a properly prepared fiat-rail strategy.

In our practice, we map the full correspondent chain as part of the initial analysis. A client that understands the banking risk before committing to a licence jurisdiction avoids the situation – more common than it should be – of obtaining a licence in a jurisdiction whose banking infrastructure cannot support the business model.

Account closure reversed: a recent matter

In a recent matter, a payments company licensed in an EU member state received a termination notice from its primary EMI with no customer-specific reason given. The closure was announced on the minimum contractual notice period. We conducted an immediate review of the contract, the EMI's internal AML policies (as disclosed in its public compliance documents) and the client's own supervisory record. We prepared a formal representation to the EMI's compliance function, documenting the client's regulated status, its Travel Rule implementation, its transaction monitoring system and the absence of any adverse supervisory finding. Simultaneously, we engaged the national competent authority responsible for supervising the EMI, drawing its attention to the absence of any individual risk assessment in the termination process. Within a matter of weeks, the EMI reopened engagement, conducted a formal individual assessment and reinstated the relationship subject to enhanced reporting. The client's fiat rails were restored before any material operational disruption occurred.

Which path fits which operator: a practical decision matrix

The right defence or pre-emption strategy depends on three factors: the strength of the operator's regulatory record, the nature of the bank or EMI relationship, and the legal jurisdiction governing the account. The following profiles describe the most common situations we encounter.

Profile A – Authorised VASP in a recognised jurisdiction, account with an EMI, no adverse finding: the strongest position. The primary route is a formal representation to the EMI's compliance function, backed by a structured dossier of the regulatory record, AML programme and Travel Rule implementation. If the EMI fails to conduct an individual assessment, supervisory escalation is the next step. Litigation is rarely necessary and rarely appropriate at this stage.

Profile B – Authorised VASP, account with a clearing bank (not an EMI), termination on notice: the contractual analysis is more complex. The bank's discretion is wider. The most productive path is a combination of regulatory-leverage engagement and a parallel assessment of whether the account sits in a jurisdiction where enhanced statutory protections apply. If the bank is supervised by the FCA or an EU NCA, the supervisory-engagement route has more traction than it would in a purely offshore relationship.

Profile C – VASP without formal authorisation, account in a grey-regulation jurisdiction, termination without notice: the highest-risk profile. The absence of a regulatory record substantially narrows the supervisory-leverage argument. The immediate priority is to assess whether the termination was procedurally defective – no notice, immediate freeze without legal basis – and to preserve any loss evidence. The medium-term priority is to obtain appropriate authorisation, which itself requires a review of the banking infrastructure available in candidate jurisdictions before the licence application is filed.

Profile D – Token issuer or DeFi protocol with no direct banking relationship, relying on a third-party payments processor: the indirect position. Account closure by the processor is contractually simpler for the processor (its own risk policy, its own EMI relationship). The defence here is largely structural: the operator needs diversified fiat-rail access, not a single processor relationship that can be terminated at will.

If a prior application stalled or an account was closed, contact OBOLUS at info@oboluslaw.com. A second review can surface the structural reason and the route back.

A common assumption – and why it is wrong

A common assumption in the market is that a single offshore licence is sufficient to provide a banking solution for a global digital-asset business. This assumption appears with striking regularity in pre-engagement conversations with operators who have already experienced one de-risking event and are preparing to repeat the same structure in a different jurisdiction.

The error is a category mistake. A licence answers the question of whether the operator is permitted to carry on a regulated activity. It does not answer the question of whether a bank will process that operator's transactions. Those are different regulatory questions with different answers. The BVI VASP Act 2022 registration satisfies the BVI regulator. It does not satisfy a Dutch EMI's correspondent bank, which is supervised by the ECB and applies its own AML risk appetite entirely independently of the BVI FSC's supervisory framework.

The solution is a licence stack, not a single licence. The operating entity holds the licence appropriate to its primary market. That entity is banked through an EMI or institution that is supervised in the same or a compatible jurisdiction. The correspondent-banking chain is mapped in advance. Travel Rule compliance is built before the first onboarding application is filed. That architecture requires more planning and, usually, more than one regulatory instrument. But it is the only structure that reliably survives the scrutiny of a real-world institutional due-diligence process.

We map the licence, banking and tax stack for the full operating architecture before a client commits capital. The cost of that mapping is a fraction of the cost of rebuilding fiat rails after a closure event.

What does client-money safeguarding require – and where does it intersect with de-risking?

Client-money safeguarding – the obligation to hold customer funds separately from the firm's own assets, typically in a designated account at an approved credit institution – is a regulated requirement in most payment services and EMI regimes. Under the Payment Services Act in Singapore, under the FCA's payment services rules in the UK, and under the applicable EU payment-services provisions, a licensed firm must demonstrate that it has appropriate safeguarding arrangements in place at the point of authorisation and on a continuing basis.

De-risking creates a direct compliance risk at this layer. If the institution holding the safeguarded funds closes the account, the firm is immediately in breach of its safeguarding obligation. Regulators have little tolerance for firms that allow safeguarding arrangements to lapse, even temporarily, because a banking relationship collapsed. The obligation does not pause for commercial disruption.

The practical implication is that safeguarding accounts should be treated as the highest-priority banking relationship in the firm's fiat-rail architecture, not a secondary consideration. A payment licence without a pre-identified safeguarding institution – with a fallback in place in case the primary relationship changes – is an underbuilt compliance architecture. In our cross-border practice, we regularly advise on dual-safeguarding arrangements that provide continuity across banking disruption without breaching the ring-fencing requirement.

Pre-application checklist: testing your banking readiness

Before a VASP or licensed payment firm approaches an EMI or correspondent bank, the following self-assessment items identify the most common rejection grounds and address them in advance.

  • Regulatory record: Is the operating entity formally authorised in a jurisdiction the target institution will recognise? A letter of good standing from the supervising authority, dated within the last three months, is the foundation document.
  • AML/KYC programme: Is the programme documented, independently reviewed and appropriate to the business model? A policy that was drafted on incorporation and never updated is a rejection ground on its own.
  • Travel Rule implementation: Is a VASP-to-VASP messaging solution in place? Can the firm demonstrate compliant data transfer on the transactions the bank will be processing? This is inspected at onboarding, not assumed.
  • Correspondent-chain mapping: Has the firm identified the correspondent banks that clear the target EMI's transactions? Are any of those correspondents known to apply categorical crypto blocks?
  • Entity structure: Is the account applicant the same entity that holds the licence? If the group structure interposes a holding entity, the bank will need a clear ownership and control diagram – and a reason why the licenced entity is not the account holder.
  • Safeguarding readiness: If the firm will hold client money, is a designated safeguarding institution identified, and is that institution's onboarding process concurrent with the operating account application?
  • Transaction profile: Is the firm prepared to deliver a forward-looking transaction profile – volumes, corridors, average transaction size, counterparty types – that maps to the bank's stated risk appetite?

Addressing each of these before the application is filed is the single most effective de-risking-prevention measure available to a digital-asset operator.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks typically close crypto company accounts because the category-level AML/CFT risk of servicing virtual-asset businesses – intensive transaction monitoring, high regulatory scrutiny from their own supervisors, uncertain tail risk – exceeds their stated risk appetite. The decision is frequently categorical: the bank exits VASPs as a class rather than assessing individual customers. Where no customer-specific compliance finding exists, that categorical exit may be challengeable through supervisory engagement and, in some jurisdictions, contractual or administrative law.

How can a VASP onboard with an EMI?

A VASP seeking EMI onboarding should arrive with four elements in place: a formal authorisation from a recognised regulator; a documented and independently reviewed AML/KYC programme; a functioning Travel Rule implementation with evidence of VASP-to-VASP data transfer; and a clear entity-structure diagram showing the relationship between the licenced operating entity and the account applicant. EMIs assess all four simultaneously. Gaps at the Travel Rule or AML-programme layer are the most common reasons for rejection, and they are addressable before the application is filed.

What does client-money safeguarding require?

Client-money safeguarding requires a licensed firm to hold customer funds in a segregated account at an approved credit institution, separate from the firm's own assets. The obligation is continuous: a banking disruption does not suspend it. Regulators in the UK, the EU and Singapore, among others, expect firms to have a primary safeguarding institution identified at authorisation and a contingency arrangement in place against banking disruption. A firm that allows safeguarding to lapse – even briefly, because an account was closed – faces a regulatory compliance failure independent of the commercial banking issue.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and payment firms on EMI onboarding, fiat-rail structuring and account-closure defence across more than 70 licensing jurisdictions. We map the full licence, banking and safeguarding stack before a client commits capital to a structure – and we act when rails go down. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP authorisation, EMI onboarding strategy and the cross-border regulatory architecture of digital-asset payment businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours