For a digital-asset business, losing a bank account is not an administrative inconvenience – it is an operational crisis. De-risking (the practice by which a bank or payment institution terminates or refuses service to an entire category of customer rather than managing the risk individually) has become the defining compliance challenge for crypto operators seeking stable fiat rails (the banking and payment infrastructure through which digital-asset businesses settle in government-issued currency). The compliance burden this creates is asymmetric: regulators demand documented controls, banks demand proof of those controls, and the operator sits in the middle bearing the cost of both demands simultaneously.
This analysis examines how de-risking operates in practice, why account closures happen even when a business holds a valid licence, and what a cross-border digital-asset operator can do to build a defensible compliance position. The argument runs from the structural incentives driving bank behaviour, through the legal instruments available on account closure, to a decision framework for operators at different stages of build.
What Drives Bank De-risking of Crypto Businesses?
Banks de-risk digital-asset businesses primarily because the expected cost of monitoring and managing the relationship exceeds the expected revenue from it – a calculation that regulatory pressure has tilted heavily against crypto clients. The mechanics are straightforward. A correspondent bank exiting a domestic bank's crypto-customer base forces the domestic bank to choose between losing the correspondent relationship and losing the crypto client. The crypto client loses, almost every time.
The structural drivers are well documented. Anti-money-laundering supervisors in every major jurisdiction – the Financial Action Task Force (FATF), national competent authorities under the EU's anti-money-laundering directives, and regulators operating under the Travel Rule (the obligation to transmit originator and beneficiary data alongside virtual-asset transfers) – have increased examination intensity on virtual-asset exposures. A bank that cannot demonstrate adequate oversight of its crypto clients faces supervisory criticism. The easiest fix is exit.
In our cross-border practice, the pattern is consistent: a business with a lawfully obtained registration in one jurisdiction opens a payment account, operates without incident for several months, and then receives a termination notice citing "risk appetite" or "business decision." No specific conduct is identified. No regulatory finding is cited. The business simply no longer fits the bank's permitted risk profile. That profile is set by a compliance function responding to guidance from the bank's own regulator and, ultimately, from its correspondent banks upstream.
The cross-border angle compounds the problem. A VASP (virtual asset service provider) licensed in Lithuania under the Bank of Lithuania regime, serving customers in Western Europe, processing settlements through a London correspondent, faces scrutiny from at least three regulatory environments. None of them has jurisdiction over the bank's commercial decision to exit. All of them influence it.
For a scoped assessment of your current banking position and the structural reasons for any account friction, contact OBOLUS at info@oboluslaw.com. The analysis above describes the standard pattern. Your specific entity structure, your user base and the currencies you settle will change the risk calculus – and the defence strategy.
What Does the Law Actually Say About Account Closure?
Account closure is not legally unrestricted, but the protections available to a business customer are narrower than most operators assume. In most European jurisdictions, a payment institution or credit institution must give adequate notice before terminating a payment account or framework contract – the applicable notice period is set by the regime governing the relationship, not by individual contract terms. Under arrangements that implement the EU's Payment Services Directive framework, notice requirements exist but are expressed in general terms; the bank retains wide discretion to exercise them on commercial grounds.
The Payment Account Directive (PAD) confers a right of access to a basic payment account – but it applies to consumers and to certain categories of legal persons, not uniformly to commercial entities engaged in regulated financial activity. A VASP operating a licensed exchange business cannot, in most jurisdictions, invoke a universal right to a payment account.
What businesses can invoke is more procedural. Where a bank is publicly designated as a provider of access to a settlement system, or where the termination decision has a competition-law dimension (access to essential infrastructure), there are grounds for challenge. In the United Kingdom, the FCA has issued supervisory expectations around the treatment of customers in the cryptoasset sector, including guidance that de-risking decisions should be based on individual risk assessment rather than blanket category exclusion. Similar supervisory pressure – though at varying levels of formality – exists in jurisdictions such as Singapore (under MAS) and in several EU member states where national competent authorities have expressed concern about financial exclusion of regulated VASPs.
In our practice, we have seen termination notices that cite vague risk-appetite language while the underlying facts show a business with clean transaction histories, current regulatory registration and documented AML controls. In those cases, the compliance record becomes the instrument of defence. The bank's internal credit or compliance file, which in most jurisdictions the business can request subject to data-protection access rights, frequently reveals a checklist-driven process rather than an individual assessment.
The practical route is rarely litigation. It is a structured re-engagement: a compliance dossier assembled to the standard the bank's AML and onboarding functions require, presented with legal framing that makes the refusal of service look like an unreasonable individual-risk decision rather than a policy position. That distinction matters to a bank's compliance officer far more than a formal legal demand.
How Does EMI Onboarding Actually Work for VASPs?
An EMI (electronic money institution) is typically the first realistic alternative when a traditional bank exits a crypto relationship, but onboarding with an EMI is not a frictionless path. EMIs authorised under regimes such as those administered by the FCA, the Bank of Lithuania or national competent authorities under EU electronic money frameworks operate under their own AML obligations and are themselves subject to supervisory scrutiny of their crypto-client portfolios.
The onboarding process for a VASP client at an EMI has several distinct phases. The EMI's compliance team will require a complete picture of the VASP's regulatory status: the jurisdiction of registration, the scope of licensed activities, the jurisdictions in which services are offered, and the customer base profile. It will require AML policies and procedures documentation at a level of detail that many earlier-stage operators have not yet assembled. It will require transaction-monitoring methodology, the identity of the compliance officer (with their background and qualifications), and a description of the Travel Rule implementation in place for transfers above the applicable threshold.
Where the VASP operates across multiple jurisdictions – a common profile in our cross-border practice – the EMI's due-diligence team will map each jurisdiction against its own internal risk matrix. A VASP licensed in the BVI under the BVI FSC's VASP Act with customers in the EU faces different treatment than a CASP authorised under MiCA with passporting rights across the EEA. The MiCA authorisation carries a regulatory imprimatur that the EMI's compliance team can point to in its own supervisory file. The BVI registration, while lawful and operationally legitimate, requires the EMI to conduct more of its own analysis.
In practice, operators who succeed in EMI onboarding do three things consistently. They present a complete, structured compliance dossier – not a set of policies assembled in response to a questionnaire, but a coherent document that tells the business's regulatory story from licence to customer. They identify a named senior compliance contact at the VASP who is available to the EMI's team. And they manage the timeline: EMI onboarding for a crypto client can take significantly longer than for a non-crypto business, and operators who build that lead time into their liquidity planning fare better than those who arrive in an EMI's queue after a bank has already closed their account.
A micro-matter from our recent practice: in the first half of last year, a custody and settlement business that had received a thirty-day termination notice from its incumbent bank engaged us to manage the transition. We assembled the compliance dossier, identified three EMI candidates across two EU jurisdictions, and supported the due-diligence process in parallel. Onboarding was completed before the bank account closed. The business maintained continuous fiat settlement throughout. The critical variable was the dossier: the EMI's compliance team signed off the engagement in materially less time than their stated standard timeline because every document they would have requested was already prepared.
Why a Single Licence Does Not Solve the Banking Problem
A common assumption in the market is that obtaining a licence in a reputable jurisdiction resolves the banking problem: that a VARA licence in Dubai, or a MiCA CASP authorisation in an EU member state, or an MAS digital payment token service licence in Singapore, will open institutional banking as a natural consequence. In our practice, this assumption fails regularly.
The licence answers the regulatory question – it establishes that the business is supervised, that its AML controls have been reviewed, and that it operates within a defined legal perimeter. It does not answer the bank's commercial question. A bank's AML function will read the licence as one input into an individual risk assessment. The nature of the customer base, the volume and origin of transactions, the jurisdictions involved in settlement, and the products offered are all evaluated independently. A business operating a derivatives exchange serving high-volume traders in multiple jurisdictions with complex on-chain settlement flows presents a different risk profile to a custodian holding tokenised securities for institutional clients, even if both hold equivalent licences.
The cross-border dimension is particularly consequential. A business licensed in one jurisdiction but operating services across many – the default reality for most digital-asset businesses given the cross-border nature of the asset class – presents a regulatory perimeter question that a single licence does not resolve. The bank's correspondent network may flag exposure to jurisdictions not covered by the licence. The FATF grey list, sanctions regimes administered by OFAC and national equivalents, and correspondent bank risk matrices are applied to the transaction geography, not to the licence jurisdiction alone.
What the licence does provide – and this is not trivial – is the foundation for a compliance argument. A business that holds a current MiCA CASP authorisation, or that is supervised by VARA, or that holds an MAS licence, is in a materially stronger position than an unlicensed operator when engaging a bank or an EMI. The licence does not guarantee an account. It removes one objection and shifts the conversation to the actual business risk profile.
If your licence is in place but banking relationships remain blocked, the issue is structural – the compliance dossier, the transaction-monitoring description or the cross-border footprint. Write to info@oboluslaw.com for a diagnosis. A prior application that stalled can often be revived with targeted remediation rather than a fresh start.
What Does Client-Money Safeguarding Require in a Regulated Fiat Rails Context?
Safeguarding – the obligation to segregate and protect client funds held by a payment institution or EMI – is one of the compliance requirements that most directly affects how a VASP structures its banking arrangements. Under the regulatory regimes applicable to EMIs and payment institutions in the EU, the UK and Singapore, a licensed EMI or PI holding client funds is required to safeguard those funds either by depositing them in a segregated account at a credit institution or by holding qualifying insurance or a bank guarantee.
The practical consequence for a VASP using an EMI for fiat settlement is layered. The EMI must safeguard client balances held overnight or in transit. The VASP, if it itself holds fiat on behalf of its own customers, may have its own safeguarding obligations depending on whether it holds an EMI or payment institution authorisation. The interaction between the two safeguarding regimes requires mapping: which entity holds the obligation, which account at which institution satisfies it, and how the protection works in an insolvency scenario.
In a cross-border settlement structure – common where a VASP operates in one jurisdiction but settles in another – the safeguarding account itself becomes a structuring question. A safeguarding account in a jurisdiction where the currency is exotic or where the VASP's counterparty banks are not present may not serve the operational purpose even if it satisfies the regulatory obligation technically. Operators we advise routinely encounter this tension: the regulatory-compliant safeguarding arrangement and the operationally efficient settlement structure are not always the same.
The client-money concept extends to digital assets in some regimes. MiCA imposes safeguarding expectations on CASPs providing custody and administration services, with specific requirements for the treatment of client crypto assets in insolvency. VARA's custody and management licence activities carry safeguarding expectations aligned to that framework. The interaction between fiat safeguarding under EMI/PI regimes and crypto-asset safeguarding under CASP or custody regimes requires a coherent structure – and a bank or EMI that understands both will ask about both during onboarding.
The Cross-Border Compliance Matrix: Where Does the Burden Land?
The compliance burden in a de-risking context falls differently depending on where the entity sits, where its users are, and where its banking lives. A decision matrix helps illustrate the main profiles.
An operator with a MiCA CASP authorisation, a customer base in EU member states and a safeguarding account at a regulated credit institution in the same member state presents the most straightforward profile. The regulatory perimeter is clear. The bank or EMI has a known supervisory counterpart. The Travel Rule obligations are defined under the applicable EU regime. Onboarding friction is lower – not absent, but lower. The principal risk is transaction geography: if the CASP onboards customers from high-risk jurisdictions flagged by FATF or ESMA, the profile deteriorates quickly regardless of the licence quality.
An operator with a VARA licence in Dubai, a holding structure in the Cayman Islands, customer accounts across the Middle East and Europe, and a legacy banking relationship in a Central European jurisdiction presents a substantially different picture. The VARA regime is well-developed, but it is not MiCA. The Cayman structure adds a layer of beneficial ownership analysis. The multi-regional customer base creates Travel Rule questions across jurisdictions with varying de-minimis thresholds. The legacy bank's correspondent may have MENA exposure limits. Every link in the chain is a potential de-risking trigger.
Regulators in the leading hubs increasingly expect VASPs to demonstrate that their compliance programme is designed for the actual geographic footprint of the business, not for the jurisdiction of licence alone. An operator with a BVI VASP Act registration and EU customers, or an AFSA-licensed entity under the AIFC regime in Kazakhstan with a global remittance flow, faces audit questions about EU AML compliance or FCA financial-promotion rules – none of which the primary licence addresses directly. In our cross-border practice, we map this multi-layered perimeter before a client commits to a structure, precisely because the banking consequences of getting it wrong are severe.
The decision matrix, in plain terms: a business with a single-jurisdiction operation and a contained customer geography should focus on depth of compliance documentation within that jurisdiction. A business with multi-jurisdictional operations should prioritise regulatory perimeter mapping and the selection of an EMI or banking partner with explicit cross-border risk appetite for its footprint – before the incumbent bank asks the question.
Building the Compliance Dossier That Banks and EMIs Require
The compliance dossier is the instrument through which a digital-asset business communicates its risk profile to a bank or EMI. It is not a collection of regulatory filings; it is a structured argument that the relationship is manageable and the risk is bounded.
In practice, the dossier that succeeds in onboarding or in resisting a termination decision contains several discrete components. The regulatory summary establishes the current licence or registration status in each jurisdiction where the business is supervised, the scope of permitted activities, and the status of any pending authorisations. The AML/CFT section documents the policies and procedures in place, the identity verification and transaction-monitoring technology in use, the identity and qualification of the Money Laundering Reporting Officer, and the suspicious activity reporting record. The Travel Rule section describes the technical implementation, the data fields transmitted and the VASP counterparties to which the obligation applies.
The business profile section explains, in non-technical language, what the business does, who its customers are (by type and geography, without naming individuals), what the average and peak transaction volumes look like, and how fiat and digital-asset flows are separated at the account level. Banks are not crypto experts. A dossier that assumes expertise the bank's compliance team does not have will be filed and forgotten. One that explains the business model in the language of financial crime risk – source of funds, transaction purpose, counterparty types – will be read.
The governance section covers ownership, beneficial ownership and the management team. Ultimate beneficial ownership transparency is not negotiable: any ambiguity here will trigger enhanced due diligence at minimum and termination at worst. Ownership structures involving multi-layer holding companies, nominees or jurisdictions with limited corporate transparency require particular care.
We regularly advise clients on the assembly and presentation of this dossier, both as a proactive onboarding tool and as a defence document when termination notice has been received. The standard of documentation required has risen materially over the past several years. A dossier that would have satisfied a mid-tier EMI's compliance team previously may not meet current expectations – particularly where the EMI itself has received supervisory feedback about the quality of its crypto-client monitoring.
The Objection Handler: Common Assumptions That Lead to Banking Failures
A common assumption in the digital-asset sector is that banking difficulty is a temporary condition – that as regulation matures and the asset class becomes mainstream, bank risk appetite will follow. This assumption underestimates the structural nature of the problem. Correspondent bank risk matrices are updated slowly and are influenced by enforcement actions that may be several years old. A sector-wide de-risking posture, once embedded in a correspondent's risk framework, takes sustained supervisory pressure and demonstrated low-loss experience to shift. Operators who plan for permanent banking friction are better positioned than those who expect the market to improve.
A second common assumption is that diversifying across multiple EMIs solves the problem. It reduces concentration risk – which is real and important – but it does not address the underlying compliance deficit that caused the first account closure. An operator that moves from a closed bank account to an EMI without understanding why the bank exited will encounter the same question from the EMI, usually at a point of greater operational stress.
A third assumption, addressed earlier in this analysis, is the single-licence fallacy: that holding a valid licence in one jurisdiction resolves the banking and compliance question globally. The multi-jurisdictional reality of digital-asset business makes this approach inadequate. The compliance programme must match the operational footprint – across the entity, the customer base and the payment infrastructure.
Operators we advise who have built defensible, durable banking relationships share a common characteristic: they treat compliance documentation as an asset, not as an overhead. They update it proactively, they share it with banking partners before they are asked, and they engage counsel to review the structure before a bank or EMI asks the questions rather than after.
Related at OBOLUS
- Banking, Payments & EMI Onboarding – the full practice area covering fiat rails, EMI selection and account defence for digital-asset businesses.
- EMI Onboarding for VASPs – Institutional Clients – structured onboarding support for exchanges, custodians and funds seeking regulated fiat access.
- Cross-Chain Bridge Legal Risk in France (AMF/PSAN) – analysis of bridge and DeFi exposure under the French AMF and PSAN regime, relevant to EU-facing operators.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because the compliance cost of managing the relationship – under pressure from their own regulators and correspondent banks – exceeds the commercial value of it. The decision is usually made at the level of risk appetite, not individual misconduct. A business may have a clean record and valid registration and still lose its account if its sector is classified as high-risk in the bank's risk framework. The absence of an individual finding does not mean the decision is legally unchallengeable, but the grounds for challenge are procedural rather than substantive in most jurisdictions.
How can a VASP onboard with an EMI?
A VASP can onboard with an EMI by presenting a complete, structured compliance dossier that addresses the EMI's AML, Travel Rule and beneficial-ownership requirements in advance. The dossier should cover regulatory status in each operating jurisdiction, AML and transaction-monitoring procedures, the MLRO's identity and qualifications, and a business-profile summary framed in financial-crime-risk language. EMIs authorised in the EU or UK are themselves regulated and will conduct enhanced due diligence on crypto clients. Operators who prepare thoroughly and allow adequate lead time consistently achieve faster onboarding outcomes.
What does client-money safeguarding require?
Client-money safeguarding requires a payment institution or EMI to hold client funds in a segregated account at a regulated credit institution, or to protect them with qualifying insurance or a bank guarantee. The obligation applies to funds held overnight or in transit. For a VASP using an EMI, safeguarding affects how the settlement account is structured and what happens to client balances in an insolvency. Under MiCA, CASPs providing custody services face additional obligations for the treatment of client crypto assets in insolvency – which must be addressed alongside the fiat safeguarding structure.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise crypto exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance structures that connect them. We map the licence, banking and payment stack across operating, custody and payment layers before our clients commit to a structure – not after a bank has closed an account. Digital assets are the whole of our practice. To discuss your banking position or a de-risking defence, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Lydia Brennan, Tax & Structuring Analyst – specialising in cross-border payment structures, EMI onboarding frameworks and the fiat-infrastructure compliance requirements that affect digital-asset businesses operating across multiple jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.