EST · MMXXVI
Home/Insights/Tax/Fiat on/off-ramp banking: Practical Lessons for Boards
Banking, Payments & EMI Onboarding

Fiat on/off-ramp banking: Practical Lessons for Boards

Fiat on/off-ramp banking: Practical Lessons for Boards. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBO

Operating a digital-asset business without stable fiat on/off-ramp banking is the fastest route from compliance to crisis. A single debanking event – one account closure letter on a Friday afternoon – can freeze client withdrawals, breach service-level obligations and trigger regulatory scrutiny simultaneously. Boards that treat banking as a treasury back-office issue rather than a strategic legal risk learn the hard way that fiat rails (the bank accounts and payment infrastructure that convert between fiat currency and digital assets) sit at the intersection of licensing law, AML regulation and cross-border payment compliance. This analysis sets out the practical lessons, organised around the decisions a board must take before the rails go dark.

The core problem is structural. A VASP (virtual asset service provider) may hold a sound operating licence in its home jurisdiction, yet find that every correspondent bank applying its own de-risking policy refuses to maintain the account. Licensing and banking are legally separate questions – but they are commercially inseparable. The page that follows maps the regime context, the operational fault lines and the decisions that separate businesses with resilient payment licence stacks from those that are permanently one banker's risk-appetite away from collapse.

Fiat on/off-ramp access fails for legal reasons as often as for commercial ones, and the board-level response must be legal in character. Banks terminate crypto accounts primarily because they cannot satisfy their own AML/CFT obligations when processing transactions for a VASP that has not provided adequate compliance documentation, a credible corporate structure or a licence that the bank's correspondent network recognises. The underlying driver is FATF Recommendation 15, which requires financial institutions to identify and assess the money-laundering and terrorist-financing risks associated with virtual-asset business and to apply enhanced due diligence proportionate to those risks. A bank that cannot demonstrate it has done that work faces its own regulatory exposure.

In our practice, the accounts that survive are those where the operator treated banking onboarding as a legal mandate before opening the account – not a relationship managed after the fact. The businesses that lose accounts tend to share a profile: a licence from a jurisdiction the bank's compliance team cannot easily interpret, a corporate structure with layers the bank did not ask about and therefore does not understand, and a transaction-monitoring narrative that was never reduced to writing.

The cross-border dimension compounds the problem. A business incorporated in one jurisdiction, licensed in a second, banking in a third and serving users in a fourth creates four overlapping regulatory perimeters. Each bank in the chain applies its home-country correspondent-banking rules. An account in an EU jurisdiction that routes USD through a US correspondent bank must satisfy both the bank's EU regulator and FinCEN's expectations around the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer). Treating these as independent issues is how boards arrive at the Friday afternoon letter.

For a scoped assessment of your current banking structure and its legal exposure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard risk profile. Your facts – the entity, the user base, the correspondent chain – change the analysis. Map your options.

What Regulators Expect from a VASP Before a Bank Will Engage

A bank's compliance team is, in effect, conducting a secondary regulatory assessment of every VASP it onboards – and the documentation a regulator expects from the VASP is the same documentation the bank needs to perform that assessment. Under MiCA, a VASP seeking a CASP (crypto-asset service provider) authorisation must demonstrate governance arrangements, a compliance programme and systems adequate to the activities being carried out. The same materials that satisfy ESMA or a national competent authority form the core of a banking onboarding pack.

In the UAE, VARA's activity-based rulebooks require licensed entities to maintain AML/CFT policies that meet or exceed FATF standards. A VASP operating under a VARA licence that presents those policies to a UAE bank has a material advantage over one that cannot produce an up-to-date compliance manual at the point of onboarding. Similarly, the MAS regime in Singapore requires Payment Services Act licensees to maintain records sufficient for MAS inspection – records that map directly onto what DBS or OCBC needs to open and maintain a payment account.

The operational lesson is that a licence is a necessary but not sufficient condition for banking access. What the bank actually needs is a compliance narrative: who owns the entity, who controls it, what the transaction flow looks like, how unusual transactions are identified and escalated, and what happens when a sanctioned counterparty is detected. Operators we advise routinely prepare a banking readiness file – distinct from the licence application – that answers those questions in a format a compliance officer can sign off on within a standard review cycle.

The jurisdiction of the licence matters more than many boards appreciate. A licence from the BVI Financial Services Commission under the VASP Act 2022 carries different weight with a European correspondent bank than a CASP authorisation from an EU national competent authority under MiCA. That is not a comment on the quality of the BVI regime – it is a comment on how correspondent banks assess recognisability. A business planning to hold EUR accounts in the EU and USD accounts in the US needs licences that the respective banking systems will recognise, not just licences that satisfy the home regulator.

How Do EMI Relationships Work for Digital Asset Businesses?

EMI onboarding – establishing a relationship with an EMI (electronic money institution) authorised under the EU Electronic Money Directive or its equivalent – has become the primary route to fiat rails for crypto businesses that cannot obtain a direct bank account. An EMI can hold client funds, issue IBANs, process SEPA and SWIFT payments, and often has an existing compliance posture oriented toward higher-risk fintech clients. For a VASP that has been declined by a Tier 1 bank, an EMI relationship is frequently the practical path to functioning EUR rails.

The legal architecture matters, however. An EMI is itself a regulated entity. It applies its own enhanced due diligence to VASP clients and is accountable to its regulator – typically an EU national competent authority, the FCA in the UK, or a comparable body – for the quality of that due diligence. In recent years, several EMIs active in the crypto space have had their authorisations suspended or revoked following supervisory review. When that happens, every VASP using that EMI as its primary rail faces an operational emergency. Concentration risk in EMI relationships is a board-level treasury risk that is also a legal risk.

The structural mitigation is multiple-rail architecture: at minimum two EMI or bank relationships in different jurisdictions, covering both EUR and USD or GBP settlement. We have seen businesses that planned for this outcome recover from a rail failure in a matter of days; those that had not planned for it faced client-withdrawal queues measured in weeks. The legal documentation underpinning each rail – account agreements, safeguarding confirmations, third-party payment-processing terms – must be reviewed before the rail is needed in an emergency, not after it fails.

For businesses holding client money, the safeguarding obligation under the applicable EMI provisions requires that client funds be either held in a segregated account at a credit institution or covered by an eligible insurance policy or comparable guarantee. This is not a choice between two equivalent options. The segregated-account route requires a bank that will accept the designation; the insurance route requires a policy that genuinely covers the full balance at all times. Neither is as straightforward to arrange as the statutory language implies, and in our cross-border practice we have seen both structures fail in stress scenarios because the underlying documentation did not match the legal requirement.

What Are the Debanking Triggers Boards Consistently Miss?

Debanking is rarely random. The triggers that cause a bank to serve a termination notice are, in most cases, identifiable in advance and addressable if the board knows to look for them. The most common are structural opacity, transaction-pattern anomalies and regulatory change in the bank's own jurisdiction.

Structural opacity means the bank cannot map the beneficial ownership chain to its satisfaction within a standard review cycle. A VASP with multiple holding layers, nominee structures or jurisdictions that trigger the bank's enhanced-due-diligence policy will face account review. If the review produces documentation that takes weeks to assemble, the bank draws an adverse inference. The legal answer is a corporate structure that is genuinely transparent – not simplified beyond what the business needs, but structured so that every layer has a documented purpose and a clean ownership register.

Transaction-pattern anomalies arise when the account's actual activity does not match the business description the VASP gave at onboarding. A business that described itself as an institutional OTC desk and then processes retail-style micro-transactions has created a compliance problem for its bank. The bank's transaction-monitoring system flags the deviation; the compliance officer cannot resolve it without a business-purpose explanation; the account goes into review. Regulators in the leading hubs increasingly expect VASPs to maintain current account-usage documentation and to proactively update their banking partners when business lines evolve.

Regulatory change in the bank's jurisdiction is the least controllable trigger. When a regulator issues guidance that effectively reclassifies crypto business as high-risk – as several EU national competent authorities have done during the MiCA transition period – banks in that jurisdiction conduct portfolio reviews and exit relationships they can no longer underwrite confidently. A VASP with all its banking in one jurisdiction is fully exposed to that review. Geographic diversification of the banking stack is not a nice-to-have; it is a structural necessity for any business serving clients across multiple markets.

A word on sanction exposure: any VASP whose transaction flow touches wallets on OFAC, EU or UK consolidated sanction lists – however briefly and however unknowingly – creates an existential banking risk. A single matched transaction, if it reaches a bank's correspondent without prior remediation, can trigger not just account closure but regulatory referral. The Travel Rule obligation to screen originator and beneficiary data before processing a transfer is the technical mechanism that catches this risk, but it requires real-time screening infrastructure, not a weekly batch review.

The Cross-Border Licensing Stack: Which Jurisdictions Do the Work?

The right licensing stack for a digital-asset business depends on where it operates, where its users are and where its banking must sit – and those three coordinates rarely point to the same answer. No single licence resolves all three questions, which is the structural refutation of the assumption that one offshore authorisation is sufficient for global operations.

For a business targeting European users, a MiCA CASP authorisation obtained through an EU national competent authority provides the passporting mechanism that allows the business to serve clients across all EU and EEA member states from a single regulatory home. Lithuania, under the Bank of Lithuania, has historically been an accessible EU entry point, though the MiCA transition has raised the documentation and capital bar for all NCAs. An EU CASP authorisation also provides the licensing credential most recognised by European banks and EMIs.

For a business with material operations in the Middle East, a VARA licence in Dubai or an FSRA authorisation within ADGM in Abu Dhabi addresses the UAE regulatory perimeter but does not resolve the correspondent-banking question for USD. USD correspondent banking continues to be governed by US expectations – FinCEN, OFAC and, for New York-facing business, the NYDFS. A business that holds a VARA licence and needs USD wires needs either a US money-transmitter licence or a banking partner that itself holds the appropriate US authorisation and is willing to extend that relationship to its VASP client.

In Asia, the MAS Payment Services Act regime in Singapore and the SFC VASP licensing regime in Hong Kong serve different profiles. Singapore's framework is designed for businesses that want to operate within a well-regulated common-law jurisdiction with deep correspondent-banking access; Hong Kong's regime is oriented toward businesses whose primary market is Greater China and who need access to the HKD and CNH payment systems. The two are not substitutes, and we regularly advise clients who need both for the same operational reason that a US business needs both a federal MSB registration and state MTLs for the same activity.

For businesses in the BVI, the Cayman Islands or similar offshore structures, the VASP registration requirements under the respective acts provide regulatory standing but not banking access. The offshore entity typically serves as the holding or contracting vehicle; the operating subsidiary that actually holds fiat and processes payments must be licensed in a jurisdiction whose authorisation the relevant banks recognise. Treating the holding structure as the only regulated entity is the structural mistake we see most often in mid-market crypto businesses.

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to info@oboluslaw.com. Map your options.

Decision Matrix: Which Structure Fits Which Operator Profile?

Operator profiles diverge sharply on the banking question, and the structure that works for a large centralised exchange will create compliance overhead without corresponding benefit for a smaller B2B payments provider. The following matrix describes four common profiles in qualitative terms, because the specific capital, fee and timeline figures vary by category and should be confirmed against current regulatory guidance before a board commits capital.

Profile A – EU-facing exchange or custodian. The primary instrument is a MiCA CASP authorisation from an EU NCA with passporting. The banking structure should prioritise EUR accounts at EMIs or Tier 2 banks that already serve licensed CASPs, with a USD correspondent arrangement through a bank that recognises the EU licence. The timeline to full operational status – licence plus banking – is a matter of months for a well-prepared applicant; the key risk is the compliance and capital assessment, which is more demanding under MiCA than under the prior national VASP regimes it replaced.

Profile B – UAE/GCC-focused operator. The primary instrument is a VARA licence for mainland Dubai operations or an FSRA authorisation within ADGM. Banking in AED is accessible through UAE banks once the licence is in place. USD access requires either a US-licensed banking partner or a UAE bank with robust US correspondent relationships. The timeline varies by activity category; VARA's activity-based licensing means an advisory-only entity and an exchange face materially different processes. Key risk is the gap between UAE licensing and US banking expectations, which allied counsel in the US jurisdiction should address in parallel.

Profile C – Asian hub operator. The primary instrument is a MAS DPT service licence (Singapore) or an SFC VATP licence (Hong Kong), depending on the target market. Singapore provides deeper correspondent-banking access for USD and EUR; Hong Kong provides access to HKD, CNH and the Greater China payment system. The timeline under either regime is a matter of many months from application to approval for a complex applicant. Key risk is the capital assessment and the ongoing technology-systems requirements, which are demanding under both the MAS and SFC regimes.

Profile D – Offshore holding structure with operating subs. The BVI or Cayman holding entity provides contractual flexibility and structural efficiency; it does not provide banking. The operating subsidiaries must each hold the licence appropriate to their activity in the jurisdiction where they operate. Key risk is the temptation to rely on the holding entity's VASP registration as a substitute for operating-entity licensing – a structure that creates regulatory exposure in every jurisdiction where the operating sub transacts without its own authorisation.

The Client Money Safeguarding Obligation in a Multi-Rail Structure

Safeguarding client money is the most technically demanding aspect of fiat on/off-ramp banking for regulated VASPs, and it is the area where documentation failures are most likely to attract regulatory attention. The applicable EMI and payment-institution provisions in most major jurisdictions require that money received from a client and not yet applied to a payment transaction be held in a manner that protects it in the event of the operator's insolvency. The precise mechanism – statutory trust, segregated account, insurance policy – varies by jurisdiction, but the underlying obligation is consistent: client money must not be commingled with the operator's own funds.

In practice, this creates an operational tension. A VASP that operates both a payment function and an exchange function must maintain clear accounting segregation between the fiat it holds as a payment institution and the fiat it holds as its own trading capital. The bank account structure must reflect that segregation. If a single account holds both, the safeguarding protection fails – and in an insolvency scenario, the clients whose funds were in the commingled account rank as unsecured creditors rather than trust beneficiaries. The legal consequence of a documentation failure is that clients lose the protection the licence was supposed to provide them.

The cross-border dimension adds a further layer. A VASP that holds EUR in an EU EMI account and GBP in a UK-regulated account is subject to different safeguarding regimes for each balance. The EU account is governed by the applicable EU payment-institution provisions; the UK account is governed by the FCA's client-money rules under the applicable UK legislation. The documentation – account designations, trustee language, segregation confirmations from the account bank – must satisfy each regime independently. A single safeguarding policy document that does not address jurisdiction-specific requirements will not satisfy either regulator.

In a recent structuring matter, a payments company operating across three jurisdictions had maintained its fiat balances in a single EMI account for operational simplicity. When the EMI came under supervisory review, the company discovered that its safeguarding documentation did not identify which funds were held for which clients in which jurisdictions. We restructured the account arrangements and the trust documentation before the review concluded, establishing clear segregation across all three balances. The company maintained uninterrupted operations and satisfied the supervisory inquiry without enforcement action.

Common Structural Mistakes and How to Address Them

The most damaging structural mistakes in fiat on/off-ramp banking share a common characteristic: they are invisible until a stress event – a bank review, a regulatory inspection, a counterparty default – forces them into the open. By that point, remediation is more expensive and more constrained than design-stage prevention would have been.

The first mistake is conflating the licensing question with the banking question. A board that obtains a VASP licence and then approaches banks expecting the licence to do the banking work will be surprised. The licence establishes that the business meets the regulatory threshold for its activity; the bank needs to know that the business's ongoing transaction flow will not create a compliance liability for the bank. Those are related but distinct assessments, and only the second one determines whether the account opens.

The second mistake is maintaining a single-jurisdiction banking stack. Whether the concentration is in one EU country, one UAE bank or one Singapore EMI, the risk profile is the same: a single regulatory or supervisory event in that jurisdiction can disable the entire fiat operation. The solution – multiple rails, multiple jurisdictions, documented contingency switching – is more expensive to build than a single-rail operation, but materially cheaper than the commercial and legal cost of a unplanned rail failure.

The third mistake is failing to maintain the banking relationship as a live legal obligation. Account agreements have renewal and review cycles. Banks' enhanced-due-diligence requirements change as their own regulatory environment evolves. A business that answered a bank's KYC questionnaire accurately at account opening and has not updated its answers in two years has created a factual gap that, in a review, looks like concealment even when it was simply neglect. Operators we advise treat banking documentation maintenance as a quarterly legal task, not a one-time onboarding exercise.

A common assumption we encounter is that a single offshore licence is sufficient to serve clients globally. That assumption does not survive contact with a correspondent bank's compliance team. A US correspondent bank processing USD transfers for a VASP licensed only in an offshore jurisdiction that the bank's compliance team cannot verify will not maintain that relationship indefinitely. The jurisdictions that provide genuine banking access are those whose licensing regimes are recognisable to the banks whose correspondent networks the VASP needs.

FAQ

Why do banks close crypto company accounts?

Banks close crypto accounts primarily because they cannot satisfy their own AML/CFT obligations when processing transactions for a VASP that has not provided adequate compliance documentation, a recognisable licence or a clear beneficial-ownership structure. Under FATF Recommendation 15, financial institutions must apply enhanced due diligence to virtual-asset business. When a VASP cannot supply the materials needed for that assessment, the bank's risk-adjusted response is account termination rather than ongoing exposure to regulatory scrutiny from its own supervisor.

How can a VASP onboard with an EMI?

A VASP onboards with an EMI by presenting a complete compliance pack: the operating licence, an up-to-date AML/CFT policy, a beneficial-ownership register, a transaction-flow narrative and – where required by the EMI's own regulator – a risk assessment specific to the VASP's business model. EMIs are regulated entities that conduct their own enhanced due diligence on high-risk clients. The VASP should treat EMI onboarding as a secondary regulatory assessment and prepare accordingly, rather than treating it as a commercial account-opening exercise.

What does client-money safeguarding require?

Client-money safeguarding requires that fiat received from clients and not yet applied to a payment transaction be held separately from the operator's own funds, in a manner that protects it on insolvency. The specific mechanism – segregated bank account, statutory trust or qualifying insurance – varies by jurisdiction. The account designation, trust documentation and segregation confirmation from the account bank must each satisfy the requirements of the jurisdiction governing that specific balance. A single safeguarding policy that does not address jurisdiction-specific requirements is unlikely to satisfy any of the relevant regulators.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack across operating, custody and payment layers as one mandate – not three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.

By Lydia Brennan, Tax & Structuring Analyst – specialising in cross-border fiat structuring, EMI onboarding and the payment-licence stack for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours