Client funds safeguarding sits at the intersection of regulatory compliance and live litigation risk. When a digital-asset business loses access to its fiat rails – whether through a bank exit, a payment-institution suspension or an EMI account closure – the first casualty is client money. That money may be unprotected, commingled or simply frozen, and the legal exposure that follows moves fast.
The disputes angle on client funds safeguarding (the legal obligation to hold client money separately, at all times, in a manner that survives the insolvency of the operator) is routinely underweighted by crypto operators who treat banking as a commercial problem rather than a structural legal one. Under the applicable payment-institution and EMI (electronic money institution) regimes across the EU, the UK and the leading offshore hubs, safeguarding is not optional – it is a licence condition, and a breach of it is a trigger for enforcement, civil claims and, in the most severe cases, criminal referral. This analysis examines where the legal risk concentrates, how disputes arise from safeguarding failures, and what an operator must do before the clock starts running.
What is the regulated perimeter for client funds?
The regulated perimeter for client funds in a digital-asset context covers any fiat balance held by or on behalf of a client in connection with a payment, exchange or custody function. Across the EU under MiCA and the applicable payment-services regime, the UK under FCA rules, and Singapore under the Payment Services Act administered by MAS, the obligation is materially the same: client money must be ring-fenced, placed in a designated account or invested in liquid low-risk assets, and kept outside the reach of the operator's general creditors on insolvency.
The perimeter is broader than many operators assume. A crypto exchange that holds fiat pending conversion is almost certainly a payment institution for the purposes of these regimes. A custodian that holds stablecoin redemption proceeds overnight is in the same position. The label the operator attaches to its activity is irrelevant – what matters is the economic substance of what it does with the money.
The practical consequence is that a VASP (virtual asset service provider) operating without a payment licence, or without a formal safeguarding arrangement anchored to a licensed counterparty, is holding client fiat in a legally ambiguous state. That ambiguity is precisely where disputes begin.
In our cross-border practice, we see operators who licensed themselves as a VASP under one regime and assumed that licence covered their fiat-handling function. It does not, in most jurisdictions. The VASP licence covers the crypto side; the fiat side requires a separate instrument – or a structured relationship with a licensed EMI.
For a scoped assessment of your current safeguarding structure and where exposure sits, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity's jurisdiction, the currency of the client balance, the banking counterparty – change the analysis materially. Map your options.
How do safeguarding failures generate disputes?
Safeguarding failures generate disputes through four distinct pathways: regulatory enforcement, client class actions, insolvency proceedings and contractual claims against banking counterparties. Each pathway has a different timeline and a different set of defendants.
The most immediate pathway is regulatory enforcement. An EMI or payment institution that commingles client funds with its own – even temporarily, even unintentionally – is in breach of a licence condition. Under the FCA regime, under MiCA's applicable provisions and under the MAS Payment Services Act, the regulator has the power to vary, suspend or revoke the licence and to impose a civil penalty. In the digital-asset context, enforcement moves quickly because regulators are sensitive to systemic risk: a freeze on one operator's EMI account can cascade to dozens of downstream VASPs that rely on that account for their own fiat rails.
The second pathway is client claims. Where a safeguarding failure results in client money being unavailable – because it was commingled with operational funds that were then frozen, or because it was placed with a banking counterparty that itself became insolvent – clients have direct claims against the operator. In England and Wales, the courts have repeatedly recognized crypto-related assets as property capable of supporting proprietary claims. A client who can demonstrate that their fiat was held on trust has a claim that survives the operator's insolvency; a client who cannot demonstrate that faces an unsecured creditor position.
The third pathway is insolvency. When an operator enters administration or liquidation, the insolvency officeholder must immediately triage which funds are client money (subject to a statutory trust) and which are the company's own assets. Where the operator did not maintain clean segregation, this triage is a forensic exercise – expensive, slow and contested. The clients who lose in that exercise lose everything above the general-creditor dividend.
The fourth pathway is contractual. Banking agreements with EMIs and payment institutions typically contain representations about the operator's regulatory status and its AML/KYC posture. A VASP that misrepresented its licensing position, or that failed to maintain the compliance programme it described at onboarding, gives the banking counterparty a contractual right to terminate – with or without notice. That termination freezes the rails, and the downstream disputes with clients follow immediately.
Why does EMI onboarding create structural legal risk?
EMI onboarding for VASPs is structurally risky because the EMI is taking on the VASP's regulatory risk by association, and most EMIs have underwritten that risk without fully understanding it. When the risk materialises – through a regulator inquiry, a media event or a blockchain forensics alert – the EMI's response is almost always to close the account, and often with very short notice.
The legal problem for the VASP is that account closure without adequate notice may itself be a breach of contract. Several operators we advise have faced exactly this scenario: the EMI terminates the account citing its own regulatory obligations, but the notice period is shorter than the time required to migrate client funds to a successor institution. In that gap, client money is frozen. The VASP is in breach of its own obligations to clients. And the timeline for recovery depends entirely on what legal tools are available.
Under English law, which governs many of these banking agreements, a bank or payment institution does have a right to close an account – but that right is not absolute. Where the closure would cause serious and immediate harm to a third party (the downstream clients), and where the notice given is materially inadequate, there is a basis for injunctive relief. The threshold is high, but it is not insurmountable. In our practice, we have seen interim injunctions sought in commercial courts within 48 hours of an account closure notice, in order to preserve the client balance while a successor account is established.
The more durable solution is structural. A VASP that relies on a single EMI for its entire fiat operation has concentrated all of its legal risk in one counterparty relationship. Building redundancy – a second licensed banking relationship, a tri-party safeguarding arrangement, or a direct payment-institution licence in the operating jurisdiction – substantially reduces the exposure to this category of dispute.
The cross-border dimension amplifies the risk. A VASP incorporated in one jurisdiction, licensed in a second, operating through an EMI in a third and serving clients in a fourth faces a conflict-of-laws question from the moment the dispute arises. Which court has jurisdiction? Which insolvency regime governs the client money? Which regulator has the power to intervene? These are not abstract questions – they determine, in practical terms, whether a client recovery is possible.
How does the Travel Rule intersect with safeguarding disputes?
The Travel Rule (the FATF obligation to pass originator and beneficiary data with a virtual-asset transfer) intersects with safeguarding disputes in a specific and underappreciated way: Travel Rule failures are among the leading reasons that EMIs and correspondent banks exit VASP relationships, and each exit triggers the safeguarding cascade described above.
Under FATF Recommendation 15 and the implementing regimes across the EU, UK, Singapore and other leading jurisdictions, a VASP must collect, verify and transmit originator and beneficiary data for transfers above the applicable threshold. A VASP that cannot demonstrate a functioning Travel Rule compliance programme is, in the eyes of an EMI's compliance team, a liability. The EMI does not need to wait for a regulatory breach to occur – the absence of a demonstrable programme is itself a ground for account closure.
The dispute that follows is not primarily a Travel Rule dispute. It is a client-money dispute, triggered by a Travel Rule compliance gap. The lesson for operators is that safeguarding and AML/KYC are not separate compliance workstreams – they are part of the same operational risk. A failure in one creates immediate exposure in the other.
We regularly advise operators on structuring their Travel Rule solution before onboarding with an EMI. The practical requirement is a technical integration (with a VASP-to-VASP messaging protocol), a policy framework, and a counterparty identification programme. Without all three, the operator is likely to face account-closure risk within the first year of the EMI relationship – regardless of the commercial terms agreed at onboarding.
Which operator profile faces which safeguarding risk?
Safeguarding risk varies materially by operator profile, and the appropriate legal instrument differs accordingly. The following analysis maps the principal profiles to the key risk and the primary mitigation path.
A crypto exchange holding client fiat pending conversion faces the highest safeguarding exposure. Its fiat balance turns over rapidly, its client base is large, and it is almost always classified as a payment institution under the applicable regime. The primary mitigation is a direct payment-institution licence in the operating jurisdiction – or, where that is not available, a formal agency arrangement with a licensed EMI that includes explicit contractual protection for the VASP's clients. The key risk is commingling during the conversion cycle; the instrument is a designated client-money account with daily reconciliation obligations.
A custodian holding stablecoin redemption proceeds or fiat collateral against a crypto lending book faces a different profile. The balance may be large but less liquid; the client relationship is typically institutional. The risk is concentrated in insolvency: if the custodian fails, the clients need to demonstrate a proprietary claim over the fiat. The instrument is a trust account structure, documented in the custody agreement, with a named beneficiary-class provision that survives insolvency. The jurisdiction of the account matters enormously here – an account in England and Wales sits under a well-developed statutory trust framework; an account in a less-developed jurisdiction may offer no equivalent protection.
A token issuer holding subscription proceeds pending a token-generation event faces a time-limited but acute risk. The proceeds are client money from the moment they are received. The issuer must segregate them immediately and must not use them for operational expenditure until the token is delivered or returned. The key risk is that the issuer's own payment licence (if any) does not cover the period of subscription-proceed holding; the instrument is a third-party escrow arrangement with a licensed payment institution as escrow agent.
A fund with digital-asset exposure faces the most complex structure. The fund itself is typically not a payment institution, but its administrator and prime broker may be. The safeguarding obligation attaches to each intermediary that holds fiat on the fund's behalf. The key risk is a gap in the safeguarding chain – a moment when fiat has left one intermediary but not yet arrived at the next. The instrument is a contractual chain-of-custody provision in each intermediary agreement, with explicit representations about safeguarding compliance and a right of audit.
If a safeguarding structure review would help your organisation before a banking transition, write to OBOLUS at info@oboluslaw.com. If a prior EMI application stalled or an account was closed, a second-read assessment can surface the structural reason and the route back. Map your options.
What happens when safeguarding disputes cross borders?
Cross-border safeguarding disputes are harder to resolve than domestic ones because they typically involve multiple regulators, multiple courts and a conflict-of-laws analysis that determines whether client money can be recovered at all. The question of which jurisdiction's insolvency law governs the client-money trust is often the decisive one.
Consider the practical scenario: a VASP incorporated in the BVI holds its operating account with an EMI in Lithuania (supervised by the Bank of Lithuania under the MiCA transition regime). It serves clients in the EU and UK. Its clients' fiat is denominated in euros and sterling. The VASP enters financial difficulty. The BVI court applies its own insolvency framework; the Lithuanian regulator applies the payment-institution safeguarding regime; the English High Court may be asked to recognize a proprietary claim by UK clients. Three jurisdictions, three legal regimes, one pool of money.
In our experience, the clients who recover in this scenario are those whose contractual agreements with the VASP explicitly designated the client-money account, named the beneficiary class and incorporated a governing-law clause that pointed to a jurisdiction with a well-developed trust framework. Clients who relied on general terms and conditions – without specific client-money language – face a much harder path.
The DIFC Courts in Dubai have developed a growing body of practice around cross-border asset recovery and freezing orders in support of foreign proceedings. The CFAAR (Crypto Fraud and Asset Recovery) network, launched in London in September 2021, provides a structured forum for cross-border coordination. These tools are available, but they require early engagement – typically within hours of a suspected misappropriation or account freeze, not days or weeks later.
In a recent recovery matter, a payments company identified that client fiat had been swept into an operational account at an EMI counterparty following an erroneous reconciliation. We worked with allied counsel in the relevant jurisdiction to issue a formal demand under the applicable payment-services framework and secured a contractual hold on the disputed balance before withdrawal. The funds were restored within a matter of days. The key factor was speed: the contractual and regulatory tools available in the early hours of a dispute are substantially more effective than those available once the money has moved.
What are the most common safeguarding mistakes in digital-asset operations?
The most common safeguarding mistake in digital-asset operations is treating client-money segregation as an accounting function rather than a legal one. The practical consequence is that the segregation exists on paper but not in substance – the designated account is not truly ring-fenced, the reconciliation is not daily, and the trust characterisation has not been documented in the client agreement.
The second most common mistake is relying on a single banking relationship for all client-money functions. When that relationship terminates – and in the digital-asset sector, terminations are frequent – the operator has no fallback. The time required to establish a new safeguarding-compliant account with a new EMI is rarely less than several weeks. In that period, client money is exposed.
A third mistake is failing to update the safeguarding structure as the business grows. An operator that began as a small exchange with a simple client-money account may now be a multi-product business with custody, lending and staking functions. Each new function adds a new category of client money and, potentially, a new safeguarding obligation. The original structure rarely covers the expanded business.
The fourth mistake is specific to the cross-border context: nominating a governing-law jurisdiction for the client-money trust without considering whether that jurisdiction's insolvency law actually gives the clients a proprietary claim. English law, for example, has a well-developed statutory and common-law framework for client-money trusts in the payment-services context. Some other jurisdictions do not have an equivalent. An operator that holds client money in an account governed by a less-developed legal system may be offering its clients the form of protection without the substance.
A common assumption among operators is that a single offshore VASP licence is sufficient to cover client-money obligations globally. It is not. The safeguarding obligation is jurisdictionally specific: it attaches in the jurisdiction where the client is located, where the money is held and where the payment function is performed. A VASP licence obtained in one jurisdiction does not automatically satisfy the payment-institution requirements of another. Operators who proceed on this assumption expose themselves to enforcement in every jurisdiction where their clients are resident.
Self-assessment: is your safeguarding structure litigation-ready?
A litigation-ready safeguarding structure is one that, on the day the EMI account closes or the regulator calls, can demonstrate clean ring-fencing, a documented trust characterisation and a live successor-account plan. The following questions identify the most common gaps.
First, does your client agreement explicitly characterise the client-money account as a trust for the benefit of clients – and does the banking agreement with your EMI reflect that characterisation? Many operators have one without the other, which breaks the chain of title in an insolvency.
Second, do you reconcile the client-money account against client ledgers daily? A reconciliation gap of more than one business day is, in most regulated jurisdictions, a breach of the safeguarding requirement – and it is exactly the gap that an insolvency officeholder will find first.
Third, do you hold at least two independent safeguarding accounts with two independent licensed counterparties? If the answer is no, the business is one EMI termination away from a safeguarding failure.
Fourth, does your Travel Rule compliance programme satisfy the requirements of every jurisdiction in which your clients are resident? A gap in the Travel Rule programme is the leading proximate cause of EMI account closure in the digital-asset sector.
Fifth, has your governing-law analysis been reviewed by counsel with specific knowledge of the insolvency treatment of client-money trusts in the nominated jurisdiction? A general commercial law opinion is not sufficient for this purpose.
If the answer to any of these questions is uncertain, the safeguarding structure requires legal review before the next banking transition or regulatory inquiry – not after.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital-Asset Businesses – structuring the full banking and payments stack for VASPs and exchanges
- EMI Onboarding for VASPs in the United States – federal and state money-transmitter licensing for US-facing digital-asset operations
- Tokenised Fund Structuring in Jersey – fund-level safeguarding and structuring for digital-asset vehicles in Jersey
FAQ
Why do banks close crypto company accounts?
Banks and EMIs close crypto company accounts primarily because of perceived regulatory risk. The most common triggers are an inadequate AML/KYC programme, a Travel Rule compliance gap, a mismatch between the operator's declared business activity and its actual transaction profile, or a regulatory inquiry directed at the operator. In many cases the closure is a commercial decision made by the bank's compliance committee without a formal legal process. The VASP's legal recourse depends on the governing law of the account agreement and the adequacy of the notice given.
How can a VASP onboard with an EMI?
A VASP seeking to onboard with an EMI must typically demonstrate a functioning AML/KYC framework, a Travel Rule-compliant messaging solution, a valid VASP licence in its operating jurisdiction and a clean transaction history. The EMI's onboarding process mirrors a regulatory examination: it will review corporate structure, source-of-funds documentation, a compliance policy suite and, increasingly, a blockchain forensics attestation from a recognised analytics provider. The timeline varies by EMI and jurisdiction but is rarely less than several weeks for a VASP with cross-border operations.
What does client-money safeguarding require?
Client-money safeguarding requires an operator to hold client fiat in a designated account that is legally separated from the operator's own funds, reconciled against client ledgers on a frequent basis and documented as a trust in both the client agreement and the banking agreement. The applicable regime – whether MiCA, the FCA's payment-services rules, the MAS Payment Services Act or another – sets the specific operational requirements. The common thread is that client money must survive the operator's insolvency and be returned to clients as a priority over general creditors.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and safeguarding stack across operating, custody and payment layers before you commit – and we advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialising in the technical and regulatory intersection of payment-layer infrastructure, safeguarding structures and cross-border compliance for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.