EST · MMXXVI
Home/Insights/Tech/Client funds safeguarding: What Recent Enforcement Tells Operators
Banking, Payments & EMI Onboarding

Client funds safeguarding: What Recent Enforcement Tells Operators

Client funds safeguarding: What Recent Enforcement Tells Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring.

Client Funds Safeguarding: What Recent Enforcement Tells Operators

Operating a digital-asset business without structurally sound client-funds safeguarding is one of the fastest ways to trigger regulatory enforcement, lose banking access and face civil liability simultaneously. Client funds safeguarding – the legal obligation to hold client money separately from operating capital, in eligible institutions, under legally recognised structures – is no longer a compliance checkbox. Regulators across the major licensing hubs are using it as the primary test of whether an operator is fit to hold client assets at all. This analysis draws on enforcement patterns across the EU, the UAE, the UK, Singapore and the United States to map what the rules actually require, where operators are failing and what a structurally sound arrangement looks like in practice.

Why Safeguarding Failures Trigger Enforcement Before Anything Else

Safeguarding failures are the first regulatory tripwire because they are easy to identify and carry immediate consumer-harm evidence – making them the regulator's preferred enforcement entry point even when the underlying concern is broader. When a regulator examines an operator, it can determine within days whether client funds are pooled with operating capital, whether they sit in an eligible credit institution and whether the legal structure supports segregation. It does not need to build a complex fraud case. The result is that operators who fall short on safeguarding face action faster and with less procedural warning than those facing conduct or AML findings.

In the EU, MiCA places explicit own-funds and safeguarding obligations on authorised crypto-asset service providers (CASPs). The regime requires that client crypto-assets and client fiat are held in a manner that protects them in the event of insolvency. ESMA has indicated that the practical application of these obligations will follow the model established under the Payment Services Directive and the E-Money Directive – both of which impose segregation, eligible-institution and audit-trail requirements. An operator that fails to demonstrate compliant safeguarding during MiCA authorisation will not receive a licence. One that lets the arrangement lapse post-authorisation faces suspension or revocation.

In the UK, the FCA has made safeguarding under the Money Laundering Regulations registration track and, separately, under the Payment Services Regulations, a recurring inspection focus. Operators seeking to maintain fiat rails through UK-regulated payment institutions must demonstrate that client money is not commingled and that the institution holding it understands the nature of the underlying business. In our cross-border practice, we have seen UK-connected operators lose their EMI relationships not because of AML deficiencies but because the EMI conducting periodic review concluded that the safeguarding structure did not meet its own obligations to its regulator.

The core lesson from recent enforcement across these forums is structural, not cosmetic. Regulators are not satisfied by a policy document. They examine the actual bank account structure, the contractual terms with the custodian and whether the insolvency-remote logic holds under local law.

For a scoped assessment of your current safeguarding structure and where it sits against the applicable regime, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.

What the Applicable Regimes Actually Require

The legal content of a safeguarding obligation varies by regime, but four structural elements appear consistently across MiCA, the UK payment services regime, the VARA rulebooks in Dubai and the MAS Payment Services Act framework in Singapore: separation, eligibility, acknowledgment and reconciliation.

Separation means client funds are held in accounts that are legally distinct from the operator's own working capital. Most regimes require this to be structurally enforceable – meaning the account title, the contractual terms and the insolvency analysis all support the conclusion that a liquidator cannot reach those funds to satisfy unsecured creditors of the operator.

Eligibility defines where the funds can sit. Under payment-services models, client fiat must generally be held in a credit institution authorised in an eligible jurisdiction or invested in specified low-risk liquid assets. The VARA regime imposes its own approved-custodian logic. MAS, under the Payment Services Act, distinguishes between the licence tier – standard payment institution versus major payment institution – and adjusts the obligation accordingly. Operators who hold client fiat in non-eligible accounts, or in a jurisdiction whose institutions are not recognised by the home regulator, create a gap that shows up immediately on examination.

Acknowledgment refers to the tripartite structure some regimes require: the bank or custodian must acknowledge in writing that the funds are held for clients, not for the operator, and that the bank will not set off its own claims against those balances. This acknowledgment is frequently missing when operators set up accounts in a hurry. The account opens, the fiat starts flowing and no one obtains the formal letter. Regulators regard the absence of an acknowledgment letter as evidence that the safeguarding arrangement does not exist in legally enforceable form.

Reconciliation is the operational layer. The operator must maintain records that match client entitlements to specific pooled balances on at least a daily basis, and must be able to produce those records on demand. Regulators examining operators post-incident consistently find that reconciliation failures preceded the safeguarding failure – the operator did not know its own position before a liquidity event exposed the gap.

Across the UAE, VARA's activity-specific rulebooks extend the safeguarding logic into the custody layer. An operator licensed for custody activities must demonstrate that virtual assets held for clients are segregated at the wallet level and that the private-key management architecture supports the segregation claim. A policy that says "we segregate" is not enough; the technical architecture must deliver the segregation.

How Does the Cross-Border Structure Affect the Obligation?

A VASP or CASP operating across multiple jurisdictions faces a safeguarding obligation that is not satisfied by compliance with the home-jurisdiction rules alone – the obligation extends to every jurisdiction in which the operator holds client assets or receives client fiat, and the structural question is which layer of the regulatory stack governs each element.

Consider a common pattern: a token issuer is incorporated in the BVI under the BVI Financial Services Commission's VASP Act 2022 regime, licensed as a CASP under MiCA through a Malta entity supervised by the MFSA, and processes fiat through an EMI onboarded in Lithuania under the supervision of the Bank of Lithuania. Client fiat collected by the Malta entity flows through the Lithuanian EMI, which holds it in accounts at a credit institution in the eurozone. The safeguarding obligation applies at each layer: the Malta CASP authorisation imposes MiCA obligations on the Malta entity; the Lithuanian EMI's own licence conditions govern how client fiat is held and acknowledged; the BVI entity's registration conditions address the crypto-asset custody layer. A failure at any layer exposes the whole structure.

This multi-layer reality is where the single-licence myth does its most damage. Operators who believe that a CASP authorisation in one EU member state, or a VASP registration in one offshore hub, satisfies their global safeguarding obligation are wrong. The obligation follows the activity and the asset. Wherever a client's fiat lands in an account, wherever a client's crypto-asset sits in a wallet, the local regime's rules apply – and so does the local regulator's enforcement jurisdiction.

In our practice, we regularly advise operators who have structured the licensing layer carefully but overlooked the fiat-rail layer. The bank or EMI holding client fiat is itself a regulated entity with its own safeguarding obligations. If the EMI's regulator is not satisfied that the operator's clients are adequately disclosed and that the pass-through arrangement meets the EMI's licence conditions, the EMI will exit the relationship – often with short notice and little explanation.

Where Operators Are Failing: The Enforcement Patterns

Enforcement patterns across the major hubs reveal four recurring failure modes, each of which is avoidable with adequate structural planning.

The first is commingling. Client fiat arrives into the operator's own bank account, is used to fund operations and is replenished before the client withdraws. This is classic commingling. It violates the separation requirement under every major regime and, critically, it exposes client funds to the operator's own creditors on insolvency. Regulators treat commingling as evidence of dishonesty even when the operator intended to return the funds – the legal structure failed regardless of intent.

The second is inadequate acknowledgment and documentation. The operator has a separate account, but the bank's terms treat it as an ordinary business account, there is no acknowledgment letter and the account title does not identify the client-money nature of the holding. On examination, this structure fails the eligibility and acknowledgment tests simultaneously. The remedy – obtaining the letter, amending the account terms, possibly moving the account to a different institution – is straightforward in principle but time-consuming in practice, particularly when the operator is already under regulatory scrutiny.

The third is reconciliation lag. The operator maintains separate accounts but does not reconcile daily. Client balances grow; the operator's internal records fall behind; and when a withdrawal event or a regulatory examination arrives, the operator cannot demonstrate that the pooled balance matches the sum of individual client entitlements. Regulators in the UK and the EU have consistently treated reconciliation failure as a stand-alone breach, separate from and additional to any underlying shortfall.

The fourth – and increasingly the most consequential for cross-border operators – is banking disruption mid-compliance. The operator has a compliant safeguarding structure. The EMI or correspondent bank then exits the relationship, citing its own risk appetite or regulatory pressure. Client fiat is suddenly in transit, the safeguarding account is being wound down and the operator has a window – measured in days, not weeks – to onboard a replacement. Operating during that window without a compliant holding structure is a regulatory breach even if it is brief. Regulators do not generally accept "our bank left us" as a defence to a safeguarding obligation.

A matter we advised on recently illustrates the third and fourth failure modes together. A payments-adjacent digital-asset operator had maintained a compliant safeguarding structure for over a year. Its EMI partner gave notice of exit, citing a routine portfolio review. During the transition, the operator's reconciliation process broke down because the new account was not fully integrated with the internal ledger. By the time the regulator examined the operator's monthly reconciliation records, a four-week gap existed. The enforcement consequence was a formal requirement notice and a six-month enhanced monitoring period – not because any client lost money, but because the operator could not demonstrate, at the time of examination, that client funds were held compliantly. We assisted the operator in restructuring the acknowledgment documentation, moving to a new EMI and rebuilding the daily reconciliation workflow to a standard that satisfied the regulator's monitoring requirements.

If a prior application stalled, an account was closed or a reconciliation gap has appeared in your records, a second read can surface the structural cause and the route forward. Contact OBOLUS at info@oboluslaw.com. Map your options.

The EMI Onboarding Reality for VASPs and CASPs

EMI onboarding – the process by which a digital-asset business secures a fiat-processing relationship with a licensed e-money institution – has become one of the most operationally consequential steps in building a compliant digital-asset business, and one of the most frequently underestimated.

An EMI that accepts a VASP or CASP as a client takes on regulatory exposure of its own. The EMI's regulator – whether the Bank of Lithuania, the FCA, the MFSA or another national competent authority – expects the EMI to perform enhanced due diligence on digital-asset clients, to understand the nature of the client's business and user base and to satisfy itself that the pass-through arrangement does not create obligations the EMI cannot meet. This means the onboarding process for a well-structured VASP or CASP involves not just KYB documentation but a genuine technical and legal dialogue about the safeguarding architecture.

Operators who approach EMI onboarding as a documentation exercise – submitting a business plan, AML policies and a corporate structure chart – frequently stall at the technical review stage. The EMI's compliance team asks: How do client funds flow into your platform? Where do they sit before you convert or deploy them? What happens to the fiat pool on insolvency? If the operator cannot answer these questions with reference to a documented, legally enforced structure, the EMI will not proceed.

The jurisdictional angle compounds the difficulty. A Lithuanian-licensed EMI processing fiat for a Dubai-licensed VASP must satisfy both the Bank of Lithuania's expectations and, indirectly, VARA's expectations about how fiat interacts with the virtual-asset activity. A UK-regulated EMI processing fiat for a Cayman-registered entity supervised by CIMA faces FCA scrutiny of the entire arrangement. In practice, operators who understand this dynamic prepare a multi-jurisdictional safeguarding memorandum before approaching the EMI – a document that maps the legal obligation in each relevant regime to the structural feature of the arrangement that satisfies it. Operators who do not prepare this document negotiate from a weaker position and often fail the first onboarding attempt.

In our cross-border practice, we have seen the EMI onboarding process take anywhere from a matter of weeks where the operator's documentation is complete and the business profile is straightforward, to several months where the operator's cross-border structure requires sequential regulatory sign-off. Timing is not a function of the EMI's backlog alone; it is a function of the operator's preparation.

Crypto Banking and Fiat Rails: What the Decision Matrix Looks Like

No single fiat-rail arrangement is optimal for every digital-asset operator. The right structure depends on the operator's licence profile, its user jurisdiction, the currencies it handles and its risk appetite for banking disruption.

Profile A – EU-licensed CASP with a eurozone user base. This operator should prioritise a safeguarding account at an EU-authorised credit institution, with acknowledgment terms that satisfy the MiCA CASP conditions and the EMI's own licence conditions. The timeline to onboard with a compliant EU EMI varies by the operator's preparedness and the EMI's current book; operators should plan for a process measured in months. The primary risk is EMI concentration: a single EMI relationship creates a single point of failure that, as the enforcement patterns show, can materialise quickly and without warning.

Profile B – VARA-licensed Dubai operator serving a Middle East and Asia user base. This operator faces a multi-currency fiat environment. Client fiat may arrive in AED, USD and multiple Asian currencies. The safeguarding obligation under VARA's rulebooks extends to the fiat layer, but the practical holding of USD fiat outside the UAE introduces the additional layer of US federal and state money-transmission regulation. A UAE-based operator with significant USD fiat flows should take advice on whether its fiat-handling activity triggers licensing requirements under FinCEN's federal framework or under state-level money-transmitter regimes before routing fiat through a US correspondent.

Profile C – MAS-licensed Singapore operator with Asia-Pacific reach. Under the Payment Services Act, the licence tier – standard versus major payment institution – determines the precise safeguarding obligation. A major payment institution faces more prescriptive requirements. For an operator handling client fiat above the threshold that triggers the major-institution designation, the safeguarding structure must be established and documented before licence upgrade, not after. Waiting until the threshold is crossed to build the structure creates a window of non-compliance that MAS examinations have identified as a recurring problem.

Profile D – Offshore-registered entity (BVI or Cayman) seeking EU and UK banking access. This is the most structurally complex profile. The operator's home regime – BVI FSC under the VASP Act 2022 or CIMA under the Cayman VASP Act – may impose its own safeguarding requirements. But EU and UK EMIs onboarding this operator will apply their own regime's standards to the arrangement regardless. The operator effectively faces concurrent safeguarding obligations and must structure the account architecture to satisfy both simultaneously. A common approach is to establish an EU subsidiary to hold the EMI relationship, thereby bringing the safeguarding obligation cleanly within MiCA or the Payment Services Directive framework – but this introduces corporate complexity and its own regulatory obligations that must be planned for.

Objection: "A Single Licence Is Enough to Serve Clients Globally"

A common assumption among operators entering the digital-asset market is that obtaining one licence in a recognised jurisdiction – a CASP authorisation under MiCA, a VASP registration in the BVI, a Payment Services Act licence from MAS – is sufficient to serve clients across borders without additional regulatory exposure. This assumption is incorrect, and the safeguarding layer is where it most visibly fails.

The MiCA passporting right, for example, allows a CASP authorised in one EU member state to provide services across the EU without a separate licence in each member state. That is a real and significant benefit. But passporting addresses the licence-to-operate question, not the safeguarding architecture question. A Lithuanian-passported CASP serving clients in Germany still needs its safeguarding account to sit in an eligible institution and still needs the acknowledgment and reconciliation infrastructure to be in place. The passport does not substitute for the structural safeguarding obligation; it simply means the operator does not need a German licence to serve German clients.

More fundamentally, the passporting right applies within the EU. It does not address the operator's obligations when it holds client fiat through a UK-regulated EMI, when it routes transactions through a Singapore-regulated payment institution or when its US clients' fiat touches the US banking system. Each of those connections activates the relevant local regime. The single-licence model works only if the operator's actual activity is genuinely confined to the licensed jurisdiction – which is rarely the case for a business with meaningful scale.

We regularly see this dynamic play out in the banking disruption scenario. An operator with a strong primary licence loses its EMI because the EMI's own regulator – not the operator's regulator – concludes that the pass-through arrangement creates compliance risk. The operator is surprised: it believed its licence resolved the regulatory question. In fact, the EMI's regulator applies the EMI's licence conditions, which include independent safeguarding obligations, independently of what the operator's home regulator thinks about the operator's structure.

Building a Structurally Sound Safeguarding Arrangement

A structurally sound safeguarding arrangement for a cross-border digital-asset operator requires planning across three layers: the legal layer, the banking layer and the operational layer – and the three must be consistent with each other before any one of them can satisfy a regulator's examination.

At the legal layer, the operator needs a documented analysis of the safeguarding obligation in each jurisdiction where it holds client assets or receives client fiat. That analysis should identify: the legal basis of the obligation, the eligible-institution requirement, the acknowledgment requirement and the insolvency-remoteness logic under local law. Where multiple jurisdictions are relevant, the analysis should identify conflicts and the structural solutions that resolve them.

At the banking layer, the operator needs accounts that are structurally compliant with the legal analysis – meaning the account title, the bank's terms and the acknowledgment letter all reflect the client-money nature of the holding. The operator also needs a backup arrangement – a secondary EMI or custodian relationship that can be activated quickly if the primary relationship exits. This is not a luxury for large operators; it is a structural necessity demonstrated by the enforcement pattern.

At the operational layer, the operator needs a daily reconciliation process that matches client entitlements to pooled balances, produces auditable records and generates an alert when a discrepancy appears. The reconciliation process should be integrated with the account architecture from the outset – not bolted on after the accounts are live. Regulators across the major hubs have been consistent: they regard a reconciliation failure as a breach regardless of whether any client suffered a loss.

The cross-border angle also affects the operational layer. Where client fiat moves through multiple accounts across multiple jurisdictions before settling into a safeguarding account, the reconciliation must track the full journey. A mismatch at any intermediate step can create a gap that is difficult to explain on examination, even if the endpoint is correct.

We map the licence, banking and safeguarding stack across operating, custody and payment layers before an operator commits to a structure. To have that mapping done before you go live – not after enforcement finds the gap – write to us at info@oboluslaw.com or message via t.me/oboluslaw. Map your options.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks exit crypto company relationships primarily because of regulatory risk to the bank itself, not necessarily because the operator has done anything wrong. A bank regulated by the FCA, the Federal Reserve or the ECB must satisfy its own supervisor that its crypto clients do not create unmanageable AML, safeguarding or reputational exposure. When a bank cannot obtain adequate documentation of the operator's safeguarding structure, licence status and beneficial ownership – or when its own regulator signals concern about crypto-sector exposure – it exits the relationship as a risk-management decision. Operators with documented, structured safeguarding arrangements and clear licensing histories are materially more likely to retain banking access and to onboard replacement institutions when disruption occurs.

How can a VASP onboard with an EMI?

A VASP seeking to onboard with an e-money institution (EMI) needs to demonstrate four things: a valid licence or registration in a recognised jurisdiction, a documented AML and KYC framework, a clear description of client fund flows and a safeguarding structure the EMI's compliance team can independently verify. In practice, this means preparing a multi-jurisdictional safeguarding memorandum, an organogram of the corporate structure, a transaction-flow narrative and, where relevant, a legal opinion on the insolvency-remote character of the safeguarding account under the applicable law. EMIs that onboard VASPs accept regulatory exposure of their own and will conduct enhanced due diligence accordingly. Operators that approach the process without this preparation typically stall at the technical review stage and face a longer, more uncertain onboarding timeline.

What does client-money safeguarding require?

Client-money safeguarding, across the major regulatory regimes, requires four structural elements: separation of client funds from the operator's own capital in legally distinct accounts; placement of those funds in eligible institutions recognised under the applicable regime; formal acknowledgment by the holding institution that the funds belong to clients and are not available to satisfy the operator's debts; and daily reconciliation of client entitlements against the pooled balance, with records available on regulatory demand. The precise requirements vary by regime – MiCA's CASP framework, the UK Payment Services Regulations, VARA's rulebooks and MAS's Payment Services Act each impose their own specifics – but these four structural elements appear in all of them. Failure on any one element is treated as a safeguarding breach independent of whether client money was actually lost.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before operators commit to a structure – and when banking disruption or enforcement finds a gap, we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications. To discuss your situation, contact info@oboluslaw.com.

By Roman Levitt, Technology and DeFi Counsel – advises digital-asset operators on the intersection of technical architecture, payment infrastructure and the regulatory regimes that govern client-fund handling across multiple jurisdictions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours