EST · MMXXVI
Home/Insights/Tech/Correspondent banking access: The Disputes Angle
Banking, Payments & EMI Onboarding

Correspondent banking access: The Disputes Angle

Correspondent banking access: The Disputes Angle. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Correspondent banking – the chain of nostro/vostro accounts and interbank relationships that moves fiat money across borders – is the single most consequential infrastructure question for any digital-asset business seeking to operate at scale. When that chain breaks, or refuses to connect in the first place, the legal consequences arrive fast: frozen settlement accounts, stranded client balances, regulatory breach notices, and, in the worst cases, insolvency. The disputes angle is real, and it is underexplored.

For a virtual asset service provider (VASP) or licensed exchange, losing correspondent access is not merely an operational inconvenience. It can constitute a material breach of licensing conditions, trigger client money obligations, and produce multi-forum litigation simultaneously – across the jurisdiction where the entity is licensed, the jurisdiction where the bank sits, and the jurisdiction where the clients hold claims. Operating without resilient, properly documented banking arrangements exposes the business to enforcement, frozen rails and lost banking relationships that can take months to rebuild.

This analysis maps the disputes terrain: why correspondent relationships fail, what legal instruments respond when they do, how the cross-border dimension compounds the exposure, and what a well-structured banking architecture looks like from a disputes-prevention perspective. Each section opens with a direct answer, written to stand alone for the reader in a hurry.

Why Do Correspondent Banking Relationships Fail for Crypto Businesses?

Correspondent banks terminate or refuse digital-asset business for a discrete set of legal and compliance reasons – not, as is commonly assumed, because of blanket hostility to crypto. The primary drivers are AML/CFT exposure under the FATF Recommendations, including Recommendation 15 on virtual assets, inadequate Travel Rule compliance (the obligation to pass originator and beneficiary data with a transfer), and regulatory uncertainty in the respondent's home jurisdiction. A bank that cannot satisfy its own regulator that it has adequate oversight of a downstream VASP's compliance posture will exit the relationship.

The risk is systemic. A correspondent bank in New York sits under NYDFS and FinCEN supervision. If the respondent bank – the one holding the crypto firm's account – cannot demonstrate that its VASP client has adequate KYC, transaction monitoring and Travel Rule procedures, the correspondent faces its own examination risk. The respondent therefore exits before the correspondent does. By the time the VASP receives a termination notice, the decision has often been made several levels above the relationship manager.

In our cross-border practice, we see two additional failure modes that operators frequently miss. First, the regulated perimeter shifts: a VASP licensed in one jurisdiction expands user activity into another without updating its AML programme, and the bank's compliance team flags the geographic mismatch. Second, the entity structure changes – a holding company reorganisation, a token issuance, a new product line – without a formal notification to the bank. Both trigger enhanced due diligence reviews that the VASP is unprepared for.

The legal consequence of termination is not limited to losing the account. If client funds are held in the terminated account, the question of who holds those funds on trust, under what conditions they must be returned, and within what timeframe, immediately becomes a multi-party dispute. Client money safeguarding obligations under regimes such as MiCA, the UK FCA regime and MAS Payment Services Act rules require segregation of client balances. A bank termination that freezes those balances without a clear release mechanism puts the VASP in breach of those obligations simultaneously.

For a scoped assessment of your banking architecture and its regulatory exposure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard failure path. Your facts – the entity structure, the user base geography, the licensing layer, the banking counterparties – change the analysis materially. Map your options

When correspondent banking access is lost or frozen, the available legal instruments fall into three categories: contractual claims against the bank, regulatory escalation within the relevant supervisory framework, and court-based interim relief to preserve assets or compel disclosure while the underlying claim is resolved.

Contractual claims are the most straightforward in theory and the most difficult in practice. Banking agreements for corporate accounts are almost universally written to permit termination on notice – often as little as thirty days – without cause. A claim for breach of contract therefore requires establishing that the bank acted contrary to an implied duty of good faith, breached a specific provision, or violated applicable banking regulations in the manner of termination. In England and Wales, the implied duty of fair dealing in banking contracts has been tested in a series of commercial decisions. In the US, the analysis turns on state law and federal banking regulation, with the Madden line of cases and subsequent developments informing the scope of lender discretion. Neither path is simple.

Regulatory escalation – filing a complaint with the relevant regulator – operates on a different timeline and with a different objective. The FCA in the UK, MAS in Singapore, and ESMA-coordinating NCAs under MiCA each have supervisory tools that can, in theory, encourage a bank to reconsider. In practice, regulators are reluctant to intervene in individual commercial relationships. The value of regulatory escalation is less about the immediate outcome and more about creating a documented record that the termination was not caused by the VASP's own compliance failures – a record that matters if a licensing renewal or a new banking application is pending.

Court-based interim relief is the highest-velocity tool available, and the one most relevant where client funds are at risk. A worldwide freezing order (an injunction freezing a defendant's assets globally) obtained in England and Wales, or an equivalent Mareva-style order in Singapore or Hong Kong, can preserve assets against dissipation while the underlying claim is determined. More directly relevant to the banking access question is a mandatory injunction – an order requiring the bank to continue providing the service pending trial. Courts in the major common-law forums will grant such orders in exceptional circumstances, but the threshold is high: the applicant must show a serious question to be tried, that damages would not be adequate, and that the balance of convenience favours continuance.

In a recent matter in our disputes practice, a payments company operating under a European payment institution licence lost its correspondent banking relationship following a compliance review triggered by a counterparty freeze. The bank's termination notice arrived with a fourteen-day wind-down period. We secured an emergency undertaking from the bank extending the period, engaged with the relevant NCA to document the VASP's clean compliance posture, and identified a replacement correspondent with adequate capacity before the original relationship closed. The outcome was a managed transition rather than a gap in rails. The key was acting within the first forty-eight hours of receiving the termination notice.

How Does EMI Onboarding Change the Disputes Calculus?

For many digital-asset businesses, the route to fiat rails does not run directly through a correspondent bank but through an electronic money institution (EMI) – a licensed payment firm that holds client funds, issues IBANs, and accesses the interbank system on the VASP's behalf. EMI onboarding is structurally different from direct bank onboarding, and the disputes calculus shifts accordingly.

An EMI operating under the EU's Payment Services Directive framework, the UK's EMI regime, or MAS licensing is itself a regulated entity. Its onboarding of a VASP is therefore a regulated activity: the EMI must apply its own AML/CFT procedures to the VASP as a business customer, perform a risk classification, and satisfy its own correspondent bank that the downstream VASP client base is adequately screened. The chain of regulatory obligation does not shorten – it lengthens.

The dispute risk for a VASP relying on an EMI sits at two junctions. First, if the EMI loses its own correspondent banking access – a risk that has materialised for several EMIs serving high-risk categories in recent years – the VASP's rails fail without any notice to the VASP itself. The VASP has no contractual relationship with the correspondent and no standing to claim against it directly. Its claim runs against the EMI, which may itself be insolvent or in regulatory proceedings. Second, if the EMI is acquired, changes ownership, or has its licence varied by its regulator, the risk classification of the VASP account may be reassessed unilaterally.

We regularly advise clients on the structural terms they should seek in EMI master agreements: explicit notice periods keyed to specific termination events, segregation clauses that survive any insolvency of the EMI, and information rights that give the VASP visibility into the EMI's own correspondent posture. Without these provisions, the VASP is entirely exposed to the EMI's downstream decisions.

The cross-border dimension compounds the risk. A VASP licensed in Lithuania or Malta using a UK-based EMI to access GBP rails, while its users are primarily in Southeast Asia, presents a compliance profile that each institution in the chain will assess differently. MiCA's CASP passporting concept does not extend to banking: a MiCA authorisation does not compel any bank or EMI to provide services, and the commercial decisions of banking counterparties remain outside the regulatory framework's direct reach.

Which Forums Handle Cross-Border Banking Access Disputes?

Cross-border banking access disputes for digital-asset businesses are resolved across several forums, each with different tools, timelines and costs – and the choice of forum is itself a strategic decision that shapes the outcome.

England and Wales remains the leading forum for complex cross-border financial disputes involving digital assets. The Commercial Court has jurisdiction to hear claims with an international dimension where the contract contains an English law clause or where assets are held by a bank with a London presence. The court's toolkit – freezing orders, Norwich Pharmacal disclosure orders compelling third parties to identify wrongdoers, and Bankers Trust orders compelling banks to disclose account information – is the most developed of any common-law jurisdiction. The CFAAR (Crypto Fraud and Asset Recovery) network, launched in London in September 2021, formalises cooperation between practitioners, exchanges and law enforcement on rapid asset recovery.

The DIFC Courts in Dubai offer a comparable common-law toolkit in the Middle East context. For a VASP licensed under VARA or operating in the DIFC financial free zone, the DIFC Courts can issue interim relief in support of proceedings seated elsewhere, as illustrated in recent decisions involving worldwide freezing orders in support of foreign proceedings. The courts apply English common law principles and their decisions are enforceable across a growing network of reciprocal enforcement jurisdictions.

Singapore's High Court has developed a sophisticated jurisprudence on crypto assets as property and on the availability of proprietary injunctions over digital-asset balances. For a VASP with operations or banking relationships in Singapore, the court's willingness to treat crypto as a recognisable form of property – and to grant interim relief accordingly – makes Singapore a credible litigation forum for disputes involving both fiat and on-chain assets simultaneously.

The choice of forum turns on several practical variables: where the bank is incorporated, where the contract is governed, where the client money is held, and where enforcement against the bank's assets is most efficient. A multi-forum analysis is almost always required in cross-border banking disputes, and the sequencing of proceedings – which forum moves first, and what relief it grants – is often determinative of the outcome.

If a prior banking application stalled, a relationship was terminated without adequate notice, or a compliance review has produced a freeze, a second read of the facts can surface the structural reason and the route forward. Write to info@oboluslaw.com with the timeline. Map your options

How Does MiCA and the Payment Licence Stack Interact with Banking Access?

Under MiCA, a CASP (crypto-asset service provider) authorisation creates a passportable regulatory status across the EU – but it does not create a right to banking services. The regulatory and commercial strata are formally separate, and the failure to understand that separation produces the most common structuring error we see in practice.

A business that obtains a CASP authorisation in, say, Malta under the MFSA framework or in Lithuania under the Bank of Lithuania's transition regime gains the right to offer its licensed activities to users across the EU/EEA without seeking separate authorisation in each member state. That is a significant advantage. What it does not gain is an obligation on any bank or EMI in the EU to provide it with an account, correspondent access, or fiat settlement infrastructure.

The practical consequence is that licensing and banking must be pursued in parallel, not in sequence. We have seen businesses spend considerable time and capital obtaining a MiCA CASP authorisation, only to discover at the point of launch that no bank within the passporting jurisdiction is willing to onboard them at the required transaction volume. The licensing clock and the banking clock do not run together, and the gap between them is a structural risk.

The payment licence stack adds a further dimension. A VASP that also processes fiat payments – taking deposits, executing transfers, issuing virtual IBANs – may require both a CASP authorisation and a payment institution or EMI licence, depending on the specific activities conducted. Under the MiCA regime and the Payment Services Directive framework, these are distinct authorisations with distinct capital requirements and compliance obligations. Holding one does not exempt from the other, and a bank will conduct due diligence at the level of each regulated activity separately.

In our structuring practice, we regularly map the full licence stack – operating licence, custody authorisation if applicable, payment institution or EMI licence, and AML registration – before advising on where to incorporate or where to apply first. The banking access question is built into that analysis from day one, not added as an afterthought after the first account is closed.

A Decision Matrix: Banking Architecture by Operator Profile

Different operator profiles face different banking access risks, and the right structural response varies accordingly. The following matrix is a starting point, not a prescriptive answer – the facts of each business change the analysis.

Profile A: An early-stage VASP with a single EU CASP authorisation, sub-scale transaction volumes, and no existing banking relationship. The primary risk is that no Tier 1 bank will onboard at this stage. The practical route is an EMI that specialises in crypto-adjacent businesses, with contractual protections for the segregation and return of client funds. The timeline to a functioning banking relationship via this route is typically measured in weeks from the point of a complete onboarding file. The key risk is EMI counterparty fragility – the EMI's own correspondent posture must be assessed before relying on it for material client balances.

Profile B: A mid-scale exchange with VASP registration in multiple jurisdictions, existing banking relationships, and a growing institutional client base. The primary risk is a compliance mismatch between the exchange's rapidly evolving product set and the due diligence profile the bank holds on file. The structural response is a formal banking relationship management programme – regular proactive disclosure to banking counterparties of regulatory developments, new product lines, and AML programme updates. Operators we advise in this profile typically maintain relationships with at least two banking counterparties in different jurisdictions as a continuity measure.

Profile C: An institutional-grade custodian or digital-asset fund seeking Tier 1 bank correspondent access for fiat settlement of institutional transactions. The primary risk is the length and intensity of the bank's due diligence process, which at the institutional level can run for many months and require disclosure of the full compliance framework, stress test results, and regulatory correspondence. The strategic response is engaging with banking counterparties at the earliest possible stage – ideally before the regulatory application is complete – so that the bank's diligence runs in parallel with the regulator's. Allied counsel in the relevant banking jurisdiction is typically required to navigate the bank's local regulatory requirements.

Profile D: A VASP that has experienced a banking termination and needs to rebuild rails under regulatory scrutiny. The primary risk is that the circumstances of the prior termination are treated by prospective banking counterparties as a disqualifying event. The structural response requires a clean legal record of the termination event – demonstrating that it was driven by the bank's own risk appetite, not by the VASP's compliance failures – combined with an updated and audited AML programme. The timeline to restored banking access in this profile is the longest of the four: measured in months rather than weeks, and contingent on the regulatory record.

The "Single Offshore Licence" Assumption: Why It Fails Under Dispute Pressure

A common assumption among operators entering the digital-asset space is that a single offshore licence – a BVI VASP registration, a Cayman VASP Act filing, or an equivalent registration in a light-touch jurisdiction – is sufficient to serve a global client base and maintain banking access. That assumption does not survive contact with the disputes environment.

The offshore registration addresses the question of whether the entity is registered as a VASP in its home jurisdiction. It does not address whether the entity is required to be licensed or registered in the jurisdictions where its clients are located, where its marketing is directed, or where its servers process transactions. Under MiCA, for example, a non-EU VASP actively targeting EU retail clients is subject to the regulation's marketing restrictions and may face enforcement by ESMA-coordinated NCAs regardless of its offshore registration. Under MAS regulation, a VASP providing services to Singapore residents without the applicable DPT licence faces similar exposure.

The disputes dimension is acute. When a regulatory action is commenced against an offshore-registered VASP operating across multiple jurisdictions, the entity's banking relationships in each of those jurisdictions become immediately vulnerable. Banks receive regulatory enquiry letters. Correspondent banks receive SWIFT compliance queries. The offshore registration, which provided no buffer in the regulatory analysis, also provides no protection in the banking termination that follows.

We have seen this pattern repeatedly in our practice. The structural fix is a jurisdiction-by-jurisdiction licensing analysis conducted before the business reaches scale – not after the first enforcement letter arrives. Mapping the operating jurisdiction, the user base jurisdictions, the custody jurisdiction, and the settlement jurisdiction separately, and identifying the licence required in each, is a process that takes weeks when done proactively and is far more costly when done reactively under regulatory pressure.

Self-Assessment: Is Your Banking Architecture Dispute-Resilient?

A dispute-resilient banking architecture for a digital-asset business requires more than an open account – it requires a documented, regularly reviewed set of structural protections that survive termination events, regulatory inquiries, and counterparty failures. The following questions identify the most common gaps.

First: does your banking agreement contain an explicit notice period for termination, and does that period give you sufficient time to identify and onboard a replacement? A thirty-day notice period is standard in many jurisdictions. For a business holding material client balances, it is typically insufficient. Negotiating an extended notice period – or a right to a cure period for compliance-related terminations – is achievable at the onboarding stage and very difficult to achieve afterwards.

Second: are client funds held in a segregated account that survives the insolvency of the bank or EMI? Client money safeguarding obligations under MiCA, the FCA regime and the MAS Payment Services Act all require segregation. But the contractual mechanics of how that segregation operates – who controls the account, under what conditions funds can be released, and what triggers a return obligation – must be documented in the account agreement, not assumed from the regulatory framework alone.

Third: do you have at least two independent fiat settlement relationships in different jurisdictions? A single banking relationship is a single point of failure. Regulators in the leading hubs increasingly expect licensed VASPs and payment institutions to demonstrate banking resilience as part of their ongoing compliance posture. A VARA-supervised entity in Dubai, a MiCA-authorised CASP in the EU, and an FCA-registered firm in the UK will each face this question from their respective supervisors.

Fourth: is your AML programme updated to reflect your current product set, and has that update been communicated to your banking counterparties? The compliance profile a bank holds on file is a snapshot taken at onboarding. If your business has added new products, new geographies, or new customer categories since that snapshot was taken, the bank's risk model may no longer match your actual activity. That mismatch is the most common trigger for an enhanced due diligence review that precedes a termination.

Fifth: do you have legal counsel with cross-border banking dispute experience identified and briefed before you need them? The recovery window after a banking termination is short. Acting within the first forty-eight to seventy-two hours is typically the difference between a managed transition and a gap in rails that triggers client claims and regulatory notifications simultaneously.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because of AML/CFT compliance exposure: the bank cannot adequately supervise the downstream VASP's transaction monitoring, Travel Rule compliance, or customer risk classifications, and closing the account is less costly than failing a regulatory examination. Regulatory uncertainty in the VASP's home jurisdiction, product-line changes not disclosed to the bank, and geographic expansion into higher-risk markets are the most common specific triggers. The decision is rarely about crypto as an asset class in isolation.

How can a VASP onboard with an EMI?

A VASP seeking EMI onboarding must approach the process as a regulated business customer, not as an individual account holder. The EMI will require a complete corporate structure pack, an audited or reviewed AML programme, evidence of the VASP's own regulatory status, and often a sample of transaction monitoring outputs. The onboarding timeline varies by EMI and by the VASP's risk classification. Negotiating contractual protections – segregation clauses, extended notice periods, and information rights regarding the EMI's own correspondent posture – is essential before the account agreement is signed.

What does client-money safeguarding require?

Client-money safeguarding under the major regulatory regimes – MiCA, the FCA framework, and the MAS Payment Services Act – requires that client funds be held separately from the firm's own assets, in a designated account with a regulated bank or equivalent institution. The segregation must be documented in the account agreement and must survive the insolvency of the holding entity. In practice, the mechanics of segregation – account titling, control provisions, and release conditions – must be negotiated explicitly with the banking counterparty and reviewed regularly as the regulatory framework evolves.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before clients commit – and we act when banking relationships fail. Operators we advise rely on us for cross-border banking architecture assessments before new product launches and after account closures. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Roman Levitt, Technology & DeFi Counsel – specialising in the intersection of payment infrastructure, banking access, and regulatory compliance for digital-asset businesses operating across multiple jurisdictions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours