For a digital-asset business, the moment fiat touches the business model is the moment legal exposure multiplies. A crypto exchange, a stablecoin issuer, a VASP (virtual asset service provider) taking client deposits – each entity depends on a banking or payment relationship that can be closed with thirty days' notice. Losing those fiat rails (the payment-system infrastructure that moves sovereign currency into and out of a crypto platform) does not merely slow growth. It stops the business entirely. With regulators in the EU, the UAE, Singapore, the UK and the United States each tightening their expectations around who may accept client fiat and under what licence, the question of where to bank and how to structure the payment layer is now a first-order legal decision, not a back-office task.
This analysis compares how the leading digital-asset jurisdictions treat the fiat on/off-ramp problem: what licences and registrations are required, where the cross-border fractures appear, and how an operator can build a payment stack that survives regulatory scrutiny across multiple markets. We examine the positions of the relevant regulators, identify the structural risks that most often strand operators, and offer a decision framework for the operator choosing between an EMI (electronic money institution), a payment licence and a third-party acquirer arrangement.
Why Fiat Rails Are the Pressure Point for Digital-Asset Businesses
The fiat on/off-ramp is the commercial chokepoint in every crypto business model. Without the ability to accept client funds in sovereign currency and to return them on demand, no exchange, no custodian and no fund administrator can function. Banks and EMIs (electronic money institutions, which issue e-money and hold funds on behalf of clients) understand this leverage and exercise it. Compliance teams at traditional financial institutions routinely flag crypto-company accounts as high-risk, citing exposure to money-laundering, sanctions evasion and regulatory uncertainty in the counterparty's home jurisdiction. Account closure risk is real and, in our cross-border practice, one of the most common crises we are called in to manage.
The underlying legal question is layered. First: does the operator itself need a licence to accept fiat from clients? Second: does the institution holding those funds – whether a bank or an EMI – have the risk appetite and compliance architecture to serve a VASP counterparty? Third: does the structure hold across the jurisdictions where clients sit, not just where the entity is incorporated? Each layer has a different answer depending on the regulatory regime in play. Operators who focus only on the crypto licence and treat the banking relationship as an administrative step routinely discover the structural flaw too late – after a bank exit letter arrives.
The practical trigger for most account closures is a mismatch between the risk profile declared at onboarding and the activity the bank subsequently observes. A VASP that describes itself as a "blockchain analytics" company at account opening and then routes high-volume retail fiat flows through the same account will not survive the bank's periodic review. In our practice, we regularly advise on disclosure strategy at the EMI or bank onboarding stage precisely to avoid this outcome.
How Does MiCA Change the EU's Approach to Fiat On-Ramps?
Under MiCA (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and the relevant national competent authorities), the fiat on/off-ramp question becomes a two-track problem: the VASP needs a CASP (crypto-asset service provider) authorisation under MiCA, and the entity that holds client fiat needs to do so under an EMI or payment institution licence – or rely on a licensed third party to do so on its behalf.
MiCA is explicit that a CASP authorisation does not, by itself, authorise the holder to issue e-money or to provide payment services. A crypto exchange that wants to hold euro balances for clients while they trade must either obtain its own EMI or payment institution authorisation or enter into an arrangement with an already-licensed EMI. The practical effect is that a single EU-authorised entity covering both the CASP and the e-money function requires two separate regulatory permissions – obtained either in the same member state or across two – and both must be in good standing for the operation to be lawful.
Passporting under MiCA allows a CASP authorised in one EU member state to provide crypto-asset services across the EU/EEA without additional authorisation in each country. EMI passporting works in a similar way under the existing e-money directive. The critical cross-border risk is that the passporting status of the CASP and the passporting status of the EMI are tracked separately by different national regulators. An operator whose Lithuanian EMI passport is suspended while the Malta CASP authorisation remains active is still non-compliant for the fiat element across every member state where it operates. Regulators in the leading hubs increasingly expect operators to have mapped this dual-track compliance architecture before they apply, not as an afterthought.
Operators we advise routinely underestimate the time needed to obtain both permissions sequentially. Where the two-track structure is required, we recommend beginning the EMI application in parallel with, or ahead of, the CASP process. A CASP authorisation without a live EMI arrangement is commercially dead on arrival for any exchange or custody business that takes client fiat.
To map the licence and EMI stack for an EU operation before the first application is filed, contact OBOLUS at info@oboluslaw.com. The structure of your entity, the location of your users and the currency flows you anticipate all change the analysis. We regularly work through these questions with operators before any regulatory commitment is made.
What Are the Banking Options Under the VARA Regime in Dubai?
The UAE presents a structural paradox for fiat rails: Dubai's VARA regime is among the world's more defined and hospitable for crypto-asset businesses, yet banking for those same businesses remains constrained by the risk appetite of the UAE banking sector. A VARA-licensed exchange operating in mainland Dubai requires a bank account to function, but UAE-licensed banks have been cautious about onboarding crypto firms, and the accounts that do exist often come with transaction limits, enhanced due diligence requirements and periodic reviews that can materially disrupt the business.
VARA's activity-based licensing model – covering advisory, broker-dealer, custody, exchange, lending, management and transfer/settlement – is architecturally sophisticated. Each activity has its own rulebook. But neither VARA nor the FSRA (in Abu Dhabi's ADGM financial free zone) issues banking licences. The payment layer remains with licensed banks or, increasingly, with licensed payment-service providers operating in the UAE market.
The cross-border dimension here is acute. Many UAE-based crypto firms maintain fiat accounts in other jurisdictions – Europe, Georgia, certain Asian markets – and route client fiat through those accounts while keeping the trading and custody infrastructure in Dubai. This structure raises two legal issues. First, the foreign account must be held at an institution that has itself performed adequate due diligence on the UAE-licensed crypto counterparty. Second, the fiat flows between jurisdictions may trigger money-transmitter or payment-service obligations in the intermediate jurisdiction. Operators who build this structure without legal analysis in each leg of the flow regularly find that the intermediate bank exits after its own compliance review.
In our practice, we have seen VARA-licensed entities lose their primary banking relationship in the first twelve months of operation – not because of any regulatory failure in Dubai, but because the correspondent banking relationship supporting the UAE account changed its crypto-sector policy globally. The redundancy structure – at minimum two banking or EMI relationships in different jurisdictions – is not optional for any crypto business that cannot afford a payment interruption of more than a few days.
How Does Singapore's MAS Framework Address the Fiat On-Ramp?
Singapore's MAS (Monetary Authority of Singapore) has developed one of the more deliberate frameworks for managing the boundary between crypto-asset activity and regulated payment services. Under the Payment Services Act, a business that facilitates the exchange of fiat currency for DPTs (digital payment tokens) requires a DPT service licence. The licence tier – standard payment institution or major payment institution – depends on thresholds that MAS sets by reference to transaction volumes and the value of e-money in issue.
Singapore's approach is notable for its clarity on what falls within the regulated perimeter: providing a platform through which fiat is exchanged for a digital token, even if the operator does not itself hold the fiat, is a regulated DPT activity. The practical implication is that a crypto business which routes fiat through a third-party payment processor but owns the matching logic and the client-facing interface may still need its own DPT licence, not merely a commercial agreement with a licensed processor. MAS has been explicit that substance prevails over structure in characterising the activity.
Singapore's AML/CFT requirements for DPT licensees track the FATF Recommendations, including the Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual asset transfer above a specified threshold). For the fiat on-ramp specifically, MAS expects the DPT licensee to conduct customer due diligence at a standard that matches or exceeds that of a licensed payment institution in the traditional finance space. Banks in Singapore have generally been more willing to onboard MAS-licensed DPT firms than unlicensed or foreign-licenced crypto businesses – which means the MAS licence itself functions as a banking pre-condition, not merely a regulatory formality.
For operators with a regional Asian hub strategy, the Singapore licence provides a credible anchor. But MAS licensing does not extend to the rest of Southeast Asia. An operator serving Thai, Indonesian or Vietnamese clients from a Singapore entity needs separate analysis of whether those jurisdictions' payment or VASP rules are engaged, and whether the fiat flows through the Singapore account create regulatory obligations in the client's home market.
Is the UK a Viable EMI Gateway for Crypto On-Ramp Business?
The UK presents a layered and, for many operators, frustrating regulatory picture. The FCA (Financial Conduct Authority) supervises both the Money Laundering Regulations registration for crypto businesses and the EMI authorisation process for firms seeking to issue e-money and hold client funds. The two regimes are legally distinct but practically intertwined: an operator that wants to run a fiat on/off-ramp within the UK, or to use a UK EMI to hold client fiat for a VASP operation, must satisfy both.
FCA MLR registration – required for any crypto-asset business carrying on business in the UK – has become materially harder over the past two years. The FCA's rejection rate for initial applications has been reported in the press as high, and the agency has been explicit about its expectations around AML systems, governance and the fitness of senior management. Many operators that obtained MLR registration when the regime was newer now face a re-assessment when they attempt to expand the scope of their activities or add a UK fiat component.
The EMI authorisation route in the UK has its own timeline and capital expectations, which vary by the scope of the permissions sought. Crucially, a UK EMI that onboards a VASP as a client must itself conduct enhanced due diligence on that VASP relationship. The EMI is not absolved of AML responsibility by virtue of the VASP's own registration. UK-authorised EMIs that serve the crypto sector have become a preferred entry point for continental European and Asian crypto businesses seeking a fiat gateway into the pound sterling zone – but the number of EMIs willing to onboard a VASP without a prior commercial relationship has narrowed as the FCA has increased its expectations of the EMI's own controls over VASP customer relationships.
For any cross-border operator considering the UK as a fiat gateway, the financial-promotion regime adds a further layer. UK financial-promotion rules for crypto-assets apply to communications made to UK persons regardless of where the communicating entity is based. An operator whose marketing materials invite UK retail users to deposit fiat may trigger the financial-promotion regime before it has any UK licence at all. We regularly advise operators on the geo-targeting and disclaimer architecture needed to manage this risk while the UK licensing process is in progress.
Why Does the US Present the Most Complex Fiat On-Ramp Challenge?
The United States presents the most structurally complex fiat on-ramp environment among the major jurisdictions. At the federal level, the relevant regulators are the SEC (for securities-linked digital assets), the CFTC (for commodity-linked assets), and FinCEN (for AML/CFT, including the Bank Secrecy Act obligations that apply to money services businesses operating in the US). Federal registration with FinCEN is a floor, not a ceiling. Above it sits a patchwork of state money-transmitter licences (MTLs) – one per state, each with its own application, surety bond, capital requirement and ongoing reporting obligation.
The NYDFS BitLicense – the New York Department of Financial Services' licence for virtual currency businesses operating in or with New York residents – is among the most demanding in the world. Obtaining it takes substantial time and resources. Operating without it while serving New York users exposes the business to enforcement that can include cease-and-desist orders, civil money penalties and personal liability for officers and directors. Yet no crypto exchange with material US retail volume can afford to exclude New York users indefinitely.
For non-US operators, the threshold question is whether US persons are being served at all. The mere availability of a website in the US, or the failure to implement robust geo-blocking, can constitute operating in the US for MTL and BitLicense purposes. We regularly advise operators on whether their current US user volumes and geo-blocking architecture place them inside or outside the US regulated perimeter – and on the remediation steps when they discover they are inside it without the required licences. The answer is almost always more nuanced than the operator's initial assumption.
An anonymized matter from our recent practice illustrates the risk. A payments business had built a fiat on-ramp serving European and Asian users, with a clear contractual prohibition on US persons. A forensic review of the IP and KYC data, conducted as part of a prospective EMI onboarding review, identified a material cohort of US-based users who had passed through KYC with non-US addresses. The operator faced a choice: immediate cessation of service to those users, or an accelerated MTL application strategy covering the states where exposure was highest. We structured the cessation and remediation program to reduce regulatory exposure while the licensing process began. No enforcement action followed.
If a prior application stalled or a banking account was closed without explanation, a second review of the structural facts often surfaces the reason and the route forward. Write to info@oboluslaw.com to discuss.
How Does a VASP Successfully Onboard With an EMI?
EMI onboarding for a VASP is a defined commercial and compliance process – but one that most operators approach underprepared. An EMI that accepts a crypto-business as a client takes on AML risk in respect of that client's own user base. The EMI's own regulator will scrutinise whether the EMI has done adequate due diligence on its crypto counterparties. This means the VASP must present itself not merely as a viable commercial counterparty but as a compliance-credible institution in its own right.
The standard information package that a regulated EMI will require includes: evidence of the VASP's own licence or registration in its home jurisdiction; a complete AML/CFT policy and procedures document; the VASP's own customer due diligence and transaction monitoring framework; details of the forensic and blockchain-analytics tools in use; the VASP's geographic markets and user demographics; a funds-flow diagram showing how client fiat enters and exits the business; and evidence of the beneficial ownership and governance structure of the VASP entity. A package that is incomplete, inconsistent or obviously templated will be declined – often without explanation.
The cross-border dimension matters. An EMI regulated under MiCA in the EU will apply enhanced scrutiny to a VASP whose crypto licence comes from a jurisdiction it regards as less developed – for example, a Seychelles or Belize entity without a serious regulatory relationship. Conversely, a MAS-licensed or VARA-licensed VASP presenting to a European EMI will typically encounter a faster and smoother onboarding process because the home regulator is recognised as credible by its European counterpart. The strategic implication is that the choice of licensing jurisdiction for the VASP itself is partly a banking pre-condition decision.
In our practice, we regularly prepare the compliance-documentation package that a VASP presents to an EMI at onboarding. We have observed that the most common reasons for rejection are: absence of a complete transaction monitoring policy with defined escalation triggers; an AML officer who cannot credibly explain the VASP's blockchain forensics capability; and a funds-flow that shows commingling of client and operating funds at any point. Each of these is fixable before the application is made.
Decision Matrix: Which Structure Fits Which Operator Profile?
Operators approaching the fiat on/off-ramp question arrive in different legal and commercial conditions. The right structure varies significantly by entity profile, volume, geography and the timeline the business can sustain.
Profile A – Early-stage exchange, EU-focused, no existing licence. This operator needs a CASP authorisation under MiCA (likely starting in Lithuania, Malta or another MiCA-implementing member state) and a separate EMI arrangement, typically via a licensed third-party EMI in the EU. Building the EMI relationship before the CASP application is complete is possible if the business plan and AML framework are sufficiently advanced. The timeline for this dual-track structure varies by jurisdiction and the completeness of the initial application, but should be planned as a matter of months rather than weeks. The primary risk is that the operator commences commercial activity before both tracks are live, creating an unlicensed-activity exposure in the fiat element.
Profile B – Established Asian exchange, expanding to Europe and the UK. This operator likely already holds a MAS DPT licence or is in the SFC VATP process in Hong Kong. The EU expansion requires a MiCA CASP authorisation (passporting will cover the bloc once obtained) and a separate EU EMI arrangement. The UK requires its own FCA MLR registration and, for any UK fiat component, a relationship with a UK-authorised EMI. The existing Asian licence provides credibility with European EMIs but does not substitute for the EU or UK permissions. The priority sequence is typically: EU CASP application, parallel EU EMI search, UK MLR registration, UK EMI relationship.
Profile C – UAE-based VASP, serving global clients. A VARA-licensed entity has strong local credentials but limited banking options within the UAE. The structure that most operators in this profile adopt is a multi-bank approach: a UAE account for local and GCC client flows, an EU EMI for European client fiat, and a separate arrangement for US clients (if any, requiring at minimum FinCEN MSB registration and state MTLs). Each leg of this structure needs independent legal analysis in its operating jurisdiction. The cross-border risk is the regulatory interaction between the legs – particularly the question of whether fiat movement between the legs triggers payment-service obligations in the transit or destination jurisdiction.
Profile D – US-based operator, seeking global fiat rails. This operator faces the hardest starting position. Federal registration with FinCEN and state MTLs are the minimum domestic floor. The NYDFS BitLicense is effectively required for any operation with material US retail volume. For international fiat rails, the operator needs EMI relationships in the relevant foreign markets – and those EMIs will conduct their own due diligence on the US regulatory status of their counterparty. An operator with full MTL coverage and FinCEN registration presents a materially stronger onboarding case to a foreign EMI than one with partial or informal US compliance. The cost and timeline of building full US compliance before seeking international rails is substantial, but operators who attempt to sequence it the other way – international rails first, US compliance later – routinely find the foreign EMI withdraws when it discovers the US compliance gap.
A Common Assumption: One Offshore Licence Is Enough
One of the most persistent misconceptions we encounter in this practice area is that a single offshore registration – from the Seychelles, Belize or another lightly regulated jurisdiction – provides a sufficient legal basis for global fiat on/off-ramp operations. It does not. It provides no banking licence, no authorisation to accept client fiat in regulated markets, and no passport into the EU, UK, US, Singapore, Hong Kong or the UAE. Banks and EMIs in those markets will decline to onboard an entity whose only regulatory credential is an offshore registration that lacks an AML framework, a supervisory relationship with a credible regulator and a recognised capital structure.
The offshore entity does serve a legitimate function in some structures: as a holding company, as the technical operator of a non-custodial protocol, or as a vehicle for certain professional investor relationships conducted entirely outside regulated markets. But for a consumer-facing crypto business that touches fiat – taking deposits, processing withdrawals, holding balances – the offshore structure as a standalone is not a compliance solution. It is a liability that will surface at the first serious banking review, the first regulatory inquiry or the first dispute with a client.
Regulators in the leading hubs increasingly expect operators to have a credible home-jurisdiction regulatory relationship and to be able to demonstrate that relationship at short notice. An operator that cannot produce its licence, its supervisor's name and its most recent regulatory interaction when asked is not operating at the standard that any serious banking counterparty requires.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – how OBOLUS structures the banking and payment layer for crypto firms across jurisdictions
- PSP and Acquiring Agreements: The Compliance Burden in Practice – what payment service provider and acquiring agreements require from a crypto business
- Redemption and Liquidity Terms: A Cross-jurisdiction Comparison – how redemption obligations and liquidity requirements interact across the leading regimes
FAQ
Why do banks close crypto company accounts?
Banks close crypto-company accounts primarily because of AML risk assessment, mismatch between declared activity and observed transaction flows, or a change in the bank's sector-wide policy on digital-asset clients. A VASP that was onboarded as a low-risk counterparty but subsequently shows high-volume, high-velocity fiat flows will trigger a periodic review. Banks also respond to supervisory pressure from their own regulators, which may discourage or prohibit exposure to unregulated or lightly regulated crypto counterparties. The practical mitigation is full disclosure at onboarding, a credible AML framework and a banking strategy that maintains at least two relationships in different jurisdictions.
How can a VASP onboard with an EMI?
A VASP onboards with an EMI by presenting a complete compliance package: the VASP's own licence or registration, a detailed AML/CFT policy, transaction monitoring procedures, blockchain-analytics tools and capacity, a funds-flow diagram, and full beneficial ownership disclosure. The EMI will assess whether the VASP's own regulatory standing is credible in its home jurisdiction. A VASP licensed under MiCA, VARA, MAS or another recognised regime presents a materially stronger onboarding case than an offshore-registered entity. Incomplete documentation is the most common reason for rejection. Legal preparation of the onboarding package materially improves the outcome.
What does client-money safeguarding require?
Client-money safeguarding requires the entity holding client fiat to keep those funds separate from its own operating funds and to maintain them in a designated account at a credit institution or central bank, or to hold equivalent eligible assets. Under MiCA and the EU e-money framework, this obligation falls on the EMI or payment institution holding the funds, not the CASP that introduced the client. A VASP that commingles client fiat with its own treasury – even temporarily – violates safeguarding rules in every major jurisdiction and creates insolvency risk for clients if the VASP fails. Regulators treat safeguarding breaches as serious, and enforcement consequences include licence revocation.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance that sit around them. We map the licence, payment and EMI stack across operating, custody and payment layers before you commit – so structural gaps surface in planning, not in a bank exit letter. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology and DeFi Counsel – advising digital-asset businesses on payment infrastructure, EMI onboarding and the cross-border legal architecture of fiat on/off-ramp operations.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.