EST · MMXXVI
Home/Insights/Tech/Fiat on/off-ramp banking: The Compliance Burden in Practice
Banking, Payments & EMI Onboarding

Fiat on/off-ramp banking: The Compliance Burden in Practice

Fiat on/off-ramp banking: The Compliance Burden in Practice. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk t

Fiat on/off-ramp banking – the conversion layer between digital assets and traditional currency – sits at the sharpest edge of the compliance burden that crypto businesses face today. As regimes converge on the MiCA (Markets in Crypto-Assets Regulation) model and regulators in every major hub tighten VASP (virtual asset service provider) supervision, the question is no longer whether fiat rails require regulatory infrastructure. The question is how much infrastructure, in how many jurisdictions, and who bears the cost when it is absent. This analysis maps the compliance terrain, identifies the principal risk points and offers a decision framework for operators building or stress-testing their banking stack.

The core problem is structural. A crypto business needs fiat rails to function: to onboard clients, settle trades and distribute proceeds. Banks and EMIs (electronic money institutions) that provide those rails carry their own regulatory obligations – and they extend those obligations, contractually and operationally, to every business they bank. Operating without the right licence therefore does not merely risk enforcement from a crypto regulator. It risks the sudden closure of the fiat gateway itself, which can be existential for a business that has no alternative banking relationship in place.

Why Fiat Rails Are a Regulatory Pressure Point

Fiat on/off-ramp banking is a pressure point because two separate regulatory regimes converge at the same transaction. The crypto business carries its VASP or CASP (crypto-asset service provider) obligations; the bank or EMI carries its payment institution or banking licence obligations. When the bank's compliance team reviews the crypto client, it is not merely assessing creditworthiness. It is assessing whether its own AML and sanctions exposure is manageable. That assessment is the compliance burden in practice.

Regulators in every major hub have made the calculation clear. The FATF Recommendation 15 regime requires VASPs to be registered or licensed and to apply AML/CFT controls equivalent to those applied in traditional finance. A bank that provides fiat rails to an unregistered VASP is providing a regulated service to an unregulated counterpart, which its own supervisors – the FCA in the United Kingdom, the relevant national competent authority under MiCA, MAS in Singapore – regard as a risk-management failure. The practical consequence is that banks apply a higher compliance threshold to crypto clients than to most other financial-services businesses. In our practice, we see this threshold applied at onboarding, at periodic review, and at any material change in the client's business model.

The cross-border dimension multiplies the pressure. A VASP domiciled in one jurisdiction – say, an entity authorised under the BVI VASP Act 2022 – that serves users in the European Union, holds fiat in a Lithuanian bank account and uses a UK-regulated EMI for card processing is simultaneously subject to BVI FSC expectations, MiCA transition rules administered by the Bank of Lithuania, and FCA crypto-financial-promotion standards. Each of those regulators has a different risk appetite, and each of the banking relationships reflects that appetite.

What Do Banks Actually Require from Crypto Clients?

Banks that agree to bank crypto businesses require a documented compliance programme – not a policy document, but evidence of operational controls. In our cross-border practice, the minimum package that sophisticated banks and EMIs expect includes: a licence or registration certificate from a recognised regulator, an AML policy tailored to the specific VASP activity, a transaction-monitoring procedure, a sanctions-screening procedure, a list of jurisdictions served, a description of how the Travel Rule is implemented, and the identity of the MLRO (money laundering reporting officer).

That list is a floor. Banks in the EU increasingly expect sight of the CASP authorisation notification or, where MiCA transition provisions apply, the prior national registration under the legacy VASP regime. Banks in Singapore expect the MAS Digital Payment Token licence or, at minimum, an in-progress application under the Payment Services Act. An entity that arrives at a banking relationship with only a white-label compliance policy and an offshore registration is unlikely to pass onboarding – and if it does pass initially, it is likely to fail the first periodic review.

The EMI route is sometimes positioned as a faster or less demanding alternative to a direct banking relationship. In practice, EMIs carry the same statutory AML/CFT obligations as banks, and they apply the same or a more conservative screening process because their own banking relationships – the correspondent banks that process their settlement – depend on the quality of their client base. We have seen EMI onboardings move efficiently when the crypto client presents a clean licence, a documented compliance structure and a business model that the EMI's risk team can explain to its own correspondent. We have seen them stall for months when the client's corporate structure spans multiple offshore entities without a clear regulated head.

For a scoped assessment of your banking and EMI onboarding position, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the jurisdictions served, the assets handled – change the analysis materially.

How Does the Travel Rule Obligation Affect Fiat Rail Access?

The Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer, derived from FATF Recommendation 16) is now a hard requirement in every major licensing jurisdiction, and its implementation directly affects a VASP's ability to maintain fiat rails. Banks and EMIs ask whether a VASP complies with the Travel Rule because non-compliance is an AML failure – and an AML failure at the crypto layer creates counterparty risk for the bank.

Implementing the Travel Rule is technically and operationally complex. A VASP must identify its counterpart VASPs, verify that they are themselves registered or licensed, transmit the required data fields at the point of transfer, and manage situations where the counterpart is unhosted or based in a jurisdiction with no Travel Rule framework. Each of these steps requires a technical solution (typically one of the established VASP-to-VASP messaging protocols), a legal agreement governing data exchange, and a procedure for handling exceptions.

The cross-border complication is that Travel Rule data thresholds, de-minimis exemptions and the precise data fields required vary by jurisdiction. An operator running a single transfer can face different obligations depending on whether the sending VASP, the receiving VASP or the fiat settlement leg falls under EU rules, Singapore rules or UK rules. Operators we advise routinely underestimate this fragmentation at the build stage and discover it only when a bank's compliance team asks for a written Travel Rule implementation summary as part of account opening.

The practical advice is to treat Travel Rule compliance as part of the banking stack, not as a separate compliance workstream. A bank relationship is easier to maintain when the Travel Rule procedure is documented before account opening and is available on request. An EMI will ask for it in any event.

Risk Appetite Fragmentation Across Hubs

Not every hub applies the same risk appetite to crypto banking, and operators who understand the differences can structure their banking stack more efficiently. The fragmentation is real, documented in regulatory guidance and visible in day-to-day practice.

In the EU, the MiCA CASP authorisation framework, administered by ESMA and national competent authorities, creates a passport that in principle should ease banking access across member states. In practice, individual banks in larger EU jurisdictions remain cautious about crypto clients, while banks in smaller member states with a history of VASP activity – including Lithuania, which built a significant VASP registration base before the MiCA transition – are more accustomed to the due diligence package a crypto business presents. The Bank of Lithuania, as the supervising authority through the transition period, has issued guidance that shapes the expectations of Lithuanian banks dealing with VASP clients.

In the UAE, the VARA (Virtual Assets Regulatory Authority) regime in Dubai and the FSRA regime within ADGM in Abu Dhabi have both attracted banking attention. Local and international banks operating in the UAE have, in recent years, developed more structured onboarding processes for VARA-licensed and FSRA-regulated entities, although the process remains demanding and typically requires engagement at a senior level with the bank's financial-crime compliance team.

Singapore and Hong Kong present a different dynamic. The MAS Payment Services Act DPT licensing regime and the SFC VATP licensing regime in Hong Kong both carry strong international recognition, which supports banking access in those jurisdictions. The trade-off is that the application process for those licences is demanding – capital, governance, compliance infrastructure and technology must all be in place before authorisation – which means the banking benefit accrues only to operators who have invested in the full regulatory stack.

The UK presents a specific challenge. The FCA's cryptoasset registration under the Money Laundering Regulations has a high attrition rate; a significant proportion of applicants have withdrawn or been refused. Businesses that are FCA-registered carry strong credibility with UK banks, but the path to registration is not straightforward. Businesses that rely on a registration in another jurisdiction to serve UK users may find that UK banks still expect them to demonstrate FCA oversight or, at minimum, a clear analysis of why UK registration is not required.

Why an Offshore Licence Alone Is Not Enough

A common assumption in the market is that a single offshore registration – under the BVI VASP Act, the Cayman VASP regime administered by CIMA, or a similar light-touch framework – is sufficient to support global banking and client service. It is not, and the gap between that assumption and operational reality is one of the most consistent patterns we observe.

An offshore registration resolves the question of whether the entity is registered somewhere. It does not resolve the question of whether it is registered in the right place for the banking relationships it needs, the clients it serves or the jurisdictions whose regulators assert supervisory reach over its activities. A BVI FSC registration is a legitimate regulatory credential. A European bank's compliance team will still ask whether the entity is authorised under MiCA if it is serving European users. An Asian bank will ask about MAS or SFC recognition. The offshore licence is a starting point, not an endpoint.

The structural answer is a multi-layer licensing approach. Operators we advise who are building for scale typically work through three layers: the operating entity (where the exchange or custody function is licensed), the payment or EMI entity (where fiat movement is regulated), and the holding or IP entity (where structure, tax efficiency and investor capital interact). Getting each layer right – and ensuring that the licensed entities in each layer can open and maintain the banking relationships their function requires – is the practical compliance burden.

If a prior banking application stalled or an account was closed, a second-read analysis can surface the structural reason and the route forward. Contact OBOLUS at info@oboluslaw.com or write to us via t.me/oboluslaw.

What Does Client-Money Safeguarding Require of Fiat Operators?

Client-money safeguarding is a distinct layer of the fiat compliance burden that sits on top of AML/CFT requirements and affects the banking relationships a VASP or EMI can maintain. In most major licensing regimes, an entity that holds client fiat balances – even temporarily, as part of an on/off-ramp function – must either segregate those balances from its own funds or cover them with an insurance or guarantee arrangement meeting regulatory specifications.

The practical implications for banking are significant. A safeguarding obligation requires a separate designated bank account, held with a credit institution that meets the regulator's criteria. Not every bank will open a designated safeguarding account for a crypto business. Those that will may impose additional due diligence obligations or restrict the jurisdictions whose client funds can be held in that account.

Under MiCA, CASP authorisations that include a custody or administration function carry explicit safeguarding requirements. The Payment Services Act regime in Singapore and the EMI framework applicable in EU member states both impose segregation obligations on entities holding client funds. The FCA's client-money rules, applicable where a UK-authorised firm is involved in the fiat leg, are among the most detailed and technically demanding in any major jurisdiction.

Operators building a fiat on/off-ramp function need to map these safeguarding requirements at the design stage. A banking relationship that cannot support a designated safeguarding account is not a banking relationship that can support a compliant fiat operation in a jurisdiction where safeguarding is mandatory. Discovering this after the business is live creates an urgent remediation problem.

Anonymized Practice Illustration

In a recent banking and structuring matter, a crypto exchange operator sought EMI onboarding in the EU after its principal banking relationship in an offshore jurisdiction closed without notice. The operator held a legacy national VASP registration under a pre-MiCA regime but had not yet completed a MiCA CASP transition notification. Its corporate structure included a BVI holding company, an EU operating subsidiary and a separate entity handling fiat settlement. Three EMI applications had stalled at the enhanced due diligence stage. We conducted a structural review, identified that the fiat-settlement entity held client funds without a documented safeguarding procedure, and prepared an updated compliance package – including Travel Rule implementation documentation and a CASP notification strategy – tailored to the EMI's correspondent bank requirements. Banking was restored within the quarter. No capital restructuring was required.

Decision Matrix: Which Profile Needs What

The right banking and licensing configuration depends on the operator's business model, jurisdictional footprint and growth stage. The following profiles illustrate the principal decision axes, written qualitatively because thresholds and capital requirements vary by jurisdiction and are confirmed only through current regulatory guidance.

Profile A – Early-stage exchange, single jurisdiction: An operator serving users in one EU member state with a single fiat currency pair. The priority is MiCA CASP authorisation in the operating jurisdiction, a direct banking relationship with a domestic bank familiar with VASP clients, and a Travel Rule solution that covers the transaction volume. The EMI route may be appropriate for card processing. The risk at this stage is underinvesting in the compliance programme, which delays banking onboarding and pushes the business toward informal or high-risk payment channels.

Profile B – Multi-jurisdiction operator, significant fiat volume: An operator with users in multiple regions, fiat in multiple currencies and a banking stack spanning at least two jurisdictions. The priority is a multi-entity structure with a CASP or equivalent licence in each material operating jurisdiction, a payment or EMI licence at the entity that moves fiat, and documented group-level AML policies that each banking partner can review. The risk here is structural fragmentation: entities that are not clearly linked in the compliance documentation create gaps that banks and EMIs identify quickly.

Profile C – Institutional OTC or custody operator: A business serving professional counterparties with large-value fiat conversions. Banks at this level apply the most rigorous due diligence. The priority is a licence from a high-recognition regulator – MAS, SFC, FSRA or VARA – combined with a tier-one banking relationship in the same or a complementary jurisdiction. Safeguarding documentation, custody-specific compliance controls and, typically, a relationship-managed banking arrangement rather than a standard commercial account are all required.

A Common Assumption: One Licence Covers Everything

A common assumption among first-time crypto business founders is that obtaining a licence in the most accessible jurisdiction resolves the banking and compliance question globally. It does not. The licence establishes a regulatory credential in one place. The banking question, the client-money question and the cross-border regulatory question are each governed by the facts of the specific business – where users are, where funds flow, where assets are held – not by the domicile of the licensed entity alone.

The practical consequence is that a business with a single licence and a single banking relationship is one adverse event away from operational paralysis. If the licence jurisdiction's regulator changes its standards, if the bank closes the account, or if a correspondent bank in the chain decides the risk profile is unacceptable, the business has no fall-back. Operators we advise who are at or above a meaningful transaction volume invest in redundancy: a second banking relationship in a complementary jurisdiction, an EMI relationship as a secondary fiat gateway, and a compliance programme that can be presented to any new banking partner without re-architecture.

The cross-border reality is not a bureaucratic obstacle. It is the operating environment. Businesses that treat it as a permanent feature of their model – rather than a temporary compliance cost – build structures that are materially more durable.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts when the client's compliance documentation no longer satisfies the bank's own AML obligations, when the business model changes without prior disclosure, or when the bank's correspondent banking relationships impose restrictions on crypto-related activity. Changes in senior personnel, an adverse regulator action or a failed periodic review can each trigger closure. The risk is mitigated by maintaining current documentation, providing proactive updates and holding a secondary banking relationship before the primary is at risk.

How can a VASP onboard with an EMI?

A VASP can onboard with an EMI by presenting a complete compliance package at the outset: a licence or registration certificate, an AML policy tailored to the VASP's specific activity, a Travel Rule implementation summary, a sanctions-screening procedure and a clear description of the jurisdictions served and the client base. EMIs apply enhanced due diligence to crypto clients and will typically escalate to their correspondent banks. The process moves more quickly when the VASP's corporate structure is simple and its regulated status is unambiguous.

What does client-money safeguarding require?

Client-money safeguarding requires that fiat balances belonging to clients be held separately from the operator's own funds, in a designated account at a qualifying credit institution. The specific requirements – which institutions qualify, what documentation the regulator expects and whether an insurance alternative is permitted – vary by licensing regime. Under MiCA, entities authorised for custody or administration functions carry explicit safeguarding obligations. Under the EU Payment Services regime and the Singapore Payment Services Act, EMIs and payment institutions face comparable segregation requirements.

About OBOLUS. OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – mapping the full licence stack across operating, custody and payment layers before you commit capital to a structure that cannot be banked. To discuss your situation, contact info@oboluslaw.com.

By Roman Levitt, Technology and DeFi Counsel – specialising in the regulatory and compliance architecture of fiat/crypto payment infrastructure and cross-border VASP structuring.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours